ExecuteMalware

2021-02-17 Trickbot IOCs

Feb 17th, 2021
4,577
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.03 KB | None | 0 0
  1. THREAT IDENTIFICATION: TRICKBOT
  2.  
  3. TRICKBOT GTAG
  4. rob13
  5.  
  6. SUBJECTS OBSERVED
  7. DocuSign: Equipment # 23345
  8. DocuSign: Equipment # 23858
  9. DocuSign: Equipment # 66844
  10.  
  11. SENDERS OBSERVED
  12.  
  13. MALDOC FILE HASHES
  14. DocuSign_1172656286_1046320036.xls
  15. 0005d7d793f8bdde9eb8f9cbe753929a
  16.  
  17. DocuSign_191043083_1949587583.xls
  18. 963adbac37cb5704704e716f12986b7b
  19.  
  20. DocuSign_1157143460_2013384555.xls
  21. c8f01b787d5aa47c0524282655e0915d
  22.  
  23. DocuSign_695116892_1420962722.xls
  24. f7154025eaba7b56a412783ae980fdad
  25.  
  26. TRICKBOT PAYLOAD FILE HASHES
  27. 8.xxls
  28. 5ed8ba344e7e14a158994bccc1d96882
  29.  
  30. TRICKBOT PAYLOAD URLS
  31. https://destinostumundo.com/layout/recruter.php
  32.  
  33. TRICKBOT C2
  34. http://134.119.186.201:443
  35. http://169.239.45.42:449
  36. http://195.123.241.195:443
  37. http://85.204.116.134:443
  38. http://92.242.214.203:449
  39. http://94.158.245.54:443
  40.  
  41. SUPPORTING EVIDENCE
  42. https://urlhaus.abuse.ch/url/1016269/
  43. https://tria.ge/210217-5461xvx1en
  44. https://isc.sans.edu/forums/diary/Malspam+pushing+Trickbot+gtag+rob13/27112/
Advertisement
Add Comment
Please, Sign In to add comment