ExecuteMalware

2021-04-01 Hancitor IOCs

Apr 1st, 2021
16,629
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.52 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Service
  5. You got invoice from DocuSign Electronic Signature Service
  6. You got invoice from DocuSign Service
  7. You got invoice from DocuSign Signature Service
  8. You received invoice from DocuSign Electronic Service
  9. You received invoice from DocuSign Service
  10. You received notification from DocuSign Electronic Signature Service
  11. You received notification from DocuSign Signature Service
  12.  
  13. SENDERS OBSERVED
  14.  
  15. MALDOC LANDING PAGE URLS
  16. https://docs.google.com/document/d/e/2PACX-1vQ2ppWe--iSJ3VEepl33K3vEYx0gXf_Vkz3idvlRX-ldhzzIvZmDQtJk9yfG-UWU57uTVYnRhpq79mr/pub
  17. https://docs.google.com/document/d/e/2PACX-1vQq9436z3PaO3ndtW5pGcIm1YikMciJe3N_ubr_syEz4aAvni4vErDDVYfKzsjhUI-GebIn__P15VhJ/pub
  18. https://docs.google.com/document/d/e/2PACX-1vRK7cgPdCcaipphRW5W-cpwwdg0zjbdGPE7G5movv0OjLBdlHsvIB5gpvew1hRfk8nw4Ny3zr_akv1G/pub
  19. https://docs.google.com/document/d/e/2PACX-1vSAFHJAKO7WKmMnN7jvLOmTtWe8gM2SxQ9z4geBfdSb7hlCU95JVd_-rg2qnS-_qu0StKoK_PJrAfII/pub
  20. https://docs.google.com/document/d/e/2PACX-1vScYVQddX7qBiZz6jcwdQnj-ID10gVbO_ZPv4Gie_zjo13YbWOvFueYiYouEQ-W2GhU5L9Ig2ZUFhPa/pub
  21. https://docs.google.com/document/d/e/2PACX-1vSD-I9R60TDGfvJ4K7sTLZF1h2h1vV0xUYh4QCCRlVzMc1yHTakTW4ulE4DNjDH-LoB8kweitIJVlrP/pub
  22. https://docs.google.com/document/d/e/2PACX-1vSTw3jgBO8aOSTzwKQectTvkOpITY5drKQIMY_pHUhRpMdvpWs_APbxXDXaMEiuhLUrSdC-1r6_8-NJ/pub
  23. https://docs.google.com/document/d/e/2PACX-1vTHkVlb-r3k5ObTZZ_wW1Y2lq9TQbE-0aC-tEmmUv6i6hWBN1u8m6XH7iDnV2C0sV2KtWIPcMHUkgEw/pub
  24.  
  25. MALDOC DISTRIBUTION URLS
  26. http://tlfthelifefactory.com.au/foxglove.php
  27. https://iriti.net/crap.php
  28. https://iriti.net/newuser.php
  29. https://koonol.mx/yestereve.php
  30. https://loyalty.kkcoaches.co.ug/prosperous.php
  31. https://pharmaciebougieba.org/stypsis.php
  32. https://silverwhipmedia.com/ethernet.php
  33. https://silverwhipmedia.com/phonorecord.php
  34.  
  35. iriti.net
  36. koonol.mx
  37. loyalty.kkcoaches.co.ug
  38. pharmaciebougieba.org
  39. silverwhipmedia.com
  40. tlfthelifefactory.com.au
  41.  
  42. HANCITOR MALDOC FILE HASHES
  43. Unknown
  44.  
  45. HANCITOR PAYLOAD FILE HASH
  46. Unknown
  47.  
  48. HANCITOR C2
  49. http://cilidobas.com/8/forum.php
  50. http://onvoursmo.ru/8/forum.php
  51. http://bilematicdu.ru/8/forum.php
  52.  
  53. FICKER STEALER PAYLOAD URLS
  54. http://pipopetfiu.ru/6gdj9oidfg.exe
  55.  
  56. FICKER STEALER FILE HASH
  57. Unknown
  58.  
  59. FICKER STEALER C2
  60. http://sweyblidian.com
Advertisement
Add Comment
Please, Sign In to add comment