Advertisement
ExecuteMalware

2021-05-26 Hancitor IOCs

May 26th, 2021
16,407
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 14.19 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2505_nxat9
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC LANDING PAGE URLS
  27. https://docs.google.com/document/d/e/2PACX-1vQ1kpqwZTIx_HkCSmVKs6RneBCN_PxL3Jx6KOXzf0AWs6Zry0mKUZmK3WMSyHU-woy_bszBOqHz0eHp/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQ5pOm1gR4djNDxVZAaTnwaY-PO3KCYGGcg-ODfp07hMlpWYGxlArPNN4BdqIGnwT-ix3TuNSSLjG6E/pub
  29. https://docs.google.com/document/d/e/2PACX-1vQ9RAX2bPbnS2zYNBU8TOWiZjceN_dVGroAlvKbL518nLwXb19nu2pQV3DXRnHckizdXh58hJEVs0l5/pub
  30. https://docs.google.com/document/d/e/2PACX-1vQCILjaT883nyG83_UwtUC0Rdw3IIgJ8lCtHqegBqQFsMOMfNHc5GKEu1GQ6I0YRH8tljiiNw6FG5BT/pub
  31. https://docs.google.com/document/d/e/2PACX-1vQF7uBuzOwp2y8US6NU70R9_PWRG5dzcvV5C5yj2fBAz3laMrrdUp15un1u6xaZQH70f41Bc1E2ep5V/pub
  32. https://docs.google.com/document/d/e/2PACX-1vQFVKxI0whZaPG-2pE9UUooAxHpChMJ5pns4nMlo_PkSz4zxzI85589ChMggqnNftWocBXGzk3XMoyw/pub
  33. https://docs.google.com/document/d/e/2PACX-1vQGc7j2KI07OyjTFDGyaIiQSIRPdGGVmuaThrCzg_Q_tV9_J-0R44pk_mGsw7Lp04Wv5sUcMPp8XV7s/pub
  34. https://docs.google.com/document/d/e/2PACX-1vQrk7bsdVZONe_MGL4YdIfFSsfR5mI2rPglsd41T-yVMdGW3ignz-rh7T4o3eUoA9AM405mN-kLrFNT/pub
  35. https://docs.google.com/document/d/e/2PACX-1vQRu89hE0DiOo7PVJlBntEHRHDGIuAVpGrTi1mXysLJaz4hG2b_HTBz-2CfChgO8v0kMSFN926URIsm/pub
  36. https://docs.google.com/document/d/e/2PACX-1vQRyWm5i5nGBQCXg0NB7kATK41T0db7B99LUicEC1bQLueQcpNtYJB4e0Rnd62WplAcT7ts2Stvw7Zj/pub
  37. https://docs.google.com/document/d/e/2PACX-1vQTEX8FPstJYVMQiCooI2qfqjfRLe7cpeMkTGiEl2aGb_eTJCMT43ragFS_ILX5vTzdHThzf_CTnErN/pub
  38. https://docs.google.com/document/d/e/2PACX-1vQwB-mxWTpHJJ0-MKkwgZWASAbnmDL6PV2U-Byv0skRDySil2vmY7V5CIgdA2Kfm-GPLoHoK9MXAQ7n/pub
  39. https://docs.google.com/document/d/e/2PACX-1vQwsggn_fGWwfNYDNci_U5A8rBQAhudtz_dYz3CrM4f5aCxsEtUsFGgtjrco7rhpDagYgjsG4MR3FhV/pub
  40. https://docs.google.com/document/d/e/2PACX-1vR3iqbwFbI8BXMTNPj3kI9JUKwedEEjG3BWhXv8AG4BLcbafn188Xz14aJh4or2gsfDC9EOZIimb5DR/pub
  41. https://docs.google.com/document/d/e/2PACX-1vR6JARGqATFU4jLrzwqXdPLS3mBGDxh2U95roGFq6e-j8SbX5G0oKneFS3Hs5YFe38XrNAXT_qXO-ll/pub
  42. https://docs.google.com/document/d/e/2PACX-1vR_76pa09Lh2WOdtlnD3oTfCumhazKreEFwOLs0GrU4ZImFdWAWwoUXCNtUAfzjCTgVPlNs10XjeWgl/pub
  43. https://docs.google.com/document/d/e/2PACX-1vRchJ0lUJc25wl5P19_cHNQwWKqSPRkHdxwYWYiLbvZDQJHHRPjGdqhhEGRnx3-JDCGPHcdG6ZQdfde/pub
  44. https://docs.google.com/document/d/e/2PACX-1vReQSiP9YVlNn_DS4kqaxkTVuJXmS_MgGXegw8GH3Niia87-0PaViYS46bIRsFykMrdlqwo2OiPDj18/pub
  45. https://docs.google.com/document/d/e/2PACX-1vRgggpcxjpOA6SNy0sZ7vnDw6GOrXOCL8tifCLsjNVm5lqzgUyHoVPPkAGSkcVS5IOM2BUlsRPvOoir/pub
  46. https://docs.google.com/document/d/e/2PACX-1vRkBSE_ucF2VA51FyFI_DmCkFqBTzQVW_6AJIxQeFDAgawh9EJCBXUw-r-xfdiMTTHST1jA2xI_ymiy/pub
  47. https://docs.google.com/document/d/e/2PACX-1vRLTU_8sjgaFfoo5Qs8z8VBkooy1GUDXPPDS4EnGLWcvfEoHxjd8w4NxYdF3rylX4WlMLQbvEqtUzzJ/pub
  48. https://docs.google.com/document/d/e/2PACX-1vRMcI-T2WqURKIOEPtVzGoy7p7w1CS7GIRp_LK6hmG_RXN7RhWpOWBt0uTvw9M9-NimQkL6UM6sGxE4/pub
  49. https://docs.google.com/document/d/e/2PACX-1vRmnw2M7Qk_9mMWzyRiC_W2l_bpkoSfG5z5SQYzuJO568xL9yJGS-eglYUHbomVsyKUWRfC9CKiGSlz/pub
  50. https://docs.google.com/document/d/e/2PACX-1vRNNuOsKeztN9UMUAaX3ZQ6EYdwBYOtU7lKM6RwU9ta4NB_f-JfHElraxWOVGlFlXvOcPAV9I3LoYrI/pub
  51. https://docs.google.com/document/d/e/2PACX-1vRodpMlgZWDcTo9K-DzyBrQVHvv-R9vVO9dvcXgFZ2352OE13dVdMqTG5sFDryXdxwCa_Kr-xKYqUlK/pub
  52. https://docs.google.com/document/d/e/2PACX-1vROGft9RhYHiedS7H-KFDTaT9ApAAXKo2tUpeFceAwRI8ERFn3cX7KzWg4sbTKpm-xk2gZC9xJwxk-A/pub
  53. https://docs.google.com/document/d/e/2PACX-1vRouYV9VtMUamD-HlJN61Hpgje0Ouk4NATroWk3f7-WxymYWFIcfqbUmN6du3S5JyjwADp44pY4Y-C_/pub
  54. https://docs.google.com/document/d/e/2PACX-1vRP_KchSb033DrRDIs1OLl9BizQf8tYOVtR7lmFGJfcmEMa1gqwj6vDeboTTmafYsOkU3gAjO8jUw75/pub
  55. https://docs.google.com/document/d/e/2PACX-1vRPp6fU_wk6tZCP7rwtpBIoQcmoPHBZJJ7PkmgXD1hHydssM6h-QzyhLrPzGt-rAR73xGrPv5Rz86va/pub
  56. https://docs.google.com/document/d/e/2PACX-1vRs5D2YGum7OqSyw4mcLio20z2qf7nGiNiHtXmSxffBL4vrQ3-y3gA19kqDfNksMqcbrHMOTIut_0wD/pub
  57. https://docs.google.com/document/d/e/2PACX-1vRSESrnNfnMln2twnWEtyIhdXq4uj6clI2ntxLIn0McF-uyj24q4fXEkwAZOr6bh9wkQL4_ad072L0E/pub
  58. https://docs.google.com/document/d/e/2PACX-1vRtnhy8iPm82eGefG7zhukJ5qwBit31-jlHdsxOVfF8rCeFW2UHPNdpuClv_ffRQQDJHXYXYmpJ3ame/pub
  59. https://docs.google.com/document/d/e/2PACX-1vRyqM0ENjdl9up6wF866lgPmSxMd-RJ-u0VfnybX7Q6vDDPoSR_jA9CG9IB_GV4-psXDTWH0tl0yD6C/pub
  60. https://docs.google.com/document/d/e/2PACX-1vRYRAo2Ak4MoPJi4uz5-4i9ZODluTA1K56NZ1HdqCB9x7fT3kAgZARysQrMDsVS692mXnJ9Cpji2M3g/pub
  61. https://docs.google.com/document/d/e/2PACX-1vS2dE_jzMDQrayv_TXLMnbeUEHZGtGpgHpLOXRh7g__5Mwl-RPf84gB73Yf0RcqWKZzuwEHa1v-Ualf/pub
  62. https://docs.google.com/document/d/e/2PACX-1vS5-dsI9J7r9sxab4tIQxCgVoIi5i_ghKYBFsydELsCGdWg63nxKR0hpQ7CTa-iDiTZKEB6lztiUsJA/pub
  63. https://docs.google.com/document/d/e/2PACX-1vS7NQ7mmBbO8GkTFGjNXrvIIHNH9542xBEkTCdZpsM3SlRPAk6ZS7P0iI27le7rTJsSbPGL-83WdyeL/pub
  64. https://docs.google.com/document/d/e/2PACX-1vScKSF5UK37b5zbQrJxgyt-gOvS1mmiLiZ4ZBemgAFGd0ilZxrprzGyvAXBSZnz0d4W_n02BbQofz3D/pub
  65. https://docs.google.com/document/d/e/2PACX-1vSdtlydpUXTBDjA1TxmZzlMh60f9NOcNLaATj6-uxM8bSBHWoVXmMiDmmmUDxgRSLNvrFvjYBdLZ9wm/pub
  66. https://docs.google.com/document/d/e/2PACX-1vSdXOwVWTj9dybjktXZct23qiQoCE_BA--q9mVAegRCdxjc0nk8i-9-AxhWwX4TbFqRBAnDOF_PntiT/pub
  67. https://docs.google.com/document/d/e/2PACX-1vSg-dwkOl4m1dolwxvUS9o3F7G9eX-T5-sp68LU8BOvOOt7lFh5AXAIhUV4wVnJkxnpvTdl9PGemjIj/pub
  68. https://docs.google.com/document/d/e/2PACX-1vSiL5Su7Xb3Z9zxXnjacHTF8f425J7SUaQ6yfFFyL6pRoGuCgQcti0M9JYb5vz_naJqXi5rQPYtnzRm/pub
  69. https://docs.google.com/document/d/e/2PACX-1vSjPbZLXplxlDd8K8IC1Vt2mYUCrMCk5QT9OHj5kTaG7T9iqSMgOfNhWGnyD-qG5qVJDQYAotNAY51v/pub
  70. https://docs.google.com/document/d/e/2PACX-1vSLLG_TTEUDglI2ju1qUUEG3-yTK5NGPZZBujA2QEvcwDDAibFdKXOtb4mBbz5Zu5fKtlvQJee-imDN/pub
  71. https://docs.google.com/document/d/e/2PACX-1vSNTwLQnFQ-2k8cA3RZMx99r4_pxRju_7R6p8M6S2szJJhipdoNAvEpDMlaE9ksQjtCIOH6dgC3O_cz/pub
  72. https://docs.google.com/document/d/e/2PACX-1vSrxN_fpBk_e2k_oJkaJO2tx0-n7jkxdhEuKiRU4HaN01aJurLemw93g9f5rp6b4Jqejl5yQvBuYUPO/pub
  73. https://docs.google.com/document/d/e/2PACX-1vStqNpvPveJkgLQD3UUP4NrZsV5c7BWSax0X5ey0kHlFSQ36IhJhRM69LQiS2K1aVjhUIsQPdYWdnnd/pub
  74. https://docs.google.com/document/d/e/2PACX-1vSwCLTRsYLhj7M4af9gEvT39eCKNleynw3buMDTaEoXTuO6D3oPQFT5PB6bZeu-RLvuWV4xhzz-IriN/pub
  75. https://docs.google.com/document/d/e/2PACX-1vSWJUWG2Ebk2tQ5GK9nlCLAnlYFnPG8zmkEYBnNzWcPdpnJJj9TeVq_FmnK2Cdu_W2RHVpWrH3fqtdP/pub
  76. https://docs.google.com/document/d/e/2PACX-1vSyH7ZRCEnfhccj-9wagUUJF_NmEWcuZtGe60HCrbmJ96UobzyVYweHhgYC4mN-aZrA4IjN-6OMO0Tz/pub
  77. https://docs.google.com/document/d/e/2PACX-1vTaiB8oEbZl8yqRSjhGVJJm_CLfwJycU6h4Nl1L-hzjulrDOhZZvrqOiRR8pYeieU_v4YnOy7CDWKXj/pub
  78. https://docs.google.com/document/d/e/2PACX-1vTc2O33ZBR3G_dBJW0z5OjqcNbLrmz2UxFm-6qSyXEVLZvGC8z0GyS7u7aqRp8HG2kyMN1tup04GDKo/pub
  79. https://docs.google.com/document/d/e/2PACX-1vTc9ozHMmP8_b1MUcvblRkLTKUG9NISWPn1Yh2XgXpEYWwpa4flcreVnm-ANYvdCHScX587JVwzlMJ9/pub
  80. https://docs.google.com/document/d/e/2PACX-1vTcfDv_0SrlqbMtFzi6HIVmiKKNsFqd5bubueM-s-MzPZFsva62ZYnCOy-PHkZysUhuDDL0YHlYAjYE/pub
  81. https://docs.google.com/document/d/e/2PACX-1vTFghXphb23SE6rDBEtCnV-4raw2zNWQX_8qjusVoW2MdKYl29EJ08fFiUeyO0OCRIAl0HJom0-QCor/pub
  82. https://docs.google.com/document/d/e/2PACX-1vTngXmQi_f62qpADP5gKU9S_wHe2GnCgyF0SYBsh-feR1Da3NEdHx9CyIWCRNGCoyAKdZnklsWUB2t4/pub
  83. https://docs.google.com/document/d/e/2PACX-1vTqKos5ApbAXyGIv7wkHuA_wzItIhUypYxdIAslLxOrS6kwRMSLVrEw9f3xw-69PfnL10fj0t70ZRas/pub
  84. https://docs.google.com/document/d/e/2PACX-1vTvblcf2093m-J6dvSv-8SXsoQiInbrAbXwECvQYv7LnzstbDI8gPUbEG73VLv0p8ZM9DsEeNn39131/pub
  85.  
  86. MALDOC DISTRIBUTION URLS
  87. http://app.enlavaguada.org/var/www/vhosts/enlavaguada.org/sioux.php
  88. http://folstop.com/darkroom.php
  89. http://shop.blifemm.com/ferocious.php
  90. http://sitio.vipsaesa.com/assertive.php
  91. http://www.comitato-antimafia-lt.org/bifurcated.php
  92. https://ayurvaidh.com/dimwitted.php
  93. https://demo.hmsmicro.uproducts.in/amigo.php
  94. https://demo.sms.uproducts.in/bifurcated.php
  95. https://historybanks.net/external.php
  96. https://ibooking.campaignhub.net/media/avatar/portable.php
  97. https://impactmarketingservice.in/splintbone.php
  98. https://impactmarketingservice.in/zephyr.php
  99. https://kallaru.com/calorimeter.php
  100. https://koonol.mx/fiddlesticks.php
  101. https://koonol.mx/keypad.php
  102. https://merinocraft.ro/drab.php
  103. https://merinocraft.ro/week.php
  104. https://natural-healing-central.com/discourteous.php
  105. https://productoslaesperanza.co/dimwit.php
  106. https://productoslaesperanza.co/tame.php
  107. https://serdenhukuk.com/held.php
  108. https://sunrise.uproductslive.com/mahogany.php
  109. https://www.ceethoglobal.com.ng/maggot.php
  110. https://yayabo.net/prev.php
  111. https://yayabo.net/unaesthetic.php
  112.  
  113. ayurvaidh.com
  114. blifemm.com
  115. campaignhub.net
  116. ceethoglobal.com.ng
  117. comitato-antimafia-lt.org
  118. enlavaguada.org
  119. folstop.com
  120. historybanks.net
  121. impactmarketingservice.in
  122. kallaru.com
  123. koonol.mx
  124. merinocraft.ro
  125. natural-healing-central.com
  126. productoslaesperanza.co
  127. serdenhukuk.com
  128. uproducts.in
  129. uproductslive.com
  130. vipsaesa.com
  131. yayabo.net
  132.  
  133. HANCITOR MALDOC FILE HASHES
  134. 06ffd044865299dd00a7bbd0127058b5
  135. 07c3eab0e9c682aea9d1787305bca443
  136. 2e0fef3fee8ef670d59e8ffc2a15a5c2
  137. 32f4df433bc4b126c1b2c128bd10ca80
  138. 538b4631d98fbad5f46e6775111884a3
  139. 57d8c01e17a424e4fe06f80586023836
  140. 60a1ab106a4e39b39f78b6efc4ccf983
  141. 7a962931ad4b2e19cd1de99a803d0582
  142. 7cffd58544adcbd8e8ccf6ab7b099554
  143. 96dc7caf468a8d2bf285b3c44d680654
  144. 9895fb5c1d7b575fbf8251106a57e7a1
  145. a49e1e3df252e10446d928d2d55874de
  146. bf2ef626690980a47488a94ffb006c7f
  147. ee2d6d385dffa576fda4e442350a018e
  148.  
  149. HANCITOR PAYLOAD FILE HASH
  150. ket.t
  151. 35950be5426336ec2da69ec279356f84
  152.  
  153. HANCITOR C2
  154. http://lansiagerri.ru/8/forum.php
  155. http://nalbukers.com/8/forum.php
  156. http://restanumb.ru/8/forum.php
  157.  
  158. FICKER STEALER PAYLOAD URL
  159. http://obtiron.ru/6hs8usig.exe
  160.  
  161. FICKER STEALER FILE HASH
  162. 6hs8usig.exe
  163. 77be0dd6570301acac3634801676b5d7
  164.  
  165. FICKER STEALER C2
  166. http://sweyblidian.com
  167.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement