ExecuteMalware

2021-02-09 Hancitor IOCs

Feb 9th, 2021
4,885
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.70 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD=0902_ntcwe4
  5.  
  6. SUBJECTS OBSERVED
  7. KeyBank Platform Notice
  8. KeyBank System Message
  9. KeyBank System Notice
  10. KeyBank System Notification
  11.  
  12. SENDERS OBSERVED
  13.  
  14. MALDOC LANDING PAGES
  15. https://docs.google.com/document/d/e/2PACX-1vRw2I0KDZHTZfUkXHIKA-It65nXEqhi8ybWS2nVm_yQwdOVg388PfwfBFFZchFsssKQflUbfCuAHWnY/pub
  16. https://docs.google.com/document/d/e/2PACX-1vS4eGHO3lJ5nQb09wLzvCxlk4WVUYcZQR1UGrcKtAY99Jz7Vqoix4OAgCvZKQM3yxvLLreG3jM-m7zR/pub
  17. https://docs.google.com/document/d/e/2PACX-1vSrd5ET1gc4wl2mW0FnOtgA7xG2LXZKwPhu0VwMFttRqAf89PIDs4QX1Sio6FobIP1ohxUe9CuDUnR2/pub
  18. https://docs.google.com/document/d/e/2PACX-1vSsf1gL56xQGmvAnEOCYpjpl2f1zcEvV5kIQUZAn8ZhG4DWKtXbe4InQqxR_ILwlGecr6nUWumpApxG/pub
  19. https://docs.google.com/document/d/e/2PACX-1vSYr0SPVSJOQLtF96wqwsmwZiHmtj_pHpq1eJiYvJDsDjmeoaKXcffMmjTAbrUEYTOPQa0Ck9SqCcGU/pub
  20. https://docs.google.com/document/d/e/2PACX-1vTBqY1EHOR6rBSsIJxfAEayczUyKGFFSboMoQy0ZQGMo1GvazkUXqJIBtnew7drlDipf0Bw6rOk0-Pr/pub
  21.  
  22. MALDOC DOWNLOAD URLS
  23. https://www.keepsmilinglog.com/includes/cache/nob.php
  24. https://pepselectricailservice.co.uk/dangerous.php
  25. https://facturasenlineamarx.com/numskull.php
  26. https://facturasenlineamarx.com/socials.php
  27.  
  28. facturasenlineamarx.com
  29. keepsmilinglog.com
  30. pepselectricailservice.co.uk
  31.  
  32. MALDOC FILE HASHES
  33. 0209_2385408482604.doc
  34. aca88c452204462e7be913009fd38199
  35.  
  36. HANCITOR PAYLOAD FILE HASHES
  37. W0rd.dll
  38. deb1e328feb39c49c0a39cd37d4f7792
  39.  
  40. HANCITOR C2
  41. http://sibetaver.com/8/forum.php
  42. http://ceirsitsin.ru/8/forum.php
  43. http://formawas.ru/8/forum.php
  44.  
Advertisement
Add Comment
Please, Sign In to add comment