pandazheng

2021-04-09 Trickbot IOCs

Apr 10th, 2021
243
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. THREAT IDENTIFICATION: TRICKBOT
  2.  
  3. TRICKBOT GTAG
  4. gtag: rob50
  5.  
  6. SUBJECTS OBSERVED
  7. Here’s your invoice (76897)
  8.  
  9. SENDERS OBSERVED
  10.  
  11. MALDOC FILE HASHES
  12. inv_872895176_1700788183.xls
  13. 7f9db9d6085249928deb6dde9625f4bb
  14.  
  15. TRICKBOT PAYLOAD URLS
  16. http://hometownchick.com/patron/ibufen.php
  17.  
  18. TRICKBOT PAYLOAD FILE HASHES
  19. popmddj.dblo
  20. de63e7e3da96f915446dff531a4c09dc
  21.  
  22. TRICKBOT C2
  23. https://36.95.27.243
  24.  
  25. TRICKBOT ADDITIONAL DOWNLOADS
  26. http://91.200.101.3/images/redbutton.png
  27.  
  28. TRICKBOT ADDITIONAL FILE HASHES
  29. redbutton.png
  30. 49d503b1e59dc38764cc747a8affd15d
  31.  
  32. ADDITIONAL TRICKBOT MODULES
  33. shareDll64
  34. 9b75fadae3d4fc4e70e751b71616c33e
  35.  
  36. tabDll64
  37. 2f0f6ffc6e71c2b132b613e3a8f6ab80
  38.  
  39. wormDll64
  40. f021d817c5c6cd89d835507c4839fe6b
  41.  
  42. networkDll64
  43. c9e79d2f60b6630116aaee9abb02a06f
  44.  
  45. SUPPORTING EVIDENCE
  46. https://urlhaus.abuse.ch/url/1105162/
Advertisement
Add Comment
Please, Sign In to add comment