Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: BAZARCALL / TRICKBOT
- SENDERS OBSERVED
- None
- SUBJECTS OBSERVED
- None
- LURE PHONE NUMBER
- Unknown
- MALDOC LANDING PAGE URLS
- https://justpayless.us/
- MALDOC DOWNLOAD URLS
- https://justpayless.us/cancel.php
- MALDOC (XLSB) FILE HASHES
- cancel_sub_JPL8295##########.xlsb
- db3591a2399045b6bb5f44e49ac240b1
- ADDITIONAL/CAMPO LOADER FILES
- 5015.x2
- e823e06ea0c70beed8761338108c1b9b
- 5015.xlsb
- ac93399749a63a9c3584ae48a586cde8
- 5015.x1
- ac93399749a63a9c3584ae48a586cde8
- CAMPO LOADER PAYLOAD DOWNLOAD URLS
- http://176.111.174.80/campo/u/n3
- PAYLOAD DOWNLOAD URL
- http://bargemaster.in/yas30vbdrfdE.dll
- TRICKBOT FILE HASHES
- yas30vbdrfdE.dll
- 60a7f90fa282934e3054d0d5cb00bb98
- Renamed and copied:
- itjbn.dll
- 60a7f90fa282934e3054d0d5cb00bb98
- TRICKBOT GTAG
- gtag: yas30
- TRICKBOT C2s
- https://181.176.174.139
- https://181.176.221.151
- https://182.16.165.38
- https://185.138.78.73
- https://185.242.88.63
- https://185.242.89.198
- https://186.32.3.108
- https://186.46.168.46
- https://188.137.76.235
- https://188.254.102.79
- https://190.255.36.100
- https://190.96.84.250
- https://200.170.149.209
- https://200.58.84.94
- https://203.80.171.162
- https://203.80.171.189
- https://206.192.254.100
- https://31.129.228.122
- https://36.71.150.118
- https://36.91.98.231
- https://36.95.4.29
- https://41.189.214.11
- https://43.225.148.118
- https://45.182.190.142
- https://45.234.248.146
- https://45.7.56.172
- SUPPORTING EVIDENCE
- https://tria.ge/210520-qwfdf1za9s
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement