ExecuteMalware

2020-06-30 Trickbot IOCs

Jun 30th, 2020
2,731
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.77 KB | None | 0 0
  1. THREAT ATTRIBUTION: TRICKBOT - gtag:ono52
  2.  
  3. SUBJECTS OBSERVED
  4. Credit and Reissued Invoice 12878
  5. Credit and Reissued Invoice 44231
  6. Credit and Reissued Invoice 45014
  7. Credit and Reissued Invoice 54543
  8. Credit and Reissued Invoice 64975
  9. Credit and Reissued Invoice 86673
  10.  
  11. SENDERS OBSERVED
  12. aquick@cguhsd[.]org
  13. blpachecolo@uide[.]edu[.]ec
  14. CDHIXON39@RANGERS[.]NWOSU[.]EDU
  15. cyril[.]leite@viacesi[.]fr
  16. E1151@365office[.]one
  17. stigrero@agroproduzca[.]com[.]ec
  18.  
  19. EMAIL BODY
  20. Good morning,
  21.  
  22. See attached for credit note and invoice request for your approval. Information regarding the reasons for the credit note is below in the email chain.
  23.  
  24.  
  25. AR,
  26.  
  27. On Ellen’s approval, please raise the credit note and invoice.
  28.  
  29. Please note the request in both documents where the number for each document is to be referenced in the other. If you have any questions don’t hesitate to ask.
  30.  
  31. Thanks,
  32.  
  33. MALDOC FILE HASHES
  34. CreditNote (1377).xls
  35. 15985bae9492afba65bf71ecefa1980a
  36.  
  37. fddr_1660.xls
  38. 8de84c345735147bea7d024afd15a0b6
  39.  
  40. fddr_1699.xls
  41. 40ad66f4e94b9917659cce3d7e62b5cb
  42.  
  43. TRICKBOT PAYLOAD FILE HASHES
  44. 832o7n8n9n0m0[.]exe
  45. 4f471b6c788cabc4d520028360bb494d
  46.  
  47. Saw this when I ran it in my sandbox:
  48. dZOiYPd[.]exe
  49. 09f273b309d070247e3118c525e7b0b4
  50.  
  51. SECONDARY DOWNLOAD FILE HASHES
  52. cursor[.]png
  53. 816a5be6fad59f4abf7dc87ee9a37587
  54.  
  55. imgpaper[.]png
  56. ac63ac867af3aaf2c3d6e1ffaf3654ea
  57.  
  58. TRICKBOT PAYLOAD URLS
  59. hxxps://www[.]ruths-brownies[.]com/adbanner/ololomadam[.]php
  60.  
  61. SECONDARY PAYLOAD URLS
  62. hxxp://5[.]182[.]210[.]136/images/cursor[.]png
  63. hxxp://5[.]182[.]210[.]136/images/imgpaper[.]png
  64.  
  65. TRICKBOT C2
  66. hxxp://170[.]238[.]117[.]187:8082/ono52/WIN7PC_W617601[.]5851ABB11A8412C201F720DC1508EBCF/81/
  67. hxxp://203[.]176[.]135[.]102:8082/ono52/WIN7PC_W617601[.]5851ABB11A8412C201F720DC1508EBCF/90
Add Comment
Please, Sign In to add comment