Advertisement
ExecuteMalware

2021-07-21 Hancitor IOCs

Jul 21st, 2021
12,006
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.56 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=1907_hjfsd
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25. a@divosad.com
  26. aedioyi@divosad.com
  27. afoy@divosad.com
  28. agigi@divosad.com
  29. ahauho@divosad.com
  30. ahioqe@divosad.com
  31. aienyl@divosad.com
  32. aja@divosad.com
  33. ajyutiw@divosad.com
  34. aneponi@divosad.com
  35. anueodg@divosad.com
  36. anymih@divosad.com
  37. arixidf@divosad.com
  38. awvrah@divosad.com
  39. azivu@divosad.com
  40. azovaix@divosad.com
  41. azpaa@divosad.com
  42. b@divosad.com
  43. bab@divosad.com
  44. baiyxm@divosad.com
  45. bepjut@divosad.com
  46. biurayv@divosad.com
  47. bo@divosad.com
  48. by@divosad.com
  49. cafm@divosad.com
  50. ceczmij@divosad.com
  51. ci@divosad.com
  52. cy@divosad.com
  53. das@divosad.com
  54. dofyury@divosad.com
  55. drjaaog@divosad.com
  56. duvwoel@divosad.com
  57. dyqi@divosad.com
  58. e@divosad.com
  59. eazo@divosad.com
  60. ebjued@divosad.com
  61. eeywtom@divosad.com
  62. ej@divosad.com
  63. emtir@divosad.com
  64. emuki@divosad.com
  65. epavuce@divosad.com
  66. eqqy@divosad.com
  67. eroxye@divosad.com
  68. esdyqov@divosad.com
  69. etit@divosad.com
  70. euitiyo@divosad.com
  71. ey@divosad.com
  72. ezzc@divosad.com
  73. f@divosad.com
  74. fesivke@divosad.com
  75. ffy@divosad.com
  76. fhfu@divosad.com
  77. fuvydoo@divosad.com
  78. fyeaiq@divosad.com
  79. g@divosad.com
  80. gahiogh@divosad.com
  81. gardyg@divosad.com
  82. gdegyic@divosad.com
  83. gecyumy@divosad.com
  84. gevobef@divosad.com
  85. gncekle@divosad.com
  86. gop@divosad.com
  87. gow@divosad.com
  88. gtwieyg@divosad.com
  89. guakyem@divosad.com
  90. gvuxuvu@divosad.com
  91. habbeoa@divosad.com
  92. hebxswh@divosad.com
  93. hfepr@divosad.com
  94. hgibbeo@divosad.com
  95. huuan@divosad.com
  96. hwyv@divosad.com
  97. i@divosad.com
  98. iaooppa@divosad.com
  99. ide@divosad.com
  100. ifo@divosad.com
  101. ikosiny@divosad.com
  102. ilru@divosad.com
  103. iugxjuw@divosad.com
  104. iuzmeew@divosad.com
  105. ivywazh@divosad.com
  106. iyq@divosad.com
  107. izci@divosad.com
  108. jieysek@divosad.com
  109. jiupeac@divosad.com
  110. jrpoto@divosad.com
  111. k@divosad.com
  112. ka@divosad.com
  113. kavhexa@divosad.com
  114. kdykhuf@divosad.com
  115. kiqjoli@divosad.com
  116. kiwakeq@divosad.com
  117. kogwixw@divosad.com
  118. koyae@divosad.com
  119. lendazy@divosad.com
  120. lhiiz@divosad.com
  121. lhnafah@divosad.com
  122. liadyt@divosad.com
  123. lmizoby@divosad.com
  124. lopur@divosad.com
  125. m@divosad.com
  126. maduui@divosad.com
  127. mearcis@divosad.com
  128. menemye@divosad.com
  129. mh@divosad.com
  130. n@divosad.com
  131. nanyapy@divosad.com
  132. nceoo@divosad.com
  133. noupn@divosad.com
  134. nuupfmy@divosad.com
  135. nuyt@divosad.com
  136. o@divosad.com
  137. ocuywed@divosad.com
  138. ofimin@divosad.com
  139. ojba@divosad.com
  140. olek@divosad.com
  141. oqvxin@divosad.com
  142. oviuvue@divosad.com
  143. ovzenlo@divosad.com
  144. oyrgyxu@divosad.com
  145. ozinkjo@divosad.com
  146. p@divosad.com
  147. papqa@divosad.com
  148. parowaz@divosad.com
  149. pcyi@divosad.com
  150. pe@divosad.com
  151. pjnhu@divosad.com
  152. pnrogby@divosad.com
  153. pz@divosad.com
  154. qi@divosad.com
  155. qiprhey@divosad.com
  156. qx@divosad.com
  157. r@divosad.com
  158. rayme@divosad.com
  159. rgsuy@divosad.com
  160. ron@divosad.com
  161. rvojy@divosad.com
  162. ryikas@divosad.com
  163. ryuwijd@divosad.com
  164. ryx@divosad.com
  165. sa@divosad.com
  166. sawmajt@divosad.com
  167. se@divosad.com
  168. su@divosad.com
  169. submnob@divosad.com
  170. svai@divosad.com
  171. syzulk@divosad.com
  172. t@divosad.com
  173. tmyxwef@divosad.com
  174. tofuauk@divosad.com
  175. toryvac@divosad.com
  176. tubemyz@divosad.com
  177. tulfoq@divosad.com
  178. tyvipyl@divosad.com
  179. tyyumvo@divosad.com
  180. tzorexa@divosad.com
  181. ua@divosad.com
  182. uao@divosad.com
  183. ubavfgl@divosad.com
  184. ucafem@divosad.com
  185. ueixe@divosad.com
  186. uelaony@divosad.com
  187. uk@divosad.com
  188. ukup@divosad.com
  189. upo@divosad.com
  190. uropa@divosad.com
  191. uusty@divosad.com
  192. uux@divosad.com
  193. uyymavf@divosad.com
  194. vetfebe@divosad.com
  195. vewieuz@divosad.com
  196. vjeui@divosad.com
  197. voprpip@divosad.com
  198. vug@divosad.com
  199. vxaaloe@divosad.com
  200. wapenyq@divosad.com
  201. whkoovn@divosad.com
  202. wl@divosad.com
  203. woqiuvd@divosad.com
  204. wqicivy@divosad.com
  205. wyqiu@divosad.com
  206. x@divosad.com
  207. xapkafi@divosad.com
  208. xuuqam@divosad.com
  209. xy@divosad.com
  210. xydduyf@divosad.com
  211. xyguc@divosad.com
  212. xyt@divosad.com
  213. yd@divosad.com
  214. yikqzyq@divosad.com
  215. yjdyzu@divosad.com
  216. yji@divosad.com
  217. ykia@divosad.com
  218. yohax@divosad.com
  219. yuhcfko@divosad.com
  220. yuugym@divosad.com
  221. yvoyd@divosad.com
  222. ywmy@divosad.com
  223. yyeodef@divosad.com
  224. z@divosad.com
  225. za@divosad.com
  226. zaaoaox@divosad.com
  227. zeiqayu@divosad.com
  228. zeomado@divosad.com
  229. zipajzc@divosad.com
  230. ziqycay@divosad.com
  231. zlubhel@divosad.com
  232. zobekg@divosad.com
  233. zvtwieh@divosad.com
  234. zycudyl@divosad.com
  235. zyuovey@divosad.com
  236. zzb@divosad.com
  237.  
  238. MALDOC PROXY DISTRIBUTION URLS
  239. http://feedproxy.google.com/~r/ubrbdz/~3/bJamsKHFAfk/metallurgist.php
  240. http://feedproxy.google.com/~r/udcbgnbhl/~3/p5FUZcPBCEU/breadbasket.php
  241. http://feedproxy.google.com/~r/qergkluvhuv/~3/SUsTLKh812c/simpleminded.php
  242. http://feedproxy.google.com/~r/npfjs/~3/sSx348jo1gk/steeplechase.php
  243. http://feedproxy.google.com/~r/rpacrc/~3/zqtp-OUTWSw/unable.php
  244.  
  245. MALDOC REDIRECT DOWNLOAD URLS
  246. Unavailable
  247.  
  248. MALDOC FILE HASHES
  249. 0721_7525265361.xls
  250. ddfe01c006b3cbf4a6929073e235a8b4
  251.  
  252. HANCITOR PAYLOAD FILE HASH
  253. omsh.dll
  254. 24190cd699631d16521dfb588b2571a3
  255.  
  256. HANCITOR C2
  257. http://anithedtatione.ru/8/forum.php
  258. http://thervidolown.com/8/forum.php
  259. http://wiltuslads.ru/8/forum.php
  260.  
  261. FICKER STEALER DOWNLOAD URL
  262. http://falan4zadron.ru/7hsjfd9w4refsd.exe
  263.  
  264. FICKER STEALER FILE HASH
  265. 7hsjfd9w4refsd.exe
  266. 270c3859591599642bd15167765246e3
  267.  
  268. FICKER STEALER C2
  269. http://pospvisis.com
  270.  
  271. COBALT STRIKE STAGER DOWNLOAD URLS
  272. http://falan4zadron.ru/1907.bin
  273. http://falan4zadron.ru/1907S.bin
  274.  
  275. COBALT STRIKE STAGER FILE HASHES
  276. 1907.bin
  277. f11e2c4dded5a019edf7718af78e8731
  278.  
  279. 1907s.bin
  280. 4cd7b8233b10bf0ffa75986b4479cd19
  281.  
  282. COBALT STRIKE BEACON DOWNLOAD URL
  283. http://37.1.208.250/j7Pk
  284.  
  285. COBALT STRIKE BEACON FILE HASH
  286. j7Pk
  287. 122fef124babe98581e285e148d841d2
  288.  
  289. COBALT STRIKE C2
  290. http://37.1.208.250/IE9CompatViewList.xml
  291.  
  292.  
  293. COBALT STRIKE BEACON CONFIG (extracted using Didier Stevens 1768 Python script)
  294. 0x0003 sleeptime 0x0002 0x0004 60000
  295. 0x0004 maxgetsize 0x0002 0x0004 1048576
  296. 0x0005 jitter 0x0001 0x0002 0
  297. 0x0007 publickey 0x0003 0x0100 30819f300d06092a864886f70d010101050003818d0030818902818100a738cde75f1fbb1c18646c377e03016b162b12ba72bdf7dc36b4cd2e4e9bae12205a95c26170bf908105ad7fa4bbccfa798632261bed9870f975f20794e1fe499523d71f08a56cae0315bfde3d6c8a16386b03b7a6551aa1336d50325a3500db27d78ad8fd13b6a73b9fb7c3fb4d7a088e323f07618656ecd83595fa5f823613020301000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
  298. 0x0008 server,get-uri 0x0003 0x0100 '37.1.208.250,/IE9CompatViewList.xml'
  299. 0x0043 0x0001 0x0002 0
  300. 0x0044 0x0002 0x0004 4294967295
  301. 0x0045 0x0002 0x0004 4294967295
  302. 0x0046 0x0002 0x0004 4294967295
  303. 0x000e SpawnTo 0x0003 0x0010 (NULL ...)
  304. 0x001d spawnto_x86 0x0003 0x0040 '%windir%\\syswow64\\rundll32.exe'
  305. 0x001e spawnto_x64 0x0003 0x0040 '%windir%\\sysnative\\rundll32.exe'
  306. 0x001f CryptoScheme 0x0001 0x0002 0
  307. 0x001a get-verb 0x0003 0x0010 'GET'
  308. 0x001b post-verb 0x0003 0x0010 'POST'
  309. 0x001c HttpPostChunk 0x0002 0x0004 0
  310. 0x0025 license-id 0x0002 0x0004 0
  311. 0x0026 bStageCleanup 0x0001 0x0002 0
  312. 0x0027 bCFGCaution 0x0001 0x0002 0
  313. 0x0009 useragent 0x0003 0x0100 'Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322)'
  314. 0x000a post-uri 0x0003 0x0040 '/submit.php'
  315. 0x000b Malleable_C2_Instructions 0x0003 0x0100 '\x00\x00\x00\x04'
  316. 0x000c http_get_header 0x0003 0x0200
  317. b'Cookie'
  318. 0x000d http_post_header 0x0003 0x0200
  319. b'&Content-Type: application/octet-stream'
  320. b'id'
  321. 0x0036 HostHeader 0x0003 0x0080 (NULL ...)
  322. 0x0032 UsesCookies 0x0001 0x0002 1
  323. 0x0023 proxy_type 0x0001 0x0002 2 IE settings
  324. 0x003a 0x0003 0x0080 '\x00\x04'
  325. 0x0039 0x0003 0x0080 '\x00\x04'
  326. 0x0037 0x0001 0x0002 0
  327. 0x0028 killdate 0x0002 0x0004 0
  328. 0x0029 textSectionEnd 0x0002 0x0004 0
  329. 0x002b process-inject-start-rwx 0x0001 0x0002 64 PAGE_EXECUTE_READWRITE
  330. 0x002c process-inject-use-rwx 0x0001 0x0002 64 PAGE_EXECUTE_READWRITE
  331. 0x002d process-inject-min_alloc 0x0002 0x0004 0
  332. 0x002e process-inject-transform-x86 0x0003 0x0100 (NULL ...)
  333. 0x002f process-inject-transform-x64 0x0003 0x0100 (NULL ...)
  334. 0x0035 process-inject-stub 0x0003 0x0010 '2ÍAíð\x81\x0c[_I\x8eßG1Ìm'
  335. 0x0033 process-inject-execute 0x0003 0x0080 '\x01\x02\x03\x04'
  336. 0x0034 process-inject-allocation-method 0x0001 0x0002 0
  337. 0x0000
  338.  
  339.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement