Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: HANCITOR
- HANCITOR BUILD
- Build: 0302_095463
- SUBJECTS OBSERVED
- You got invoice from DocuSign Electronic Signature Service
- You got invoice from DocuSign Signature Service
- You received notification from DocuSign Service
- SENDERS OBSERVED
- MALDOC LANDING PAGES
- https://docs.google.com/document/d/e/2PACX-1vRJcCxmq6V91L1_nGEv44Upt3uhU_BwVsF7bTLTtxPbc7gm24NNiK1l0CLKMriwfQGHzHMH1q-qm39K/pub
- https://docs.google.com/document/d/e/2PACX-1vTb8bBuckRwz8JXbAIvNfZjJdMv1O-Q3QimNmsHnwtXbcTkCEmhTS6drFarFXB4o20ElpwePCQ-OQg2/pub
- https://docs.google.com/document/d/e/2PACX-1vTD5YthhcE0t9iRn0SQi1ZU3TPVT_73SzYC-zKuFqLONsz9RB6LXlfqplElZXUpq-QosggzFSNN-eRo/pub
- MALDOC DOWNLOAD URLS
- http://ajlpublicidade.pt/synthesist.php
- http://www.serve-tour.com/undocumented.php
- https://btcclique.com/subornation.php
- ajlpublicidade.pt
- btcclique.com
- serve-tour.com
- MALDOC FILE HASHES
- a87349c5e2fe7ef31cad560eb767b7ba
- cf9abed05058d19d188f50c0f1d495e4
- HANCITOR PAYLOAD FILE HASHES
- W0rd.dll
- faba140b4629acca24726fc44facaf58
- HANCITOR C2
- http://efelsdvismade.com/8/forum.php
- http://curishisral.ru/8/forum.php
- FICKER STEALER PAYLOAD
- http://buckeyesecurity.net/6lajhbjyuk.exe
- FICKER STEALER FILE HASHES
- 77be0dd6570301acac3634801676b5d7
- FICKER STEALER C2
- http://sweyblidian.com
- http://185.100.65.29
Advertisement
Add Comment
Please, Sign In to add comment