2020-07-10 - TRICKBOT GTAG CHIL65 INFECTION
- 2020-07-10-some-IOCs-for-Trickbot-gtag-chil65.txt.zip 1.2 kB (1,245 bytes)
- 2020-07-10-Trickbot-gtag-chil65-infection-traffic.pcap.zip 3.6 MB (3,615,351 bytes)
- 2020-07-10-Trickbot-gtag-chil65-malware-and-artifacts.zip 1.4 MB (1,376,526 bytes)
- All zip archives on this site are password-protected with the standard password. If you don't know it, see the "about" page of this website.
Shown above: Screenshot from the Excel spreadsheet I used for this infection.
Shown above: Initial location the Trickbot DLL was saved to.
Shown above: Trickbot persistent through a scheduled task.
Shown above: Traffic from the infection filtered in Wireshark.
Click here to return to the main page.