ExecuteMalware

2021-03-01 Hancitor with Cobalt Strike IOCs

Mar 1st, 2021
4,656
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.68 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD=0103_jepskew
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got notification from DocuSign Electronic Service
  9. You got notification from DocuSign Service
  10. You got notification from DocuSign Signature Service
  11. You received invoice from DocuSign Electronic Service
  12. You received invoice from DocuSign Electronic Signature Service
  13. You received invoice from DocuSign Service
  14. You received notification from DocuSign Signature Service
  15.  
  16. SENDERS OBSERVED
  17.  
  18. MALDOC LANDING PAGE URLS
  19. https://docs.google.com/document/d/e/2PACX-1vQ1BBFmsSzUwpCZ-Uja7NHss8TYWEzJ_34oUPH83iem-_nwfFSWx4fL55yiOo5dl_0iKlduWyyYWTRo/pub
  20. https://docs.google.com/document/d/e/2PACX-1vR0__W8JBBAqUKv4cCPNpPkJg8viAGgsChkS6DQMeNH0U-rcnjezW1HTidjvcnBI1TYiVPMPDVIUoHQ/pub
  21. https://docs.google.com/document/d/e/2PACX-1vRGkFAdGp3mXtlBv5D8P41ClN69-vnvScwD_ZOauh7MlK41TfP6tluhhUlDAqpnXQjeWcBUnaapRgW6/pub
  22. https://docs.google.com/document/d/e/2PACX-1vRi0Ovc9gOO8byt1z8pTYhlgpVXjHjMzJPU7S-9IygNuDD7XW_4H2Sv60CM6b1xVh9G2ebf_E8c6wBx/pub
  23. https://docs.google.com/document/d/e/2PACX-1vRiA8cNdUVs-m5sq-Q_s5-paQVU1u0IfIg9-loXJjHqTcXEi9daJYw3nFYkkE10rAbRdGJMwTt2kIgg/pub
  24. https://docs.google.com/document/d/e/2PACX-1vRxaJV_jRNas-jKbTQwFRU9-NC4_toXqpTveUjzeZUIhxVYBwOU8gMI5Lzpv1aOy9hTaSuAMZpXqk3f/pub
  25. https://docs.google.com/document/d/e/2PACX-1vRxYpQ_bnUJfGnjA052uiEXM4ZxU_lUB4evRC2R95Okt4_i1ffM23S_AB4fPC6S4NChmpKzYQtQW8z5/pub
  26. https://docs.google.com/document/d/e/2PACX-1vS_DkYI_GouxsICJqTb6y9mL1zB2lgcUi2k-2NWRqo9lxtswXHgkMBtBFgpMe7OBSrzPBAHL7nYZ0bX/pub
  27. https://docs.google.com/document/d/e/2PACX-1vSFTUvqL6a0ot_nKE8asntyX8JP36imF5aV0hPYQERVCHW93GklFnv3pD5SCC3iBlxydqzCYguakDEF/pub
  28. https://docs.google.com/document/d/e/2PACX-1vSLQMLDzGHCZ55B8kuzEeDCzm7LWuJxeU07FuUj217O9ieC-kewtDAxeQ8iMmggGCEFbNTlwxftFekU/pub
  29. https://docs.google.com/document/d/e/2PACX-1vSnLI_zroqVc45v0qVIgq4NS18rGDL1_tfcGTf2rD277XrRhEuEwvQEBuIPRc9wilU7X6RtPBpTbY4r/pub
  30. https://docs.google.com/document/d/e/2PACX-1vSOShpI-Zj4HZxdkssmk72EfxAabzii42omy1dQixWt3MERVhgFr-rGZvtOn3nwbSJK4CpPdSVw5165/pub
  31. https://docs.google.com/document/d/e/2PACX-1vTCp9Qx5lwEGH28FcUHYLUgG_k6-2rqKoVZHnjH8qPQVFAm4hH_Z3qPhcxD6PL9bxH2MD4iN2GlBazY/pub
  32. https://docs.google.com/document/d/e/2PACX-1vTdzsjFl3gZZx2A0apd_kKexsNP2HlEro-IVlRC3CJ3lwd5R04cD69yoZmxE2l4P7va_AvwRKZkYnZ5/pub
  33. https://docs.google.com/document/d/e/2PACX-1vTi_7pKKEYNftGgONZ4ET5A2r_9J2KEiXOoncNg0QUpPC8NJvD6zOFC5ATANv1o3iNm_YpxSlyic7p6/pub
  34. https://docs.google.com/document/d/e/2PACX-1vTqWgR7_-sp6OwZIHiqia9DQoAfwCaD6FquL1QkUIokf_ZER3DLn04a7_2GeBJlC-hzYyj6VlXVED4K/pub
  35.  
  36. MALDOC DISTRIBUTION URLS
  37. http://kiehlturkey.com/endoenzyme.php
  38. http://kiehlturkey.com/underclothes.php
  39. https://bgurbanglam.com/scheme.php
  40. https://bgurbanglam.com/stuck.php
  41. https://connect.rio.br/forage.php
  42. https://crm.basilrealty.in/germany.php
  43. https://crm.basilrealty.in/sophist.php
  44. https://losgedeones.com/stimulated.php
  45. https://notredame.netafrica-sarl.com/catastrophe.php
  46. https://notredame.netafrica-sarl.com/estimation.php
  47. https://webworks.nepila.com/peculation.php
  48. https://webworks.nepila.com/readies.php
  49.  
  50. basilrealty.in
  51. bgurbanglam.com
  52. connect.rio.br
  53. kiehlturkey.com
  54. losgedeones.com
  55. nepila.com
  56. netafrica-sarl.com
  57.  
  58. HANCITOR MALDOC FILE HASHES
  59. 4fa931626b5cfaa706213db17d0c61dc
  60. 609d8d63f5a483b4e333d54aa9e5c60b
  61. 693fa214e73716254347f33f0c50a289
  62. 6b5e020928e890335ec896cf9037e144
  63. 8932fef09da75fa3b39382fb861bedf1
  64. d996737591be99bf9a3085dcda2cd81f
  65. de6deb3c6429e930ce2edb82ce788dbf
  66.  
  67. HANCITOR PAYLOAD FILE HASH
  68. Static.dll
  69. 8d54e98795c459e0263c1d40cbdfc9f8
  70.  
  71. HANCITOR C2
  72. http://ementincied.com/8/forum.php
  73. http://watoredprocaus.ru/8/forum.php
  74. http://noriblerughly.ru/8/forum.php
  75.  
  76. FICKER STEALER PAYLOAD URLS
  77. http://mymooney.ru/6fwedzs3w3fg.exe
  78.  
  79. FICKER STEALER FILE HASH
  80. 6fwedzs3w3fg.exe
  81. 77be0dd6570301acac3634801676b5d7
  82.  
  83. FICKER STEALER C2
  84. http://sweyblidian.com
  85.  
  86. COBALT STRIKE PAYLOAD URLS
  87. http://mymooney.ru/0103.bin
  88. http://mymooney.ru/0103s.bin
  89.  
  90. COBALT STRIKE FILE HASHES
  91. 0103.bin
  92. 51e57f45762d279776b98d27f415ce6c
  93.  
  94. 0103s.bin
  95. ab918b8f731858bef1b8994608ffb66d
  96.  
  97. COBALT STRIKE TRAFFIC
  98. http://45.63.69.93/Qn7f
  99. http://45.63.69.93/cx
  100.  
Advertisement
Add Comment
Please, Sign In to add comment