SHARE
TWEET

2019-08-12 - Trickbot EXEs from URLs ending with .png

malware_traffic Aug 12th, 2019 794 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. TRICKBOT EXE FILES FROM PNG-EXTENSION URLS SEEN ON MONDAY 2019-08-12:
  2.  
  3. hxxp://195.133.196[.]173/samerton.png
  4. hxxp://195.133.196[.]173/tablone.png
  5. hxxp://195.133.196[.]173/wredneg2.png
  6.  
  7. $ file *.png
  8. samerton.png: PE32 executable (GUI) Intel 80386, for MS Windows
  9. tablone.png:  PE32 executable (GUI) Intel 80386, for MS Windows
  10. wredneg2.png: PE32 executable (GUI) Intel 80386, for MS Windows
  11.  
  12. $ shasum -a 256 *.png
  13. dd343915dfcc904ec8b49cf7e01f92055ac8358069ef86af4d4432e59cb44bdd  samerton.png
  14. 4c6e4ce2b368273b6302d1649dd85d9376a30f6b2cd54b573939fa876e5e63ef  tablone.png
  15. 3840f4556fd6c985ba2a03d76ddde1930b40aa686492b65e821ad84f445fd63e  wredneg2.png
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top