ExecuteMalware

2020-12-10 Hancitor IOCs

Dec 10th, 2020
4,320
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.38 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Signature Service
  5. You got notification from DocuSign Electronic Service
  6. You got notification from DocuSign Service
  7. You received notification from DocuSign Signature Service
  8.  
  9. SENDERS OBSERVED
  10.  
  11. MALDOC DISTRIBUTION URLS
  12. https://docs.google.com/document/d/e/2PACX-1vSYcP7kvGXGJjGAXg4qzj-Jfi0vLojCdCdFTLgxg_8mZuwLK32DYEVUo7LTFGiucGE4arlAWvO-TIlZ/pub
  13. https://docs.google.com/document/d/e/2PACX-1vTMBXvwgGd4DU8rmBf6FomQ8sQAXv3924gEeWg8cBH7l7xlYW897PWcHCRf-BVa3moVQLr81MfoNe0t/pub
  14. https://docs.google.com/document/d/e/2PACX-1vTvaHCNCRkx6c0oZCC376vrth8kdGZ5bYDtJ-xVeKUsKkbGA0sSpBYvFViAodeSeaE6dPxg21IVWBpr/pub
  15.  
  16. HANCITOR DOWNLOAD URLS
  17. https://akashcrusher.webscript.co.in/credibility.php
  18. https://aryfa.com/pelter.php
  19. https://www.razwerks.com/devilishly.php
  20.  
  21. aryfa.com
  22. razwerks.com
  23. webscript.co.in
  24.  
  25. MALDOC FILE HASHES
  26. 1210_262874651.doc
  27. 34f20f2fdde3d4311e27c23733ae2734
  28.  
  29. HANCITOR PAYLOAD FILE HASHES
  30. W0rd.dll
  31. 8a46cd66d6f65b40e6ecdce3d29a4d2e
  32.  
  33. HANCITOR C2
  34. http://nuatanste.com/8/forum.php
  35. http://thircussovirom.ru/8/forum.php
  36. http://otsoebabe.com/8/forum.php
  37.  
  38. FICKER STEALER PAYLOAD
  39. http://gadeforsenate.com/sjh7843.exe
  40.  
  41. FICKER STEALER FILE HASH
  42. sjh7843.exe
  43. 107f4a58dc56c803088abb23d29b279c
Advertisement
Add Comment
Please, Sign In to add comment