2018-04-12 - QUICK POST: TRICKBOT MALSPAM AND INFECTION TRAFFIC
ASSOCIATED FILES:
- Zip archive of the email: 2018-04-12-Trickbot-malspam-1020-UTC.eml.zip 42.7 kB (42,733 bytes)
- Zip archive of the pcap: 2018-04-12-Trickbot-malspam-infection-traffic.pcap.zip 8.3 MB (8,301,981 bytes)
- Zip archive of the malware/artifacts: 2018-04-12-Trickbot-malware-and-artifacts.zip 230 kB (229,998 bytes)
NOTES:
- Follwing up on post by My Online Security: Fake Barclays "FW: Case BARC2736166" delivers Trickbot via Microsoft Equation Editor Exploits and exploit CVE-2017-0199.
- Zip archives are password-protected with the standard password. If you don't know it, look at the "about" page of this website.
IMAGES
Shown above: Screenshot of the email.
Shown above: Opening the Word document on a vulnerable Windows host.
Shown above: Traffic from the infection filtered in Wireshark.
Shown above: Some artifacts from the infection.
Click here to return to the main page.