pandazheng

2021-05-05 Trickbot IOCs

May 6th, 2021
184
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. THREAT IDENTIFICATION: TRICKBOT
  2.  
  3. TRICKBOT GTAG
  4. gtag: rob72
  5.  
  6. SUBJECTS OBSERVED
  7. [#TN#9217724#GEN
  8.  
  9. SENDERS OBSERVED
  10.  
  11. MALDOC FILE HASHES
  12. 3128117926_1127128272.xlsm
  13. 031bb042ecdda96d89ea759c79f45261
  14.  
  15. TRICKBOT PAYLOAD FILE HASHES
  16. Nioka.meposv
  17. af770c0cf74689a62e0339e59ade60fd
  18.  
  19. image2.bmp
  20. 98e7b944113b0a9d26ed50909e4d30bc
  21.  
  22. TRICKBOT MODULE FILE HASHES
  23. tabDll64
  24. 98173c732d2dbe14a1327a652046738c
  25.  
  26. wormDll64
  27. 65157248a7e65d45067cb495870d032b
  28.  
  29. networkDll64
  30. c9e79d2f60b6630116aaee9abb02a06f
  31.  
  32. shareDll64
  33. e126d5fc4a4d20925ebd7e5bcdc0d16a
  34.  
  35. ADDITIONAL DOWNLOADS
  36. http://192.119.171.206/images/redbutton.png
  37. http://192.119.171.206/images/cutscroll.png
  38. http://192.119.171.206/ico/viodifot
  39.  
  40. ADDITIONAL FILE HASHES
  41. cutscroll.png
  42. f22cedaec475d7a55b5464cb2858fa56
  43.  
  44. redbutton.png
  45. 0eb145602076b0b5bc1d5f319f847ecd
  46.  
  47. viodifot
  48. 88263ba0eb7638901f5668f3625c60de
  49.  
  50. TRICKBOT C2s
  51. http://103.102.220.50:443
  52. http://5.202.120.150:443
  53. http://36.95.27.243:443
  54.  
Advertisement
Add Comment
Please, Sign In to add comment