ExecuteMalware

2021-02-23 Trickbot IOCs

Feb 23rd, 2021
7,105
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.98 KB | None | 0 0
  1. THREAT IDENTIFICATION: TRICKBOT
  2.  
  3. TRICKBOT GTAG
  4. gtag: rob16
  5.  
  6. SUBJECTS OBSERVED
  7. Important Notification: Precept # 6423
  8. Important Notification: Precept # 8251
  9.  
  10. SENDERS OBSERVED
  11.  
  12. MALDOC FILE NAMES
  13. Attach_2024121422_59606374.xls
  14. ef149fa0e847a59880b1fc0b6b1977f1
  15.  
  16. Attach_452701361_1806650968.xls
  17. 21c92b5f324f5c301e8911c39c24d0e5
  18.  
  19. MALDOC FILE HASHES
  20. ef149fa0e847a59880b1fc0b6b1977f1
  21. 21c92b5f324f5c301e8911c39c24d0e5
  22.  
  23. TRICKBOT PAYLOAD URLS
  24. http://bearcatpumps.com.cn/css/tolkio.php
  25.  
  26. TRICKBOT PAYLOAD FILE HASHES
  27. 10.point
  28. 884dab96c679194fc5140322d5ce9e9d
  29.  
  30. TRICKBOT C2
  31. https://102.164.211.138:449
  32. https://103.119.117.42:443
  33. https://103.146.2.152:449
  34. https://103.73.101.98:449
  35. https://103.76.20.226:443
  36. https://103.84.164.87:443
  37. https://103.91.244.102:449
  38. https://108.170.20.72:443
  39. https://111.235.66.83:443
  40. https://117.212.193.62:449
  41. https://118.67.216.238:449
  42. https://154.79.252.132:449
  43. https://167.179.194.205:443
  44. https://168.232.188.88:449
  45. https://173.81.4.147:449
  46. https://177.47.88.62:443
  47. https://178.54.230.164:443
  48. https://179.191.108.58:449
  49. https://179.60.243.52:443
  50. https://182.48.66.106:443
  51. https://185.234.72.84:443
  52. https://186.195.199.238:449
  53. https://187.19.200.154:449
  54. https://187.190.116.59:443
  55. https://190.119.167.154:447
  56. https://190.152.71.230:443
  57. https://200.6.169.124:443
  58. https://201.184.190.59:449
  59. https://202.142.151.190:449
  60. https://221.176.88.201:449
  61. https://36.92.93.5:449
  62. https://36.94.202.131:443
  63. https://37.235.230.123:449
  64. https://45.234.248.66:449
  65. https://79.122.166.236:449
  66. https://80.78.75.246:443
  67. https://80.78.77.116:449
  68. https://85.159.214.61:443
  69.  
  70. TRICKBOT ADDITIONAL DOWNLOAD FILE HASH
  71. pwgrab64
  72. f653abaab18c36ad20bfc369f2a87fd3
  73.  
  74. shareDll64
  75. 7e40b08dc13256e67b4d94080f4d9a24
  76.  
  77. networkDll64
  78. c9e79d2f60b6630116aaee9abb02a06f
  79.  
  80. TRICKBOT CONFIG FILE
  81. serviceworker.txt
  82. e8e485ac450f7daac1dc7e245b52b8f9
  83.  
  84.  
  85. FIDDLER TRAFFIC CAPTURE
  86. http://bearcatpumps.com.cn/css/tolkio.php
  87. http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?0a882b783b913a3b
  88. http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?184cc342f3942d16
  89. http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?06cb81692939b5c4
  90. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/5/kps/
  91. https://api.ipify.org/?format=text
  92. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/0/Windows 7 x64 SP1/1103/104.140.52.99/B7E4CBA0AC3BFD329AB910D91B19E896CD3FC46BD43AB29ED7A447624A92BB20/RHEoK375rj75w4i8c4jzFbP/
  93. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/14/user/analyst/0/
  94. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/14/path/C:\Users\analyst\AppData\Roaming\InternetFreeDownloadManager2420202460\kiTDCSqy.dwn/0/
  95. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/23/2000026/
  96. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/14/DNSBL/not listed/0/
  97. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/14/NAT status/client is behind NAT/0/
  98. https://190.119.167.154:447/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/5/pwgrab64/
  99. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/5/dpost/
  100. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/10/62/BRHJHVXVPLJHF/1/
  101. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/64/pwgrab/VERS//
  102. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/0CEi2SaSK2UUawMI/
  103. https://190.119.167.154:447/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/5/networkDll64/
  104. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/64/pwgrab/DEBG//
  105. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/64/networkDll/NETWORKDLL//
  106. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/64/pwgrab/DPST//
  107. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/10/62/498676/1/
  108. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/63/networkDll/start///
  109. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/ZfpWRo3y9CYJUP5mhsYzAPlSNc/
  110. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/10/62/498678/1/
  111. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/14/pwgrab/sTart pwgrab working/0/
  112. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/37XXLjnvjJBF7hpdV5D1t/
  113. https://190.119.167.154:447/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/5/shareDll64/
  114. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/10/62/498680/1/
  115. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/63/shareDll/infect///
  116. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/X3aZmjqEHORjwzwKXUXz25CQdah58FIa/
  117. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/N6eGDam7vAIJRAxltgLTjXr/
  118. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/fzvdjpP39DrVddHv15lLRV9n/
  119. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/3LhVndDNXJ97PFt3Lzlv5rh/
  120. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/Llnjh1nd9vB53JdvRlXNtfvln3NfBVD7/
  121. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/BFrLVJ75FTHFTH53dRFDRBPNbPDB/
  122. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/y0ckaASyoggo64u2UIaGKWowYM2Am/
  123. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/LPt7fzRz9nJT1LnLZpft3hDNvFhFPjZ/
  124. https://186.195.199.238:449/rob16/WIN7PC_W617601.51CB3CF6B57C9F7F6675DC98BB8EBDFA/1/AAy1wBMETeZlwr6E9O/
  125.  
  126.  
Advertisement
Add Comment
Please, Sign In to add comment