ExecuteMalware

2021-06-08 Hancitor IOCs

Jun 8th, 2021 (edited)
16,522
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.97 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. HANCITOR BUILD NUMBER
  4. BUILD=0806_2xvek
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Service
  8. You got invoice from DocuSign Electronic Signature Service
  9. You got invoice from DocuSign Service
  10. You got invoice from DocuSign Signature Service
  11. You got notification from DocuSign Electronic Service
  12. You got notification from DocuSign Electronic Signature Service
  13. You got notification from DocuSign Service
  14. You got notification from DocuSign Signature Service
  15. You received invoice from DocuSign Electronic Service
  16. You received invoice from DocuSign Electronic Signature Service
  17. You received invoice from DocuSign Service
  18. You received invoice from DocuSign Signature Service
  19. You received notification from DocuSign Electronic Service
  20. You received notification from DocuSign Electronic Signature Service
  21. You received notification from DocuSign Service
  22. You received notification from DocuSign Signature Service
  23.  
  24. SENDERS OBSERVED
  25.  
  26. MALDOC PROXY DISTRIBUTION URLS
  27. http://feedproxy.google.com/~r/achcrza/~3/vsl1LsuuwYA/darken.php
  28. http://feedproxy.google.com/~r/anykj/~3/TtCuarFO3Ds/tatter.php
  29. http://feedproxy.google.com/~r/aqdlsxol/~3/i9CvYQQ7zGQ/estranging.php
  30. http://feedproxy.google.com/~r/boidwe/~3/4hpodogJaT4/force.php
  31. http://feedproxy.google.com/~r/bpwmm/~3/lwpJRQb0LfA/plummet.php
  32. http://feedproxy.google.com/~r/bszjuxh/~3/49chtVhTeR8/diatribe.php
  33. http://feedproxy.google.com/~r/ctfodopaelb/~3/W%0D%0APc0qFiG3Ro/student.php
  34. http://feedproxy.google.com/~r/ctfodopaelb/~3/WPc0qFiG3Ro/student.php
  35. http://feedproxy.google.com/~r/dmnvpsdsrcm/~3/ip55LftUb-c/stipendless.php
  36. http://feedproxy.google.com/~r/dykmmccfm/~3/3bhzQ9CeB9E/penumbrae.php
  37. http://feedproxy.google.com/~r/eazkshoj/~3/FjbKYTWmU3U/ford.php
  38. http://feedproxy.google.com/~r/embbmyfp/~3/T1YlRciflm4/microfolio.php
  39. http://feedproxy.google.com/~r/eomwtapws/~3/FLb6zOmkKB0/tyke.php
  40. http://feedproxy.google.com/~r/erotiamcikz/~3/-kacmPWUhrw/cordless.php
  41. http://feedproxy.google.com/~r/extgsczxld/~3/sp1rYo7QdEs/brunet.php
  42. http://feedproxy.google.com/~r/fiajajfjuvz/~3/PD04KvgN69g/unilateral.php
  43. http://feedproxy.google.com/~r/fnnhtbcuohp/~3/ip55LftUb-c/stipendless.php
  44. http://feedproxy.google.com/~r/fticgofqi/~3/6Jc-g0FC5FA/funded.php
  45. http://feedproxy.google.com/~r/hanczahtwz/~3/54Py-AQlr_U/policing.php
  46. http://feedproxy.google.com/~r/hdidktlz/~3/54Py-AQlr_U/policing.php
  47. http://feedproxy.google.com/~r/hicvurye/~3/JPnGTxfhdYI/compactor.php
  48. http://feedproxy.google.com/~r/htkdo/~3/T1YlRciflm4/microfolio.php
  49. http://feedproxy.google.com/~r/ioolxrj/~3/Pd4R3-7pexk/bilevel.php
  50. http://feedproxy.google.com/~r/jlspyibxi/~3/RfMxCuN6LbM/kabul.php
  51. http://feedproxy.google.com/~r/juaomjjwfsw/~3/Wbmifp8uwMQ/constituency.php
  52. http://feedproxy.google.com/~r/kysxsen/~3/LTllAGfdybU/cape.php
  53. http://feedproxy.google.com/~r/lqmqpby/~3/vhmFFu2ZGkI/aha.php
  54. http://feedproxy.google.com/~r/nvptp/~3/mZwlgmPteDI/institutional.php
  55. http://feedproxy.google.com/~r/ocidtmwpvnv/~3/mwnvAT_VbCo/unamendable.php
  56. http://feedproxy.google.com/~r/oxbuwtnnmo/~3/QpuFCYG4geQ/barbarian.php
  57. http://feedproxy.google.com/~r/pdagfrdbh/~3/WF4wEqs6DjQ/shapelessness.php
  58. http://feedproxy.google.com/~r/qpzwmtlg/~3/pdqaQGdtFEs/bakelite.php
  59. http://feedproxy.google.com/~r/sldial/~3/dMfkUQuSTjQ/mph.php
  60. http://feedproxy.google.com/~r/smhdeqaizot/~3/bx6FjykFngY/simultaneity.php
  61. http://feedproxy.google.com/~r/spyzajnwrbl/~3/vhmFFu2ZGkI/aha.php
  62. http://feedproxy.google.com/~r/txmsbpjlvdx/~3/tSIZWTkjucc/donate.php
  63. http://feedproxy.google.com/~r/umegqguz/~3/GwzempQ-BE0/vehemence.php
  64. http://feedproxy.google.com/~r/vbgzo/~3/nPtUeQZykwc/hare.php
  65. http://feedproxy.google.com/~r/vbhezbyhu/~3/4hpodogJaT4/force.php
  66. http://feedproxy.google.com/~r/vkougrmv/~3/nzgfpFP8aBs/sitcom.php
  67. http://feedproxy.google.com/~r/vlbguhxhbw/~3/GV6UvQgYito/virtuous.php
  68. http://feedproxy.google.com/~r/whcxyd/~3/rC0CDHGpEdI/gelatinous.php
  69. http://feedproxy.google.com/~r/wnqutol/~3/-iCqgSSdsMU/hoopoe.php
  70. http://feedproxy.google.com/~r/wqbzrmqqpyx/~3/ziUb07b6GGs/chlorination.php
  71. http://feedproxy.google.com/~r/wvnijwiupbs/~3/BOHXg60nd5k/proadvisor.php
  72. http://feedproxy.google.com/~r/wzjya/~3/vhmFFu2ZGkI/aha.php
  73. http://feedproxy.google.com/~r/xgtsn/~3/dCufOc1AWCM/pictorial.php
  74. http://feedproxy.google.com/~r/yrhisgkqcun/~3/O06L2ZfwnVk/imperialist.php
  75. http://feedproxy.google.com/~r/yuvhi/~3/tL5m0astNEk/day.php
  76.  
  77. MALDOC REDIRECT DOWNLOAD URLS
  78. https://airpaviliontours.com/virtuous.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+vlbguhxhbw+%28seimanetcetera%29
  79. https://assistenciadeaquecedores.com/constituency.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+juaomjjwfsw+%28diversitybouillon%29
  80. https://assistenciadeaquecedores.com/day.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+yuvhi+%28underchargeafterburner%29
  81. https://assistenciadeaquecedores.com/kabul.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+jlspyibxi+%28goshferrite%29
  82. https://assistenciadeaquecedores.com/simultaneity.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+smhdeqaizot+%28unbelovedexorcize%29
  83. https://csakcserep.hu/imperialist.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+yrhisgkqcun+%28mannedrepellent%29
  84. https://dev-wbs1.pantheonsite.io/force.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+vbhezbyhu+%28appraisementbe%29
  85. https://panel.ppsa.in/darken.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+achcrza+%28phosphatecentime%29
  86. https://piemontesasaffitti.e-bill.it/institutional.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+nvptp+%28ventilatorsenseless%29
  87. https://pos.nittosupport.ca/mph.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+sldial+%28ripenesssloppily%29
  88. https://thiagoribeirokungfu.com/unamendable.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+ocidtmwpvnv+%28sedimentchaste%29
  89. https://www.porvootransitioncare.com/tatter.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+anykj+%28squawkabhorrer%29
  90. https://www.shiksharatna.com/policing.php?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+hanczahtwz+%28euphoniousbear%29
  91.  
  92. airpaviliontours.com
  93. assistenciadeaquecedores.com
  94. csakcserep.hu
  95. e-bill.it
  96. nittosupport.ca
  97. pantheonsite.io
  98. porvootransitioncare.com
  99. ppsa.in
  100. shiksharatna.com
  101. thiagoribeirokungfu.com
  102.  
  103. HANCITOR MALDOC FILE HASHES
  104. 02c4f753108081c7f52389a45a7f228d
  105. 68c9ced15e2b7bcc4b7ad7bb5462afa2
  106. 737925a806043690bb4245a4897dbc84
  107. 8f16fed4d428ae25781ea82a05c55c30
  108. a031e7e304561145c6c20f924d3f107b
  109. a34aee2dba01707667d2a3a06066c7de
  110.  
  111. HANCITOR PAYLOAD FILE HASH
  112. omsh.dll
  113. cdee38da67289ef49f9d0c64a14fb22a
  114.  
  115. HANCITOR C2
  116. http://aniumbougual.ru/8/forum.php
  117. http://cogymbealpar.ru/8/forum.php
  118. http://threcenvionsh.com/8/forum.php
  119.  
  120.  
  121.  
  122.  
Add Comment
Please, Sign In to add comment