ExecuteMalware

2021-02-16 Hancitor IOCs

Feb 16th, 2021 (edited)
4,837
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.31 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD=1602_78210h
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Signature Service
  10. You got notification from DocuSign Service
  11. You got notification from DocuSign Signature Service
  12. You received invoice from DocuSign Electronic Signature Service
  13. You received invoice from DocuSign Signature Service
  14. You received notification from DocuSign Electronic Signature Service
  15. You received notification from DocuSign Signature Service
  16.  
  17. SENDERS OBSERVED
  18.  
  19. MALDOC LANDING PAGE URLS
  20. https://docs.google.com/document/d/e/2PACX-1vQ-TOKSbojPiWivTRK1DaYhuhejxG-W_3gTqy3fILcXneNL2VCLiB89kHJ1j8e_S1zrdB6pGBG3BWeR/pub
  21. https://docs.google.com/document/d/e/2PACX-1vQDMHO5Wik1RGy1S9Y14PRSv89DAhgtlH7yGYw9B3YvsuDy1oviRuPFV6XWqmwBkVGxkMAXp4v8BJav/pub
  22. https://docs.google.com/document/d/e/2PACX-1vQJo0VZB21h9O0qo5m6VGJB9NQon8Zj_MRz7AsN4Qz6JQvryklXYVIgx_IDHb8Do0mhxzUZoVpNovBA/pub
  23. https://docs.google.com/document/d/e/2PACX-1vQqQsOsBMQQjS4I-UFYWwELh2usHWmp93AyQ85_UBAAW5WQIRYjCgbOuiZcHZs4Qc2wxwGqEWrr59aw/pub
  24. https://docs.google.com/document/d/e/2PACX-1vQwiFij9GqINgF948lYkjlg5iXOC-fGt9i5eioBb7yd01mJGV3-QgbYvwuzieMM3pAGy8dzZzv50S4E/pub
  25. https://docs.google.com/document/d/e/2PACX-1vR0ntAgZfXCTB5JMI3p3njZwYCDHz0zT3DvvDlfZzck9B-ENKtA-Ht9IQ2-y__-eX2fvLAlWr88F0hq/pub
  26. https://docs.google.com/document/d/e/2PACX-1vR8Egrl1ChxOD_NxrwdK1uTFMsNhoRmIOqfKHZ8oCaAFvUtpufz1jxlxp4UGeMUq_Lm4ouU_fwhHU5T/pub
  27. https://docs.google.com/document/d/e/2PACX-1vRFm3kRa3v_AtHbzGX0SmctZ4d_vz3MhM7_O3cpgKr8KOlpG3h-3itpEdkdj4e4DB3r1nVBTV0mDTZ0/pub
  28. https://docs.google.com/document/d/e/2PACX-1vRwUR6I2FR_0zACu6mmotKfMk11BaV0ANnvU4yB_Izl3OAekkFyKtY4tieE1i-6bZDl1Nt9jIWlvj5b/pub
  29. https://docs.google.com/document/d/e/2PACX-1vSfT58iMzu0SNB-6Ub06QsjBzwe8Lad9PpCmE2FWeITi0Ku2_DvMpbVzUqsnw3Q5GeHUrY5gvcpR41k/pub
  30. https://docs.google.com/document/d/e/2PACX-1vSjpBv3-kauMjOLcP11Yp8DDjvNth-Qzylir8CPU03zYHevrcwX-HCB90hRkr8XQoKGu43eEP8Q_XGe/pub
  31. https://docs.google.com/document/d/e/2PACX-1vSkDg7W15UT1KJmNMYkY23Gd-SeTa2ECQBeXih13zjCHhEnLs3DX3dzCB4j6ysLbrndMtIvCV-JoXPN/pub
  32. https://docs.google.com/document/d/e/2PACX-1vSNIXamlE2wyg3bmkibMPlpvD-HjANrQ7n4sahFa1VXtr9QcJU9g4yQJToF6ULhUyZ3ss5RRX5UYME-/pub
  33. https://docs.google.com/document/d/e/2PACX-1vSph8hD7G3uq5Ws9MPie1YYjPIwCRxlRUb6wuzdW-3quKraJAbvEetH9PCBNQuoOYFeEZ58xZohsHeJ/pub
  34. https://docs.google.com/document/d/e/2PACX-1vTdRsReD4hC2KPDejwL0eW51etDMJ_6JnsGn5ozNiYJ0osbEowOy33fvbWwI3kB3C2VBiPpV0sL65OL/pub
  35. https://docs.google.com/document/d/e/2PACX-1vTiQcRnwJQ-_h7HL1HHHk3vORa3vXwNp_y-70wcJg8zTkYQf9jV37ra_grOdEz-CbUfTfCEcF7jCshy/pub
  36. https://docs.google.com/document/d/e/2PACX-1vTjlvhgNkO5VTbeJi2z-J5lgNPHOS6FlnK-D0HVkLeaxIi06lkhU-oni7TMNC5y4P0TSa2huWkX5K9q/pub
  37. https://docs.google.com/document/d/e/2PACX-1vTsp9M-cXWwP3Xs_IT6RQjbqqshh40-d3pgN1hqn50xXXRx-EybouCkpYZNfLvrGMKD6LhqzCjfqmXY/pub
  38.  
  39. HANCITOR MALDOC FILE HASHES
  40. 349d70637313a7bdddd17535c92e2ac4
  41. ebd4881f14c5693c145bce8af7534bd0
  42. f759d85240d5ce3135a92e6a60aaed35
  43.  
  44. MALDOC DISTRIBUTION URLS
  45. https://fatemaoverseas.com/disbursement.php
  46. https://hortodovalqueire.com.br/cocaine.php
  47. https://pepselectricailservice.co.uk/assotiation.php
  48. https://platinumherring.com/projects/TowerDefense/images/convent.php
  49. https://www.brooksmarts.com/mystified.php
  50.  
  51. brooksmarts.com
  52. fatemaoverseas.com
  53. hortodovalqueire.com.br
  54. pepselectricailservice.co.uk
  55. platinumherring.com
  56.  
  57. KEYBANK THEMED LANDING PAGE
  58. https://key.xn--avigatorkey-56b.com/ktt/cmd/logon
  59.  
  60. HANCITOR PAYLOAD FILE HASH
  61. W0rd.dll
  62. 1df163e33efe6c95d051322b8fe99302
  63.  
  64. HANCITOR C2
  65. http://eviddinlahal.com/8/forum.php
  66. http://saisepsdrablis.ru/8/forum.php
  67. http://obvionsweyband.ru/8/forum.php
  68.  
  69. FICKER STEALER PAYLOAD URLS
  70. http://belcineloweek.ru/6hyuyj.exe
  71.  
  72. FICKER STEALER FILE HASH
  73. 77be0dd6570301acac3634801676b5d7
  74.  
  75. FICKER STEALER C2
  76. http://sweyblidian.com
  77.  
  78.  
Advertisement
Add Comment
Please, Sign In to add comment