Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: HANCITOR
- SUBJECTS OBSERVED
- You got invoice from DocuSign Electronic Service
- You got invoice from DocuSign Service
- You got invoice from DocuSign Signature Service
- You got notification from DocuSign Electronic Service
- You got notification from DocuSign Electronic Signature Service
- You got notification from DocuSign Service
- You got notification from DocuSign Signature Service
- You received invoice from DocuSign Electronic Service
- You received invoice from DocuSign Electronic Signature Service
- You received invoice from DocuSign Service
- You received invoice from DocuSign Signature Service
- You received notification from DocuSign Electronic Signature Service
- You received notification from DocuSign Signature Service
- SENDERS OBSERVED
- aiduqad@gmbrakeproblems.com
- bt@gmbrakeproblems.com
- bxauwuf@gmbrakeproblems.com
- cey@gmbrakeproblems.com
- dbof@gmbrakeproblems.com
- ekfwee@gmbrakeproblems.com
- ekilii@gmbrakeproblems.com
- f@gmbrakeproblems.com
- fexilej@gmbrakeproblems.com
- gdiayr@gmbrakeproblems.com
- hriiaik@gmbrakeproblems.com
- inbef@gmbrakeproblems.com
- jvuxmay@gmbrakeproblems.com
- moehqyt@gmbrakeproblems.com
- mouicor@gmbrakeproblems.com
- oyabz@gmbrakeproblems.com
- quiime@gmbrakeproblems.com
- rewwou@gmbrakeproblems.com
- saaxydy@gmbrakeproblems.com
- spilaba@gmbrakeproblems.com
- u@gmbrakeproblems.com
- vckqaa@gmbrakeproblems.com
- vutpupg@gmbrakeproblems.com
- wiqotq@gmbrakeproblems.com
- wuyuqi@gmbrakeproblems.com
- xininu@gmbrakeproblems.com
- yzmi@gmbrakeproblems.com
- zeuyt@gmbrakeproblems.com
- MALDOC LANDING PAGE URLS
- https://docs.google.com/document/d/e/2PACX-1vQb_Cf549fj2pQPO25v9ojYrJjTGp3eJGV4hliM9DgjF-QW2IxJXDLb-0XZCSaWpEj8ZOwZB%0D%0AZTPdWAd/pub
- https://docs.google.com/document/d/e/2PACX-1vQb_Cf549fj2pQPO25v9ojYrJjTGp3eJGV4hliM9DgjF-QW2IxJXDLb-0XZCSaWpEj8ZOwZBZTPdWAd/pub
- https://docs.google.com/document/d/e/2PACX-1vQDfWkvyL4Jn4vEEd5HwdPHBU9KjWSWwLONEuACRL4u7AS-VXqOUVFayIJlQCJzs5k8bVTQWHj6CEMQ/pub
- https://docs.google.com/document/d/e/2PACX-1vQEkWwlbXrRDtPnkSxHAg9dhegP7ExakvLUEb9wL059FIL--_bOtHq07G0DHH4ENgmHp06QSSsXukaa/pub
- https://docs.google.com/document/d/e/2PACX-1vQQEN472JRKWjvwAQV5QLdlEaIqTTHMqcTqS58GS5jOOvbPzpWUfsmDdeFY6mIhMo2Fgofi1HFcCfNt/pub
- https://docs.google.com/document/d/e/2PACX-1vQR5I6sgvLHdrRyvbm6OGheMXW6948OXS-ZgspBg5KTFIMvooQxAVV4AAW2xBlqj17Sy-VR-IHnVi8B/pub
- https://docs.google.com/document/d/e/2PACX-1vQReiJoSegcZ1VVhIELm7WXo6a4g9e9y1sxQAy1YTFss0pgaFpQiIk5r5xR6qcWHVqdulBN50kOSJPq/pub
- https://docs.google.com/document/d/e/2PACX-1vQtONbpdn9bqkoAUYxcD6-h7KrQlR9aur75e8eWNSp-j1VqlY37ZDhWek6lwgOCv4lrjCyyo7CY6XpV/pub
- https://docs.google.com/document/d/e/2PACX-1vR1IyTW2cL1l0CxTyW7iIlPv0-v5kk8sjzafV3hRhZqJEjja7epKbWHsGnoW_skZFqybf6KfxLY87c7/pub
- https://docs.google.com/document/d/e/2PACX-1vRTxmNNbsPEmu1DUhhB6htot75D8ikiW92EbUWSO-maSy0SK9FHBmk3ITVdFGQcmgqoYWJW2ManyVxK/pub
- https://docs.google.com/document/d/e/2PACX-1vRU0ptNZY4Pzj9UNvC-6j0DtPEXlX6cGueIhZzSRnusKSnZkRmDsAf0MpgxE9HLHOkv4sGS_%0D%0A5EvfbNX/pub
- https://docs.google.com/document/d/e/2PACX-1vRU0ptNZY4Pzj9UNvC-6j0DtPEXlX6cGueIhZzSRnusKSnZkRmDsAf0MpgxE9HLHOkv4sGS_5EvfbNX/pub
- https://docs.google.com/document/d/e/2PACX-1vSJg7IKDL0VGasjcuGuYLmOfYJUgpCRZOOABHXh5LTAQCEEyKpba8-tb6NfROXbacK3hI2JY609Uuz3/pub
- https://docs.google.com/document/d/e/2PACX-1vSNJ3cfYeKi-_J5zlJcN_mPAJ6q3JinZZyko2DkxtECq8CiqOvv_ExdPLL5djvbzBgaUEOORwNrrEAA/pub
- https://docs.google.com/document/d/e/2PACX-1vSqpYx4SpuAkVgRqeSeD5ohF6ZDw-w8KSOMbX5Xicwfu0BLlSeHQ37eturcdMLHUqCnbR5-oAln-2Al/pub
- https://docs.google.com/document/d/e/2PACX-1vSUq99KU6vf3mMu6AqHQoW-ontgiKxIR6RZ1NjBc6ZgxyoWoutTmt9rFqVtSHvki-eHQUHE84SEQ11i/pub
- https://docs.google.com/document/d/e/2PACX-1vT_m0bb46gtdUJUPHynUqq5gez_yph0N4Y2BrpDszbOoas_tHPgkM33_xEPWlBGmcIMNv_enC4O9Hyi/pub
- https://docs.google.com/document/d/e/2PACX-1vTATa_Q7EvzVC9U1r7VWmQ9hDc4SrhcXn7r40-FO-agBHSGiQl_IfDggDm6Fui56fQjYyFj7WtTJTcA/pub
- https://docs.google.com/document/d/e/2PACX-1vTB4GmNmMLbyx6H2A0RNpJPMpLepA4ej-MlI3QQTf44Dc5UacMTxT9XN2OTe702U9unXh9_G-Q2Wi3q/pub
- https://docs.google.com/document/d/e/2PACX-1vTdhseIST0ibLbt8ZY5bHZh_1a-noHbutLKZqrKcch3t93AiwC4ZHs-kWrq7sKYGQ4_ZicohlQ4mJUo/pub
- https://docs.google.com/document/d/e/2PACX-1vTooeIYmNjJGu0cZKVAj_fYv20tBHuZJZqS3u2w1K8KeRp35bPQBzrfrTDPPQXR2_UC_YRhMov7ODxA/pub
- https://docs.google.com/document/d/e/2PACX-1vTRcp-OV07xGqzudatZCAsJCsyF3YHMK_rSfme_GqN2UkEgDFBxXlRjvww8_emoXDY95YxlHcE5d_Tx/pub
- https://docs.google.com/document/d/e/2PACX-1vTu6cGnqv7kyph3gPVgUxS6daNtaIcxwlVS36ovodHNPCcugS4b0l9o7FXlX79gUjTVFEQSBNl-Z896/pub
- MALDOC DISTRIBUTION URLS
- https://edukare.info/evaluate.php
- https://lukacepatkering.com/miss.php
- https://solosalong.ee/appear.php
- https://www.plazadistrital.com/schedule.php
- https://solosalong.ee/satisfy.php
- https://demloxo.com.vn/run.php
- https://humateindia.com/talk.php
- https://humateindia.com/enhance.php
- https://woocommerce-1.boxtal.build/surprise.php
- https://pixellanestudios.com/begin.php
- https://blog.naturespersonnalise.com.br/stay.php
- https://afamiaperfume.com/lose.php
- https://demloxo.com.vn/choose.php
- https://blog.naturespersonnalise.com.br/affect.php
- https://lukacepatkering.com/equipment.php
- https://rtpulse.hubit.gr/improve.php
- HANCITOR MALDOC FILE HASHES
- 1102905893.doc
- 9238004746767a7ce20f406e16c594ab
- PAYLOAD FILE HASHES
- Hancitor.exe
- 5be68b4b9979659d13bea38fb9c6fd8d
- HANCITOR DOWNLOAD URLS
- None - it was embedded in the Word document.
- HANCITOR C2
- http://kuzinium.com/7/forum.php
- http://shhirtradej.ru/7/forum.php
Add Comment
Please, Sign In to add comment