ExecuteMalware

2020-12-09 Hancitor IOCs

Dec 9th, 2020 (edited)
4,288
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.41 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Electronic Signature Service
  6. You got notification from DocuSign Electronic Signature Service
  7. You got notification from DocuSign Service
  8. You got notification from DocuSign Signature Service
  9. You received notification from DocuSign Electronic Service
  10. You received notification from DocuSign Signature Service
  11.  
  12. SENDERS OBSERVED
  13.  
  14. MALDOC DISTRIBUTION URLS
  15. https://account.docusign.com/
  16. https://docs.google.com/document/d/e/2PACX-1vQsFAg7ZZheOHgX0SStDarvlEFqAPB_RuDozpytvGaZbrjdD4SYv041Lcmi30TRr2z73Dgxe8BC0VqI/pub
  17. https://docs.google.com/document/d/e/2PACX-1vR9pR-5HjpY4A3asy_Z1NHzYPGJ_1QlMCK5f46Rxjc9-R9U_XsVeTf-NgmVsVWW55yDoUZchmH0wmBe/pub
  18. https://docs.google.com/document/d/e/2PACX-1vSc90aIj5BZOI7kpC_RT9ju4VMsd9YystaXzOJawI1hIu4VUd4qbKV2qX3cTtmJukNZPVUfiHztCC4R/pub
  19. https://docs.google.com/document/d/e/2PACX-1vSL1zdoauY-UZOY11ILLKOlfesH0YcVO28_zc8CyfZMmvhjt_m6giiUwsOwHF_mcUgQufTIE4ZyK9wu/pub
  20. https://docs.google.com/document/d/e/2PACX-1vSP5OWu-mtF_tVERleU6KSN4Fu2fxwBE-5r9huU_kD3Npfs499nP9S_t3G6TCLyCGdyRMZ4DIkt0Y4I/pub
  21. https://docs.google.com/document/d/e/2PACX-1vT_IKe3EBuwDqqm4FrSNGWfrEMCi6MzOn5jz86q2lUAg64Ixqa9nDfbB4GddD6tIMt5c6BH02KnGUk8/pub
  22. https://docs.google.com/document/d/e/2PACX-1vTtWEvtITd6_L5N3LdSAm3x5shrb25N85CHnZdXit2YA7x6k1ZK-M-tKv_cFTDJPrTKII9g9FyY14Fq/pub
  23. https://docs.google.com/document/d/e/2PACX-1vTU1VdMVs8JpHrhxPd3KRSy9gN4XgzF6lHf3vGZ5YFMnRjp0sJjyI2C9dhBKlrtZ9-b_1NNyBRxR2zM/pub
  24.  
  25. HANCITOR DOWNLOAD URLS
  26. https://www.razwerks.com/inversion.php
  27. https://email.amitairways.com/stonily.php
  28. http://alkalinevitaminc.co.za/basin.php
  29. https://jesuscomes.co.in/bathhouse.php
  30.  
  31. alkalinevitaminc.co.za
  32. amitairways.com
  33. jesuscomes.co.in
  34. razwerks.com
  35.  
  36. MALDOC FILE HASHES
  37. 1209_153569242.doc
  38. 55d09c5626df7116e1d9d60610809bd5
  39.  
  40. HANCITOR PAYLOAD FILE HASHES
  41. W0rd.dll
  42. 54486e420b12bbedd839e472dfc16e62
  43.  
  44. HANCITOR C2
  45. http://otsoebabe.com/8/forum.php
  46. http://spardethe.com/8/forum.php
  47. http://tworkityre.ru/8/forum.php
  48.  
  49. FICKER STEALER PAYLOAD
  50. http://gadeforsenator.com/438h.exe
  51.  
  52. FICKER STEALER FILE HASH
  53. 438h.exe
  54. 107f4a58dc56c803088abb23d29b279c
Add Comment
Please, Sign In to add comment