ExecuteMalware

2020-12-14 Hancitor IOCs

Dec 14th, 2020
4,621
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.41 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Electronic Signature Service
  6. You got invoice from DocuSign Service
  7. You got invoice from DocuSign Signature Service
  8. You got notification from DocuSign Electronic Service
  9. You got notification from DocuSign Electronic Signature Service
  10. You got notification from DocuSign Service
  11. You got notification from DocuSign Signature Service
  12. You received invoice from DocuSign Electronic Service
  13. You received invoice from DocuSign Electronic Signature Service
  14. You received invoice from DocuSign Service
  15. You received invoice from DocuSign Signature Service
  16. You received notification from DocuSign Electronic Service
  17. You received notification from DocuSign Electronic Signature Service
  18. You received notification from DocuSign Service
  19. You received notification from DocuSign Signature Service
  20.  
  21. SENDERS OBSERVED
  22.  
  23. MALDOC LANDING PAGE URLS
  24. https://docs.google.com/document/d/e/2PACX-1vQgBn-XsOGbUzUYbkLWlo8gKfkT9o0o7Ev69OjKle576X6MwV3EuuyG3e-xaVd5t-YQCwQemhNAqZuk/pub
  25. https://docs.google.com/document/d/e/2PACX-1vQgniYLo2h8XyPvRTf7TESPutnUo4EViqPYeLRqqTyx8AEZSynkEm_rwqoQhXBvIBE1V5VsZyH_2JJq/pub
  26. https://docs.google.com/document/d/e/2PACX-1vQLuR8E9nPFtw8vidmgs6Ay6-cxZKGTRY8csOchWxoByBdT2BIrzzap6V1bO0D42g_5y9v30sjxW-mn/pub
  27. https://docs.google.com/document/d/e/2PACX-1vQrHDk9ORW-YVts7ph89IVefA-LZnU5COVUX99SllbramDYhGLoAWBmykf0xDkyhMQ5e2MnSWRjaPvO/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQrJCGJvX-jsaFFhJg2r0SEGs07AABCfcqxym_25QPlSg7icNfDqSRG5EqNLAxuvKh5WgZEKIiqXYE3/pub
  29. https://docs.google.com/document/d/e/2PACX-1vR7WMtTOK0JJclqCJvtC6BXwrZ_Jxw1eJS3R2iDVB_52UB4aTU_55J0EBpM568KSEjrhacjR7u_Vyao/pub
  30. https://docs.google.com/document/d/e/2PACX-1vR8RffNg5ZlmctGsP_umTJACWzmuLSpr2F_xz0Ib1VYckTmJp2rZtirR3Qlc1zozfLF8B08vxUJ4DZt/pub
  31. https://docs.google.com/document/d/e/2PACX-1vRAVNRXFAQYLta05OWWr_bMdt9J10iGd9GtbKauVsjliXfu421I7c6VV2ZzjxNFFdXpFhljIyuwAOTY/pub
  32. https://docs.google.com/document/d/e/2PACX-1vRpqp8nqoAGkRU3ZFDRCaw0wIva_wixUXsvKnubncNYKFH0N7JK0lLrUevkBzuxCcK37FIu04HC56Xb/pub
  33. https://docs.google.com/document/d/e/2PACX-1vRQGXPxMGNs7io43NOZGYvOB_7iaaJtVPhXsNibHihcP4IMFNDDEkkCtzENJvdSa2DruuS8PypiJK-7/pub
  34. https://docs.google.com/document/d/e/2PACX-1vRr9CTrQMVK0IiPiVa2_ND0rVzamTNbnyFZr6xtQbxvz0z2fDwXn1cioodL2aew5bS6cqVRHbyxhDw5/pub
  35. https://docs.google.com/document/d/e/2PACX-1vRUlHjE7PnZ5QCuIsGUWvMk3W4RSBY3FPCdzAu9yeS8jYVXAiTqYaCWdfAh5qWAjHE_6NbOWk4KCzM5/pub
  36. https://docs.google.com/document/d/e/2PACX-1vRyOEo6kyvwbu4O1re2DKzwD-eVIOCTquH2C9cRgOuz6OK_cZrV2QCROzJe9cCmrtb1MmHw7VIok7QD/pub
  37. https://docs.google.com/document/d/e/2PACX-1vS1LjQamV-jq_mUaH4OVzWeuqFax4dPYgVQBkRTjY5GLd_dCFmAgKZZ5LrLoRxsdfxPSMcw9yZb6fQr/pub
  38. https://docs.google.com/document/d/e/2PACX-1vS5xQKRz_vxJWApV9agHEiACNu6v-xWMdZdN9qyR2dG6XoS5gpYm395oy1-fFKQzrzBrIgm2401BNBT/pub
  39. https://docs.google.com/document/d/e/2PACX-1vSdycPumzrDyarBd8GvPNFMQGmZRKyfZJXe6z55yfLIiWgZ1lZZ-vazBkbaL0FLUYRuvvYXg5Y_Eue_/pub
  40. https://docs.google.com/document/d/e/2PACX-1vSFxeHFZKA-yGDfIvOaOqhGwkRERtdOSxpyc5Hcm5xFLf1aGFke_PaPA1UFhSYeC36GWz5RvYlKiX92/pub
  41. https://docs.google.com/document/d/e/2PACX-1vSgW1rXeeaIlD6NdmI1hSRQx0rWs48MZ4Lu0f7hYkSo5TMjWyLs9IBxDezX6YSReTYhtl2PzTfjXB6p/pub
  42. https://docs.google.com/document/d/e/2PACX-1vSIxteQn4VMWo7YIL2CcwQNUmxp8aTGfBAMCLweVy8lh_Gqx619TluHMdMOhH78MlUu-tbt-zmy40TD/pub
  43. https://docs.google.com/document/d/e/2PACX-1vSKdY6r64XWzVZM0LBJk7inRfPSQTILRjad-icdRDKk2oSMM7PUi1wYqHsv5U1g6iM2Jqfv4GWOqfUh/pub
  44. https://docs.google.com/document/d/e/2PACX-1vSN8yjeKESWD3QT3hXT5ZoWGEz0jM0ZsmFsHgVqB1TWlNqtk-X5Ku--iCRYhY7ezvGMMvfdrLVdw2fm/pub
  45. https://docs.google.com/document/d/e/2PACX-1vSVjM9s9CThnlu-J6Gx9ayCsk7n3UWqPleEuC38C-XlycMuvQyLiC5XYPW3wH3WOdZG9MVAm1e9xv4V/pub
  46. https://docs.google.com/document/d/e/2PACX-1vSzVahhfy4wVkwL3YNSrYUIV-udUbdlC3Uw11NVcVa_h5Vyzgdvyk-NIQgENBz8IjUGf_IVbZSYPyK0/pub
  47. https://docs.google.com/document/d/e/2PACX-1vT5r5OvafdiQNL30CVmB9EzGAwZqx8Y2G_dS5DbNln30qmwkVTZxRyZNljO_FpuuGh5X9OX_M_FfPmu/pub
  48. https://docs.google.com/document/d/e/2PACX-1vT85r-affhtqu6fTii4dh9DhnMrDywLOp7027bzgIwk8JXZilV1kIAGu78OO__2iys3Aux582KCQjBN/pub
  49. https://docs.google.com/document/d/e/2PACX-1vTHf6tzn471dAx05R3JmIcbUyN1Phn0NJIMTzQGR-LBD5w0ugnVopPCFLUODZYX9X6GbzUUX83N1F03/pub
  50. https://docs.google.com/document/d/e/2PACX-1vTO299w3BtWnOD29mGoOS-vQKJNiocaXb0sdIsa5FEZwcNJrSBpOJPFRJh6ZvTvcmaTFE-NSvEwzEU8/pub
  51. https://docs.google.com/document/d/e/2PACX-1vToy5kLdp9E7JfJIfR9hF5dVcZvUTVnJfVG9j4YJ9L6tqFdrW3ZhvDdwfzNGhgwptzNYEJbhrqKgFbB/pub
  52. https://docs.google.com/document/d/e/2PACX-1vTUlTws4vSrUYRkSD8OXL41I2hPxoxwb9B6G7jVrpiXXx6PYPFhLQKzBeOFjgg-WMHQH0T8GJX1j-rD/pub
  53. https://docs.google.com/document/d/e/2PACX-1vTvvu72IhdsSsfX1sXdSg_vsk9XiJs0ksc7VVixfXqnK0W2hcjqztqbAIeQNDy0kFPE5jdvYzsAwfP2/pub
  54. https://docs.google.com/document/d/e/2PACX-1vTXK7yzJ07VWz0GHxVMAMgh0-Er_aHgsn1lrSTwzXk0TM6arQIs6sOoVPf1ZVmPuNf2Ko3mmCj_9pI9/pub
  55. https://docs.google.com/document/d/e/2PACX-1vTyhmloJp3DSaqwvlKR3sHkTzmEGNmRcPD8RiWz3_F8ooQKRqkn8Q5amCRE_HSE2NbwAPeYZ_voNNAP/pub
  56.  
  57. MALDOC DISTRIBUTION URLS
  58. http://alnafidevelopers.com/quartos.php
  59. http://cares.com.mx/distinctive.php
  60. http://iptv.yoinicio.com/alimentary.php
  61. http://iptv.yoinicio.com/antinomian.php
  62. http://iptv.yoinicio.com/bled.php
  63. http://iptv.yoinicio.com/plumb.php
  64. https://baru.bethanyperthchurch.org.au/ammo.php
  65. https://baru.bethanyperthchurch.org.au/seller.php
  66. https://baru.bethanyperthchurch.org.au/uncase.php
  67. https://baru.bethanyperthchurch.org.au/validly.php
  68. https://cartagourmet.com/hypodermic.php
  69. https://cartagourmet.com/luxuriate.php
  70. https://cartagourmet.com/superscribed.php
  71. https://josetyres.co.ke/ambidexterity.php
  72. https://josetyres.co.ke/waterskier.php
  73. https://okmms.com/obsequious.php
  74. https://okmms.com/shimmer.php
  75. https://okmms.com/weeper.php
  76. https://roromap.com/connate.php
  77. https://roromap.com/neutralized.php
  78. https://roromap.com/sexily.php
  79. https://roromap.com/spilt.php
  80. https://roromap.com/trivia.php
  81. https://sulamericacontabil.com.br/highborn.php
  82. https://todolaptops.com/strangling.php
  83.  
  84. alnafidevelopers.com
  85. bethanyperthchurch.org.au
  86. cares.com.mx
  87. cartagourmet.com
  88. josetyres.co.ke
  89. okmms.com
  90. roromap.com
  91. sulamericacontabil.com.br
  92. todolaptops.com
  93. yoinicio.com
  94.  
  95. MALDOC FILE HASHES
  96. 1214_56873981.doc
  97. 98128d32362c564c4f82d4ceef5b0aa0
  98.  
  99. HANCITOR PAYLOAD FILE HASHES
  100. W0rd.dll
  101. 9d9c0905193720761ef52b8a8b045451
  102.  
  103. HANCITOR C2
  104. http://ductivery.com/8/forum.php
  105. http://horyinwheorm.ru/8/forum.php
  106. http://strucervach.ru/8/forum.php
  107.  
Advertisement
Add Comment
Please, Sign In to add comment