ExecuteMalware

2021-06-10 Hancitor IOCs

Jun 10th, 2021 (edited)
16,735
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.15 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR / FICKER STEALER
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=1006_jspoi
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC PROXY DISTRIBUTION URLS
  27. http://feedproxy.google.com/~r/aqafzzyv/~3/MIiIEfAB1sw/hall.php
  28. http://feedproxy.google.com/~r/arkdoln/~3/svmxgrdZF8s/rerecording.php
  29. http://feedproxy.google.com/~r/cdorea/~3/HwRlbROK1Nk/seniority.php
  30. http://feedproxy.google.com/~r/ddexh/~3/TnugEOI1wPI/unemployed.php
  31. http://feedproxy.google.com/~r/ddirltdc/~3/xs4xAIK9YW0/antecedent.php
  32. http://feedproxy.google.com/~r/dgpkac/~3/fIBLNkD-m_Q/crampons.php
  33. http://feedproxy.google.com/~r/ebmhnmu/~3/CuLUNXC3mwg/cartilage.php
  34. http://feedproxy.google.com/~r/eynqby/~3/gJK9awZMeZU/lately.php
  35. http://feedproxy.google.com/~r/fbibnskhd/~3/MIiIEfAB1sw/hall.php
  36. http://feedproxy.google.com/~r/fctjuzqqvv/~3/cO2HBRnByWc/ruleless.php
  37. http://feedproxy.google.com/~r/frwqwo/~3/zERU9awGMqY/foreseen.php
  38. http://feedproxy.google.com/~r/fxptxbrekvz/~3/7UEF5vR_Sd0/optimization.php
  39. http://feedproxy.google.com/~r/gdxetzwns/~3/NjRtKgWIL_w/wnw.php
  40. http://feedproxy.google.com/~r/goqkeazpl/~3/CuLUNXC3mwg/cartilage.php
  41. http://feedproxy.google.com/~r/gpnge/~3/0nUUpOiwNMc/admissible.php
  42. http://feedproxy.google.com/~r/gsgsgzuofhw/~3/3JW5L3rquNQ/bogotify.php
  43. http://feedproxy.google.com/~r/iuemscklz/~3/8hq1ELWa_Yw/unripe.php
  44. http://feedproxy.google.com/~r/jlyoqpv/~3/XYeCBvUWbjg/interrelated.php
  45. http://feedproxy.google.com/~r/jtabmx/~3/YocPXxnMQ0M/xeroxed.php
  46. http://feedproxy.google.com/~r/kevoxvlshcl/~3/e26Hms8IqX0/abstemiousness.php
  47. http://feedproxy.google.com/~r/khasbipeox/~3/IxgJ6Dp23Os/indecision.php
  48. http://feedproxy.google.com/~r/kpmrzq/~3/APo05_PsL0Q/publicize.php
  49. http://feedproxy.google.com/~r/lffsz/~3/idyhce7j-H8/pix.php
  50. http://feedproxy.google.com/~r/lkzsyzgjux/~3/agDs31Tdt8Q/computing.php
  51. http://feedproxy.google.com/~r/nhnaadosjhj/~3/Df-elJltppY/habitual.php
  52. http://feedproxy.google.com/~r/nzwyuhyg/~3/qI-0bOVjQz0/saclike.php
  53. http://feedproxy.google.com/~r/oecyo/~3/77aT06kVjCk/revet.php
  54. http://feedproxy.google.com/~r/ontlxo/~3/cO2HBRnByWc/ruleless.php
  55. http://feedproxy.google.com/~r/pwrqwzbgmn/~3/9RH2Blm3bUs/ves%0D%0Atment.php
  56. http://feedproxy.google.com/~r/pwrqwzbgmn/~3/9RH2Blm3bUs/vestment.php
  57. http://feedproxy.google.com/~r/qzjrn/~3/aKons1AqrDQ/stud.php
  58. http://feedproxy.google.com/~r/rlnzasahkv/~3/0nUUpOiwNMc/admissible.php
  59. http://feedproxy.google.com/~r/rqfvhrptr/~3/cO2HBRnByWc/ruleless.php
  60. http://feedproxy.google.com/~r/sadnyysqhr/~3/u3xXWsk3z64/integ%0D%0Arability.php
  61. http://feedproxy.google.com/~r/sadnyysqhr/~3/u3xXWsk3z64/integrability.php
  62. http://feedproxy.google.com/~r/swozskp/~3/-kS0wiQdOBk/subtraction.php
  63. http://feedproxy.google.com/~r/sxqjyepei/~3/aN0juNR9evY/celling.php
  64. http://feedproxy.google.com/~r/tbzhp/~3/bIOnBKhFBzI/interrupting.php
  65. http://feedproxy.google.com/~r/thynzpbgmwt/~3/J2YSCYuHgDA/adulterant.php
  66. http://feedproxy.google.com/~r/txitb/~3/QcM2lh04daA/metallography.php
  67. http://feedproxy.google.com/~r/vfarq/~3/dG_tPcg1HGE/pear.php
  68. http://feedproxy.google.com/~r/wgpjb/~3/WcCIsQutvrQ/son.php
  69. http://feedproxy.google.com/~r/wtfftdhkr/~3/zHHAShh38zA/disfigured.php
  70. http://feedproxy.google.com/~r/wywvfhn/~3/_yc4wc9Mkao/interval.php
  71. http://feedproxy.google.com/~r/yvzzy/~3/aSvARx_F7D0/azure.php
  72.  
  73. MALDOC REDIRECT DOWNLOAD URLS
  74. https://afriqanlimited.com/interval.php
  75. https://afriqanlimited.com/seniority.php
  76. https://airpaviliontours.com/bogotify.php
  77. https://business.sngtorg.ru/computing.php
  78. https://dev-ieltsevaluate.pantheonsite.io/adulterant.php
  79. https://dev-ieltsevaluate.pantheonsite.io/interrupting.php
  80. https://dsg-saudi.com/celling.php
  81. https://dsg-saudi.com/indecision.php
  82. https://dsg-saudi.com/lately.php
  83. https://globaldirection.mn/foreseen.php
  84. https://groupfeaab.com/abstemiousness.php
  85. https://groupfeaab.com/crampons.php
  86. https://groupfeaab.com/hall.php
  87. https://groupfeaab.com/publicize.php
  88. https://groupfeaab.com/vestment.php
  89. https://interconnect.bigweb.co.za/azure.php
  90. https://interconnect.bigweb.co.za/saclike.php
  91. https://jyothishmathi.in/habitual.php
  92. https://jyothishmathi.in/ruleless.php
  93. https://nancyyoscar.miwebdding.com/wnw.php
  94. https://newsdataworld.com/disfigured.php
  95. https://newsdataworld.com/integrability.php
  96. https://newsdataworld.com/pear.php
  97. https://sataware.net/admissible.php
  98. https://sushiandpoke.pt/metallography.php
  99. https://sushiandpoke.pt/pix.php
  100. https://tonicata.musicliveradio.com/interrelated.php
  101. https://tonicata.musicliveradio.com/unemployed.php
  102. https://vetechsalary.com/stud.php
  103. https://vetechsalary.com/xeroxed.php
  104. https://vulkanvegasbonus.dealmanshop.com/son.php
  105.  
  106. afriqanlimited.com
  107. airpaviliontours.com
  108. bigweb.co.za
  109. dealmanshop.com
  110. dsg-saudi.com
  111. globaldirection.mn
  112. groupfeaab.com
  113. jyothishmathi.in
  114. miwebdding.com
  115. musicliveradio.com
  116. newsdataworld.com
  117. pantheonsite.io
  118. sataware.net
  119. sngtorg.ru
  120. sushiandpoke.pt
  121. vetechsalary.com
  122.  
  123. HANCITOR MALDOC FILE HASHES
  124. 46eff58594a2ea12edd1833019e00aae
  125. 4f44dde6383c0f5abec0efc070fa167c
  126. 9ba7829e7bd2314b91b69b35403eed6d
  127. a788a0890861c8f9880dffef5cbf12e1
  128. ba7555efe908b9aa59d39c57de10b68f
  129. bb3d6ac5cc9bca35dd5b74801b3f322b
  130. bfeebdc604abdc97c9da2b337045e577
  131. cddcb0ada50e05f4d0cff1311ea0c8d1
  132. d0f72f4ceb96872340ed545ad6e11ef6
  133. dd5629147657859790cdb03337487231
  134. e91e95875adbcae6b40f363032acef10
  135. f9312ab4b04dc4b429a3eb3fca699a10
  136. f9bbbe5df20138752175cccb96db1101
  137.  
  138. HANCITOR PAYLOAD FILE HASH
  139. omsh.dll
  140. 7c4b7cca0ba65ceccd38feb943e942da
  141.  
  142. HANCITOR C2
  143. http://musertwoolion.ru/8/forum.php
  144. http://pingerrhospea.com/8/forum.php
  145. http://sanduallsocco.ru/8/forum.php
  146.  
  147. FICKER STEALER DOWNLOAD URL
  148. http://zazno9a.ru/f7jk8uisdfkh.exe
  149.  
  150. FICKER STEALER FILE HASH
  151. f7jk8uisdfkh.exe
  152. 270c3859591599642bd15167765246e3
  153.  
  154. FICKER C2
  155. http://pospvisis.com
  156.  
Add Comment
Please, Sign In to add comment