Advertisement
DarthInvader

Hancitor Sep 5, 2017 fake USPS holdmail

Sep 5th, 2017
813
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.46 KB | None | 0 0
  1. Hancitor phishing IOC
  2.  
  3. September 5, 2017
  4. Subject: Holdmail Confirmation Document <8 digits> OR Holdmail Document <8 digits>
  5. Downloaded document name: Tracking_<6 digist>.doc
  6. Document SHA-256: c95a068e72de595a6e9b0c29bdc1745e87f2eb54eedeeb58c0fbf4fad9ce2211
  7.  
  8. Phishing URLs
  9. http://downetwpnj.net/lenta.php?d=
  10. http://eaglesmereautomuseum.info/lenta.php?d=
  11. http://eaglesmereautomuseum.org/lenta.php?d=
  12. http://firelinktechnology.com/lenta.php?d=
  13. http://firelinktechnology.net/lenta.php?d=
  14. http://keatingfamilymail.info/lenta.php?d=
  15. http://keatingfamilymail.net/lenta.php?d=
  16. http://keatingfamilymail.org/lenta.php?d=
  17. http://proconservicesllc.com/lenta.php?d=
  18. http://superiorcomfortpro.us/lenta.php?d=
  19. http://superiorhvacuniversity.com/lenta.php?d=
  20. http://superiorhvacuniversity.org/lenta.php?d=
  21. http://turbotville.com/lenta.php?d=
  22.  
  23. Botnet CNC URLs
  24. http://orcateheck.com/ls5/forum.php
  25. http://hedtfortedlet.ru/ls5/forum.php
  26. http://disitofle.ru/ls5/forum.php
  27.  
  28. Malware delivery URLs
  29. http://crabbiesfruits.com/wp-content/plugins/regenerate-thumbnails/3
  30. http://fortexintl.com/3
  31. http://www.oklifestore.com/blog/3
  32. http://www.idyemyhair.com/blog/3
  33. http://www.hkcwcc.edu.hk/wordpress/3
  34. http://migs.me/3
  35.  
  36. File 1 SHA-256 8355b66cfaa30f16a8f2e19ef48881d665e8895b3087f95641ee188b8865d361
  37. File 2 SHA-256 e0083ede887e41e704067f590c8b41c5aaa02056469a015bb5965e3504636bd0
  38. File 3 SHA-256 b1ad489c9fd767f562e475fedb28382501207008846e9846cb524da8fdc8298e
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement