ExecuteMalware

2021-07-15 Hancitor IOCs

Jul 15th, 2021
15,748
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.38 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=1507_pewut
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Signature Service
  12. You got notification from DocuSign Service
  13. You got notification from DocuSign Signature Service
  14. You received invoice from DocuSign Electronic Service
  15. You received invoice from DocuSign Electronic Signature Service
  16. You received invoice from DocuSign Service
  17. You received notification from DocuSign Electronic Service
  18. You received notification from DocuSign Electronic Signature Service
  19. You received notification from DocuSign Signature Service
  20.  
  21. SENDERS OBSERVED
  22.  
  23. MALDOC PROXY DISTRIBUTION URLS
  24. http://feedproxy.google.com/~r/aekrtojfcd/~3/kMNi_-9P1sU/introduce.php
  25. http://feedproxy.google.com/~r/bdaxd/~3/Vc1NSC7_7Wc/unisource.php
  26. http://feedproxy.google.com/~r/bjpisoxgv/~3/HzQEp8BQpI4/pharmaceuticals.php
  27. http://feedproxy.google.com/~r/cgktoiwlax/~3/j0uF0n9HAdU/receivership.php
  28. http://feedproxy.google.com/~r/clvaf/~3/NO98PqeZz-w/pane.php
  29. http://feedproxy.google.com/~r/elqwhhdtauz/~3/QpCvcTYXgOI/fortnight.php
  30. http://feedproxy.google.com/~r/ezhaqoq/~3/be9zOM2iv8g/thorough.php
  31. http://feedproxy.google.com/~r/fklxcoe/~3/HqRsrS_nxLU/naturalizing.php
  32. http://feedproxy.google.com/~r/frzarg/~3/YSQQjrihlZA/lactic.php
  33. http://feedproxy.google.com/~r/gyxkllszgmf/~3/g7FqjNMRJq4/carnegie.php
  34. http://feedproxy.google.com/~r/ivqbcgklu/~3/jwsjbopWaXo/waxworks.php
  35. http://feedproxy.google.com/~r/ksljgoqkwv/~3/VlDidoofuFw/lobe.php
  36. http://feedproxy.google.com/~r/ltieizomh/~3/nzcJaDcX_3Q/correspondent.php
  37. http://feedproxy.google.com/~r/magwrhwgy/~3/w0Y5L_P4STE/sipped.php
  38. http://feedproxy.google.com/~r/maqcxppuz/~3/Vc1NSC7_7Wc/unisource.php
  39. http://feedproxy.google.com/~r/nkbvef/~3/CeWFvhRpxGA/aglitter.php
  40. http://feedproxy.google.com/~r/ruxaznasy/~3/n0mldUWiNaU/pui%0D%0Assant.php
  41. http://feedproxy.google.com/~r/ruxaznasy/~3/n0mldUWiNaU/puissant.php
  42. http://feedproxy.google.com/~r/ruxaznasy/~3/n0mldUWiNaU/puissant.php
  43. http://feedproxy.google.com/~r/sqbruikykmh/~3/lS7Jtn6bvzE/brothel.php
  44. http://feedproxy.google.com/~r/vqhflr/~3/-uViJ-4Pz78/various.php
  45. http://feedproxy.google.com/~r/wbpbdalxrsy/~3/YQ0u_MZTZgg/shillelagh.php
  46. http://feedproxy.google.com/~r/wingwiycgs/~3/Hc9qJRjavwk/fief.php
  47. http://feedproxy.google.com/~r/xmyldqmxd/~3/-%0D%0A3WQXaHy40w/provolone.php
  48. http://feedproxy.google.com/~r/xmyldqmxd/~3/-3WQXaHy40w/provolone.php
  49. http://feedproxy.google.com/~r/xtqdswjxyw/~3/J7cagM7UsC8/dimness.php
  50. http://feedproxy.google.com/~r/yvwyahw/~3/vfwhsfrWNcQ/washrag.php
  51. http://feedproxy.google.com/~r/zkqnrxfdt/~3/xiLSi0AclGg/questionability.php
  52.  
  53. MALDOC REDIRECT DOWNLOAD URLS
  54. Unavailable
  55.  
  56. MALDOC FILE HASHES
  57. 0715_522785908988.doc
  58. b2a7e405503858e1e6f8ec093e50d8e5
  59.  
  60. HANCITOR PAYLOAD FILE HASH
  61. ier.dll
  62. 2dc334887c1180331aca5fe3316adbe9
  63.  
  64. HANCITOR C2
  65. http://accomead.ru/8/forum.php
  66. http://dialencelu.ru/8/forum.php
  67. http://gatiallyde.com/8/forum.php
  68.  
  69. FICKER STEALER DOWNLOAD URL
  70. http://min0sra.ru/7t4dfgnmkk7.exe
  71.  
  72. FICKER STEALER FILE HASH
  73. 7t4dfgnmkk7.exe
  74. 270c3859591599642bd15167765246e3
  75.  
  76. FICKER STEALER C2
  77. http://pospvisis.com
  78.  
  79. COBALT STRIKE STAGER DOWNLOAD URLS
  80. http://min0sra.ru/1407.bin
  81. http://min0sra.ru/1407s.bin
  82.  
  83. COBALT STRIKE STAGER FILE HASHES
  84. 1407.bin
  85. ee8283d406475b5015fe3faca2896b2d
  86.  
  87. 1407s.bin
  88. 80c225a95caba77a72289472c73291df
  89.  
  90. COBALT STRIKE BEACON DOWNLOAD URL
  91. http://207.148.23.64/Rcn9
  92.  
  93. COBALT STRIKE BEACON FILE HASH
  94. Rcn9
  95. 2ce9fd855d3fd4316c7d46d28d183c16
  96.  
  97. COBALT STRIKE C2
  98. Unavailable
  99.  
Advertisement
Add Comment
Please, Sign In to add comment