2020-01-17 - QUICK POST: EMOTET EPOCH 2 INFECTION WITH TRICKBOT GTAG MOR78
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2020-01-17-Emotet-epoch-2-infection-with-Trickbot-gtag-mor78.pcap.zip 4.0 MB (4,002,241 bytes)
- 2020-01-17-Emotet-epoch-2-infection-with-Trickbot-gtag-mor78.pcap (4,875,819 bytes)
- 2020-01-17-Emotet-epoch-2-infection-with-Trickbot-gtag-mor78-malware-and-artifacts.zip 887 kB (887,323 bytes)
- 2020-01-17-Emotet-epoch-2-binary.exe (727,626 bytes)
- 2020-01-17-Trickbot-gtag-mor78-retreived-by-Emotet-infected-host.exe (712,823 bytes)
- 2020-01-17-downloaded-Word-doc-with-macro-for-Emotet-epoch-2.doc (261,805 bytes)
- 2020-01-17-registry-update-for-Emotet-epoch-2.txt (620 bytes)
- 2020-01-17-scheduled-task-for-Trickbot-gtag-mor78.txt (3,640 bytes)
IMAGES
Shown above: Traffic from the infection filtered in Wireshark, part 1 of 3.
Shown above: Traffic from the infection filtered in Wireshark, part 2 of 3.
Shown above: Traffic from the infection filtered in Wireshark, part 3 of 3.
Click here to return to the main page.