Advertisement
DarthInvader

Hancitor IRS and SolarWinds Phishing IOCs Oct 5, 2017

Oct 5th, 2017
786
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.38 KB | None | 0 0
  1. Hancitor Oct 5, 2017 IRS and SolarWinds Phish IOCs
  2. Subject: FW: IRS
  3. Subject: Make Hacking Difficult
  4.  
  5. SolarWinds Downloaded document name: ebook_<6 digits >.doc
  6. SolarWindows SHA256: 3ab1f686ce7355bd4405e66aacb148cea198ceb26cd1c0b15b9ddd7c3d68a682
  7.  
  8. IRS Downloaded document name: subpoena_<6 digits>.doc
  9. IRS Document SHA256:3ab1f686ce7355bd4405e66aacb148cea198ceb26cd1c0b15b9ddd7c3d68a682
  10.  
  11. Phishing URLs
  12. all4insurance.com/[email protected]
  13. creatingmiracleswithmalas.com
  14. creatingmiracleswithmalas.net
  15. goal-link.com
  16. integralund.com
  17. prayersmalasandmiracle.com
  18. prayersmalasandmiracles.com
  19. prayersmalasandmiracles.net
  20. satyainstitute.biz
  21. satyainstitute.com
  22. satyainstitute.info
  23. satyainstitute.net
  24. satyawholesale.com
  25.  
  26. C2 domains
  27. http://talwilwasled.com/ls5/forum.php
  28. http://wasidrinve.ru/ls5/forum.php
  29. http://dapahedtsed.ru/ls5/forum.php
  30.  
  31. Malware Download URLs
  32. http://timwaters.com.au/wp-includes/pomo/2
  33. http://thijsfeuth.nl/plugins/files/2
  34. http://lelukauppa.pro/wp-includes/pomo/3
  35. http://timwaters.com.au/wp-includes/pomo/3
  36. http://thijsfeuth.nl/plugins/files/3
  37.  
  38. File1 SHA256: b10ca7fcbce3fa534f7a53c366ee823817465a49b004998fd80e07e5c64e14d8
  39. File2 SHA256: d85a58776e5230c18fd1e5cf8f3c7cc5efb4bac4efe741958a3118168ea5414b
  40. File3 SHA256: 5ac18efce332a9bebcc46fbcb2c7944ae7ed382be3460b0bacb00aea8e1b14e0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement