ExecuteMalware

2021-04-13 Hancitor IOCs

Apr 13th, 2021
17,903
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.03 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD NUMBER
  4. &BUILD=1204_spk
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC LANDING PAGE URLS
  27. https://docs.google.com/document/d/e/2PACX-1vQ7GZHdTnd4MNIPCKQfsYLwFZg9jCf6RZc_dWmBNfv1b8_-gpDeULqR_q4wH3OwsQdojU2rNA2rxYLu/pub
  28. https://docs.google.com/document/d/e/2PACX-1vQARNsiEr4NRhhLMvlaK_goqoo3oPG1y0J-iMVq2YHqFoRBdG1u2VB0d36M-emX-lKW4H-WaoitZEHo/pub
  29. https://docs.google.com/document/d/e/2PACX-1vQb2jsfd_f-e9EScoCYB2kyW6BI1wWrf0fpr7m2NbYTHGnYz3JC8yThf8jOSBKRv5MJmIV_QYbvg3Ah/pub
  30. https://docs.google.com/document/d/e/2PACX-1vQc_hGGw3VFMcBMJtxNUPDU8KpHOKAUxbFYoNVr_fNLRq3b949KMNpZ_a7Q3I1qPaenTS-QF93-3Bu6/pub
  31. https://docs.google.com/document/d/e/2PACX-1vQdxbDGdL4qjHvGSi4eBJIwjQiYeXuUi8AFR8KijDC1iTw2hQX1zVgiguNXY4fBaM_h08vWcfQs7OyG/pub
  32. https://docs.google.com/document/d/e/2PACX-1vQe4c-gkca8K1jqpgTRTWD9UHk9DD0Zr11GuLaDVGHqJHLUzXR8SpqQhR7X4p8cCshR3h2SUtmLFOM2/pub
  33. https://docs.google.com/document/d/e/2PACX-1vQeLDxEfFrw8-q8v9wP4m9iCoyVZuipAUv0oc0VqTU4CWtS0lD9Cr9z1EQ5asNhOBXixhU74rdQH_tK/pub
  34. https://docs.google.com/document/d/e/2PACX-1vQhntNo5hUCvmFpdZNhl1nySppwD5Tzeb8YRR57bC28BiEuUFr8a89Rv02CEcEZN6V5u9i91Y52S7RW/pub
  35. https://docs.google.com/document/d/e/2PACX-1vQmNei9lHHaejfSxZHtaJA1YZS0x3iV2jAetlQYLzwN7IUqdtERnqxnZS1-k6WzXJbuuugCYk650TWH/pub
  36. https://docs.google.com/document/d/e/2PACX-1vQRs16g-NlaXb6wC66bAxo9kN27BdecsTfGVdg5yYUck5vNaP34Vq3dWoLmmaDt4gEIhGR5i3b5rT5W/pub
  37. https://docs.google.com/document/d/e/2PACX-1vQvd5YIdxQRFLWWhsF6twI9aQjtZ5VAtGurDKIM9nqjK01OEmtXpKpsHlGIq2aFGI4S_xE5z6OAozsw/pub
  38. https://docs.google.com/document/d/e/2PACX-1vQvZDcn6KwITcTjKbTpDv_Tfnb8QsAfkZc84yxG9pXYGuXKaZ95D88oV5W5I_skbN2YPSO_5LyyZdDw/pub
  39. https://docs.google.com/document/d/e/2PACX-1vQw4qEaGEOqZiVRzIoCLfZ5R1zBY4c1lhHB-7Ndr9qOBazXIPhk1YJQPfGXuG4-VvM1QJlxIjlC0HaH/pub
  40. https://docs.google.com/document/d/e/2PACX-1vQW_V99gzrzOqOC2C5hHgEmZsAwEW9v2vUYkKRDQ-ZLN_W5N1J2x1K8h050TTXtp-AFKigDRoMKbgox/pub
  41. https://docs.google.com/document/d/e/2PACX-1vR7FAbnyTk1LMI90_r0bYvec9xnxtIzeVNEAUhCOztMNs8BdwGncVoA5FmAxeF3BjRnTtsTQ3ewMJZW/pub
  42. https://docs.google.com/document/d/e/2PACX-1vR_4OvWET2aduOgh0GQEFyx0I1X4tbFjxIx4beaAf0Ya2Iqz-iU3ASolh1q4JVzH6Z1gvSbcvCZHISg/pub
  43. https://docs.google.com/document/d/e/2PACX-1vRAManPTahs1WyilUHdYIwYivRuzWySszYCqtbCTksHafrC_xAMWNk_5UgzaLXX8rnL0xrpQxaBz4RV/pub
  44. https://docs.google.com/document/d/e/2PACX-1vRAyC9tNLx4ghnSzNYzEEYxEN7GdX3iKuHJbU-K9lRvLBof05yFPbuuQa6yKg23AAylCsKj6Kpynq_A/pub
  45. https://docs.google.com/document/d/e/2PACX-1vRBha-RpZGZWnvRUxoEAGnR1GBJugmz5Vi5txpTsOrOgveUjpIbYBBZrvZX5NmftTLvToRKZ_n6VHXi/pub
  46. https://docs.google.com/document/d/e/2PACX-1vRDdsmGXPLYiM4IDXVNp-GqZIzu51hGeoROvxOAZ_RTncLXnVvul87NLCWh_-W34O0iwSN0b5AzYZqm/pub
  47. https://docs.google.com/document/d/e/2PACX-1vRjJHObzw4XBxklCIbC-XT3oxhKbNlheBbLqWR-8sV7XR1SYiX5JtDJABO9RcURYORBfP4Fzw6g1cAn/pub
  48. https://docs.google.com/document/d/e/2PACX-1vRM6SH4toHMg6Ooc9CJVYESoklQ3OHYG5Pp11sTDyuyhe01X82PwCzP-lSz_fFPogou7Q__Ik1Bn1vv/pub
  49. https://docs.google.com/document/d/e/2PACX-1vRm9U1GI9QadPnkX6dRXx5DMAXmpycDijkeNEN8Jeuq5xkeX4vjOW9km64i3YbNgZaNe6fCKQDzYaaZ/pub
  50. https://docs.google.com/document/d/e/2PACX-1vRR7gkFmYxDpSNtrHpUcC-8_p0r6AxkWLyXVqWWEPMO-jM9lp43Y0ntnbISMelPRJPTiLtvC8ias4a_/pub
  51. https://docs.google.com/document/d/e/2PACX-1vRRAHWjcf5PEH5acMqtJk427SARzAQ_BPSGM9XTOyzARD3HSaGco6VHyfkSe03lm104-pSe9s-j18my/pub
  52. https://docs.google.com/document/d/e/2PACX-1vRT-cBjZPYg0ujadB68Rrb4LoKpsw1h3mkUFrGfCETESxKYvDzzn4OtxEayvArEtw7cR8XNz850igOg/pub
  53. https://docs.google.com/document/d/e/2PACX-1vRx4Z0Ue6OuSLfbDj1WPufod_qkwZTGAWJ1BrmoTk4E0zWle51n0C5EiP4Jmd8Jnd9K0aWkUGSZ4-9b/pub
  54. https://docs.google.com/document/d/e/2PACX-1vRzyjVDGGIp_ar1brisWvb3yrMW7U_8pTUFl-y8HVe8tzppbNQlRNnfAQXFCWr8kc2VvbAplzQGHa5R/pub
  55. https://docs.google.com/document/d/e/2PACX-1vS0I-8aHoczDKhhcNz_dr9oDidJ9QlctQsLoeTN9iBNexXd_YyinjN5MoTJH0cjQm36UQtSEzRJO-gE/pub
  56. https://docs.google.com/document/d/e/2PACX-1vS8hl0zqGwOZ20dtv02cjHZBSazxQZdRaYE7s_gXXQQlpvrL6l9HBgPqD0bc_-ZZSLLghW4vYzILwi-/pub
  57. https://docs.google.com/document/d/e/2PACX-1vS9TZSOp-YOf48vG0Pcn_NjzMu3Q7Htx6U1u9L-V-F_8KDaeyO40BnsENdnBxGdeO2tmke1GewAf8SB/pub
  58. https://docs.google.com/document/d/e/2PACX-1vSCHVBB6Ft41g3Qr5YL-Jp41u5OTzoKdKiqCz5v2zzSJSs4QTl3DWJcyCvs66MVCyx4jQCoDderK1QV/pub
  59. https://docs.google.com/document/d/e/2PACX-1vSEzuXWdoRUzmZvx3Jc51gE3AlPlusBAv0wUULwwTCZmdzThCDT67azP9zrQB6d2JZwqmxG3OebHpOK/pub
  60. https://docs.google.com/document/d/e/2PACX-1vSlMX0bjW8JU4wvpySQGmvwtQLHC9jcGaJ47ZIszO1d-7NoZ0dVjP56vFsloembMa3muUTPos6aUhee/pub
  61. https://docs.google.com/document/d/e/2PACX-1vSlpzJlCyg5cvM6QppqdYGLvyPLXZfac1aw96-GYHNs2nohf3e3Tqm7uLCx8CSnvA3VsGi1eImZOOkL/pub
  62. https://docs.google.com/document/d/e/2PACX-1vSpxKHz-i-GlQC01doVoXd9KJ92HNW2NScg_QVUrSksZDDUL4_VbVVv_FAE_LiO2VG3CN9C8olcHacM/pub
  63. https://docs.google.com/document/d/e/2PACX-1vSS5vaUNEtt_lkHZe-wTyEgYd_KzVqlJpgt0KSnnKWCN0lB8jjLUZ90r3oxDBAFWDeMraHJtAUeNLvY/pub
  64. https://docs.google.com/document/d/e/2PACX-1vSSCnpkbVGIsC23ez2j7RJ376aNyaqM02vN-vyp3-L-L5ZGsivyj93M0tl3dqEzcpd6TzfC83AxJQ9w/pub
  65. https://docs.google.com/document/d/e/2PACX-1vT5vGgUBWOpuOUTYhhwT0jNt5JHXfnQnKuwTLdVcoUFMBu9K9BZcraRCkzNj4OcnZEgAxRj8GqWc7wP/pub
  66. https://docs.google.com/document/d/e/2PACX-1vT8uBkLQIBTsq10Wh9fpHzLT8mi8_pdTahb1JrecLd0waYEUpbAhng1u1hkHUgKRy5EUxI-7Asv1dfT/pub
  67. https://docs.google.com/document/d/e/2PACX-1vT_rYIlZ4-8_f7q07puopTbYWRI0gds9wklRNGMzQUXNCpfCQgRiH8ReL6-6f-_KcqEJb5D2JbmYozp/pub
  68. https://docs.google.com/document/d/e/2PACX-1vTaUqijCc-LzrZFfNQHgOao8C08tsTX0ikzlTBpaC7hVLAYzCTeh7KzL7zw4iUiJerUBcvCImLyKnQE/pub
  69. https://docs.google.com/document/d/e/2PACX-1vTdwTeXZjC0-0KuKqc4dGy2LNCfHdZJTdhWW7js3xNARlgqhPsGzVpVTDbBYZuOECWhLwtNcaK5Bgjg/pub
  70. https://docs.google.com/document/d/e/2PACX-1vTfWbKM0Gr5G5JoyriG-Tai4edW2fEn65BVXA6YBpBOGywFbrofnS89Lon560QQjLMYwzcHD8EHMhiS/pub
  71. https://docs.google.com/document/d/e/2PACX-1vTgoaRUlu5hwC3VV_TkvCY3PDTXZK6SCpEcN0a4A_Jh8qEHJLv2buEzVqrmI5U84CB84HA2Utyo1Hrv/pub
  72. https://docs.google.com/document/d/e/2PACX-1vTMHgXrSJmP1qJ4YW4fmX9Sg6jUFX5qWoit-aE7zhlvjMXPOxA2nPVqPovsrBKXCghiIal6EJFZCdTJ/pub
  73. https://docs.google.com/document/d/e/2PACX-1vTnSq5MELwYp_69PoxAR4psWSxl8bu3x-EeIqSPHN-td050hDiK6lzKmK81GmEMK1qlpZX669fQft9r/pub
  74. https://docs.google.com/document/d/e/2PACX-1vTQilJjiiGxbj8_Qx7gKEZCvjLSpPhji5zY37gx-v7dKUysLFr5seNBJ00esPQERqdvPQFGtHy04mqy/pub
  75. https://docs.google.com/document/d/e/2PACX-1vTqJ5B5kJShZ80bKc0d7WjxLI-lO3RlcQ4vn18ekvO3UXDIQiUnzXhYLos-cAl11MjytRdqf3CUUowz/pub
  76. https://docs.google.com/document/d/e/2PACX-1vTS8kb4TRgwFQa_O6ubOqKUMFb8X1ATh-jctAVnNs3iB3nbombZpMP2C-XwwmOdCGM6PNGZdGyIPJrC/pub
  77. https://docs.google.com/document/d/e/2PACX-1vTw2pixoeeYV_yFoC6HqMiiQCcOgkA0pvZTrB7pNtKcvZqIEzULX7ccOBYYYCGSsuy53BTzsDjiyBnJ/pub
  78. https://docs.google.com/document/d/e/2PACX-1vTyFK-2Iv00-di3B9wWFYirDnzHNrZJ5JEVZoU-l1MX9JVIh-Te5n-HppDvmQ9PhHACF7uxI8HwGnv3/pub
  79. https://docs.google.com/document/d/e/2PACX-1vTZmeyLUsy8osQ9PBTqXpflRIYikPzKv_VatQt3Ws1xXfnAF6Ms-9fIsPsZ7vhO1M2HNS-1clRBYW0Z/pub
  80.  
  81. MALDOC DISTRIBUTION URLS
  82. http://3.133.244.105/trustful.php
  83. http://www.nucala.inspia.net/antemeridian.php
  84. https://andrewsworld.com.ng/total.php
  85. https://andrewsworld.com.ng/weediness.php
  86. https://api.cdmvertical.com/cling.php
  87. https://ccucu.com/carry.php
  88. https://ccucu.com/refund.php
  89. https://itemp.ppdkuk.com/stipendless.php
  90. https://itemp.ppdkuk.com/unsurpassed.php
  91. https://mybrandedge.com/bridle.php
  92. https://mybrandedge.com/dyadic.php
  93. https://mybrandedge.com/scratchpad.php
  94. https://timberart.com.br/hi.php
  95. https://timberart.com.br/strobing.php
  96. https://www.databet96.com/tepidity.php
  97. https://www.databet96.com/tuneups.php
  98. https://www.educacionvirtualavanzada.mx/preserved.php
  99. https://www.educacionvirtualavanzada.mx/temblor.php
  100.  
  101. andrewsworld.com.ng
  102. ccucu.com
  103. cdmvertical.com
  104. databet96.com
  105. educacionvirtualavanzada.mx
  106. inspia.net
  107. mybrandedge.com
  108. ppdkuk.com
  109. timberart.com.br
  110.  
  111. HANCITOR MALDOC FILE HASHES
  112. 203f1d3cc82a33fec4b2d64f83ae35d0
  113. 6f252f2c05781517eccd105bb607d1c9
  114. 93aed6511cc8daa095cdb51bae6a51fc
  115. ae7a4b68f58ec19099534bc1286a134b
  116. bb515821e10c027d0d02f2df4a02cc4c
  117. f4f26b181cd17b5b26e3e84545d99393
  118. fa9578141e9f8826b79e638a8f721e64
  119.  
  120. HANCITOR PAYLOAD FILE HASH
  121. wermgr.dll
  122. 74c88ddb4f064d406adf21a4169880fd
  123.  
  124. HANCITOR C2
  125. http://varembacen.com/8/forum.php
  126. http://twomplon.ru/8/forum.php
  127. http://latiounitere.ru/8/forum.php
  128.  
  129. FICKER STEALER PAYLOAD URL
  130. http://derferper.ru/6ghikjmfghj.exe
  131.  
  132. FICKER STEALER FILE HASH
  133. 6ghikjmfghj.exe
  134. 77be0dd6570301acac3634801676b5d7
  135.  
  136. FICKER STEALER C2
  137. http://sweyblidian.com
Add Comment
Please, Sign In to add comment