Advertisement
ExecuteMalware

2021-04-07 Hancitor IOCs

Apr 7th, 2021
16,238
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.42 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD NUMBER
  4. &BUILD=0704_scxe
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Signature Service
  10. You got notification from DocuSign Electronic Signature Service
  11. You got notification from DocuSign Service
  12. You got notification from DocuSign Signature Service
  13. You received invoice from DocuSign Signature Service
  14. You received notification from DocuSign Electronic Service
  15. You received notification from DocuSign Electronic Signature Service
  16. You received notification from DocuSign Service
  17. You received notification from DocuSign Signature Service
  18.  
  19. SENDERS OBSERVED
  20.  
  21. MALDOC LANDING PAGE URLS
  22. https://docs.google.com/document/d/e/2PACX-1vQ0IB4AW49Yrh1G0r4szTjX9iWYRWes1WK8Ko1_AARZOY7dxI4we4AcKX34EIHduxYN8AZhtcVuR5DI/pub
  23. https://docs.google.com/document/d/e/2PACX-1vQ8sgMrw4Y6uzuy5Sct0vOFS4lHr_rj6-L4ld2qijj-xJNIPQAUxDpX5mxnNmxWhqd6YJbNBIiWstTi/pub
  24. https://docs.google.com/document/d/e/2PACX-1vQ_usou7tDRcDZU8hx5Nc26wHDdlLXaGjp2cv8JHFPlZJbSf6GIZOKhgOwpoPr7xar6dz_wRJAxOWev/pub
  25. https://docs.google.com/document/d/e/2PACX-1vQdn84kAA3U6gGp5LtHJ9_KpRNuhs-BcTf3EtJ8QDfJF5eX5rPN7gw421LKR-frCjzR-n5y2g53FBun/pub
  26. https://docs.google.com/document/d/e/2PACX-1vQjBRR7kz1n0OqKPjirbg8O6CcBF0Ofhe636SBE-S-vKvcJKfc_gthWAWcRtyFh4EGRnswsRKb5Ss_k/pub
  27. https://docs.google.com/document/d/e/2PACX-1vQwK0gtj7HiCdxp2H_DAL6Ufhuxpbdg8XmpGyi2hjD4eUdjBVk5W2WvUWI-T4LZBSDTCUrx34zEOZTN/pub
  28. https://docs.google.com/document/d/e/2PACX-1vRBAdUu58td4Ovr4yuy3GiFEzW0E0uY7ysFRtASmgNs64irOsebkwdK3WuXSO7Ycg1WkVDujZ6LEc49/pub
  29. https://docs.google.com/document/d/e/2PACX-1vRIzYn_nQOPMNpFfO1u1s-oW_bmJpjhQXuvTQahjnpR3AP9S6VBg1DMd4njkNKYDbhJVqw5-Ha7PJ64/pub
  30. https://docs.google.com/document/d/e/2PACX-1vRjAthVvGFRonXQG4gsuab9bqoH467TEqUPZw2_cFO8Fyeh5VTm-ckCiX5wD3D2yEb0u4CsO2lSEKv0/pub
  31. https://docs.google.com/document/d/e/2PACX-1vRJQjgqU-78FRpffuwB7UdDE7YlWnB2NWTXbJq8k9AyhZx8oaWI6iRBno0I_pWqxr5S4QbFXifu7X4n/pub
  32. https://docs.google.com/document/d/e/2PACX-1vSHn-kBOtunJVSN73AaxTxP10A4fmD72cg5NKS1lIjiNwUtO12UZardWN8XFAPCXvjbed4ve4KxPLyx/pub
  33. https://docs.google.com/document/d/e/2PACX-1vSlkF6AAdiiVVUeHLbYvSopcbm2DGbEPoUwK4B6KA2YZWogtrwGTGQiKMzAsGXnUSYDqQgTCNYllIIT/pub
  34. https://docs.google.com/document/d/e/2PACX-1vSWeH6EtBiYKzlGOTm8gx53_ruELGohXgOUToOrgEyDRMxIwI4xgGOV076lFUTfHuTeUnXYAEVW-5tK/pub
  35. https://docs.google.com/document/d/e/2PACX-1vT-Qve9km4E1lLd9IcTzBFGPFHm_G-aR48HBWVF8FtPxh8PCcbGbV3JYetrTfTjoWXfU8ngd9vLUW23/pub
  36. https://docs.google.com/document/d/e/2PACX-1vT33281lMXIJoPgUsciT8gPWvYhTQmvlAxr8pUANCiLtqLZJdGCfKrsDS4PK8IBjDfaPg2ROAZBH7tr/pub
  37. https://docs.google.com/document/d/e/2PACX-1vTaAMuJcabO61pA_ezeRm7ZXcc88ikS0qqYJ7Melzx_xsNWxSDzZ_NHFDn72HuNuh3CZQHWbWjSMky0/pub
  38. https://docs.google.com/document/d/e/2PACX-1vTpjko79htJXUB_U-HeB-YeJemi_bShpp4ZgJG0-u0LUKJShOZ6TTtalBoo1egjpL-U5yZsgvQW6egE/pub
  39. https://docs.google.com/document/d/e/2PACX-1vTY8Nd7L3GankqR6bKDnSPy91dDenDbTXHPFuv4oY4OrUEcHNQ3c3jsCUGEjo4PLi-vq18t6PvrdDmb/pub
  40.  
  41. MALDOC DISTRIBUTION URLS
  42. https://aklatdelmundo.com/ditty.php
  43. https://aklatdelmundo.com/holler.php
  44. https://jollygul.com/ford.php
  45. https://jollygul.com/nipple.php
  46. https://kabimmo.com/seclusion.php
  47. https://kabimmo.com/struggler.php
  48. https://medicinainterna-critica.com/lubricant.php
  49. https://quickcompanyreg.co.za/accordion.php
  50. https://save.makemoneywith.website/housewarming.php
  51.  
  52. aklatdelmundo.com
  53. jollygul.com
  54. kabimmo.com
  55. makemoneywith.website
  56. medicinainterna-critica.com
  57. quickcompanyreg.co.za
  58.  
  59. HANCITOR MALDOC FILE HASHES
  60. 26f6537ae7eab818013eb021f54c46d2
  61. 6541b3e2c5a8f86531721ec1d417be6c
  62. 7fb1cc93b51cf6db68ae20bdbd197023
  63. 882ea66f8685633ae0195060dc60076f
  64.  
  65. HANCITOR PAYLOAD FILE HASH
  66. MsMp.dll
  67. 8ee94ecdec0de4f4e60e589dae57dbdb
  68.  
  69. HANCITOR C2
  70. http://windetheta.com/8/forum.php
  71. http://undereasus.ru/8/forum.php
  72. http://frougelylo.ru/8/forum.php
  73.  
  74. FICKER STEALER PAYLOAD URL
  75. http://67xfjk.ru/6jhu8yhd.exe
  76.  
  77. FICKER STEALER FILE HASH
  78. 6jhu8yhd.exe
  79. 77be0dd6570301acac3634801676b5d7
  80.  
  81. FICKER STEALER C2
  82. http://sweyblidian.com
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement