Contenu disponible en langue originale
class="post-article">

TrickBotMultiDropper

TrickBot XMR miner modulu + BrokenShield + revShell + SteamGhost enjeksiyonu iceren cok amacli dropper. api.foxovsky.ru/gate/connection.php TrickBot C2 gate. CPUMinerThread ile XMR madenciligi. Cok sayida payload URL. 12 PE section. Gelistirici imzalari: Meister (BrokenShield), x (Trik builder).

Profil de menace
Type Loader
Langage de programmationC++
Protocole C2HTTP
Première détection2024
Cibles Kuresel/Oyuncu
Objectif / Capacités
  • Loader/Miner/Dropper/Injection

Serveurs C2 5

Adresse Port Protocole Statut Action
api.foxovsky.ru
TrickBot XMR miner C2 gate /gate/connection.php CPUMinerThre
80 HTTP INACTIVE
185.185.25.175
C2 gate /ref45.php
80 HTTP INACTIVE
138.204.171.108
Payload download /BxjL5iKld8.zip
80 HTTP INACTIVE
92.63.197.153
Payload download /good.exe
80 HTTP INACTIVE
1226bye.xyz
SCR+DLL payload /v.sctscrobj.dll port 280
280 HTTP INACTIVE

⚠ Les adresses C2 sont partagées uniquement à des fins de renseignement sur les menaces et de défense. Tout accès non autorisé à ces adresses constitue une infraction pénale.

Rapports de recherche (1)

Kritik

TrickBotMultiDropper 12454a32 -- TrickBotXMRMiner apifoxovskyru CPUMinerThread BrokenShield revShell SteamGhost AsusShellcode PayloadDownload 1226byexyz | Kritik

TrickBotMultiDropper 12454a32 PE32+ x64 332KB. TrickBot miner api.foxovsky.ru/gate/connection.php. CPUMinerThread. BrokenShield PDB. 8 C2 IP. 1226bye.xyz:280.

Lire le rapport →