ExecuteMalware

2021-01-26 Hancitor IOCs

Jan 26th, 2021
4,291
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.47 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. Build: 2601_ven87
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Service
  9. You got notification from DocuSign Electronic Service
  10. You got notification from DocuSign Electronic Signature Service
  11. You got notification from DocuSign Service
  12. You received invoice from DocuSign Electronic Signature Service
  13. You received invoice from DocuSign Service
  14. You received invoice from DocuSign Signature Service
  15.  
  16. SENDERS OBSERVED
  17.  
  18. MALDOC LANDING PAGES
  19. https://docs.google.com/document/d/e/2PACX-1vQb9kTLGGlIhF9tzzyqHN0LGSETsH5skWAj_eQdl1S9pA1mrROAKXJuwp_Bu16tBT6l55taVOirdPi7/pub
  20. https://docs.google.com/document/d/e/2PACX-1vQeZ_Bb-DkvdOvCS42umsZzDI-cMx-H4SzTXUk7uPbzk2TdoxZ2DczEhvinch48BuSfR1Z4hJbAYKa5/pub
  21. https://docs.google.com/document/d/e/2PACX-1vQWIZOS9oRoaU_xZn0e_IFZ9rbigHPU4Sye0SbMgbrz4O8CRmcL-8yWatPRZEmEadmyp_5Jj82Az16N/pub
  22. https://docs.google.com/document/d/e/2PACX-1vRbrQ9ZigCB6_f2tzhDUYC67rOlI2IzVvnajb7tXttEckGpOp7t8BIfNXJzWjsE8m7tlrzgAGyvYwGs/pub
  23. https://docs.google.com/document/d/e/2PACX-1vROTXXx5L63qCLmICk8KniCwRkWpu8T3fi5Z_mE1GAPe7dunslEG0kkxpfWUQTNOQygNfA-J5R8orWX/pub
  24. https://docs.google.com/document/d/e/2PACX-1vRTHUELErftSm6lh6iXgsE78jFtcF0KqXmJLUMckOkmiuidG48-r0SRKPABGA7TDrB5xpO_rXSNMZxm/pub
  25. https://docs.google.com/document/d/e/2PACX-1vSIme9CaLvq2CDIra8KZe86vVo5vLTeodlASmbPfUuvdbTaQGjbAF2NYIm_KjdCtvMsAeUh5oIldYmM/pub
  26. https://docs.google.com/document/d/e/2PACX-1vSn8CaWkcszp6yO6qQftphWqW3RQCD1KlY9DzRmKtNYZFHtc2h1El2tfvQc3hkgaL_QOY2XiEk2UniM/pub
  27. https://docs.google.com/document/d/e/2PACX-1vSQqKAlKN__ndBF2SBBWB1_GWOSQjwYw7r3KvzQB7ZhPLTr1Oz6W9bd8bjP1ClPkWUag6qu-0Kxdw1m/pub
  28. https://docs.google.com/document/d/e/2PACX-1vTTzvvOixhA0pBXubkEPT8d3FPp5LEqdS4olINuO579aiqVbrhFRKe-RU4F_w_A13mOXjr1ASipUfAq/pub
  29. https://docs.google.com/document/d/e/2PACX-1vTZB9KTJD7y3vDxdB214lU8QUHm8yCnnoZQZ0N1Jwm0RjGXjR96c1jCHrV4jG52LjP1_BqwShgLsxbj/pub
  30.  
  31. MALDOC DOWNLOAD URLS
  32. http://cariustadz.org/file_manager/thumbs/kelas-9/materi/bab-1-perpangkatan-bentuk-akar/agate.php
  33. http://cariustadz.org/file_manager/thumbs/kelas-9/materi/bab-1-perpangkatan-bentuk-akar/pontiff.php
  34. http://libimprov.com/wp-content/plugins/thim-core/templates/dashboard/prophesying.php
  35. http://premierpt.co.uk/wp-includes/sodium_compat/src/Core32/ChaCha20/baton.php
  36. http://premierpt.co.uk/wp-includes/sodium_compat/src/Core32/ChaCha20/victorianism.php
  37. http://rollpaper.hu/wpadmin/wp-content/themes/i-craft/css/wynd.php
  38. https://broadgr.com/wp-content/plugins/woocommerce-conversion-tracking/includes/integrations/pundit.php
  39. https://en.gooddrink.com.tr/wp-content/plugins/revslider/views/system/aligns.php
  40. https://en.gooddrink.com.tr/wp-content/plugins/revslider/views/system/bathrobe.php
  41. https://muchoruidoacademy.com/site/cryptic.php
  42. https://muchoruidoacademy.com/site/dromedary.php
  43.  
  44. broadgr.com
  45. cariustadz.org
  46. gooddrink.com.tr
  47. libimprov.com
  48. muchoruidoacademy.com
  49. premierpt.co.uk
  50. rollpaper.hu
  51.  
  52. MALDOC FILE HASHES
  53. N/A
  54.  
  55. HANCITOR PAYLOAD FILE HASHES
  56. N/A
  57.  
  58. HANCITOR C2
  59. http://locroplenes.ru/8/forum.php
  60. http://iderfeirel[.]com/8/forum.php
  61. http://locroplenes[.]ru/8/forum.php
  62. http://surpopene[.]ru/8/forum.php
  63.  
  64.  
Advertisement
Add Comment
Please, Sign In to add comment