ExecuteMalware

2021-07-01 Hancitor IOCs

Jul 1st, 2021
15,881
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.20 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2806_ldfa1
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Signature Service
  12. You got notification from DocuSign Signature Service
  13. You received invoice from DocuSign Electronic Service
  14. You received invoice from DocuSign Electronic Signature Service
  15. You received invoice from DocuSign Service
  16. You received invoice from DocuSign Signature Service
  17. You received notification from DocuSign Electronic Service
  18. You received notification from DocuSign Electronic Signature Service
  19. You received notification from DocuSign Service
  20. You received notification from DocuSign Signature Service
  21.  
  22. SENDERS OBSERVED
  23.  
  24. MALDOC PROXY DISTRIBUTION URLS
  25. http://feedproxy.google.com/~r/afubkyadw/~3/W8TDwP-aCsA/shadowboxing.php
  26. http://feedproxy.google.com/~r/ajtaluq/~3/BHas8Qaf2pw/liniment.php
  27. http://feedproxy.google.com/~r/bpbsdeoaexf/~3/jSgDuetsZbA/fineness.php
  28. http://feedproxy.google.com/~r/bumpro/~3/6Put3tH7alQ/smitten.php
  29. http://feedproxy.google.com/~r/cduwwzkg/~3/dF0DLhBadro/await.php
  30. http://feedproxy.google.com/~r/csiuor/~3/UmWE7aKqEa8/distemper.php
  31. http://feedproxy.google.com/~r/dzeywlnner/~3/42ThwIJW4p8/scantling.php
  32. http://feedproxy.google.com/~r/fbixnijnz/~3/FAWU0S23G2U/foundling.php
  33. http://feedproxy.google.com/~r/fdhkmwqsyv/~3/TTUf3hfqqV4/terminologist.php
  34. http://feedproxy.google.com/~r/flosuusnz/~3/LsLexMc3JBM/tacit.php
  35. http://feedproxy.google.com/~r/izoeo/~3/OO1Mhb0WCyU/women.php
  36. http://feedproxy.google.com/~r/jklzm/~3/OeJu1g3eTlY/sailfish.php
  37. http://feedproxy.google.com/~r/jtzifdls/~3/wRyBFahZdpc/respects.php
  38. http://feedproxy.google.com/~r/krxydhl/~3/HzYz3AAH2ts/colloid.php
  39. http://feedproxy.google.com/~r/laqqikm/~3/gpLNiUKyTNU/existent.php
  40. http://feedproxy.google.com/~r/lsnqp/~3/rL7_7aqzyyc/seisms.php
  41. http://feedproxy.google.com/~r/mkgchoa/~3/A5936nfsab0/serigraphy.php
  42. http://feedproxy.google.com/~r/mwzuzfosf/~3/jSgDuetsZbA/fineness.php
  43. http://feedproxy.google.com/~r/neyziwzs/~3/fKCpZlfZKlA/physiographic.php
  44. http://feedproxy.google.com/~r/pgvzndw/~3/MRQwELy7ev8/titanium.php
  45. http://feedproxy.google.com/~r/qgkeo/~3/XNVtFqP-Zus/blockmark.php
  46. http://feedproxy.google.com/~r/stwwuc/~3/paDwGMmON7Y/dropping.php
  47. http://feedproxy.google.com/~r/suunph/~3/OmtH9VFvy4w/seperatism.php
  48. http://feedproxy.google.com/~r/teeuq/~3/vBCdzLM-FmU/skittish.php
  49. http://feedproxy.google.com/~r/tiwtopbrjq/~3/WBgwPaVjygo/monk.php
  50. http://feedproxy.google.com/~r/tpcdf/~3/pgVIFxclWAg/phasic.php
  51. http://feedproxy.google.com/~r/ulpchz/~3/mxaYqayNLXk/trichotomy.php
  52. http://feedproxy.google.com/~r/vxpdjpngzkk/~3/d7Ujr1E9Pu8/warship.php
  53. http://feedproxy.google.com/~r/wfpjvnv/~3/AGIoaLi5K70/stratigraphic.php
  54. http://feedproxy.google.com/~r/wjwrkbwealt/~3/6Put3tH7alQ/smitten.php
  55. http://feedproxy.google.com/~r/wktwibdfdtx/~3/ioCq6SAXKvQ/geriatric.php
  56. http://feedproxy.google.com/~r/wtgcnccfbjx/~3/n4pM2AVidqc/oxides.php
  57. http://feedproxy.google.com/~r/xvyvb/~3/HzYz3AAH2ts/colloid.php
  58. http://feedproxy.google.com/~r/ybjtmhl/~3/n7G6502qxgU/wiper.php
  59. http://feedproxy.google.com/~r/zfwpgri/~3/7AqSTm_giDk/codify.php
  60.  
  61. MALDOC REDIRECT DOWNLOAD URLS
  62. http://advansys.com.ar/liniment.php
  63. http://arboonksa.com/titanium.php
  64. http://arboonksa.com/trichotomy.php
  65. http://buddy-pad.com/existent.php
  66. http://callbizapp.com/geriatric.php
  67. http://callbizapp.com/warship.php
  68. http://dallaswebserv.com/distemper.php
  69. http://dallaswebserv.com/wiper.php
  70. http://destination.dgi.is/codify.php
  71. http://dinfotechs.com/monk.php
  72. http://facebook.commit.capitaluniversity.net/physiographic.php
  73. http://insolvenzthemen.de/shadowboxing.php
  74. http://insolvenzthemen.de/skittish.php
  75. http://insolvenzthemen.de/tacit.php
  76. http://jeanscolors.com/terminologist.php
  77. http://kafrawifood.com/phasic.php
  78. http://mingalarorchidfamily.com/seperatism.php
  79. http://rangsay.com/serigraphy.php
  80. http://storiafrica.com/colloid.php
  81. http://storiafrica.com/fineness.php
  82. http://storiafrica.com/respects.php
  83. http://sultanaexecutive.com/sailfish.php
  84. http://sultanaexecutive.com/seisms.php
  85. http://sultanaexecutive.com/stratigraphic.php
  86. http://sultanaexecutive.com/women.php
  87. http://thehaider.com/await.php
  88. https://carpet.awesometrips.net/blockmark.php
  89. https://carpet.awesometrips.net/dropping.php
  90. https://carpet.awesometrips.net/oxides.php
  91. https://carpet.awesometrips.net/smitten.php
  92. https://www.adstudiophotography.com/foundling.php
  93. https://www.adstudiophotography.com/scantling.php
  94.  
  95. adstudiophotography.com
  96. advansys.com.ar
  97. arboonksa.com
  98. awesometrips.net
  99. buddy-pad.com
  100. callbizapp.com
  101. capitaluniversity.net
  102. dallaswebserv.com
  103. destination.dgi.is
  104. dinfotechs.com
  105. insolvenzthemen.de
  106. jeanscolors.com
  107. kafrawifood.com
  108. mingalarorchidfamily.com
  109. rangsay.com
  110. storiafrica.com
  111. sultanaexecutive.com
  112. thehaider.com
  113.  
  114. HANCITOR MALDOC FILE HASHES
  115. 0ab4d245656e7919ba74ebda307945ce
  116. 213bb37c2d1c824f33a9c590f820bdb8
  117. 392fc3d980b07be74eb27eb133ac48ae
  118. 46c447f115f1e12890ce8e671674feab
  119. 5faf696b558d1c4e7f5ee43c32ee6f2b
  120. 644cae9eddc369ad967fda0669a6f53d
  121. 9356504a6a8d79d51aa95230673bf131
  122. 967799fa39f90847507ef1853f1724c2
  123. bb0246e7ac3697afcb4ce8e47d204756
  124. dd40635ba026133a8d16f68357ec8589
  125.  
  126. HANCITOR PAYLOAD FILE HASH
  127. niberius.dll
  128. 76bbdd2beb9c8fbddce8ea9759c6656f
  129.  
  130. HANCITOR C2
  131. http://duclowtionly.ru/8/forum.php
  132. http://raeonoran.com/8/forum.php
  133. http://unteladenad.ru/8/forum.php
  134.  
  135. FICKER STEALER DOWNLOAD URL
  136. http://rar1tet.ru/7sdf43fs.exe
  137.  
  138. FICKER STEALER FILE HASH
  139. 7sdf43fs.exe
  140. 270c3859591599642bd15167765246e3
  141.  
  142. FICKER C2
  143. http://pospvisis.com
  144.  
  145. COBALT STRIKE STAGER PAYLOAD URLS
  146. http://rar1tet.ru/3006.bin
  147. http://rar1tet.ru/3006s.bin
  148.  
  149. COBALT STRIKE STAGER FILE HASHES
  150. 3006.bin
  151. 33033e4dbe92a9946d9ef2bc9e418572
  152.  
  153. 3006s.bin
  154. d02f6490851abf56419b9e72621316d7
  155.  
  156. COBALT STRIKE BEACON FILE HASH
  157. SyDL
  158. 7d0af120c4da85357de4156244641812
  159.  
  160. COBALT STRIKE BEACON
  161. http://216.250.248.91/SyDL
  162.  
  163. COBALT STRIKE C2
  164. http://216.250.248.91/cm
  165.  
  166. ADDITIONAL COBALT STRIKE URLS FROM MEMORY STRINGS
  167. https://216.250.248.91/g.pixel
  168. https://216.250.248.91/WXbK
Advertisement
Add Comment
Please, Sign In to add comment