ExecuteMalware

2021-02-25 Trickbot IOCs

Feb 25th, 2021
5,605
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.08 KB | None | 0 0
  1. THREAT IDENTIFICATION: TRICKBOT
  2.  
  3. TRICKBOT GTAG
  4. gtag: rob64
  5.  
  6. SUBJECTS OBSERVED
  7. Important Notification: Precept # 69299
  8.  
  9. SENDERS OBSERVED
  10.  
  11. MALDOC FILE NAMES
  12. Att_1950394704_743646710.xls
  13. 06b7763a62cbdd2cee1b3055fbdf9617
  14.  
  15. MALDOC FILE HASHES
  16. 06b7763a62cbdd2cee1b3055fbdf9617
  17.  
  18. TRICKBOT PAYLOAD URLS
  19. http://sundancemotelwy.com/dummy/counter.php
  20.  
  21. TRICKBOT PAYLOAD FILE HASHES
  22. 8.strike
  23. 2b1eb009e6282801c4ec6a417e9861e5
  24.  
  25. renamed to:
  26. VDRK.OLASE
  27. 2b1eb009e6282801c4ec6a417e9861e5
  28.  
  29. TRICKBOT C2
  30. https://103.146.185.107:447
  31. https://131.255.106.152:449
  32. https://45.155.173.242
  33.  
  34. TRICKBOT ADDITIONAL DOWNLOAD FILE HASH
  35. networkDll64
  36. e643d3ab98806bd1ec90cafac3c83589
  37.  
  38. pwgrab64
  39. 783802a08864d86405a99adc3ca0179e
  40.  
  41. importDll64
  42. 2fc0809e1ebae2165a91a44396037f0c
  43.  
  44. TRICKBOT CONFIG FILE
  45. PluginManager.ini
  46. 28b312447a63f02cf76a9777c95135b8
  47.  
  48. FIDDLER TRAFFIC CAPTURE
  49. http://sundancemotelwy.com/dummy/counter.php
  50. http://45.155.173.242:443
  51. https://45.155.173.242/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/file/
  52. http://131.255.106.152:449
  53. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/file/
  54. http://www.myexternalip.com:443
  55. https://www.myexternalip.com/raw
  56. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/0/Windows%207%20x64%20SP1/1104/62.182.99.63/B7E4CBA0AC3BFD329AB910D91B19E896CD3FC46BD43AB29ED7A447624A92BB20/HPQ81NpzsygqjpHhWg8INXz92Oq/
  57. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/14/user/analyst/0/
  58. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/14/path/C:%5CUsers%5Canalyst%5CAppData%5CRoaming%5CWNetMonitor9913433283%5ChmVDRKrj.rrd/0/
  59. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/23/100012/
  60. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/14/DNSBL/not%20listed/0/
  61. http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?acc524294d6983a7
  62. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/14/NAT%20status/client%20is%20behind%20NAT/0/
  63. http://103.146.185.107:447
  64. https://103.146.185.107:447/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/pwgrab64/
  65. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/dpost/
  66. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/pwgrab/VERS//
  67. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/10/62/UCSYWOUAEWCIGYEKOG/1/
  68. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/WWu0IueGcEKsEqaCYSCoAm/
  69. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/pwgrab/DEBG//
  70. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/pwgrab/DPST//
  71. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/vNFxzj7r9PHX3HBhvRrZbLBTl1t9f/
  72. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/WYkx5uXMUhwlH6LYgV8x5IXMsh/
  73. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/zjNXhJTttfp5F11RbDNnnZ/
  74. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/9rjKvb8lmyZcDPU3eKrUVhILw/
  75. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/be8hGuTQhdCrQMda9nMJaW5kJFWT2gFC/
  76. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/L1nxh3DZJlpB1NRtdz/
  77. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/VZjFpBVrRt7P9VfBl7RnNp3L/
  78. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/uOClupuGtGPFOlSkt/
  79. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/zZx5LTx5LTx5TTx5TT/
  80. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/10/62/137905/1/
  81. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/63/pwgrab/sTart/U3VjY2Vzcw==//
  82. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/nzt0uH2DJUFgWhipj6r28J/
  83. https://103.146.185.107:447/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/importDll64/
  84. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/10/62/137906/1/
  85. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/63/importDll/getdata///
  86. http://127.0.0.1:50969/30321
  87. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/ZX7BX3Pt3Zvzl5RVr/
  88. https://103.146.185.107:447/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/5/networkDll64/
  89. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/importDll/InternetExplorer/grabber/
  90. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/networkDll/NETWORKDLL//
  91. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/10/62/137908/1/
  92. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/63/networkDll/start///
  93. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/importDll/Firefox/grabber/
  94. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/64/importDll/DebugLog/USER/
  95. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/Tz9F199JP9DNTXHRXbfVXfjpbj/
  96. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/vr5VRNj3TLL5VxN73z/
  97. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/h9xRb99ntLV59hrLV33hnFPz3bl/
  98. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/m4ksmu6E8GSaUcowqyYICKueYgG0u2c/
  99. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/Xfpr7PTVp379ThlnvLPRZz35Ddhjr5/
  100. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/PzfjRNvrdZF7tpNJ55dZLHpl/
  101. https://131.255.106.152:449/rob64/WIN7PC_W617601.B34A3556F7BB9A2197D9BB04D51155BF/1/B5p99RrlBTPn91Rll3Tnn51/
  102.  
Advertisement
Add Comment
Please, Sign In to add comment