Hancitor Malware Analizi

Dosya Ozellikleri

SHA256: 41e2e1899e11c4e9efbd7042989a3e5a5960faf205fa181a7486d350a277cc6c

MD5: ad5155b07bad3b1326cecce84afcd1f2

Dosya Tipi: docx

Boyut: 547,328 byte

Ilk Gorulme: 2021-10-19

AV Imzasi: Hancitor

Raporlayan: zbetcheckin

Etiketler: doc, docx, Hancitor

Statik analiz: metadata tabanli (ornek indirilmedi)

Hancitor — Malware Profile

Hancitor (Chanitor) email dropper. PuTTY SSH disguise. Cobalt Strike/Ficker dropper.

Malware Type
Loader
Programming Language
C
C2 Protocol
HTTP
Target Systems
Windows

Technical Details

Loader ailesi: HTTP/HTTPS C2, payload sifre cozme ve bellek icerisinde yükleme, anti-sandbox/VM kontrolleri, process injection, persistence mekanizmasi, yükü indirme ve calistirma zinciri

Capabilities & Behavior

Payload İndirme
Süreç Enjeksiyonu
Modüler Mimari
Kimlik Bilgisi Hırsızlığı
Yanal Hareket
Kalıcılık
Anti-VM/Sandbox
İkincil Payload Dağıtımı

IOC List (1 indicators)

IOC — Hancitor
# FILEPATH 41e2e1899e11c4e9efbd7042989a3e5a5960faf205fa181a7486d350a277cc6c
TypeValueNote
filepath 41e2e1899e11c4e9efbd7042989a3e5a5960faf205fa181a7486d350a277cc6c PDB

C2 Servers (1 recorded servers for this family)

Address Type Port Protocol Status Country
5.61.46.161 ip 80 HTTP sinkholed UA

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
docdocxHancitor