Advertisement
ExecuteMalware

2020-12-08 Hancitor IOCs

Dec 8th, 2020 (edited)
3,670
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.36 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Signature Service
  5. You got invoice from DocuSign Service
  6. You got invoice from DocuSign Signature Service
  7. You got notification from DocuSign Electronic Service
  8. You got notification from DocuSign Electronic Signature Service
  9. You got notification from DocuSign Service
  10. You got notification from DocuSign Signature Service
  11. You received invoice from DocuSign Electronic Service
  12. You received invoice from DocuSign Electronic Signature Service
  13. You received invoice from DocuSign Service
  14. You received invoice from DocuSign Signature Service
  15. You received notification from DocuSign Electronic Service
  16. You received notification from DocuSign Service
  17. You received notification from DocuSign Signature Service
  18.  
  19. SENDERS OBSERVED
  20. aacqs@gadeforvasenate.com
  21. bpyuqyr@gadeforvasenate.com
  22. dsjiauj@gadeforvasenate.com
  23. eqferoi@gadeforvasenate.com
  24. faobpvs@gadeforvasenate.com
  25. ff@gadeforvasenate.com
  26. hbolybe@gadeforvasenate.com
  27. huyfea@gadeforvasenate.com
  28. ie@gadeforvasenate.com
  29. iwhocgo@gadeforvasenate.com
  30. jtaaw@gadeforvasenate.com
  31. m@gadeforvasenate.com
  32. oehkyao@gadeforvasenate.com
  33. piaks@gadeforvasenate.com
  34. pjejapu@gadeforvasenate.com
  35. pypafa@gadeforvasenate.com
  36. re@gadeforvasenate.com
  37. reqaoec@gadeforvasenate.com
  38. semyfuc@gadeforvasenate.com
  39. tsua@gadeforvasenate.com
  40. uxiqemy@gadeforvasenate.com
  41. vkioiwy@gadeforvasenate.com
  42. wiqjvb@gadeforvasenate.com
  43. xoaha@gadeforvasenate.com
  44. yb@gadeforvasenate.com
  45. ylovcfo@gadeforvasenate.com
  46. yoi@gadeforvasenate.com
  47. ywnhi@gadeforvasenate.com
  48. yygumlu@gadeforvasenate.com
  49. zoxogoy@gadeforvasenate.com
  50.  
  51. MALDOC LANDING PAGE URLS
  52. https://docs.google.com/document/d/e/2PACX-1vQ05NXM0vhHlnlrYxUL8Iiyq0yVAm89jkVrK6lsi1Xb5xKGXbIpNSykl7weQrvKQzTeyex3A5lkoRVe/pub
  53. https://docs.google.com/document/d/e/2PACX-1vQZ3cuH6wQMcXhFfNzXdxlo6RmRuhw5FuG30j_3WgBxddJ-DhnvoxEQM9z00qQg-XbT7bGkjwwK47dw/pub
  54. https://docs.google.com/document/d/e/2PACX-1vR5LZqj9AAPv9zXLDoIt45C6Akp5DWglYIzv_PE4gLcxsjrApVFaXB30R5VHuadnmACHLIexJHuUWSS/pub
  55. https://docs.google.com/document/d/e/2PACX-1vRgrW1rFi0CHNn2mZ_zS7qVggTQPdVfMlEsPWbgAyZEyh-HtZcb6RNr6BFA4R4h8wl1mCiiYxSV6PoP/pub
  56. https://docs.google.com/document/d/e/2PACX-1vRM1gIeyI0gqidSpV-DpCSW-i2b1-uoLAjKf_UcVEgWvzycsSFHyG4dAKFhxNBCDSOeKnMHs5TXgqe1/pub
  57. https://docs.google.com/document/d/e/2PACX-1vRwdcIuP_t55_Z1hw5I7PN8tS4O9l5INcvVzyViR1sN3YWX2g8NISqWqWeSMypWKmhIFEt27bYWbiqi/pub
  58. https://docs.google.com/document/d/e/2PACX-1vS5QR4Sywek0Bx__Z2Fm8dZkvVhw-z0LgpSkRvcY6vmF4vnT9KymyvItdN_FdC-Kj3pv2ivoEgzxaiQ/pub
  59. https://docs.google.com/document/d/e/2PACX-1vSaCcYK1FTIRc7eUJytdlM393Oc_N0Ywh171y2Xc93zyjpYag2zm7kg_-B2CD0QC-PbVZN9tVp0J-EN/pub
  60. https://docs.google.com/document/d/e/2PACX-1vSOWlhkA_040VLXA66Tm7rQ57lFO1oDa0ZoybBlUR_dMlkwJHR5cQmAn3d95SNFAFE2tZdWCNI90Pkx/pub
  61. https://docs.google.com/document/d/e/2PACX-1vTeVlK4n35ZKNeN-lUZEniggXHuQgaT_RgICLF8-tKM1vvFe3MUHRDII5u-kLZHF1nVjJuecJV1fYHu/pub
  62. https://docs.google.com/document/d/e/2PACX-1vTOD6irOby5Vtn4qV-uNqnhtGiFNup5t3uQ9Sjc3bGvF00N0IDWL4X7AnxpEaBXjICIM-t4G7S5U7cu/pub
  63. https://docs.google.com/document/d/e/2PACX-1vTp4CLFAO1LvTChUnUy-6SnMVFSkqyGWfjrqxt-8vqzlADkZauVxlOElAnbFGJlrbNa2wnTplh0JkzU/pub
  64. https://docs.google.com/document/d/e/2PACX-1vTUYm9BWad7wYEMGrlpW02CvAYIjKTf0r3NAsFejLjr90mNzU-uzS09Bg4sf70Q7eucK5_uxs_721Oj/pub
  65. https://docs.google.com/document/d/e/2PACX-1vTxOae17o35666TabLmuIq1dBbfEqsK1otSJz3vfoPLbNCuXFFFR30_88BGOBxAtTN34jka8Tqdk9Xn/pub
  66.  
  67. HANCITOR MALDOC DOWNLOAD URLS
  68. http://alkalinevitaminc.co.za/pyramid.php
  69. http://ate-okna.pl/quarantine.php
  70. http://ate-okna.pl/ratline.php
  71. http://ate-okna.pl/thursday.php
  72. http://baiiddevices.com/heroism.php
  73. http://baiiddevices.com/multibus.php
  74. http://baiiddevices.com/nuptials.php
  75. http://baiiddevices.com/teak.php
  76. http://muslihin.com/quarantine.php
  77. http://www.zolyoter.co.il/curative.php
  78. https://accounting.marayo.com/toxemic.php
  79. https://addcomunicaciones.cl/quarantine.php
  80. https://addcomunicaciones.cl/rationale.php
  81. https://tododiabetes.mx/imbalance.php
  82.  
  83. accounting.marayo.com
  84. addcomunicaciones.cl
  85. alkalinevitaminc.co.za
  86. ate-okna.pl
  87. baiiddevices.com
  88. muslihin.com
  89. tododiabetes.mx
  90. www.zolyoter.co.il
  91.  
  92. HANCITOR MALDOC FILE HASHES
  93. 1208_4735106192.doc
  94. 49eb4e67b1cef5a235b2858cc899b594
  95.  
  96. HANCITOR PAYLOAD FILE HASHES
  97. W0rd.dll
  98. b0b16d046655871f9a452e2c34d062e5
  99.  
  100. HANCITOR C2
  101. http://maduabin.com/8/forum.php
  102. http://thenexames.ru/8/forum.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement