ExecuteMalware

2021-06-17 Hancitor IOCs

Jun 17th, 2021
17,135
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.64 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=1706_apkreb6
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC PROXY DISTRIBUTION URLS
  27. http://feedproxy.google.com/~r/afibwaqjsf/~3/5m5A32MMdhk/antirational.php
  28. http://feedproxy.google.com/~r/cmhzepi/~3/LqpleTY2lE0%0D%0A/oust.php
  29. http://feedproxy.google.com/~r/cmhzepi/~3/LqpleTY2lE0/oust.php
  30. http://feedproxy.google.com/~r/daaau/~3/rZEE5Z7c-5w/etc.php
  31. http://feedproxy.google.com/~r/dvfcr/~3/r6f3V-siqpw/allotrope.php
  32. http://feedproxy.google.com/~r/edaisuvzey/~3/6qbTO0cyjQk/incisive.php
  33. http://feedproxy.google.com/~r/euevnjcc/~3/5f5ZEjmjslU/writes.php
  34. http://feedproxy.google.com/~r/fhnpkksr/~3/nUnXyuKN0Nw/taffeta.php
  35. http://feedproxy.google.com/~r/fxgspogbo/~3/dMlOI-awzjs/bunker.php
  36. http://feedproxy.google.com/~r/gjgyatlzm/~3/0iQG7ocX5P4/bothway.php
  37. http://feedproxy.google.com/~r/haysztots/~3/0T9hQvWi3X8/erect.php
  38. http://feedproxy.google.com/~r/hwatlrhwfgq/~3/Ri-twOs6Rsw/evolution.php
  39. http://feedproxy.google.com/~r/ixjnsbmggc/~3/Mvb-Yrh7m98/derivable.php
  40. http://feedproxy.google.com/~r/jkafsusu/~3/tE6qb1yM-JA/turnoff.php
  41. http://feedproxy.google.com/~r/jodxkf/~3/YcOmUvcnnWI/male.php
  42. http://feedproxy.google.com/~r/kfpnparzbwu/~3/oFgoOUPSvs8/deserializer.php
  43. http://feedproxy.google.com/~r/kupftfftcwp/~3/O8PgafXviDQ/rubicund.php
  44. http://feedproxy.google.com/~r/mogrgpgytyw/~3/6VVs_lzUZds/unsolvability.php
  45. http://feedproxy.google.com/~r/mqvmjfrcf/~3/Lm_PYKXWE68/taffrail.php
  46. http://feedproxy.google.com/~r/nuesxlnvdtr/~3/Lm_PYKXWE68/taffrail.php
  47. http://feedproxy.google.com/~r/odjjvzra/~3/9cXJA5Y6GYo/toolbox.php
  48. http://feedproxy.google.com/~r/otifhmxq/~3/qjiUo5RNl7k/instrument.php
  49. http://feedproxy.google.com/~r/ozpdhqij/~3/NHbemJRTL5w/coronary.php
  50. http://feedproxy.google.com/~r/pawhmy/~3/bC_GFcEpow8/prairie.php
  51. http://feedproxy.google.com/~r/pelxauctc/~3/Pf56p-5qSp0/harm.php
  52. http://feedproxy.google.com/~r/qsyjwvdk/~3/kiACGtiVg7Y/inadequate.php
  53. http://feedproxy.google.com/~r/rhkgbarrn/~3/hhlOQ4aFktw/wobbler.php
  54. http://feedproxy.google.com/~r/rspmdlhsd/~3/G7JCEQYXRVU/unswitching.php
  55. http://feedproxy.google.com/~r/rugvt/~3/LljddUsyk1I/envisage.php
  56. http://feedproxy.google.com/~r/scnotzvv/~3/UgfIYrDkBO8/consistently.php
  57. http://feedproxy.google.com/~r/seduqdrxbk/~3/lDwqBzvUPx8/latched.php
  58. http://feedproxy.google.com/~r/tttfp/~3/Pp1rR1d0RC4/skewers.php
  59. http://feedproxy.google.com/~r/tyynjpk/~3/IIsq1L8DPn4/roller.php
  60. http://feedproxy.google.com/~r/vomfqjlyyjv/~3/LqpleTY2lE0/oust.php
  61. http://feedproxy.google.com/~r/wjopjcrmdwy/~3/S5PSxrBv5zU/gag.php
  62. http://feedproxy.google.com/~r/wqzycfzepk/~3/qy7OLiR8M1A/virtualization.php
  63. http://feedproxy.google.com/~r/xflnb/~3/ZTh6-B8D-Kw/burgher.php
  64. http://feedproxy.google.com/~r/ychxxzohhl/~3/ecmoexqCi_4/sorceress.php
  65. http://feedproxy.google.com/~r/yirrqxtpbq/~3/hhlOQ4aFktw/wobbler.php
  66. http://feedproxy.google.com/~r/ylxdqyncnnv/~3/LqpleTY2lE0/oust.php
  67. http://feedproxy.google.com/~r/yryvzb/~3/GakTKOBdVVw/transpire.php
  68. http://feedproxy.google.com/~r/yssry/~3/Yqu6jXZ9Plg/crosshair.php
  69. http://feedproxy.google.com/~r/yvqzm/~3/GiOkBdI4wcM/contented.php
  70.  
  71. MALDOC REDIRECT DOWNLOAD URLS
  72. http://3.138.183.193/bunker.php
  73. http://3.138.183.193/taffeta.php
  74. http://365helpus.net/coronary.php
  75. http://abitcoinbull.com/virtualization.php
  76. http://akrealty.in/bothway.php
  77. http://akrealty.in/taffrail.php
  78. http://chefsvn.com.vn/wobbler.php
  79. http://globaltelemedicine-bd.com/oust.php
  80. http://globaltelemedicine-bd.com/turnoff.php
  81. http://handsonptr.com/harm.php
  82. http://horamedical.in/contented.php
  83. http://horamedical.in/unswitching.php
  84. http://htlreps.com/male.php
  85. http://htlreps.com/transpire.php
  86. http://htlreps.com/unsolvability.php
  87. http://lombrozo.org/burgher.php
  88. http://lombrozo.org/crosshair.php
  89. http://shreeanandinternational.co.in/consistently.php
  90. http://shreeanandinternational.co.in/instrument.php
  91. http://subtown.studio/deserializer.php
  92. http://subtown.studio/writes.php
  93. http://theresearchandpractice.com/envisage.php
  94. http://theresearchandpractice.com/evolution.php
  95. http://vordplay.com/derivable.php
  96. http://vordplay.com/etc.php
  97. http://vordplay.com/toolbox.php
  98. https://dsg-saudi.com/allotrope.php
  99. https://dsg-saudi.com/incisive.php
  100. https://dsg-saudi.com/sorceress.php
  101. https://icuyjon.com/rubicund.php
  102. https://waschschuesseln.de/inadequate.php
  103. https://waschschuesseln.de/latched.php
  104. https://www.entippos.gr/erect.php
  105. https://www.sametciveleksigorta.com/antirational.php
  106.  
  107. 365helpus.net
  108. abitcoinbull.com
  109. akrealty.in
  110. chefsvn.com.vn
  111. dsg-saudi.com
  112. entippos.gr
  113. globaltelemedicine-bd.com
  114. handsonptr.com
  115. horamedical.in
  116. htlreps.com
  117. icuyjon.com
  118. lombrozo.org
  119. sametciveleksigorta.com
  120. shreeanandinternational.co.in
  121. subtown.studio
  122. theresearchandpractice.com
  123. vordplay.com
  124. waschschuesseln.de
  125.  
  126. HANCITOR MALDOC FILE HASHES
  127. 1dde1d019e8b28577765e4802c073ae6
  128. 3ac019815a5f863e51bd1a141579d99e
  129. 3dcc62b12c1126f74c8f97fa56dc7863
  130. 3e77e5058f020cde5a39105dd76a14ca
  131. 3fc46bdf5dd164e821c1e2cff1fec85d
  132. 5c7862df6e8da6785882f0b9fa1a9e0a
  133. 5e8ed39008dfba09d149ec83cabcb895
  134. 676c41477e24ade0b943c188f77ab1e5
  135. 67b6288984f5c92c60589eaa963b8a04
  136. 7cd8423932018a573c44747beeaa054e
  137. 7e83f0ae12f22321324f4e36f97a9467
  138. 8f93e5563c1da97eb63c54873f8b53f5
  139. 97d0dc7d56fc1a18157d52afeeeac173
  140. 988d18d2d0f47a0db322332a10e1f480
  141. a4be4925e5378d191bfea9e2f9d5b055
  142. a70433cb0eb6f2eeeec2b15be58783a6
  143. a976c93a5f75895bfe65b558ce75421f
  144. b84b745f9cdb50b2fd329e6af927b1c3
  145. b9c41b6b809efa689b11c9854d1cc23c
  146. e6a73954c1f190891eb2f17904ad79e5
  147.  
  148. HANCITOR PAYLOAD FILE HASH
  149. kikus.dll
  150. 3199137d81a7a21993fe8c819ec7ea6e
  151.  
  152. HANCITOR C2
  153. http://arguendinfuld.ru/8/forum.php
  154. http://thestaccultur.com/8/forum.php
  155. http://waxotheousch.ru/8/forum.php
  156.  
  157.  
Advertisement
Add Comment
Please, Sign In to add comment