Malware Signature
The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with Hancitor
Database Entry
Malware: | Hancitor |
---|---|
First seen: | 2016-08-18 08:59:20 UTC |
Last seen: | 2018-10-18 05:31:06 UTC |
Malware Samples
The table below documents all malware samples associated with this malware family.
Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
---|---|---|---|---|
2018-10-18 05:31:06 | 8359e029989b712bfd33b6b82d36ab46 | 17/56 (30.36%) | Hancitor | 193.183.98.122:443 |
2018-10-18 05:31:06 | 8359e029989b712bfd33b6b82d36ab46 | 17/56 (30.36%) | Hancitor | 193.183.98.122:443 |
2018-09-12 04:51:00 | a1ac08123d98990c905e2608ce25d5e6 | 24/67 (35.82%) | Hancitor | 89.223.94.240:443 |
2018-09-12 04:51:00 | a1ac08123d98990c905e2608ce25d5e6 | 24/67 (35.82%) | Hancitor | 89.223.94.240:443 |
2018-08-22 17:00:11 | 46df3b0ed4eef0de5552a6c509492e0d | 23/59 (38.98%) | Hancitor | 91.217.90.133:443 |
2018-08-22 17:00:11 | 46df3b0ed4eef0de5552a6c509492e0d | 23/59 (38.98%) | Hancitor | 91.217.90.133:443 |
2017-10-27 11:21:58 | 1621f341e058349973f8d71a3242dd9a | 16/59 (27.12%) | Hancitor | 164.132.28.118:443 |
2017-10-27 11:21:58 | 1621f341e058349973f8d71a3242dd9a | 16/59 (27.12%) | Hancitor | 164.132.28.118:443 |
2016-11-16 19:23:20 | ddef86a97d892abbdc0f61407ec769fe | 21/56 (37.50%) | Hancitor | 137.74.194.227:443 |
2016-11-16 19:23:20 | ddef86a97d892abbdc0f61407ec769fe | 21/56 (37.50%) | Hancitor | 82.146.32.87:443 |
2016-11-16 19:23:20 | ddef86a97d892abbdc0f61407ec769fe | 21/56 (37.50%) | Hancitor | 137.74.194.227:443 |
2016-11-16 19:23:20 | ddef86a97d892abbdc0f61407ec769fe | 21/56 (37.50%) | Hancitor | 82.146.32.87:443 |
2016-10-13 06:42:05 | ef26e4c1eb933fac780dd6e337ee6f4c | n/a | Hancitor | 78.155.217.154:443 |
2016-10-13 06:42:05 | ef26e4c1eb933fac780dd6e337ee6f4c | n/a | Hancitor | 78.155.217.154:443 |
2016-10-12 18:26:05 | b37da106cbe73a4450dc28786f7da27f | 40/57 (70.18%) | Hancitor | 31.184.233.105:443 |
2016-10-12 18:26:05 | b37da106cbe73a4450dc28786f7da27f | 40/57 (70.18%) | Hancitor | 78.155.217.154:443 |
2016-10-12 18:26:05 | b37da106cbe73a4450dc28786f7da27f | 40/57 (70.18%) | Hancitor | 31.184.233.105:443 |
2016-10-12 18:26:05 | b37da106cbe73a4450dc28786f7da27f | 40/57 (70.18%) | Hancitor | 78.155.217.154:443 |
2016-10-11 20:56:55 | 1d5040d5cf56bdfa46987a6736586515 | 32/56 (57.14%) | Hancitor | 91.220.131.174:50007 |
2016-10-11 20:56:55 | 1d5040d5cf56bdfa46987a6736586515 | 32/56 (57.14%) | Hancitor | 91.220.131.174:50007 |
2016-09-27 18:03:59 | cebd26c28f001e8931fa494723d7844a | 35/57 (61.40%) | Hancitor | 185.22.65.47:443 |
2016-09-27 18:03:59 | cebd26c28f001e8931fa494723d7844a | 35/57 (61.40%) | Hancitor | 85.17.82.104:443 |
2016-09-27 18:03:59 | cebd26c28f001e8931fa494723d7844a | 35/57 (61.40%) | Hancitor | 185.22.65.47:443 |
2016-09-27 18:03:59 | cebd26c28f001e8931fa494723d7844a | 35/57 (61.40%) | Hancitor | 85.17.82.104:443 |
2016-08-29 15:47:05 | cc05867751b1de3cab89c046210faed4 | 33/56 (58.93%) | Hancitor | 185.22.65.47:443 |
2016-08-29 15:47:05 | cc05867751b1de3cab89c046210faed4 | 33/56 (58.93%) | Hancitor | 185.22.65.47:443 |
2016-08-21 09:14:15 | 8be0ca71efa2ba3d3fb2acebcc88e5e7 | 33/56 (58.93%) | Hancitor | 185.22.65.47:443 |
2016-08-21 09:14:15 | 8be0ca71efa2ba3d3fb2acebcc88e5e7 | 33/56 (58.93%) | Hancitor | 185.22.65.47:443 |
2016-08-18 08:59:20 | 5c0d870c2d427806691fc773a2b5942c | 31/56 (55.36%) | Hancitor | 185.46.8.214:443 |
2016-08-18 08:59:20 | 5c0d870c2d427806691fc773a2b5942c | 31/56 (55.36%) | Hancitor | 185.46.8.214:443 |