ExecuteMalware

2021-07-06 Hancitor IOCs

Jul 6th, 2021
15,916
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.61 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=0607_qxwd0
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC PROXY DISTRIBUTION URLS
  27. http://feedproxy.google.com/~r/akgtot/~3/JBG3NcDQ-jE/sphinx.php
  28. http://feedproxy.google.com/~r/bpvrl/~3/L1-mu8j17io/detour.php
  29. http://feedproxy.google.com/~r/ckfgxig/~3/-fLudX5EIs4/invertor.php
  30. http://feedproxy.google.com/~r/cpizxgy/~3/1HE1NbHNq7A/palmistry.php
  31. http://feedproxy.google.com/~r/dormeqi/~3/1GYCuBEa_rU/inflammatory.php
  32. http://feedproxy.google.com/~r/dvhvrgpejq/~3/yJHdwZsuupo/cognizance.php
  33. http://feedproxy.google.com/~r/eyibvrmmeae/~3/yCm4BBw49oU/biochemical.php
  34. http://feedproxy.google.com/~r/fsgiqoehl/~3/BmekNNLZ6s8/sandy.php
  35. http://feedproxy.google.com/~r/fyarc/~3/F9hpBVqYr8Y/extort.php
  36. http://feedproxy.google.com/~r/hfozsby/~3/S_7iIz8f4G4/trolley.php
  37. http://feedproxy.google.com/~r/hhfgijfx/~3/VtvveFyEpTE/drench.php
  38. http://feedproxy.google.com/~r/hvkpeje/~3/E_jZP26mTvI/diction.php
  39. http://feedproxy.google.com/~r/hzcvgzre/~3/fwiZs3G9FJE/tubbiness.php
  40. http://feedproxy.google.com/~r/izalif/~3/N3pM4eAAQ2k/peaceably.php
  41. http://feedproxy.google.com/~r/khjkpgcysv/~3/hGtK6HPmL8U/wrathful.php
  42. http://feedproxy.google.com/~r/ksaankkbze/~3/t_GafwZvGAY/halo.php
  43. http://feedproxy.google.com/~r/lctuhe/~3/z_dZFLETTrU/abye.php
  44. http://feedproxy.google.com/~r/lewgc/~3/3fEoC5LdR4o/dour.php
  45. http://feedproxy.google.com/~r/ljccejij/~3/yVRSn0tU6RM/maim.php
  46. http://feedproxy.google.com/~r/ltrbtk/~3/8xNPK-mTOrA/refugee.php
  47. http://feedproxy.google.com/~r/mbludriihy/~3/8P6AfpR3t1I/dirt.php
  48. http://feedproxy.google.com/~r/mmkvlqzh/~3/kQ9is7Edr8s/smoothed.php
  49. http://feedproxy.google.com/~r/mprtvxwlq/~3/p0RKlbltAmw/garret.php
  50. http://feedproxy.google.com/~r/nhtgwnsb/~3/qmg23XQgCAM/populism.php
  51. http://feedproxy.google.com/~r/ozuim/~3/8ZnvBmKOZ1w/shed.php
  52. http://feedproxy.google.com/~r/payaey/~3/FVcF30V-Tmc/suit.php
  53. http://feedproxy.google.com/~r/pgxkj/~3/UwO3wgJKU6o/assorted.php
  54. http://feedproxy.google.com/~r/qowvyxb/~3/iezQJeoO2fA/mausoleum.php
  55. http://feedproxy.google.com/~r/qtqoftapvct/~3/5LalLw4O6HI/ridiculously.php
  56. http://feedproxy.google.com/~r/qugrztxnale/~3/KVWz_XsafSM/baron.php
  57. http://feedproxy.google.com/~r/sjmxqp/~3/r14ADW--pRA/chiefly.php
  58. http://feedproxy.google.com/~r/swumkhxrvs/~3/iezQJeoO2fA/mausoleum.php
  59. http://feedproxy.google.com/~r/tiarstrmlvx/~3/WjBZUdL3snA/concede.php
  60. http://feedproxy.google.com/~r/timsoijk/~3/dP1iTN_9Mcg/ratter.php
  61. http://feedproxy.google.com/~r/vytrgpamt/~3/JBG3NcDQ-jE/sphinx.php
  62. http://feedproxy.google.com/~r/wgrteifbafz/~3/WTBFILZEQVQ/serigraph.php
  63. http://feedproxy.google.com/~r/wrdxgk/~3/cyCrDCnJn8s/ornamental.php
  64. http://feedproxy.google.com/~r/wtnugfmd/~3/dhuf1HgEA9E/rearranged.php
  65. http://feedproxy.google.com/~r/wvbqpy/~3/vCSnNSDaPSc/genocide.php
  66. http://feedproxy.google.com/~r/wvswwxmigba/~3/cEQ5jAxt9vU/warped.php
  67. http://feedproxy.google.com/~r/wwhyfoo/~3/o3hFfKBDDc4/chair.php
  68. http://feedproxy.google.com/~r/wwlarxs/~3/h2M9fFM_Itc/wriggler.php
  69. http://feedproxy.google.com/~r/wxsrtgyd/~3/jdXMN6sNoKc/fatalities.php
  70. http://feedproxy.google.com/~r/wxujtw/~3/5LalLw4O6HI/ridiculously.php
  71. http://feedproxy.google.com/~r/xzpsdlt/~3/0zoXxC1wFyY/pursing.php
  72. http://feedproxy.google.com/~r/yknempiq/~3/yCm4BBw49oU/biochemical.php
  73. http://feedproxy.google.com/~r/znaiyaykz/~3/3egTwGNq0jM/infirmary.php
  74. http://feedproxy.google.com/~r/ztdrghxwy/~3/mKRlj4h9B0U/antipodal.php
  75.  
  76. MALDOC REDIRECT DOWNLOAD URLS
  77. http://24gramhealth.com/detour.php
  78. http://24gramhealth.com/genocide.php
  79. http://24gramhealth.com/populism.php
  80. http://an.nastena.lv/garret.php
  81. http://an.nastena.lv/inflammatory.php
  82. http://an.nastena.lv/shed.php
  83. http://destination.dgi.is/chiefly.php
  84. http://destination.dgi.is/invertor.php
  85. http://destination.dgi.is/ratter.php
  86. http://destination.dgi.is/ridiculously.php
  87. http://destination.dgi.is/suit.php
  88. http://farmranch.mx/wriggler.php
  89. http://grecozenobi.com.ar/ornamental.php
  90. http://grecozenobi.com.ar/sphinx.php
  91. http://greechip.net/biochemical.php
  92. http://gunsify.com/baron.php
  93. http://live.gssl.email/halo.php
  94. http://live.gssl.email/mausoleum.php
  95. http://mail.juvilis.ca/palmistry.php
  96. http://maoptions.xyz/abye.php
  97. http://mustangfastback.wireditsolutions.com.au/maim.php
  98. http://mustangfastback.wireditsolutions.com.au/pursing.php
  99. http://new.novapilates.com/chair.php
  100. http://nextclickcorp.net/smoothed.php
  101. http://omsteelgroup.in/dour.php
  102. http://omsteelgroup.in/rearranged.php
  103. http://seatranscorp.com/cognizance.php
  104. http://sofitra-hightech.com/drench.php
  105. http://sofitra-hightech.com/warped.php
  106. http://sportsrunouts.com/diction.php
  107. http://sportsrunouts.com/fatalities.php
  108. http://stock.moltechnologies.com/extort.php
  109. http://takeout-app.com/peaceably.php
  110. http://takeout-app.com/sandy.php
  111. http://turquoisecoaching.co.uk/concede.php
  112. http://turquoisecoaching.co.uk/dirt.php
  113. http://virfilms.in/assorted.php
  114. http://virfilms.in/serigraph.php
  115. http://virfilms.in/tubbiness.php
  116. http://vivo.com.pk/antipodal.php
  117. http://vivo.com.pk/wrathful.php
  118. https://file.tianshuyu.top/refugee.php
  119. https://www.adstudiophotography.com/infirmary.php
  120. https://www.adstudiophotography.com/trolley.php
  121.  
  122. 24gramhealth.com
  123. adstudiophotography.com
  124. an.nastena.lv
  125. destination.dgi.is
  126. farmranch.mx
  127. file.tianshuyu.top
  128. grecozenobi.com.ar
  129. greechip.net
  130. gunsify.com
  131. live.gssl.email
  132. mail.juvilis.ca
  133. maoptions.xyz
  134. mustangfastback.wireditsolutions.com.au
  135. new.novapilates.com
  136. nextclickcorp.net
  137. omsteelgroup.in
  138. seatranscorp.com
  139. sofitra-hightech.com
  140. sportsrunouts.com
  141. stock.moltechnologies.com
  142. takeout-app.com
  143. turquoisecoaching.co.uk
  144. virfilms.in
  145. vivo.com.pk
  146.  
  147. HANCITOR MALDOC FILE HASHES
  148. 025078292aee21fa56cb7f20ec6d4a62
  149. 0b61b7cac9776d9cd2e5380a659e541b
  150. 19ca475a43a95f2543750a46d4f09f4b
  151. 2b2770712a21624dea13832f9a8f695f
  152. b1a57b1a512c238391ae6638970e182f
  153. bc7c80f02dc87d01105355be3d3a0f22
  154. cf341c78541df3e6461625e58c22316f
  155. d14e2dc37f9d3f1913cfb5b1ddcb1159
  156. d5e25c333ed6b914038948d77996a4de
  157. fec1808861e804fbdff31ca922f5dbcc
  158.  
  159. HANCITOR PAYLOAD FILE HASH
  160. niberius.dll
  161. 90e51ee20c33ea576696ca59a524893e
  162.  
  163. HANCITOR C2
  164. http://hosouggs.com/8/forum.php
  165. http://mancause.ru/8/forum.php
  166. http://hievescits.ru/8/forum.php
  167.  
  168. FICKER STEALER DOWNLOAD URL
  169. http://kubantr0.ru/7gfdg5egds.exe
  170.  
  171. FICKER STEALER FILE HASH
  172. 7gfdg5egds.exe
  173. 270c3859591599642bd15167765246e3
  174.  
  175. FICKER C2
  176. http://pospvisis.com
  177.  
  178. COBALT STRIKE STAGER PAYLOAD URLS
  179. http://kubantr0.ru/0607.bin
  180. http://kubantr0.ru/0607s.bin
  181.  
  182. COBALT STRIKE STAGER FILE HASHES
  183. 0607.bin
  184. c7b8743c7c77067d6203263f104a8f14
  185.  
  186. 0607s.bin
  187. 1c89a0d567fb2b5d91f51fbe77c27016
  188.  
  189. COBALT STRIKE BEACON DOWNLOAD URLS
  190. http://158.51.96.24/QTnI
  191.  
  192. COBALT STRIKE BEACON FILE HASH
  193. QTnI
  194. 11f2b1c1309ca74cbf4873d5d90ed35c
  195.  
  196. COBALT STRIKE C2
  197. http://158.51.96.24/pixel.gif
  198.  
  199. ADDITIONAL COBALT STRIKE URLS FROM MEMORY STRINGS
  200. https://158.51.96.24/2cYn
  201. https://158.51.96.24/ga.js
  202.  
Advertisement
Add Comment
Please, Sign In to add comment