ExecuteMalware

2021-05-20 Hancitor IOCs

May 20th, 2021
16,327
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.63 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR / FICKER STEALER
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=2005_mesbn
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Signature Service
  9. You got notification from DocuSign Service
  10. You received invoice from DocuSign Electronic Service
  11. You received invoice from DocuSign Electronic Signature Service
  12. You received invoice from DocuSign Signature Service
  13. You received notification from DocuSign Service
  14. You received notification from DocuSign Signature Service
  15.  
  16. SENDERS OBSERVED
  17.  
  18. MALDOC LANDING PAGE URLS
  19. https://docs.google.com/document/d/e/2PACX-1vQdgtNuLxD48C4JhUaesn_ZFgAFsZ_EJaSCBpbDItEYzNdf_SAu2s6gLNjPBqRXnBDNKwmyA4Y3THsW/pub
  20. https://docs.google.com/document/d/e/2PACX-1vQk5kwI89J1WNz2CiNd_oADJyY29FmwknX_ZHCyAzK5KQ2wn4p2H1wAvy9kS2mi54-62KRxrox-iFrF/pub
  21.  
  22. MALDOC DISTRIBUTION URLS
  23. https://skillsit.com.br/centrality.php
  24.  
  25. HANCITOR MALDOC FILE HASHES
  26. 24047349658d77867ee29c89735655a0
  27.  
  28. HANCITOR PAYLOAD FILE HASH
  29. rem.r
  30. 705864ea2d02aa4e6d66f673fac35fe9
  31.  
  32. HANCITOR C2
  33. http://vaethemanic.com/8/forum.php
  34. http://tembovewinated.ru/8/forum.php
  35. http://prournauseent.ru/8/forum.php
  36.  
  37. FICKER STEALER PAYLOAD URL
  38. http://q09pi7.ru/6jkio9ukds.exe
  39.  
  40. FICKER STEALER FILE HASH
  41. 6jkio9ukds.exe
  42. 77be0dd6570301acac3634801676b5d7
  43.  
  44. FICKER STEALER C2
  45. http://sweyblidian.com
Advertisement
Add Comment
Please, Sign In to add comment