Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: HANCITOR
- SUBJECTS OBSERVED
- You got invoice from DocuSign Electronic Service
- You got invoice from DocuSign Electronic Signature Service
- You got notification from DocuSign Electronic Signature Service
- You got notification from DocuSign Service
- You got notification from DocuSign Signature Service
- You received notification from DocuSign Electronic Service
- You received notification from DocuSign Signature Service
- SENDERS OBSERVED
- MALDOC DISTRIBUTION URLS
- https://account.docusign.com/
- https://docs.google.com/document/d/e/2PACX-1vQsFAg7ZZheOHgX0SStDarvlEFqAPB_RuDozpytvGaZbrjdD4SYv041Lcmi30TRr2z73Dgxe8BC0VqI/pub
- https://docs.google.com/document/d/e/2PACX-1vR9pR-5HjpY4A3asy_Z1NHzYPGJ_1QlMCK5f46Rxjc9-R9U_XsVeTf-NgmVsVWW55yDoUZchmH0wmBe/pub
- https://docs.google.com/document/d/e/2PACX-1vSc90aIj5BZOI7kpC_RT9ju4VMsd9YystaXzOJawI1hIu4VUd4qbKV2qX3cTtmJukNZPVUfiHztCC4R/pub
- https://docs.google.com/document/d/e/2PACX-1vSL1zdoauY-UZOY11ILLKOlfesH0YcVO28_zc8CyfZMmvhjt_m6giiUwsOwHF_mcUgQufTIE4ZyK9wu/pub
- https://docs.google.com/document/d/e/2PACX-1vSP5OWu-mtF_tVERleU6KSN4Fu2fxwBE-5r9huU_kD3Npfs499nP9S_t3G6TCLyCGdyRMZ4DIkt0Y4I/pub
- https://docs.google.com/document/d/e/2PACX-1vT_IKe3EBuwDqqm4FrSNGWfrEMCi6MzOn5jz86q2lUAg64Ixqa9nDfbB4GddD6tIMt5c6BH02KnGUk8/pub
- https://docs.google.com/document/d/e/2PACX-1vTtWEvtITd6_L5N3LdSAm3x5shrb25N85CHnZdXit2YA7x6k1ZK-M-tKv_cFTDJPrTKII9g9FyY14Fq/pub
- https://docs.google.com/document/d/e/2PACX-1vTU1VdMVs8JpHrhxPd3KRSy9gN4XgzF6lHf3vGZ5YFMnRjp0sJjyI2C9dhBKlrtZ9-b_1NNyBRxR2zM/pub
- HANCITOR DOWNLOAD URLS
- https://www.razwerks.com/inversion.php
- https://email.amitairways.com/stonily.php
- http://alkalinevitaminc.co.za/basin.php
- https://jesuscomes.co.in/bathhouse.php
- alkalinevitaminc.co.za
- amitairways.com
- jesuscomes.co.in
- razwerks.com
- MALDOC FILE HASHES
- 1209_153569242.doc
- 55d09c5626df7116e1d9d60610809bd5
- HANCITOR PAYLOAD FILE HASHES
- W0rd.dll
- 54486e420b12bbedd839e472dfc16e62
- HANCITOR C2
- http://otsoebabe.com/8/forum.php
- http://spardethe.com/8/forum.php
- http://tworkityre.ru/8/forum.php
- FICKER STEALER PAYLOAD
- http://gadeforsenator.com/438h.exe
- FICKER STEALER FILE HASH
- 438h.exe
- 107f4a58dc56c803088abb23d29b279c
Add Comment
Please, Sign In to add comment