ExecuteMalware

2020-11-10 Hancitor IOCs

Nov 10th, 2020 (edited)
4,358
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.48 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Electronic Signature Service
  6. You got invoice from DocuSign Service
  7. You got invoice from DocuSign Signature Service
  8. You got notification from DocuSign Electronic Service
  9. You got notification from DocuSign Electronic Signature Service
  10. You got notification from DocuSign Service
  11. You got notification from DocuSign Signature Service
  12. You received invoice from DocuSign Electronic Service
  13. You received invoice from DocuSign Service
  14. You received invoice from DocuSign Signature Service
  15. You received notification from DocuSign Electronic Service
  16. You received notification from DocuSign Electronic Signature Service
  17. You received notification from DocuSign Service
  18. You received notification from DocuSign Signature Service
  19.  
  20. SENDERS OBSERVED
  21.  
  22. MALDOC PROXY URLS
  23. https://docs.google.com/document/d/e/2PACX-1vQnoRr4CxkhGNNtYmXL47etHQ8s5SWMjiiXsJiBPkWruRM2JVjH6OfuHaJvzZHq7vo5UnSUdN-zI5iR/pub
  24. https://docs.google.com/document/d/e/2PACX-1vQo2AQeCB2a9hjDFxdhtpKF60NybVjxD5MQit0y5uiyQ975GoB1oNVAhly4fO2-QPC-bHpiH-AB38_l/pub
  25. https://docs.google.com/document/d/e/2PACX-1vQO6kczpZKQlvDX34Q6i28dVT6m5O4abKnueFPUkyXJH0-DYSl_9fn0ENl-X_Ln2f40E0J0q%0D%0Ar7AO0Lf/pub
  26. https://docs.google.com/document/d/e/2PACX-1vQO6kczpZKQlvDX34Q6i28dVT6m5O4abKnueFPUkyXJH0-DYSl_9fn0ENl-X_Ln2f40E0J0qr7AO0Lf/pub
  27. https://docs.google.com/document/d/e/2PACX-1vQPGnoS9sdusc9f6pJ92xarOR5zHKU43uyALyYSxx3bccMnqIukPDhJYZCtEEt9Gk7n_eEojIE-E2ID/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQw_fXxK1YprhQUbfli7XsIueQ-dt7zUFA_09N9mKFACKIMrjo2qRv0atw9E84NdBG2vHHRX7s-jK-F/pub
  29. https://docs.google.com/document/d/e/2PACX-1vQYrbq2YvGgXOw9mmDNrHQtTGNOaQvnMw_i0KW92JOUQKqMm0LC-T_NHyayaPFdo0N9A3EZqRgoVXhF/pub
  30. https://docs.google.com/document/d/e/2PACX-1vQzgCfHvLHR3MFowBMd0gzYKdinrK49qzYuu7hQGpA_-3tLGzZ-7YQCgwv1JLTj09K4m7r21%0D%0A5EwhMkk/pub
  31. https://docs.google.com/document/d/e/2PACX-1vQzgCfHvLHR3MFowBMd0gzYKdinrK49qzYuu7hQGpA_-3tLGzZ-7YQCgwv1JLTj09K4m7r215EwhMkk/pub
  32. https://docs.google.com/document/d/e/2PACX-1vReql3LgZo22AjZWzuZlY1x5M4FD2PJU2BiqvQYhtyswbMdCoo0eld1EOpSbitkGGH-hx5qdpDk_7-R/pub
  33. https://docs.google.com/document/d/e/2PACX-1vRHtAkIul64aftt7JQUKkSO7lUHaixqcds6K7CDLx5H_aYWr6HUO1656STQ4vxVI0juLLqPfZBtQDmQ/pub
  34. https://docs.google.com/document/d/e/2PACX-1vRJHn57p6sYuxq2-1SZHVDudhYR6FhGOOoiciq-QsnthxaL4uRHr9VrZlEbJyBo6ZOcdTwWP1Ed_xeC/pub
  35. https://docs.google.com/document/d/e/2PACX-1vRJrh5C_FYRSxW7_AyPfMZ4pPNXWg7IfC6DIyu55wy2cn3fUEVCE7jL-P78o1p3Z6aCHbs0tOso1cyx/pub
  36. https://docs.google.com/document/d/e/2PACX-1vRkeMym6iOZ4WV5ntlGyTbtqrt1Qkco-U3jnDWNh6gbhu4G3iLdLFrcMqWZCrc203cJhztxPKIw150S/pub
  37. https://docs.google.com/document/d/e/2PACX-1vRNTDt6fGFsVbhy7xr67buNeTlRoA2RPdJ5V-mb-DNjqXXV0oIv0hokeXpexQ7pZnthAbKRHSRCi6ws/pub
  38. https://docs.google.com/document/d/e/2PACX-1vRP90HyOapfMcl10IVu-04t0N2Mh0oIv9sGjbELL1vuD4034-t9hKqB_kIMfiG_YyBHOK0uJcQtmj3r/pub
  39. https://docs.google.com/document/d/e/2PACX-1vRPaNWKVrRPKU-4FHFVuis1E1pfDWZmbc5uGgGNZ2WZoGvyQ-vQd2w26qIpzPRF7xI85nqoNHTAst-5/pub
  40. https://docs.google.com/document/d/e/2PACX-1vRt6E4OKVxiGfHQtdTez8_iHGzXk19-8BdMc0OXv8_UH44M6Sp-GEQ6EsyLFy8xaCT8EyGtWfsfi7OP/pub
  41. https://docs.google.com/document/d/e/2PACX-1vRv8QLL31CgrZiZAMtknywRsTA3y1VT6JxyjODN53AvI_fMwcuchYLJiEnbIsVZLGMyX0R1zTozQm9Y/pub
  42. https://docs.google.com/document/d/e/2PACX-1vRwoWLmvRsgZWBqX_ybQtdPb8AebDD9C69qNRd40-FW3x4Vv21zopMC3JR8Lbeu_2jwe51iR%0D%0AytGw4ol/pub
  43. https://docs.google.com/document/d/e/2PACX-1vRwoWLmvRsgZWBqX_ybQtdPb8AebDD9C69qNRd40-FW3x4Vv21zopMC3JR8Lbeu_2jwe51iRytGw4ol/pub
  44. https://docs.google.com/document/d/e/2PACX-1vRWrUwcCz7wOfiZ_TvQcz9Lu3SuY-o2xzmTaPXCE8PZXmXJcnQAEple5ZR1S8pC2TU02WPSwPWScUWw/pub
  45. https://docs.google.com/document/d/e/2PACX-1vRxk6Ik6RMlR3LiCKyVt7XWaxyEBST-VVIn75cUndu13kQSaCVdIwE3FJZJclhTB-xRjALTW5-zIHMM/pub
  46. https://docs.google.com/document/d/e/2PACX-1vRzQxOdRSDtSiLBa-WRfCd_VVI4u_aKUQTu2N2poeDAWaZ2HUgZwUOmaKTXyBzim1hERz6paxeGUkhG/pub
  47. https://docs.google.com/document/d/e/2PACX-1vRZzLUH-deBYmhsn7pxz-DSLavVmFFvRNkj3EeC6IK0H1X9ySCpuoFs4gt2dWA27yUJantIl2JC0ui-/pub
  48. https://docs.google.com/document/d/e/2PACX-1vS4uA3kEN3V498yzAX9__80gLIxmbQ5Qwa5jhJHWDDS8kwBAbsB97KxWG_uniqCmXEX-NjlnwVqYuqu/pub
  49. https://docs.google.com/document/d/e/2PACX-1vSavApbfZn2kXVtdrZ1qizqbj4ss3HbEti48w1YaiDNrNHBJWfDfzF1HXrqAAc79mD5HlDLZiB_SW-Y/pub
  50. https://docs.google.com/document/d/e/2PACX-1vSiXWGl4k3SKXWQBK7WF7coo_SSICJmaFa9LneYtnuSR-XJ8Ju3PP6AM7jXL1CXymaOpzy2VlHV7ElB/pub
  51. https://docs.google.com/document/d/e/2PACX-1vSPF9RFFVduT-e-50aBLu1YYC9FDM4lHXEgTX-AFLeMxnbjO-yoUh5bfu9ZQ8Q3JkADlR2Y5%0D%0AHL2oNNA/pub
  52. https://docs.google.com/document/d/e/2PACX-1vSPF9RFFVduT-e-50aBLu1YYC9FDM4lHXEgTX-AFLeMxnbjO-yoUh5bfu9ZQ8Q3JkADlR2Y5HL2oNNA/pub
  53. https://docs.google.com/document/d/e/2PACX-1vSv6YHyh27I1rv3ZhXtmED5UMBOlpbOtqVl0dDyW3DDckNeEwepr9ct-VQKtUvV1OG3DXgtZpC8SFjY/pub
  54. https://docs.google.com/document/d/e/2PACX-1vT7I7AgtHLmparcxKWWUj6UQ89fQwcvWnrGKrvCElkhJwBwQmyANlpz4Qet5ku3dv0hC-SdCx17Mp2G/pub
  55. https://docs.google.com/document/d/e/2PACX-1vTeYpISYhaKAhUNyN44VZbS8gbfR97C4_fXkrkctW2vQOPh1Z-bEHlrDIzlZiqYhflc_7cys5KgvSC4/pub
  56. https://docs.google.com/document/d/e/2PACX-1vTQD98SAMWxrpQukvQU6rnoA0TShM_X3cNlos1hOQ0YM8kPalzuHgHFlrbLG73YCkwAkMQll5StgvOq/pub
  57. https://docs.google.com/document/d/e/2PACX-1vTU4fSvHAIYBfY_6WCshXXqtqV98uYiDb7MtnNUODRatY8yadwbHzRUG5iHMXiGrDcYdwSyBGGxVd3D/pub
  58.  
  59. MALDOC DISTRIBUTION URLS
  60. http://actorwebsitereview.com/gun.php
  61. http://agroturismemallorca.com/ride.php
  62. http://allinclusivemajorca.com/domestic.php
  63. http://demo2.brand-chemist.com/stealthily.php
  64. http://mallorca.buzz/adolescent.php
  65. http://mallorcamedical.com/monochroic.php
  66. https://airborne.pro/soph.php
  67. https://crazydeal101.com/alacrity.php
  68. https://edukare.info/matriculate.php
  69. https://hidrautest.com.br/bacteriology.php
  70. https://hidrautest.com.br/correctness.php
  71. https://imugan.com/starfish.php
  72. https://rumahsyariahmks.com/yahweh.php
  73. https://sedgefuneralplan.com/circulatory.php
  74. https://spertoglass.com/memoranda.php
  75. https://spertoglass.com/stapedes.php
  76. https://spertoglass.com/therms.php
  77. https://wordpress.manpow.co/starves.php
  78.  
  79. MALDOC FILE HASHES
  80. 1110_74634.doc
  81. 2e09612f1a523f862ba91e4260dc4a9c
  82.  
  83. HANCITOR DOWNLOAD URLS
  84. Embedded in the Word document
  85.  
  86. HANCITOR PAYLOAD FILE HASHES
  87. 22.mp4
  88. 15e3a3bba36953e8492a64b55be03bb7
  89.  
  90. HANCITOR C2
  91. http://codathegorthe.ru/8/forum.php
  92. http://julthatpallike.ru/8/forum.php
  93. http://trideprere.com/8/forum.php
  94.  
  95. FICKER STEALER DOWNLOAD URLS
  96. http://tennysondonehue.com/f44.exe
  97.  
  98. FICKER STEALER FILE HASHES
  99. f44.exe
  100. 1db6bd4d13cb9966e8875b3812aef71d
  101.  
  102. I also saw DNS queries to:
  103. taftahrice.com: type A, class IN
  104. cussoricti.com: type A, class IN
  105.  
Advertisement
Add Comment
Please, Sign In to add comment