Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #trickbot IoC 20190702
- 3 separate campaigns identified (URL targets)
- VBS hosts all 64.37.52.18
- https://urlscan.io/search/#64.37.52.189
- https://www.virustotal.com/graph//drawer/node-summary/node/n64.37.52.189/1562158387651
- -----------OBSERVED-CAMPAIGN------------------
- delivery via mailchimp email
- Subject: Chartered Society of Physiotherapy Statement
- Subject: Report MediShed
- From: <displaycsp@media-shed.co.uk>
- Date: Tue, 2 Jul 2019 10:25:31 +0000
- X-MC-User: c2215dfba48a9bd45650525e4
- https://media-shed.us4.list-manage.com/track/click?u=c2215dfba48a9bd45650525e4&id=****&e=****
- see also https://urlscan.io/search/#media-shed.us4.list-manage.com
- -----------------------------
- vbs download (64.37.52.189)
- https://app.any.run/tasks/a2b5233b-3d2e-4f68-bd8a-dffc44651735/
- https://john1715.com/statement_2.php
- exe download (64.37.52.189)
- https://holahospice.org/support_edition.php
- -----------OTHER-OBSERVED-IOC------------------
- suspended (64.37.52.189)
- s://vistrav.com/pieces.php
- s://schoolquizshow.com/localsmith.php
- -----------------------------
- vbs download (64.37.52.189)
- https://app.any.run/tasks/10715be6-5915-4b12-ad92-729777c0914d
- https://gruporyg.com/summary.php
- https://app.any.run/tasks/947afb1d-d8c7-4958-bc2d-0def50a19ccd
- https://nibgroup.net/nibgroup.php
- https://app.any.run/tasks/bda3a966-1edf-4771-9ce3-86ba6f90aa5b
- https://lostinthepines.com/pen.php
- https://app.any.run/tasks/422927d4-4d63-4223-a0b3-275bc110711f
- https://abcin.org/view.php
- exe download
- https://www.1.solutions//828_929_929.exe (104.24.124.104, 104.24.125.104)
- https://beespeedy.com/388499_9939.doc (104.18.56.232, 104.18.57.232)
- https://blushingsugar.com/3332332.scr (104.31.94.21, 104.31.95.21)
- https://yown.us/goodemail.pdf (104.27.167.128, 104.27.166.128)
- https://aaaofficesupplies.com/ono1_929sminfo.docx (104.31.68.202, 104.31.69.202)
- -----------------------------
- vbs download (64.37.52.189)
- https://app.any.run/tasks/075414ef-720e-43b6-95aa-9f8348e54765
- https://starbourne.info/adjust.php
- https://app.any.run/tasks/05036cac-fc4e-41de-b2db-c55ca3f54e71
- https://planticacr.com/southaudi.php
- exe download (64.37.52.189)
- https://parkc.org/filetext.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement