ExecuteMalware

2021-04-06 Hancitor IOCs

Apr 6th, 2021
17,206
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.74 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD NUMBER
  4. &BUILD=0504_khrn7
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Service
  9. You got invoice from DocuSign Signature Service
  10. You got notification from DocuSign Electronic Service
  11. You got notification from DocuSign Electronic Signature Service
  12. You got notification from DocuSign Service
  13. You got notification from DocuSign Signature Service
  14. You received invoice from DocuSign Electronic Service
  15. You received invoice from DocuSign Electronic Signature Service
  16. You received invoice from DocuSign Service
  17. You received invoice from DocuSign Signature Service
  18. You received notification from DocuSign Electronic Service
  19. You received notification from DocuSign Electronic Signature Service
  20. You received notification from DocuSign Signature Service
  21.  
  22. SENDERS OBSERVED
  23.  
  24. MALDOC LANDING PAGE URLS
  25. https://docs.google.com/document/d/e/2PACX-1vQ9XcRcgT1n0O7_Ata3ZoR2ZSs7v7u6Q1TGVMsOKX1SXEdHWOI3uzhWWAY5A07RMRk3-ry3_e1RJ4Yy/pub
  26. https://docs.google.com/document/d/e/2PACX-1vQAI_OD4LRHilqUa8YupVfbR78HZIs6Usbh_gY7YgNsMGO5SLi65yDDnVS5I8_OM1yEqDbvYme4PbIR/pub
  27. https://docs.google.com/document/d/e/2PACX-1vQGtiAUMQPqK18942rGSNpYfkobPiQ0fsNv9eGdAnVixmPgfr24Fkulx0_lU42vHTD0Wm500hyV_h43/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQJr9NtWzzmxkni7ckatWW5n5KZlCKuAyF20zLc40eHt9VcfRMfbxes8gVhva_oP-2x5onlwx9Z5jLc/pub
  29. https://docs.google.com/document/d/e/2PACX-1vQKtVWt7lmHmqvgT_3TbwVppRqZSDph1DlVO6sYAmPglPDFcc2_3II2j_pKx9X7SGY_slO-sb6fHIJO/pub
  30. https://docs.google.com/document/d/e/2PACX-1vQqTFHCCRDCxjDqC2ksjf1dF4ne0-zScp4SsH4VI2OjvyOXrLkJwgYtK426ZisxMaSj_lMW72-qeNII/pub
  31. https://docs.google.com/document/d/e/2PACX-1vRaSmtpv316Grxbq4k_Ao6ciz7Xq12KQDcnC-JmcVT1cXjVI3hw5EVkbA1Ie1putCixClriNjI79v-0/pub
  32. https://docs.google.com/document/d/e/2PACX-1vRDFpZMV2aSAm13Kla7MSDL1iEwlkNDq8rGsT3_8rAXF6gsaBQ84wU7RYB4mXEXsYq0gFDrLQGERnEl/pub
  33. https://docs.google.com/document/d/e/2PACX-1vRf7lFvJnnmvjBpQS2hBk16jA94_iHRnMs7_xYGcWvJRi-2dQCXHeaKfjj8lqDcUmG8MbU2_XyfMn-a/pub
  34. https://docs.google.com/document/d/e/2PACX-1vRgtRHpzv2mfl6Ii1z1V3saMlQiA4kRZbfMjd4glrDzXu4Mx7AO4RodFJgmJLcgOmgANDYsljDjYqNn/pub
  35. https://docs.google.com/document/d/e/2PACX-1vRJtXpsUCiHladmThehUuaGaPvNA9VkmgdqSlBKpCcNT93cqeOFb0gjoR5KutH7f5_oeCKUg4EZMlzl/pub
  36. https://docs.google.com/document/d/e/2PACX-1vRlEu9lSnGhf_x5JGkQJrFS5NWRi-88gXcAJa9yNdRzJoZm6FhGhM1mbMMTZo8HdZpHjLUv0WlKw0es/pub
  37. https://docs.google.com/document/d/e/2PACX-1vS1pEmY5kmv4V6sQ7UNUMcwk18gsp6ETFzv6DGecZOXU19VK5P_NAiLY8_6Alfhe_TNykfEygD3i_UU/pub
  38. https://docs.google.com/document/d/e/2PACX-1vSKOqk6ag67OHl2Mk54ADDVlXMdgwz_3Lqldx1EkPVehl9v_9ywxrqllLU4SjiZWSGSHGFJZb9bHG1p/pub
  39. https://docs.google.com/document/d/e/2PACX-1vSM6GKqOeWjEh2PfR_H0dP8bvcTxOfjXsqVVnDL29ceMmSF4kz2uaDrvjyt1LwGF8ukmsCY-sMa34YN/pub
  40. https://docs.google.com/document/d/e/2PACX-1vSOq6cS13HHkMKuFP8BKkZPed561DUyLwiskgy8uX02-6Uqei6imKgF8NS78Qv0r3WnjgROFbYgjyyD/pub
  41. https://docs.google.com/document/d/e/2PACX-1vSU1rJa3yMtW6vXeihCzK695N-spOphRfwQ1iCiTuv4W8hNg3JSFTsRIsggd7l6kzuFwiVB0jKa5Y3g/pub
  42. https://docs.google.com/document/d/e/2PACX-1vSw8vir5Y9plQkCuAxjgmVlTOnI671vIzs_6hLv4LM2MbxntUAtYjEudrkbM-Nmg6BZ1UH42GsOPBUy/pub
  43. https://docs.google.com/document/d/e/2PACX-1vT7Nfz2LlFfe4OzGrLP-F-tEZXR1UfqsDcEOxxDd2HEa39gwxQxmiFtsfsdgCKxJ_3kIalFwed9Us7B/pub
  44. https://docs.google.com/document/d/e/2PACX-1vT_q1IiiG31N5svdtCQuF91sQpC_8qKOKKqbf4WG_KOYr3tAsYOP0chCgznAn5jAUOBVKauu-9-N9Qi/pub
  45. https://docs.google.com/document/d/e/2PACX-1vTku9R9HwOVre3LgWrw-myaxun_eudBpgvFFt_5Jh_l1RK8C8j9950SlLlG0r2IbWoG-JN1QYvsYYtl/pub
  46. https://docs.google.com/document/d/e/2PACX-1vTqrWv-xt7Pe0yw22SdBCNHz3kXPWfqIoAPjbXHUE_sjUktRn7M8v-2d4g2jvyglSGt4EZGEXbecbXG/pub
  47. https://docs.google.com/document/d/e/2PACX-1vTtwsSk4MWtsc4zgz8ZYvLDsH2Q4dJ4NLGUpVZu5OpMxa9bJxJ2IPePfZHGV2Jw80BkO0Yav_bUe1Sk/pub
  48. https://docs.google.com/document/d/e/2PACX-1vTWADwvXDs2xfqC1DgH6RE7JJ_I0UAR1z9cF--Ta1tIhFHApIXg7lVLczwiOBfRhypgSwtGLOJprSMh/pub
  49. https://docs.google.com/document/d/e/2PACX-1vTyhCYxQ8-QiGYJIFiCg9eKeYOVmgs2ciXS4gSDsaXz7cQaa7vBTtmjzsoLn8ruSWDgtBLWqmkXXQp3/pub
  50. https://docs.google.com/document/d/e/2PACX-1vTzLp4KPycaBYR456_IfFi4gGPJT0wlvG7qRWRnFYtbf2qVkS2qYGS5ANYglmvqFIHAR6o5JqVhU8d9/pub
  51.  
  52. MALDOC DISTRIBUTION URLS
  53. https://asianmedicaldevices.com/helper.php
  54. https://asianmedicaldevices.com/oriental.php
  55. https://asianmedicaldevices.com/sunstone.php
  56. https://dev.triamanggala.com/fulmar.php
  57. https://dev.triamanggala.com/smoother.php
  58. https://espectaculos.empresasuv.mx/incise.php
  59. https://hseconosur.com/student.php
  60. https://hseconosur.com/transhipment.php
  61. https://ieltsbritishcouncil.co/romanticize.php
  62. https://ieltsbritishcouncil.co/steamed.php
  63. https://loyalty.kkcoaches.co.ug/navigability.php
  64. https://loyalty.kkcoaches.co.ug/osteologist.php
  65. https://loyalty.kkcoaches.co.ug/quinbinary.php
  66. https://loyalty.kkcoaches.co.ug/racist.php
  67. https://metastudies.gr/croatian.php
  68. https://metastudies.gr/dropper.php
  69. https://operations.kkcoaches.co.ug/blinds.php
  70. https://operations.kkcoaches.co.ug/honing.php
  71. https://operations.kkcoaches.co.ug/paperless.php
  72. https://sma1sapuran.sch.id/outgrowth.php
  73.  
  74. asianmedicaldevices.com
  75. empresasuv.mx
  76. hseconosur.com
  77. ieltsbritishcouncil.co
  78. kkcoaches.co.ug
  79. metastudies.gr
  80. sma1sapuran.sch.id
  81. triamanggala.com
  82.  
  83. HANCITOR MALDOC FILE HASHES
  84. 07ac3c85d62db7c650df8095aa693d0e
  85. 364f80a5b16841597256388191a2981e
  86. 6800a4b6c4f2f1bf98db25b2175ab1f9
  87. 7bfa20649012bb4d7a38331cb1f1439d
  88. 8e0ea61f2cf1c3b999f19184caffd82b
  89. 914f4441e94cf5e2fcb1bed512ca9bc1
  90. 94d5a498c40c795a24fc127db09e9806
  91. c9374d2cce44359478c4f56d2f0d67e1
  92. cefdb562f6972e78309b165b125f4055
  93. ee654e3a199b6ddd2da0dd7ad854ed80
  94. f98badc4dbe19eddac7464bca1933067
  95. fc7fac4b8e77b228f967cd25c39476fa
  96.  
  97. HANCITOR PAYLOAD FILE HASH
  98. MsMp.dll
  99. 3737ff2818c3648a90028e695bd0ad31
  100.  
  101. HANCITOR C2
  102. http://cametateleb.ru/8/forum.php
  103. http://divelerevol.com/8/forum.php
  104. http://polionallas.ru/8/forum.php
  105.  
  106. FICKER STEALER PAYLOAD URLS
  107. http://tren0.ru/6jhuy675rt.exe
  108.  
  109. FICKER STEALER FILE HASH
  110. 6jhuy675rt.exe
  111. 77be0dd6570301acac3634801676b5d7
  112.  
  113. FICKER STEALER C2
  114. http://sweyblidian.com
Advertisement
Add Comment
Please, Sign In to add comment