MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6f67beb15edea5f47a2ca655bca9a534e5944e3704a916a2b3d00ed7790e25f0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Hancitor


Vendor detections: 8


Maldoc score: 7


Intelligence 8 IOCs YARA 4 File information Comments 1

SHA256 hash: 6f67beb15edea5f47a2ca655bca9a534e5944e3704a916a2b3d00ed7790e25f0
SHA3-384 hash: ea46e7108578547813cfcb42d4ea975fdb7d38978a66afd459c2e3d45128bf68f084ccc778570d723280a5b9a67a45ae
SHA1 hash: de672dfb061f7f0d62940800f60ea963dc3cce3b
MD5 hash: df5926ad349dad39884d0a71f8c7318b
humanhash: summer-carolina-bakerloo-blue
File name:df5926ad349dad39884d0a71f8c7318b
Download: download sample
Signature Hancitor
File size:547'328 bytes
First seen:2021-10-19 18:20:16 UTC
Last seen:Never
File type:Word file docx
MIME type:application/msword
ssdeep 12288:o8CmEKY7gpWMB7goM6scG2u302l0HwbsG7kWunEDXm/zjHcB7:o8CmEj6B7pMDn2u3049HSn+Xm/E
TLSH T10AC40103B544CF53E00A8B78BEA2D9D53729FE05AF4AB3AB30147F5E3E796109C42695
Reporter zbetcheckin
Tags:doc docx Hancitor

Office OLE Information


This malware samples appears to be an Office document. The following table provides more information about this document using oletools and oledump.

OLE id
Maldoc score: 7
OLE dump

MalwareBazaar was able to identify 31 sections in this file using oledump:

Section IDSection sizeSection name
1114 bytesCompObj
2280 bytesDocumentSummaryInformation
3408 bytesSummaryInformation
413526 bytes1Table
5126580 bytesData
6569 bytesMacros/PROJECT
7152 bytesMacros/PROJECTwm
81883 bytesMacros/VBA/Module1
93086 bytesMacros/VBA/Module123345
103254 bytesMacros/VBA/Module2
112209 bytesMacros/VBA/Module3
126731 bytesMacros/VBA/ThisDocument
134500 bytesMacros/VBA/_VBA_PROJECT
143553 bytesMacros/VBA/__SRP_0
15416 bytesMacros/VBA/__SRP_1
162722 bytesMacros/VBA/__SRP_2
17388 bytesMacros/VBA/__SRP_3
18725 bytesMacros/VBA/__SRP_4
19360 bytesMacros/VBA/__SRP_5
20624 bytesMacros/VBA/__SRP_6
21392 bytesMacros/VBA/__SRP_7
22374 bytesMacros/VBA/__SRP_8
23236 bytesMacros/VBA/__SRP_9
24170 bytesMacros/VBA/__SRP_a
25170 bytesMacros/VBA/__SRP_b
26770 bytesMacros/VBA/dir
2776 bytesObjectPool/_1696132576/CompObj
28349987 bytesObjectPool/_1696132576/Ole10Native
294976 bytesObjectPool/_1696132576/EPRINT
306 bytesObjectPool/_1696132576/ObjInfo
314096 bytesWordDocument
OLE vba

MalwareBazaar was able to extract and deobfuscate VBA script(s) the following information from OLE objects embedded in this file using olevba:

TypeKeywordDescription
AutoExecDocument_OpenRuns when the Word or Publisher document is opened
SuspiciousOpenMay open a file
SuspiciousRunMay run an executable file or a system command
SuspiciousBase64 StringsBase64-encoded strings were detected, may be used to obfuscate strings (option --decode to see all)

Intelligence


File Origin
# of uploads :
1
# of downloads :
1'229
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malicious
File Type:
Legacy Word File with Macro
Document image
Document image
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
macros macros-on-open
Result
Threat name:
Hancitor
Detection:
malicious
Classification:
troj.expl.evad
Score:
100 / 100
Signature
Antivirus detection for URL or domain
Contains functionality to inject threads in other processes
Document contains an embedded VBA macro which may execute processes
Document contains an embedded VBA with functions possibly related to ADO stream file operations
Document contains encrypted data (likely password protected)
Document exploit detected (drops PE files)
Document exploit detected (process start blacklist hit)
May check the online IP address of the machine
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Office process drops PE file
Sigma detected: Microsoft Office Product Spawning Windows Shell
Sigma detected: Suspicious Splwow64 Without Params
System process connects to network (likely due to code injection or exploit)
Yara detected Hancitor
Behaviour
Behavior Graph:
Threat name:
Document-Word.Trojan.Valyria
Status:
Malicious
First seen:
2021-10-19 17:19:31 UTC
AV detection:
18 of 43 (41.86%)
Threat level:
  5/5
Result
Malware family:
hancitor
Score:
  10/10
Tags:
family:hancitor downloader macro macro_on_action suricata
Behaviour
Checks processor information in registry
Enumerates system info in registry
Modifies Internet Explorer settings
Modifies registry class
NTFS ADS
Suspicious behavior: AddClipboardFormatListener
Suspicious behavior: EnumeratesProcesses
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Office loads VBA resources, possible macro or embedded object present
Drops file in Windows directory
Looks up external IP address via web service
Loads dropped DLL
Blocklisted process makes network request
Hancitor
Process spawned unexpected child process
suricata: ET MALWARE Tordal/Hancitor/Chanitor Checkin
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:BitcoinAddress
Author:Didier Stevens (@DidierStevens)
Description:Contains a valid Bitcoin address
Rule name:hancitor_halo_generated
Author:Halogen Generated Rule, Corsin Camichel
Rule name:INDICATOR_OLE_ObjectPool_Embedded_Files
Author:ditekSHen
Description:Detects OLE documents with ObjectPool OLE storage and embed suspicous excutable files
Rule name:TA505_Maldoc_21Nov_2
Author:Arkbird_SOLG
Description:invitation (1).xls
Reference:https://twitter.com/58_158_177_102/status/1197432303057637377

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Hancitor

Word file docx 6f67beb15edea5f47a2ca655bca9a534e5944e3704a916a2b3d00ed7790e25f0

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
zbet commented on 2021-10-19 18:20:17 UTC

url : hxxps://gdpfjw.bn.files.1drv.com/y4mpO-jxyJEANxwU41aXz5IcEUnLdpbUffIqz-ehFAxZceuHFCrrzv4mg0iVhAx0WBY-CisKJB1j1D4fQ8yg2LBUw6xJYc7345J0xjr98StDixu7t_ZgkalSDx_AM_nJ9boQ-OrzfJT56fDZ3hMZFOyRc2f61CNThS4s9ZeUVZF6z5qj-97ctXOazs5fZ5ywUvC/1019_869601806433.doc?download&psid=1/