Files
splunk-security_content/docs/_stories/trickbot.md
2022-03-09 11:36:28 +01:00

3.4 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Trickbot 2021-04-20 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint
Actions on Objectives
Exploitation
Installation
Reconnaissance

Try in Splunk Security Cloud{: .btn .btn--success}

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to the trickbot banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection even in LDAP environment.

  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2021-04-20
  • Author: Rod Soto, Teoderick Contreras, Splunk
  • ID: 16f93769-8342-44c0-9b1d-f131937cce8e

Narrative

trickbot banking trojan campaigns targeting banks and other vertical sectors.This malware is known in Microsoft Windows OS where target security Microsoft Defender to prevent its detection and removal. steal Verizon credentials and targeting banks using its multi component modules that collect and exfiltrate data.

Detections

Name Technique Type
Account Discovery With Net App None TTP
Attempt To Stop Security Service None TTP
Cobalt Strike Named Pipes None TTP
Executable File Written in Administrative SMB Share None TTP
Mshta spawning Rundll32 OR Regsvr32 Process None TTP
Office Application Spawn rundll32 process None TTP
Office Document Executing Macro Code None TTP
Office Product Spawn CMD Process None TTP
Powershell Remote Thread To Known Windows Process None TTP
Schedule Task with Rundll32 Command Trigger None TTP
Suspicious Rundll32 StartW None TTP
Trickbot Named Pipe None TTP
Wermgr Process Connecting To IP Check Web Services None TTP
Wermgr Process Create Executable File None TTP
Wermgr Process Spawned CMD Or Powershell Process None TTP

Reference

source | version: 1