Advertisement
ExecuteMalware

2021-02-18 Trickbot IOCs

Feb 18th, 2021
3,726
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.20 KB | None | 0 0
  1. THREAT IDENTIFICATION: TRICKBOT
  2.  
  3. TRICKBOT GTAG
  4. gtag: rob59
  5.  
  6. SUBJECTS OBSERVED
  7. DocuSign: Contract # 18264
  8. DocuSign: Contract # 3844
  9.  
  10. SENDERS OBSERVED
  11. steve@curbhuggers.com
  12.  
  13. MALDOC FILE HASHES
  14. Sign_1122909780-1482301699.xls
  15. 5210bb023dd17deb4ef356a19cd81db7
  16.  
  17. Sign_1003875156-920007929.xls
  18. adb7ee67f5846ec880190a91878f2958
  19.  
  20. TRICKBOT PAYLOAD URLS
  21. http://artifkt.com/okmobi/certificate.php
  22.  
  23. TRICKBOT PAYLOAD FILE HASHES
  24. 10.fbr
  25. 853c5f48616fd2afd63e487d197c9796
  26.  
  27. TRICKBOT C2
  28. http://108.170.20.75:443
  29. http://110.39.160.66:447
  30. http://185.118.15.137:447
  31. http://186.137.85.76:443
  32. http://200.52.147.93:443
  33. http://222.124.7.150:447
  34. http://36.94.113.249:447
  35.  
  36. TRICKBOT ADDITIONAL DOWNLOAD FILE HASH
  37. pwgrab64
  38. 783802a08864d86405a99adc3ca0179e
  39.  
  40. TRICKBOT CONFIG FILE
  41. opera_shutdown_ms.txt
  42. 0d2a3e13ac22198b62134ffa0c880ed7
  43.  
  44. ADDITIONAL IOCs
  45. Here's what Fiddler captured during the run:
  46. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/0/Windows%207%20x64%20SP1/1103/62.182.99.35/B7E4CBA0AC3BFD329AB910D91B19E896CD3FC46BD43AB29ED7A447624A92BB20/PXJtvJf1xRh35TpB7/
  47. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/1HLlH9ZBhZXPvnrpLDx39R/
  48. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/3rHBhljH99pjFJHphhNHnrpNF/
  49. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/AwLAYY65JJ1qEEmlz/
  50. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/jtzNjpxVln5Tpv3brt/
  51. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/NZ3NN51fLvflBtPFnjFDzZ9TpB/
  52. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/rVb7hrDN9pR5fpBL7nDdvtjbBbX/
  53. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/rzV1nJZvV1HpZ5LbHnrbLrNN3/
  54. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/v3LV7nx7rPhrT9JTDl3DpVfpZ7/
  55. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/1/xl0flTNY8qGv1jdoO6WBHzt/
  56. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/10/62/TRRFHFLXTZB/1/
  57. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/14/DNSBL/not%20listed/0/
  58. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/14/NAT%20status/client%20is%20behind%20NAT/0/
  59. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/14/path/C:%5CUsers%5Canalyst%5CAppData%5CRoaming%5CQNetMonitor2686282466%5CamNDksgk.rrd/0/
  60. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/14/user/analyst/0/
  61. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/23/100011/
  62. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/5/dpost/
  63. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/5/file/
  64. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/64/pwgrab/DEBG//
  65. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/64/pwgrab/DPST//
  66. https://200.52.147.93/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/64/pwgrab/VERS//
  67. https://222.124.7.150:447/rob59/WIN7PC_W617601.B055FB70DF37D903BF0FBB37DFB9E977/5/pwgrab64/
  68.  
  69.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement