ExecuteMalware

2020-10-29 Hancitor IOCs

Oct 29th, 2020
3,604
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.08 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Signature Service
  5. You got invoice from DocuSign Signature Service
  6. You got notification from DocuSign Electronic Service
  7. You got notification from DocuSign Signature Service
  8. You received invoice from DocuSign Electronic Service
  9. You received invoice from DocuSign Electronic Signature Service
  10. You received invoice from DocuSign Signature Service
  11. You received notification from DocuSign Electronic Service
  12. You received notification from DocuSign Electronic Signature Service
  13. You received notification from DocuSign Signature Service
  14.  
  15. SENDERS OBSERVED
  16.  
  17. MALDOC PROXY URLS
  18. https://docs.google.com/document/d/e/2PACX-1vQbYdXWRoQ3P-5Muar5aSNI_dHAcot9CUkr6WxVxXRXpkWD8m9bu4t6aSJnrVL9tzp-xp9f2%0D%0AhTxzH9k/pub
  19. https://docs.google.com/document/d/e/2PACX-1vQbYdXWRoQ3P-5Muar5aSNI_dHAcot9CUkr6WxVxXRXpkWD8m9bu4t6aSJnrVL9tzp-xp9f2hTxzH9k/pub
  20. https://docs.google.com/document/d/e/2PACX-1vQdF1Gqjhtk3O5Tt41duwhRaFj8bCDaoUlJZ8W7zE-Es4q5TaOrkjAMRVD8f6Lo_p1fy4HnFM5tPLCX/pub
  21. https://docs.google.com/document/d/e/2PACX-1vQGgSdv4KYHv5AQxSuescNPh4J02qJlDhQ1rhpoLsvqVb75g9uefTgx0TP6Uf2pH1pYGMSi_F3XFjY3/pub
  22. https://docs.google.com/document/d/e/2PACX-1vRfUbKsfer__oU_vwWwxrO8cxPtNA2F2lWtw6ZEoqvWUOljKK68JIBGl6xsk-23zBaZt36nIQz87OwS/pub
  23. https://docs.google.com/document/d/e/2PACX-1vRQds__1KP5Aftg-AiQyX9ZTb5K4-Us1yH7e_s3TcENW1ltiBOvUWyFlFqNB2xLW9s1XJmsM6qF-Lpl/pub
  24. https://docs.google.com/document/d/e/2PACX-1vSAbxgv0JxuenYiQbQtrCHGLb2RKaYKuTIWPwvtWK6aRtB8x8j3XBgGtEJZCs-3zMPURP8o4Lwpn8iB/pub
  25. https://docs.google.com/document/d/e/2PACX-1vSCouIjf_W9ItrHSJ991kFWwiqVnZQ_pLQ8XRJ2R1mWs4bIks6Ug3WfKRinhnsvTLjZ8kV05dJYFXpn/pub
  26. https://docs.google.com/document/d/e/2PACX-1vT5yWeRD5F_Ux-T06V5XiYCAmFMIjFkhtdN4-9mlELbgZ-qSUzWEoTJ1eO_gcoTVnx0cRTFQY-9HDqj/pub
  27. https://docs.google.com/document/d/e/2PACX-1vTbLDj0BlEomcWdd3DEdz-67uRqstgom-1e2i1Y5P8flAaeMTUe3ua5Ie2QGPq3B_AsnWYUYsfIxt8K/pub
  28. https://docs.google.com/document/d/e/2PACX-1vTvPWHmcdxy5Twv5egLpNAuv9VambCIk-G2tvV2Yrk1IzeKN0eXV8SUOElLYM40ivFaseLa1XR9hL_A/pub
  29.  
  30. MALDOC DISTRIBUTION URLS
  31. http://czyszczeniesrebra.pl/delivery.php
  32. http://schrijfdrift.nl/grow.php
  33. https://fastcheff.com.br/permission.php
  34. https://hrm.nxsinfotech.com/explanation.php
  35. https://juulslabel.nl/recommend.php
  36. https://kaibophil.com/affect.php
  37. https://kaibophil.com/support.php
  38. https://sewfactory.ru/invite.php
  39. https://spheriz.fr/own.php
  40.  
  41. MALDOC FILE HASHES
  42. corp_89432.xlsb
  43. 7f1368cccf51636cf4c149f8ff0ca67b
  44.  
  45. HANCITOR PAYLOAD DOWNLOAD URLS
  46. http://ubercancellationfeelawsuit.com/p.png
  47.  
  48. HANCITOR PAYLOAD FILE HASES
  49. p.png
  50. d860b8a46bdf5f113c36ecc32760daf8
  51.  
  52. HANCITOR C2
  53. http://eventlarva.com/7/forum.php
Add Comment
Please, Sign In to add comment