Advertisement
ExecuteMalware

2020-12-10 Hancitor IOCs

Dec 10th, 2020
3,702
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.38 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Signature Service
  5. You got notification from DocuSign Electronic Service
  6. You got notification from DocuSign Service
  7. You received notification from DocuSign Signature Service
  8.  
  9. SENDERS OBSERVED
  10. b@nelsonfallsafeinc.net
  11. gachiq@nelsonfallsafeinc.net
  12. iapuill@nelsonfallsafeinc.net
  13. pjrya@nelsonfallsafeinc.net
  14.  
  15. MALDOC DISTRIBUTION URLS
  16. https://docs.google.com/document/d/e/2PACX-1vSYcP7kvGXGJjGAXg4qzj-Jfi0vLojCdCdFTLgxg_8mZuwLK32DYEVUo7LTFGiucGE4arlAWvO-TIlZ/pub
  17. https://docs.google.com/document/d/e/2PACX-1vTMBXvwgGd4DU8rmBf6FomQ8sQAXv3924gEeWg8cBH7l7xlYW897PWcHCRf-BVa3moVQLr81MfoNe0t/pub
  18. https://docs.google.com/document/d/e/2PACX-1vTvaHCNCRkx6c0oZCC376vrth8kdGZ5bYDtJ-xVeKUsKkbGA0sSpBYvFViAodeSeaE6dPxg21IVWBpr/pub
  19.  
  20. HANCITOR DOWNLOAD URLS
  21. https://akashcrusher.webscript.co.in/credibility.php
  22. https://aryfa.com/pelter.php
  23. https://www.razwerks.com/devilishly.php
  24.  
  25. aryfa.com
  26. razwerks.com
  27. webscript.co.in
  28.  
  29. MALDOC FILE HASHES
  30. 1210_262874651.doc
  31. 34f20f2fdde3d4311e27c23733ae2734
  32.  
  33. HANCITOR PAYLOAD FILE HASHES
  34. W0rd.dll
  35. 8a46cd66d6f65b40e6ecdce3d29a4d2e
  36.  
  37. HANCITOR C2
  38. http://nuatanste.com/8/forum.php
  39. http://thircussovirom.ru/8/forum.php
  40. http://otsoebabe.com/8/forum.php
  41.  
  42. FICKER STEALER PAYLOAD
  43. http://gadeforsenate.com/sjh7843.exe
  44.  
  45. FICKER STEALER FILE HASH
  46. sjh7843.exe
  47. 107f4a58dc56c803088abb23d29b279c
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement