ExecuteMalware

2021-04-29 Trickbot IOCs

Apr 29th, 2021
17,802
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.23 KB | None | 0 0
  1. THREAT ATTRIBUTION: TRICKBOT
  2.  
  3. SUBJECTS OBSERVED
  4. DocuSign Please.
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. Documents_426352811_571431978.xls
  10. 6099cc9b417f2902e0c01e52bd0c3a16
  11.  
  12. TRICKBOT PAYLOAD URLS
  13. https://jrfastener.com/netmount.dll
  14.  
  15. TRICKBOT PAYLOAD FILE HASHES
  16. isnsondlk.ksu
  17. 3f3cb269876273534664a5d37118de14
  18.  
  19. TRICKBOT GTAG
  20. gtag: net5
  21.  
  22. TRICKBOT MODULE FILE HASHES
  23. networkDll64
  24. c9e79d2f60b6630116aaee9abb02a06f
  25.  
  26. shareDll64
  27. 75356318504e259a5930fb84105507ce
  28.  
  29. tabDll64
  30. 86d2499559223eb57d1b6ec878c7c30d
  31.  
  32. wormDll64
  33. 401deb42f30a0aa6d6add840f921bb29
  34.  
  35. ADDITIONAL DOWNLOADS
  36. http://23.160.193.91/images/redbutton.png
  37. http://23.160.193.91/images/cutscroll.png
  38.  
  39. ADDITIONAL FILE HASHES
  40. redbutton.png
  41. 53e9a0d31d13590a26485e4ed5f2774c
  42.  
  43. cutscroll.png
  44. bc0fda0c6d368d4bbebee5f392b1b404
  45.  
  46. TRICKBOT C2s
  47. https://154.79.251.172:443
  48. https://103.124.173.35:443
  49. https://103.66.72.217:443
  50. https://131.0.112.122:443
  51. https://117.54.250.246:443
  52.  
  53. POST TRAFFIC
  54. http://36.95.27.243:443/net5/WIN7PC_W617601.65B7FDBB55EDD8897BF95BD390FB3852/90
  55. http://5.202.120.150:443/net5/WIN7PC_W617601.65B7FDBB55EDD8897BF95BD390FB3852/90
  56. http://103.102.220.50:443/net5/WIN7PC_W617601.65B7FDBB55EDD8897BF95BD390FB3852/90
  57.  
Advertisement
Add Comment
Please, Sign In to add comment