2018-09-21 - EMOTET INFECTIONS WITH TRICKBOT (UK AND US)

ASSOCIATED FILES:

  • 2018-09-21-Emotet-infection-with-Trickbot-from-UK-location.pcap   (17,525,561 bytes)
  • 2018-09-21-Emotet-infection-with-Trickbot-from-US-location.pcap   (3,419,428 bytes)
  • 2018-09-21-downloaded-Word-doc-with-macro-for-Emotet-from-UK-infection.doc   (91,008 bytes)
  • 2018-09-21-downloaded-Word-doc-with-macro-for-Emotet-from-US-infection.doc   (84,864 bytes)
  • 2018-09-21-Emotet-malware-binary-from-UK-infection.exe   (139,264 bytes)
  • 2018-09-21-Emotet-malware-binary-from-US-infection.exe   (139,264 bytes)
  • 2018-09-21-Trickbot-gtag-arz1-caused-by-Emotet-infection-from-US-location.exe   (483,438 bytes)
  • 2018-09-21-Trickbot-gtag-del77-caused-by-Emotet-infection-from-UK-location.exe   (494,641 bytes)
  • 2018-09-21-Trickbot-gtag-jim316-found-on-client-during-UK-infection.exe   (536,576 bytes)
  • 2018-09-21-Trickbot-gtag-lib316-found-on-DC-during-UK-infection.exe   (536,576 bytes)
  • 2018-09-21-other-Trickbot-related-binary-found-on-DC-during-UK-infection.exe   (115,712 bytes)
  • 2018-09-21-scheduled-task-for-Trickbot-on-DC-Msntcs.xml.txt   (3,602 bytes)
  • 2018-09-21-scheduled-task-for-Trickbot-on-client-Msntcs.xml.txt   (3,734 bytes)

NOTES:

 


Shown above:  Updated flow chart for what I've been seeing from Emotet malspam.

 

WEB TRAFFIC BLOCK LIST

Indicators are not a block list.  If you feel the need to block web traffic, I suggest the following URLs and partial URLs:

 

TRAFFIC

TRAFFIC FROM AN INFECTED WINDOWS HOST IN THE UK - EMOTET:

TRAFFIC FROM AN INFECTED WINDOWS HOST IN THE UK - TRICKBOT:

TRAFFIC FROM AN INFECTED WINDOWS HOST IN THE US - EMOTET:

TRAFFIC FROM AN INFECTED WINDOWS HOST IN THE US - TRICKBOT:

 

MALWARE

MALWARE FROM THE INFECTED WINDOWS HOSTS:

 

IMAGES


Shown above:  Traffic from the US-based infection filtered in Wireshark.

 


Shown above:  Traffic from the UK-based infection filtered in Wireshark.

 


Shown above:  Using Wireshark to export Trickbot malware binaries from SMB traffic in the UK-based pcap.

 

FINAL NOTES

Once again, here are the associated files:

Zip archives are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.