Trojan

Win32/TrojanDownloader.Hancitor.B information

Malware Removal

The Win32/TrojanDownloader.Hancitor.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrojanDownloader.Hancitor.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Win32/TrojanDownloader.Hancitor.B?


File Info:

name: 3A34533A28971D15F6EB.mlw
path: /opt/CAPEv2/storage/binaries/f95f9fb0548c8265dc9d2f4013d847ad0010016a6de706ea192b04bbbd7680f8
crc32: 2CA1EC8B
md5: 3a34533a28971d15f6eb71072415bf53
sha1: eac40b92e80c3aef54abe13a17c6997f3ece9e47
sha256: f95f9fb0548c8265dc9d2f4013d847ad0010016a6de706ea192b04bbbd7680f8
sha512: c775ee6799ac4db66be25c4f69c8da19abdc1d7326e59ca7002006a35e71035f0752da2efefb2c8e073e07d462ae810e7cda78a2296f00d2c5d280ee02a1cefd
ssdeep: 1536:M7LtT8pKSMRUkOznzPXkzihQgmZky9Jb8zjil6B0DVfBI5gY6DsyyEWyn3N/:MGpSRgdhFmJfbejiO0DwUPKynl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191D37D50FF508771C052867044A2BB60CA69AFE056644D6FF7BC3E5A6FB06C23AE1357
sha3_384: 2cd0db7b05b1dac064021c873d3b90532a375e17cb46971115ec7966bda89e22631408e0fda4cdd56cc07b09ebb5cb69
ep_bytes: e87b270000e989feffffc701d4c14000
timestamp: 2015-03-04 15:08:06

Version Info:

0: [No Data]

Win32/TrojanDownloader.Hancitor.B also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Yakes.4!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.3a34533a28971d15
CAT-QuickHealTrojan.Generic.B4
McAfeeGeneric-FAWE!3A34533A2897
CylanceUnsafe
ZillyaTrojan.Yakes.Win32.30701
SangforTrojan.Win32.Yakes.jupg
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
K7GWTrojan-Downloader ( 0055e3da1 )
CrowdStrikewin/malicious_confidence_100% (D)
VirITTrojan.Win32.Generic.LTR
CyrenW32/Trojan.XXRB-7533
SymantecW32.Extrat
ESET-NOD32Win32/TrojanDownloader.Hancitor.B
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Yakes.jupg
NANO-AntivirusTrojan.Win32.Yakes.dossiv
AvastWin32:GenMalicious-IXF [Trj]
TencentWin32.Trojan.Yakes.Ljua
ComodoMalware@#2m0ax22qxjvnj
DrWebTrojan.Siggen6.23859
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_HANCITOR.VVQD
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
IkarusTrojan.Win32.CoinMiner
JiangminTrojan/Yakes.sjz
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1213655
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.EA3FEC
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotTrojan.Win32.Agent.131584.U
MicrosoftVirTool:Win32/Injector.GE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Chanitor.R136245
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.iuW@aawk6Eai
VBA32BScope.Malware-Cryptor.Tinba
TrendMicro-HouseCallTROJ_HANCITOR.VVQD
RisingDownloader.Hancitor!8.A19 (CLOUD)
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Kryptik.DDLY!tr
AVGWin32:GenMalicious-IXF [Trj]
Cybereasonmalicious.a28971
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.300983.susgen

How to remove Win32/TrojanDownloader.Hancitor.B?

Win32/TrojanDownloader.Hancitor.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment