+ -

Pages

Thursday, July 20, 2017

TrickBot Banking Malware - some features of interest

Here's one:

It creates this dir - c:\Users\%username%\appdata\Roaming\winapp\

Now - if you're thinking that creating this dir yourself and then read/write protecting it will make this malware not execute fully, you're wrong :)

If it cant access that location to create the directory, it simply dumps the PE on Desktop and executes from there.

Cool stuff!
5 RakshaTec: TrickBot Banking Malware - some features of interest Here's one: It creates this dir - c:\Users\%username%\appdata\Roaming\winapp\ Now - if you're thinking that creating this dir y...

No comments:

Post a Comment

< >