forked from executemalware/Malware-IOCs
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy path2021-09-09 Hancitor IOCd
164 lines (147 loc) · 5.87 KB
/
2021-09-09 Hancitor IOCd
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
THREAT IDENTIFICATION: HANCITOR / COBALT STRIKE
HANCITOR BUILD NUMBER
BUILD=0909_zyap
SUBJECTS OBSERVED
You got invoice from DocuSign Electronic Service
You got invoice from DocuSign Electronic Signature Service
You got invoice from DocuSign Service
You got invoice from DocuSign Signature Service
You got notification from DocuSign Electronic Service
You got notification from DocuSign Electronic Signature Service
You got notification from DocuSign Service
You got notification from DocuSign Signature Service
You received invoice from DocuSign Electronic Service
You received invoice from DocuSign Electronic Signature Service
You received invoice from DocuSign Service
You received notification from DocuSign Electronic Service
You received notification from DocuSign Electronic Signature Service
You received notification from DocuSign Service
You received notification from DocuSign Signature Service
SENDERS OBSERVED
MALDOC FEEDPROXY DISTRIBUTION URLS
http://feedproxy.google.com/~r/ayaqatksu/~3/KKaUYo8u9Uo/affordably.php
http://feedproxy.google.com/~r/chdlhxulsi/~3/bFYzqqyN_5g/implode.php
http://feedproxy.google.com/~r/ckihqm/~3/nLzL-0QVuJ0/marshal.php
http://feedproxy.google.com/~r/cqbooaqsb/~3/UHuFvcdA1ZE/prefab.php
http://feedproxy.google.com/~r/dctgachgm/~3/EyqptEVV8So/coreligionist.php
http://feedproxy.google.com/~r/domygsmrrs/~3/XBcs8ywlqXc/resolute.php
http://feedproxy.google.com/~r/dytrmfvq/~3/eunSyFIk0LQ/subjection.php
http://feedproxy.google.com/~r/fimptiivnos/~3/XSuT1ZjfmhI/toolbox.php
http://feedproxy.google.com/~r/fnizs/~3/obv_cqSlGLM/affordably.php
http://feedproxy.google.com/~r/hiwhladgg/~3/6JqGEvGhB3k/coatroom.php
http://feedproxy.google.com/~r/hxauvicrzwv/~3/E2ix2vjM6Bc/lithuanian.php
http://feedproxy.google.com/~r/istaihhm/~3/k0R_Z1tGWZg/zap.php
http://feedproxy.google.com/~r/jhbmnea/~3/1Slk64BZHfw/redhead.php
http://feedproxy.google.com/~r/jiycllchrnb/~3/GEcv6WMArRk/pastelist.php
http://feedproxy.google.com/~r/kwawnh/~3/O5iaj7-u-tA/schools.php
http://feedproxy.google.com/~r/lpapjxkqeif/~3/qWp_MHrrOt0/niece.php
http://feedproxy.google.com/~r/lysgfpgvld/~3/vos1VPHYKrU/aortic.php
http://feedproxy.google.com/~r/mrvqaoxfn/~3/XBcs8ywlqXc/resolute.php
http://feedproxy.google.com/~r/nqzprzswysb/~3/Pk5oIfZXehA/trundle.php
http://feedproxy.google.com/~r/odhcnrw/~3/tW-wRCmmFF8/unshielded.php
http://feedproxy.google.com/~r/pkrct/~3/bTntvy7WkaQ/dicotyledonous.php
http://feedproxy.google.com/~r/pmlme/~3/6eB5okSh2Es/prometheus.php
http://feedproxy.google.com/~r/qlirzpnkgg/~3/PQl146ocP-k/pedagogy.php
http://feedproxy.google.com/~r/rebcyip/~3/WtRrS7g0jWM/seeding.php
http://feedproxy.google.com/~r/stvrtojjpa/~3/Y6ZYFD1Msuc/yang.php
http://feedproxy.google.com/~r/tgnrfblw/~3/k3QAKOOXbDI/theosophist.php
http://feedproxy.google.com/~r/tyrserlcret/~3/6PCM40qG5nU/aggregative.php
http://feedproxy.google.com/~r/tyzgkyfvk/~3/k0R_Z1tGWZg/zap.php
http://feedproxy.google.com/~r/tzfosxhw/~3/M9js6BjYRn0/acarpelous.php
http://feedproxy.google.com/~r/vlbdadaclwp/~3/NOd5dr1MKLw/arrhythmias.php
http://feedproxy.google.com/~r/wfmgqalpee/~3/14SWNbimXZQ/strolling.php
http://feedproxy.google.com/~r/wpmhjmkgnvc/~3/jC6TC9djC0A/ample.php
http://feedproxy.google.com/~r/xayrfta/~3/a9K8ZPTBub0/trillium.php
http://feedproxy.google.com/~r/zbjuikjbfx/~3/yeWOZZ7RX1c/wracked.php
http://feedproxy.google.com/~r/zmfmygrmys/~3/GVxcGYh6u_s/neighborhood.php
http://feedproxy.google.com/~r/zuygdqnf/~3/LyhnHuwNaaA/dran.php
MALDOC REDIRECT DOWNLOAD URLS
http://ah.btp-inc.ca/yang.php
http://ani-immigration.com/unshielded.php
http://dermasmart.org/neighborhood.php
http://futurespace.orbitships.org/pastelist.php
http://newdevjyq.devjyq.com/toolbox.php
http://salonways.com/dicotyledonous.php
http://salonways.com/redhead.php
ani-immigration.com
btp-inc.ca
dermasmart.org
devjyq.com
orbitships.org
salonways.com
MALDOC FILE HASHES
6efcbcc36340f4f4c54b3410ab72091c
2f7f25afc1699d8bc376552bcef67a09
EMBEDDED DOC FILE HASH
reform.doc
6ef57b9ce972938abc0f04b368ce8443
HANCITOR PAYLOAD FILE HASH
hhhh.mp3
93550847b83aa1c0d367a60ed4de0e4c
HANCITOR C2
http://calloyean.ru/8/forum.php
http://fulgeterly.ru/8/forum.php
http://goramilly.ru/8/forum.php
COBALT STRIKE STAGER DOWNLOAD URLS
http://furu7nu.ru/0909.bin
http://furu7nu.ru/0909s.bin
COBALT STRIKE STAGER FILE HASHES
0909.bin
8270b7dc614041c96f860ae0c563087f
0909s.bin
202da014c544091cbcbcbb447629adbe
COBALT STRIKE BEACON DOWNLOAD URLS
https://107.155.127.246/jcCL
http://107.155.127.246/eGXX
COBALT STRIKE BEACON FILE HASHES
eGXX
e56b336cfbbfbe97b835f72bbd6a68da
jcCL
bd1afec6332b7133bd88297a77fd8334
COBALT STRIKE C2s
https://107.155.127.246/j.ad
http://107.155.127.246/fwlink