ExecuteMalware

2021-02-10 Hancitor IOCs

Feb 10th, 2021
5,149
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.97 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD=1002_280302
  5.  
  6. SUBJECTS OBSERVED
  7. KeyBank Platform Email
  8. KeyBank Platform Message
  9. KeyBank Platform Notice
  10. KeyBank Platform Notification
  11. KeyCorp Platform Email
  12. KeyCorp Platform Notice
  13. KeyCorp Platform Notification
  14. KeyCorp System Email
  15. KeyCorp System Message
  16. KeyCorp System Notice
  17.  
  18. SENDERS OBSERVED
  19.  
  20. MALDOC LANDING PAGES
  21. https://docs.google.com/document/d/e/2PACX-1vQePZdjrz_-a1sIYDl_bROT6SaDC73JS9C3Rdz2z4RFCLyBzNmKl5vjdBrtdaUDpaoniX12s8CZ1rWO/pub
  22. https://docs.google.com/document/d/e/2PACX-1vQJPgRqCRX3AnXm14I40KAzua-xp_vNhSHq_4FmJCvjXm5JTxsdaH6VwsPYLTtYYfd73z5By-oUzK-6/pub
  23. https://docs.google.com/document/d/e/2PACX-1vR7B9mYxPpyTWie3GSKxNY74rd_Cxj3xlPUNcPWgHvBtoxraQuF77CHa9CnNwHoF7nlX5TkPbTyAdf3/pub
  24. https://docs.google.com/document/d/e/2PACX-1vRaNGy8woW99S0HAgvNmcXTQiNH0E5FitxUPG9NLPALuzp4rCjoe-eCZ_8ELGIrK-Rol3Nz8fNwXyOl/pub
  25. https://docs.google.com/document/d/e/2PACX-1vRlRRshXlemxDK1eRwCsv6U7wJkeIerWIGJPx3LSasJhc07eu2a5enW80sPUCEVesFOCm09ZDJTWh3v/pub
  26. https://docs.google.com/document/d/e/2PACX-1vROqHB6lfNb_d2B2AyKzM_JuUR2fRZV6iMfAYLyUAdT4KFl00VhmylcEQ6R0OImRqsTJXcyiV9hyBae/pub
  27. https://docs.google.com/document/d/e/2PACX-1vSKl56y1YSwrh6hMm2X9x0MoARtfS-FYcnPXteFHOeLuQ4Gf_6WEuXqSC8sYUP1LvvXULzDRY4gBdeZ/pub
  28. https://docs.google.com/document/d/e/2PACX-1vSpChAwK5ApnpOZ35Z0s9kQWSkvrArer4jX6S3UCQYwzc-nhGiCPbnO9aRcDCQZzv1Sx9k6vQ6Dqmlg/pub
  29. https://docs.google.com/document/d/e/2PACX-1vT8I-AoL5-pL414JWGrMlrHbWPAGBX2tMzc02XDvqHoV6p5y4SXeoIZXCa4cXTjmxOtB2BJVYJ4q_KF/pub
  30. https://docs.google.com/document/d/e/2PACX-1vTePp_gR08Panlke-R-Y7aGHi1se59L3wutDBK1ZzKwhM5KLDOakaDNTQPwnfltgRheQebN1dTXXe5t/pub
  31. https://docs.google.com/document/d/e/2PACX-1vTM3-1zyA_zsd1v_JpYeIy2jGUxVPNd0a6wzizwIBPh0hbWZFeV8AypLSiiUuIYkfvPwLj4KObxzwfS/pub
  32. https://docs.google.com/document/d/e/2PACX-1vTMLgwpvPCFoyMPQcOQUIFD-GboOgZK7WgAaZQvmnIPDsrz0BYBw2jfXEKY0jU0D4SqtkQVtjxsQo7e/pub
  33. https://docs.google.com/document/d/e/2PACX-1vTOYkvSBuZUp-ouW4Qc7lx-M9fwZiamIuAfxe1ozGevT4T6UtoPgIZBvYtKLAF1aL9cvGJaNMyWyGaI/pub
  34. https://docs.google.com/document/d/e/2PACX-1vTtDWIx5KIBfGbp4mSrcQGUy4A9bceCxhZPQjD4RZ2GNGPMrh_HcLWfJpRvVDY6phmp9cNJMQornn4q/pub
  35.  
  36. MALDOC DOWNLOAD URLS
  37. http://premierpt.co.uk/souffles.php
  38. http://somdeeppalace.com/monostable.php
  39. http://technodealspte.com/tryout.php
  40. http://www.swingsidebilbao.com/wp-content/plugins/contact-form-7/includes/block-editor/shiah.php
  41. https://en.gooddrink.com.tr/subscriptions.php
  42. https://facturasenlineamarx.com/since.php
  43. https://old.fitbodyfarm.com/labourite.php
  44. https://pepselectricailservice.co.uk/reaper.php
  45. https://social.powerpc.in/asker.php
  46. https://social.powerpc.in/dregs.php
  47. https://social.powerpc.in/patch.php
  48. https://thequin-nso.com/hobbed.php
  49. https://ubialergenos.es/spat.php
  50.  
  51. facturasenlineamarx.com
  52. fitbodyfarm.com
  53. gooddrink.com.tr
  54. pepselectricailservice.co.uk
  55. powerpc.in
  56. premierpt.co.uk
  57. somdeeppalace.com
  58. swingsidebilbao.com
  59. technodealspte.com
  60. thequin-nso.com
  61. ubialergenos.es
  62.  
  63. MALDOC FILE HASHES
  64. 2dcc62745bcd3679e5db93ac5adf9446
  65. 2f7e7319df6e084fb0e35ff15b0d0158
  66. 374d832773cff2a16d0163ea3e2106e6
  67. 4f1e1c7ec9508e704c09199d3a56f7e2
  68. 84a34dc5171a911f502d857508a86264
  69. 95c11a55ae5fefedff50ccc27a73e549
  70. bbd3469be1564ec5972eacaf57149434
  71. e3dd781f9b782e0c6ea02e171431435f
  72. e56c935300fe5b670454fed48df8911b
  73. f6fa699803007d4414bb30df527b6a6d
  74.  
  75. HANCITOR PAYLOAD FILE HASHES
  76. W0rd.dll
  77. 04e64b9d55adb9a8bc7d570cb77adf0a
  78.  
  79. HANCITOR C2
  80. http://anumessensan.ru/8/forum.php
  81. http://grectedparices.ru/8/forum.php
  82. http://shifiticans.com/8/forum.php
  83.  
  84.  
Advertisement
Add Comment
Please, Sign In to add comment