Windows_Trojan_Trickbot_f8dac4bc
Description
Targets rdpscan module used to bruteforce RDP
Query · yara
strings:
$a1 = "rdpscan.dll" ascii fullword
$a2 = "F:\\rdpscan\\Bin\\Release_nologs\\"
$a3 = "Cookie: %s %s" wide fullword
$a4 = "<moduleconfig><needinfo name=\"id\"/><needinfo name=\"ip\"/><autoconf><conf ctl=\"srv\" file=\"srv\" period=\"60\"/></autoconf><"
$a5 = "<moduleconfig><needinfo name=\"id\"/><needinfo name=\"ip\"/><autoconf><conf ctl=\"srv\" file=\"srv\" period=\"60\"/></autoconf><"
$a6 = "X^Failed to create a list of contr" ascii fullword
$a7 = "rdp/domains" wide fullword
$a8 = "Your product name" wide fullword
$a9 = "rdp/over" wide fullword
$a10 = "rdp/freq" wide fullword
$a11 = "rdp/names" wide fullword
$a12 = "rdp/dict" wide fullword
$a13 = "rdp/mode" wide fullword
condition:
4 of ($a*)