2020-01-17 - QUICK POST: EMOTET EPOCH 2 INFECTION WITH TRICKBOT GTAG MOR78

ASSOCIATED FILES:

  • 2020-01-17-Emotet-epoch-2-infection-with-Trickbot-gtag-mor78.pcap   (4,875,819 bytes)
  • 2020-01-17-Emotet-epoch-2-binary.exe   (727,626 bytes)
  • 2020-01-17-Trickbot-gtag-mor78-retreived-by-Emotet-infected-host.exe   (712,823 bytes)
  • 2020-01-17-downloaded-Word-doc-with-macro-for-Emotet-epoch-2.doc   (261,805 bytes)
  • 2020-01-17-registry-update-for-Emotet-epoch-2.txt   (620 bytes)
  • 2020-01-17-scheduled-task-for-Trickbot-gtag-mor78.txt   (3,640 bytes)

NOTES:

 

IMAGES


Shown above:  Traffic from the infection filtered in Wireshark, part 1 of 3.

 


Shown above:  Traffic from the infection filtered in Wireshark, part 2 of 3.

 


Shown above:  Traffic from the infection filtered in Wireshark, part 3 of 3.

 

Click here to return to the main page.