Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2020-10-27 (TUESDAY) - HANCITOR WITH COBALT STRIKE AND UNIDENTIFIED INFO-STEALER
- EMAIL INFO:
- - Received from: acuraaccelerationproblems.com ([62.232.211.230])
- - Received from: acuraaccelerationproblems.com ([123.59.173.195])
- - Received from: acuraaccelerationproblems.com ([166.156.27.93])
- - Received from: acuraaccelerationproblems.com ([182.237.124.38])
- - Received from: acuraaccelerationproblems.com ([212.5.141.134])
- - From: "DocuSign Electronic Signature and Invoice Service" <fgodut@acuraaccelerationproblems.com>
- - From: "DocuSign Electronic Signature and Invoice Service" <iysurlg@acuraaccelerationproblems.com>
- - From: "DocuSign Signature " <cofnu@acuraaccelerationproblems.com>
- - From: "DocuSign Signature and Invoice" <boru@acuraaccelerationproblems.com>
- - From: "DocuSign Signature Service" <yxaizao@acuraaccelerationproblems.com>
- - Subject: You got invoice from DocuSign Signature Service
- - Subject: You got notification from DocuSign Service
- - Subject: You got notification from DocuSign Signature Service
- - Subject: You received invoice from DocuSign Electronic Signature Service
- LINKS FROM THE EMAILS:
- - Link: hxxps://docs.google[.]com/document/d/e/2PACX-1vQWHPnAL19--S5fhuKYwz4kBBd02AMx21__UIa1V-NtzAAD9cRnqkRYsEDKx8BgUg86bMHDk66-yys9/pub
- - Link from Google Docs page: hxxps://www.google[.]com/url?q=hxxp://czyszczeniesrebra[.]pl/insure.php&sa=D&ust=1603827760891000&usg=AOvVaw05xTtuU2LfqUqVYMYFf2o8
- - Link: hxxps://docs.google[.]com/document/d/e/2PACX-1vQsh8vxGwEsmF9YUXvPrmYoNrQDuW58Qk9JZJQJtgLaeFTh3Z2HJLKwlQhRCs0S1n8UA0lbmJmGn9so/pub
- - Link from Google Docs page: hxxps://www.google[.]com/url?q=hxxps://www.brafa.com[.]br/draw.php&sa=D&ust=1603827618317000&usg=AOvVaw2dYS0ytGsKQYAcmFsi47vM
- - Link: hxxps://docs.google[.]com/document/d/e/2PACX-1vS_KjrbqlXUcZ2KS5he0a_7_58Yf6L6ngaOm5vBMHPY7zIEwNqvbMF7r8OeOmwG6anVdqMR2Dt199sg/pub
- - Link from Google Docs page: hxxps://www.google[.]com/url?q=hxxp://kgi.shakiltrade[.]com/design.php&sa=D&ust=1603827914987000&usg=AOvVaw3Cugz2dPIDcazKGjUqpalh
- - Link: hxxps://docs.google[.]com/document/d/e/2PACX-1vToBIzhSVxmQLHqUK7cC7uWqMvN2qsBzVifLoYP3BytPdSvmz6VmiMxBpzji7exwqi0_HqRviBw1Fe9/pub
- - Link from Google Docs page: hxxps://www.google[.]com/url?q=hxxps://novopedido.camaleaocamisas.com[.]br/go.php&sa=D&ust=1603827914352000&usg=AOvVaw2jxyjn1CgNz702y4Mms6Ab
- - Link: hxxps://docs.google[.]com/document/d/e/2PACX-1vQoeG8-nJekDDIKFmTvrZ8iTfZoA2jul57ug0iaPDnORepcuAIROu_kuzfiJcNQ8uIbFYGZeCFZUuOq/pub
- - Link from Google Docs page: hxxps://www.google[.]com/url?q=hxxps://numbayfoundation[.]org/put.php&sa=D&ust=1603829390319000&usg=AOvVaw1yTW0oM-3VfNn8LyRM4-_6
- HANCITOR TRAFFIC CAUSED BY SPREADSHEET MACRO:
- - 8.209.127[.]167 port 80 - oreillyautolawsuit[.]com - GET /x.png
- - port 80 - api.ipify.org - GET /
- - 95.216.151[.]81 port 80 - ziverbsel[.]com - POST /7/forum.php
- FOLLOW-UP MALWARE REQUEST FOR COBALT STRIKE (DID NOT RUN ON MY LAB HOST):
- - 69.30.232[.]138 port 80 - 69.30.232[.]138 - GET /download/138.exe
- TRAFFIC FOR FOLLOW-UP MALWARE
- - 8.209.127[.]167 port 80 - oreillyautolawsuit[.]com - GET /f3.exe
- - port 80 - api.ipify.org - GET /?format=xml
- - 5.63.155[.]126 port 80 - functionalrejh[.]com - TCP traffic over port 80 (not hxxp)
- MALWARE:
- - SHA256 hash: 7c9eb9658a1782702301ed2c943c9f59f45c0ac2ffb7fb3e0da8ed6036f752a2
- - File size: 290,944 bytes
- - File name: comp_4389.xlsb
- - File description: XLSX file with macros for Hancitor
- - SHA256 hash: c3e21f7b2bfc3da5e77b37f6556fb985e4402551bac45636a7488664e67d477f
- - File size: 689,496 bytes
- - File location: hxxp://oreillyautolawsuit[.]com/x.png
- - File location: C:\Users\[username]\WinHost32.exe
- - File description: EXE file for Hancitor
- - SHA256 hash: 3b547e3bd5f3040c824ea497f265bf355483cce29c4e059d16e04fba20325498
- - File size: 689,496 bytes
- - File location: hxxp://oreillyautolawsuit[.]com/f3.exe
- - File location: C:\Users\[username]\AppData\Local\Temp\BN6E83.tmp
- - File location: unidentified info-stealer (comms with functionalrejh.com)
- - SHA256 hash: 53c9abf3e3d86b1d9d633aff273a70f11e83858d3fdb362108395f170bcdebc4
- - File location: hxxp://69.30.232[.]138/download/138.exe
- - File description: EXE file for Cobalt Strike
- - SHA256 hash: dc021a0ca0bb3f66d54d15d2b236422c0b90399ea762c7d7aa6d727b9bd5b46c
- - File size: 274,958 bytes
- - File location: C:\Users\[username]\AppData\Local\Temp\SU7096.tmp
- - FIle description: unidentified info-stealer (comms with functionalrejh.com) - same hash seen during last week's Hancitor infection
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement