ExecuteMalware

2021-06-15 Hancitor IOCs

Jun 15th, 2021 (edited)
15,852
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.93 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=1506_necix
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC PROXY DISTRIBUTION URLS
  27. http://feedproxy.google.com/~r/alnewvjcnu/~3/Ev3UT1cSrwg/saucily.php
  28. http://feedproxy.google.com/~r/bkpdy/~3/DKhvTR21e5M/prevalent.php
  29. http://feedproxy.google.com/~r/buggilsitc/~3/iqNHgWV6DA4/sag.php
  30. http://feedproxy.google.com/~r/cfmqpm/~3/LtrBPLHDHBI/absolute.php
  31. http://feedproxy.google.com/~r/ckmbsqnvbki/~3/cS5HqTfSsmw/arabian.php
  32. http://feedproxy.google.com/~r/cwiwz/~3/J3clknmmyeM/transition.php
  33. http://feedproxy.google.com/~r/cwzxpkbl/~3/lcX_Got4d%0D%0A6g/france.php
  34. http://feedproxy.google.com/~r/cwzxpkbl/~3/lcX_Got4d6g/france.php
  35. http://feedproxy.google.com/~r/dhumbvq/~3/YErayDQpc04/quintillionth.php
  36. http://feedproxy.google.com/~r/dnbbzxczt/~3/Xo2jDDv35Uw/dissent.php
  37. http://feedproxy.google.com/~r/doscqdxavt/~3/VnopxKjBMAA/countersign.php
  38. http://feedproxy.google.com/~r/dtpiyfyhe/~3/YH2H2Y9EU24/namely.php
  39. http://feedproxy.google.com/~r/ebtux/~3/6-mS0ZiSlkk/picked.php
  40. http://feedproxy.google.com/~r/eijevp/~3/apTB_rIAwbU/familial.ph%0D%0Ap
  41. http://feedproxy.google.com/~r/eijevp/~3/apTB_rIAwbU/familial.php
  42. http://feedproxy.google.com/~r/fixox/~3/NkroQy6NOWA/diversified.php
  43. http://feedproxy.google.com/~r/fpukiszyeg/~3/TsPm7J_dW7I/corinth.php
  44. http://feedproxy.google.com/~r/gfxwbgoiua/~3/VnopxKjBMAA/countersign.php
  45. http://feedproxy.google.com/~r/ghianqmpyrj/~3/u5tnuoH1nrw/prescope.php
  46. http://feedproxy.google.com/~r/giaetua/~3/n5X-1HiQ2CU/%0D%0Aspearman.php
  47. http://feedproxy.google.com/~r/giaetua/~3/n5X-1HiQ2CU/spearman.php
  48. http://feedproxy.google.com/~r/goralawxu/~3/TQrL5k_uh3g/common.php
  49. http://feedproxy.google.com/~r/hagdupdkiky/~3/1sSd1FVTAk4/acorn.php
  50. http://feedproxy.google.com/~r/hdbpwfyscxj/~3/h_6P_HPOaoQ/broadcast.php
  51. http://feedproxy.google.com/~r/hfmmxbim/~3/KY21AqqoOnk/catch.php
  52. http://feedproxy.google.com/~r/htkewchpcoy/~3/jEldhv3Db68/inhibition.php
  53. http://feedproxy.google.com/~r/itzeweywlk/~3/pEholbTfpa4/baleful.php
  54. http://feedproxy.google.com/~r/knect/~3/yUD5HIMT2pM/stumbling.php
  55. http://feedproxy.google.com/~r/lhespsw/~3/2FQtvjHrE7A/memorialize.php
  56. http://feedproxy.google.com/~r/mkewgdmacjw/~3/0hrSRK59S5I/fiche.php
  57. http://feedproxy.google.com/~r/nciasjppt/~3/0toCZyfqfZE/pinout.php
  58. http://feedproxy.google.com/~r/nqmswm/~3/luetG43St04/lyre.php
  59. http://feedproxy.google.com/~r/ocidtiojaoj/~3/i0Ix__rKvqA/p%0D%0Alod.php
  60. http://feedproxy.google.com/~r/ocidtiojaoj/~3/i0Ix__rKvqA/plod.php
  61. http://feedproxy.google.com/~r/oiefojc/~3/HBUC-s__Wow/overheating.php
  62. http://feedproxy.google.com/~r/otbhw/~3/Eddgs_7yF54/benevolence.php
  63. http://feedproxy.google.com/~r/pvihopiy/~3/FBj29Uerz1M/morsel.php
  64. http://feedproxy.google.com/~r/ruplzv/~3/lVxN9qzr8rs/profundity.php
  65. http://feedproxy.google.com/~r/seiyqlcojkq/~3/KAc3W53zw1A/animator.php
  66. http://feedproxy.google.com/~r/spqdo/~3/aIdRrJhO1bk/photometer.php
  67. http://feedproxy.google.com/~r/synzpqmkloz/~3/JMJYufCyJw0/pauperize.php
  68. http://feedproxy.google.com/~r/tsiezjb/~3/uz-Jn_5rBL0/inkstand.php
  69. http://feedproxy.google.com/~r/ueeaem/~3/2x1wd9NwrtU/ibuprofen.php
  70. http://feedproxy.google.com/~r/uejhclpmrm/~3/Y7_Xvh3dyDs/outgrowth.php
  71. http://feedproxy.google.com/~r/vcrvu/~3/hUGRtXlkf8s/subcontracted.php
  72. http://feedproxy.google.com/~r/vmswyfrnr/~3/6GEEJoXvxEg/vestment.php
  73. http://feedproxy.google.com/~r/vsmltlh/~3/O3mQ7yRb2AI/aftereffect.php
  74. http://feedproxy.google.com/~r/wfpby/~3/KAc3W53zw1A/animator.php
  75. http://feedproxy.google.com/~r/wfvlr/~3/YPSshEESDrE/jobless.php
  76. http://feedproxy.google.com/~r/wmklnymjzx/~3/ItT__wYzBNA/tenacity.php
  77. http://feedproxy.google.com/~r/xazdczerd/~3/Oae5O2LXrqs/usual.php
  78. http://feedproxy.google.com/~r/xewwqxke/~3/TsPm7J_dW7I/corinth.php
  79. http://feedproxy.google.com/~r/xoxmcwlcma/~3/gQvQ9bG24p8/abashed.php
  80. http://feedproxy.google.com/~r/xpdexlvf/~3/1rnTIhTXkzw/trustfulness.php
  81. http://feedproxy.google.com/~r/xwlyp/~3/H2cxdP69hb4/steeplechases.php
  82. http://feedproxy.google.com/~r/yyehyxoqcgn/~3/XrLd-ukVysM/filter.php
  83. http://feedproxy.google.com/~r/zibfysgypj/~3/PGerdpduV6c/swampiness.php
  84. http://feedproxy.google.com/~r/zqqjgrvxgi/~3/PTJdCu7HM9c/annihilator.php
  85.  
  86. MALDOC REDIRECT DOWNLOAD URLS
  87. https://airpaviliontours.com/media/widgetkit/widgets/accordion/images/annihilator.php
  88. https://airpaviliontours.com/usual.php
  89. https://business.sngtorg.ru/common.php
  90. https://business.sngtorg.ru/jobless.php
  91. https://cemexint.org/wp-content/themes/business-contra/template-parts/header/spearman.php
  92. https://cemexint.org/wp-content/themes/business-contra/template-parts/header/tenacity.php
  93. https://dsg-saudi.com/demo/css/inhibition.php
  94. https://dsg-saudi.com/demo/css/profundity.php
  95. https://dsg-saudi.com/filter.php
  96. https://escrowbank.co/broadcast.php
  97. https://euroacademia.co.uk/arabian.php
  98. https://euroacademia.co.uk/countersign.php
  99. https://euroacademia.co.uk/vendor/multi-select/test/lib/jasmine-1.2.0/plod.php
  100. https://euroacademia.co.uk/vendor/multi-select/test/lib/jasmine-1.2.0/subcontracted.php
  101. https://groupfeaab.com/aftereffect.php
  102. https://groupfeaab.com/corinth.php
  103. https://groupfeaab.com/ibuprofen.php
  104. https://groupfeaab.com/namely.php
  105. https://groupfeaab.com/wp-includes/js/tinymce/themes/inlite/acorn.php
  106. https://groupfeaab.com/wp-includes/js/tinymce/themes/inlite/animator.php
  107. https://groupfeaab.com/wp-includes/js/tinymce/themes/inlite/stumbling.php
  108. https://jyothishmathi.in/familial.php
  109. https://jyothishmathi.in/pinout.php
  110. https://jyothishmathi.in/steeplechases.php
  111. https://kamalskincenter.com/skincernter/FTBv3-3-0/aspnet_client/FreeTextBox/Languages/diversified.php
  112. https://londonshemale.magento2e.com/swampiness.php
  113. https://mitarmilan.com/wp-content/plugins/wordpress-seo/lib/migrations/absolute.php
  114. https://mitarmilan.com/wp-content/plugins/wordpress-seo/lib/migrations/morsel.php
  115. https://mitarmilan.com/wp-content/plugins/wordpress-seo/lib/migrations/transition.php
  116. https://nicelyeg.com/catch.php
  117. https://sataware.net/photometer.php
  118. https://sataware.net/StyleFit/laravel_application/vendor/league/flysystem/trustfulness.php
  119. https://tonicata.musicliveradio.com/quintillionth.php
  120. https://votobicentenario.com/vestment.php
  121. https://www.entippos.gr/outgrowth.php
  122. https://www.entippos.gr/pegasus_cloud_app/prints_libs/FPDF/font/unifont/saucily.php
  123.  
  124. airpaviliontours.com
  125. cemexint.org
  126. dsg-saudi.com
  127. entippos.gr
  128. escrowbank.co
  129. euroacademia.co.uk
  130. groupfeaab.com
  131. jyothishmathi.in
  132. kamalskincenter.com
  133. magento2e.com
  134. mitarmilan.com
  135. musicliveradio.com
  136. nicelyeg.com
  137. sataware.net
  138. sngtorg.ru
  139. votobicentenario.com
  140.  
  141. HANCITOR MALDOC FILE HASHES
  142. 019c4c9d46a095e7a38e75c7f88d5e32
  143. 18ad286d9b51d143cf6f67a4c912b09b
  144. 2de100af62e7a60ae0401ba804042684
  145. 3a3bef5746571319772475408f555f64
  146. 595caa2c6508a694e05f6ab00236406e
  147. 5978f1a67330eba1ed85ca4441edcdea
  148. 7841815291ce7e0c00fbbea15284b589
  149. 87ec45d241e6ea5758ad56b0d55b1da3
  150. bc6e6aee27d6c5f2fe4eebc0aab7f9e6
  151. d5474b0ad1073e3e13d5072ca61a932b
  152. e3b690e3e28005fc56c4456812fca293
  153. fcbf9eca8a66007969577a3b2ff34b4e
  154.  
  155. HANCITOR PAYLOAD FILE HASH
  156. omsh.dll
  157. c290968d2c547416d712c737f539b55d
  158.  
  159. HANCITOR C2
  160. http://sciandwourgy.com/8/forum.php
  161. http://pariamarraire.ru/8/forum.php
  162. http://thiceshouthas.ru/8/forum.php
  163.  
  164. FICKER STEALER DOWNLOAD URL
  165. http://larn9kany.ru/f7h7jhhjbch.exe
  166.  
  167. FICKER STEALER FILE HASH
  168. f7h7jhhjbch.exe
  169. 270c3859591599642bd15167765246e3
  170.  
  171. FICKER C2
  172. http://pospvisis.com
Add Comment
Please, Sign In to add comment