TrickBot Continues Resurgence with Port-Scanning Module
#1
Information 
Quote:The TrickBot trojan is continuing its bounce-back from an autumn takedown, recently adding a network-scanning module that uses the Masscan open-source tool to look for open ports.
 
Masscan is a mass TCP/IP port scanner, which can scan the entire internet in under five minutes according to its authors, transmitting 10 million packets per second of data from a single machine. The TrickBot module that uses it, dubbed “masrv,” is likely used for network reconnaissance, according to researchers at Kryptos Logic.
 
The module arrives as either a 32-bit or 64-bit DLL library, depending on the Windows OS version of the victim machine the bot is running on. Once installed, it makes requests to the command-and-control server (C2) for a list of IP address ranges to scan, followed by port range, that it can pass as parameters to Masscan. The C2 also communicates the frequency for sending results and the transmission rate.

“At first, the module makes GET requests for information from the commands ‘freq,’ ‘domains’ and ‘rate,'” Kryptos Logic researchers explained in a Monday blog posting. “If successful, the module executes Masscan’s main function routine, which is compiled within the DLL.”

Read more: https://threatpost.com/trickbot-port-sca...le/163615/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Sysinternals Suite 4.09.2026
Changes in 4.09.202...harlan4096 — 06:57
AnyDesk 9.7.0 for Windows
Version 9.7.0 for ...harlan4096 — 06:56
NVIDIA launches DLSS 4.5 Dynamic Multi ...
DLSS 4.5 Dynamic Fra...harlan4096 — 06:55
Google Chrome 146 Adds Device Bound Sess...
Google has introdu...harlan4096 — 06:54
WhatsApp is rolling out long-overdue use...
If you use the pop...harlan4096 — 06:53

[-]
Birthdays
Today's Birthdays
avatar (36)Kiran78
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>