| elastic |
AdFind Command Activity |
production |
2026-09-18 |
| splunk |
Plain HTTP POST Exfiltrated Data |
production |
2026-09-08 |
| splunk |
Windows App Layer Protocol Wermgr Connect To NamedPipe |
production |
2026-08-18 |
| splunk |
Windows Gather Victim Network Info Through Ip Check Web Services |
production |
2026-07-20 |
| splunk |
Powershell Remote Thread To Known Windows Process |
production |
2026-07-01 |
| splunk |
Trickbot Named Pipe |
production |
2026-05-13 |
| splunk |
Schedule Task with Rundll32 Command Trigger |
production |
2026-05-13 |
| splunk |
Wermgr Process Spawned CMD Or Powershell Process |
production |
2026-05-13 |
| splunk |
Wermgr Process Create Executable File |
production |
2026-05-13 |
| splunk |
Mshta spawning Rundll32 OR Regsvr32 Process |
production |
2026-05-13 |
| splunk |
Wermgr Process Connecting To IP Check Web Services |
production |
2026-05-13 |
| splunk |
Windows Scheduled Task Created Via XML |
production |
2026-05-13 |
| suricata |
ET MALWARE Trickbot Checkin Response |
rev 9 |
2024-05-04 |
| suricata |
ET MALWARE Win32/TrickBot Anchor Variant Style External IP Check |
rev 3 |
2024-04-29 |
| suricata |
ET MALWARE Win32/TrickBot maserv Module CnC Activity |
rev 3 |
2024-04-28 |
| suricata |
ET MALWARE Anchor_DNS Trickbot DNS CnC Command - Receive Data |
rev 3 |
2024-04-12 |
| suricata |
ET MALWARE Anchor_DNS Trickbot DNS CnC Command - Sending Data |
rev 4 |
2024-04-12 |
| suricata |
ET MALWARE Anchor_DNS Trickbot DNS CnC Command - Prepare to Receive Data |
rev 3 |
2024-04-12 |
| suricata |
ET MALWARE Win32/Trickbot Data Exfiltration M2 |
rev 3 |
2024-03-26 |
| suricata |
ET MALWARE Win32/Trickbot Data Exfiltration M4 |
rev 3 |
2024-03-26 |
| suricata |
ET MALWARE Win32/Trickbot Data Exfiltration M3 |
rev 3 |
2024-03-26 |
| snort |
ET TROJAN Win32/Trickbot Data Exfiltration M4 |
rev 2 |
2023-05-19 |
| snort |
ET TROJAN Trickbot Checkin Response |
rev 4 |
2023-05-19 |
| sigma |
Esentutl Gather Credentials |
test |
2022-10-09 |
| snort |
ET TROJAN Win32/Trickbot Data Exfiltration M3 |
rev 2 |
2022-03-01 |
| snort |
ET TROJAN Win32/Trickbot Data Exfiltration M2 |
rev 2 |
2022-03-01 |
| sigma |
Trickbot Malware Activity |
stable |
2021-11-27 |
| snort |
ET TROJAN Win32/TrickBot maserv Module CnC Activity |
rev 2 |
2021-02-02 |
| suricata |
ET MALWARE Win32/Trickbot Data Exfiltration |
rev 2 |
2020-11-27 |
| snort |
ET TROJAN Win32/Trickbot Data Exfiltration |
rev 2 |
2020-11-27 |
| snort |
ET TROJAN Win32/TrickBot Anchor Variant Style External IP Check |
rev 2 |
2020-11-16 |
| snort |
ET TROJAN Trickbot Anchor ICMP Request |
rev 1 |
2020-11-02 |
| suricata |
ET MALWARE Trickbot Anchor ICMP Request |
rev 1 |
2020-11-02 |
| suricata |
ET MALWARE Trickbot/Anchor ICMP Request |
rev 1 |
2020-08-18 |
| snort |
ET TROJAN Trickbot/Anchor ICMP Request |
rev 1 |
2020-08-18 |
| suricata |
ET JA3 Hash - [Abuse.ch] Possible Trickbot |
rev 2 |
2019-10-29 |
| suricata |
ET JA3 Hash - [Abuse.ch] Possible Trickbot |
rev 2 |
2019-10-29 |
| suricata |
ET JA3 Hash - [Abuse.ch] Possible Trickbot |
rev 2 |
2019-10-29 |
| suricata |
ET JA3 Hash - [Abuse.ch] Possible Trickbot |
rev 2 |
2019-10-29 |
| suricata |
ET JA3 Hash - Possible Malware - Trickbot |
rev 2 |
2019-10-29 |
| yara |
Trickbot |
— |
— |
| yara |
MALW_dllinject_trickbot_module |
— |
— |
| yara |
MALW_systeminfo_trickbot_module |
— |
— |
| yara |
MALW_trickbot_bankBot |
— |
— |
| yara |
MALW_mailsercher_trickbot_module |
— |
— |