ExecuteMalware

2020-06-16 Trickbot IOCs

Jun 16th, 2020
3,515
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.01 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. Office notification # 72714
  3.  
  4. SENDERS OBSERVED
  5.  
  6. EXCEL MALDOC FILE HASH
  7. workbook_13.xls
  8. 097f3773c30aea33b0ab4a0bcd73c4e0
  9.  
  10. TRICKBOT PAYLOAD
  11. https://pops.works/manahet/omuscreativos.php
  12.  
  13. TRICKBOT FILE HASH
  14. 1333ab4nu59ok.exe
  15. 5ebfefd6165826b56658dce374c33cf9
  16.  
  17. TRICKBOT C2s
  18. http://203.176.135.102:8082/ono47/WIN7PC_W617601.45C53ECFF74734259CB34797A36C2804/90
  19. http://203.176.135.102:8082/ono47/WIN7PC_W617601.45C53ECFF74734259CB34797A36C2804/81/
  20. http://203.176.135.102:8082/jim747/WIN7PC_W617601.F97B577E1419B4CB127BE49CF55CB5D5/90
  21. http://203.176.135.102:8082/jim747/WIN7PC_W617601.F97B577E1419B4CB127BE49CF55CB5D5/81/
  22.  
  23. http://195.123.221.93:443/ono47/WIN7PC_W617601.45C53ECFF74734259CB34797A36C2804/81/
  24. http://195.123.221.93:443/jim747/WIN7PC_W617601.F97B577E1419B4CB127BE49CF55CB5D5/81/
  25.  
  26. SUPPORTING EVIDENCE
  27. Open directory here with almost 2,000 Trickbot executables: https://pops.works/manahet/
  28.  
  29. http://www.malware-traffic-analysis.net/2020/06/16/index.html
Advertisement
Add Comment
Please, Sign In to add comment