ExecuteMalware

2020-11-05 Hancitor IOCs

Nov 5th, 2020
4,116
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.42 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Signature Service
  6. You got notification from DocuSign Service
  7. You received invoice from DocuSign Electronic Signature Service
  8. You received invoice from DocuSign Service
  9. You received notification from DocuSign Electronic Service
  10. You received notification from DocuSign Electronic Signature Service
  11.  
  12. SENDERS OBSERVED
  13.  
  14. MALDOC LANDING PAGE URLS
  15. https://docs.google.com/document/d/e/2PACX-1vRhOFdbCP5WgkUWJ-8n8KBaWvjsA2OF1TJNCWfMO7LEc_8j0vWey-ybgkn3YpDZYOPPH0S_pAqHAeTe/pub
  16. https://docs.google.com/document/d/e/2PACX-1vRnS63LCMGaJ1q54IMJaM5Nwx5XfPBr4S10SwtJ_-71jVZElCknScBWe5xtuzYJnFiAHwAy5v82qhxS/pub
  17. https://docs.google.com/document/d/e/2PACX-1vRX7Zo2XeQJ-R_cYwaBU-_4EAluXTm5I91a1bjFe2ZXCtRBGZTWWgrFKecl6joHedcFdHWHt1bk8T0s/pub
  18. https://docs.google.com/document/d/e/2PACX-1vRZErlpxqbjVczPzSUZqHtLVUxcKuTdkIb4LaxkxfN5OtNlftlMzfBsPVNQJLmBtAwiSIzJsVMxYcCn/pub
  19. https://docs.google.com/document/d/e/2PACX-1vSLp5ANN4q2i50ow-mgALTzIzoGqF3Y8qORs7DAKIP83QN7FyItkbE8Gb5u_5qYqLoKWd63T7a1nTU5/pub
  20. https://docs.google.com/document/d/e/2PACX-1vSsq1rord6OYY4vmM3heocyLD8uu5zQGgRmN8hXHxNqEFta1HtbeQEG763Tl0lDa5bGMGcpreCNBEBG/pub
  21. https://docs.google.com/document/d/e/2PACX-1vTkmqCe4oJCgwMr-_naWlpM0V3AE9V01mz6kX-QZOtRvnjTuoti369Njkk72JUHfkRovr6z0VJ_1V9R/pub
  22. https://docs.google.com/document/d/e/2PACX-1vTTNBNVfnadxdQ0Yx89ABSo8dWoBxW8jCemmIXp59SDegHTimIAG3cVeAD5B-VawhYIhoIfPIVYYj3z/pub
  23.  
  24. MALDOC DISTRIBUTION URLS
  25. https://asoukala.com/surprise.php
  26. https://imugan.com/instructions.php
  27. https://rishtiindia.com/celebrate.php
  28. https://rmwshops.com/vary.php
  29. https://sedgefuneralplan.com/interest.php
  30. https://testleadershipcongress-ny.com/start.php
  31. https://webseriesaudition.xyz/growth.php
  32. https://yarazon.com/update.php
  33.  
  34. asoukala.com
  35. imugan.com
  36. rishtiindia.com
  37. rmwshops.com
  38. sedgefuneralplan.com
  39. testleadershipcongress-ny.com
  40. webseriesaudition.xyz
  41. yarazon.com
  42.  
  43. HANCITOR DOWNLOAD URLS
  44. Embedded.
  45.  
  46. MALDOC FILE HASHES
  47. 1105_748543.doc
  48. 52fd82d4e234d5f913fd89a000d20171
  49.  
  50. PAYLOAD FILE HASHES
  51. hancitor.exe
  52. 9d87adf0cb56ffa905a7a811169068fd
  53.  
  54. HANCITOR C2
  55. http://albilverde.com/7/forum.php
  56. http://fabickng.ru/7/forum.php
  57. http://fineladiver.ru/7/forum.php
Add Comment
Please, Sign In to add comment