Inside a TrickBot Variant Using DNS Tunneling for C2
ID: 4c8a36dc-fa8b-58a1-a260-e59a59142b1b
STIX ID: report--4c8a36dc-fa8b-58a1-a260-e59a59142b1b
Feed Name: Fortinet Blog
This report analyzes a TrickBot malware variant that uses DNS tunneling instead of HTTP for C2, describing its runtime string/API obfuscation, persistence through Windows Task Scheduler and NTFS Alternate Data Streams, packet encoding/fragmentation and IP-based data transport, supported remote commands (including module download and process injection), performance characteristics, and mitigation/IOC details such as the C2 domain (westurn.in), multiple sample SHA-256 hashes, and Fortinet detection signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
