ExecuteMalware

2021-02-04 Hancitor IOCs

Feb 4th, 2021
4,585
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.67 KB | None | 0 0
  1. THREAT ATTRIBUTION: HANCITOR
  2.  
  3. SUBJECTS OBSERVED
  4. You got invoice from DocuSign Electronic Signature Service
  5. You got invoice from DocuSign Signature Service
  6. You got notification from DocuSign Electronic Service
  7. You got notification from DocuSign Service
  8. You received invoice from DocuSign Signature Service
  9. You received notification from DocuSign Electronic Service
  10.  
  11. SENDERS OBSERVED
  12.  
  13. MALDOC LANDING PAGES
  14. https://account.docusign.com/
  15. https://docs.google.com/document/d/e/2PACX-1vQ3IGdTBPs2GWdv8aZScT0Z7PJQqHzvW0nJalB-u3GpyG3MF9BlEgGRkWQAEeTF5AUPuYpHf_pEyVPq/pub
  16. https://docs.google.com/document/d/e/2PACX-1vQvUd98gU5vGjO1kyzhZDlcHCf1KUlU1JwgI8Anyf8GsUAqxmj6J8uFx-kf6iBm7u_zB9ubNpzX_gCE/pub
  17. https://docs.google.com/document/d/e/2PACX-1vQzKt_l7-LSHcWC8OC9zGYT941bcNe7EOR6EA2vCkCWHJYkF8FJMSANG2Zis2ccq9K6EqJeAgEoEOUn/pub
  18. https://docs.google.com/document/d/e/2PACX-1vRd7hWSHgjUyjqfG1dNs3dcqlQouGcFnplW0RqL8K15_H1UOeTOceVhbbueQE0qpQWYPKp5hYaDAFNT/pub
  19. https://docs.google.com/document/d/e/2PACX-1vSkC9oUqQhMFlhPl4XNNtLrO_fY0qqnGoVNl6HNWR2QL6RqWnj1WI8bVZrIA4uR1gmv6oja3nvMF8Wg/pub
  20. https://docs.google.com/document/d/e/2PACX-1vTc7J4DiZtHUdVN04v5zhvn-KMuACB7_l661DjP3ryxWgGzx4hX5ybfViNWphiOehzKh8216qW9uFBt/pub
  21. https://docs.google.com/document/d/e/2PACX-1vTxIMJSLl5grWsa6aTOQiCCVC-0GolUlzuDXNW90ZbSZ6IJvinjm32pxksT2vUY-HrseTi9uZ46T9jr/pub
  22. https://docs.google.com/document/d/e/2PACX-1vTZq3b0HQ6Jev2A6PMlPh8lCqCGXR0vVlu3VhaBs9-VxKI88cbpJE2Zwx5NscOVDKc6eqY_mGoODH60/pub
  23.  
  24. MALDOC DOWNLOAD URLS
  25. http://ajlpublicidade.pt/js/jquery/plugins/alerts/images/annexation.php
  26. http://cloud.gespont.com/resources/lib/jquery-fileupload/server/php/files/sledded.php
  27. http://cloud.gespont.com/resources/lib/jquery-fileupload/server/php/files/surfacing.php
  28. https://www.hellosiroco.com/wp-content/themes/wp_haswell/woocommerce/cart/pedaling.php
  29. https://www.hellosiroco.com/wp-content/themes/wp_haswell/woocommerce/cart/sliver.php
  30.  
  31. ajlpublicidade.pt
  32. cloud.gespont.com
  33. hellosiroco.com
  34.  
  35. MALDOC FILE HASHES
  36. 294b4ac93a807892db834cc9387ac6c2
  37. 375eb549703158b147124c9dcce2b085
  38. 49219ec467e5b3bafc1d067344c27e39
  39. 53ef9b55dfd6d7148206cc424413d52a
  40.  
  41. HANCITOR PAYLOAD FILE HASHES
  42. W0rd.dll
  43. 884d2601e6377691200e7d6eac67d0e7
  44.  
  45. HANCITOR C2
  46. http://feirecropl.com/8/forum.php
  47. http://oresteseu.ru/8/forum.php
  48.  
  49. FICKER STEALER
  50. http://sungardspo.com/6lhjgfdghj.exe
  51.  
  52. FICKER STEALER FILE HASHES
  53. 6lhjgfdghj.exe
  54. 77be0dd6570301acac3634801676b5d7
  55.  
  56. FICKER STEALER C2
  57. http://sweyblidian.com
  58. http://185.100.65.29
Advertisement
Add Comment
Please, Sign In to add comment