ExecuteMalware

2021-06-22 Hancitor IOCs

Jun 22nd, 2021 (edited)
17,184
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.78 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2106_xhidt
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Signature Service
  8. You got invoice from DocuSign Service
  9. You got invoice from DocuSign Signature Service
  10. You got notification from DocuSign Electronic Service
  11. You got notification from DocuSign Service
  12. You got notification from DocuSign Signature Service
  13. You received invoice from DocuSign Electronic Service
  14. You received invoice from DocuSign Electronic Signature Service
  15. You received invoice from DocuSign Service
  16. You received invoice from DocuSign Signature Service
  17. You received notification from DocuSign Electronic Service
  18. You received notification from DocuSign Electronic Signature Service
  19. You received notification from DocuSign Service
  20. You received notification from DocuSign Signature Service
  21.  
  22. SENDERS OBSERVED
  23.  
  24. MALDOC PROXY DISTRIBUTION URLS
  25. http://feedproxy.google.com/~r/afpavjrzsq/~3/tHOiExRei-g/digestible.php
  26. http://feedproxy.google.com/~r/bkhasyobl/~3/WeIBU6KZXYk/digging.php
  27. http://feedproxy.google.com/~r/buugwwqmgd/~3/fPSv3F8HzKk/dogwood.php
  28. http://feedproxy.google.com/~r/bvbrkzjjuz/~3/yEzDDHR1wR8/columbus.php
  29. http://feedproxy.google.com/~r/dxsbow/~3/S6h_71K466w/tamely.php
  30. http://feedproxy.google.com/~r/eucmfnrduo/~3/uPiStd51NxE/surfeiting.php
  31. http://feedproxy.google.com/~r/ezpazywgeqq/~3/oEO4H0zsVsc/slag.php
  32. http://feedproxy.google.com/~r/jgfof/~3/X7EC-SZw2zc/buffoon.php
  33. http://feedproxy.google.com/~r/jtupivnc/~3/WMrF0nEDtxQ/oscillated.php
  34. http://feedproxy.google.com/~r/lrhearkwquj/~3/MXcwIvlGyko/selenology.php
  35. http://feedproxy.google.com/~r/mfazpb/~3/_CpRojrSJAk/cubism.php
  36. http://feedproxy.google.com/~r/mmahllh/~3/_OcWnYN0Mp4/escaped.php
  37. http://feedproxy.google.com/~r/oifmjgou/~3/h-_2tzanl8Y/archbishopric.php
  38. http://feedproxy.google.com/~r/phngfkgkxoi/~3/sfDO2k40ChA/curler.php
  39. http://feedproxy.google.com/~r/pujvwj/~3/dYz3dayeyhE/as.php
  40. http://feedproxy.google.com/~r/smlwbncw/~3/za2an2RFOh4/uncooked.php
  41. http://feedproxy.google.com/~r/ttxdbqvqfd/~3/2B4FeTzJUwM/milk.php
  42. http://feedproxy.google.com/~r/ufxfgoguir/~3/iJBUj6DZBSQ/annelid.php
  43. http://feedproxy.google.com/~r/wwvevtycwkv/~3/bbV106ekAkg/offhand.php
  44. http://feedproxy.google.com/~r/wxzthhfycuc/~3/JNPudq6MD6U/sortie.php
  45. http://feedproxy.google.com/~r/zfofzz/~3/zxzTP3yfQqI/apeasement.php
  46.  
  47. MALDOC REDIRECT DOWNLOAD URLS
  48. http://coba.msp-id.com/buffoon.php
  49. http://dalaceducate.com/oscillated.php
  50. http://firstaidbar.parachuteconsultingllc.com/columbus.php
  51. http://floristeria-ilusion.com/annelid.php
  52. http://floristeria-ilusion.com/escaped.php
  53. http://floristeria-ilusion.com/offhand.php
  54. http://luvurself.co.in/tamely.php
  55. http://luvurself.co.in/uncooked.php
  56. http://main.lahoreshoes.com/apeasement.php
  57. http://main.lahoreshoes.com/digestible.php
  58. http://main.lahoreshoes.com/milk.php
  59. http://main.lahoreshoes.com/sortie.php
  60. http://pamenagreens.com/as.php
  61. http://pamenagreens.com/curler.php
  62. http://parueltoys.com/surfeiting.php
  63. http://sfl-condoexpert.com/cubism.php
  64. http://test.ivoireboutik.ci/selenology.php
  65. http://tutimovil.com/dogwood.php
  66. http://www.amranhvac.com/archbishopric.php
  67. http://www.amranhvac.com/digging.php
  68.  
  69. amranhvac.com
  70. dalaceducate.com
  71. floristeria-ilusion.com
  72. ivoireboutik.ci
  73. lahoreshoes.com
  74. luvurself.co.in
  75. msp-id.com
  76. pamenagreens.com
  77. parachuteconsultingllc.com
  78. parueltoys.com
  79. sfl-condoexpert.com
  80. tutimovil.com
  81.  
  82. HANCITOR MALDOC FILE HASHES
  83. 1a59ceac9950a65bfc6f1b48e90069cb
  84. 1b078fa68ab61137698ec90b248b3a41
  85. 253cd14997221a45cefc5af71899225c
  86. 661addd0800c78c582a91971097436cb
  87. 8edfb2978ec5d8bea344f66b08b52e4b
  88. ad722cfceae43ac474649d028cd20078
  89. d6537faa40b3a1f9aea71451daf4dfa7
  90. e4b5102981531c4b23ddd286a10fbd74
  91. e76139e98a50f583ddf813eba72340b3
  92. ecc1216b4d36f5451a5abb2c54f4e7e5
  93. f04b83f20d19dc41825c9b8faed3ddb8
  94.  
  95. HANCITOR PAYLOAD FILE HASH
  96. kikus.dll
  97. cc915aa31f31934ab132f45bf965d200
  98.  
  99. HANCITOR C2
  100. http://vidompleury.com/8/forum.php
  101. http://cobleignespos.ru/8/forum.php
  102. http://moutraturche.ru/8/forum.php
  103.  
  104. FICKER STEALER DOWNLOAD URL
  105. http://t578qnar.ru/7sdf45gsg.exe
  106.  
  107. FICKER STEALER FILE HASH
  108. 7sdf45gsg.exe
  109. 270c3859591599642bd15167765246e3
  110.  
  111. FICKER C2
  112. http://pospvisis.com
  113.  
  114. COBALT STRIKE STAGER PAYLOAD URLS
  115. http://t578qnar.ru/2206.bin
  116. http://t578qnar.ru/2206s.bin
  117.  
  118. COBALT STRIKE STAGER FILE HASHES
  119. 2206s.bin
  120. 4dca76922be24b36a8060653f8862a00
  121.  
  122. 2206.bin
  123. 9f6ce0d2896378d173db713033c6c955
  124.  
  125. COBALT STRIKE BEACON
  126. http://45.136.113.163/KakE
  127.  
  128. KakE
  129. aad493200a6a03e07968616d52124c97
  130.  
  131. COBALT STRIKE C2
  132. http://45.136.113.163/push
  133.  
Advertisement
Add Comment
Please, Sign In to add comment