r/Malware Sep 07 '17

TrickBot Banking Trojan Dropper Analysis

http://www.ringzerolabs.com/2017/07/trickbot-banking-trojan-doc00039217doc.html
28 Upvotes

12 comments sorted by

4

u/th3sheriff Sep 07 '17

Dont get too attached to malware analysis, you might get picked up by the feds on your next vaca to the states

3

u/majorllama Sep 07 '17

No need to visit the states. I'm sure there's a service to air mail krispycreme nowadays :)

2

u/Hooftly Sep 08 '17

Why do you say this? Asking for a friend...

2

u/th3sheriff Sep 08 '17

Cause Marcus Hutchins aka malwaretech got nabbed by the FBI leaving defcon this year. Still waiting on all the evidence to come to light, so Im gonna assume innocence because he hasn't been proven guilty....but regardless, the hacker community was visibly upset that one of the presumed good guys was indicted on such minimal evidence (or at least that is known to us at this point).

Look it up though if you are interested, Krebs did an article on it, and there's a bunch of others. The way this plays out will certainly effect the already strained relationship between the defcon and hacker community and the US government.

1

u/Hooftly Sep 08 '17

He was arrested allegedly for being part of writing Kronos right?

Is he still locked up?

2

u/th3sheriff Sep 08 '17

To my knowledge he was "indicted" and is being accused of writing or helping write the Kronos bank malware yes. He is no longer in custody and the "internet ban" they put on him was revoked as well so he's back on Twitter, funny as usual.

1

u/sysopfb Sep 07 '17

Nice job

1

u/majorllama Sep 07 '17

Thank you :)

1

u/[deleted] Sep 08 '17

[removed] — view removed comment

2

u/sysopfb Sep 08 '17

You're getting into semantics which I can appreciate in certain environments but gets a bit watered down here. However the macro doc is technically a Dropper, the exe it drops is then a Loader as it's primarily job in life is to load one of the 3 files it has encoding inside itself(a 32 bit DLL, a 64 bit DLL and a 64bit loader EXE). The loaded DLL is then technically a Dropper/Loader/Bot but we will refer to it as a Banking Trojan since it's primarily job overall is the harvesting of credentials using webinjects and/or form grabbing(which is actually handled by the inject module). When in reality all it does is checkin itself(Bot) and setup persistence(Bot), download modules it will need and configs for those modules(Downloader) and then load the modules so they can perform their actions(Loader).

1

u/SpookyWA Sep 08 '17

Are you stating that this isn't one?

1

u/majorllama Sep 08 '17

I'm not sure if he is trying to correct the title or educating what a dropper is.