3r1c
@p5yb34m
1nc1d3n7 r35p0n53
ID: 884503938937962496
10-07-2017 20:05:47
363 Tweet
867 Takipçi
119 Takip Edilen
#IcedID: .dll's: ://45.140.146.34/44270.7073414352.dat ://185.82.219.160/44270.7073414352.dat ://188.127.254.114/44270.7073414352.dat C2: asforthemines99[.]uno .xls Sample: bazaar.abuse.ch/sample/2baf563… .dll Sample: bazaar.abuse.ch/sample/8e51ccc… Malware Config: tria.ge/210315-3lcddwd…
#Gozi #IFSB (5513 botnet): .doc dropper Sample: bazaar.abuse.ch/sample/8a87c11… C2: greenwoodgrace[.]website Malware Config: tria.ge/210316-1tdtkqq… JAMESWT_MHT
#Trickbot (rob78 botnet) #TA505: .dll: ://www.linkinc.es/scss/water.php .dll Sample: bazaar.abuse.ch/sample/162bfeb… .xlsm Sample: bazaar.abuse.ch/sample/3812b84… C2 Traffic: pastebin.com/raw/XBy2rJF3 Malware Config: tria.ge/210316-brmdt7s… JAMESWT_MHT
#Trickbot (mon156 botnet): PE32 .dll Source: s://ozpinarco.com/wp-content/themes/archi-child/images/prettyPhoto/156.dll PE32 .dll Sample: bazaar.abuse.ch/sample/9ec541b… C2 Traffic: pastebin.com/raw/Ap9UKSy1 Malware Config: tria.ge/210319-2neldc7… JAMESWT_MHT
#Trickbot (mon147 botnet): .dll: s://ozpinarco.com/wp-content/themes/archi-child/images/prettyPhoto/147.dll .dll Sample: bazaar.abuse.ch/sample/aed2b8d… C2 Traffic: pastebin.com/raw/HLE7pSaL Malware Config: tria.ge/210319-qaxfy9s… JAMESWT_MHT
#Trickbot #opendir (mon### botnet payloads): ://wajirmaternityandnursinghome.co.ke/vendor/phpunit/phpunit-mock-objects/tests/MockObject/ Malware Config (C2s for mon156 botnet): tria.ge/210319-tcpzt1j… JAMESWT_MHT
#Gozi #IFSB (1100 botnet) #opendir (with #Trickbot): s://wajirmaternityandnursinghome.co[.]ke/vendor/phpunit/phpunit-mock-objects/tests/MockObject/ C2s: api10[.]laptok[.]at/api1 golang[.]feel500[.]at/api1 go.in100k[.]at/api1 Malware Config: tria.ge/210319-6ybds9f… JAMESWT_MHT