Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
- HANCITOR BUILD NUMBER
- BUILD=2806_ldfa1
- SUBJECTS OBSERVED
- You got invoice from DocuSign Electronic Service
- You got invoice from DocuSign Electronic Signature Service
- You got invoice from DocuSign Service
- You got invoice from DocuSign Signature Service
- You got notification from DocuSign Electronic Signature Service
- You got notification from DocuSign Signature Service
- You received invoice from DocuSign Electronic Service
- You received invoice from DocuSign Electronic Signature Service
- You received invoice from DocuSign Service
- You received invoice from DocuSign Signature Service
- You received notification from DocuSign Electronic Service
- You received notification from DocuSign Electronic Signature Service
- You received notification from DocuSign Service
- You received notification from DocuSign Signature Service
- SENDERS OBSERVED
- MALDOC PROXY DISTRIBUTION URLS
- http://feedproxy.google.com/~r/afubkyadw/~3/W8TDwP-aCsA/shadowboxing.php
- http://feedproxy.google.com/~r/ajtaluq/~3/BHas8Qaf2pw/liniment.php
- http://feedproxy.google.com/~r/bpbsdeoaexf/~3/jSgDuetsZbA/fineness.php
- http://feedproxy.google.com/~r/bumpro/~3/6Put3tH7alQ/smitten.php
- http://feedproxy.google.com/~r/cduwwzkg/~3/dF0DLhBadro/await.php
- http://feedproxy.google.com/~r/csiuor/~3/UmWE7aKqEa8/distemper.php
- http://feedproxy.google.com/~r/dzeywlnner/~3/42ThwIJW4p8/scantling.php
- http://feedproxy.google.com/~r/fbixnijnz/~3/FAWU0S23G2U/foundling.php
- http://feedproxy.google.com/~r/fdhkmwqsyv/~3/TTUf3hfqqV4/terminologist.php
- http://feedproxy.google.com/~r/flosuusnz/~3/LsLexMc3JBM/tacit.php
- http://feedproxy.google.com/~r/izoeo/~3/OO1Mhb0WCyU/women.php
- http://feedproxy.google.com/~r/jklzm/~3/OeJu1g3eTlY/sailfish.php
- http://feedproxy.google.com/~r/jtzifdls/~3/wRyBFahZdpc/respects.php
- http://feedproxy.google.com/~r/krxydhl/~3/HzYz3AAH2ts/colloid.php
- http://feedproxy.google.com/~r/laqqikm/~3/gpLNiUKyTNU/existent.php
- http://feedproxy.google.com/~r/lsnqp/~3/rL7_7aqzyyc/seisms.php
- http://feedproxy.google.com/~r/mkgchoa/~3/A5936nfsab0/serigraphy.php
- http://feedproxy.google.com/~r/mwzuzfosf/~3/jSgDuetsZbA/fineness.php
- http://feedproxy.google.com/~r/neyziwzs/~3/fKCpZlfZKlA/physiographic.php
- http://feedproxy.google.com/~r/pgvzndw/~3/MRQwELy7ev8/titanium.php
- http://feedproxy.google.com/~r/qgkeo/~3/XNVtFqP-Zus/blockmark.php
- http://feedproxy.google.com/~r/stwwuc/~3/paDwGMmON7Y/dropping.php
- http://feedproxy.google.com/~r/suunph/~3/OmtH9VFvy4w/seperatism.php
- http://feedproxy.google.com/~r/teeuq/~3/vBCdzLM-FmU/skittish.php
- http://feedproxy.google.com/~r/tiwtopbrjq/~3/WBgwPaVjygo/monk.php
- http://feedproxy.google.com/~r/tpcdf/~3/pgVIFxclWAg/phasic.php
- http://feedproxy.google.com/~r/ulpchz/~3/mxaYqayNLXk/trichotomy.php
- http://feedproxy.google.com/~r/vxpdjpngzkk/~3/d7Ujr1E9Pu8/warship.php
- http://feedproxy.google.com/~r/wfpjvnv/~3/AGIoaLi5K70/stratigraphic.php
- http://feedproxy.google.com/~r/wjwrkbwealt/~3/6Put3tH7alQ/smitten.php
- http://feedproxy.google.com/~r/wktwibdfdtx/~3/ioCq6SAXKvQ/geriatric.php
- http://feedproxy.google.com/~r/wtgcnccfbjx/~3/n4pM2AVidqc/oxides.php
- http://feedproxy.google.com/~r/xvyvb/~3/HzYz3AAH2ts/colloid.php
- http://feedproxy.google.com/~r/ybjtmhl/~3/n7G6502qxgU/wiper.php
- http://feedproxy.google.com/~r/zfwpgri/~3/7AqSTm_giDk/codify.php
- MALDOC REDIRECT DOWNLOAD URLS
- http://advansys.com.ar/liniment.php
- http://arboonksa.com/titanium.php
- http://arboonksa.com/trichotomy.php
- http://buddy-pad.com/existent.php
- http://callbizapp.com/geriatric.php
- http://callbizapp.com/warship.php
- http://dallaswebserv.com/distemper.php
- http://dallaswebserv.com/wiper.php
- http://destination.dgi.is/codify.php
- http://dinfotechs.com/monk.php
- http://facebook.commit.capitaluniversity.net/physiographic.php
- http://insolvenzthemen.de/shadowboxing.php
- http://insolvenzthemen.de/skittish.php
- http://insolvenzthemen.de/tacit.php
- http://jeanscolors.com/terminologist.php
- http://kafrawifood.com/phasic.php
- http://mingalarorchidfamily.com/seperatism.php
- http://rangsay.com/serigraphy.php
- http://storiafrica.com/colloid.php
- http://storiafrica.com/fineness.php
- http://storiafrica.com/respects.php
- http://sultanaexecutive.com/sailfish.php
- http://sultanaexecutive.com/seisms.php
- http://sultanaexecutive.com/stratigraphic.php
- http://sultanaexecutive.com/women.php
- http://thehaider.com/await.php
- https://carpet.awesometrips.net/blockmark.php
- https://carpet.awesometrips.net/dropping.php
- https://carpet.awesometrips.net/oxides.php
- https://carpet.awesometrips.net/smitten.php
- https://www.adstudiophotography.com/foundling.php
- https://www.adstudiophotography.com/scantling.php
- adstudiophotography.com
- advansys.com.ar
- arboonksa.com
- awesometrips.net
- buddy-pad.com
- callbizapp.com
- capitaluniversity.net
- dallaswebserv.com
- destination.dgi.is
- dinfotechs.com
- insolvenzthemen.de
- jeanscolors.com
- kafrawifood.com
- mingalarorchidfamily.com
- rangsay.com
- storiafrica.com
- sultanaexecutive.com
- thehaider.com
- HANCITOR MALDOC FILE HASHES
- 0ab4d245656e7919ba74ebda307945ce
- 213bb37c2d1c824f33a9c590f820bdb8
- 392fc3d980b07be74eb27eb133ac48ae
- 46c447f115f1e12890ce8e671674feab
- 5faf696b558d1c4e7f5ee43c32ee6f2b
- 644cae9eddc369ad967fda0669a6f53d
- 9356504a6a8d79d51aa95230673bf131
- 967799fa39f90847507ef1853f1724c2
- bb0246e7ac3697afcb4ce8e47d204756
- dd40635ba026133a8d16f68357ec8589
- HANCITOR PAYLOAD FILE HASH
- niberius.dll
- 76bbdd2beb9c8fbddce8ea9759c6656f
- HANCITOR C2
- http://duclowtionly.ru/8/forum.php
- http://raeonoran.com/8/forum.php
- http://unteladenad.ru/8/forum.php
- FICKER STEALER DOWNLOAD URL
- http://rar1tet.ru/7sdf43fs.exe
- FICKER STEALER FILE HASH
- 7sdf43fs.exe
- 270c3859591599642bd15167765246e3
- FICKER C2
- http://pospvisis.com
- COBALT STRIKE STAGER PAYLOAD URLS
- http://rar1tet.ru/3006.bin
- http://rar1tet.ru/3006s.bin
- COBALT STRIKE STAGER FILE HASHES
- 3006.bin
- 33033e4dbe92a9946d9ef2bc9e418572
- 3006s.bin
- d02f6490851abf56419b9e72621316d7
- COBALT STRIKE BEACON FILE HASH
- SyDL
- 7d0af120c4da85357de4156244641812
- COBALT STRIKE BEACON
- http://216.250.248.91/SyDL
- COBALT STRIKE C2
- http://216.250.248.91/cm
- ADDITIONAL COBALT STRIKE URLS FROM MEMORY STRINGS
- https://216.250.248.91/g.pixel
- https://216.250.248.91/WXbK
Advertisement
Add Comment
Please, Sign In to add comment