ExecuteMalware

2021-02-19 Trickbot IOCs

Feb 19th, 2021
5,216
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.03 KB | None | 0 0
  1. THREAT IDENTIFICATION: TRICKBOT
  2.  
  3. TRICKBOT GTAG
  4. gtag: rob60
  5.  
  6.  
  7. SUBJECTS OBSERVED
  8. DocuSign: Contract # 15857
  9. DocuSign: Contract # 1635
  10. DocuSign: Contract # 23927
  11. DocuSign: Contract # 3349
  12. Request: DocuSign # 62694
  13. Request: DocuSign # 71527
  14. Request: DocuSign # 86656
  15. Request: DocuSign # 91551
  16.  
  17. SENDERS OBSERVED
  18.  
  19. MALDOC FILE NAMES
  20. Sign-777989348_690562785.xls
  21. 0416d69ff8f4be772867357dd1115a12
  22.  
  23. Sign-1164698353_995554445.xls
  24. 4111bf4a088edc1caeeb60d7b809f5d7
  25.  
  26. Sign-722622391_2109099014.xls
  27. 41731607dd571b658f0a1a4ab67a7a23
  28.  
  29. Sign-392849493_2120691334.xls
  30. 4dae73b1365a37f7c8a34b5b11579dff
  31.  
  32. Sign-948540970_2090324338.xls
  33. 77ac79ee534e358c7f1ae039f6996d4f
  34.  
  35. Sign-143552984_750391982.xls
  36. 8daf50667544d9f76c0ba495698727bb
  37.  
  38. Sign-667647526_1098738197.xls
  39. cc11f8c2e555d3e4ff6277c53658db9f
  40.  
  41. Sign-15182856_2144370817.xls
  42. fd54778c030770d8a8734660c993ceba
  43.  
  44. MALDOC FILE HASHES
  45. 0416d69ff8f4be772867357dd1115a12
  46. 4111bf4a088edc1caeeb60d7b809f5d7
  47. 41731607dd571b658f0a1a4ab67a7a23
  48. 4dae73b1365a37f7c8a34b5b11579dff
  49. 77ac79ee534e358c7f1ae039f6996d4f
  50. 8daf50667544d9f76c0ba495698727bb
  51. cc11f8c2e555d3e4ff6277c53658db9f
  52. fd54778c030770d8a8734660c993ceba
  53.  
  54. TRICKBOT PAYLOAD URLS
  55. http://www.chipmania.it/mails/open.php
  56.  
  57. TRICKBOT PAYLOAD FILE HASHES
  58. 8.jjkes
  59. 25056df6d3546de971eafe5da5f9ae44
  60.  
  61. This file was renamed and moved to the \Documents folder
  62. BASE.BABAA
  63. 25056df6d3546de971eafe5da5f9ae44
  64.  
  65. TRICKBOT C2
  66. http://216.239.32.21:80
  67. https://134.119.186.202:443
  68. https://142.202.191.164:443
  69. https://142.202.191.164:443
  70. https://182.253.107.34:443
  71. https://185.163.45.138:443
  72. https://193.8.194.96:443
  73. https://200.52.147.93:443
  74. https://212.126.125.10:447
  75. https://222.124.7.150:447
  76. https://23.160.192.125:447
  77. https://36.94.167.167:447
  78. https://36.94.62.207:443
  79. https://45.155.173.242:443
  80.  
  81. TRICKBOT ADDITIONAL DOWNLOAD FILE HASH
  82. pwgrab64
  83. 783802a08864d86405a99adc3ca0179e
  84.  
  85. TRICKBOT CONFIG FILE
  86. configmgr.ini
  87. a81fd06c1ac80050c4210c7c6e869078
Advertisement
Add Comment
Please, Sign In to add comment