Hancitor Malware Analizi

Dosya Ozellikleri

SHA256: aad9ff8bf349da1e222d11a78c6284541999b73d80d3f7e09778e6cae4ff81a1

MD5: f8d2e89830798e79dc2f5ab6996a4cf6

Dosya Tipi: dll

Boyut: 745,472 byte

Ilk Gorulme: 2021-04-28

AV Imzasi: Hancitor

Imphash: c2f48b2179c91b4a60f8506722ec57ef

Raporlayan: James_inthe_box

Etiketler: dll, Hancitor

Statik analiz: metadata tabanli (ornek indirilmedi)

Hancitor — Malware Profile

Hancitor (Chanitor) email dropper. PuTTY SSH disguise. Cobalt Strike/Ficker dropper.

Malware Type
Loader
Programming Language
C
C2 Protocol
HTTP
Target Systems
Windows

Technical Details

Loader ailesi: HTTP/HTTPS C2, payload sifre cozme ve bellek icerisinde yükleme, anti-sandbox/VM kontrolleri, process injection, persistence mekanizmasi, yükü indirme ve calistirma zinciri

Capabilities & Behavior

Payload İndirme
Süreç Enjeksiyonu
Modüler Mimari
Kimlik Bilgisi Hırsızlığı
Yanal Hareket
Kalıcılık
Anti-VM/Sandbox
İkincil Payload Dağıtımı

IOC List (1 indicators)

IOC — Hancitor
# FILEPATH aad9ff8bf349da1e222d11a78c6284541999b73d80d3f7e09778e6cae4ff81a1
TypeValueNote
filepath aad9ff8bf349da1e222d11a78c6284541999b73d80d3f7e09778e6cae4ff81a1 PDB

C2 Servers (1 recorded servers for this family)

Address Type Port Protocol Status Country
5.61.46.161 ip 80 HTTP sinkholed UA

C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.

Tags
dllHancitor