Windows_Trojan_Trickbot_78a26074
Description
Targets psfin64.dll module containing point-of-sale recon functionality
Query · yara
strings:
$a1 = "<moduleconfig><needinfo name=\"id\"/><needinfo name=\"ip\"/><autoconf><conf ctl=\"SetConf\" file=\"dpost\" period=\"14400\"/></a"
$a2 = "Dpost servers unavailable" ascii fullword
$a3 = "moduleconfig>" ascii fullword
$a4 = "ALOHA found: %d" wide fullword
$a5 = "BOH found: %d" wide fullword
$a6 = "MICROS found: %d" wide fullword
$a7 = "LANE found: %d" wide fullword
$a8 = "RETAIL found: %d" wide fullword
$a9 = "REG found: %d" wide fullword
$a10 = "STORE found: %d" wide fullword
$a11 = "POS found: %d" wide fullword
$a12 = "DOMAIN %s" wide fullword
$a13 = "/%s/%s/90" wide fullword
$a14 = "CASH found: %d" wide fullword
$a15 = "COMPUTERS:" wide fullword
$a16 = "TERM found: %d" wide fullword
condition:
3 of ($a*)