Advertisement
DarthInvader

Hancitor fake invoice September 21, 2017

Sep 21st, 2017
779
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.40 KB | None | 0 0
  1. Hancitor fake invocie phish September 21, 2017
  2. From: Advanced Maintenance Inc. <[email protected]>
  3. Subject: FW: Your Invoice I11<7 digits> from Advanced Maintenance
  4. Downloaded document name: invoice_<6 digits>.doc
  5. Document SHA256: 39d99fdcc0bd9bb9c7ccf65af499eec073265424f1310bc02b51954b8f6f9782
  6.  
  7. Phishing URLs (email not base64 encoded)
  8. eafgi.com/in.php?n=
  9. elefson.com/in.php?n=
  10. elefson.info/in.php?n=
  11. elefsonhvac.biz/in.php?n=
  12. howtobeanemployee.com/in.php?n=
  13. ktraintrucking.com/in.php?n=
  14. trustdeedcapital.info/in.php?n=
  15. trustdeedcapital.net/in.php?n=
  16. trustdeedcapital.org
  17. wpipm.net/in.php?n=
  18. wpipm.org/in.php?n=
  19.  
  20. C2 domains
  21. http://saritbida.com/ls5/forum.php
  22. http://getinwithme.ru/ls5/forum.php
  23. http://maheckkejec.ru/ls5/forum.php
  24.  
  25. Malware download sites
  26. File 1 SHA256 969f1d78a5f40302af23ad52c03755db678118673ba55bd9947a241e51f148a2
  27. File 2 SHA256 0a2a674f6f2c8bb7181b5140925875c4e71165e1e432507950b742bc4a8d909e
  28. File 3 SHA256 6b8d6fab9f6b12a41b9a4380cd9f48f51aef4bfff4d837a7fefcd4e0e79306e9
  29. http://3dprintbudapest.com/wp-content/plugins/all-in-one-seo-pack/2
  30. http://www.photo4passion.at/wp-content/plugins/lumen-gallery/2
  31. http://alvesmarcia.com.br/wp-content/plugins/tilt-social-share-widget/2
  32. http://brs4.com.br/wp-content/plugins/duplicate-post/2
  33. http://aidiag.azurewebsites.net/wp-content/plugins/polylang/2
  34. http://marketresearchlosangeles.com/wp-content/themes/twentythirteen/inc/2
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement