Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: TRICKBOT
- TRICKBOT GTAG
- gtag: rob60
- SUBJECTS OBSERVED
- DocuSign: Contract # 15857
- DocuSign: Contract # 1635
- DocuSign: Contract # 23927
- DocuSign: Contract # 3349
- Request: DocuSign # 62694
- Request: DocuSign # 71527
- Request: DocuSign # 86656
- Request: DocuSign # 91551
- SENDERS OBSERVED
- ashwariya@ancortransport.com
- dhipps@philwrightautoplex.com
- tcr@netvalue.eu
- wwileman@bigrivergrp.com
- MALDOC FILE NAMES
- Sign-777989348_690562785.xls
- 0416d69ff8f4be772867357dd1115a12
- Sign-1164698353_995554445.xls
- 4111bf4a088edc1caeeb60d7b809f5d7
- Sign-722622391_2109099014.xls
- 41731607dd571b658f0a1a4ab67a7a23
- Sign-392849493_2120691334.xls
- 4dae73b1365a37f7c8a34b5b11579dff
- Sign-948540970_2090324338.xls
- 77ac79ee534e358c7f1ae039f6996d4f
- Sign-143552984_750391982.xls
- 8daf50667544d9f76c0ba495698727bb
- Sign-667647526_1098738197.xls
- cc11f8c2e555d3e4ff6277c53658db9f
- Sign-15182856_2144370817.xls
- fd54778c030770d8a8734660c993ceba
- MALDOC FILE HASHES
- 0416d69ff8f4be772867357dd1115a12
- 4111bf4a088edc1caeeb60d7b809f5d7
- 41731607dd571b658f0a1a4ab67a7a23
- 4dae73b1365a37f7c8a34b5b11579dff
- 77ac79ee534e358c7f1ae039f6996d4f
- 8daf50667544d9f76c0ba495698727bb
- cc11f8c2e555d3e4ff6277c53658db9f
- fd54778c030770d8a8734660c993ceba
- TRICKBOT PAYLOAD URLS
- http://www.chipmania.it/mails/open.php
- TRICKBOT PAYLOAD FILE HASHES
- 8.jjkes
- 25056df6d3546de971eafe5da5f9ae44
- This file was renamed and moved to the \Documents folder
- BASE.BABAA
- 25056df6d3546de971eafe5da5f9ae44
- TRICKBOT C2
- http://216.239.32.21:80
- https://134.119.186.202:443
- https://142.202.191.164:443
- https://142.202.191.164:443
- https://182.253.107.34:443
- https://185.163.45.138:443
- https://193.8.194.96:443
- https://200.52.147.93:443
- https://212.126.125.10:447
- https://222.124.7.150:447
- https://23.160.192.125:447
- https://36.94.167.167:447
- https://36.94.62.207:443
- https://45.155.173.242:443
- TRICKBOT ADDITIONAL DOWNLOAD FILE HASH
- pwgrab64
- 783802a08864d86405a99adc3ca0179e
- TRICKBOT CONFIG FILE
- configmgr.ini
- a81fd06c1ac80050c4210c7c6e869078
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement