ExecuteMalware

2020-12-16 Hancitor IOCs

Dec 16th, 2020
4,205
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.75 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD=1612_ui478sd
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Signature Service
  10. You received invoice from DocuSign Electronic Service
  11. You received invoice from DocuSign Signature Service
  12. You received notification from DocuSign Electronic Signature Service
  13. You received notification from DocuSign Service
  14.  
  15. SENDERS OBSERVED
  16.  
  17. MALDOC LANDING PAGE URLS
  18. https://docs.google.com/document/d/e/2PACX-1vQvltdnTwXQpa43unbk09fLhx2qvNsqRAwYqLgOsvSpnqrYc8s52xziqIcrd_ZwU2BwmCvAsvS1klBf/pub
  19. https://docs.google.com/document/d/e/2PACX-1vRhdZFB7W6p8BJRFhAZKGMLrkA9oE4LesVrhJpdQFQZozlFzhxzhkoD8o4x6vI17zIft4Rm_NablpqS/pub
  20. https://docs.google.com/document/d/e/2PACX-1vSaC3-RRB91ArSXFvAgCPQp0eKUUTQulqioVUeaNAtSTACS7Z4qNWzTCOO9WvQ6e243mKa6Ht_uF41o/pub
  21. https://docs.google.com/document/d/e/2PACX-1vSKG2EoqPQDkiKAEZX6vsoVtSIhu7XcxAc-yZLvhKLeYvrwYco7wtZa33rhCNczl2Oagt8izzSq92gg/pub
  22. https://docs.google.com/document/d/e/2PACX-1vSNZv_8eN9eJ1Fd8Gt4NVXcx_FKaZemPGX1KQGFA--e7ZOdSIe-gN6Z6gKkV44IqfPrhOKYAR7FA007/pub
  23. https://docs.google.com/document/d/e/2PACX-1vSRVoEZobVqPq9-C_elnTAPfr7LIpb7hU7eIdY7O6kuNb2a3490bAL2aC6sc2wcQTN8ZiyCtDVpMK7j/pub
  24. https://docs.google.com/document/d/e/2PACX-1vTdKGF2fOwGGpHfMgzbDyUgE16f47acbpoJsjUsixNPAFfkB9hTdo6UbNIT0TwGK4Ry3yN2f-zRYCdS/pub
  25. https://docs.google.com/document/d/e/2PACX-1vTma9FuweH1814rZ4ooU1TgDSo2S-MtHKtb5wZ8E6ZS8Pnqq4bDRBqVrolzjvrIPZ2pJuyYemGUPkOR/pub
  26.  
  27. MALDOC DISTRIBUTION URLS
  28. https://bmmm.in/conversely.php
  29. https://bmmm.in/serviceability.php
  30. https://demo.24onlinenewspaper.com/despicably.php
  31.  
  32. 24onlinenewspaper.com
  33. bmmm.in
  34.  
  35. MALDOC FILE HASHES
  36. 1216_3896101931.doc
  37. 2350c157408b69cc5b88bec7e1824d61
  38.  
  39. 1216_114086062.doc
  40. 2b47bfbef6f4080a7a44cc89bf481331
  41.  
  42. 1216_77796024.doc
  43. 63abbcbfc103e00d860e340bbccaea64
  44.  
  45. 1216_372977361.doc
  46. 7270cc86be7b3265386f5e6dc841fc16
  47.  
  48. 1216_130942272.doc
  49. 992a0a152bbd65877f68856772b37aa2
  50.  
  51. 1216_1079750132.doc
  52. d60af09913c8efe15cbf008d72ca5f72
  53.  
  54. HANCITOR PAYLOAD FILE HASHES
  55. W0rd.dll
  56. d404861f4a274c4cf780d6ae0e237e51
  57.  
  58. 1216_77796024.doc_ya.wav
  59. 8b820d43f60282e0f06af42723376fac
  60.  
  61. W0rd.dll
  62. ee9ac4b07ac689002716940ec5ea38d0
  63.  
  64. 1216_1079750132.doc_ya.wav
  65. d211ac7d70d9e9f6088f7b62ab032d35
  66.  
  67. HANCITOR C2
  68. http://bicescuryseu.ru/8/forum.php
  69. http://ulaginceter.com/8/forum.php
  70. http://meordsovellia.ru/8/forum.php
  71.  
  72. bicescuryseu.ru
  73. meordsovellia.ru
  74. ulaginceter.com
  75.  
  76.  
Advertisement
Add Comment
Please, Sign In to add comment