ExecuteMalware

2021-06-24 Hancitor IOCs

Jun 24th, 2021
16,178
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.50 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2406_plois
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Signature Service
  9. You got notification from DocuSign Electronic Service
  10. You got notification from DocuSign Electronic Signature Service
  11. You got notification from DocuSign Service
  12. You received invoice from DocuSign Electronic Service
  13. You received invoice from DocuSign Electronic Signature Service
  14. You received notification from DocuSign Electronic Service
  15. You received notification from DocuSign Electronic Signature Service
  16. You received notification from DocuSign Service
  17. You received notification from DocuSign Signature Service
  18.  
  19. SENDERS OBSERVED
  20.  
  21. MALDOC PROXY DISTRIBUTION URLS
  22. http://feedproxy.google.com/~r/bgbvibju/~3/QTY163Ko7JQ/optometrist.php
  23. http://feedproxy.google.com/~r/cggveg/~3/AmXmZw57kAk/inserption.php
  24. http://feedproxy.google.com/~r/choafrtq/~3/Fyd552myfZg/debt.php
  25. http://feedproxy.google.com/~r/ckwyijh/~3/b-gPX_4XNhk/subdebutante.php
  26. http://feedproxy.google.com/~r/djuagyinxje/~3/Q0ZTjJyuDYQ/miscellany.php
  27. http://feedproxy.google.com/~r/fqsxgzaihhx/~3/AgqgWUMrqCg/pluckily.php
  28. http://feedproxy.google.com/~r/gkhhwd/~3/q21hCpeqCcQ/pontifficate.php
  29. http://feedproxy.google.com/~r/homon/~3/lqSjvHz93J8/dig.php
  30. http://feedproxy.google.com/~r/lwfmysckzck/~3/P3heVxtuxuw/overgrown.php
  31. http://feedproxy.google.com/~r/nqumgmojti/~3/_0tkzYNiM0s/amazement.php
  32. http://feedproxy.google.com/~r/opuuysffvyh/~3/_0tkzYNiM0s/amazement.php
  33. http://feedproxy.google.com/~r/oqpno/~3/itKCwOQFdN8/nondata.php
  34. http://feedproxy.google.com/~r/smlarmgttmx/~3/f0N37_RQ7vc/madhouse.php
  35. http://feedproxy.google.com/~r/tspdzbzqo/~3/9nMNQjqMr2E/defences.php
  36. http://feedproxy.google.com/~r/xsaswa/~3/gs2bW7Axxj0/whirr.php
  37. http://feedproxy.google.com/~r/zpfphkwbb/~3/kbiPmbJv080/portable.php
  38. http://feedproxy.google.com/~r/zsmwvj/~3/anfgsZbZF-E/waspish.php
  39.  
  40. MALDOC REDIRECT DOWNLOAD URLS
  41. http://aladainexpress.com/portable.php
  42. http://alpharettaagency.com/optometrist.php
  43. http://anahurtado.co/miscellany.php
  44. http://bhumisilveriio.com/amazement.php
  45. http://bigs.bikershop.biz/debt.php
  46. http://bigs.bikershop.biz/overgrown.php
  47. http://invoiceonline.aaawastudio.com/whirr.php
  48. http://mail1.mycollege.com.my/inserption.php
  49. http://mrnutritionlive.mawaqaatest.com/pontifficate.php
  50. http://olga-grigoryeva.codehunt.site/madhouse.php
  51. http://olga-grigoryeva.codehunt.site/waspish.php
  52. http://wallempire.in/defences.php
  53. http://www.ezdarsoft.com/nondata.php
  54. https://gilhotras.alwarfoodies.com/pluckily.php
  55. https://gilhotras.alwarfoodies.com/subdebutante.php
  56. https://renesh.in/dig.php
  57.  
  58. aaawastudio.com
  59. aladainexpress.com
  60. alpharettaagency.com
  61. alwarfoodies.com
  62. anahurtado.co
  63. bhumisilveriio.com
  64. bikershop.biz
  65. codehunt.site
  66. ezdarsoft.com
  67. mawaqaatest.com
  68. mycollege.com.my
  69. renesh.in
  70. wallempire.in
  71.  
  72. HANCITOR MALDOC FILE HASHES
  73. 245962e326821690c73413f46fd87eab
  74. 28f529fcc12ad32b8733426a20464983
  75. 2f25702198b430cfcfebc55fcde9fd99
  76. 39ce3258d1c5a581fa832805cbf3d57c
  77. 7db66b44bb1d78e15135da32aafd503c
  78. a390a8c1d250d0768bf9d8506eb6a433
  79. a46dcaddce07cd7eb46c38363cce1019
  80. af003c7721484cbb648cf5356a90e179
  81. ca354ad05ee4966a012f725439bec0a4
  82. d83cf535f763128f7ae09d0fda196da9
  83.  
  84. HANCITOR PAYLOAD FILE HASH
  85. kikus.dll
  86. 022187805d2d54186e04c96993cfdd4b
  87.  
  88. HANCITOR C2
  89. http://eftegropecial.ru/8/forum.php
  90. http://sloyeatfroyin.ru/8/forum.php
  91. http://wouncring.com/8/forum.php
  92.  
  93. FICKER STEALER DOWNLOAD URL
  94. http://kubantr0.ru/7klyuds.exe
  95.  
  96. FICKER STEALER FILE HASH
  97. 7klyuds.exe
  98. 270c3859591599642bd15167765246e3
  99.  
  100. FICKER STEALER C2
  101. http://pospvisis.com
  102.  
  103. COBALT STRIKE STAGER PAYLOAD URLS
  104. http://kubantr0.ru/2406s.bin
  105. http://kubantr0.ru/2406.bin
  106.  
  107. COBALT STRIKE STAGER FILE HASHES
  108. 2406.bin
  109. af292caf8f001c326040fb22082c6219
  110.  
  111. 2406s.bin
  112. 7881495e12310261bb490321667b6647
  113.  
  114. COBALT STRIKE BEACON DOWNLOAD URLS
  115. http://80.209.242.126/Lk7n
  116. http://80.209.242.126/n1kR
  117.  
  118. COBALT STRIKE C2
  119. http://80.209.242.126/IE9CompatViewList.xml
  120.  
Advertisement
Add Comment
Please, Sign In to add comment