ExecuteMalware

2020-12-17 Hancitor IOCs

Dec 17th, 2020
4,985
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.90 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD=1712_undet67
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Service
  12. You received invoice from DocuSign Electronic Service
  13. You received invoice from DocuSign Signature Service
  14. You received notification from DocuSign Signature Service
  15.  
  16. SENDERS OBSERVED
  17.  
  18. MALDOC LANDING PAGE URLS
  19. https://docs.google.com/document/d/e/2PACX-1vQ2QXfOGpxae9IyFfzasZP1u-mT03K1S-TW7hTa6bnitTQMBfXjo7jFQ9CToMfSsnpYDzpdMlct6sjR/pub
  20. https://docs.google.com/document/d/e/2PACX-1vQ_k8CrPpNCrPsDUbfD9hmKcz_-eyncjNzturXJ9iFeaz8Hwwa4sM2tGvm4niK9WiwUMo96YYPi3XYG/pub
  21. https://docs.google.com/document/d/e/2PACX-1vQe-03qu-wutEmftaeT_Uf53buI_EdCg5Ux-9gGzE2vgz6cu2ZBQkN7wg8EhniRDX9z4bQSlzwas_B_/pub
  22. https://docs.google.com/document/d/e/2PACX-1vQl03hxnXxTir2zvOvGekN9OJ06ON1J_6Tsnn31c007_1oFTuZGx-zrBOpsrDPqYXPZ_Ic9sehitTj2/pub
  23. https://docs.google.com/document/d/e/2PACX-1vRROYyqkkZIRkNmvjxJPT7kwstgEIIzt4cGk4O6rSdeNuP0_oIONLbUCSR5nPCcEK9kdZZqLA3NwWsd/pub
  24. https://docs.google.com/document/d/e/2PACX-1vSt-e2k0HQpUADMTE9MBcr66CJzY6VXGKO5BWGiLbCI5tRsF2QiZcwqP8gElzZwS1wHoPQ9tr1HniE9/pub
  25. https://docs.google.com/document/d/e/2PACX-1vSWuuLYx4vpv7ZFB2xQdtt_sK838DR_r-9pxEJX4HIDMdiWAk8JSW1szCGmYchkgOi7FjrYRdVQLgNo/pub
  26. https://docs.google.com/document/d/e/2PACX-1vT4cIgiI75tt8LddzyNAnUTZ8zgpKxIB4DPsyry9xrdrQHZmhOlS0AW25qQz-c4eO8ibE65_DtTUHl-/pub
  27. https://docs.google.com/document/d/e/2PACX-1vTNZjcpwpglRscfZfD7-0BtQSrz-vygWKDNpmUG-pd2hii2olti5Z97sIueHp0j0HrfhJefd90S2a3j/pub
  28.  
  29. MALDOC DISTRIBUTION URLS
  30. http://clientpreview.site/counterfeit.php
  31. http://clientpreview.site/sheepdog.php
  32. http://crm.brees.com.au/multilist.php
  33. http://crm.brees.com.au/november.php
  34. http://plataforma.iestpasco.edu.pe/madera.php
  35. https://hvlegal.com.mx/twitchily.php
  36. https://phqindia.paramwebinfo.in/hardship.php
  37. https://phqindia.paramwebinfo.in/ubiety.php
  38. https://store.matstijmes.com/trephines.php
  39.  
  40. brees.com.au
  41. clientpreview.site
  42. hvlegal.com.mx
  43. iestpasco.edu.pe
  44. matstijmes.com
  45. paramwebinfo.in
  46.  
  47. MALDOC FILE HASHES
  48. 1217_1005636132.doc
  49. 173be5ae82d52008905fbcf25c7b5677
  50.  
  51. 1217_776111571.doc
  52. e62fbfc3525edd9fd0e18002e996cdb6
  53.  
  54. HANCITOR PAYLOAD FILE HASHES
  55. W0rd.dll
  56. 82302391c9e003e5796abee20a6134fa
  57.  
  58. 1217_776111571.doc_ya.wav
  59. 82302391c9e003e5796abee20a6134fa
  60.  
  61. 1217_1005636132.doc_ya.wav
  62. e75c6b79339fed8026e913c8092f9f2f
  63.  
  64. HANCITOR C2
  65. http://wourionlion.ru/8/forum.php
  66. http://peasseal.com/8/forum.php
  67.  
  68.  
Advertisement
Add Comment
Please, Sign In to add comment