AhnLab

  • Privacy & Security
  • EULA
  • Contact Us
  • Terms of Use
  • Sitemap

Subscribe to Our Newsletter

Stay informed with AhnLab’s latest threat intelligence
and security insights delivered monthly to your inbox.

Country
AhnLab V3 Engine VersionOES :
Update Engine Now →
  • Visit our LinkedIn Profile
  • Visit our Twitter page
  • Visit our YouTube channel
  • © AhnLab, Inc. All rights reserved.
  • ASEC
  • MyCompany(ELS)
  • AhnLab Document Center
    • Contact Us
    • My Company
    • Security Map
Article
09-01-2017

TrickBot, a Reincarnation of “The” Dyre

A new malware bot TrickBot seemed like Dyre was brought back to life. TrickBot had a lot in common with the infamous Dyre banking Trojan.

 

In 2014, Dyre malware caused havoc in the banking systems all over the world for stealing online banking information via spammed emails tailored to look like a legitimate bank notification. Just like Dyre, TrickBot used the same method of operation: spammed emails.

 

TrickBot targets banking information via emails with malicious attachments. If a user opens the .doc attachment, an image appears as shown in Figure 1, which is disguised as the login page of a well-known bank.

 

 

[Figure 1] TrickBot malware disguised as a bank login page

 

However, the attachment contains macros that downloads TrickBot from the C&C server using PowerShell when activated.

 

TrickBot was first discovered in October 2016, designed to steal financial information from infected systems and has been steadily distributed via spammed emails and vulnerable websites. The name comes from the mutex name within the code, which was Global\\TrickBot. However, the recently discovered TrickBot has a different mutex name, VLock.

 

TrickBot operates by copying itself to a specific path within an infected system and adding itself as a task in the Windows Task Scheduler to automatically re-execute the process. There is an encrypted malware within the resources of TrickBot code which loads onto the computer’s memory and executes when TrickBot is operated. The malware loaded in the memory collects information about the infected system, such as the computer name and operating system type, and generates an ID that serves as the unique identifier of the infected system.

 

TrickBot then generates a specific URL string based on the unique identifier and attempts to access the C&C server. TrickBot will use the information it collected from a system and inject itself to a website browser and online banking information.

 

AhnLab’s major solutions provide proactive measures against malware that are distributed via spam emails, such as TrickBot. AhnLab’s Advanced Persistent Threat (APT) protection solution, AhnLab MDS, counters such malware attacks by employing Mail Transfer Agent (MTA) mode. In this mode, AhnLab MDS detects, analyzes, and quarantines potentially malicious emails, thereby responding effectively not only to advanced spear-phishing email attacks, but also to email-based ransomware.

 

To learn more about AhnLab MDS, please visit ahnlab.com. 

 

The relevant aliases identified by AhnLab’s security solutions are as below:

<Aliases identified by AhnLab V3>

W97M/Downloader 

Trojan/Win32.Trickbot 

Trojan/Win32.ZBot 

 

<Alias identified by AhnLab MDS>

Malware/MDP.Execute

List

Related Content

Article

AhnLab V3 Earns VB100 Certification with Grade A+

AhnLab V3 Earns VB100 Certification with Grade A+

White Paper

How Agentic AI Is Reshaping the Role of Security Admins

How Agentic AI Is Reshaping the Role of Security Admins

Article

AhnLab Partners with the Korean National Police Agency to Combat Phishing Crimes

AhnLab Partners with the Korean National Police Agency to Combat Phishing Crimes

Article

The Evolution of AI-Powered Hacking Tools

The Evolution of AI-Powered Hacking Tools

skip navigation
  • 메뉴
  • 본문
  • 하단 정보(링크)
  • Products
    • AhnLab PLUS Platform
    • AhnLab Endpoint PLUS
      • Anti-Malware
      • EPP
      • Sandbox (ATD)
      • EDR
      • SMB Security
      • Mobile Security
    • AhnLab Network PLUS
      • NGFW
      • IPS
      • DDoS Mitigation
      • Sandbox (ATD)
      • Threat Management
    • AhnLab Cloud PLUS
      • CWPP
      • Cloud NGFW
      • Cloud IPS
      • Cloud Threat Management
    • AhnLab Connect PLUS
      • XDR
      • Threat Intelligence
      • SOAR
    • AhnLab CPS PLUS
      • CPS Protection Management
      • OT Endpoint Protection
      • OT IDS
      • OT Portable AV
      • OT Firewall
      • OT Data Diode
      • OT Network Sandbox
      • IT Endpoint Protection
      • IT Anti-Malware
      • CPS Threat Intelligence
    • AhnLab AI PLUS
    • All Products and Services
  • Services
    • AhnLab Service PLUS
      • MDR
      • MSS
      • Professional Service
      • Security Consulting
      • Digital Forensics
      • Cloud Managed Service
      • Global Partners
    • All Products and Services
  • Solution
    • Ransomware Protection
    • Hybrid Cloud Security
    • Zero Trust
    • CPS Protection
    • SOC Modernization
    • TDR
    • DDoS Mitigation
  • Support
    • Technical Support
    • Threat Inquiry
    • Online Support
      • Q&A
    • Notice
    • Download
    • AhnLab Document Center
  • Content Center
    • Content Center
    • ASEC
      • Threat Descriptions
      • Threat Actor Naming
      • ASEC Security Advisory
      • ASEC Blog
    • Highlights
      • MITRE ATT&CK Eval Round 7
      • AhnLab 30th Anniversary
      • Frost Radar CPS Security Leader
  • Partners
  • Company
    • About Us
    • Strategic Materials
my page
Sign InSign Up
언어 선택

No recent searches