Trojan:Win32/Hancitor.BK!MTB information

Malware Removal

The Trojan:Win32/Hancitor.BK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware - Review 2020

GridinSoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend to use GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the TRIAL period.
6-day free trial available.

What Trojan:Win32/Hancitor.BK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Uae)
  • Looks up the external IP address
  • Behavior consistent with a dropper attempting to download the next stage.
  • A process sent information about the computer to a remote location.
  • Anomalous binary characteristics

Related domains:

api.ipify.org
calloyean.ru
fulgeterly.ru
goramilly.ru

How to determine Trojan:Win32/Hancitor.BK!MTB?


File Info:

crc32: A84BCB60
md5: 93550847b83aa1c0d367a60ed4de0e4c
name: 93550847B83AA1C0D367A60ED4DE0E4C.mlw
sha1: d4c510130cc831c393e0e50c22c9e3d353cf6f5e
sha256: 84e01014a04b8896a4bcf0e8d72cbe180e5e0c9c6eb1fc7f4bfcc87f027f96e3
sha512: 6db61b8b26be1c6ff743e2f09edffa24fd1ac1b2cd6eb24dc39fb63f0f6cd3af0b66df8133f39b379babbdab94930f7f4a3a825c3fa94416537a3bedbeef18ca
ssdeep: 12288:JsIu1b7w8b70eMaOuiAXtaD2gjN0SVVVVwDnqF:0ZDb7Ea5/tahq9n
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Hancitor.BK!MTB also known as:

Elasticmalicious (high confidence)
MalwarebytesMalware.AI.3848947555
CrowdStrikewin/malicious_confidence_90% (W)
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
SophosMal/EncPk-APY
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.93550847b83aa1c0
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Hancitor.BK!MTB
McAfeeArtemis!93550847B83A
VBA32BScope.Trojan.Hancitor
RisingTrojan.Generic@ML.87 (RDML:iHbas+SxlwtPvWJNlOIOFw)
MaxSecureTrojan.Malware.300983.susgen
Paloaltogeneric.ml

How to remove Trojan:Win32/Hancitor.BK!MTB?

Trojan:Win32/Hancitor.BK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

Leave a Comment