Skip to content

Commit

Permalink
Created 2020-08-24-IOCs-for-Trickbot-gtag-ono66.txt
Browse files Browse the repository at this point in the history
  • Loading branch information
brad-duncan authored Aug 29, 2023
1 parent 554b25d commit d26d622
Showing 1 changed file with 155 additions and 0 deletions.
155 changes: 155 additions & 0 deletions 2020-08-24-IOCs-for-Trickbot-gtag-ono66.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,155 @@
2020-08-24 (MONDAY) - MALSPAM PUSHES TRICKBOT GTAG ONO66

REFERENCE:

- https://twitter.com/Unit42_Intel/status/1298317496265605146

CHAIN OF EVENTS:

- Link from malspam --> Word doc --> enable macros --> Trickbot EXE

EMAIL HEADER INFO FROM AN EXAMPLE OF THE MALSPAM:

- Date: Sun, 23 Aug 2020 18:40:52 -0400 (EDT)
- Received: from ccm201.constantcontact.com (ccm201.constantcontact.com. [208.75.123.201])
- From: Talkline Communications <[email protected]>
- Reply-To: [email protected]
- To: [removed]
- Subject: , Shipment delivery problem #00000112525

LINKS FOUND FROM THE MALSPAM SO FAR:

- hxxps://shimicenter[.]org/clientlabel/memberlabel.php
- hxxps://shoppinglink[.]co/labels/userlabel.php

- NOTE: The above URLs contain ?user= followed by the recipient's email address.

41 EXAMPLES OF SHA256 HASHES FOR DOWNLOADED WORD DOCUMENTS FROM MALSPAM LINKS:

- NOTE: These Word docs all have a creation date of 2020-08-17

- 027a24eb1f6d46881fb07cef75b4a1c3dbf0128019eebc70a08d01bc3d28b8c3
- 052d119afc4fc2454bfece6c0cab0fd60e165543b5282b580f8dbded5e32f21b
- 0b3d505677eff9327f22b8a3549e2a84e2672d18f3ef39c310e11146e1cc1b76
- 0d888424de5d82ce796e02a70de4829f0811e39fd7bb60de5e6362ad90d1179f
- 11ca528465fe70f3933c2b5260cda5095ae4f37d261745057c194fd05f2eb8e2
- 13957bf2c2d4bc4dac5cdfc8fb43766f901e038eff0d5c9ff115a4e21e054378
- 148429d7b5678de0122b17da6fa70c1bd0ed8b4534dc4e45cf8280cefba28193
- 1b3449d3af4d0525f7fa72f2dbe5cfabc0efff7c9e33bfebfe6e63c98d16d13d
- 2303edf7519645a62695cd57ebaa6c267507a689cb2ba6e1ec28b7ddce1b952c
- 25e2ecd88b1760c2f4fb3a13eff41437f46ff6f70b380cb2af70a2cd58721ec7
- 35efc1a4484801b7f80c526060f24ca86c24dd5af35d7b1c5bffa47f7229ca71
- 38f022e7ab256afb05fba77a31a2dfea583157290e10c44a1e17f05d4313d5d9
- 3be479c19f7b8656011dc5aebecea6726c1c91c1f6bc5eb0acc5a7086fc78a5f
- 4595f0adf9d61c53d2818d5817c9a7d074d57df1c545105aa341a058c29482dd
- 521271b1607fa1e88bcc9c004b4320b687e835b3f5293535c675ccecfb6b0180
- 59af2e578f4a62af2e6f4fc0f441ff285190c0eaad01ff1ffcbff8d1dfe1a47e
- 61c0fc6f73d372c9e60cfb2d39263c9adccd0c33d257d18debe8ce794197dc4c
- 6622661ea5a8ea8344183fc4a22ccbeb067ab738f3c4605640aed7a8b3826f05
- 6da9c775a26e6b69da9402ce7e49cd52511f88c14fe0dbe629935480cf511f65
- 734fd2f30ae722feec5b95679554d9ec7e6a3b75203ffc0a3b2c5b1f89cc3e64
- 773c07c9453d658039863940d7b8cb7150c4167c4cf31cc5602a2e4c2704c171
- 80a3582314db9962a482f0c5fa9196853d4b2a5a9a0250c1489de5550efdc258
- 8c9e6374a30ed12867dcb9dde5c67ec3bfbeb9b6cd6dde93dcda4b1e8391c6ab
- 9eb7a7123aca15a658a73b8b8b3a3d636279f07f7260a766dbed32f71077a9c2
- 9eb9ffa4bc0f9311b5bb31676adced6535d41878ee2f713a1b2a4919a34a631a
- a463ad285307e9f4aa8c5879e3502e7ea81894b6dff0fa487a6c1bc2f30c8e82
- a67b1c8ad104f838393fd4ce48e72072f9ef036179e65dee2a6e3dd180919c13
- a91841c7bf641208ee9a126a8ef97a672501ca4c03a2dc6b6f26cb4bd5bc54a7
- ba5bfba9a0babc6ed990e41744ddf221773d6794fcd85b5f902499424c1b0c3f
- bd4f4e611aba3a4df54d04682946bc0422f66378b0eeca9a9f4cbb397e04b54b
- c90faa765ec658fcf16b5ee78dc06e9143976cf348d71265ae77ceec482b8303
- cc57d8c1296fcbeec89e7a64e8a0d8df115ef6d0df935801e811099d5231f737
- d4f5faac38e9ff4982c903eb723d27e1196b638af3cb0a2ea9fb3d7f55b1133b
- d567afd1e98b9386e668318813e1026ce535e9cb4c1e915b191189c6c4870503
- db1ca5d4537d1edec0d000747591891b756a9e073caf35b987b9a8d4450a41dd
- e3d069b96b15c8fe4feb43f2a74ac78c1737e9a4462ef167429587716bfc6ea1
- ede77611fbaeb7b6d9b87f0e2386e65cfb6168cb887a958f1d635be891ceeff6
- f0649082dd835fb6835c4475cd46457dca1560c24d27e89b2e047120990a7bb4
- fb2255bbf0556f114b8e447ea6c1e64e27ff900d3370ed78a4d6218078c4a11a
- fcf6860ba9bd6e610dc6e7a191ade232eefdeed915cdc3ca993c9f171f31f4db
- ff9a955b5dadee0340bca220f7a5c00f76b616bf6dc65ca83f6c35437a4d3064

URL GENERATED AFTER ENABLING WORD MACROS:

- hxxp://yektairon[.]com/brands/goodmanstory.php

60 EXAMPLES OF SHA256 HASHES FOR DOWNLOADED EXE FILES FROM THE ABOVE URL:

- 01fe7574243a39b2b0b0ebcb004e0fd5f1eec7759bd1a8ac4b654d31fe415b38
- 09b077883ee1a92949f30700b526dc4f03ce2c0b1305d994aaac3988a3c1cd35
- 0db7acd63e1432ed6a33cf0ff7a273f1e1249d6ade7e64481034b4517e4b3eb5
- 120217a7f83fe9d49ccaee15de69dc224ac970f1ca23267b53dd01e41a6b9224
- 127f91cff87d0effd556661c1ca5fe6215c4021069d05ce1388e6512cc708f27
- 137c638c8e763ecaea07e3b20c3bda714296b2ed829ef1cbc5d6857a6c9eef3a
- 148712319bb788124ce7a71968d0dfe163337dd47e1b9b65ad4180206113eaea
- 2a4663e66ebc597d99904b30afd1626824b2b33769421537e7334e55e7e0d9aa
- 2b2e773f5cee0f8bf7a8f58b8bdc656508fdd566efda6f2759e68a096049e8ce
- 2c86205388ca0d6e607a52050d5deb54472653ef4271eb7cf1771c97438fc8b8
- 3c4f127e4b285f1bbc17c09ed608e786019ea36d89020fbf15ca471a063aa2cf
- 3d583ab83d32642fada52f8561dd5f6c3b2970ece430612822e47688da0e88f4
- 42167256ce4d9231fa3cabdbf77dbe2461d5fbd3ca25c2b7528218c608be9961
- 4306f57c8f5300e16569af579819e8f138f4bac4af1480862c60980f7e135a10
- 4881fe4297f66c560506d47547d05b6896ee285b3b12d3a6b9da9d98d7d0fdfe
- 4b151f30b84f914924123bd3a4e1258c1e14e109986a2d7fc88967b432c3bcfe
- 5097c593c8cf1d46cd3853d3bf6a8e58fd07c8ba1d4d453bad0947bd47bfe171
- 5536a399c64bb73d774e498e845ec752bac7677811f8503f3c10df9b007967af
- 5754c1f883fbee1afddca9cddbd6b6f6ba9e2aa2d165301a491d2d5823720ca4
- 5b11869d609a8c2dd28639b420eb1ca509a7cdd50c66c0c24f5fc7e08aef65f4
- 5b25dfac45d26292b99c176e0a9149738e1c6f486cb9d6f6af83e589bae63704
- 5d0a24fc86706e9bae2a14d9494aa467c9dae3c3c8dd1754e6ae513247160442
- 65e1818003c402310f2c3e956bdb0795c6540ea00f0a73d4771363f3e536ccbc
- 6ef39beb0376804ddefcf4b2e4354999c21144fcf5310933831e1947cae944d8
- 6fb6cd383d13f835c2312a4bbcb5bb0424ded6b728d5cb36f1d46516047fcaab
- 70b378185295a41492e0fc84acd953fdb4516cb312218c24490cbe909c6ceaf7
- 734e93887fd2b2bc3be6fd0500b1a80ec2d9ec128c08d885760e2bf5d26752ba
- 7519ac1cee11868a95b8dbbb43c366cfeba4c695b4e815f650019c3945ae2e49
- 756e8a6262d6bac29259f78fe1a5d01f81607b61cd167df33c84589525d924ad
- 758c431901256af82a60f246f89ac73a7dc4b2217fdb661703499c5f9677fecb
- 78102754d475b19d91940d162473396fa1a997f38a02d231bd79981adb202dca
- 7927c497248f33ef4af1c251fd035952027403ab3a51869aab4d73afe5f01e4e
- 7b2261b3bbecb7590ed99cd7a0bcc7237d01bf99b13ef3cf2c8c320562d7056b
- 84f4a08e116683411053fbff431f39236907e7130294c0f975b5abe5a69e1008
- 873b9dc144b35fbf9c182df52f843ee734b19b19c99e4445c0ec08fd690c2b8b
- 8d982c732aa184881706733327db7a64a2d3c92e28c991a57723c154f597ed97
- 8dccb4e8371cba0ff473b053ccb1033715c5601084d2c0cb03ea50c00db17d07
- 9491b775ea64e2a5b2fd7f40633331187c5be0d2d15c282d42206716d7d0ba8f
- 98949318fb8d1eb285bee2bd543396147859c4145bc94693a789c7591d4f2551
- a44f4bf172ab83f746f70e43cc99785ada55681dacd28e3b53e718f71bfc7acd
- a4e9a5ba4de379254ae44845ac9ce9353e2298a7693a471571030c39f6455290
- aafd66e2de980c33e7fb498ab5f2dc2264a596cf66019d9f792867b94c5fff97
- ac4a8ba57ca8e25a09bf618e331a67fc71ee87b1295c6f463cd27af193c7bca4
- ac738c7cc7e75f87d8a67341ef0816e3ec45f7d34d20ba7ab86f05f797d68f69
- c0837fba358fb1085585d0b93c53547d2b5857891256e76509a521f83593ec95
- ca5e09d099b7ef2f2e8979b2d0c9cedc6c2269e529e32edf6c98dbe6401654be
- caec349cedf1ef2ed36e2fa5ca93bfaffac4a04d7034140e168b3869c8753064
- d241fc05eed729aef55b3daa7b616f737d88781ac0a8e5b6414a276c05758701
- d2c5a1c1a714f68609b2d5e4a44fb34e5b4eec31b8f73274fded5cb7788af094
- d52cd83db8b7fcd5aa73fd8e542191c70f97a21b1ae8c852970b590d0be5bf12
- d9f703d56a4f4319c77cc4195d899c680f5208757e830762b0d1750b3844c5fa
- dbe50712cea0b5b633f44ec30cce912814fe3f09965ab4c8d9c1655863df9015
- ded10fbb9465f34715dc2854ae8ca457954b4aea046fb3a127aeb8cfa43e2c1d
- df98ddc945bb359c36543e8b347f307008c8df4907afa3468f3173d32fa483ee
- f023bd079a867c69345312e4fc35c30efe0eb7860c3bfe780f4de84b1e6be670
- f02e6b41c635851e220e111ee4354607c9a4015e92a46364f10a1bb81bec77f8
- f0d98aaf2e3fecd015ef9b23878d50f87dd7660d1ce6e4b4314aa384e453946b
- f2497c6f75658d5477231006289a0f87ed5d31148110d2dd7a0e46feb06f6e2b
- fe6f7c3fbadac63eb9231365dd3e754bfc87dcc8ac0cfef4f46aff461f79332a
- ffe90b50e23eb471fc0993d82c667e1e0a7b55223ec8b7ee0b0fa287368d398d

TRAFFIC FROM AN INFECTED WINDOWS HOST:

- 185.10.75[.]26 port 443 (HTTPS) - shimicenter[.]org - GET /clientlabel/memberlabel.php
- 185.10.75[.]26 port 80 - yektairon[.]com - GET /brands/goodmanstory.php
- 185.10.75[.]26 port 443 (HTTPS) - yektairon[.]com - GET /brands/goodmanstory.php
- 82.146.46[.]220 port 443 - attempted TCP connections, unsuccessful
- 86.104.194[.]116 port 443 - attempted TCP connections, unsuccessful
- 185.164.32[.]215 port 443 - attempted TCP connections, unsuccessful
- 92.62.65[.]163 port 449 - HTTPS/SSL/TLS traffic caused by Trickbot
- 37.220.0[.]28 port 447 - HTTPS/SSL/TLS traffic caused by Trickbot
- port 80 - myexternalip.com - GET /raw (IP address check, not inherently malicious)
- 203.176.135[.]102 port 8082 - 203.176.135[.]102:8082 - POST /ono66/[string with info about infected host]/90
- 96.9.73[.]73 port 80 - 96.9.73[.]73 POST /ono66/[string with info about infected host]/81/
- 96.9.73[.]73 port 80 - 96.9.73[.]73 POST /ono66/[string with info about infected host]/83/
- 107.174.192[.]219 port 80 - 107.174.192[.]219 - GET /images/cursor.png
- 107.174.192[.]219 port 80 - 107.174.192[.]219 - GET /images/imgpaper.png

0 comments on commit d26d622

Please sign in to comment.