ExecuteMalware

2020-10-20 Hancitor IOCs

Oct 20th, 2020
3,929
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.96 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Signature Service
  5. You got notification from DocuSign Electronic Service
  6. You received invoice from DocuSign Electronic Signature Service
  7. You received notification from DocuSign Electronic Signature Service
  8. You received notification from DocuSign Service
  9.  
  10. SENDERS OBSERVED
  11.  
  12. MALDOC LANDING PAGE URLS
  13. https://docs.google.com/document/d/e/2PACX-1vQ2_QVmL13WvuV9TNRBqBBaTPYsdyx-Nz2nLaM9EojKtNRjitS2nmk2bx_KbEaYOjcS085HxdnBj_zb/pub
  14. https://docs.google.com/document/d/e/2PACX-1vQhndfOxhPD3jQQ73J8KxppCdzOAKRo4ObwzsBiC8GfFjhPbEw_16_StST_5HZUPkC4kAttI%0D%0AbFPHJ8o/pub
  15. https://docs.google.com/document/d/e/2PACX-1vQhndfOxhPD3jQQ73J8KxppCdzOAKRo4ObwzsBiC8GfFjhPbEw_16_StST_5HZUPkC4kAttIbFPHJ8o/pub
  16. https://docs.google.com/document/d/e/2PACX-1vR4nGUu16IcLQooUvA0UiWDSGdFZr0w-FizWVaAC0hE5LLRMk7fvEGV0Rpk35LvWxF-9z5elns6G4nf/pub
  17. https://docs.google.com/document/d/e/2PACX-1vTXyLPCBwzVDJyFIjQq6tJyn2PKAfe261LdpiIaFjD1oMM3G893avJgxtqYeRSuBKNISaf0MO3GPQhu/pub
  18.  
  19. MALDOC DISTRIBUTION URLS
  20. http://dieeulenklasse.com/pack.php
  21. http://owlmarketingexcellence.com/dismiss.php
  22.  
  23. I couldn't retrieve the actual download url for the .xlsb file.
  24.  
  25. 10_20_report.xlsb
  26. 28ab25f8f1addbd3c9a93d156e7407b1
  27.  
  28. HANCITOR DOWNLOAD URLS
  29. http://marspetcarelawsuit.com/xls.png
  30.  
  31. HANCITOR PAYLOAD FILE HASH
  32. xls.png
  33. 83ba2586ea176dfb069ec4bf49439d94
  34.  
  35. HANCITOR C2
  36. http://stylefersan.com/7/forum.php
  37.  
  38. SECONDARY PAYLOAD
  39. http://nepbag.com/f3.exe
  40.  
  41. f3.exe
  42. c9917fd15fed108ad9d6ee548dd2e4c1
  43.  
  44. UNKNOWN C2
  45. functionalrejh.com
  46.  
  47. SUPPORTING EVIDENCE
  48. https://bazaar.abuse.ch/browse.php?search=83ba2586ea176dfb069ec4bf49439d94
  49. https://www.virustotal.com/gui/file/dc7f971af6d534662501decd86d0cb8d58392149a0cf06a236f6aec2490808aa/detection
  50. https://app.any.run/tasks/0df02d87-76ef-4bc1-813b-45d974b5b517/
Add Comment
Please, Sign In to add comment