Detricking TrickBot Loader
ID: 45041651-1e3b-5802-b3db-d8ead27dbb00
STIX ID: report--45041651-1e3b-5802-b3db-d8ead27dbb00
Feed Name: CERT Polska
Threat Score
Technical analysis of the TrickBot (TrickLoader) loader describing its multi-stage unpacking and detricking workflow: function-table XOR encryption, custom-base64 string encoding, API hash resolution, anti-debug/anti-AV checks (DLL and service detection plus attempts to stop/delete AV services), and payload execution methods including MiniLZO-compressed payloads and a 32→64-bit switch via Heaven's Gate; the report includes sample hashes and a list of distributed modules.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
