2018-04-16 - QUICK POST: TRICKBOT
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2018-04-16-Trickbot-malspam-1155-UTC.eml.zip 26.3 kB (26,302 bytes)
- 2018-04-16-Trickbot-infection-traffic.pcap.zip 4.3 MB (4,273,455 bytes)
- 2018-04-16-malware-from-Trickbot-infection.zip 410.6 kB (410,596 bytes)
IMAGES

Shown above: Screenshot of the email.

Shown above: Opening the attached file on a vulnerable Windows host.

Shown above: Traffic from an infection filtered in Wireshark.

Shown above: Artifacts found on the infected Windows host (1 of 2).

Shown above: Artifacts found on the infected Windows host (2 of 2).

Shown above: Scheduled task to ensure persistence on the infected Windows host.
Click here to return to the main page.
