MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee3f6c3fe59b1f5925699e91f49ea5439c0daae112173a303d2c25dd36a42b35. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Hancitor


Vendor detections: 3


Intelligence 3 IOCs YARA 2 File information Comments

SHA256 hash: ee3f6c3fe59b1f5925699e91f49ea5439c0daae112173a303d2c25dd36a42b35
SHA3-384 hash: fc1fa2c83ca3dfd41583e54599be18a2c9e0ac4da67e89581be4368b000b3984b5c9f29ffd1c03721564efa99ea6635c
SHA1 hash: 553a5cfa827df7424f7e760cb5bb2c695f78d036
MD5 hash: d70da1281e9c72b078638d0f1539f478
humanhash: robert-south-stream-ink
File name:ee3f6c3fe59b1f5925699e91f49ea5439c0daae112173a303d2c25dd36a42b35
Download: download sample
Signature Hancitor
File size:106'496 bytes
First seen:2020-03-23 15:58:10 UTC
Last seen:2020-03-23 16:17:33 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 030adec688438a988f1667738515503b (1 x Hancitor)
ssdeep 3072:dm69q1igSMg4cdt3WU2OMHc48HmsquUd:dnRfvBaZHr8Gs
Threatray 322 similar samples on MalwareBazaar
TLSH 20A3D34AFAA5554DF1720F36B47E4A023994EC52887982FED092518EDDEF1C4DA283F3
Reporter Marco_Ramilli
Tags:exe Hancitor

Intelligence


File Origin
# of uploads :
2
# of downloads :
639
Origin country :
n/a
Vendor Threat Intelligence

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:hancitor
Author:J from THL <j@techhelplist.com>
Description:Memory string yara for Hancitor
Rule name:win_hancitor_g2
Author:mak

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Hancitor

Executable exe ee3f6c3fe59b1f5925699e91f49ea5439c0daae112173a303d2c25dd36a42b35

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_AUTHENTICODEMissing Authenticodehigh
CHECK_NXMissing Non-Executable Memory Protectioncritical
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh
Reviews
IDCapabilitiesEvidence
WIN32_PROCESS_APICan Create Process and ThreadsKERNEL32.dll::CloseHandle
WIN_BASE_APIUses Win Base APIKERNEL32.dll::TerminateProcess
KERNEL32.dll::LoadLibraryW
KERNEL32.dll::GetStartupInfoW
KERNEL32.dll::GetCommandLineA
WIN_BASE_EXEC_APICan Execute other programsKERNEL32.dll::WinExec
KERNEL32.dll::WriteConsoleW
KERNEL32.dll::SetStdHandle
KERNEL32.dll::GetConsoleCP
KERNEL32.dll::GetConsoleMode
WIN_BASE_IO_APICan Create FilesKERNEL32.dll::CreateDirectoryA
KERNEL32.dll::CreateFileA
KERNEL32.dll::CreateFileW
KERNEL32.dll::GetWindowsDirectoryW

Comments