logo

Following the RTM

ID: 982971be-9ff9-5d60-88e8-79220ff115c0

STIX ID: report--982971be-9ff9-5d60-88e8-79220ff115c0

Feed Name: Group-IB Blog

Threat Score
72/100

Date Published: 2019-05-08

Date Updated: 2026-04-27

...
...

This report provides a forensic analysis of a Windows 7 image infected with the RTM banking trojan, describing how investigators used Sleuth Kit, RegRipper and other tools to identify evidence of compromise. Key findings include a phishing-driven campaign (over 11,000 malicious emails in one period), a malicious apg.exe binary masquerading as TeamViewer with a dropped msi.dll (DLL search-order hijacking), persistence via Run keys, anti-forensic TeamViewer.ini settings, and AppCompatCache entries indicating execution — together producing IOCs and TTPs useful for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.