cyber_threat_intelligence/actors/TrickBot
2023-06-06 10:26:07 +02:00
..
README.md Update June 2023 2023-06-06 10:26:07 +02:00

TrickBot - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as TrickBot. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.trickbot

Campaigns

The following campaigns are known and can be associated with TrickBot:

  • AnchorMail
  • Bitzlato

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with TrickBot:

There are 2 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of TrickBot.

ID IP address Hostname Campaign Confidence
1 3.130.204.160 ec2-3-130-204-160.us-east-2.compute.amazonaws.com Bitzlato Medium
2 3.131.233.90 ec2-3-131-233-90.us-east-2.compute.amazonaws.com Bitzlato Medium
3 3.209.171.143 ec2-3-209-171-143.compute-1.amazonaws.com - Medium
4 3.217.175.153 ec2-3-217-175-153.compute-1.amazonaws.com - Medium
5 3.224.145.145 ec2-3-224-145-145.compute-1.amazonaws.com - Medium
6 3.231.23.10 ec2-3-231-23-10.compute-1.amazonaws.com - Medium
7 5.1.81.68 mx4.tarifvergleichbhv.net - High
8 5.2.70.145 merlinsbeard.co.uk - High
9 5.2.72.84 cipixia.com - High
10 5.2.75.93 - - High
11 5.2.75.137 - - High
12 5.2.75.167 coms.a9v34.com.cn - High
13 5.2.76.122 mx3.ximple.eu - High
14 5.2.78.118 - - High
15 5.34.74.210 - - High
16 5.34.177.50 unallocated.layer6.net - High
17 5.34.178.126 yhlas111410.pserver.ru - High
18 5.34.180.173 - - High
19 5.34.180.180 stportal.com.ua - High
20 5.34.180.185 vt-bak-scan-0.antkar.hosted-by.itldc.com - High
21 5.39.47.22 mail.dmgs.site - High
22 5.53.124.49 dgbtechnologies.com - High
23 5.59.205.32 dhcp-32-205-59-5.metro86.ru - High
24 5.79.68.107 - Bitzlato High
25 5.79.68.108 - Bitzlato High
26 5.79.68.109 - Bitzlato High
27 5.79.68.110 - Bitzlato High
28 5.133.179.108 5-133-179-108.freeucouponsnow.ru - High
29 5.149.253.99 - - High
30 5.152.175.57 - - High
31 5.182.210.30 realestatepromotion.ru - High
32 5.182.210.109 - - High
33 5.182.210.132 - - High
34 5.182.210.178 mail.rainingdreams.to - High
35 5.182.210.226 - - High
36 5.182.210.230 - - High
37 5.182.210.246 - - High
38 5.182.210.254 n01-nlam.kdktech.com - High
39 5.182.211.44 - - High
40 5.196.247.14 ip14.ip-5-196-247.eu - High
41 5.199.173.152 - - High
42 5.202.120.150 - - High
43 5.230.22.40 - - High
44 5.255.96.217 vps11.host1.be - High
45 5.255.96.218 - - High
46 8.247.119.126 - - High
47 8.253.38.248 - - High
48 8.253.140.118 - - High
49 8.253.141.249 - - High
50 8.253.154.236 - - High
51 13.107.21.200 - - High
52 14.102.15.100 - - High
53 14.102.15.101 - - High
54 14.102.46.9 - - High
55 14.102.72.204 - - High
56 14.102.188.227 axntech-dynamic-227.188.102.14.axntechnologies.in - High
57 14.232.161.45 - - High
58 14.241.244.60 - - High
59 18.139.111.104 ec2-18-139-111-104.ap-southeast-1.compute.amazonaws.com - Medium
60 18.213.79.189 ec2-18-213-79-189.compute-1.amazonaws.com - Medium
61 18.213.250.117 ec2-18-213-250-117.compute-1.amazonaws.com Bitzlato Medium
62 18.215.128.143 ec2-18-215-128-143.compute-1.amazonaws.com Bitzlato Medium
63 18.233.90.151 ec2-18-233-90-151.compute-1.amazonaws.com - Medium
64 23.3.13.88 a23-3-13-88.deploy.static.akamaitechnologies.com - High
65 23.3.13.154 a23-3-13-154.deploy.static.akamaitechnologies.com - High
66 23.3.125.111 a23-3-125-111.deploy.static.akamaitechnologies.com - High
67 23.19.31.135 - - High
68 23.19.227.147 - - High
69 23.20.220.174 ec2-23-20-220-174.compute-1.amazonaws.com - Medium
70 23.20.239.12 ec2-23-20-239-12.compute-1.amazonaws.com Bitzlato Medium
71 23.21.27.29 ec2-23-21-27-29.compute-1.amazonaws.com - Medium
72 23.21.48.44 ec2-23-21-48-44.compute-1.amazonaws.com - Medium
73 23.21.121.219 ec2-23-21-121-219.compute-1.amazonaws.com - Medium
74 23.21.252.4 ec2-23-21-252-4.compute-1.amazonaws.com - Medium
75 23.23.83.153 ec2-23-23-83-153.compute-1.amazonaws.com - Medium
76 23.23.243.154 ec2-23-23-243-154.compute-1.amazonaws.com - Medium
77 23.46.150.43 a23-46-150-43.deploy.static.akamaitechnologies.com - High
78 23.46.150.58 a23-46-150-58.deploy.static.akamaitechnologies.com - High
79 23.46.150.81 a23-46-150-81.deploy.static.akamaitechnologies.com - High
80 23.62.6.161 a23-62-6-161.deploy.static.akamaitechnologies.com - High
81 23.62.6.170 a23-62-6-170.deploy.static.akamaitechnologies.com - High
82 23.94.70.12 23-94-70-12-host.colocrossing.com - High
83 23.94.233.210 23-94-233-210-host.colocrossing.com - High
84 23.95.97.59 23-95-97-59-host.colocrossing.com - High
85 23.95.231.187 23-95-231-187-host.colocrossing.com - High
86 23.96.30.229 - - High
87 23.160.192.125 unknown.ip-xfer.net - High
88 23.160.193.106 unknown.ip-xfer.net - High
89 23.202.231.166 a23-202-231-166.deploy.static.akamaitechnologies.com - High
90 23.202.231.167 a23-202-231-167.deploy.static.akamaitechnologies.com Bitzlato High
91 23.217.138.107 a23-217-138-107.deploy.static.akamaitechnologies.com - High
92 23.217.138.108 a23-217-138-108.deploy.static.akamaitechnologies.com Bitzlato High
93 23.227.196.5 23-227-196-5.static.hvvc.us - High
94 23.227.206.170 23-227-206-170.static.hvvc.us - High
95 23.254.224.2 hwsrv-1062664.hostwindsdns.com - High
96 24.28.12.23 cpe-24-28-12-23.austin.res.rr.com - High
97 24.32.202.68 - - High
98 24.153.175.236 rrcs-24-153-175-236.sw.biz.rr.com - High
99 24.162.214.166 cpe-24-162-214-166.elp.res.rr.com - High
100 24.182.101.64 024-182-101-064.res.spectrum.com - High
101 24.227.152.42 rrcs-24-227-152-42.sw.biz.rr.com - High
102 27.72.107.215 dynamic-adsl.viettel.vn - High
103 27.147.173.227 173.227.cetus.link3.net - High
104 30.10.121.157 - - High
105 31.31.204.59 cluster25.reg.ru Bitzlato High
106 31.31.204.61 parking.reg.ru Bitzlato High
107 31.128.13.45 31-128-13-45.ip.oxynet.pl - High
108 31.129.228.122 - - High
109 31.131.21.184 - - High
110 31.131.26.122 - - High
111 31.134.60.181 31-134-60-181.telico.pl - High
112 31.134.124.90 - - High
113 31.172.177.90 poczta.mp-lift.pl - High
114 31.173.137.39 - - High
115 31.173.137.47 - - High
116 31.173.137.49 - - High
117 31.184.253.6 - - High
118 31.184.253.37 models9.vixgrafica.de - High
119 31.202.132.22 - - High
120 31.211.85.110 - - High
121 31.214.138.207 f0a4213918138.rev.snt.net.pl - High
122 31.220.16.53 - Bitzlato High
123 34.117.59.81 81.59.117.34.bc.googleusercontent.com - Medium
124 34.160.111.145 145.111.160.34.bc.googleusercontent.com - Medium
125 34.192.250.175 ec2-34-192-250-175.compute-1.amazonaws.com - Medium
126 34.196.181.158 ec2-34-196-181-158.compute-1.amazonaws.com - Medium
127 34.198.132.204 ec2-34-198-132-204.compute-1.amazonaws.com - Medium
128 34.233.102.38 ec2-34-233-102-38.compute-1.amazonaws.com - Medium
129 36.37.99.242 - - High
130 36.37.176.6 - - High
131 36.66.111.251 - - High
132 36.66.115.180 - - High
133 36.66.188.251 - - High
134 36.67.97.127 - - High
135 36.67.109.15 - - High
136 36.71.150.118 - - High
137 36.89.85.103 - - High
138 36.89.98.183 - - High
139 36.89.106.69 - - High
140 36.89.191.119 - - High
141 36.89.193.181 - - High
142 36.89.193.235 - - High
143 36.89.228.201 - - High
144 36.89.243.241 - - High
145 36.91.36.29 - - High
146 36.91.45.10 - - High
147 36.91.87.227 - - High
148 36.91.88.164 - - High
149 36.91.98.231 - - High
150 36.91.117.231 - - High
151 36.91.186.235 - - High
152 36.92.59.93 - - High
153 36.92.93.5 - - High
154 36.94.27.124 - - High
155 36.94.33.102 - - High
156 36.94.62.207 - - High
157 36.94.100.202 - - High
158 36.94.202.131 - - High
159 36.95.4.29 - - High
160 36.95.23.89 - - High
161 36.95.27.243 - - High
162 36.95.110.19 - - High
163 37.7.123.244 apn-37-7-123-244.dynamic.gprs.plus.pl - High
164 37.44.212.179 - - High
165 37.44.212.216 - - High
166 37.48.65.136 - Bitzlato High
167 37.48.65.143 - Bitzlato High
168 37.48.65.145 - Bitzlato High
169 37.48.65.148 - Bitzlato High
170 37.48.65.149 - Bitzlato High
171 37.48.65.150 - Bitzlato High
172 37.48.65.151 - Bitzlato High
173 37.48.65.152 - Bitzlato High
174 37.48.65.153 - Bitzlato High
175 37.48.65.154 - Bitzlato High
176 37.48.65.155 - Bitzlato High
177 37.57.82.112 112.82.57.37.triolan.net - High
178 37.59.183.142 - - High
179 37.143.150.186 - - High
180 37.228.70.134 - - High
181 37.228.117.146 metobor.ru - High
182 37.228.117.250 janome.ru - High
183 37.230.112.146 audiotop.ru - High
184 37.230.114.93 admin1.fvds.ru - High
185 37.230.114.248 kosmolot.com - High
186 37.230.115.129 dvcarry.fvds.ru - High
187 37.230.115.133 wdai.io - High
188 37.230.115.138 i2.com - High
189 37.230.115.171 geobrox.com - High
190 37.230.115.184 21922vdscom.com - High
191 37.235.230.123 37-235-230-123.dynamic.customer.lanta.me - High
192 38.110.100.33 - - High
193 38.110.100.104 - - High
194 38.110.100.142 - - High
195 38.110.100.242 - - High
196 38.110.103.18 - - High
197 38.110.103.113 - - High
198 38.110.103.124 - - High
199 38.110.103.136 - - High
200 38.132.99.174 - - High
201 41.57.156.203 - - High
202 41.60.233.170 - - High
203 41.77.134.250 cliente6386477933.clubnet.mz - High
204 41.159.31.227 - - High
205 41.175.22.226 - - High
206 41.189.214.11 - - High
207 41.216.166.142 - - High
208 41.243.29.182 182-29-243-41.r.airtel.cd - High
209 43.225.148.118 - - High
210 43.245.216.116 - - High
211 43.252.158.104 ipv4-104-158-252.as55666.net - High
212 45.4.29.26 - - High
213 45.5.152.39 - - High
214 45.6.16.68 - - High
215 45.7.56.172 - - High
216 45.14.226.101 - - High
217 45.14.226.115 - - High
218 45.36.99.184 cpe-45-36-99-184.triad.res.rr.com - High
219 45.65.249.154 - - High
220 45.66.11.116 vm1488716.2ssd.had.wf - High
221 45.70.4.108 - - High
222 45.70.14.98 host-45-70-14-98.nedetel.net - High
223 45.77.55.61 45.77.55.61.vultrusercontent.com Bitzlato High
224 45.79.90.143 45-79-90-143.ip.linodeusercontent.com - High
225 45.79.126.97 45-79-126-97.ip.linodeusercontent.com - High
226 45.79.155.9 45-79-155-9.ip.linodeusercontent.com - High
227 45.79.212.97 45-79-212-97.ip.linodeusercontent.com - High
228 45.79.253.142 45-79-253-142.ip.linodeusercontent.com - High
229 45.80.148.30 - - High
230 45.83.129.224 - - High
231 45.83.151.103 - - High
232 45.86.74.111 - - High
233 45.89.125.214 - - High
234 45.89.127.70 - - High
235 45.89.127.92 - - High
236 45.89.127.240 - - High
237 45.115.172.105 - - High
238 45.116.106.45 - - High
239 45.125.1.34 45.125.1.34.static.xtom.hk - High
240 45.127.222.8 - - High
241 45.137.151.198 ourdiaspora.net - High
242 45.138.158.32 - - High
243 45.142.213.58 vm372119.pq.hosting - High
244 45.142.215.235 vm1246284.stark-industries.solutions - High
245 45.144.113.168 - - High
246 45.148.120.153 - - High
247 45.148.120.195 pe195.peryon.web.tr - High
248 45.155.173.242 - - High
249 45.155.173.248 - - High
250 45.160.145.11 - - High
251 45.160.145.179 - - High
252 45.160.145.216 - - High
253 45.161.33.88 - - High
254 45.164.80.94 - - High
255 45.167.249.126 - - High
256 45.178.142.14 - - High
257 45.181.207.101 - - High
258 45.181.207.156 - - High
259 45.182.190.142 - - High
260 45.201.134.202 - - High
261 45.201.136.3 - - High
262 45.201.209.29 - - High
263 45.224.214.34 clientes-214-34.intercommtech.com.br - High
264 45.226.124.226 45-226-124-226.gilsonnet.com.br - High
265 45.229.71.211 static-45-229-71-211.extrememt.com.br - High
266 45.229.162.233 - - High
267 45.230.244.20 - - High
268 45.233.116.8 - - High
269 45.233.170.75 ip-cr4523316975.clientesimectgroup.com - High
270 45.234.248.66 45.-234.248-66.rev.voanet.br - High
271 45.234.248.146 45.-234.248-146.rev.voanet.br - High
272 45.234.248.154 45.-234.248-154.rev.voanet.br - High
273 45.235.5.162 45-235-5-162.aknet.net.br - High
274 45.235.213.126 - - High
275 45.239.233.131 45-239-233-131.speednetinformatica.com.br - High
276 45.239.234.2 - - High
277 45.250.65.9 - - High
278 46.4.167.227 static.227.167.4.46.clients.your-server.de - High
279 46.4.167.250 ip-subnet46-4-167.unassigned.theideahosting.net - High
280 46.8.21.10 53980.web.hosting-russia.ru - High
281 46.8.21.113 64403.web.hosting-russia.ru - High
282 46.30.41.229 vm494526.eurodir.ru - High
283 46.30.45.208 vm418209.eurodir.ru - High
284 46.99.175.149 - - High
285 46.99.175.217 - - High
286 46.99.188.223 - - High
287 46.105.84.141 - - High
288 46.166.182.54 suggest-wrong.shamrockuser.com Bitzlato High
289 46.166.182.62 all-multiuser.aboveoption.com Bitzlato High
290 46.174.235.36 host36.net46-174-235.interkam.pl - High
291 46.209.140.220 - - High
292 46.237.117.193 - - High
293 46.254.128.174 46.254.128.174.lanultra.net - High
294 47.37.90.57 047-037-090-057.res.spectrum.com - High
295 47.51.21.82 047-051-021-082.biz.spectrum.com - High
296 47.51.219.98 047-051-219-098.biz.spectrum.com - High
297 47.190.2.12 static-47-190-2-12.crtn.tx.frontiernet.net - High
298 49.156.34.134 - - High
299 49.156.39.150 - - High
300 49.176.188.184 static-n49-176-188-184.bla2.nsw.optusnet.com.au - High
301 49.248.217.170 static-170.217.248.49-tataidc.co.in - High
302 50.16.229.140 ec2-50-16-229-140.compute-1.amazonaws.com - Medium
303 50.19.247.198 ec2-50-19-247-198.compute-1.amazonaws.com - Medium
304 50.63.202.53 53.202.63.50.host.secureserver.net Bitzlato High
305 50.63.202.64 64.202.63.50.host.secureserver.net Bitzlato High
306 50.63.202.65 65.202.63.50.host.secureserver.net Bitzlato High
307 50.63.202.69 69.202.63.50.host.secureserver.net Bitzlato High
308 50.63.202.93 93.202.63.50.host.secureserver.net Bitzlato High
309 50.75.131.6 rrcs-50-75-131-6.nys.biz.rr.com - High
310 50.84.233.214 rrcs-50-84-233-214.sw.biz.rr.com - High
311 50.197.243.125 50-197-243-125-static.hfc.comcastbusiness.net - High
312 50.208.68.153 50-208-68-153-static.hfc.comcastbusiness.net - High
313 51.38.101.194 - - High
314 51.68.247.62 ip62.ip-51-68-247.eu - High
315 51.77.92.215 - - High
316 51.77.124.137 - - High
317 51.81.112.144 - - High
318 51.81.113.25 - - High
319 51.89.73.159 theladbible.site - High
320 51.89.115.101 secure-3111.buzztary.com - High
321 51.89.115.108 coms.jt120.com.cn - High
322 51.89.115.110 pocket-usage.nationfox.net - High
323 51.89.115.112 brides-crude.nationfox.net - High
324 51.89.115.116 tombe.nationfox.net - High
325 51.89.115.121 mail1.cmailer.online - High
326 51.89.115.124 mta.ga-emailcamel.com - High
327 51.89.177.20 ip20.ip-51-89-177.eu - High
328 51.159.23.217 jambold.co.uk - High
329 51.254.25.115 ip115.ip-51-254-25.eu - High
330 51.254.69.244 - - High
331 51.254.83.17 ip17.ip-51-254-83.eu - High
332 51.254.164.243 amortizserv.info - High
333 51.254.164.244 y9gs.gaurented.com - High
334 51.254.164.245 ip245.ip-51-254-164.eu - High
335 51.254.164.249 ip249.ip-51-254-164.eu - High
336 52.0.197.231 ec2-52-0-197-231.compute-1.amazonaws.com - Medium
337 52.0.217.44 ec2-52-0-217-44.compute-1.amazonaws.com Bitzlato Medium
338 52.4.209.250 ec2-52-4-209-250.compute-1.amazonaws.com Bitzlato Medium
339 52.6.128.155 ec2-52-6-128-155.compute-1.amazonaws.com Bitzlato Medium
340 52.20.78.240 ec2-52-20-78-240.compute-1.amazonaws.com - Medium
341 52.20.197.7 ec2-52-20-197-7.compute-1.amazonaws.com - Medium
342 52.44.169.135 ec2-52-44-169-135.compute-1.amazonaws.com - Medium
343 52.54.24.134 ec2-52-54-24-134.compute-1.amazonaws.com Bitzlato Medium
344 52.55.255.113 ec2-52-55-255-113.compute-1.amazonaws.com - Medium
345 52.73.179.54 ec2-52-73-179-54.compute-1.amazonaws.com Bitzlato Medium
346 52.202.139.131 ec2-52-202-139-131.compute-1.amazonaws.com - Medium
347 52.204.109.97 ec2-52-204-109-97.compute-1.amazonaws.com - Medium
348 52.206.161.133 ec2-52-206-161-133.compute-1.amazonaws.com - Medium
349 52.206.178.1 ec2-52-206-178-1.compute-1.amazonaws.com - Medium
350 53.182.82.27 - - High
351 54.39.106.25 ns560342.ip-54-39-106.net - High
352 54.111.105.80 - - High
353 54.161.222.85 ec2-54-161-222-85.compute-1.amazonaws.com Bitzlato Medium
354 54.204.36.156 ec2-54-204-36-156.compute-1.amazonaws.com - Medium
355 54.221.253.252 ec2-54-221-253-252.compute-1.amazonaws.com - Medium
356 54.225.159.35 ec2-54-225-159-35.compute-1.amazonaws.com - Medium
357 54.235.124.112 ec2-54-235-124-112.compute-1.amazonaws.com - Medium
358 54.235.203.7 ec2-54-235-203-7.compute-1.amazonaws.com - Medium
359 54.235.220.229 ec2-54-235-220-229.compute-1.amazonaws.com - Medium
360 54.243.147.226 ec2-54-243-147-226.compute-1.amazonaws.com - Medium
361 54.243.198.12 ec2-54-243-198-12.compute-1.amazonaws.com - Medium
362 54.243.208.112 ec2-54-243-208-112.compute-1.amazonaws.com - Medium
363 58.97.72.83 58-97-72-83.static.asianet.co.th - High
364 60.51.47.65 - - High
365 61.19.116.53 - - High
366 61.69.102.170 61-69-102-170.mel.static-ipl.aapt.com.au - High
367 62.64.9.237 clients-62.64.9.237.misp.ru - High
368 62.69.241.103 62-69-241-103.internetia.net.pl - High
369 62.99.76.213 213.62-99-76.static.clientes.euskaltel.es - High
370 62.99.79.77 77.62-99-79.static.clientes.euskaltel.es - High
371 62.109.2.172 megamart24.ru - High
372 62.109.6.188 velomarket31.ru - High
373 62.109.14.24 btc-manager1.ru - High
374 62.109.16.17 jl.ru5 - High
375 62.109.22.2 youavto.ru - High
376 62.109.22.172 map4child.fvds.ru - High
377 62.109.24.176 api.etkrasnodar.ru - High
378 62.109.24.242 cadtain.ru - High
379 ... ... ... ...

There are 1514 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by TrickBot. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1006 CWE-22, CWE-23, CWE-24, CWE-29, CWE-425 Pathname Traversal High
2 T1055 CWE-74 Injection High
3 T1059 CWE-94 Cross Site Scripting High
4 ... ... ... ...

There are 14 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by TrickBot. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File /admin/?page=user/list High
2 File /admin/ajax.php?action=save_area High
3 File /admin/contacts/organizations/edit/2 High
4 File /admin/modal_add_product.php High
5 File /admin/reportupload.aspx High
6 File /admin/update_s6.php High
7 File /ajax.php?action=read_msg High
8 File /ajax.php?action=save_company High
9 File /bin/login Medium
10 File /cgi-bin/wlogin.cgi High
11 File /forum/away.php High
12 File /librarian/bookdetails.php High
13 File /note/index/delete High
14 File /ServletAPI/accounts/login High
15 File /whbs/admin/?page=user High
16 File ?r=dashboard/approval/del High
17 ... ... ...

There are 141 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2023 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!