Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: HANCITOR
- HANCITOR BUILD
- BUILD=0103_jepskew
- SUBJECTS OBSERVED
- You got invoice from DocuSign Electronic Service
- You got notification from DocuSign Electronic Service
- You got notification from DocuSign Service
- You got notification from DocuSign Signature Service
- You received invoice from DocuSign Electronic Service
- You received invoice from DocuSign Electronic Signature Service
- You received invoice from DocuSign Service
- You received notification from DocuSign Signature Service
- SENDERS OBSERVED
- MALDOC LANDING PAGE URLS
- https://docs.google.com/document/d/e/2PACX-1vQ1BBFmsSzUwpCZ-Uja7NHss8TYWEzJ_34oUPH83iem-_nwfFSWx4fL55yiOo5dl_0iKlduWyyYWTRo/pub
- https://docs.google.com/document/d/e/2PACX-1vR0__W8JBBAqUKv4cCPNpPkJg8viAGgsChkS6DQMeNH0U-rcnjezW1HTidjvcnBI1TYiVPMPDVIUoHQ/pub
- https://docs.google.com/document/d/e/2PACX-1vRGkFAdGp3mXtlBv5D8P41ClN69-vnvScwD_ZOauh7MlK41TfP6tluhhUlDAqpnXQjeWcBUnaapRgW6/pub
- https://docs.google.com/document/d/e/2PACX-1vRi0Ovc9gOO8byt1z8pTYhlgpVXjHjMzJPU7S-9IygNuDD7XW_4H2Sv60CM6b1xVh9G2ebf_E8c6wBx/pub
- https://docs.google.com/document/d/e/2PACX-1vRiA8cNdUVs-m5sq-Q_s5-paQVU1u0IfIg9-loXJjHqTcXEi9daJYw3nFYkkE10rAbRdGJMwTt2kIgg/pub
- https://docs.google.com/document/d/e/2PACX-1vRxaJV_jRNas-jKbTQwFRU9-NC4_toXqpTveUjzeZUIhxVYBwOU8gMI5Lzpv1aOy9hTaSuAMZpXqk3f/pub
- https://docs.google.com/document/d/e/2PACX-1vRxYpQ_bnUJfGnjA052uiEXM4ZxU_lUB4evRC2R95Okt4_i1ffM23S_AB4fPC6S4NChmpKzYQtQW8z5/pub
- https://docs.google.com/document/d/e/2PACX-1vS_DkYI_GouxsICJqTb6y9mL1zB2lgcUi2k-2NWRqo9lxtswXHgkMBtBFgpMe7OBSrzPBAHL7nYZ0bX/pub
- https://docs.google.com/document/d/e/2PACX-1vSFTUvqL6a0ot_nKE8asntyX8JP36imF5aV0hPYQERVCHW93GklFnv3pD5SCC3iBlxydqzCYguakDEF/pub
- https://docs.google.com/document/d/e/2PACX-1vSLQMLDzGHCZ55B8kuzEeDCzm7LWuJxeU07FuUj217O9ieC-kewtDAxeQ8iMmggGCEFbNTlwxftFekU/pub
- https://docs.google.com/document/d/e/2PACX-1vSnLI_zroqVc45v0qVIgq4NS18rGDL1_tfcGTf2rD277XrRhEuEwvQEBuIPRc9wilU7X6RtPBpTbY4r/pub
- https://docs.google.com/document/d/e/2PACX-1vSOShpI-Zj4HZxdkssmk72EfxAabzii42omy1dQixWt3MERVhgFr-rGZvtOn3nwbSJK4CpPdSVw5165/pub
- https://docs.google.com/document/d/e/2PACX-1vTCp9Qx5lwEGH28FcUHYLUgG_k6-2rqKoVZHnjH8qPQVFAm4hH_Z3qPhcxD6PL9bxH2MD4iN2GlBazY/pub
- https://docs.google.com/document/d/e/2PACX-1vTdzsjFl3gZZx2A0apd_kKexsNP2HlEro-IVlRC3CJ3lwd5R04cD69yoZmxE2l4P7va_AvwRKZkYnZ5/pub
- https://docs.google.com/document/d/e/2PACX-1vTi_7pKKEYNftGgONZ4ET5A2r_9J2KEiXOoncNg0QUpPC8NJvD6zOFC5ATANv1o3iNm_YpxSlyic7p6/pub
- https://docs.google.com/document/d/e/2PACX-1vTqWgR7_-sp6OwZIHiqia9DQoAfwCaD6FquL1QkUIokf_ZER3DLn04a7_2GeBJlC-hzYyj6VlXVED4K/pub
- MALDOC DISTRIBUTION URLS
- http://kiehlturkey.com/endoenzyme.php
- http://kiehlturkey.com/underclothes.php
- https://bgurbanglam.com/scheme.php
- https://bgurbanglam.com/stuck.php
- https://connect.rio.br/forage.php
- https://crm.basilrealty.in/germany.php
- https://crm.basilrealty.in/sophist.php
- https://losgedeones.com/stimulated.php
- https://notredame.netafrica-sarl.com/catastrophe.php
- https://notredame.netafrica-sarl.com/estimation.php
- https://webworks.nepila.com/peculation.php
- https://webworks.nepila.com/readies.php
- basilrealty.in
- bgurbanglam.com
- connect.rio.br
- kiehlturkey.com
- losgedeones.com
- nepila.com
- netafrica-sarl.com
- HANCITOR MALDOC FILE HASHES
- 4fa931626b5cfaa706213db17d0c61dc
- 609d8d63f5a483b4e333d54aa9e5c60b
- 693fa214e73716254347f33f0c50a289
- 6b5e020928e890335ec896cf9037e144
- 8932fef09da75fa3b39382fb861bedf1
- d996737591be99bf9a3085dcda2cd81f
- de6deb3c6429e930ce2edb82ce788dbf
- HANCITOR PAYLOAD FILE HASH
- Static.dll
- 8d54e98795c459e0263c1d40cbdfc9f8
- HANCITOR C2
- http://ementincied.com/8/forum.php
- http://watoredprocaus.ru/8/forum.php
- http://noriblerughly.ru/8/forum.php
- FICKER STEALER PAYLOAD URLS
- http://mymooney.ru/6fwedzs3w3fg.exe
- FICKER STEALER FILE HASH
- 6fwedzs3w3fg.exe
- 77be0dd6570301acac3634801676b5d7
- FICKER STEALER C2
- http://sweyblidian.com
- COBALT STRIKE PAYLOAD URLS
- http://mymooney.ru/0103.bin
- http://mymooney.ru/0103s.bin
- COBALT STRIKE FILE HASHES
- 0103.bin
- 51e57f45762d279776b98d27f415ce6c
- 0103s.bin
- ab918b8f731858bef1b8994608ffb66d
- COBALT STRIKE TRAFFIC
- http://45.63.69.93/Qn7f
- http://45.63.69.93/cx
Advertisement
Add Comment
Please, Sign In to add comment