ExecuteMalware

2021-03-29 Hancitor IOCs

Mar 29th, 2021
16,648
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.17 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD: 2903_21387h
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Signature Service
  10. You got notification from DocuSign Electronic Signature Service
  11. You got notification from DocuSign Service
  12. You got notification from DocuSign Signature Service
  13. You received invoice from DocuSign Electronic Service
  14. You received invoice from DocuSign Electronic Signature Service
  15. You received invoice from DocuSign Service
  16. You received notification from DocuSign Electronic Signature Service
  17. You received notification from DocuSign Signature Service
  18.  
  19. SENDERS OBSERVED
  20.  
  21. MALDOC LANDING PAGE URLS
  22. https://docs.google.com/document/d/e/2PACX-1vQ1k5haNY3R3DYdn4KoE3WOWJ_0YbFYYpoI--8Pr__v-3trX-Sg4KOVXJSgLZKWP_Mr7gHOIEzun1e7/pub
  23. https://docs.google.com/document/d/e/2PACX-1vQ1KAK7aaqzgKFJkCXrYTOcft-AFuS7LxQEYNTSklrAo-Hwxir8iAiD89s7t97UUFWZfajga79ntRaw/pub
  24. https://docs.google.com/document/d/e/2PACX-1vQMw5Ox8cjE4orkyf060C6LjyHeUgoco7kI5NVedLK_QgPvJRgShjqMUXIosfmtLmjm41FwuAB5RHob/pub
  25. https://docs.google.com/document/d/e/2PACX-1vQoG6vVOGpLgZyY5cggjzHNaGwqt-M4ysHkK5bVmn6NNSbisNeCUbhq2l_tXnY1cgDI5qFZT5FpUR22/pub
  26. https://docs.google.com/document/d/e/2PACX-1vQwGz-YYSXW8Gy603rOoZXOCj4oza87GANBvZn-gW92UKzk0XZliyDizziOe7_W4XcyJ3ojyMssz5Li/pub
  27. https://docs.google.com/document/d/e/2PACX-1vQWIIBWB8IVZvm-d80llrww4_pIQzGb_skH4fVirRfkUjC3hZc9I9b_yuS89dtSFx3mocsS47heNfiP/pub
  28. https://docs.google.com/document/d/e/2PACX-1vRfclJ-5wm88C7kfUmrxIYAZyIc32NTQJZGwOpT4wNLsJjlH7TYL-AGhE98XVtT2EmKH6Z_J7BalRbI/pub
  29. https://docs.google.com/document/d/e/2PACX-1vRM820mzzUiMnq8fNVUlj-Y0-qvmrdCsvnLNkgRQu1pMwzbAgmKTdpGqPf5RlR5Gq1-s1hiQVmcFa6Y/pub
  30. https://docs.google.com/document/d/e/2PACX-1vRTsKwyv9_Mlv70s15f5OvEqWr8TjkYubswwcjxwv6BQ5d1mXDflfZ7P3N6ELIbFfY6Nbvhb48U4mZ-/pub
  31. https://docs.google.com/document/d/e/2PACX-1vRtzzvX7R5nATANdr3E67WE-_UFTRzuxtBHNVfOI6ew6kLbOMQUDmWCiV4d1w7TsrchxhppYZ_D9WVv/pub
  32. https://docs.google.com/document/d/e/2PACX-1vRudi0dfzvK6TV586FWkJo3UiuqXByg-sK2lHFwbuH7QLi7xgj9_aXY7qE7jJknJEE2DaC_KRgwIVvo/pub
  33. https://docs.google.com/document/d/e/2PACX-1vS_1zHfjW9Z7PXSgGYu_t8BaBZ3Lo0EauSBjSe2e9vCqz2CATpIRoVVPCvQUJvUS4IrFVTanKV2ZpFJ/pub
  34. https://docs.google.com/document/d/e/2PACX-1vSKSYNEgU5H8pcIXVLkyXTnM_GMy4KGj1rycaEJZlEDtGjzgc96ZdMgNDLYSG95wfJX5npjLcxXpOfW/pub
  35. https://docs.google.com/document/d/e/2PACX-1vT2gTBGFNVb9Jer7vMQfiYVvlVCp18Q56Uf0wpU2oHDYxOyolZP8hR98XkqunQXfpKafWXO6scmEVGA/pub
  36. https://docs.google.com/document/d/e/2PACX-1vT4cKVYcBgq7bhS4sRZy0uEhmmAGqdE4YRZAhbwii_mOVfPS3JJxIaK6BR72PdPAKGyjudYez34K4jI/pub
  37. https://docs.google.com/document/d/e/2PACX-1vTOF0TUFykX588-rc_a7rHZ0r2G72MKHKX7MYjL4XKnQIDJqJYrNuemN2uYFH8mPZkiqbK-jtM0x25L/pub
  38. https://docs.google.com/document/d/e/2PACX-1vTPOf_OxJTqxaPDirVmUIjwpWSADfGpdJCmTzyP2eksu3sa2YntM3T5Un1eYtjXzmnK2xd5oitPlaoJ/pub
  39. https://docs.google.com/document/d/e/2PACX-1vTwUTDdPyAtmnrIB7S32qKVsw6QVuHrKB11vhKn1BMv-9FugDuMsJFbNfbtGap245LwMBhLlXBjjNfB/pub
  40.  
  41. MALDOC DISTRIBUTION URLS
  42. http://necocheasexshop.com/reversibility.php
  43. http://necocheasexshop.com/subnormality.php
  44. http://razwerks.com/crier.php
  45. http://razwerks.com/epicurean.php
  46. http://tlfthelifefactory.com.au/aquiculture.php
  47. http://tlfthelifefactory.com.au/cyanosis.php
  48. http://tlfthelifefactory.com.au/explored.php
  49. http://tlfthelifefactory.com.au/wizened.php
  50. https://demas.tech/arraigned.php
  51. https://demas.tech/bleeder.php
  52. https://demas.tech/defecated.php
  53. https://demas.tech/goldfish.php
  54. https://emiratesminning.com/ext.php
  55. https://record-israel.co.il/prothalamion.php
  56. https://uniquewebservice.com/shovelsful.php
  57. https://www.oacts.com/forehand.php
  58. https://www.razwerks.com/maxim.php
  59. https://www.razwerks.com/workaholism.php
  60.  
  61. demas.tech
  62. emiratesminning.com
  63. necocheasexshop.com
  64. razwerks.com
  65. record-israel.co.il
  66. tlfthelifefactory.com.au
  67. uniquewebservice.com
  68. oacts.com
  69.  
  70. HANCITOR MALDOC FILE HASHES
  71. 2c9a441be8cfb3aad3e11e0dead70f90
  72. 8368ff71e252a7f4f9cca096f960c372
  73. 8e14056b96b9707d4ecde884fcb8a48b
  74. 9421fadb1a0deea4af0d039df07602d9
  75. 94b64acb4498129f3551f48c8aad4ec4
  76. 9c6bdac4a903bc77f49e33ab6eecd6e9
  77. c1f0517a9df9cbcfdb9bfc61c02b44e0
  78. c87c6d11cd68e5090f4346daaaa88131
  79. cd23383155515a64ac8329129bf4ec1d
  80.  
  81. HANCITOR PAYLOAD FILE HASH
  82. Static.dll
  83. e85bb81c96515538f804ef7230bb47a6
  84.  
  85. HANCITOR C2
  86. http://probassita.com/8/forum.php
  87. http://frobenalini.ru/8/forum.php
  88. http://proubleblecilm.ru/8/forum.php
  89.  
  90. FICKER STEALER PAYLOAD URLS
  91. http://clublifes.ru/6jiuu8934u.exe
  92.  
  93. FICKER STEALER FILE HASH
  94. 6jiuu8934u.exe
  95. 77be0dd6570301acac3634801676b5d7
  96.  
  97. FICKER STEALER C2
  98. http://sweyblidian.com
Advertisement
Add Comment
Please, Sign In to add comment