Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- TRICKBOT EXE FILES FROM .PNG URLs ON MONDAY 2020-03-16
- URLS:
- - hxxp://64.44.51[.]120/images/cursor.png
- - hxxp://64.44.51[.]120/images/imgpaper.png
- - hxxp://64.44.51[.]120/images/redcar.png
- NOTES:
- - The http request for cursor.png is caused by Trickbot's mshareDll module.
- - The http request for imgpaper.png is caused by Trickbot's tabDll module.
- - The http request for redcar.png is caused by Trickbot's mwormDll module.
- - All of these URLs returned a Windows executable file (EXE).
- - Each of these Trickbot EXE has a different gtag.
- - These URLs may return files with different hashes every time they are retrieved.
- FILE INFO:
- - SHA256 hash: 3e6570e962b3c327e27c46e1cb48adba417858d5abf8888242a22c8c02303343
- - File size: 483,328 bytes
- - File location: hxxp://64.44.51[.]120/images/cursor.png
- - File description: Windows executable file for Trickbot, gtag tot697
- - Analysis:
- -- https://urlhaus.abuse.ch/url/325821/
- -- https://app.any.run/tasks/90d52d06-c52a-4371-a630-ddf79469ed2c
- -- https://capesandbox.com/analysis/14421/
- -- https://www.hybrid-analysis.com/sample/3e6570e962b3c327e27c46e1cb48adba417858d5abf8888242a22c8c02303343
- - SHA256 hash: d6ff25b6331fe776f5d8dd3749adef221eaf627e5c764327ebf30929a648bd79
- - File size: 483,328 bytes
- - File location: hxxp://64.44.51[.]120/images/imgpaper.png
- - File description: Windows executable file for Trickbot, gtag lib697
- - Analysis:
- -- https://urlhaus.abuse.ch/url/325822/
- -- https://app.any.run/tasks/a5951422-91fb-47cb-9b5b-e7470ca4343d
- -- https://capesandbox.com/analysis/14422/
- -- https://www.hybrid-analysis.com/sample/d6ff25b6331fe776f5d8dd3749adef221eaf627e5c764327ebf30929a648bd79
- - SHA256 hash: 51903e594cf91da56380accc7a6f7e990d926ade2ff0bf1c428c8a917c4b14e3
- - File size: 491,520 bytes
- - File location: hxxp://64.44.51[.]120/images/redcar.png
- - File description: Windows executable file for Trickbot, gtag jim697
- - Analysis:
- -- https://urlhaus.abuse.ch/url/325823/
- -- https://app.any.run/tasks/90d52d06-c52a-4371-a630-ddf79469ed2c
- -- https://capesandbox.com/analysis/14423/
- -- https://www.hybrid-analysis.com/sample/51903e594cf91da56380accc7a6f7e990d926ade2ff0bf1c428c8a917c4b14e3
RAW Paste Data