Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- TRICKBOT PROPAGATION URLS ON FRIDAY 2020-06-19
- URLS:
- - hxxp://162.216.0[.]166/ico/VidT6cErs
- - hxxp://162.216.0[.]166/images/cursor.png
- - hxxp://162.216.0[.]166/images/imgpaper.png
- NOTES:
- - These URLs were noted as early as Wednesday 2020-06-16.
- - Theese URLs appear to be return a different file hash each time they are queried.
- - The HTTP request for VidT6cErs is caused by Trickbot's nwormDll module (jim-series gtag).
- - The HTTP request for cursor.png is caused by Trickbot's mshareDll module (tot-series gtag).
- - The HTTP request for imgpaper.png is caused by Trickbot's tabDll module (lib-series gtag).
- More info on the new "nworm" module used by Trickbot:
- - https://unit42.paloaltonetworks.com/goodbye-mworm-hello-nworm-trickbot-updates-propagation-module/
- $ file *.png
- VidT6cErs: data
- cursor.png: PE32 executable (GUI) Intel 80386, for MS Windows
- imgpaper.png: PE32 executable (GUI) Intel 80386, for MS Windows
- FILE INFO:
- - SHA256 hash: 1ec9bdc03f0f642dc27730fe1be83dc9960c133bd3aadc163fcdc65d3b7740ca
- - File size: 105,555 bytes
- - File location: hxxp://162.216.0[.]166/ico/VidT6cErs
- - File description: encoded binary (not an executable) associated with nwormDll for Trickbot, gtag jim750
- - Analysis:
- -- https://urlhaus.abuse.ch/url/399496/
- -- https://app.any.run/tasks/2b0a7593-9ec5-474e-9197-cccb73b14825
- -- https://capesandbox.com/analysis/9817/
- -- https://www.hybrid-analysis.com/sample/1ec9bdc03f0f642dc27730fe1be83dc9960c133bd3aadc163fcdc65d3b7740ca
- - SHA256 hash: 605a4c603284686d5d31831b7d9b34cd7cd639332c10c97d55dff2f7835ac2a0
- - File size: 593,920 bytes
- - File location: hxxp://162.216.0[.]166/images/cursor.png
- - File description: Windows executable file associated with mshareDll for Trickbot, gtag tot750
- - Analysis:
- -- https://urlhaus.abuse.ch/url/399494/
- -- https://app.any.run/tasks/6f6e9807-2a9f-4632-a23a-e74551072d2c
- -- https://capesandbox.com/analysis/9808/
- -- https://www.hybrid-analysis.com/sample/605a4c603284686d5d31831b7d9b34cd7cd639332c10c97d55dff2f7835ac2a0
- - SHA256 hash: 05f9b81e3cfa7c83a4ddecd9978e4136f64a396622355497885e2209a4c28065
- - File size: 593,920 bytes
- - File location: hxxp://162.216.0[.]166/images/imgpaper.png
- - File description: Windows executable file associated with tabDll for Trickbot, gtag lib750
- - Analysis:
- -- https://urlhaus.abuse.ch/url/399495/
- -- https://app.any.run/tasks/b8900487-3fcf-454e-b8bb-82667f849ce0
- -- https://capesandbox.com/analysis/9815/
- -- https://www.hybrid-analysis.com/sample/05f9b81e3cfa7c83a4ddecd9978e4136f64a396622355497885e2209a4c28065
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement