ATT&CKReferencesTrend Micro Totbrick Oct 2016

Trend Micro Totbrick Oct 2016

Antazo, F. (2016, October 31). TSPY_TRICKLOAD.N. Retrieved September 14, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1053.005
Scheduled Task
MalwareTrickBot

TrickBot creates a scheduled task on the system that provides persistence.

T1055.012
Process Hollowing
MalwareTrickBot

TrickBot injects into the svchost.exe process.

T1105
Ingress Tool Transfer
MalwareTrickBot

TrickBot downloads several additional files and saves them to the victim's machine.

T1571
Non-Standard Port
MalwareTrickBot

Some TrickBot samples have used HTTP over ports 447 and 8082 for C2. Newer versions of TrickBot have been known to use a custom communication protocol which sends the data unencrypted over port 443.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.