Sunday, 1 October 2017

Initial Adhoc TrickBot Analysis - SRV port usage

Here's some initial analysis of the TrickBot Banking Trojan's command and control (C2) server entries in its 'mcconf'. The graph shows the number of server entries using ports 443 and 449 across 26 version, up to 1000062.

Thanks to @VK_Intel for providing the configurations.