Files
splunk-security_content/docs/_stories/trickbot.md
T
2021-09-20 20:45:22 -04:00

2.8 KiB

title, last_modified_at, toc, tags
title last_modified_at toc tags
Trickbot 2021-04-20 true
Splunk Enterprise
Splunk Enterprise Security
Splunk Cloud
Endpoint

Description

Leverage searches that allow you to detect and investigate unusual activities that might relate to the trickbot banking trojan, including looking for file writes associated with its payload, process injection, shellcode execution and data collection even in LDAP environment.

  • ID: 16f93769-8342-44c0-9b1d-f131937cce8e
  • Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
  • Datamodel: Endpoint
  • Last Updated: 2021-04-20
  • Author: Rod Soto, Teoderick Contreras, Splunk

Detection profiles

Name Technique Type
Account Discovery With Net App None TTP
Attempt To Stop Security Service None TTP
Cobalt Strike Named Pipes None TTP
Mshta spawning Rundll32 OR Regsvr32 Process None TTP
Office Application Spawn rundll32 process None TTP
Office Document Executing Macro Code None TTP
Office Product Spawn CMD Process None TTP
Powershell Remote Thread To Known Windows Process None TTP
Schedule Task with Rundll32 Command Trigger None TTP
Suspicious Rundll32 StartW None TTP
Trickbot Named Pipe None TTP
Wermgr Process Connecting To IP Check Web Services None TTP
Wermgr Process Create Executable File None TTP
Wermgr Process Spawned CMD Or Powershell Process None TTP
Write Executable in SMB Share None TTP

Reference

source | version: 1