Advertisement
hazmalware

2018-06-05 Hancitor Malspam

Jun 5th, 2018
255
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.63 KB | None | 0 0
  1. 2018-06-05 #hancitor #maldoc distribution URLs
  2. subjects like:
  3. You got invoice from DocuSign
  4. You got notification from DocuSign
  5. You received invoice from DocuSign
  6. You received notification from DocuSign
  7.  
  8. sender: docusign@texasliquorlicense[.]com
  9.  
  10. MALDOC distribution URLs
  11. hxxp://abrassart.org
  12. hxxp://biblebaptistchurch.us
  13. hxxp://biblebaptistchurches.com
  14. hxxp://exportedfromsiliconvalley.com
  15. hxxp://idgalactic.com
  16. hxxp://idtechcampsonline.com
  17. hxxp://idtechonline.com
  18. hxxp://idtechsummerstaff.com
  19. hxxp://internaldrive.co.uk
  20. hxxp://ppsvc3.com
  21. hxxp://techieandyouknowit.com
  22.  
  23. Additinal IOCs via @techhelplist
  24. c2 :
  25. http://bipaboone.com/4/forum.php
  26. http://cypartedle.ru/4/forum.php
  27. http://unboforkin.ru/4/forum.php
  28.  
  29. payloads :
  30. http://letoilerestaurant.com/wp-content/plugins/hide-update-reminder/1
  31. http://compassplumbing.ca/wp-content/plugins/responsive-add-ons/templates/1
  32. http://wrcbss.com/wp-content/plugins/feed-wrangler/1
  33. http://csetv.net/wp-content/plugins/gxp/1
  34. http://dolmetscherbueromueller.de/wp-content/plugins/gxp/1
  35. http://letoilerestaurant.com/wp-content/plugins/hide-update-reminder/2
  36. http://compassplumbing.ca/wp-content/plugins/responsive-add-ons/templates/2
  37. http://wrcbss.com/wp-content/plugins/feed-wrangler/2
  38. http://csetv.net/wp-content/plugins/gxp/2
  39. http://dolmetscherbueromueller.de/wp-content/plugins/gxp/2
  40. http://letoilerestaurant.com/wp-content/plugins/hide-update-reminder/3
  41. http://compassplumbing.ca/wp-content/plugins/responsive-add-ons/templates/3
  42. http://wrcbss.com/wp-content/plugins/feed-wrangler/3
  43. http://csetv.net/wp-content/plugins/gxp/3
  44. http://dolmetscherbueromueller.de/wp-content/plugins/gxp/3
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement