The following graph shows the rate of discovery of TrickBot versions in the wild, based on shared mcconfs. (Note: The flatter the line, the more frequently versions are discovered.) Three new versions discovered last week (1000083, 1000084 and 1000085), four the week before, and five the week before that.
The following graph shows the number of server entries using ports:
- 443 (HTTPS);
- 445 (IBM AS Server Mapper);
- 449 (Cray Network Semaphore Server); and
- 451 (SMB).
The BGP prefix registrations for the C2 server IP address are heavily biased to RU. New IPs allocated to 21xRU, 5xLT, 3xLU, 3xNL, 3xPA, and 1xPL
The following table shows a new analysis - the BGP allocation to country by TrickBot version.
Thanks to
@mpvillafranca94,
@VK_Intel,
@K_N1kolenko,
@hasherezade,
@ArnaudDlms,
@StackGazer,
@0bscureC0de,
@voidm4p,
@James_inthe_box,
@MakFLwana,
@_ddoxer,
@spalomaresg,
@virsoz,
@botNET___,
@moutonplacide, and
@JasonMilletary
for sharing the mcconfs.