ATT&CKReferencesFireEye Hancitor

FireEye Hancitor

Anubhav, A., Jallepalli, D. (2016, September 23). Hancitor (AKA Chanitor) observed using multiple attack approaches. Retrieved August 13, 2020.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1027.015
Compression
MalwareHancitor

Hancitor has delivered compressed payloads in ZIP files to victims.

T1059.001
PowerShell
MalwareHancitor

Hancitor has used PowerShell to execute commands.

T1070.004
File Deletion
MalwareHancitor

Hancitor has deleted files using the VBA kill function.

T1106
Native API
MalwareHancitor

Hancitor has used CallWindowProc and EnumResourceTypesA to interpret and execute shellcode.

T1140
Deobfuscate/Decode Files or Information
MalwareHancitor

Hancitor has decoded Base64 encoded URLs to insert a recipient’s name into the filename of the Word document. Hancitor has also extracted executables from ZIP files.

T1204.002
Malicious File
MalwareHancitor

Hancitor has used malicious Microsoft Word documents, sent via email, which prompted the victim to enable macros.

T1497
Virtualization/Sandbox Evasion
MalwareHancitor

Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads.

T1547.001
Registry Run Keys / Startup Folder
MalwareHancitor

Hancitor has added Registry Run keys to establish persistence.

T1566.001
Spearphishing Attachment
MalwareHancitor

Hancitor has been delivered via phishing emails with malicious attachments.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.