Advertisement
ExecuteMalware

2020-12-01 Hancitor IOCs

Dec 1st, 2020
4,203
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.59 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Electronic Signature Service
  6. You got invoice from DocuSign Service
  7. You got notification from DocuSign Electronic Signature Service
  8. You got notification from DocuSign Service
  9. You got notification from DocuSign Signature Service
  10. You received invoice from DocuSign Electronic Signature Service
  11. You received invoice from DocuSign Service
  12. You received invoice from DocuSign Signature Service
  13. You received notification from DocuSign Electronic Service
  14. You received notification from DocuSign Service
  15. You received notification from DocuSign Signature Service
  16.  
  17. SENDERS OBSERVED
  18. atehuxo@floydnicholsonsc.com
  19. emvudyf@floydnicholsonsc.com
  20. fytuqc@floydnicholsonsc.com
  21. gu@floydnicholsonsc.com
  22. he@floydnicholsonsc.com
  23. hrtih@floydnicholsonsc.com
  24. jhoxoha@floydnicholsonsc.com
  25. juiarif@floydnicholsonsc.com
  26. lpi@floydnicholsonsc.com
  27. lue@floydnicholsonsc.com
  28. memasup@floydnicholsonsc.com
  29. nayolec@floydnicholsonsc.com
  30. nsaab@floydnicholsonsc.com
  31. nufyovi@floydnicholsonsc.com
  32. omhwyuq@floydnicholsonsc.com
  33. ppzqolb@floydnicholsonsc.com
  34. qeriop@floydnicholsonsc.com
  35. roohawc@floydnicholsonsc.com
  36. roujgeu@floydnicholsonsc.com
  37. tneki@floydnicholsonsc.com
  38. ujaer@floydnicholsonsc.com
  39. vbhial@floydnicholsonsc.com
  40. vuecres@floydnicholsonsc.com
  41. wgdubit@floydnicholsonsc.com
  42. wmeymic@floydnicholsonsc.com
  43. ynugylo@floydnicholsonsc.com
  44. yokwete@floydnicholsonsc.com
  45. yuoy@floydnicholsonsc.com
  46. z@floydnicholsonsc.com
  47.  
  48. MALDOC LANDING PAGE URLS
  49. https://docs.google.com/document/d/e/2PACX-1vQ56hL1S9wi5_cf-PM_yo3DAMAVRlpKxalNWQtdor_e5nEJi-ypPd81a6sbosM88BYoXJ-xrs-b2MIO/pub
  50. https://docs.google.com/document/d/e/2PACX-1vQ_ejRVaPfRSeyGOH-_gxWcs5ML6r09pDGYmthIAj0a_TiLOHF6If21mKE2Clky0Mb_jDQt_NBj7O0g/pub
  51. https://docs.google.com/document/d/e/2PACX-1vQepTBRKoBYvOVS00vOG89CUn8zBo5oh0PgDDZ0zLQsAA5YTPSYvwdFs9FRxQTP0PF7wR8qBXXelCa0/pub
  52. https://docs.google.com/document/d/e/2PACX-1vQnoH425xcZ-g7U5gAyZdAUwpWnKJ4eS8SKfRBZ7rGCxF_oqCtmSfiAwKa08djhwQ_4wHdfUbnzxLxd/pub
  53. https://docs.google.com/document/d/e/2PACX-1vQVA0p6mPvpxKrIuAWYEHr_qbp9LIz3Ypjqr82dQ6vfdCdR2pvUutLKH5dO4NFJ7WULHVUD724dJkCT/pub
  54. https://docs.google.com/document/d/e/2PACX-1vRfg8Wp3HL8clUwBx0E03qSzGtUbv7-kCH_Ob4PmSf6G7cwKEKMF8TcYyUvJZxmLmbf2sazkNdvHVsB/pub
  55. https://docs.google.com/document/d/e/2PACX-1vRgVimR650Q681Hf2hemzeZgO3DahpEjrv9AySMcaNhZI2vNePVjo7nf8Zc92wi9vDAjhzUT2c3INUR/pub
  56. https://docs.google.com/document/d/e/2PACX-1vRWahdcqJJZsAx0YzWT-LDdLsdBwgOgwRdLs9_cH0jzRAzhgWrTeWLU02BEo_YaEMTZQr2as_IDpRxE/pub
  57. https://docs.google.com/document/d/e/2PACX-1vRWK65LTlJOqoEns40fUjlkcy-Vq7H1X_f9wLwIqn-8pSlIK5lchuZ52A22RvxWgCaXlQtNJnLAtYMp/pub
  58. https://docs.google.com/document/d/e/2PACX-1vSCyfdxcaI264D3YxETs_rIQtv6qzAqMuwij1P4dt9OJJNscT7pWdmT-XsOoP7UQqGyI7IHaeOS20Cn/pub
  59. https://docs.google.com/document/d/e/2PACX-1vSdY4v5ql3SIpXCLrewGnGNuIdW4PDeE5iW2mxDisqSxN2ka8FsWU1pCqUEIp9uDaHg7ex_LgmknK0N/pub
  60. https://docs.google.com/document/d/e/2PACX-1vSjkuv8QqtZD4vxz7B-bRuq3A4gRtjMhfRnzkiOz0GdxPYISZfc4wQsUMg-JXXpOfVIC_-TwNF9EQLL/pub
  61. https://docs.google.com/document/d/e/2PACX-1vQ7qr29WdXLGHr_RN8_sxT3Iq0pab4dgoydK2z2PjZV0bTPqMuo1QOtzr8k2GX1E3Jwb2r3qOYqNDCF/pub
  62. https://docs.google.com/document/d/e/2PACX-1vQIFaYf2s6IkIqUcRB70qh6uyulN6IaaTHQbZ7XICR30icpLQf_HqprhpZPfC56nB4w_PWMQtERuZkp/pub
  63. https://docs.google.com/document/d/e/2PACX-1vRfg8Wp3HL8clUwBx0E03qSzGtUbv7-kCH_Ob4PmSf6G7cwKEKMF8TcYyUvJZxmLmbf2sazkNdvHVsB/pub
  64. https://docs.google.com/document/d/e/2PACX-1vRWK65LTlJOqoEns40fUjlkcy-Vq7H1X_f9wLwIqn-8pSlIK5lchuZ52A22RvxWgCaXlQtNJnLAtYMp/pub
  65. https://docs.google.com/document/d/e/2PACX-1vRzJHMd8fWZbzr-C7GfyHDqCF_utejsGG9XBeYBw95TEwo6o1uvAot2HsGrmL3tm3uDmWpjITvUsk72/pub
  66. https://docs.google.com/document/d/e/2PACX-1vSuFPP3RAcW-HjifvTI49f8-qJxxinAsOU4Quf6B0MZBbpZF1bbhB0mvvXU5BMLRzUp3TqOzOYqLPls/pub
  67. https://docs.google.com/document/d/e/2PACX-1vTQdWdQwxUzgyJXPq9lLM93qrWdUXKGwpoR8WML1QTLnNQ8mXpNJi4bFhL-z4aRfPK1WAqecfQqXtNo/pub
  68. https://docs.google.com/document/d/e/2PACX-1vTqoVDo0swxNa8jI7ZPOUHF4dilURlmax9E9sIs8U0lqsCUkv9zmVnELxs-w5uSibub5Nt2fvy0fwNW/pub
  69.  
  70. MALDOC DISTRIBUTION URLS
  71. http://actorwebsitereview.com/pulser.php
  72. http://actorwebsitereview.com/veneration.php
  73. https://accounting.marayo.com/duce.php
  74. https://addcomunicaciones.cl/farmland.php
  75. https://addcomunicaciones.cl/lie.php
  76. https://demo.infinitechlabs.in/forester.php
  77. https://irchemicals.com/sledges.php
  78. https://irchemicals.com/waterflood.php
  79. https://licambala.in/probable.php
  80. https://mycourse.campusdirect.lk/interstage.php
  81. https://mycourse.campusdirect.lk/nominee.php
  82. https://rumahsyariahmks.com/dribble.php
  83. https://webshop.today/antler.php
  84. https://webshop.today/duce.php
  85. https://webshop.today/humidifier.php
  86. https://webshop.today/skinned.php
  87.  
  88. actorwebsitereview.com
  89. accounting.marayo.com
  90. addcomunicaciones.cl
  91. demo.infinitechlabs.in
  92. irchemicals.com
  93. licambala.in
  94. mycourse.campusdirect.lk
  95. rumahsyariahmks.com
  96. webshop.today
  97.  
  98. HANCITOR MALDOC FILE HASHES
  99. 1201_1005636132.doc
  100. 58ea9efecaa0b253fa380d4276042971
  101.  
  102. HANCITOR DOWNLOAD URLS
  103. None - .dll is embedded
  104.  
  105. HANCITOR PAYLOAD FILE HASHES
  106. W0rd.dll
  107. 5c308000e25bd8d813f9a73f895ea3cb
  108.  
  109. HANCITOR C2
  110. http://exieverhiltur.ru/8/forum.php
  111. http://neectuded.com/8/forum.php
  112. http://otsoebabe.com/8/forum.php
  113.  
  114. exieverhiltur.ru
  115. 45.129.96.151 - 0 days old
  116.  
  117. neectuded.com
  118. 185.82.218.163 - 0 days old
  119.  
  120. otsoebabe.com
  121. 185.18.52.47 - 7 days old
  122.  
  123. FICKER STEALER PAYLOAD
  124. http://canadiantourismroundtable.com//hajdfjadf.exe
  125.  
  126. canadiantourismroundtable.com
  127. 8.208.99.64 - 6 months old
  128.  
  129. FICKER STEALER PAYLOAD FILE HASHES
  130. hajdfjadf.exe
  131. 107f4a58dc56c803088abb23d29b279c
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement