Advertisement
vk_intel

2018-12-04: Hancitor -> ISFB Gozi v2 IOCs

Dec 4th, 2018
594
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.13 KB | None | 0 0
  1. https://isc.sans.edu/forums/diary/Campaign+evolution+Hancitor+changes+its+Word+macros/24376
  2. h/t @malware_traffic
  3.  
  4. Hancitor Bin (BUILD=03gre12):
  5. SHA256: ad783ca9c2bd4c9905b131d170c1dce5bad9de8b8c2d4607a8cd051021284df0
  6. https://cape.contextis.com/analysis/25398/
  7.  
  8.  
  9. // l -> Download and execute .EXE in separate thread (arg=1)
  10. {l:http://todoemergencias.cl/wp-includes/1|http://adm-architecture.com/adm/wp-includes/1|http://heargear.net/templates/1|http://rosegreenstein.com/wp-includes/customize/1|http://accidentalpodcast.com/wp-content/plugins/site-is-offline-plugin/1}
  11.  
  12. // b -> Download and inject code into svchost.exe
  13. {b:http://todoemergencias.cl/wp-includes/2|http://adm-architecture.com/adm/wp-includes/2|http://heargear.net/templates/2|http://rosegreenstein.com/wp-includes/customize/2|http://accidentalpodcast.com/wp-content/plugins/site-is-offline-plugin/2}
  14.  
  15. // r -> Download and execute .DLL or .EXE
  16. {r:http://todoemergencias.cl/wp-includes/3|http://adm-architecture.com/adm/wp-includes/3|http://heargear.net/templates/3|http://rosegreenstein.com/wp-includes/customize/3|http://accidentalpodcast.com/wp-content/plugins/site-is-offline-plugin/3}
  17.  
  18. MD5 (2018-12-04.isfbv217.loader.decoded.vk.exe) = 94c524462cf4d756c37f641e4c8b835b
  19.  
  20. Bot ['2.17']
  21. Build ['49']
  22. Botnet/Group ID ['200']
  23. DGA TLDs ['com', 'ru', 'org']
  24. Server [’550’]
  25. Encryption key ['Gwe9HMygngWe8kPK']
  26. DGA CRC ['0x4eb7d2ca']
  27. DGA Base URL ['constitution.org/usdeclar.txt']
  28. Domains ['api2.doter.at/webstore', 'beetfeetlife.bit/webstore', 'in.extremas.at/webstore', 'asx.zenjom.at/webstore', 'g2.ex100p.at/webstore', 'gif.doter.at/webstore', 'extra.avareg.cn/webstore', 'foo.avaregio.at/webstore', 'op.iowbased.at/webstore', 'ws.doter.at/webstore', 'f1.cnboal.at/webstore', 'xxx.doolop.at/webstore']
  29. Domains2 ['51.255.48.78', '8.8.8.8', '192.71.245.208', '178.17.170.179', '193.183.98.66', '207.148.83.241', '111.67.20.8', '103.236.162.119', '142.4.205.47', '213.136.85.253', '159.89.249.249', '82.196.9.45']
  30. Path: ['/webstore/']'
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement