Advertisement
ExecuteMalware

2020-12-15 Hancitor IOCs

Dec 15th, 2020
3,790
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.31 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Service
  6. You got invoice from DocuSign Signature Service
  7. You got notification from DocuSign Electronic Service
  8. You got notification from DocuSign Electronic Signature Service
  9. You got notification from DocuSign Service
  10. You got notification from DocuSign Signature Service
  11. You received invoice from DocuSign Electronic Service
  12. You received invoice from DocuSign Electronic Signature Service
  13. You received invoice from DocuSign Service
  14. You received invoice from DocuSign Signature Service
  15. You received notification from DocuSign Electronic Service
  16. You received notification from DocuSign Electronic Signature Service
  17. You received notification from DocuSign Service
  18. You received notification from DocuSign Signature Service
  19.  
  20. SENDERS OBSERVED
  21. a@backupez.com
  22. airdu@backupez.com
  23. bofgisu@backupez.com
  24. dmedure@backupez.com
  25. doqu@backupez.com
  26. e@backupez.com
  27. exiviai@backupez.com
  28. fogaqi@backupez.com
  29. hcayz@backupez.com
  30. ji@backupez.com
  31. kxdotkw@backupez.com
  32. leixjma@backupez.com
  33. lfeqfo@backupez.com
  34. msa@backupez.com
  35. otim@backupez.com
  36. pavzaoy@backupez.com
  37. qauado@backupez.com
  38. qedakef@backupez.com
  39. qtzkkc@backupez.com
  40. rbaqweb@backupez.com
  41. sjiqif@backupez.com
  42. vuiua@backupez.com
  43. wagu@backupez.com
  44. wiyg@backupez.com
  45. wizuucw@backupez.com
  46. wizuucw@backupez.com
  47. wizuucw@backupez.com
  48. wizuucw@backupez.com
  49. wizuucw@backupez.com
  50. xeohoyh@backupez.com
  51. ywg@backupez.com
  52.  
  53. MALDOC LANDING PAGE URLS
  54. https://docs.google.com/document/d/e/2PACX-1vQ86S5QjJHqDYxFtUfBNqR09jJLbegSo_SzGf7W7KKJChotrbb5Ozvz1vrFnGllGdMkAZjBwhN-N9Nq/pub
  55. https://docs.google.com/document/d/e/2PACX-1vQcuCU0Pwen4WlzLd8WlM3Rokuj3TFLxug8QWmb3lYw2y6WK8nL6SqQfBAbMxemqvYynj7ckeZinNR7/pub
  56. https://docs.google.com/document/d/e/2PACX-1vQiqmw1rvPhUy0DGbCJ44AonMJ-L3YODp9yZz4iIkzyqk-6T53H0Bn80RW3N054GUnpclhX9edPwTRy/pub
  57. https://docs.google.com/document/d/e/2PACX-1vQN6DoIIl2HD8a47Kr-aNwQAAffbCOINyupzBji5H9paWbkdCQeh6yBq8QpTIA-Ed0OmRwdmb2IZTIQ/pub
  58. https://docs.google.com/document/d/e/2PACX-1vQNtoEYbqkEhaJBHnKzcJk1Vv7oyUyxxVIK8qtSWe3dblawUvQUDe-jg7cH-JpiBOL5P2ufF2Qtx_ab/pub
  59. https://docs.google.com/document/d/e/2PACX-1vQRKW3pqNP2CBz1qE6Hm9Wp48LPZkXkeShjOA0jLCLhVvKH03IlKJP7wtukSlrgJ_3e0qQpS6NUuxX5/pub
  60. https://docs.google.com/document/d/e/2PACX-1vQTDxLPDawThda8G6Hp20mf6_3k3zHVfjUnsQX09dI5ld-TmTHHrQqDUhxUcBskiEvkuqmj9buS1VHz/pub
  61. https://docs.google.com/document/d/e/2PACX-1vQwC2hXwh4xsnVqIorvo32mHvE4avehcMnH0iVDX1VOUMczyyyH9Pv4M4o8yb6pVxAcNv7FsS1OvVq4/pub
  62. https://docs.google.com/document/d/e/2PACX-1vRMu-G1A1CyqvXDMno4pxoRkQkDoorRGwty4ilRl5UNxT6uvM_QsmgAssHd19Qg00pFa2xkdc5YqFLZ/pub
  63. https://docs.google.com/document/d/e/2PACX-1vRtzy_GdhlhOKUIvMonUBCXLdL4gFH2EvSGw8eR9RfAqKbjtYwb2FSxTDQ5QB_9_54zP6v1gi72wPJs/pub
  64. https://docs.google.com/document/d/e/2PACX-1vRyQdvLDtYVYDLxNVgTiZMEaY5qBPPyoRytWXUBnugyOn41bPGBFVek_nXhs0VfhRZmVkyFb3hYvkgm/pub
  65. https://docs.google.com/document/d/e/2PACX-1vS-tv4XVR9elECzZTBDkKBdonfPfQT2Ri04ernx76sm-WA8oY8o-nvFR5olOCc3FSEQLoAlpqtifjbX/pub
  66. https://docs.google.com/document/d/e/2PACX-1vSIxu5qRkq3yJoZo-1HhvDMonaaLeJjoG2pgbXDa1tMwjU-lZbsu_K0RoMHc5FULVqiN-gbDclUkpRt/pub
  67. https://docs.google.com/document/d/e/2PACX-1vT-YPxd5B8TgygoPtqGILx9nCOP2JgPEvjBQ_u8psbMgOp4-WAoc_L0CIHUrkWgZ69Lx4GQhmLVza_v/pub
  68. https://docs.google.com/document/d/e/2PACX-1vT3oZVcjt6w0aLkOXAPX1DOUsRfy4pf2jEt9Iwnb08GL0fCLs-doiRm3BnNorAXo_2H4ynC_pichPg6/pub
  69. https://docs.google.com/document/d/e/2PACX-1vTBY7ju44LenxOGCmF94Z8XMmvKxOwxhQnqwdRJFBSkkTPdEsCIQVkWMdgbKyTZvZ-FAKs6XSA1qIv9/pub
  70. https://docs.google.com/document/d/e/2PACX-1vTKhvcSoWxzy3EQf2g-YbWDtQUTk7nxkUThk83XcQMKduWaHcCrwoutw3qHssT3yR0d-WrcKfnBLqmn/pub
  71. https://docs.google.com/document/d/e/2PACX-1vTNj3Jzrzu6cLz5wwtJEbnBzmRju6tS2wxOwC9cV22xr-fAQieNsqKqDdwKXatnmZGC9NRKj6O1X5lr/pub
  72. https://docs.google.com/document/d/e/2PACX-1vToW-xuL6mwRu470qU1DmVdS8-SsRrGW2qravIxNDasfg8SyP5jkvUN_164owQ7djD7JHHdn4KoReD5/pub
  73. https://docs.google.com/document/d/e/2PACX-1vTWk08Ayfim-wCkzt1t8fKyd3U8mJi4xV4vcTzIzoibNnm3Um0YfiDDqPqlRrdO5GAsvX3Pp11LFL_I/pub
  74.  
  75. MALDOC DISTRIBUTION URLS
  76. http://cares.com.mx/ankylosis.php
  77. http://cares.com.mx/sensibleness.php
  78. http://iptv.yoinicio.com/ankylosis.php
  79. https://baru.bethanyperthchurch.org.au/linchpin.php
  80. https://cartagourmet.com/cranium.php
  81. https://cartagourmet.com/tar.php
  82. https://okmms.com/elderly.php
  83. https://okmms.com/wickiup.php
  84. https://roromap.com/hipping.php
  85. https://sulamericacontabil.com.br/hazy.php
  86. https://todolaptops.com/reconfiguration.php
  87.  
  88. bethanyperthchurch.org.au
  89. cares.com.mx
  90. cartagourmet.com
  91. okmms.com
  92. roromap.com
  93. sulamericacontabil.com.br
  94. todolaptops.com
  95. yoinicio.com
  96.  
  97. MALDOC FILE HASHES
  98. 1215_8447229.doc
  99. 9117e3ccfe098f8bcda4da7907a4843c
  100.  
  101. HANCITOR PAYLOAD DOWNLOAD URLS
  102. http://gade4senate.com/m.dll
  103.  
  104. HANCITOR PAYLOAD FILE HASHES
  105. m.dll
  106. 58c9f038b75b77656b7da5ec791ec9b8
  107.  
  108. HANCITOR C2
  109. http://novearecoms.ru/8/forum.php
  110. http://otsoebabe.com/8/forum.php
  111. http://purclughtz.com/8/forum.php
  112.  
  113. FICKER STEALER PAYLOAD DOWNLOAD URLS
  114. http://gade4senate.com/dfgg45g.exe
  115.  
  116. FICKER STEALER FILE HASHES
  117. dfgg45g.exe
  118. 107f4a58dc56c803088abb23d29b279c
  119.  
  120. SUPPORTING EVIDENCE
  121. I downloaded and opened the malicious Word document in my lab and collected the IOCs.
  122.  
  123. Also:
  124. https://urlhaus.abuse.ch/url/918649/
  125. https://app.any.run/tasks/45c6e754-a28e-4ad5-b8c7-ea814bfaa8b8/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement