Hancitor

S0499

Malware.View on attack.mitre.org

About this malware

Hancitor is a downloader that has been used by Pony and other information stealing malware.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1027
Obfuscated Files or Information

Hancitor has used Base64 to encode malicious links.

T1027.015
Compression

Hancitor has delivered compressed payloads in ZIP files to victims.

T1059.001
PowerShell

Hancitor has used PowerShell to execute commands.

T1070.004
File Deletion

Hancitor has deleted files using the VBA kill function.

T1105
Ingress Tool Transfer

Hancitor has the ability to download additional files from C2.

T1106
Native API

Hancitor has used CallWindowProc and EnumResourceTypesA to interpret and execute shellcode.

T1140
Deobfuscate/Decode Files or Information

Hancitor has decoded Base64 encoded URLs to insert a recipient’s name into the filename of the Word document. Hancitor has also extracted executables from ZIP files.

T1204.001
Malicious Link

Hancitor has relied upon users clicking on a malicious link delivered through phishing.

T1204.002
Malicious File

Hancitor has used malicious Microsoft Word documents, sent via email, which prompted the victim to enable macros.

T1218.012
Verclsid

Hancitor has used verclsid.exe to download and execute a malicious script.

T1497
Virtualization/Sandbox Evasion

Hancitor has used a macro to check that an ActiveDocument shape object in the lure message is present. If this object is not found, the macro will exit without downloading additional payloads.

T1547.001
Registry Run Keys / Startup Folder

Hancitor has added Registry Run keys to establish persistence.

T1566.001
Spearphishing Attachment

Hancitor has been delivered via phishing emails with malicious attachments.

T1566.002
Spearphishing Link

Hancitor has been delivered via phishing emails which contained malicious links.

Groups that use it0

None recorded.

Campaigns0

None recorded.

References2

  1. FireEye Hancitor Open source
    Anubhav, A., Jallepalli, D. (2016, September 23). Hancitor (AKA Chanitor) observed using multiple attack approaches. Retrieved August 13, 2020.
  2. Threatpost Hancitor Open source
    Tom Spring. (2017, January 11). Spammers Revive Hancitor Downloader Campaigns. Retrieved August 13, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.