2018-10-05 - QUICK POST: TRICKBOT MALSPAM, GTAG SAT74
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2018-10-05-Trickbot-malspam-1644-UTC.eml.zip 23.2 kB (23,158 bytes)
- 2018-10-05-Trickbot-infection-traffic.pcap.zip 18 MB (18,014,913 bytes)
- 2018-10-05-Trickbot-malware-and-artifacts.zip 11.9 MB (11,898,072 bytes)
- 2018-10-05-Trickbot-artifact-libc.bat.txt
- 2018-10-05-scheduled-task-to-keep-Trickbot-persistent-Msnetcs.xml.txt
- 2018-10-05-Trickbot-malware-binary-gtag-sat74.exe
- AMNI/
- AMNI/FAQ
- AMNI/grabber_temp.INTEG.RAW
- AMNI/Modules/
- AMNI/Modules/importDll64
- AMNI/Modules/injectDll64
- AMNI/Modules/injectDll64_configs/
- AMNI/Modules/injectDll64_configs/dinj
- AMNI/Modules/injectDll64_configs/dpost
- AMNI/Modules/injectDll64_configs/sinj
- AMNI/Modules/mailsearcher64
- AMNI/Modules/mailsearcher64_configs/
- AMNI/Modules/mailsearcher64_configs/mailconf
- AMNI/Modules/networkDll64
- AMNI/Modules/networkDll64_configs/
- AMNI/Modules/networkDll64_configs/dpost
- AMNI/Modules/systeminfo64
- AMNI/README.md
- AMNI/rtrddsettrnrtack.exe
IMAGES
Shown above: Screenshot of the email pushing Trickbot.
Shown above: Word document attached to the malspam.
Shown above: Traffic from an infected host filtered in Wireshark.
Click here to return to the main page.