查看: 1069|回复: 7
收起左侧

[病毒样本] TRICKBOT GTAG GI6

[复制链接]
YorkWaugh
发表于 2020-6-12 22:55:29 | 显示全部楼层 |阅读模式
已经不热乎了,就来水一贴

NOTES:
  • This Trickbot infection happened in an Active Directory (AD) environment with a Domain Controller (DC).
  • The infected Win7 client is at 10.6.10.197 (CINCINATTI-PC) and the DC is at 10.6.10.6 (2THUMBSUP-DC).
  • The DC was infected through Trickbots "nworm" module.
  • For some background on nworm, see:  Goodbye Mworm, Hello Nworm: TrickBot Updates Propagation Module.
  • Click on any of the below images for a higher-resolution view of the image.
  • This was originally reported by @abuse_ch as part of a malspam campaign using Black Lives Matter-themed emails to push Trickbot (link to tweet).
IMAGES

Shown above:  Screenshot of the Word doc used to generate this infection traffic.

Shown above:  Traffic from the infection filtered in Wireshark.

Shown above:  Initial location of the Trickbot DLL downloaded over HTTPS after enabling Word macros.

Shown above:  Scheduled task to keep the Trickbot infection persistent.

Shown above:  Directory with the persistent Trickbot DLL.

Shown above:  Trickbot modules on the infected Win7 host.


feixiangba
发表于 2020-6-12 23:11:06 | 显示全部楼层
Kaspersky
  1. 12.06.2020 23.05.14        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3142.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3142.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  2. 12.06.2020 23.05.14        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3142.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3142.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  3. 12.06.2020 23.05.13        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_5735.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_5735.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  4. 12.06.2020 23.05.13        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_5735.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_5735.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  5. 12.06.2020 23.05.12        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_44875.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_44875.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  6. 12.06.2020 23.05.12        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_44875.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_44875.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  7. 12.06.2020 23.05.11        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3019.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3019.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  8. 12.06.2020 23.05.11        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3019.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3019.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  9. 12.06.2020 23.05.10        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_25518.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_25518.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  10. 12.06.2020 23.05.10        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_25518.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_25518.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  11. 12.06.2020 23.05.10        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54899.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54899.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  12. 12.06.2020 23.05.10        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54899.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54899.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  13. 12.06.2020 23.05.09        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_9458.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_9458.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  14. 12.06.2020 23.05.09        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_9458.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_9458.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  15. 12.06.2020 23.05.09        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_35354.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_35354.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  16. 12.06.2020 23.05.09        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_35354.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_35354.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  17. 12.06.2020 23.05.08        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_70738.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_70738.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  18. 12.06.2020 23.05.08        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_70738.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_70738.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  19. 12.06.2020 23.05.07        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_64799.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_64799.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  20. 12.06.2020 23.05.07        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_64799.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_64799.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  21. 12.06.2020 23.05.06        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79335.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79335.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  22. 12.06.2020 23.05.06        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79335.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79335.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  23. 12.06.2020 23.05.05        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_94755.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_94755.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  24. 12.06.2020 23.05.05        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_94755.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_94755.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  25. 12.06.2020 23.05.05        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_97103.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_97103.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  26. 12.06.2020 23.05.05        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_97103.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_97103.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  27. 12.06.2020 23.05.04        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_67630.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_67630.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  28. 12.06.2020 23.05.04        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_67630.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_67630.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  29. 12.06.2020 23.05.04        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79172.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79172.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  30. 12.06.2020 23.05.04        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79172.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79172.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  31. 12.06.2020 23.05.03        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54947.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54947.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  32. 12.06.2020 23.05.03        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54947.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54947.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  33. 12.06.2020 23.05.03        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_61478.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_61478.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  34. 12.06.2020 23.05.03        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_61478.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_61478.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  35. 12.06.2020 23.05.02        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_2215.doc//ThisDocument        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_2215.doc//ThisDocument        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
  36. 12.06.2020 23.05.02        检测到的对象 ( 文件 ) 已删除        D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_2215.doc        文件: D:\Users\Cera\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_2215.doc        对象名称: HEUR:Trojan.MSOffice.Shellex.gen        对象类型: 木马程序        时间: 2020/6/12 23:05
复制代码


a233
发表于 2020-6-12 23:13:02 | 显示全部楼层
Avast 18X


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
狂欢...
发表于 2020-6-12 23:19:35 | 显示全部楼层
20个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
救命稻草
发表于 2020-6-12 23:42:49 | 显示全部楼层

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
OVS
发表于 2020-6-13 08:14:38 | 显示全部楼层
eset  20杀


本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
救命稻草
发表于 2020-6-13 09:14:55 | 显示全部楼层
Avira 20x
  1. 06/13/2020,09:13:50.231        [INFO]        FP reports status 'NO False Positive' for file 'C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\AppData\Local\service.rre' [I:10, S:111]
  2. 06/13/2020,09:13:50.231        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\AppData\Local\service.rre
  3. 06/13/2020,09:13:50.231        [INFO]        [DETECTION] file contains 'TR/AD.TrickBot.mrstp'
  4. 06/13/2020,09:13:50.278        [INFO]        FP reports status 'NO False Positive' for file 'C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\AppData\Roaming\SkyTmpl\rdserviceld.glk' [I:10, S:111]
  5. 06/13/2020,09:13:50.293        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\AppData\Roaming\SkyTmpl\rdserviceld.glk
  6. 06/13/2020,09:13:50.293        [INFO]        [DETECTION] file contains 'TR/AD.TrickBot.mrstp'
  7. 06/13/2020,09:13:50.293        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_2215.doc
  8. 06/13/2020,09:13:50.293        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.rlhzb'
  9. 06/13/2020,09:13:50.293        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_25518.doc
  10. 06/13/2020,09:13:50.293        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.avhgk'
  11. 06/13/2020,09:13:50.293        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3019.doc
  12. 06/13/2020,09:13:50.293        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.qycrv'
  13. 06/13/2020,09:13:50.293        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_3142.doc
  14. 06/13/2020,09:13:50.293        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.hlxmy'
  15. 06/13/2020,09:13:50.309        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_35354.doc
  16. 06/13/2020,09:13:50.309        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.jkulg'
  17. 06/13/2020,09:13:50.309        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_44875.doc
  18. 06/13/2020,09:13:50.309        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.debkg'
  19. 06/13/2020,09:13:50.309        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54899.doc
  20. 06/13/2020,09:13:50.309        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.tcytq'
  21. 06/13/2020,09:13:50.309        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_54947.doc
  22. 06/13/2020,09:13:50.309        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.mwgpz'
  23. 06/13/2020,09:13:50.309        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_5735.doc
  24. 06/13/2020,09:13:50.309        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.krnim'
  25. 06/13/2020,09:13:50.325        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_61478.doc
  26. 06/13/2020,09:13:50.325        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.ojfjm'
  27. 06/13/2020,09:13:50.325        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_64799.doc
  28. 06/13/2020,09:13:50.325        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.plyut'
  29. 06/13/2020,09:13:50.325        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_67630.doc
  30. 06/13/2020,09:13:50.325        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.fsnak'
  31. 06/13/2020,09:13:50.325        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_70738.doc
  32. 06/13/2020,09:13:50.325        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.apjhc'
  33. 06/13/2020,09:13:50.325        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79172.doc
  34. 06/13/2020,09:13:50.325        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.abgrt'
  35. 06/13/2020,09:13:50.325        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_79335.doc
  36. 06/13/2020,09:13:50.325        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.imfgn'
  37. 06/13/2020,09:13:50.340        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_9458.doc
  38. 06/13/2020,09:13:50.340        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.aroum'
  39. 06/13/2020,09:13:50.340        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_94755.doc
  40. 06/13/2020,09:13:50.340        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.ihfcr'
  41. 06/13/2020,09:13:50.340        [INFO]        C:\Users\Administrator.WIN-QN6STSKB9D5\Desktop\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\2020-06-10-Trickbot-gtag-gi6-malware-and-artifacts\word-docs\e-vote_form_97103.doc
  42. 06/13/2020,09:13:50.340        [INFO]        [DETECTION] file contains 'VBA/Dldr.Agent.vtpqh'
复制代码


heavencc
发表于 2020-6-13 12:58:02 | 显示全部楼层
智量杀了所有18个doc
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-5-1 22:28 , Processed in 0.150541 second(s), 18 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表