ExecuteMalware

2021-03-03 Hancitor IOCs

Mar 3rd, 2021
4,593
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.19 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / COBALT STRIKE
  2.  
  3. HANCITOR BUILD
  4. BUILD=0303_trew30
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Service
  8. You got notification from DocuSign Electronic Service
  9. You got notification from DocuSign Service
  10. You received invoice from DocuSign Electronic Service
  11. You received notification from DocuSign Electronic Service
  12. You received notification from DocuSign Electronic Signature Service
  13. You received notification from DocuSign Signature Service
  14.  
  15. SENDERS OBSERVED
  16.  
  17. MALDOC LANDING PAGE URLS
  18. https://docs.google.com/document/d/e/2PACX-1vQk1Da72CGqMZMEQG6oXHSE3GPwcfO7p9ipdAFW6DwN1iOx5qhofWn-dtcAJEOHXYhG0X2qOjeEG9K_/pub
  19. https://docs.google.com/document/d/e/2PACX-1vQtmhc3dUYeRlP3Qa5f_W3pYqsLpm8GhMzKWXwtBrev1va6RwJoZa46B4H2eVtGkajMJ3_RqKMX5MpD/pub
  20. https://docs.google.com/document/d/e/2PACX-1vRIhEId8jUJXA0_0enaj-8glZbnQmE7CwK2_FcKwCFhOVZr9hAPTqX7xJO-gr6NcohKe34ick1DzlIV/pub
  21. https://docs.google.com/document/d/e/2PACX-1vRzObl6qf2Hjg43G9JDvah-BAW4aQ8rJFA53yTqIUHcmtpsTNtkiH07c10wI2Bxcghn75PtWBN8WmFU/pub
  22. https://docs.google.com/document/d/e/2PACX-1vSFFEX1QJHB2_opTC1-USc6NqPQvE01ZNa_lxUhGEOpxaD4x4RgF0dmDEgZ-yPxV5AAYY-SMMPkn8l2/pub
  23. https://docs.google.com/document/d/e/2PACX-1vSgt1N3W12ZP6TzDf4edMTib_0dOhJOgY0M3SBv1L2qLzZsBxkSaqRm869lmhxSrFTVZ_5Gj9d8_z8P/pub
  24. https://docs.google.com/document/d/e/2PACX-1vSj_YIia7nLWcShxEbD4KFvcuDKwkl9GZvEi9HAnVgPklkr4nUmT5VD4MDiFL2K3sMLJh2ukEpJER-T/pub
  25. https://docs.google.com/document/d/e/2PACX-1vSnfQTOjJ3LVldXHz6l8HbjyC8P0P7VDeSl_ol5HDdTCtGHFIPlchy58D17JBBdN3hiIj_jv7rIrYjT/pub
  26. https://docs.google.com/document/d/e/2PACX-1vTSYQe4Zi3QiKrYekM9RXdOYc4_X05PcGwsgFhpVbiwMPNvK92Phfki96ou9il7QrhOJy0VzwNcMbUi/pub
  27. https://docs.google.com/document/d/e/2PACX-1vTwIT1Y2B-FBRWxr_eyddj1pwOymlGd6BxwQl7OQ3SgTuKYXSAQO8q26wGDz96ZzjH_2vf4iPqAJlE9/pub
  28.  
  29. MALDOC DISTRIBUTION URLS
  30. https://cluebazar.com/popularization.php
  31. https://mail.daunhotmiendong.vn/craze.php
  32. https://crm.basilrealty.in/uxoriousness.php
  33.  
  34. basilrealty.in
  35. cluebazar.com
  36. daunhotmiendong.vn
  37.  
  38. HANCITOR MALDOC FILE HASHES
  39. 0303_11021160093261.doc
  40. 8d4d32d950ff5ea791848fefae0c35bb
  41.  
  42. 0303_9589344049041.doc
  43. 1523d0044c726a057844b09925362ade
  44.  
  45. HANCITOR PAYLOAD FILE HASH
  46. Static.dll
  47. 3f6a65b1cdd3a80bcf48d0df223070ed
  48.  
  49. HANCITOR C2
  50. http://mainctional.com/8/forum.php
  51. http://disrulaytin.ru/8/forum.php
  52. http://puldefletat.ru/8/forum.php
  53.  
  54. FICKER STEALER PAYLOAD URLS
  55. http://nvgeeforsegt.ru/6jhfa478.exe
  56.  
  57. FICKER STEALER FILE HASH
  58. 6jhfa478.exe
  59. 77be0dd6570301acac3634801676b5d7
  60.  
  61. FICKER STEALER C2
  62. http://sweyblidian.com
  63.  
  64. COBALT STRIKE PAYLOAD URLS
  65. http://nvgeeforsegt.ru/0303.bin
  66. http://nvgeeforsegt.ru/0303s.bin
  67.  
  68. COBALT STRIKE FILE HASHES
  69. 0303s.bin
  70. a46e64f8667a0c1dc2810c92c8453f91
  71.  
  72. 0303.bin
  73. d7c42ce4f084c429185b994bbdd2fb68
  74.  
  75. COBALT STRIKE TRAFFIC
  76. http://51.81.142.72/uNPI
  77. http://51.81.142.72/push
  78. http://51.81.142.72/submit.php?id=2063695750
  79.  
Advertisement
Add Comment
Please, Sign In to add comment