Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: TRICKBOT
- SUBJECTS OBSERVED
- Products and solutions rates
- SENDERS OBSERVED
- Woodways <intake@ephomecare[.]com>
- EMAIL BODY
- Hello,
- Earlier we've spoke, you asked me to return in touch in the end of july.
- I could be a month early, but I figured itβd be seriously worth checking-in.
- I've enclosed a price list as well as info pages which describe the total series of our products and services for your personal reference.
- I anticipate receiving a reply from your side} {soon.
- Kind Regards,
- Adam Rivera
- Woodways
- MALDOC FILE HASHES
- UOD_1490.xls
- b9343a92b6b5b82a4b70ecf6e0206740
- TRICKBOT PAYLOAD FILE HASHES
- okYsjao[.]exe
- 4fdc6df3b378c716ff25423991b25a78
- SECONDARY PAYLOAD FILE HASHES
- cursor[.]png
- 76aebf3de7d58ecda30f49010ac9358a
- imgpaper[.]png
- 51dd0b7ba2dd137e4ec0a7bfdc23c158
- TRICKBOT PAYLOAD URLS
- hxxps://feedingyourhealth[.]com/oprawilson/opwasaythatthisverygoodinfo[.]php
- This is an open directory with dozens of Trickbot executables:
- hxxps://feedingyourhealth[.]com/oprawilson/
- SECONDARY PAYLOAD URLS
- hxxp://23[.]95[.]231[.]200/images/imgpaper[.]png
- hxxp://23[.]95[.]231[.]200/images/cursor[.]png
- TRICKBOT C2
- hxxp://170[.]238[.]117[.]187:8082/ono51
- hxxp://203[.]176[.]135[.]102:8082/ono51
- SUPPORTING EVIDENCE
- https://twitter.com/malware_traffic/status/1277619624243314688
- https://app.any.run/tasks/7dafa6d5-fc86-4872-a6c5-05e99afedd5e/
- https://urlhaus.abuse.ch/url/400727/
- https://urlhaus.abuse.ch/browse.php?search=feedingyourhealth.com%2Foprawilson%2F
Add Comment
Please, Sign In to add comment