Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
- HANCITOR BUILD NUMBER
- BUILD=2306_vensip
- SUBJECTS OBSERVED
- You got invoice from DocuSign Electronic Service
- You got invoice from DocuSign Electronic Signature Service
- You got notification from DocuSign Electronic Service
- You got notification from DocuSign Electronic Signature Service
- You got notification from DocuSign Service
- You got notification from DocuSign Signature Service
- You received invoice from DocuSign Electronic Service
- You received invoice from DocuSign Service
- You received notification from DocuSign Electronic Service
- You received notification from DocuSign Electronic Signature Service
- You received notification from DocuSign Service
- You received notification from DocuSign Signature Service
- SENDERS OBSERVED
- MALDOC PROXY DISTRIBUTION URLS
- http://eedproxy.google.com/~r/esjmj/~3/toe8Vav67dc/promising.php
- http://feedproxy.google.com/~r/bmmylazf/~3/YZtAz1roMPQ/constitutor.php
- http://feedproxy.google.com/~r/brrombgl/~3/LwrpMPc27V8/unconquerable.php
- http://feedproxy.google.com/~r/bvrhrrjxlkv/~3/lzszzYqv_W8/introductory.php
- http://feedproxy.google.com/~r/bzzhe/~3/uJbn2THVAmQ/fraudulent.php
- http://feedproxy.google.com/~r/csjkczyef/~3/2JBqfR4GVn4/unnerved.php
- http://feedproxy.google.com/~r/dizevm/~3/GcyqBCf000o/marquee.php
- http://feedproxy.google.com/~r/dqvbzwyfd/~3/gShg8jHUEJs/rabidity.php
- http://feedproxy.google.com/~r/esjmj/~3/toe8Vav67dc/promising.php
- http://feedproxy.google.com/~r/fwodl/~3/nYBEeK6g-D0/far.php
- http://feedproxy.google.com/~r/goddxqv/~3/j7MoaSpR9Ro/convergent.php
- http://feedproxy.google.com/~r/gzgulpkqpcz/~3/FrciNoBvk6I/somber.php
- http://feedproxy.google.com/~r/herofpk/~3/7UlS7RvOJWw/scaling.php
- http://feedproxy.google.com/~r/hmiaofh/~3/kD_WZ_yis0o/technetium.php
- http://feedproxy.google.com/~r/mfghv/~3/Z7zsihO9zd4/materialized.php
- http://feedproxy.google.com/~r/mmxqvb/~3/eAD1l_PR2Ps/interconnection.php
- http://feedproxy.google.com/~r/ouokeakjm/~3/_JBSnWLz80k/undersized.php
- http://feedproxy.google.com/~r/pvxkr/~3/pfSWbiD6Ugo/ampersand.php
- http://feedproxy.google.com/~r/qrmdremcdr/~3/IZSr5GJqgJU/delegate.php
- http://feedproxy.google.com/~r/sqjaefewr/~3/k_ZysQmLeiY/appealing.php
- http://feedproxy.google.com/~r/tikaulg/~3/bSkQDRExaQU/untie.php
- http://feedproxy.google.com/~r/uiqrhlgofb/~3/2D5h8xmNoek/disconnect.php
- http://feedproxy.google.com/~r/vqqfhhlgrqm/~3/3ewAiMskqYs/sinoauricular.php
- http://feedproxy.google.com/~r/wlukoki/~3/rV6FR-k8NeU/lithography.php
- MALDOC REDIRECT DOWNLOAD URLS
- http://cicrwanda.rw/technetium.php
- http://old.mktgsandbox.com/rabidity.php
- http://pamenagreens.com/appealing.php
- http://pamenagreens.com/marquee.php
- http://rathodsoftware.in/ampersand.php
- http://rathodsoftware.in/sinoauricular.php
- http://the3rdday.space/interconnection.php
- http://the3rdday.space/somber.php
- https://www.basticityguide.com/disconnect.php
- basticityguide.com
- cicrwanda.rw
- mktgsandbox.com
- pamenagreens.com
- rathodsoftware.in
- the3rdday.space
- HANCITOR MALDOC FILE HASHES
- 7f573d8efa3e5d52047db2e9410d0cc3
- 824ec8ea6f6b9bdc11a005189fe6aa57
- 8f02f75bc16291c29bce444aa55a5192
- bdadfe780b876ec030d2ae6b16ada151
- ed03860313a3ee414b4d3f69c6d2ec77
- HANCITOR PAYLOAD FILE HASH
- kikus.dll
- 3f91042b6e704a8aa011fc2feea10e8d
- HANCITOR C2
- http://extilivelly.com/8/forum.php
- http://cludimetifte.ru/8/forum.php
- http://sakincesed.ru/8/forum.php
- FICKER STEALER DOWNLOAD URL
- http://rar1tet.ru/7jk89ksd.exe
- FICKER STEALER FILE HASH
- 7jk89ksd.exe
- 270c3859591599642bd15167765246e3
- FICKER C2
- http://pospvisis.com
- COBALT STRIKE STAGER PAYLOAD URLS
- http://rar1tet.ru/2206.bin
- http://rar1tet.ru/2206s.bin
- COBALT STRIKE STAGER FILE HASHES
- 2206.bin
- 9f6ce0d2896378d173db713033c6c955
- 2206s.bin
- 4dca76922be24b36a8060653f8862a00
- COBALT STRIKE BEACON FILE HASH
- KakE
- c174c905359035a04caf9391e50e14e7
- COBALT STRIKE BEACON
- http://45.136.113.163/KakE
- COBALT STRIKE C2
- http://170.39.214.167/pixel
- http://170.39.214.167/submit.php?id=139859348
Advertisement
Add Comment
Please, Sign In to add comment