Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: HANCITOR
- SUBJECTS OBSERVED
- You got invoice from DocuSign Electronic Service
- You got invoice from DocuSign Electronic Signature Service
- You got invoice from DocuSign Service
- You got invoice from DocuSign Signature Service
- You got notification from DocuSign Electronic Service
- You got notification from DocuSign Electronic Signature Service
- You got notification from DocuSign Service
- You got notification from DocuSign Signature Service
- You received invoice from DocuSign Electronic Signature Service
- You received invoice from DocuSign Signature Service
- You received notification from DocuSign Electronic Signature Service
- You received notification from DocuSign Signature Service
- SENDERS OBSERVED
- afuzuzo@floydnicholson.com
- braig@floydnicholson.com
- duotp@floydnicholson.com
- ecaie@floydnicholson.com
- ejxot@floydnicholson.com
- hyajde@floydnicholson.com
- miizjda@floydnicholson.com
- ocyeo@floydnicholson.com
- qwyge@floydnicholson.com
- se@floydnicholson.com
- tuarim@floydnicholson.com
- tyrwgi@floydnicholson.com
- uuiahus@floydnicholson.com
- vjgyjkx@floydnicholson.com
- xabucen@floydnicholson.com
- xhuibba@floydnicholson.com
- xoh@floydnicholson.com
- ylagu@floydnicholson.com
- ymireut@floydnicholson.com
- yygaura@floydnicholson.com
- zepa@floydnicholson.com
- MALDOC LANDING PAGE URLS
- https://docs.google.com/document/d/e/2PACX-1vQc88iU_WCWi4r5FLV3uH-z0pctXFkzlW1hW3HSWGIOGgpjVQc87rHW6rCOXtbvZHl6siV_JyH7k1iC/pub
- https://docs.google.com/document/d/e/2PACX-1vQSA5USANUjlM90dkdbHIbt9xUQB2feG6QcMUuEmPmqj1cfiNUlclxoVe7k_AN7Q0JqvYD23heyU9Wx/pub
- https://docs.google.com/document/d/e/2PACX-1vQSCdtMM5mZZCDevBH0zvGZCAnQUhibsMbbvxzi36HdlJUppe-WJ7HkbwJ4EGoBB8jk5O7_0FOKFlSp/pub
- https://docs.google.com/document/d/e/2PACX-1vQsmFd6Xle8pZh5x-uUBgQ5JjbO90iwUqWiGGjPYNDihUWWcanwBKyv1Q1VR5zJf1xhDamn3GnPg3b0/pub
- https://docs.google.com/document/d/e/2PACX-1vRd6YtFRMDlPDXMdCxCpS7tav8XR8v29AeeUWzdRkMHDWHsV7qv7-KDX5oc4CfGi41-jaOd221w0aRS/pub
- https://docs.google.com/document/d/e/2PACX-1vRsSKJQPEW3m3Fom2c6u-xvcul3d4Wm7wirCRwh38hnWHraCfr2od7FUEuf1hi1Pw1aceMFxHB4C3DZ/pub
- https://docs.google.com/document/d/e/2PACX-1vRtk1PRA0BVD_VDYnBhT0y7ssOzM_Ax-idGnyAEzNSeIG1Q3cwus_O7PzF_-5txlK_Y-BeOIIr0G0c3/pub
- https://docs.google.com/document/d/e/2PACX-1vRU0BRzKsjpwwKtydG4jNMCHQirgad9Qig2A2tjwuP9XMkprtC_scDIsg7TrXObUzWyJv2Ya%0D%0A7uI6MZe/pub
- https://docs.google.com/document/d/e/2PACX-1vRU0BRzKsjpwwKtydG4jNMCHQirgad9Qig2A2tjwuP9XMkprtC_scDIsg7TrXObUzWyJv2Ya7uI6MZe/pub
- https://docs.google.com/document/d/e/2PACX-1vRWuD1KwvDa5JUqDb-r-jCwG7yku_NrBMhi_IeDVmVSmvA2wLKxiUYRCp1_jBn0Y0qaTj9T-VysaXby/pub
- https://docs.google.com/document/d/e/2PACX-1vRzrKqUza3n5ftqBqkQM0MF6L9YoRbBeZwnQK8ELbEkCcn4e5BNaJxlBeJpSPqatot_zXcvZ%0D%0AEaAnoyO/pub
- https://docs.google.com/document/d/e/2PACX-1vRzrKqUza3n5ftqBqkQM0MF6L9YoRbBeZwnQK8ELbEkCcn4e5BNaJxlBeJpSPqatot_zXcvZEaAnoyO/pub
- https://docs.google.com/document/d/e/2PACX-1vSbHz_F_hKGpgmPzpwpE_ee63vyd4g9X2hYpqoJ4z6a3C7WLOSSWwcbRiOlnvyZtQ2nCl_V40YpUyqQ/pub
- https://docs.google.com/document/d/e/2PACX-1vSPGLjKPT6w1mQ5a-6Zpa9wL7hrIU1mQjTkqW7eynKd9xkQGYJQfHKW9hkk-5FDhz9mPD1xfra_NIht/pub
- https://docs.google.com/document/d/e/2PACX-1vSTclS6i551ofwp2g5SPWUuX5dbJX8qarqTMcWADhtqcBGyLa75fUwMKABqdwqP3ZOlX9Cfq%0D%0A4MilpIX/pub
- https://docs.google.com/document/d/e/2PACX-1vSTclS6i551ofwp2g5SPWUuX5dbJX8qarqTMcWADhtqcBGyLa75fUwMKABqdwqP3ZOlX9Cfq4MilpIX/pub
- https://docs.google.com/document/d/e/2PACX-1vStyWSsVJHCQKeEQVZSu1CRhE0a1tVx1Z0Xpk_w6QFTT8iJJe3scvhTZIGbdhvzpYFTdS0MqDVwMlF0/pub
- https://docs.google.com/document/d/e/2PACX-1vSV6QSp0_py93Kl8XDuP34nmKlZIF8rxTmlIiHRio4XOejEom_zx1_3CJKSAa0jongWxwFaB3VNPNQs/pub
- https://docs.google.com/document/d/e/2PACX-1vSZtQQrBUMabaJCMFZRRww6NQjXijWc7_I4Zn4dLoD5al9uVYrDYDGTX-sBIqWvQUdFYJgDh%0D%0AKLgpXYU/pub
- https://docs.google.com/document/d/e/2PACX-1vSZtQQrBUMabaJCMFZRRww6NQjXijWc7_I4Zn4dLoD5al9uVYrDYDGTX-sBIqWvQUdFYJgDhKLgpXYU/pub
- https://docs.google.com/document/d/e/2PACX-1vTbyJX3pep_PAldD2h6Vh4JoiP-M6ijEefUwpfDZHxl8aRpDL5buT4GLnD8yJyRvD6ogvShYLDFKIqF/pub
- https://docs.google.com/document/d/e/2PACX-1vTnNg6VsNA-C00rk1xV33vSY0DompdjccXo_8qBr28VWGRQhn4yYhDiF4STYW0_Fplj5R-UryKZQk_z/pub
- MALDOC DISTRIBUTION URLS
- http://actorwebsitereview.com/subcutaneous.php
- https://accounting.marayo.com/manipulation.php
- https://caamitrjain.com/summers.php
- https://caamitrjain.com/warped.php
- https://edukare.info/alias.php
- https://edukare.info/resettlement.php
- https://merchants.nupayonline.com/layering.php
- https://rumahsyariahmks.com/aloe.php
- https://rumahsyariahmks.com/julie.php
- https://rumahsyariahmks.com/meteor.php
- https://rumahsyariahmks.com/salvador.php
- https://sedgefuneralplan.com/anxiously.php
- actorwebsitereview.com
- accounting.marayo.com
- caamitrjain.com
- edukare.info
- merchants.nupayonline.com
- rumahsyariahmks.com
- sedgefuneralplan.com
- HANCITOR MALDOC FILE HASHES
- 1125_689110860.doc
- 6c13a87b6dca116139e7161728486acd
- HANCITOR PAYLOAD FILE HASHES
- W0rd.dll
- 1bd7c9d9b5959607875d6ef7a8290162
- HANCITOR DOWNLOAD URLS
- None - embedded
- HANCITOR C2
- http://bilighbohooll.ru/8/forum.php
- http://lielftworiss.com/8/forum.php
- INTERESTING STRINGS
- c:\MapTiny\touchAfter\SpellTook\UnitDictionary\Walk.pdb
- https://beararrange.com
- C:\Users\win7home\AppData\Local\Temp\ya.wav
- 2016 Fig Chooseremember Corporation. All rights reserved
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement