2020-03-09 - QUICK POST: FASTLOADER --> TRICKBOT GTAG WMD44
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2020-03-09-fastloader-and-Trickbot-infection-traffic.pcap.zip 11.1 MB (11,095,720 bytes)
- 2020-03-09-fastloader-and-Trickbot-infection-traffic.pcap (11,893,878 bytes)
- 2020-03-09-fastloader-and-Trickbot-malware-and-artifacts.zip 948 kB (947,877 bytes)
- 2020-03-09-Trickbot-gtag-wmd44.bin (471,040 bytes)
- 2020-03-09-Word-doc-with-macro-for-Trickbot.bin (147,880 bytes)
- 2020-03-09-artifact-hg32j.bat.txt (39 bytes)
- 2020-03-09-artifact-kjh4ek-ban3j.bat.txt (169 bytes)
- 2020-03-09-artifact-kjh4ek-ndj34h.bat.txt (83 bytes)
- 2020-03-09-fastloader-and-Trickbot-malware-info.txt (4,378 bytes)
- 2020-03-09-fastloader-sample.bin (268,800 bytes)
- 2020-03-09-follow-up-Trickbot-EXE-cursor.png-from-64.44.133.131.bin (376,832 bytes)
- 2020-03-09-scheduled-task-to-keep-Trickbot-persistent.txt (3,702 bytes)
- 2020-03-09-settings.ini-for-Trickbot-gtag-wmd44-sample.txt (40,326 bytes)
IMAGES
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.