ATT&CKReferencesBitdefender Trickbot March 2020

Bitdefender Trickbot March 2020

Tudorica, R., Maximciuc, A., Vatamanu, C. (2020, March 18). New TrickBot Module Bruteforces RDP Connections, Targets Select Telecommunication Services in US and Hong Kong. Retrieved March 15, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareTrickBot

TrickBot uses module networkDll for process list discovery.

T1110.004
Credential Stuffing
MalwareTrickBot

TrickBot uses brute-force attack against RDP with rdpscanDll module.

T1135
Network Share Discovery
MalwareTrickBot

TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API.

T1219
Remote Access Tools
MalwareTrickBot

TrickBot uses vncDll module to remote control the victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.