ExecuteMalware

2021-04-22 Hancitor IOCs

Apr 22nd, 2021
16,381
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.25 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / COBALT STRIKE
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2204_fesw09
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC LANDING PAGE URLS
  27. https://docs.google.com/document/d/e/2PACX-1vQ-zUQCjKIiMmJsODruKcCHjM6jPpgbF0vMS79_iirj4ySsU4y2Epb2OkkbwsZkOO44L6sXO76U7Hap/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQ1-VWMu1oCTbir-SpkzoiMJwCjxbyUysooWtItB-o8ig7NmmLfeisJKySF865OY8nUfEa-ktUA0Fwq/pub
  29. https://docs.google.com/document/d/e/2PACX-1vQKaRQbeG_9NYNKZdUhRVo1ydpVt9tSw3uN8cIJSRrIPz4P0WTGoanyVSqxiOqHrjmi82JF2lKon6B7/pub
  30. https://docs.google.com/document/d/e/2PACX-1vQlbBdIjb5Nn75rj40ZrfU2Smzcdj5pKVYMQCV3EHr4sBl0xX8LMcdEae424hKaEggPREmoB0cz1B3O/pub
  31. https://docs.google.com/document/d/e/2PACX-1vQO5u3742hhCgKrMkUAtw5cN9qw3Gibe192ucOq4YnpM-Nf1VihfCzJTmnNIbf7Y_q3Mr0Fn1f_K0E3/pub
  32. https://docs.google.com/document/d/e/2PACX-1vQrXeH14pI2VozvGYF7z42FnXR5-z0Ak4FwEXpwvhz-ReoXrtbs6uDKxrBBXSwjl_zvHMxWb067Rpcx/pub
  33. https://docs.google.com/document/d/e/2PACX-1vQtrhFrTMPP8mJ7y-8_NXQckBNl_IjXld8mRz3d2eL35LA2--OooyQpt-HWq5MHGMLSg4_KAE_UeT4T/pub
  34. https://docs.google.com/document/d/e/2PACX-1vQvNwhJr6PYt1A5ml_h-XwcsG2m6KWDhcx5IbFJPUsdiK0r8Dh4JG-jGBfwUmE8RyQkOtEIfWprkELZ/pub
  35. https://docs.google.com/document/d/e/2PACX-1vQWc0AfrHjcKtUI37CyB8jpFIDXXFlTSZ8YLrPi3HC6fZHcv2AaTo06nqZMxNHXUxYhxBC1MvLtzZ5I/pub
  36. https://docs.google.com/document/d/e/2PACX-1vQY3B3ZmxlYJiGulfw6v1adU799ZO4BdYQVpbgIsMyuKuiPF5JgH2WDXKwLaOlC5HJaTH7uybNcdA3z/pub
  37. https://docs.google.com/document/d/e/2PACX-1vQZAwPqpQNV9JKtCU3itEqIDqrwRGu07OEnic5RJ8GUwmrCFUHpfNArhMlxqpCIi7YXlYOeyjVGk2Z-/pub
  38. https://docs.google.com/document/d/e/2PACX-1vQzPCN-mMHdCVbI8IXGZkBgccnXGIwVJ9qcyqm964ya-799ST3dRNynJJxZiXtHE7Te5vEam2DafQ2z/pub
  39. https://docs.google.com/document/d/e/2PACX-1vRA4CyaaysTjk-Q1gBxXB9s8TfuewiipZicV_vKUrga7ufW_u5FLGibVImlka3Y7MHaOxMOuuGSs4hv/pub
  40. https://docs.google.com/document/d/e/2PACX-1vREiuYBFznv_RF95AEmv0TInB4PN3GUp_eSO61dJdd-a4fV__KfgaFwsyDai7DwTE3Mo9YFfR8Jv44x/pub
  41. https://docs.google.com/document/d/e/2PACX-1vRi8wqz29qk6pK7adwwxFlu-YsaliqTNwL-6WHWgsNr9Ni72K7uir1iceGyeVsewiCpVAjOuRIapQdc/pub
  42. https://docs.google.com/document/d/e/2PACX-1vRiQ91kHCCDHcxXILk0_5ybQyVKOUb6h6hIUh6Jx5zOzia55ED47Frlb2ke4WRDYuYBAPfwy1yMf0VX/pub
  43. https://docs.google.com/document/d/e/2PACX-1vRK5CH1AB6EoANDNhLmhz-Ue1vqk_mvTWTccaLpetB7wW1z-q2jBBbg__Ly3zw7q9Zxt8g72n5wYa61/pub
  44. https://docs.google.com/document/d/e/2PACX-1vRNWJRazxR8nyP7ymPZPOz0MQ6D0fmqdvaZQd07fKLUVJOVZuAuLAdSfucva3u0JJYl5663zBW8z_Tx/pub
  45. https://docs.google.com/document/d/e/2PACX-1vRp0W-L1dNAJHrUzU50PmPkUSr5bcAZr7DBMyDSyrdguOCL5XZ-eQDD6YYkbCji-x3jFme3-XkkK-7m/pub
  46. https://docs.google.com/document/d/e/2PACX-1vRZANJQB0c7eDFntWBD5HqeSSBGVUn5TWeI_fsH0dnW-7CrBbfWoaTYRjme0AgR-YGCFiIGXYeDX-EE/pub
  47. https://docs.google.com/document/d/e/2PACX-1vSDRN5owfw1j5UI_lFL5XNs6iRfU-Hxau7UxZ5sf9QVLj09UIrFgs-oXmTexAJxRDjPYt24vzFi6HAV/pub
  48. https://docs.google.com/document/d/e/2PACX-1vSGodexHWSRGXtVYISsRzAHiw2AjRT2iRhYT_kE9Y34-HHy5TTLZjh10cY66yNEZFg67-cl7vgC_QdE/pub
  49. https://docs.google.com/document/d/e/2PACX-1vSIDFEuY1Gc6kNe0PZUn3DCvjVPRCZL8dIT8UL_R0XyQPCs6zRp5GEjE3F_HwKMKq_vmq-5HCP8aRcy/pub
  50. https://docs.google.com/document/d/e/2PACX-1vSMC4PqtQMcvqs_lcohllIz9Zlx4u_G4A2NNQ9nSXAPAsqnzEa5_azG_egY9lf1HGjPSJdXIilugFMB/pub
  51. https://docs.google.com/document/d/e/2PACX-1vSNF3MJkPzhcfTWUpmGrOtJhhGDd0s1YL56W4SJPD_2t24xgCCKKftUJceP0LdHt8hhM2xKBSAf625h/pub
  52. https://docs.google.com/document/d/e/2PACX-1vSp737wxQYkJzHFqdQn5AVmslymuHeP2VFzgZiD3ouuXwRac2hrJhvx7EApd_uNUewarMTvlx1zGLpD/pub
  53. https://docs.google.com/document/d/e/2PACX-1vSQH_YYvlVcXstGuvukXXxPBjnR-v2f-fICBEf8mjMFwMdWXSsEtjKfg4GM0lovvq93PwIZXcQq1zrp/pub
  54. https://docs.google.com/document/d/e/2PACX-1vSrT2ACCUqwcdDAR-stALpFLS0wHYMbgnVOQHnmViviEoCyNeJPBQqpXvfMVEZJKCiwpu_csU6QGnks/pub
  55. https://docs.google.com/document/d/e/2PACX-1vSTx3ZceyU4C_I5WntZ2L0H0oX9jTd5JkzH-ktQ15rbKedtD-FDBeu_9kZoaeS9srwGBnK5A65lxn2-/pub
  56. https://docs.google.com/document/d/e/2PACX-1vT3Jq25rP1SpSoU-EPRHIuQ0DtFF4QBkozia0cK7ng00Z3S5PhSFuDPKAuhJaRW8QNNe59jGeou9l3Z/pub
  57. https://docs.google.com/document/d/e/2PACX-1vT_l8qngGPlyTB5XBFUpUyOdONTCo-7kBpkhlhkyEESNXJFeuOQUdgEkp7F6nZOxJ9S1qUNt5LkPLnB/pub
  58. https://docs.google.com/document/d/e/2PACX-1vTAawwFuibDA47TEh9aSxvIJGlGKBEUK0-drVm_ZxpQcrXC7ubvGPQ6298D-GdXddw-si9F7mNOiqDb/pub
  59. https://docs.google.com/document/d/e/2PACX-1vTer7Hsk4P-XiiePqxW72ksxTVvIo1AFFtuhp97cePAxmZBIEIQnNkcGT6Jxax-VpZkzzuAQqZgeb1v/pub
  60. https://docs.google.com/document/d/e/2PACX-1vTfiXZGSu2S_2uaL8SNBf3bUYV5SAp9dRABBH2DmuzWeYR1zdVit2gcha97LUbgmuJx654hLK_Dge21/pub
  61. https://docs.google.com/document/d/e/2PACX-1vTFWQqRiUTpMNuK5QrJCXGZklImxKtTxfJCgPs5HONCEaHxAdY_zeVe2tYtuAMusCQnv6IkctL5zwiE/pub
  62. https://docs.google.com/document/d/e/2PACX-1vTHFgZsOLIKzBkilGs_5cXb_zGPdpsd93Pyp8boyRat6L7vik9Fq4QSmB7HAo8j0vd2WB3H3iZkhMnR/pub
  63. https://docs.google.com/document/d/e/2PACX-1vThLfoQz3qD9NQQK4C1-uu05Cls-gOTpUUymSxivVp3mK709qAq7zwAU01qGRm78P9U1Yw5hQrWB_NC/pub
  64. https://docs.google.com/document/d/e/2PACX-1vTmX-nLoGWOhpbaYFetMucQY9E_UbqbO1evsUjuFcI4TkPhDCUcvphqhKQKt8L9uM9zseJijWHl-iU3/pub
  65. https://docs.google.com/document/d/e/2PACX-1vTNnrYo_bZWZ3m25LwhWeZgs5-ue8Q4Vp70mSXpLHS-kAhOEjFN2dgNcfJLaIqGuuOxQJD1FVEhKbJM/pub
  66. https://docs.google.com/document/d/e/2PACX-1vTSleXhSYloZ-hEhcJ2WIM4jDYHNoh2UbkMXYB4hugNlrUaAUw991jqZDhPD5eyZFxVZ-bEimuOo9vO/pub
  67. https://docs.google.com/document/d/e/2PACX-1vTtcrN9KSpuSkvwUSCqHswiYkd6Ah7vdtnzO9aSKOcV0YIiUuI_Zu3BVSWywXClib62M8i_pphPQ8TI/pub
  68. https://docs.google.com/document/d/e/2PACX-1vTZuOdqIaZWisgRZsED4XFvNpTsUxGln6dCV9yaW3PJXe4oamp0n0-48F6ZGp1tlCNQoGjMRZHs33JT/pub
  69.  
  70. MALDOC DISTRIBUTION URLS
  71. http://dev.springbreaklife.com/tour/content/021815_redneck_twerk_contest_D021815/deify.php
  72. http://dev.springbreaklife.com/tour/content/021815_redneck_twerk_contest_D021815/greatest.php
  73. http://ecofiltroform.triciclogo.com/photoimpact.php
  74. http://e-learning.iskandariah.perubatan.org/pharisaical.php
  75. http://folstop.com/improperly.php
  76. http://gurshanlogistics.com/decorator.php
  77. http://ingenier.co.cr/nether.php
  78. http://ingenier.co.cr/rareness.php
  79. http://kensingtonglobalservices.co.uk/acidification.php
  80. https://3g-electronic.net/bidirectional.php
  81. https://hinchcliff.net/chauffeur.php
  82. https://impactmarketingservice.in/complain.php
  83. https://manufacturing.wyloutgroup.com/pettishly.php
  84. https://masterize.com.br/synthesist.php
  85. https://merinocraft.ro/teaching.php
  86. https://natural-healing-central.com/fixative.php
  87. https://socialpromotion.store/premode.php
  88. https://starreachersng.com/paleogene.php
  89. https://trio.ae/sceptron.php
  90. https://tsbo.company/carbide.php
  91. https://viveroscamila.cl/butylene.php
  92. https://viveroscamila.cl/scottish.php
  93. https://wingscart.in/volumetric.php
  94. http://swsgroup.sws-group.net/faro.php
  95. https://www.upperkillaycc.org.uk/susurrus.php
  96. http://tissl.lk/temporary.php
  97. http://tissl.lk/transiently.php
  98. http://www.e-voks.dk/dais.php
  99. http://www.e-voks.dk/pageant.php
  100. http://www.gemitek.com.tw/mechanized.php
  101. http://www.gemitek.com.tw/popover.php
  102. http://www.korean.britishwebsite.co.uk/disney.php
  103.  
  104. 3g-electronic.net
  105. britishwebsite.co.uk
  106. e-voks.dk
  107. folstop.com
  108. gemitek.com.tw
  109. gurshanlogistics.com
  110. hinchcliff.net
  111. impactmarketingservice.in
  112. ingenier.co.cr
  113. kensingtonglobalservices.co.uk
  114. masterize.com.br
  115. merinocraft.ro
  116. natural-healing-central.com
  117. perubatan.org
  118. socialpromotion.store
  119. springbreaklife.com
  120. starreachersng.com
  121. sws-group.net
  122. tissl.lk
  123. triciclogo.com
  124. trio.ae
  125. tsbo.company
  126. upperkillaycc.org.uk
  127. viveroscamila.cl
  128. wingscart.in
  129. wyloutgroup.com
  130.  
  131. HANCITOR MALDOC FILE HASHES
  132. 18fbb1386ba21748c307411b339e6144
  133. 4a8db898d29e568422cc9a7d0fdc98cb
  134. 4f91dbfa01c2d17f54a381285417d4a8
  135. 64bd289781298000004e25b41b54155d
  136. 677874afbdf99c7f00aa9e2ae029c511
  137. 76501ea6cf150612fe7451192759faeb
  138. 9e6790705286d936e87b44504c8c7f6c
  139. b2afa0beb08559f0b8585825c0a441b2
  140. c312ae8d89b0aa3b2b09b562c1affaf3
  141. caedba3369251d72398172d6c54c6621
  142. d5b38824de26324623c92c6b74abf506
  143. f8e74f0a605033d10a672e1f29bad281
  144. fb448443452dd1b4e74b130da9c5d2c3
  145.  
  146. HANCITOR PAYLOAD FILE HASH
  147. hurpus.dll
  148. 2ed4835cef8ac661a2f69967b087f3b3
  149.  
  150. HANCITOR C2
  151. http://adrouterigh.com/8/forum.php
  152. http://fronversimai.ru/8/forum.php
  153. http://sintiellonn.ru/8/forum.php
  154.  
  155. COBALT STRIKE STAGER DOWNLOAD URLS
  156. http://man70.ru/2204.bin
  157. http://man70.ru/2204s.bin
  158.  
  159. COBALT STRIKE STAGER FILE HASHES
  160. 2204.bin
  161. 709884bf5f5bae01f19fb06dd5569400
  162.  
  163. 2204s.bin
  164. 3c6029441b564f28d901b60376440be9
  165.  
  166. COBALT STRIKE BEACON DOWNLOAD URL
  167. http://45.136.113.10/fk5V
  168.  
  169. COBALT STRIKE BEACON FILE HASH
  170. fk5V
  171. 4c8246c8f0295012b1c1ea842c056c1d
  172.  
  173. COBALT STRIKE C2
  174. http://45.136.113.10/ptj
Advertisement
Add Comment
Please, Sign In to add comment