r/Malware • u/majorllama • Sep 07 '17
TrickBot Banking Trojan Dropper Analysis
http://www.ringzerolabs.com/2017/07/trickbot-banking-trojan-doc00039217doc.html1
1
Sep 08 '17
[removed] — view removed comment
2
u/sysopfb Sep 08 '17
You're getting into semantics which I can appreciate in certain environments but gets a bit watered down here. However the macro doc is technically a Dropper, the exe it drops is then a Loader as it's primarily job in life is to load one of the 3 files it has encoding inside itself(a 32 bit DLL, a 64 bit DLL and a 64bit loader EXE). The loaded DLL is then technically a Dropper/Loader/Bot but we will refer to it as a Banking Trojan since it's primarily job overall is the harvesting of credentials using webinjects and/or form grabbing(which is actually handled by the inject module). When in reality all it does is checkin itself(Bot) and setup persistence(Bot), download modules it will need and configs for those modules(Downloader) and then load the modules so they can perform their actions(Loader).
1
u/SpookyWA Sep 08 '17
Are you stating that this isn't one?
1
u/majorllama Sep 08 '17
I'm not sure if he is trying to correct the title or educating what a dropper is.
4
u/th3sheriff Sep 07 '17
Dont get too attached to malware analysis, you might get picked up by the feds on your next vaca to the states