ExecuteMalware

2021-03-18 Hancitor IOCs

Mar 18th, 2021 (edited)
5,370
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.78 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Service
  6. You got notification from DocuSign Electronic Service
  7. You got notification from DocuSign Electronic Signature Service
  8. You got notification from DocuSign Service
  9. You got notification from DocuSign Signature Service
  10. You received invoice from DocuSign Electronic Service
  11. You received invoice from DocuSign Electronic Signature Service
  12. You received invoice from DocuSign Service
  13. You received invoice from DocuSign Signature Service
  14. You received notification from DocuSign Electronic Service
  15. You received notification from DocuSign Electronic Signature Service
  16. You received notification from DocuSign Service
  17. You received notification from DocuSign Signature Service
  18.  
  19. SENDERS OBSERVED
  20.  
  21. MALDOC REDIRECT URLS
  22. https://www.google.com/url?q=http://alwayscomply.com/sites/default/modules/cck/translations/help/de/dip.php&source=gmail&ust=1616148253953000&usg=AFQjCNG91xuWh7Lq9xWZjbVKfeaODM47ZQ
  23. https://www.google.com/url?q=http://alwayscomply.com/sites/default/modules/cck/translations/help/de/impinge.php&source=gmail&ust=1616148253953000&usg=AFQjCNGd4y2Wcog2N19amMynsC_9AKM0Qg
  24. https://www.google.com/url?q=http://archive-admin.museubandasfilarmonicas.pt/assets/plugins/jquery-file-upload/server/php/files/austria.php&source=gmail&ust=1616148253954000&usg=%0D%0AAFQjCNHB_VH8sITckq8j_an_QD0H7bFMFQ
  25. https://www.google.com/url?q=http://archive-admin.museubandasfilarmonicas.pt/assets/plugins/jquery-file-upload/server/php/files/austria.php&source=gmail&ust=1616148253954000&usg=AFQjCNHB_VH8sITckq8j_an_QD0H7bFMFQ
  26. https://www.google.com/url?q=http://tao.arnoldinum.cloud/qtiItemPci/views/js/pciCreator/paten.php&source=gmail&ust=1616148253953000&usg=AFQjCNG3BmLzQyaMvZQyALCmO2n9MN4v3g
  27. https://www.google.com/url?q=http://tao.arnoldinum.cloud/qtiItemPci/views/js/pciCreator/trackman.php&source=gmail&ust=1616148253954000&usg=AFQjCNGI0rHP-w2onvzXvv_YC1KQe8NR6A
  28. https://www.google.com/url?q=https://alaseeldates.com/predispose.php&source=gmail&ust=1616148253954000&usg=AFQjCNHhru9FX4ASRSMGZKl1hn-x276YTA
  29. https://www.google.com/url?q=https://alaseeldates.com/snoozer.php&source=gmail&ust=1616148253953000&usg=AFQjCNHcfcedHHOyhqZamM-UV4slpRki5g
  30. https://www.google.com/url?q=https://aprilstudios.in/appropriate.php&source=gmail&ust=1616148253954000&usg=AFQjCNF-SRFZeIucjKC74M8ANtMaU8z3Hw
  31. https://www.google.com/url?q=https://aprilstudios.in/oz.php&source=gmail&ust=1616148253953000&usg=AFQjCNEZSwhqIHCN3Q2tbb-pQjseTnqTOQ
  32. https://www.google.com/url?q=https://aprilstudios.in/transverter.php&source=gmail&ust=1616148253954000&usg=AFQjCNFjlYKzOuoW2OnGXSwNThjqEXhx-g
  33. https://www.google.com/url?q=https://chamkoon.com/secund.php&source=gmail&ust=1616148253954000&usg=AFQjCNE7FNF5pQjCAW8JVDK9bmP0v5-vOw
  34. https://www.google.com/url?q=https://chamkoon.com/wrongness.php&source=gmail&ust=1616148253954000&usg=AFQjCNGDINAExVrk6errRs7HysLxHq5enA
  35. https://www.google.com/url?q=https://cluebazar.com/upstairs.php&source=gmail&ust=1616148253954000&usg=AFQjCNEBJLi_vsN1IZLzqjISwLJd4QCycw
  36. https://www.google.com/url?q=https://emiratesminning.com/refers.php&source=gmail&ust=1616148253952000&usg=AFQjCNGwmq4JG0a5nHvtM-DsfyT6g8WZRQ
  37. https://www.google.com/url?q=https://livenetworks.com.br/sakhalin.php&source=gmail&ust=1616148253953000&usg=AFQjCNGWyvivCM6mNTntohyPUmMp-UC2DQ
  38. https://www.google.com/url?q=https://locequipamentosbh.com.br/dissenting.php&source=gmail&ust=1616148253953000&usg=AFQjCNFAfNrwGvOqamAovRPSNCciZ1CLXg
  39. https://www.google.com/url?q=https://locequipamentosbh.com.br/dowager.php&source=gmail&ust=1616148253954000&usg=AFQjCNHgppXUdFMfg10tIzapFl5VAGyGRw
  40. https://www.google.com/url?q=https://locequipamentosbh.com.br/theomorphic.php&source=gmail&ust=1616148253954000&usg=AFQjCNGbJM1e4y2LlqKFyp4yj5EnC4CyfQ
  41. https://www.google.com/url?q=https://m7a.rgstage.com/brazier.php&source=gmail&ust=1616148253953000&usg=AFQjCNGdIpVlW0g5550PUTVUk7FeaInZCQ
  42. https://www.google.com/url?q=https://m7a.rgstage.com/monologue.php&source=gmail&ust=1616148253953000&usg=AFQjCNGb7yJpEnbiu-f4lpeQtBv0a6lLOw
  43. https://www.google.com/url?q=https://mail.daunhotmiendong.vn/controvertible.php&source=gmail&ust=1616148253954000&usg=AFQjCNGgyf7Tf7u9dTtvttkKCvgBTpg_zw
  44. https://www.google.com/url?q=https://mail.daunhotmiendong.vn/pusillanimous.php&source=gmail&ust=1616148253954000&usg=AFQjCNE3qPBnoC1pjGi6JlYCdqi98zm3kw
  45. https://www.google.com/url?q=https://orsan.gruporhynous.com/speed.php&source=gmail&ust=1616148253954000&usg=AFQjCNGaQvSL_y_uSRgnP3FcvXEJ-zSEmw
  46. https://www.google.com/url?q=https://webworks.nepila.com/crazed.php&source=gmail&ust=1616148253954000&usg=AFQjCNGGuc0hcxNbunmm4YHXQXwIIQ8DYA
  47. https://www.google.com/url?q=https://webworks.nepila.com/defector.php&source=gmail&ust=1616148253954000&usg=AFQjCNFYvfyuwM9fHk8UacywoyeTz6n1aA
  48.  
  49. MALDOC DISTRIBUTION URLS
  50. http://alwayscomply.com/sites/default/modules/cck/translations/help/de/dip.php
  51. http://alwayscomply.com/sites/default/modules/cck/translations/help/de/impinge.php
  52. http://archive-admin.museubandasfilarmonicas.pt/assets/plugins/jquery-file-upload/server/php/files/austria.php
  53. http://tao.arnoldinum.cloud/qtiItemPci/views/js/pciCreator/paten.php
  54. http://tao.arnoldinum.cloud/qtiItemPci/views/js/pciCreator/trackman.php
  55. https://alaseeldates.com/predispose.php
  56. https://alaseeldates.com/snoozer.php
  57. https://aprilstudios.in/appropriate.php
  58. https://aprilstudios.in/oz.php
  59. https://aprilstudios.in/transverter.php
  60. https://chamkoon.com/secund.php
  61. https://chamkoon.com/wrongness.php
  62. https://cluebazar.com/upstairs.php
  63. https://emiratesminning.com/refers.php
  64. https://livenetworks.com.br/sakhalin.php
  65. https://locequipamentosbh.com.br/dissenting.php
  66. https://locequipamentosbh.com.br/dowager.php
  67. https://locequipamentosbh.com.br/theomorphic.php
  68. https://m7a.rgstage.com/brazier.php
  69. https://m7a.rgstage.com/monologue.php
  70. https://mail.daunhotmiendong.vn/controvertible.php
  71. https://mail.daunhotmiendong.vn/pusillanimous.php
  72. https://orsan.gruporhynous.com/speed.php
  73. https://webworks.nepila.com/crazed.php
  74. https://webworks.nepila.com/defector.php
  75.  
  76. alaseeldates.com
  77. alwayscomply.com
  78. aprilstudios.in
  79. arnoldinum.cloud
  80. chamkoon.com
  81. cluebazar.com
  82. daunhotmiendong.vn
  83. emiratesminning.com
  84. gruporhynous.com
  85. livenetworks.com.br
  86. locequipamentosbh.com.br
  87. museubandasfilarmonicas.pt
  88. nepila.com
  89. rgstage.com
  90.  
  91. HANCITOR MALDOC FILE HASHES
  92. 0ddee5b7da65f3a801677a9187c92d35
  93. 30e8467c27864508ee01fa82f719849c
  94. 504afcedfccc2caf7e2bd9a440bbe566
  95. 534350c5741aa2175ca54f219ab7d905
  96. 69022fe73ea471e0a9e0af364a023cc2
  97. 709a14419d84ac5e0d8a95071008cce1
  98. 7fee47f618c0c7f18488ca357f3b26df
  99. 9bb98f4388cb39e11c17e825ffca2b84
  100. b17e33adf9f089bafe33c65c5f446287
  101. c355368d0f5ff410851ab8900da7098c
  102. df5bc23f39f5bc0926cdbed514712ed6
  103.  
  104. HANCITOR PAYLOAD FILE HASH
  105. Static.dll
  106. be81b6f1ce7a7673c1c549064de73430
  107.  
  108. HANCITOR C2
  109. http://froursmonesed.com/8/forum.php
  110. http://abouniteta.ru/8/forum.php
  111.  
  112. FICKER STEALER PAYLOAD URLS
  113. http://pirijinko.ru/6jkiuwf43.exe
  114.  
  115. FICKER STEALER FILE HASH
  116. 6jkiuwf43.exe
  117. 77be0dd6570301acac3634801676b5d7
  118.  
  119. FICKER STEALER C2
  120. http://sweyblidian.com
  121.  
  122. COBALT STRIKE FILE HASHES
  123. 1703.bin
  124. c9a34a84b8be1d3b4f84fc50bd1ac80a
  125.  
  126. 1703s.bin
  127. 339db7ec6f43de6df9109f13b17842b6
  128.  
  129. I also found these on the same domain
  130. 1102.bin
  131. 75dd171de48fb65c9ff07e937b473ced
  132.  
  133. 1102s.bin
  134. 68552585411cf40c9c7f5cda18840bd7
  135.  
Add Comment
Please, Sign In to add comment