ExecuteMalware

2021-06-23 Hancitor IOCs

Jun 23rd, 2021
15,459
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.63 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2306_vensip
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got notification from DocuSign Electronic Service
  10. You got notification from DocuSign Electronic Signature Service
  11. You got notification from DocuSign Service
  12. You got notification from DocuSign Signature Service
  13. You received invoice from DocuSign Electronic Service
  14. You received invoice from DocuSign Service
  15. You received notification from DocuSign Electronic Service
  16. You received notification from DocuSign Electronic Signature Service
  17. You received notification from DocuSign Service
  18. You received notification from DocuSign Signature Service
  19.  
  20. SENDERS OBSERVED
  21.  
  22. MALDOC PROXY DISTRIBUTION URLS
  23. http://eedproxy.google.com/~r/esjmj/~3/toe8Vav67dc/promising.php
  24. http://feedproxy.google.com/~r/bmmylazf/~3/YZtAz1roMPQ/constitutor.php
  25. http://feedproxy.google.com/~r/brrombgl/~3/LwrpMPc27V8/unconquerable.php
  26. http://feedproxy.google.com/~r/bvrhrrjxlkv/~3/lzszzYqv_W8/introductory.php
  27. http://feedproxy.google.com/~r/bzzhe/~3/uJbn2THVAmQ/fraudulent.php
  28. http://feedproxy.google.com/~r/csjkczyef/~3/2JBqfR4GVn4/unnerved.php
  29. http://feedproxy.google.com/~r/dizevm/~3/GcyqBCf000o/marquee.php
  30. http://feedproxy.google.com/~r/dqvbzwyfd/~3/gShg8jHUEJs/rabidity.php
  31. http://feedproxy.google.com/~r/esjmj/~3/toe8Vav67dc/promising.php
  32. http://feedproxy.google.com/~r/fwodl/~3/nYBEeK6g-D0/far.php
  33. http://feedproxy.google.com/~r/goddxqv/~3/j7MoaSpR9Ro/convergent.php
  34. http://feedproxy.google.com/~r/gzgulpkqpcz/~3/FrciNoBvk6I/somber.php
  35. http://feedproxy.google.com/~r/herofpk/~3/7UlS7RvOJWw/scaling.php
  36. http://feedproxy.google.com/~r/hmiaofh/~3/kD_WZ_yis0o/technetium.php
  37. http://feedproxy.google.com/~r/mfghv/~3/Z7zsihO9zd4/materialized.php
  38. http://feedproxy.google.com/~r/mmxqvb/~3/eAD1l_PR2Ps/interconnection.php
  39. http://feedproxy.google.com/~r/ouokeakjm/~3/_JBSnWLz80k/undersized.php
  40. http://feedproxy.google.com/~r/pvxkr/~3/pfSWbiD6Ugo/ampersand.php
  41. http://feedproxy.google.com/~r/qrmdremcdr/~3/IZSr5GJqgJU/delegate.php
  42. http://feedproxy.google.com/~r/sqjaefewr/~3/k_ZysQmLeiY/appealing.php
  43. http://feedproxy.google.com/~r/tikaulg/~3/bSkQDRExaQU/untie.php
  44. http://feedproxy.google.com/~r/uiqrhlgofb/~3/2D5h8xmNoek/disconnect.php
  45. http://feedproxy.google.com/~r/vqqfhhlgrqm/~3/3ewAiMskqYs/sinoauricular.php
  46. http://feedproxy.google.com/~r/wlukoki/~3/rV6FR-k8NeU/lithography.php
  47.  
  48. MALDOC REDIRECT DOWNLOAD URLS
  49. http://cicrwanda.rw/technetium.php
  50. http://old.mktgsandbox.com/rabidity.php
  51. http://pamenagreens.com/appealing.php
  52. http://pamenagreens.com/marquee.php
  53. http://rathodsoftware.in/ampersand.php
  54. http://rathodsoftware.in/sinoauricular.php
  55. http://the3rdday.space/interconnection.php
  56. http://the3rdday.space/somber.php
  57. https://www.basticityguide.com/disconnect.php
  58.  
  59. basticityguide.com
  60. cicrwanda.rw
  61. mktgsandbox.com
  62. pamenagreens.com
  63. rathodsoftware.in
  64. the3rdday.space
  65.  
  66. HANCITOR MALDOC FILE HASHES
  67. 7f573d8efa3e5d52047db2e9410d0cc3
  68. 824ec8ea6f6b9bdc11a005189fe6aa57
  69. 8f02f75bc16291c29bce444aa55a5192
  70. bdadfe780b876ec030d2ae6b16ada151
  71. ed03860313a3ee414b4d3f69c6d2ec77
  72.  
  73. HANCITOR PAYLOAD FILE HASH
  74. kikus.dll
  75. 3f91042b6e704a8aa011fc2feea10e8d
  76.  
  77. HANCITOR C2
  78. http://extilivelly.com/8/forum.php
  79. http://cludimetifte.ru/8/forum.php
  80. http://sakincesed.ru/8/forum.php
  81.  
  82. FICKER STEALER DOWNLOAD URL
  83. http://rar1tet.ru/7jk89ksd.exe
  84.  
  85. FICKER STEALER FILE HASH
  86. 7jk89ksd.exe
  87. 270c3859591599642bd15167765246e3
  88.  
  89. FICKER C2
  90. http://pospvisis.com
  91.  
  92. COBALT STRIKE STAGER PAYLOAD URLS
  93. http://rar1tet.ru/2206.bin
  94. http://rar1tet.ru/2206s.bin
  95.  
  96. COBALT STRIKE STAGER FILE HASHES
  97. 2206.bin
  98. 9f6ce0d2896378d173db713033c6c955
  99.  
  100. 2206s.bin
  101. 4dca76922be24b36a8060653f8862a00
  102.  
  103. COBALT STRIKE BEACON FILE HASH
  104. KakE
  105. c174c905359035a04caf9391e50e14e7
  106.  
  107. COBALT STRIKE BEACON
  108. http://45.136.113.163/KakE
  109.  
  110. COBALT STRIKE C2
  111. http://170.39.214.167/pixel
  112.  
  113. http://170.39.214.167/submit.php?id=139859348
Advertisement
Add Comment
Please, Sign In to add comment