Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- TRICKBOT PROPAGATION URLS ON TUESDAY 2020-06-23
- URLS:
- - hxxp://23.95.231[.]200/ico/VidT6cErs
- - hxxp://23.95.231[.]200/images/cursor.png
- - hxxp://23.95.231[.]200/images/imgpaper.png
- NOTES:
- - These URLs were noted as early as Tuesday 2020-06-23.
- - Theese URLs appear to be return a different file hash each time they are queried.
- - The HTTP request for VidT6cErs is caused by Trickbot's nwormDll module (jim-series gtag).
- - The HTTP request for cursor.png is caused by Trickbot's mshareDll module (tot-series gtag).
- - The HTTP request for imgpaper.png is caused by Trickbot's tabDll module (lib-series gtag).
- More info on the new "nworm" module used by Trickbot:
- - https://unit42.paloaltonetworks.com/goodbye-mworm-hello-nworm-trickbot-updates-propagation-module/
- $ file *
- VidT6cErs: data
- cursor.png: PE32 executable (GUI) Intel 80386, for MS Windows
- imgpaper.png: PE32 executable (GUI) Intel 80386, for MS Windows
- FILE INFO:
- - SHA256 hash: 7c55da28fd671d377ff68ab0fcf75248e804b4e910001d2a93f7af24532aa7bc
- - File size: 105,668 bytes
- - File location: hxxp://23.95.231[.]200/ico/VidT6cErs
- - File description: encoded binary (not an executable) associated with nwormDll for Trickbot, gtag jim752
- - Analysis:
- -- https://urlhaus.abuse.ch/url/400730/
- -- https://app.any.run/tasks/8beed1a6-f424-4e75-99b5-73576b3332ef
- -- https://capesandbox.com/analysis/13136/
- -- https://www.hybrid-analysis.com/sample/7c55da28fd671d377ff68ab0fcf75248e804b4e910001d2a93f7af24532aa7bc
- - SHA256 hash: b22d3482f8f33cbfa1845d701f9a7755b49d9adce7b9839e23b6d07a25da07f6
- - File size: 316,928 bytes
- - File location: hxxp://23.95.231[.]200/images/cursor.png
- - File description: Windows executable file associated with mshareDll for Trickbot, gtag tot752
- - Analysis:
- -- https://urlhaus.abuse.ch/url/400728/
- -- https://app.any.run/tasks/28ea944c-23b4-4b33-8a81-e63af357778c
- -- https://capesandbox.com/analysis/13137/
- -- https://www.hybrid-analysis.com/sample/b22d3482f8f33cbfa1845d701f9a7755b49d9adce7b9839e23b6d07a25da07f6
- - SHA256 hash: 61dacaedf57dffd1c485e3e6b44bc5c8e336f19fca301ad2976df94b0dd23172
- - File size: 316,928 bytes
- - File location: hxxp://23.95.231[.]200/images/imgpaper.png
- - File description: Windows executable file associated with tabDll for Trickbot, gtag lib752
- - Analysis:
- -- https://urlhaus.abuse.ch/url/400727/
- -- https://app.any.run/tasks/be7c7e8a-0e90-4261-a28f-0896698bc282
- -- https://capesandbox.com/analysis/13140/
- -- https://www.hybrid-analysis.com/sample/61dacaedf57dffd1c485e3e6b44bc5c8e336f19fca301ad2976df94b0dd23172
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement