2020-07-10 - TRICKBOT GTAG CHIL65 INFECTION
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2020-07-10-some-IOCs-for-Trickbot-gtag-chil65.txt.zip 1.2 kB (1,245 bytes)
- 2020-07-10-Trickbot-gtag-chil65-infection-traffic.pcap.zip 3.6 MB (3,615,351 bytes)
- 2020-07-10-Trickbot-gtag-chil65-malware-and-artifacts.zip 1.4 MB (1,377,410 bytes)
IMAGES
Shown above: Screenshot from the Excel spreadsheet I used for this infection.
Shown above: Initial location the Trickbot DLL was saved to.
Shown above: Trickbot persistent through a scheduled task.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.