2018-04-12 - QUICK POST: TRICKBOT
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- Zip archive of the email: 2018-04-12-Trickbot-malspam-1020-UTC.eml.zip 42.7 kB (42,733 bytes)
- Zip archive of the pcap: 2018-04-12-Trickbot-infection-traffic.pcap.zip 8.3 MB (8,301,965 bytes)
- Zip archive of the malware: 2018-04-12-malware-from-Trickbot-infection.zip 231 kB (230,556 bytes)
IMAGES
Shown above: Screenshot of the email.
Shown above: Opening the Word document on a vulnerable Windows host.
Shown above: Traffic from the infection filtered in Wireshark.
Shown above: Some artifacts from the infection.
Click here to return to the main page.