Advertisement
DarthInvader

Hancitor DocuSign phish September 27, 2017

Sep 27th, 2017
1,116
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.34 KB | None | 0 0
  1. Hancitor DocuSign phishing IOCs September 27, 2017
  2.  
  3. From:<Various names> via DocuSign <[email protected]> or [email protected]
  4. Subject: Your Invoice <8 digits> for accounting@<YOUR DOMAIN> Document is Ready for Signature
  5. Downloaded Document Name: invoice_<6 digits>.doc
  6. Document SHA256: 42e3fcad33e3d94b416578c86446be7762136c7707d6da08adc8075c3bd3ce61
  7.  
  8. Phishing URLs
  9. ds.php?XXX= where XXX is random
  10. hopphome.com/[email protected]
  11. hoppnews.com
  12. ifeelgreatnow.com
  13. maycompanyapartments.com
  14. maycompanybuilding.com
  15. perrypaynecondo.com
  16. perrypaynecondo.net
  17. publicsquareapartments.com
  18. ifeelgreatvideo.com
  19. maycoapts.com
  20. thomasguyton.com
  21.  
  22. C2 domains
  23. http://oneonreugh.com/ls5/forum.php
  24. http://sotyterny.ru/ls5/forum.php
  25. http://recsihedri.ru/ls5/forum.php
  26.  
  27. Malware Delivery URLs
  28. http://markimicrowave.com/blog/wp-content/themes/twentyfourteen/1
  29. http://markimicrowave.com/blog/wp-content/plugins/google-sitemap-generator/1
  30. http://taste.divino.bg/wp-content/plugins/contact-form-7/1
  31. http://www.schreckeneder.net/wp-includes/1
  32. http://www.polbest.pl/wp-includes/1
  33. http://format-format.ru/wp-admin/1
  34.  
  35. File1 SHA256: d14f5ec7f7843a5ca5c7e6900e297565946e8314c99ecd89d4e583a874a0d354
  36. File2 SHA256: 1aae22b5ed8cda013cfef67a3dd24380017f7df0d9f638df7bd6941ecd0f9ac8
  37. File3 SHA256: c8c6f89a44d629cd5a5280f7182ace9d75bd106d862dc70a1ea439bfb8bdaebe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement