ExecuteMalware

2021-02-03 Hancitor IOCs

Feb 3rd, 2021
4,698
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.37 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. Build: 0302_095463
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Signature Service
  8. You got invoice from DocuSign Signature Service
  9. You received notification from DocuSign Service
  10.  
  11. SENDERS OBSERVED
  12.  
  13. MALDOC LANDING PAGES
  14. https://docs.google.com/document/d/e/2PACX-1vRJcCxmq6V91L1_nGEv44Upt3uhU_BwVsF7bTLTtxPbc7gm24NNiK1l0CLKMriwfQGHzHMH1q-qm39K/pub
  15. https://docs.google.com/document/d/e/2PACX-1vTb8bBuckRwz8JXbAIvNfZjJdMv1O-Q3QimNmsHnwtXbcTkCEmhTS6drFarFXB4o20ElpwePCQ-OQg2/pub
  16. https://docs.google.com/document/d/e/2PACX-1vTD5YthhcE0t9iRn0SQi1ZU3TPVT_73SzYC-zKuFqLONsz9RB6LXlfqplElZXUpq-QosggzFSNN-eRo/pub
  17.  
  18. MALDOC DOWNLOAD URLS
  19. http://ajlpublicidade.pt/synthesist.php
  20. http://www.serve-tour.com/undocumented.php
  21. https://btcclique.com/subornation.php
  22.  
  23. ajlpublicidade.pt
  24. btcclique.com
  25. serve-tour.com
  26.  
  27. MALDOC FILE HASHES
  28. a87349c5e2fe7ef31cad560eb767b7ba
  29. cf9abed05058d19d188f50c0f1d495e4
  30.  
  31. HANCITOR PAYLOAD FILE HASHES
  32. W0rd.dll
  33. faba140b4629acca24726fc44facaf58
  34.  
  35. HANCITOR C2
  36. http://efelsdvismade.com/8/forum.php
  37. http://curishisral.ru/8/forum.php
  38.  
  39. FICKER STEALER PAYLOAD
  40. http://buckeyesecurity.net/6lajhbjyuk.exe
  41.  
  42. FICKER STEALER FILE HASHES
  43. 77be0dd6570301acac3634801676b5d7
  44.  
  45. FICKER STEALER C2
  46. http://sweyblidian.com
  47. http://185.100.65.29
  48.  
Advertisement
Add Comment
Please, Sign In to add comment