Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: TRICKBOT
- TRICKBOT GTAG
- gtag: rob75
- SUBJECTS OBSERVED
- Documents need you to sign and return # 71669
- SENDERS OBSERVED
- donald@signarama-myrtlebeach.com
- MALDOC FILE NAMES
- Confirm-506959931-817863611.xls
- c7692550e6bf5e54b853f45e0e553883
- MALDOC FILE HASHES
- c7692550e6bf5e54b853f45e0e553883
- TRICKBOT PAYLOAD URLS
- http://quanticemotions.com/sitemaps/maps.php
- TRICKBOT PAYLOAD FILE HASHES
- 10.iops
- 88923e29ce467b4211f407b4c26675cf
- TRICKBOT C2
- https://95.210.118.90:449
- https://103.225.138.94:449
- https://122.2.28.70:449
- https://123.200.26.246:449
- https://131.255.106.152:449
- https://142.112.79.223:449
- https://154.126.176.30:449
- https://180.92.238.186:449
- https://187.20.217.129:449
- https://201.20.118.122:449
- https://202.91.41.138:449
- SUPPORTING EVIDENCE
- https://urlhaus.abuse.ch/url/1061846/
- https://twitter.com/p5yb34m/status/1370063890181021696
- https://app.any.run/tasks/7d26019d-e708-4502-aa0f-d05227ac3168/
- https://tria.ge/210311-aqh1cd58kj
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement