2018-07-09 - QUICK POST: TRICKBOT INFECTION (GTAG: SER0709US)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2018-07-09-Trickbot-infection-in-AD-environment-no-lateral-movement.pcap.zip 13.2 MB (13,212,213 bytes)
- 2018-07-09-malware-and-artifacts-from-Trickbot-infection.zip 328 kB (328,043 bytes)
NOTES:
- No lateral movement during today's Trickbot infection. The domain controller was uninfected.
Shown above: Flow chart for today's Hancitor malspam infection.
Click here to return to the main page.