2018-04-12 - QUICK POST: TRICKBOT
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
 
ASSOCIATED FILES:
- Zip archive of the email: 2018-04-12-Trickbot-malspam-1020-UTC.eml.zip 42.7 kB (42,733 bytes)
 - Zip archive of the pcap: 2018-04-12-Trickbot-infection-traffic.pcap.zip 8.3 MB (8,301,965 bytes)
 - Zip archive of the malware: 2018-04-12-malware-from-Trickbot-infection.zip 231 kB (230,556 bytes)
 
IMAGES

Shown above:  Screenshot of the email.

Shown above:  Opening the Word document on a vulnerable Windows host.

Shown above:  Traffic from the infection filtered in Wireshark.

Shown above:  Some artifacts from the infection.
Click here to return to the main page.
