ExecuteMalware

2021-04-20 Hancitor IOCs

Apr 20th, 2021
16,566
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.66 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Electronic Signature Service
  6. You got invoice from DocuSign Service
  7. You got invoice from DocuSign Signature Service
  8. You got notification from DocuSign Electronic Service
  9. You got notification from DocuSign Electronic Signature Service
  10. You got notification from DocuSign Service
  11. You received invoice from DocuSign Electronic Service
  12. You received invoice from DocuSign Electronic Signature Service
  13. You received invoice from DocuSign Service
  14. You received invoice from DocuSign Signature Service
  15. You received notification from DocuSign Electronic Service
  16. You received notification from DocuSign Electronic Signature Service
  17. You received notification from DocuSign Service
  18. You received notification from DocuSign Signature Service
  19.  
  20. SENDERS OBSERVED
  21.  
  22. MALDOC LANDING PAGE URLS
  23. https://docs.google.com/document/d/e/2PACX-1vQa9QzPy4bCm8pHm8CwjiPeJBi7XmIxzf2IALrGkIruHTwb72pGSmP6SFUeXaNcdOjVhw0BQQhAydeV/pub
  24. https://docs.google.com/document/d/e/2PACX-1vQC1GfeIv0DdXEXmLoHcvcbMmGaFFcx1_6E0xDAALcH3efDm_wg9uHVNR1NXXYHCD4wkJngybQ2gpwT/pub
  25. https://docs.google.com/document/d/e/2PACX-1vQeiaRGvogu_Re2hI2I2P5RQYDjVLv2mXdi1N5Jo_B55wmDHYLlZbwPWZG7AVrIWaAcYVwMFyHJ_hQQ/pub
  26. https://docs.google.com/document/d/e/2PACX-1vQiuLBW05nC2m4TN70wdjSTUA75wpWmUM9zr1vTGknukogti-4jBtIYFzSRqvbVzfiQlkbw3y6Bd0hK/pub
  27. https://docs.google.com/document/d/e/2PACX-1vQLbrvHZ5NxnUypXEuZ91w0u9RY10aOMX_NVqxUnA20ySwk2TLGQEqxRbAV8muK3q5zmvvJDRYgIIer/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQNRpU8WX9jXk2CDGqHhi_k-Oi7W2wWg8wZrDDGAJXnsTd3ulg-y-mzJMKUVb4AHr-LW4d6Xs6UJ-qN/pub
  29. https://docs.google.com/document/d/e/2PACX-1vQnW7YVj17nVq2RKMNdYOtVNsBQ3P7Ngr4BXaOtjRmQrGmdBQkFcCd4leiF3dRn-Vw3C2FmerAzBm-9/pub
  30. https://docs.google.com/document/d/e/2PACX-1vQpEdoKoYo6uePO_ghrrpVyaaaYuhWML_2XxFj4CdzK6fJ56bvmR7o6T6Vr9ScQMoXwTv0WA_MqZEwl/pub
  31. https://docs.google.com/document/d/e/2PACX-1vQSkAsAPrlsVkn0a6-sowf5IL-SSKkq_L6GRd35Z-faYqZXRYUA3h5C8RuiWCWZkHKb2JotAVEJd6e4/pub
  32. https://docs.google.com/document/d/e/2PACX-1vQvG_ZgGQrA7FYDSO7KpjMrGPv-KUn42P3c8eD1oaBDoG4DOEG_lK9Z50CFQYQ95hyGfJ2sUJIHBOq1/pub
  33. https://docs.google.com/document/d/e/2PACX-1vQvzNo8PaS3S5iz0gb59uGXEYdraQC6UQNt5DTLn3vBWzkSzAFptYSFHT6Wsdw2OQVzw7OAtWOCAyig/pub
  34. https://docs.google.com/document/d/e/2PACX-1vQwin7bXd-T9M5lAI8W79raYyAZjCO2WCYfGFL9_jOKCkCg59UJhhdv4KRoUHf4lcovj7irPhmm-U13/pub
  35. https://docs.google.com/document/d/e/2PACX-1vR0qneVq4j4DBfusinlSdIctp0xffFoYgjEDZYnuQlAeCWhyipbxSVduNv19oO5MeEddfeSw8P7A9U_/pub
  36. https://docs.google.com/document/d/e/2PACX-1vR0XEKKL_pjbxPrWFnXSBa_5SrzaSsuz0rA-HhTNjU9mjrqbSpe0Xpdj2edlSrpJFCD30btPCtrHRRI/pub
  37. https://docs.google.com/document/d/e/2PACX-1vRBF2UhXfk0KRbrjbaUkUM8rhxGocLvAB-yfpABPv3i7iTWhT6M3JMN38xd5TaSIbSfpBmCWYoMirW2/pub
  38. https://docs.google.com/document/d/e/2PACX-1vRC6zp14NrlpHYpyK-WBqx9hQB4QoTx700UJ_s-pTM7HO1hvqg1zlRHapQWeJI5A4AqPTVq4DB-vZ8A/pub
  39. https://docs.google.com/document/d/e/2PACX-1vREQkXKLr8hHpYeBkI82yDabP4aAG8GYHOOZFgCPbSpwFrxNt2kPxMfIh7GB4IfXBnHEj2fb--kcQHr/pub
  40. https://docs.google.com/document/d/e/2PACX-1vRGE-pPksO5Qh5SYUDkY9CHVVJtZgBgJ_ke4Kv9Yx8dvSlvV2-19v13wtiBebjuCUqKE_rbUQvOhbT5/pub
  41. https://docs.google.com/document/d/e/2PACX-1vRQZzTokYhrZ0atAvTkvMjBKRKUDfUs2xbwiAg01ruvH4J4NBJyYodABUnJMCqwQb4kHbyIF0M0NP3u/pub
  42. https://docs.google.com/document/d/e/2PACX-1vRRMYPEqyuCVmywf9WXMeEOQ_Hd1EGgjq3SchZPKzHVCO1FCHQmbGSnLtUvs1Oz6ZB63jK6BI861v2b/pub
  43. https://docs.google.com/document/d/e/2PACX-1vRup-LNzkvsRye4fFrbTrCfeHazFDpfdIUA24xjMkWrd2rJ21DyUMiiS0uLCxKD7K4ULNtd6gm5A8fx/pub
  44. https://docs.google.com/document/d/e/2PACX-1vSbBjKuKT0PYCJyg802qnUbu-YMRU-DICPp9jrYrzs7spMCukVa_lVW7j-GYmG6j5CZK7kxx76wyxpb/pub
  45. https://docs.google.com/document/d/e/2PACX-1vSoRqRyj45G1sCdqZn49cJ8zJuiw2HvmlecY30nzA5wHnFj_sTKClwRi0Pcbm-A7Lh0_8RGLkh62h-w/pub
  46. https://docs.google.com/document/d/e/2PACX-1vSsL7wQuXd39m6d4U4C87z-CVVaLsACqABFjHseikQb0fq50kPYaPBzDulNdZ9OQeB0X4ABy9dc_XJE/pub
  47. https://docs.google.com/document/d/e/2PACX-1vSW1SrrfmHVJJWpBHQVOuxZ7_3EbB04ZeLqpNzbQ1mzPdsMVE84hdnmrMqIVQZv6v-egyhjXnTxRKx0/pub
  48. https://docs.google.com/document/d/e/2PACX-1vT4g2hEusOnqVNb_JFPlt7KaVDfXZUq1u45u-D9G8_9cQQeFzN3lEEJa4qkEMxk4kJDpf6soFeNHpRl/pub
  49. https://docs.google.com/document/d/e/2PACX-1vT5iGOsBOEBtMCYGlSWbssF5_k0oNWEo3mYedgslb-f2gYp9RPTxw6Ea9H-LR6JG_NLZiZUPqD6UtCD/pub
  50. https://docs.google.com/document/d/e/2PACX-1vT7fCmjPEPd-lESwxPH_P8jutZ5vbMoWjc0JzRYgnznUFRjyCRig5kYvfVcxNbYzXQMAcMJ6uWbUYeI/pub
  51. https://docs.google.com/document/d/e/2PACX-1vT8-GM2tO_xIthlHp_ABTfLtrI0_JJ70h9YLtK7AIvCEYstgVT70fpDIlk3eSfF8UuUDJsWdry1jjJi/pub
  52. https://docs.google.com/document/d/e/2PACX-1vTCwemExI8Wun8Owr_-8J6_9OMbRCb5A4qEwV7NpL0kFauv5kG2hUeY2VMtfE20N7yGAHM3LmYSEZfx/pub
  53. https://docs.google.com/document/d/e/2PACX-1vTeuoIoiutOLS-7xwlYjfCDiruQU1935mWBILfpPnbC-uUN1FqniFlpiEO6zgq-SbVhg-rdBedNqdk4/pub
  54. https://docs.google.com/document/d/e/2PACX-1vTgZip7wss3mTkGhAmm4CTxAAHjwR69vRcINYtHphUS9Ij_V90G_PnGftI34P__AEj3XpDrDd4tH_86/pub
  55. https://docs.google.com/document/d/e/2PACX-1vTRxyo0MIEfdl-HxdGOZoOrsz_eFY152ZYNg1qLf__0OLQPciCOM0Fzsyat77UUbWdOeVzAKK8zetRG/pub
  56. https://docs.google.com/document/d/e/2PACX-1vTVfQCo8JHjwwRco2PmMskEYdGogeEKdf5krbC807iHDvlNB63hVIvtEmHHwhiMssxv5VYwgMuvyz_9/pub
  57.  
  58. MALDOC DISTRIBUTION URLS
  59. http://adahomemodifications.com/fuss.php
  60. http://brasilk.com.br/clavichord.php
  61. http://brasilk.com.br/flagstone.php
  62. http://dev.springbreaklife.com/tour/content/021815_redneck_twerk_contest_D021815/incontinence.php
  63. http://gurshanlogistics.com/cell.php
  64. http://gurshanlogistics.com/perpetualness.php
  65. http://nicole-emer.de/potential.php
  66. https://cld.org.uk/illiquid.php
  67. https://clientes.gestionmx.net/adrenalin.php
  68. https://codesterio.com/consumption.php
  69. https://hinchcliff.net/sodomous.php
  70. https://iastoppersmantra.com/smoothness.php
  71. https://info.smabajiminasa.sch.id/aggrandizements.php
  72. https://lhagen.gc-webhosting.nl/inconclusive.php
  73. https://socialpromotion.store/compile.php
  74. https://tnk-moflad.com/urinalysis.php
  75. https://tosunotomotiv.com/modularity.php
  76. https://viveroscamila.cl/aromatic.php
  77. https://viveroscamila.cl/redlining.php
  78. https://www.upperkillaycc.org.uk/effortless.php
  79. https://www.upperkillaycc.org.uk/haze.php
  80. http://www.e-voks.dk/sternness.php
  81. http://www.korean.britishwebsite.co.uk/whiner.php
  82. http://xcx.yngw518.com/decompiling.php
  83.  
  84. adahomemodifications.com
  85. brasilk.com.br
  86. britishwebsite.co.uk
  87. cld.org.uk
  88. codesterio.com
  89. e-voks.dk
  90. gc-webhosting.nl
  91. gestionmx.net
  92. gurshanlogistics.com
  93. hinchcliff.net
  94. iastoppersmantra.com
  95. nicole-emer.de
  96. smabajiminasa.sch.id
  97. socialpromotion.store
  98. springbreaklife.com
  99. tnk-moflad.com
  100. tosunotomotiv.com
  101. upperkillaycc.org.uk
  102. viveroscamila.cl
  103. yngw518.com
  104.  
  105. HANCITOR MALDOC FILE HASHES
  106. 15a514bc4f62e69621db05c53795556a
  107. 1af72e23a6bc30e94301967c3e7ddcec
  108. 3a4e93f653c82aacf031fb2e01de5fdd
  109. 524b67bf31df7a419244b557c9cc1880
  110. 6b3a4cc1a7a043b03f07479d0d4277a7
  111. 6ba1d83193d10c81fc9b5da3012ad536
  112. 954f3c934d66f2b4fc9d7abc1bc9859b
  113. a5e5c6fb6d6841c76a4b56c03f8829e1
  114. a9935d640eb94a9bd2b39e5ea75f7ddf
  115. bc75340f261f64961382b578715701a0
  116. eb9c78470651236a57ace28437f16a5c
  117.  
  118. HANCITOR PAYLOAD FILE HASH
  119. edge.dll
  120. 8089b3d619192f3c2785265d69f1fa09
  121.  
  122. HANCITOR C2
  123. http://erisastand.com/8/forum.php
  124. http://trimpledtim.ru/8/forum.php
  125. http://balcatioplo.ru/8/forum.php
  126.  
  127. HANCITOR BUILD NUMBER
  128. &BUILD=1904_hvm
  129.  
  130. COBALT STRIKE STAGER FILE PAYLOAD URLS
  131. http://masaddrino.ru/1904.bin
  132. http://masaddrino.ru/190s4.bin
  133. http://masaddrino.ru/1904s.bin
  134.  
  135. COBALT STRIKE STAGER FILE HASHES
  136. 1904.bin
  137. cc7cbd182d4d51964a06fb19022f9393
  138.  
  139. 1904s.bin
  140. f3aa95ecf88591f8f74b2fa2b2014bb5
  141.  
  142. COBALT STRIKE BEACON
  143. http://82.117.252.78/zGi2
  144.  
  145. COBALT STRIKE C2
  146. http://82.117.252.78/load
Advertisement
Add Comment
Please, Sign In to add comment