Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Ransomware

TrickBot

Ransomware Needs review 45 detections found
This entry hasn't been reviewed yet. It was auto-detected from the MITRE ATT&CK catalog because it self-identifies as ransomware-type malware, but no one has curated a full summary or double-checked its reference links. Treat the details below as a starting point, not a verified profile.

Also known as: TSPY_TRICKLOAD, Totbrick, TrickBot

Auto-detected from the MITRE ATT&CK catalog on 2026-09-28 (S0266) - this entry has not been reviewed or curated yet. See the MITRE ATT&CK link below for what's currently known; a proper summary and authoritative eradication references are pending.

Detection & eradication references

Curated links to authoritative sources — MITRE ATT&CK, CISA advisories, law-enforcement takedown announcements, and vendor threat-intel writeups — for removal, remediation, and further technical detail. Sigma Watch does not publish its own removal steps here, since malware behavior and tooling change too fast for a static write-up to stay reliably accurate.

Detection rules

Source Rule Status Updated
elastic AdFind Command Activity production 2026-09-18
splunk Plain HTTP POST Exfiltrated Data production 2026-09-08
splunk Windows App Layer Protocol Wermgr Connect To NamedPipe production 2026-08-18
splunk Windows Gather Victim Network Info Through Ip Check Web Services production 2026-07-20
splunk Powershell Remote Thread To Known Windows Process production 2026-07-01
splunk Trickbot Named Pipe production 2026-05-13
splunk Schedule Task with Rundll32 Command Trigger production 2026-05-13
splunk Wermgr Process Spawned CMD Or Powershell Process production 2026-05-13
splunk Wermgr Process Create Executable File production 2026-05-13
splunk Mshta spawning Rundll32 OR Regsvr32 Process production 2026-05-13
splunk Wermgr Process Connecting To IP Check Web Services production 2026-05-13
splunk Windows Scheduled Task Created Via XML production 2026-05-13
suricata ET MALWARE Trickbot Checkin Response rev 9 2024-05-04
suricata ET MALWARE Win32/TrickBot Anchor Variant Style External IP Check rev 3 2024-04-29
suricata ET MALWARE Win32/TrickBot maserv Module CnC Activity rev 3 2024-04-28
suricata ET MALWARE Anchor_DNS Trickbot DNS CnC Command - Receive Data rev 3 2024-04-12
suricata ET MALWARE Anchor_DNS Trickbot DNS CnC Command - Sending Data rev 4 2024-04-12
suricata ET MALWARE Anchor_DNS Trickbot DNS CnC Command - Prepare to Receive Data rev 3 2024-04-12
suricata ET MALWARE Win32/Trickbot Data Exfiltration M2 rev 3 2024-03-26
suricata ET MALWARE Win32/Trickbot Data Exfiltration M4 rev 3 2024-03-26
suricata ET MALWARE Win32/Trickbot Data Exfiltration M3 rev 3 2024-03-26
snort ET TROJAN Win32/Trickbot Data Exfiltration M4 rev 2 2023-05-19
snort ET TROJAN Trickbot Checkin Response rev 4 2023-05-19
sigma Esentutl Gather Credentials test 2022-10-09
snort ET TROJAN Win32/Trickbot Data Exfiltration M3 rev 2 2022-03-01
snort ET TROJAN Win32/Trickbot Data Exfiltration M2 rev 2 2022-03-01
sigma Trickbot Malware Activity stable 2021-11-27
snort ET TROJAN Win32/TrickBot maserv Module CnC Activity rev 2 2021-02-02
suricata ET MALWARE Win32/Trickbot Data Exfiltration rev 2 2020-11-27
snort ET TROJAN Win32/Trickbot Data Exfiltration rev 2 2020-11-27
snort ET TROJAN Win32/TrickBot Anchor Variant Style External IP Check rev 2 2020-11-16
snort ET TROJAN Trickbot Anchor ICMP Request rev 1 2020-11-02
suricata ET MALWARE Trickbot Anchor ICMP Request rev 1 2020-11-02
suricata ET MALWARE Trickbot/Anchor ICMP Request rev 1 2020-08-18
snort ET TROJAN Trickbot/Anchor ICMP Request rev 1 2020-08-18
suricata ET JA3 Hash - [Abuse.ch] Possible Trickbot rev 2 2019-10-29
suricata ET JA3 Hash - [Abuse.ch] Possible Trickbot rev 2 2019-10-29
suricata ET JA3 Hash - [Abuse.ch] Possible Trickbot rev 2 2019-10-29
suricata ET JA3 Hash - [Abuse.ch] Possible Trickbot rev 2 2019-10-29
suricata ET JA3 Hash - Possible Malware - Trickbot rev 2 2019-10-29
yara Trickbot — —
yara MALW_dllinject_trickbot_module — —
yara MALW_systeminfo_trickbot_module — —
yara MALW_trickbot_bankBot — —
yara MALW_mailsercher_trickbot_module — —