ExecuteMalware

2021-03-30 Hancitor IOCs

Mar 30th, 2021 (edited)
16,442
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.47 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD: 3003_verio
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got notification from DocuSign Electronic Signature Service
  11. You got notification from DocuSign Service
  12. You got notification from DocuSign Signature Service
  13. You received invoice from DocuSign Electronic Signature Service
  14. You received invoice from DocuSign Signature Service
  15. You received notification from DocuSign Electronic Service
  16. You received notification from DocuSign Electronic Signature Service
  17. You received notification from DocuSign Signature Service
  18.  
  19. SENDERS OBSERVED
  20.  
  21. MALDOC LANDING PAGE URLS
  22. https://docs.google.com/document/d/e/2PACX-1vQV1Y7N0-q-0vCctsRjOdqtJ2d8YChDHAdY4HqHjIkrpVMSuuOFHQub6GHNacx74GC-lljtyw-VHMF0/pub
  23. https://docs.google.com/document/d/e/2PACX-1vR2le5OY6eitMTv7OV1eLn4--MYdrdJ0SRvjR40Mn4hyK2BMWWiGSh67_cD0GsBRGes3ipUBNlZdTjR/pub
  24. https://docs.google.com/document/d/e/2PACX-1vRAgFOqsHYGVq7BZ-cm5gtcK_Gh5rGzd5vJvVloYtI5XeZGV1EgHAVlRmjS7JlO_CuFdZ10TbQjUJBV/pub
  25. https://docs.google.com/document/d/e/2PACX-1vSKhMosGJRhAx6nPKG1CxRA5OqFCouT4mAn581iigdj6E0kW5E7pkDM7rzgT4lHSD2w4pbfIDgqO16u/pub
  26. https://docs.google.com/document/d/e/2PACX-1vSllYUcuuUT4iqwFmWWSBAi4ZnCIJfd_I7MpP8pN7_D_kvyVtrFaSRUUStKL19a4N8XVHOboTo2p1S4/pub
  27. https://docs.google.com/document/d/e/2PACX-1vSRfbQEHuTyQW0eqqmAmeC8gNg8L9WUju07_rv4tHRn-eNfCzflVELccrZKo1Vs0h9BlE5HECXJLzrK/pub
  28. https://docs.google.com/document/d/e/2PACX-1vSSt6CrA6bUtz5gwU3mv6B8tCak80azHhLnd6dMsM_XVaxj7q13YfnYOikhuYuhOm2m29tG6se7t5PG/pub
  29. https://docs.google.com/document/d/e/2PACX-1vT4DehaB_ZFCPUCo6FPTyk0AwDNQHkO55-zrMUMiTCP9S3WYEuXa4E7qklLSmx0aT3kuGKV7EhibYF1/pub
  30. https://docs.google.com/document/d/e/2PACX-1vTCL_qjggEFoZ4wzusYvmPLV_mrOXN0FYiKApb3644JPU8Ivd5wKWf1p7nfb8u6GvDiMWZ2XDABkYHQ/pub
  31. https://docs.google.com/document/d/e/2PACX-1vTi15ayB8KwOrXxIaCUH1d03KK9-aUl7SRrqsLRzUmkoQydto93KgEMKBC8mqc2GDxUwJKb7GLERXyh/pub
  32. https://docs.google.com/document/d/e/2PACX-1vToBxyjYpZycUcRkK7RAHru3il-bWv7vaLAK_102cOZPv3Ff8pqbwda0pZQK8S2apVVvW-puhjQzLd3/pub
  33. https://docs.google.com/document/d/e/2PACX-1vTOPtRbRsBAmqOcP8PdkQ6TmvxMCD-AHEqSL76R7uk-c9TRHWajt-e_iYQ2iQ1LtG36wjH7ZkvinoNB/pub
  34. https://docs.google.com/document/d/e/2PACX-1vTqyJd8ZQl6kbLiiqbI-jsAQNUJBccElVWHzJBxIy7Mo11lUqD-bemTtPGfGjeGDOvReqs7IMX_VwBd/pub
  35. https://docs.google.com/document/d/e/2PACX-1vTslVGTV3rPJYFKSK2ulbm3mnGbSU1xUy02AwSWY9Qu_XzZeoCSMdJu63rmyQXH8hEFxissf_Yd6qiN/pub
  36.  
  37. MALDOC DISTRIBUTION URLS
  38. http://tlfthelifefactory.com.au/fee.php
  39. http://www.capitallifesyariah.co.id/replay.php
  40. https://capasa.com.my/cycle.php
  41. https://koonol.mx/personably.php
  42. https://lt.app.krazyit.com.au/egor.php
  43. https://moradaimoveisjab.com.br/cranky.php
  44. https://pharmaciebougieba.org/gel.php
  45. https://uberum.ro/anoint.php
  46. https://uniquewebservice.com/wail.php
  47.  
  48. capasa.com.my
  49. capitallifesyariah.co.id
  50. koonol.mx
  51. krazyit.com.au
  52. moradaimoveisjab.com.br
  53. pharmaciebougieba.org
  54. tlfthelifefactory.com.au
  55. uberum.ro
  56. uniquewebservice.com
  57.  
  58. HANCITOR MALDOC FILE HASHES
  59. 3448cc288fca67901056db4fa75d65c5
  60. 570ea5f20ea57233801e4d8c5fbcf472
  61. 79f7b1808de6aa49e4775799b0203329
  62. 7ca22c035af153396354116cb1db11df
  63. e16b4f91101a452b9a2c5eceb8985cec
  64. fa3799eabf27a6c2c7834f48e5134088
  65. ff0131c3bad0b18758a03950179220e0
  66.  
  67. HANCITOR PAYLOAD FILE HASH
  68. Runtime.dll
  69. c1e73a655d6cb7e796d2e490d03714c5
  70.  
  71. HANCITOR C2
  72. http://stionicksilid.com/8/forum.php
  73. http://succupenous.ru/8/forum.php
  74. http://cappiasstising.ru/8/forum.php
  75.  
  76. FICKER STEALER PAYLOAD URLS
  77. http://q17ar45.ru/689uksdffs.exe
  78.  
  79. FICKER STEALER FILE HASH
  80. 689uksdffs.exe
  81. 77be0dd6570301acac3634801676b5d7
  82.  
  83. FICKER STEALER C2
  84. http://sweyblidian.com
  85.  
  86. COBALT STRIKE PAYLOAD URLS
  87. http://q17ar45.ru/3003.bin
  88. http://q17ar45.ru/3003s.bin
  89.  
  90. COBALT STRIKE FILE HASHES
  91. 3003.bin
  92. 02dadaeecc3d8ba4e8b59ca4d27b54c6
  93.  
  94. 3003s.bin
  95. 62a46578b147897724e7e808918994e2
  96.  
  97. COBALT STRIKE C2/ADDITIONAL TRAFFIC
  98. http://139.60.161.50/Hsp1
  99. http://139.60.161.50/load
Add Comment
Please, Sign In to add comment