ExecuteMalware

2021-04-21 Hancitor IOCs

Apr 21st, 2021
17,076
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.74 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER / COBALT STRIKE
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2104_mmvm
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC LANDING PAGE URLS
  27. https://docs.google.com/document/d/e/2PACX-1vQa2lHec3aZnDrLASlpJANv574j5N7zAEvEbdf5y4rjRM_z1zSgoTiZ2GP4pAdYKOeuj4o-gAIDGGcv/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQdEBn0WvNfP9CRUjnQx2x01YkjNbb0Vhi1OENoHIQKgLtSZtUgN1UL5bVWxImqWPzQ21HURkE5fVhf/pub
  29. https://docs.google.com/document/d/e/2PACX-1vQEa0zlAHYVsGyemrGwIW_fOKwxrMKBHEF9Sdm1uKeGcrar1deBmB-eJRMUiwOWW1MS5ggEkDHQDYNM/pub
  30. https://docs.google.com/document/d/e/2PACX-1vQfO-ruwcykeoPRw7PfH2LPcPWqTpv00D5O38Km_asVhQFG69LE9MM_7cVoorE99ZRsNP0dJkDskHzC/pub
  31. https://docs.google.com/document/d/e/2PACX-1vQh35a9V8flfaWkal1nkqiEnZB6_ZwM06bjeGN4lrmhuqm9b8vP0e8innfjhSlpzCBfmDz3uZnyZzpd/pub
  32. https://docs.google.com/document/d/e/2PACX-1vQHcrYLhbekiuMnEiD3Nb0hYNUQ7_1oFHe47kZlxe2i1p8B7jlv1sI79IuoPQBwrkZYF6vTqWpjqivf/pub
  33. https://docs.google.com/document/d/e/2PACX-1vQISxZrfByci4x75sRWCca0urG52NnugelbV5qere56_QB2jD9AvDjxOWuWUHFbPWS6L9-hHB-BYxIq/pub
  34. https://docs.google.com/document/d/e/2PACX-1vQl6loBT1Qe31USrvN_SRBD3WGbmDs_Bw_TDGdwbh6xZsSwp_sUnEE7dSwswUk7IeesMTle5yXysegg/pub
  35. https://docs.google.com/document/d/e/2PACX-1vQOnrn9q5CIDsk44vRNJcQRDwDiUT3zGyzId26TORz0FwJVq6nBs1kgzTQAS1iWQswgu8wIbLBOR87C/pub
  36. https://docs.google.com/document/d/e/2PACX-1vQpjNlornWkq1buphnSR20lu_Hfws7kptX5TROer5Yco9Hkn0z3C-aR1KwuGTiJhMFgnc2XRAWo0mo1/pub
  37. https://docs.google.com/document/d/e/2PACX-1vQwI2O6z1_v2dWXrfVa4KD_jaR6-UlYNIFXWto96jxDNMIpgW1WxmgU2uwLjVFmaqpLOIpR4LeEFjch/pub
  38. https://docs.google.com/document/d/e/2PACX-1vQXNV5a5h1NyQ1yq4_45DV24WWxRZJSJ_S17opfHzoAmX4iJxuiFOo4NB2hffB_h2DzLCtcscs8hxcQ/pub
  39. https://docs.google.com/document/d/e/2PACX-1vR2v41XfMLXw6EgXwtZd6h2_HvVB6Q7JBxUptYO5EYT_N1tSPl0wKKmT5l99qNgpkE8TVmJd3G0jmPp/pub
  40. https://docs.google.com/document/d/e/2PACX-1vRAGWzf1uzxhP5eNGOw23yOuaxaj-nTi-d1jJ2hFT74xiBGxMsAXpIPCNAfhr9rEVFJxiawAtdnzhs5/pub
  41. https://docs.google.com/document/d/e/2PACX-1vRBCTLEtArIY9Mx74OcJIy_suY3dm4Xp3B2oi7ANYd3HxoIpZaWkYmDh6zfisNKpECCBZLEn-OJCNyI/pub
  42. https://docs.google.com/document/d/e/2PACX-1vReoezs5sDLT2VJlMqgQVlmhK8HfcCxtLpdsAmST6ISu9ua0g5jE5f0VKlRmT3KDO5QW2-mJ3Bo_vTd/pub
  43. https://docs.google.com/document/d/e/2PACX-1vRLgwm6BEmaW0oNXqXm3qzYa3QJvLNOE92MLl8qqHgfGynI39jZ8cM8uaO-Jgolg93dk4q9kAHhIJCv/pub
  44. https://docs.google.com/document/d/e/2PACX-1vRlzXnXl36ULudYzNy1sKnUkSfcfTNfc2jRjHlutIwlcK8VlxDMTaUcrbTKilfYctq-6RpAG09qXU6Z/pub
  45. https://docs.google.com/document/d/e/2PACX-1vROu-maSYq19ditdu6FuN_vSa-6e8-pO0_wQGkEdJcFQwKHX7gvnjeTD8azWX_tI2AHqqkwR_SJ9lCM/pub
  46. https://docs.google.com/document/d/e/2PACX-1vRRTp08k8UdPWUcy9Yj_6cefz3LCzEdQq_oKkStjuMwqvx0A0R_MTcFP2nALLoFkOGelSsgm6c0mi0H/pub
  47. https://docs.google.com/document/d/e/2PACX-1vRT2ZJJvO1E9PpSMlPL-wqMMG0-2y_CNg69nQd_HYP9xPh21TOuAYkuHxbbvD9g1Nz4ZraPQa25Cu-0/pub
  48. https://docs.google.com/document/d/e/2PACX-1vRw1edhLCIqUWnA6Dq92xEdlSZk_kHWNpmRpuEyPNxIMfpar0L7Z53Tk_lKMfyX3aKe8BKStm67J2TP/pub
  49. https://docs.google.com/document/d/e/2PACX-1vRyJXRwh1FyCeKdNAqN9xrfFIx3S-rSh9pC_OHpbDDpmxQHcBBmKH7mmyY-eKzwmbAi3KS7JYDDttcM/pub
  50. https://docs.google.com/document/d/e/2PACX-1vS5vpJw__m2JLmyUFikO55zLW25S6riKy1I8E4xRLMu12Qz4RwmVJBa2gegJB5MvN2IE0ca5vCgzjyH/pub
  51. https://docs.google.com/document/d/e/2PACX-1vS7EWKL4YkJy154I9dUo1jOKVMwsiEGfBEVLMyCCR2Ibchmlu4Q4BsRDs1N1IFTCnZCR6-GxpZp00-9/pub
  52. https://docs.google.com/document/d/e/2PACX-1vS9uhdbHrieXFlHrbXqC_FbaOGlKWFmnFuHrILrzmhz9OfrWiD2XuY5JBlj2Qu8CDevKxxqRflBtBDv/pub
  53. https://docs.google.com/document/d/e/2PACX-1vSBInSakIkxFrMcLsoS-DLw8ZMMu5fu3UJVvc9n2fQd4XJi65Ezwrn1zlWoCREtvomMqTpsxxdrabHb/pub
  54. https://docs.google.com/document/d/e/2PACX-1vSDN9xAIsJNYpp_ICrdeHEP2ExvLd-nmxABd03U2Eq6IeuUxjFdCc8OG87Xm_IH8Xe2FZRdcyenUQyJ/pub
  55. https://docs.google.com/document/d/e/2PACX-1vSEDJ9Fy72QCFFY7s0NKH5XA-NB10WY61P7ZiPQDnT7DVmH5YM957TxrgHE7sH40biZG8pp5H_9qKQR/pub
  56. https://docs.google.com/document/d/e/2PACX-1vSKL0lLBrwM4uxQJ0Rg5xkWENdA6jQaCf-7E1CCg6j6VFvPN1Z8KodWFpgoazVoj1jcJ5zuqX58Qokb/pub
  57. https://docs.google.com/document/d/e/2PACX-1vSkTFbot3U3572aLoJnP4WFckj5wdiS3d_wDlrYVWtS2uOfNAnQsdG761lQV1pH1lecvPsbWRJTvNO5/pub
  58. https://docs.google.com/document/d/e/2PACX-1vSM879svKlBvmYIytybeF1f2hHzOiFkb9pjcgN2-341U7zYNpv7UtCSzlklg9tO1b8aMLceF2CIDyWL/pub
  59. https://docs.google.com/document/d/e/2PACX-1vSPd4xYMdpZFjT1emIk5FZvst5-dxpTEb4_nWxhh-3yOw3mwmmtnI587kFjpKiKo_HacJQlilGab0JZ/pub
  60. https://docs.google.com/document/d/e/2PACX-1vSPV0SOHQVTF8KWc-mYD-MMKXqO0I6YEJTgh_tY3BbeuanKiUedMCxT_ukLosiXu2P_nCSctu85Kciz/pub
  61. https://docs.google.com/document/d/e/2PACX-1vSu-rx1O-449oVuKPQ1LnYu0oYWPWMMX8ZaZL-nK23_rgOXH8GS4wwrcc4_FZRyP7eO6ydVPB6_Necn/pub
  62. https://docs.google.com/document/d/e/2PACX-1vSUfRJSOiGSp3u9owyx4TiDOXMYvsEBbBaH_PwxDqRAaP_phSgwEVOEx6jPsbFVWP58E63XJXEEIbc8/pub
  63. https://docs.google.com/document/d/e/2PACX-1vSUhKkE-N6eWH7ErUNgIUkfAs2jWD8xlxjVjwlYR9XfhytvoYsd53WG6equB41BfqSa8l64LEwk5VJC/pub
  64. https://docs.google.com/document/d/e/2PACX-1vSupd7_rLVbmVjH7wX0RGZJmmaC64o-jy5wlY-w8yuTdh1yUPobB9jrbglhASsTyZdpYRGsiW5-SbMC/pub
  65. https://docs.google.com/document/d/e/2PACX-1vT7rLG2XliW2GCkXflTxbY1h49-WQmpt5k8nmqIEY4zDp-2nh0rXHc7KZpS56f-1NONKWBzMO_pzJUk/pub
  66. https://docs.google.com/document/d/e/2PACX-1vT97j6fwNrBGgW0SS9SYW_pZpc07QgeRLpDW4vTHzo1VDEeQH6mBESvuR632JMxyQ-xk3oNYhRTBF8I/pub
  67. https://docs.google.com/document/d/e/2PACX-1vTbipHF2eY1qSkQlVqA_MUBRCi-XIRersQ9nEJsHfK7ekWhR9cmZIPDJYvh1YA_erVyNdm491dM8bYv/pub
  68. https://docs.google.com/document/d/e/2PACX-1vTdMUal8BN-eYyMLNzboRWxx_XcOyDPYBpjtuTltKukVfVvuhAsjqScV98b_CXvTbXkzRe_EE0hrt-t/pub
  69. https://docs.google.com/document/d/e/2PACX-1vThlseMwnpDOxvxTS07uvFWn3KXSW9OCW-4oENqoodMn6Puz_7gRfxsdTKPARZppyuiHhWvu5D3R-Oi/pub
  70. https://docs.google.com/document/d/e/2PACX-1vTkOs626eYb-x8Vr5Arjf2yfCi63piUGrja5Ge8aNBm3OEM8gxy1223rSK2VaQr1s2T588bYCA7nVgH/pub
  71. https://docs.google.com/document/d/e/2PACX-1vTlTg5j2mQR_LH5rWjHtnua6wv-fXKtoxAdsgmyJkIQYTJtNpxFGodLdcS_n2RsISKQAweL6d_Q3Gyg/pub
  72. https://docs.google.com/document/d/e/2PACX-1vTmtVCeUGuj9SZBiwrInw2hMU55FaIgmO2BQBOVBQHcaV-T_AYQeM9Tow-_gY6bMhxFYjrvLFHRUNQG/pub
  73. https://docs.google.com/document/d/e/2PACX-1vTONk1Gncg3V7aohk6stjUdWuui2mOPOPWPyaKT00lr0rPt0Z6uDrHF_d7Xmrc8Zk5QJujg2A9GHu1l/pub
  74. https://docs.google.com/document/d/e/2PACX-1vTqsSez9S1wkA6lJM1f3YLC1pEsj-cqgqfskaeYLchE0sVVwCvCwlj5Zp8m3EpfQsBQ5X3_57oZ9P_Z/pub
  75. https://docs.google.com/document/d/e/2PACX-1vTu46shua6yyuorCW5oPyk5ZWPZWS_gefOhO8lTGe21dKWfLjipuX9F_VFmRzWD-i9iqZALwzKRIKo6/pub
  76. https://docs.google.com/document/d/e/2PACX-1vTxCO4pUWdniWhJdu5xUjLoRvgLjQgqbKpAkx6QJUBXwrQOXCH8wLgzrrCWiFTzHtD4noC856HjC4Ip/pub
  77.  
  78. MALDOC DISTRIBUTION URLS
  79. http://alltestagain.lukehadaj.com.au/odorless.php
  80. http://alltestagain.lukehadaj.com.au/standalone.php
  81. http://ecofiltroform.triciclogo.com/warner.php
  82. http://folstop.com/subchapter.php
  83. http://folstop.com/valve.php
  84. http://ingenier.co.cr/dangle.php
  85. http://kensingtonglobalservices.co.uk/deceive.php
  86. http://swsgroup.sws-group.net/beatitude.php
  87. http://swsgroup.sws-group.net/vs.php
  88. http://tonmatdoanminh.com/firebrick.php
  89. http://www.e-voks.dk/whop.php
  90. https://3g-electronic.net/bloodstain.php
  91. https://3g-electronic.net/shot.php
  92. https://3g-electronic.net/usher.php
  93. https://allendostmen.com/invest.php
  94. https://aquamarket.com.ec/sergeantship.php
  95. https://chandlerfla.net/mitosis.php
  96. https://chandlerfla.net/psychical.php
  97. https://codesterio.com/stank.php
  98. https://contentconsultants.in/mitre.php
  99. https://design.wyloutgroup.com/supressed.php
  100. https://facturasenlineamarx.com/inflammation.php
  101. https://facturasenlineamarx.com/tacitly.php
  102. https://henkvandenakker.name/philippine.php
  103. https://istgahbazi.ir/led.php
  104. https://manufacturing.wyloutgroup.com/jingle.php
  105. https://primeservmanpower.com/transductor.php
  106. https://rubinet.com.br/debilitating.php
  107. https://socialpromotion.store/herself.php
  108. https://starreachersng.com/acrimonious.php
  109. https://tsbo.company/banning.php
  110. https://viveroscamila.cl/applicator.php
  111. https://viveroscamila.cl/discretion.php
  112. https://www.ceethoglobal.com.ng/campus.php
  113. https://www.ceethoglobal.com.ng/potion.php
  114. https://www.hellosiroco.com/adrenaline.php
  115. https://www.hellosiroco.com/improvable.php
  116.  
  117. 3g-electronic.net
  118. allendostmen.com
  119. aquamarket.com.ec
  120. ceethoglobal.com.ng
  121. chandlerfla.net
  122. codesterio.com
  123. contentconsultants.in
  124. e-voks.dk
  125. facturasenlineamarx.com
  126. folstop.com
  127. hellosiroco.com
  128. henkvandenakker.name
  129. ingenier.co.cr
  130. istgahbazi.ir
  131. kensingtonglobalservices.co.uk
  132. lukehadaj.com.au
  133. primeservmanpower.com
  134. rubinet.com.br
  135. socialpromotion.store
  136. starreachersng.com
  137. sws-group.net
  138. tonmatdoanminh.com
  139. triciclogo.com
  140. tsbo.company
  141. viveroscamila.cl
  142. wyloutgroup.com
  143.  
  144. HANCITOR MALDOC FILE HASHES
  145. 057a528d5f6578b3d20956c53b71c105
  146. 191fb95949d274f2d0c37133866974bc
  147. 2556784b1def89645da5d4894f1a84c9
  148. 4427ec7dc5ce591b43e147cc4a49ac1e
  149. 4b6ec54804d7e223f62f4cd4fcc0262a
  150. 4f94bb33078b82358cb34622c13accf6
  151. 5655271154fa66162791f188e174369f
  152. 5a58566397c5dab7cf6d5cc16db13f3a
  153. 74591b1e85cbfc849a7f0db6872a1f54
  154. 79ba2942cae8e8c010e715b1d8a5028f
  155. 849ff5a22dc506937e8f6faff2e76114
  156. 8b457f52ab30a3ff742443001df1be56
  157. a240ab65fe550a5e864948ffe28b65e4
  158. af0ec5ccac5c1c6d6bbd5ac174184a2f
  159. b39ccc1a1d228a867dea7bd0a786d41c
  160. be7b55bc9f0170d518ebd6b40a72adc5
  161. f6307efab9d5abfe2bc4198b6520ca41
  162.  
  163. HANCITOR PAYLOAD FILE HASH
  164. edge.dll
  165. bfe1bf1aa88155a2f61f8bc7ba73bc8c
  166.  
  167. HANCITOR C2
  168. http://lectionalt.com/8/forum.php
  169. http://palimenciont.ru/8/forum.php
  170. http://sidainopecelf.ru/8/forum.php
  171.  
  172. FICKER STEALER DOWNLOAD URLS
  173. http://bambinoska.ru/6gfd33ghj.exe
  174.  
  175. FICKER STEALER FILE HASHES
  176. 6gfd33ghj.exe
  177. 77be0dd6570301acac3634801676b5d7
  178.  
  179. FICKER STEALER C2
  180. http://sweyblidian.com
  181.  
  182. COBALT STRIKE STAGER DOWNLOAD URLS
  183. http://bambinoska.ru/2104.bin
  184. http://bambinoska.ru/2104s.bin
  185.  
  186. COBALT STRIKE STAGER FILE HASHES
  187. 2104.bin
  188. 3cd8759c6805f5ed97686f0d5d270203
  189.  
  190. 2104s.bin
  191. f4693f6d469a9ede94f96aba5afe7f81
  192.  
  193. COBALT STRIKE BEACON
  194. http://37.1.211.126/tV9Y
  195.  
  196. COBALT STRIKE BEACON FILE HASH
  197. tV9Y
  198. 4af1379c6f7ba6c703030ff5634f8d42
  199.  
  200. COBALT STRIKE C2
  201. http://37.1.211.126/en_US/all.js
Advertisement
Add Comment
Please, Sign In to add comment