ExecuteMalware

2021-05-24 Hancitor IOCs

May 24th, 2021 (edited)
16,014
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 16.21 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2405_pin43
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC LANDING PAGE URLS
  27. https://docs.google.com/document/d/e/2PACX-1vQ2OKVYRiO7-N_liKH6ddAFupYPRfJq7AE173WQJPcSuUNu5cH_9xpdXRLOqeb2HkSLfIsf2UkALk6j/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQ3FKZKG0-szrlLS1gJ7ufENQvrlw7LTT5RVWm-zAX9Zca8kFooe8fHY8uD21T1abvE-_r-4YcnL3MW/pub
  29. https://docs.google.com/document/d/e/2PACX-1vQ51pVbbj4wdlcxYrptavD5Oy6ocWZSnxg0nOHC3aQo1UMIoxUiZqtxPzITZ88gJPZEF9iu9ItHFg9u/pub
  30. https://docs.google.com/document/d/e/2PACX-1vQ5mIwSJ8U6ChjPWD2a-RxPbQKnZKdRw_y7Sr9vOIAA2DGCZSBnm2Qlo6GqdSxzL-K9yBXvXhPAE_m4/pub
  31. https://docs.google.com/document/d/e/2PACX-1vQ6nR-yG49VLDzzxLiqVpUPbAjoSs2NfXsnsK3KhaixmvqYDl20mXHTtP-qa7MojkWa4Osepa76nNbl/pub
  32. https://docs.google.com/document/d/e/2PACX-1vQ7f1PYDrZGRRGfa8VbuFtPNpyVQvbts0Kk4Dk2EUrFQU4P4Tb_E_YsYiooaaYDVwv3eUKIK6XvEYTY/pub
  33. https://docs.google.com/document/d/e/2PACX-1vQ8RNjYGMksylFmdhYfrOrM3nB4LEV8wZ2o8fevuQSTd1zhd1-Zw5rO5q6tUL-nKQnSttCM7GMLXsug/pub
  34. https://docs.google.com/document/d/e/2PACX-1vQ90qD-Vz_sTJpM62udvfE7h924GtPClpc43VgQIIbdKUm9VjMDxJyDal_EzMJUrWODXDluSv4gUO5x/pub
  35. https://docs.google.com/document/d/e/2PACX-1vQ_S5OcXxisZi6BlsWgtkBOZNti7qw4owEtfvrG-Ou0yNcFeVlmJIQ-mWJhOakgULezm_Wxh79TxnsY/pub
  36. https://docs.google.com/document/d/e/2PACX-1vQeIMxav1ELjPH0Xls4ZAruolrkRkadiLoAQSgkzCzyGHbi4M0yrHO3Ggg8Wde9xLYt5CQrCX1UimVu/pub
  37. https://docs.google.com/document/d/e/2PACX-1vQgikP7j-IggYB2Jfo-6PKTGjhRgoV7N61jm-QGZz4H3tnBoXfJQGs87Qr8C0WJs3qS-3st_ZgyJfFN/pub
  38. https://docs.google.com/document/d/e/2PACX-1vQHv1Ns1iDvUKZKn095xGdDS_HdxCby253LX0DAVF6JpPbdCvRa3EbBTboe-QZ4-fOA2KpJKspW8933/pub
  39. https://docs.google.com/document/d/e/2PACX-1vQMcls2tVa-Ot83JOAYqXpsnh7cr4vxBMJx3ouKCu37rzcoQKiQxoFMz8zxCZIWme892OJ0HcQWXjcJ/pub
  40. https://docs.google.com/document/d/e/2PACX-1vQpXyhJ8LwPkAxi6SSxPMzT9VJBv-vUNWz4HNf6XsxUHzzpMedq2ZLR4KaFee7WBQNsi_zUJgmm6sE6/pub
  41. https://docs.google.com/document/d/e/2PACX-1vQUAo8A5DDsfZos3avXgOVy63sKH-lsGRsJe2-N4_xFxj81L1eyd5OvQW2XND6g0GUGdqmS1yl0LR4D/pub
  42. https://docs.google.com/document/d/e/2PACX-1vQX_D_g3zEzhkn1eQYmblQ-eo2f48ZrvYL9Q1Ry4kVOYiRgp2CmmZpipf9Kxd5Cv-xnl-nRbax4l4lJ/pub
  43. https://docs.google.com/document/d/e/2PACX-1vQXjGucICrpk_wjWZCVa5mB3j2xEWey3xSVL0YbXvkU5D6zsyX5VwnEAm2hu3_5Y0fBypnJx2Rwg4c8/pub
  44. https://docs.google.com/document/d/e/2PACX-1vQYoWYOXAtA2couQA6uc3GWi59Sq5MAUAlR7yfMq6LuzVtEfQoPOGnCbLI8hX6vUBkt2b65QerqHZy8/pub
  45. https://docs.google.com/document/d/e/2PACX-1vR-an2T3T0zlWERX1hhZz3VXhLq24IslBXgN1pxkJiz44MfRwRPPSmSOvFzeshNGy2cskegEfZYm4K0/pub
  46. https://docs.google.com/document/d/e/2PACX-1vR-g0tCX7JRpTIyZMPbqplWnyXLZjIw8zRvSX8vwWBSWkAls_Dtx6Ba1ZjbVkKEnFMukVyVkWzkcgUs/pub
  47. https://docs.google.com/document/d/e/2PACX-1vR1e4KzYqnEOh2tJC5Rh_unLfWJdo31GedrvEg0wDYrPRmm3YFDxJQXDVyy535adzU5P9m4mrVDAU9v/pub
  48. https://docs.google.com/document/d/e/2PACX-1vR60n92Le8SmKRb-DV0CuhJqIZL5g4dM5g2_iIxNeHLTn9EYJhOCDMz_7aKifcHXBIkYDteTLvjid6H/pub
  49. https://docs.google.com/document/d/e/2PACX-1vR6ejqvOFG5R411G0gZJEvO7hQhIaCwWyVLAOuB6GvsyEfgvZdiVn0GD7avsjQ_DaLvI7wCGVWOgHlW/pub
  50. https://docs.google.com/document/d/e/2PACX-1vR9dl27nBxMONDeHOmdDWKGsQz1PF05DzUTtj-0dC8hD_PgXRuDfh4T4OxCus4OFcwRjWgevpaaYEeW/pub
  51. https://docs.google.com/document/d/e/2PACX-1vRaz66alGS2CzFdzTOXpRjfpcQ3Dp-fbbfHxFYnpxsefkahQ8L73gD28eb-QAKZ1OL9vIHfB5lWpbL4/pub
  52. https://docs.google.com/document/d/e/2PACX-1vRBfopfr9pnC9jOXZW94jPhjCOgiEnA0WTsGrpFAZKWqkUxvMAuTTLj8l5NVq_ntq5M7F7SJcj_3VaQ/pub
  53. https://docs.google.com/document/d/e/2PACX-1vRdqqo-Da4HBrs1-OllK_oVH1AHhdynY3ROQr1YiqZwcgPKlNwEKNDvL5FwWGf0dD5BWU-5XZbHtG0b/pub
  54. https://docs.google.com/document/d/e/2PACX-1vRFTgyuOUy2tRckpqTTVA33_O_b3rkoAl4neZGcEbKhwURmE_jIRjMA7b9sPKeCqWMi90Qt7wIo7SLn/pub
  55. https://docs.google.com/document/d/e/2PACX-1vRI2XF4UtXdBhVtpChMjklgaAsPrsxsOMvflPy8DfOw3HZsrAsp95ZZ71aMzeV0nPW2rduq06qjatTv/pub
  56. https://docs.google.com/document/d/e/2PACX-1vRiTLDCvNRp4ppcQOgk5rJFcvHiUQ6za0idWADQcfT6Z0pWp3RIwkqfip0sBbVoA8sjH-sdGrTNDwO6/pub
  57. https://docs.google.com/document/d/e/2PACX-1vRnOtUnmTLwxaTeQhzkdlOnw4IHm3z1yCmyTvfReTNHamFkPK_WRopfmsdQUYkPeHfHspCXCwi_JDK2/pub
  58. https://docs.google.com/document/d/e/2PACX-1vRp3-oZrZw8zGa6nNwc75zgVwcy1pEhVaYXU1VvOLUKMSskcPuFyBkXQyucHro-ISKd5OeN2houcMSN/pub
  59. https://docs.google.com/document/d/e/2PACX-1vRP_rUnYsZTo5fOdEjBoXrco7mW1x3FM6eD_yEj9SNpxNUroXAzS1j3-icJ9hzQTJqLCior23xBbRRt/pub
  60. https://docs.google.com/document/d/e/2PACX-1vRqd48WhzscpjIZfKg5_u9EQs6bzFXiUXzYMVH0pU5axyoEFPAkdHsdGMPBSdgp66cwc9XUrc5cbbXd/pub
  61. https://docs.google.com/document/d/e/2PACX-1vRVMUtAxfc2EwKVy_L_CeWFjWv4Md_UADQlV4onmlyC0fRnP7jOD3ru93SM6Y-tMoJ0NrvBFYLT739Z/pub
  62. https://docs.google.com/document/d/e/2PACX-1vRvNJh74ORRZJnn6xmuW6yG6EjNGb5HJI98-95-8vf4kNIq_LBDX5b3W-7hNfWusZPk0Eyj094rLMWA/pub
  63. https://docs.google.com/document/d/e/2PACX-1vRziYoeeXrq6-9gkFntqGUMvY1YIaLlbu_c0nUDk5D2L9vvYavMTLTVDvHx-NGa8dakcw4V8LPQmXxx/pub
  64. https://docs.google.com/document/d/e/2PACX-1vS_a7CW-gv5APVvAlD9CL3gpFxidgake8Y8yAjybwug1uKAA9BdDbCUPXd15K5WnBCiPXP65Bt2VHbC/pub
  65. https://docs.google.com/document/d/e/2PACX-1vSdEI5KmaGhv9_P6L5WoCaBSDTIQJ2hMpNYanIFf6NNCCjiiMi4cy5Snf2nnsnYcQfgBVa3eq4CdfC1/pub
  66. https://docs.google.com/document/d/e/2PACX-1vSelSFfVVgX36Hhp78ulTKwH-F9F6L5JiEB7m3tw4K89dsRZAFus0PyYQK_Ng3hfPJWFdN7Ggcc71rm/pub
  67. https://docs.google.com/document/d/e/2PACX-1vSKQUWlGP5mHCbSapDO5IU5vPZZX9-CNQ4RMms53zdGwyhZ66wW4VhtrBBpfWIX0oFtzMtheZLp6_Sz/pub
  68. https://docs.google.com/document/d/e/2PACX-1vSLAZyud3VpIxueEVU3IFJqpmdPZUSdYwZxJ5cLECsjJLHUeCb62RFOU-3tUoZW_adOvKVMqB6DMlwU/pub
  69. https://docs.google.com/document/d/e/2PACX-1vSNJCo8X07pHfFvX3SpStSIdx240UNEcc4zS7lwf421sRsF43CFQ26a14oaYblNyAGm7DhqU7H-fzHa/pub
  70. https://docs.google.com/document/d/e/2PACX-1vSOfaCR5qubewzCW7PzzT7XkC7n_hO3LFu0pmEdLK3UEM_zWaQ0U7DDzkm-Jk-Y7jsc1NduKRSHazia/pub
  71. https://docs.google.com/document/d/e/2PACX-1vSqAd2tYC4h5cO9Lt4sGumzOLlUzXxxJw15AcwIGoqStWGujXuLyNbwwsRy6oDYvA9nPTt3Wip7v41z/pub
  72. https://docs.google.com/document/d/e/2PACX-1vSr2L5yA9JNzBPUGHrA6ZiaDouh5tEbLF7ocmNV5iul2prKxAw0KqQprIxWikcWQvNb1xjPCa1AAaiB/pub
  73. https://docs.google.com/document/d/e/2PACX-1vSUYUcHeWCrNMS5C1wCdUv_ecRfY9OPZ_CvRvYEuFPetyR_jHB0biHIeWSZcuKmGkWszZF5g-MWlx5n/pub
  74. https://docs.google.com/document/d/e/2PACX-1vSXwD3jwDpqjwyOHonK94uPfGDt4bUTlKOqWNumfTIReM-BuRJLY7YGaMrkzGVJCRAhU6VDx69kIY0S/pub
  75. https://docs.google.com/document/d/e/2PACX-1vT49hM35YSJNG8DzRYq0mNgHgYnOKrd2q18T8NzJpUyBVeZkZd_FNurHyaUc2VHeUp0hPAGZUL66F15/pub
  76. https://docs.google.com/document/d/e/2PACX-1vT4iy9nlwUov8HsMPYkbfKn1FH1yDP7mS8Dudg2ldfjGxF8rumDtZGiW7ukoIFo3aP-pB7ybzlCdFqi/pub
  77. https://docs.google.com/document/d/e/2PACX-1vT9G-t_idHLH6i1ZECtZzGSlyNAMWce8xUihXaJ4d5bXmHiNKkZuB5aI0hBt5L9tlE5RhqBXmoivlL_/pub
  78. https://docs.google.com/document/d/e/2PACX-1vTbpdqSPndK6y6tHPAAMNnszrAAP2dBoCefIJip2i_8gbkUXFl_dIBiomEi4o2arxx1lpWtx4mInpqG/pub
  79. https://docs.google.com/document/d/e/2PACX-1vTbWHMy5C0ZDkym6jzYav6Y6Jnd6PIVWtIErYe88GFOMRObSgPyNBQVw5suD1ofwZtOrUBDmFpkXO6_/pub
  80. https://docs.google.com/document/d/e/2PACX-1vTc2Yx_CyhCCuYCE9bCh81bHnXQUZMCBFsTTOFNczm_d6qR-Bbt07MyzS9qAeLFYbGhwovM23qpyuT4/pub
  81. https://docs.google.com/document/d/e/2PACX-1vTc6avlDW-W1kSq8ycLV_tHX63IvimlxYk3xZ8ftwQj4A83ETAmR5SvZV3S-ZkGIJTlmvRyqGeLGy2s/pub
  82. https://docs.google.com/document/d/e/2PACX-1vTEcBRofm9hcrdMzZ8G7KtNeypnRPR1s7BvYoIT3r8jD7rjaNMYSK9yyuhvzmDp3DmKD-xsS7kpYfFa/pub
  83. https://docs.google.com/document/d/e/2PACX-1vTFPj3rMV4MngvvB5ueUY_evZF2BwmEqpdV608mkh8uFlSs0uj0kk1Thz3SyvM7sC2az-PCSVbzuDxy/pub
  84. https://docs.google.com/document/d/e/2PACX-1vTi_i22v4voKJuzf4dsN4Bw_R2_hlB72HySf4-nnHgh051ackCKJQg3Iz5DXVFW2o4CxH5krHqBYMQo/pub
  85. https://docs.google.com/document/d/e/2PACX-1vTlrXjiTnJ411WnX5x6OQvUqxHXKuGhf3ZGWByo1dFKW9nMGeVWwMBquj5GWzm-FtlswkE31nGPP0nC/pub
  86. https://docs.google.com/document/d/e/2PACX-1vTpEC-9ipBEZUEeLkMX9YC4_eboXvavyLowKPwtlseWCHCm-86QglvHDifjbuq78dpY4ltoOHPjbTZQ/pub
  87. https://docs.google.com/document/d/e/2PACX-1vTPhoLmraa4dir0Lg8Z5YHQlJWbZp0qkYpC3jax6d3L0Hs6n23KPm2IQgCCjvBvug5Th443jjBzs2uv/pub
  88. https://docs.google.com/document/d/e/2PACX-1vTQDX1PLKsrp41ZifKxbGT2QIsYRmjxhm-ILEtItex-YLTwnaOsBkvaY-OUmTCqqZyJHI9sqlU6N8cj/pub
  89. https://docs.google.com/document/d/e/2PACX-1vTQfGUeOm6qBua_nBg89oFIZ57-0TraBjrkP2d5MbAIFbX0rvaFPXfD21f6KfD45Ci2plBFEbbJUtIu/pub
  90. https://docs.google.com/document/d/e/2PACX-1vTW0ODoVVmhD5--VkBajfeGVHue1I1KyKYVawi5IonZki7u66PSv_ufVYMWg8oOTTvXNmWnV89--VqQ/pub
  91. https://docs.google.com/document/d/e/2PACX-1vTwD3Slu41Gq9SxdDhIdeWtWg8InlxJcPxykldkehGKBOWr2ZVOSulEdo7mWvR9uAqw_8Da_0vCt1oP/pub
  92. https://docs.google.com/document/d/e/2PACX-1vTyg409rJv4Omi3OuJyjsc6AjZfllUuz37ofzBpJJiHmrewoH2EHp2PwbflLGYy_YZQDRLdwcaeJVD5/pub
  93.  
  94. MALDOC DISTRIBUTION URLS
  95. http://app.enlavaguada.org/bingo.php
  96. http://app.enlavaguada.org/var/www/vhosts/enlavaguada.org/planar.php
  97. http://app.enlavaguada.org/var/www/vhosts/enlavaguada.org/semifinals.php
  98. http://cariustadz.org/algebraist.php
  99. http://cariustadz.org/pewter.php
  100. http://drive.tarsusbilkoleji.com/rummage.php
  101. http://drive.tarsusbilkoleji.com/walleyed.php
  102. http://ecofiltroform.triciclogo.com/swellheaded.php
  103. http://glendalefood.org/declaring.php
  104. http://lightproof.30seo.ru/beatification.php
  105. http://sitio.vipsaesa.com/redlining.php
  106. http://somdeeppalace.com/attend.php
  107. http://somdeeppalace.com/muted.php
  108. https://agencia.viajesmairma.com.mx/discord.php
  109. https://demo.hmsmicro.uproducts.in/arranger.php
  110. https://demo.hmsmicro.uproducts.in/unapproved.php
  111. https://demo.hmsmicroex.uproducts.in/cavalcade.php
  112. https://donatonpavinginc.com/coin.php
  113. https://freeanimation.org/anesthesiology.php
  114. https://hellobot.kinqo.com/going.php
  115. https://hellobot.kinqo.com/sovietism.php
  116. https://iastoppersmantra.com/shovel.php
  117. https://ibooking.campaignhub.net/bitter.php
  118. https://insidebox.pt/counterman.php
  119. https://kallaru.com/bewilderingly.php
  120. https://koonol.mx/predominantly.php
  121. https://natural-healing-central.com/scuffle.php
  122. https://nicelyeg.com/archbishop.php
  123. https://persuade21.com/dialog.php
  124. https://persuade21.com/topping.php
  125. https://skyshopzone.com/firefighter.php
  126. https://skyshopzone.com/psi.php
  127. https://tortabg.com/allowedly.php
  128. https://www.ceethoglobal.com.ng/sinisterly.php
  129. https://www.ceethoglobal.com.ng/wp-content/themes/sarraty/woocommerce/global/embitter.php
  130.  
  131. 30seo.ru
  132. campaignhub.net
  133. cariustadz.org
  134. ceethoglobal.com.ng
  135. donatonpavinginc.com
  136. enlavaguada.org
  137. freeanimation.org
  138. glendalefood.org
  139. iastoppersmantra.com
  140. insidebox.pt
  141. kallaru.com
  142. kinqo.com
  143. koonol.mx
  144. natural-healing-central.com
  145. nicelyeg.com
  146. persuade21.com
  147. skyshopzone.com
  148. somdeeppalace.com
  149. tarsusbilkoleji.com
  150. tortabg.com
  151. triciclogo.com
  152. uproducts.in
  153. viajesmairma.com.mx
  154. vipsaesa.com
  155.  
  156. HANCITOR MALDOC FILE HASHES
  157. 0310118cfc252522ac82f026853b1086
  158. 10d7815eb8849cea7baa4315976dd368
  159. 7588ae6468bbe999269d115c34e49fad
  160. 7bfe058e58ad8c0e3c9da0036172290e
  161. 7fe4fe565e70d93d3204ec02a4fbf612
  162. 9703627281db4fa37f47a9c4fe923710
  163. b8c671b138a1b72acb25ff8df7c86c35
  164. bf442f3e1befd79e44cd31eb5b52c334
  165. c3d90726fc43291111971c9d032e74f6
  166. c74c0334ed04bc42c829b1db831775a2
  167. ca999f765f35d0988e451960ca718714
  168. d08cf1dfbc61fb6aa5ed4c2969d05c2d
  169. d57b699c97bece0f7173aa3febb6012a
  170. d6bb040323781474545cfef4abdefe30
  171. d9c3526d4601d49ea27f3d1efa1f1647
  172. f7f02a918fa53ac456dfca793dc9ea3f
  173.  
  174. HANCITOR PAYLOAD FILE HASH
  175. ket.t
  176. f0ee2e74b75a44e4a7dee58846a50aea
  177.  
  178. HANCITOR C2
  179. http://thowerteigime.com/8/forum.php
  180. http://euvereginumet.ru/8/forum.php
  181.  
  182. FICKER STEALER PAYLOAD URL
  183. http://gromber6.ru/6hjusfd8.exe
  184.  
  185. FICKER STEALER FILE HASH
  186. 6hjusfd8.exe
  187. 77be0dd6570301acac3634801676b5d7
  188.  
  189. FICKER STEALER C2
  190. http://sweyblidian.com
  191.  
Add Comment
Please, Sign In to add comment