

Rewterz Threat Alert – Phobos Ransomware – Active IOC
August 31, 2022
Rewterz Threat Alert – Bitter APT Group Targeting China – Active IOCs
August 31, 2022
Rewterz Threat Alert – Phobos Ransomware – Active IOC
August 31, 2022
Rewterz Threat Alert – Bitter APT Group Targeting China – Active IOCs
August 31, 2022Severity
High
Analysis Summary
Hancitor was created in 2014 to drop other malware on infected machines. Also known as Tordal and Chanitor. Hancitor provides their loader as a service to other criminals, helping to install various malware on the target PCs. There is a sudden surge in Hancitor attacks and usually these attacks takes place on business days and falls off on the weekends.
This malware can’t be considered dangerous since even Microsoft’s built-in antivirus Windows Defender can detect it. Alot of it is being distributed in malspam campaigns, in a lot of cases emails don’t even reach their targets, being intercepted by spam filters. In essence, For users that are still using Windows seven or earlier and who either don’t have or disabled their antivirus software can still be targeted with more effectiveness. Despite such a limited “target audience”, Hancitor creators continue to update this malware and it is still very active to this day.
Impact
- Information Theft
- Data Exfiltration
Indicators of Compromise
MD5
- b107f3235057bb2b06283030be8f26e4
- 94f58df2de1da0743453600f0843cce5
SHA-256
- 5d077b1341a6472f02aac89488976d4395a91ae4f23657b0344da74f4a560c8d
- e5f54c095f81261c44445df3b4668ca01d2041c165abdd541ee3590d25fd5d11
SHA-1
- b12d2984830eee5ef668032cc13691706efce4a5
- 08074deaa6832a1d07b81c6d41532a94e277dd9b
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.
- Always be suspicious about emails sent by unknown senders.