Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: TRICKBOT
- TRICKBOT GTAG
- gtag: rob64
- SUBJECTS OBSERVED
- Important Notification: Precept # 69299
- SENDERS OBSERVED
- MALDOC FILE NAMES
- Att_1950394704_743646710.xls
- 06b7763a62cbdd2cee1b3055fbdf9617
- MALDOC FILE HASHES
- 06b7763a62cbdd2cee1b3055fbdf9617
- TRICKBOT PAYLOAD URLS
- http://sundancemotelwy.com/dummy/counter.php
- TRICKBOT PAYLOAD FILE HASHES
- 8.strike
- 2b1eb009e6282801c4ec6a417e9861e5
- renamed to:
- VDRK.OLASE
- 2b1eb009e6282801c4ec6a417e9861e5
- TRICKBOT C2
- https://103.146.185.107:447
- https://131.255.106.152:449
- https://45.155.173.242
- TRICKBOT ADDITIONAL DOWNLOAD FILE HASH
- networkDll64
- e643d3ab98806bd1ec90cafac3c83589
- pwgrab64
- 783802a08864d86405a99adc3ca0179e
- importDll64
- 2fc0809e1ebae2165a91a44396037f0c
- TRICKBOT CONFIG FILE
- PluginManager.ini
- 28b312447a63f02cf76a9777c95135b8
- FIDDLER TRAFFIC CAPTURE
- http://sundancemotelwy.com/dummy/counter.php
- http://45.155.173.242:443
- https://45.155.173.242/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/file/
- http://131.255.106.152:449
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/file/
- http://www.myexternalip.com:443
- https://www.myexternalip.com/raw
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/0/Windows%207%20x64%20SP1/1104/62.182.99.63/B7E4CBA0AC3BFD329AB910D91B19E896CD3FC46BD43AB29ED7A447624A92BB20/HPQ81NpzsygqjpHhWg8INXz92Oq/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/14/user/analyst/0/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/14/path/C:%5CUsers%5Canalyst%5CAppData%5CRoaming%5CWNetMonitor9913433283%5ChmVDRKrj.rrd/0/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/23/100012/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/14/DNSBL/not%20listed/0/
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?acc524294d6983a7
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/14/NAT%20status/client%20is%20behind%20NAT/0/
- http://103.146.185.107:447
- https://103.146.185.107:447/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/pwgrab64/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/dpost/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/pwgrab/VERS//
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/10/62/UCSYWOUAEWCIGYEKOG/1/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/WWu0IueGcEKsEqaCYSCoAm/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/pwgrab/DEBG//
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/pwgrab/DPST//
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/vNFxzj7r9PHX3HBhvRrZbLBTl1t9f/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/WYkx5uXMUhwlH6LYgV8x5IXMsh/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/zjNXhJTttfp5F11RbDNnnZ/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/9rjKvb8lmyZcDPU3eKrUVhILw/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/be8hGuTQhdCrQMda9nMJaW5kJFWT2gFC/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/L1nxh3DZJlpB1NRtdz/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/VZjFpBVrRt7P9VfBl7RnNp3L/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/uOClupuGtGPFOlSkt/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/zZx5LTx5LTx5TTx5TT/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/10/62/137905/1/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/63/pwgrab/sTart/U3VjY2Vzcw==//
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/nzt0uH2DJUFgWhipj6r28J/
- https://103.146.185.107:447/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/importDll64/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/10/62/137906/1/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/63/importDll/getdata///
- http://127.0.0.1:50969/30321
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/ZX7BX3Pt3Zvzl5RVr/
- https://103.146.185.107:447/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/networkDll64/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/importDll/InternetExplorer/grabber/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/networkDll/NETWORKDLL//
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/10/62/137908/1/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/63/networkDll/start///
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/importDll/Firefox/grabber/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/importDll/DebugLog/USER/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/Tz9F199JP9DNTXHRXbfVXfjpbj/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/vr5VRNj3TLL5VxN73z/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/h9xRb99ntLV59hrLV33hnFPz3bl/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/m4ksmu6E8GSaUcowqyYICKueYgG0u2c/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/Xfpr7PTVp379ThlnvLPRZz35Ddhjr5/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/PzfjRNvrdZF7tpNJ55dZLHpl/
- https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/B5p99RrlBTPn91Rll3Tnn51/
Advertisement
Add Comment
Please, Sign In to add comment