Following the RTM
ID: 982971be-9ff9-5d60-88e8-79220ff115c0
STIX ID: report--982971be-9ff9-5d60-88e8-79220ff115c0
Feed Name: Group-IB Blog
This report provides a forensic analysis of a Windows 7 image infected with the RTM banking trojan, describing how investigators used Sleuth Kit, RegRipper and other tools to identify evidence of compromise. Key findings include a phishing-driven campaign (over 11,000 malicious emails in one period), a malicious apg.exe binary masquerading as TeamViewer with a dropped msi.dll (DLL search-order hijacking), persistence via Run keys, anti-forensic TeamViewer.ini settings, and AppCompatCache entries indicating execution — together producing IOCs and TTPs useful for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
