ATT&CKReferencesESET Trickbot Oct 2020

ESET Trickbot Oct 2020

Boutin, J. (2020, October 12). ESET takes part in global operation to disrupt Trickbot. Retrieved March 15, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples7

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareTrickBot

TrickBot uses module networkDll for process list discovery.

T1110.004
Credential Stuffing
MalwareTrickBot

TrickBot uses brute-force attack against RDP with rdpscanDll module.

T1135
Network Share Discovery
MalwareTrickBot

TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API.

T1210
Exploitation of Remote Services
MalwareTrickBot

TrickBot utilizes EternalBlue and EternalRomance exploits for lateral movement in the modules wormwinDll, wormDll, mwormDll, nwormDll, tabDll.

T1219
Remote Access Tools
MalwareTrickBot

TrickBot uses vncDll module to remote control the victim machine.

T1547.001
Registry Run Keys / Startup Folder
MalwareTrickBot

TrickBot establishes persistence in the Startup folder.

T1559.001
Component Object Model
MalwareTrickBot

TrickBot used COM to setup scheduled task for persistence.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.