
Pikabot Loader Poses as Trend Micro DNS Module
A Win32 DLL flagged by 60 of 78 engines as trojan.pikabot/zusy carries a fake "Trend Micro Osprey" product string despite being unsigned. Syscall-level anti-debug tricks and sandbox-stalling code sit alongside network indicators that still trip Feodo Tracker and TrickBot JA3 rules.
A Win32 DLL now flagged by 60 of 78 engines as trojan.pikabot/zusy carries a product string reading "Trend Micro Osprey" and a copyright block crediting "Trend Micro Incorporated" — grafted onto a binary that is unsigned and delivers a Pikabot loader. The disguise sits alongside syscall-level anti-debug tricks and sandbox-stalling code, and the sample's associated network indicators still trip Feodo Tracker and TrickBot JA3 fingerprint rules — legacy botnet signatures riding on infrastructure…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read