-
Notifications
You must be signed in to change notification settings - Fork 84
/
2021-10-19 Hancitor IOCs
222 lines (205 loc) · 7.35 KB
/
2021-10-19 Hancitor IOCs
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
THREAT IDENTIFICATION: HANCITOR / COBALT STRIKE
HANCITOR BUILD NUMBER
BUILD=1910_nsw
SUBJECTS OBSERVED
You got invoice from DocuSign Electronic Service
You got invoice from DocuSign Electronic Signature Service
You got invoice from DocuSign Service
You got invoice from DocuSign Signature Service
You got notification from DocuSign Electronic Service
You got notification from DocuSign Electronic Signature Service
You got notification from DocuSign Service
You got notification from DocuSign Signature Service
You received invoice from DocuSign Electronic Service
You received invoice from DocuSign Electronic Signature Service
You received invoice from DocuSign Service
You received invoice from DocuSign Signature Service
You received notification from DocuSign Electronic Service
You received notification from DocuSign Electronic Signature Service
You received notification from DocuSign Service
You received notification from DocuSign Signature Service
SENDERS OBSERVED
MALDOC FEEDPROXY DISTRIBUTION URLS
http://feedproxy.google.com/~r/aixvhpqpoqa/~3/CK6SMcZGXV8/denial.php
http://feedproxy.google.com/~r/aizjsca/~3/IqJ0LrwShVo/wrongfulness.php
http://feedproxy.google.com/~r/akbzcjepaco/~3/PRMwnIp1_FE/xebec.php
http://feedproxy.google.com/~r/bexvm/~3/ILzMudKcWfA/nonmonotonic.php
http://feedproxy.google.com/~r/cjyxbk/~3/cur3YJHpEZI/finnish.php
http://feedproxy.google.com/~r/dlndvfsizeh/~3/UVCmkRYIT4E/wadded.php
http://feedproxy.google.com/~r/gbwbgal/~3/ua5OXu_koek/drummer.php
http://feedproxy.google.com/~r/hfnins/~3/jpWDgnKmHbs/be.php
http://feedproxy.google.com/~r/jzmxkeq/~3/tu_2HZY174w/abide.php
http://feedproxy.google.com/~r/klmpkeyqtu/~3/IBa__SMRxwI/boudoir.php
http://feedproxy.google.com/~r/lmbadsa/~3/tu_2HZY174w/abide.php
http://feedproxy.google.com/~r/mhxzawximuk/~3/9Js5KrooBHA/petersburg.php
http://feedproxy.google.com/~r/mqzlb/~3/4ReN59_PB_o/moan.php
http://feedproxy.google.com/~r/mybjeciew/~3/UVCmkRYIT4E/wadded.php
http://feedproxy.google.com/~r/nevvk/~3/fAU-x0IFuyI/tumor.php
http://feedproxy.google.com/~r/nwxlldt/~3/iLjKCapiIOI/thesauri.php
http://feedproxy.google.com/~r/ofdxvegcof/~3/M0QQ60yFNuw/yacht.php
http://feedproxy.google.com/~r/opixkaui/~3/YwOYjEG6qCM/ophthalmology.php
http://feedproxy.google.com/~r/oxpix/~3/-8GY5e5dkKY/musicale.php
http://feedproxy.google.com/~r/qbucdiyhqr/~3/KzYIP1O7Luw/analyse.php
http://feedproxy.google.com/~r/skskcun/~3/cxeeZlsNwqM/larynx.php
http://feedproxy.google.com/~r/tmmiwf/~3/FxI0geFIskY/cloakroom.php
http://feedproxy.google.com/~r/tthcd/~3/WmS4gNxGn7M/symbolic.php
http://feedproxy.google.com/~r/uhieciibmxa/~3/9nbeMhyfsYQ/extend.php
http://feedproxy.google.com/~r/uyalsygd/~3/7jqRdvyVVTM/prevalent.php
http://feedproxy.google.com/~r/vksoyzsl/~3/2yxebV6qc1k/pseudoscience.php
http://feedproxy.google.com/~r/vvcmekmxk/~3/9Js5KrooBHA/petersburg.php
http://feedproxy.google.com/~r/vyehpdkrm/~3/dCC6hEag_Lw/readies.php
http://feedproxy.google.com/~r/wbkejfmk/~3/w8zlT4lU10s/falter.php
http://feedproxy.google.com/~r/wuigaaw/~3/rQv-sPjeMGY/opposite.php
http://feedproxy.google.com/~r/xnzsccfdkct/~3/9Js5KrooBHA/petersburg.php
http://feedproxy.google.com/~r/xojsam/~3/OHwRdueCpO4/duration.php
http://feedproxy.google.com/~r/yeejioe/~3/fAU-x0IFuyI/tumor.php
http://feedproxy.google.com/~r/yffsiwni/~3/ILzMudKcWfA/nonmonotonic.php
http://feedproxy.google.com/~r/yplrgkbd/~3/XjuTOh5ZRsI/spicate.php
http://feedproxy.google.com/~r/yvqtiev/~3/JtPZt2jC938/chastity.php
MALDOC REDIRECT URLS
http://bharattank.me/extend.php
http://bhushankoli.com/be.php
http://bhushankoli.com/boudoir.php
http://bhushankoli.com/drummer.php
http://bhushankoli.com/spicate.php
http://blog.drmostafafouadivf.com/analyse.php
http://blog.drmostafafouadivf.com/falter.php
http://blog.drmostafafouadivf.com/wrongfulness.php
http://custominsure.com/finnish.php
http://custominsure.com/musicale.php
http://dev.promoscredits.com/symbolic.php
http://dulhagharnh.com/moan.php
http://dulhagharnh.com/nonmonotonic.php
http://dulhagharnh.com/prevalent.php
http://dulhagharnh.com/tumor.php
http://francdoc.webdev-wazoomstudio.online/ophthalmology.php
http://healthzoneapp.com/chastity.php
http://healthzoneapp.com/readies.php
http://hewadexchange.com/wadded.php
http://m.ashiwenhua.net/denial.php
http://mcybersoft.com/abide.php
http://mcybersoft.com/cloakroom.php
http://novostroyka812.ru/thesauri.php
http://portal.senseaonline.in/duration.php
http://tartaklegnica.pl/larynx.php
http://tartaklegnica.pl/pseudoscience.php
http://tartaklegnica.pl/yacht.php
https://bharattank.me/extend.php
https://bhushankoli.com/be.php
https://bhushankoli.com/boudoir.php
https://bhushankoli.com/drummer.php
https://bhushankoli.com/spicate.php
https://blog.drmostafafouadivf.com/wrongfulness.php
https://dulhagharnh.com/nonmonotonic.php
https://dulhagharnh.com/tumor.php
https://francdoc.webdev-wazoomstudio.online/ophthalmology.php
https://healthzoneapp.com/chastity.php
https://iptel.cy/opposite.php
https://mcybersoft.com/abide.php
https://mcybersoft.com/cloakroom.php
https://novostroyka812.ru/thesauri.php
https://portal.senseaonline.in/duration.php
https://tartaklegnica.pl/larynx.php
https://www.cardpay365.com/petersburg.php
https://www.cardpay365.com/xebec.php
ashiwenhua.net
bharattank.me
bhushankoli.com
cardpay365.com
custominsure.com
drmostafafouadivf.com
dulhagharnh.com
healthzoneapp.com
hewadexchange.com
iptel.cy
mcybersoft.com
novostroyka812.ru
promoscredits.com
senseaonline.in
tartaklegnica.pl
webdev-wazoomstudio.online
MALDOC FILE HASHES
07e5175afd01bd35512189731d10f8a6
1d6dfb73231da40c6d151d2e8680fb47
687eb332db14b04e7a7820fb0d1a3201
EMBEDDED DOC FILE HASH
zoro.doc
b6487ba7cff8bd5748c8dfa1f7db100c
HANCITOR PAYLOAD FILE HASH
gelforr.dap
4198ac1dc34de77ab8ceac3c9a25480e
HANCITOR C2
http://gintlyba.ru/8/forum.php
http://newnucapi.com/8/forum.php
http://stralonz.ru/8/forum.php
COBALT STRIKE STAGER DOWNLOAD URLS
http://alh1mik.ru/195.bin
http://alh1mik.ru/195s.bin
COBALT STRIKE STAGER FILE HASHES
195.bin
b6a2f7018628bf0e775cdf38efb44201
195s.bin
3e2cadcaa1f3c68860dc93314e8f193d
COBALT STRIKE BEACON DOWNLOAD URLS
http://135.148.120.195/DmBi
http://135.148.120.195:443/TjVH
COBALT STRIKE BEACON FILE HASHES
TjVH
5ec6fe1350996590db43ba440e4b6848
DmBi
5325e4005453b39c76b461ae9f243ae2
COBALT STRIKE C2s
http://135.148.120.195/dpixel
http://135.148.120.195:443/ca