jeudi 16 mars 2017

Hancitor panel overview


These weeks I've read a lot of tweets about hancitor. Hancitor is even in the CheckPoint "top 5 Most Wanted malware" (¯\_(ツ)_/¯).
You can read a lot of good stuff about the Hancitor/Fareit/Vawtrack/H1N1 gang, binaries reverse, proxy infra... but nothing about Hancitor web panels. So, I've write this (very) quick blogpost to show the attacker point of view :]

Since admin has activated White-listing, it seems that it's not possible to access to the web panel via the Nginx Proxy. When you try to access to a page admin.php or panel.php etc, proxy returns a 403 error. For accessing the panel, you have to find the real IP behind proxies.

Before the white-listing system, it was possible to access to Hancitor CNC due to a lot of vulns. Because these vuln are patched today, it's time to disclose some stuff. Let's have a look at this dropper C&C.

Bypassing authentication

When you want to access to a page, the panel developer checks if the user is authenticated with this kind of code:
This is an old school kind of vulnerability \o/. They don't use an "exit()" after the header function.
When you browse the page with a browser like Firefox, you are correctly redirected to, however if you grab the page with CURL or WGET the header function is ignored and... all the PHP code is executed :).

Here we go, the panel is composed of 4 parts:


This is the main page, with some data about infected hosts.


This page is used for sending commands to the bots. You can send commands to a specific group of bots or to a specific location.
The available commands are:
  • Download and Run
  • BOT Start
  • DLL Load
  • EXE Load
  • Uninstall
  • Load Config
  • Update
Two interesting facts: There is an "uninstall" command and if you send the correct POST request to the page commands.php, without authent', it works :)


This page is used for the password stealer module. I've never seen this feature used. It's maybe due to the fact that this gang use Fareit for stealing passwords...


And finally the statistics page, you can found online/Online in the last 12 hours/offline and create a new group of bots.
Thanks to a SQLi we can see that the database structure is:

As you can see, this super evil malware has a very basic CNC.
Some articles about this threat:
I hope that this quick post can be useful for somebody

37 commentaires:

  1. Пишиесчо!(#writemoreplz)

  2. HP OfficeJet 8702 All-in-One HP OfficeJet 8702 Wireless Printer Setup All-in-One Series Full Feature Software and Drivers Details The full setup+ programming.

  3. I'm unexpirienced in this topic, but I hope to become more prudent regarding your blog.
    Logo Esport Maker

  4. Great Content. Read Here Why nobody care about health. and more intersting topics.Read Here

  5. Allegiant Airlines Reservations A good Blog gives a lot more knowledge about this. I will continue to support your work Thank you.

  6. Lufthansa Reservations Much obliged for the pleasant blog. It was exceptionally valuable for me. I'm cheerful I discovered this blog. Much obliged to you for imparting to us, I also consistently discover some new information from your post.

  7. HP 2540 PRINTER SETUP. When you face HP Deskjet 2540 printer network issue you can follow the below steps to Quick Steps for HP Deskjet 2540 Troubleshooting.

  8. Awesome post! Acadecraft has a team of video designers and editors who work along with Subject Matter Experts to design interactive and enriching videos to impart knowledge to the students by creating professional video lectures.
    best video lectures company
    video subtitling services

  9. Nembutal Pentobarbital sodium is a short-acting barbiturate, chemically designated as sodium 5-ethyl-5-(1-methyl butyl) barbiturate. This is one of the reasons for being more suitable for suicide than longer-acting barbiturates such as phenobarbital. Nembutal is a proven, reliable drug that brings about a peaceful death. Almost no failures are known, despite large statistics (for example, the Swiss euthanasia organization Dignitas reported 840 exits with no single failure). 

    There are however reports on seemingly slow or painful deaths with Nembutal in capital punishment, although this may be due to the poor quality of the drug from compounding pharmacies given intravenously rather than orally.  Nembutal Pentobarbital sodium is sold most of the time in liquid form for use as a sedative and anesthetic in hospitals.

    Buy Nembutal Online.
    Email: keys2pharm(@) tutanota (.)com or
    Email: keys2pharm (at) Protonmail (.) com
    for any inquiries

    Veterinary Nembutal is a liquid and not in pill form, which means that it has a shorter shelf life. On the other hand, Seconal (secobarbital), a short-acting barbiturate that is as powerful as Nembutal if not more powerful, is still available in capsule form in the USA, EUROPE, and probably the UK. Nembutal pills have a bitter taste that requires the use of antiemetics to prevent vomiting when given orally at high dosages.  It is easy from today form today to obtain vials of Nembutal Sodium Solution (pentobarbital sodium injection), a sterile solution for intravenous or intramuscular injection, typically used for animal anesthesia or euthanasia. Each mL contains pentobarbital sodium 50 mg,100 mg, or 250 mg (lethal dose) in a vehicle of approximately propylene glycol, 40%, alcohol, 10%, and water for injection, to volume. The pH is adjusted to approximately 9.5 with hydrochloric acid and/or sodium hydroxide. The range of actual pentobarbital sodium in a vial may vary between 3 g to 15 g, although 6 g seems common. The containers come in a clear vial typical for sterile solutions and should have an untouched protective metal cap if unopened, and be labeled clearly with a due date.

    Buy Nembutal Online.
    Email: keys2pharm(@) tutanota (.)com or
    Email: keys2pharm (at) Protonmail (.) com
    for any inquiries

     The Nembutal solution may be taken intravenously, for very quick effect as in capital punishment, or orally. Nembutal Pentobarbital sodium, unlike other lethal drugs, may not require any additional drugs. Only antiemetic drugs must be taken in advance, in order to prevent any vomiting from occurring. This has been partially endorsed by experts in the administration of the death penalty, whereby a pure barbiturate method has been deemed less painful and more successful than prior 3-drug approaches and newer concoctions involving e.g. Midazolam (in the traditional 3-drug approach, a barbiturate was one of the components). There have, however, been reports of less successful attempts, the cause of which has been debated. The use of pentobarbital-only has also been called into question by some experts on capital punishment We make sure that we maintain the quality and purity required so that we can meet your demand.

      That is why we ship our Nembutal from the source.  We keep this quality while selling Nembutal to you at fair and reasonable prices. Lastly, we offer delivery in the US, EU, Australia, Korea, and more securely no custom issues as we package discreetly. We make sure that delivery is fast which makes it convenient for you.  It also saves you the shipping costs, which reduces your budget for Nembutal.  Buy Nembutal Online.
    Email: keys2pharm(@) tutanota (.)com or
    Email: keys2pharm (at) Protonmail (.) com
    for any inquiries


  10. We sell discreetly and do stealth shipments to customers with no package sign-off upon delivery

    Our services…
* Good and #Affordable prices.
    * Fast and Stealth delivery - #Tracking Available!
    * Various Discreet Shipping option (Overnight and Normal Plan ).
    * No Prescription Required ( No Rx )
    * Offers Reshipment if the package does not get to location or refunds

    Contact us Securely : keys2inquiries {at }gmail (.)com |
    - Wickr: { keys2pharm }

Cryptocurrency PAYMENTS only

    - Ambien 10mg,
    legit liquid Ketamine sellers
    Student Use adderall ,

    - Dilaudid 8mg,
    - Fentanyl Patches 100mcg,
    - buy hydrocodone online ,
    - Methadone 10mg,
    - buy Morphine online,
    - Opana ER 40mg,
    - Oxycotin 80 mg,
    - Percocet 5/325mg, 10/325mg ,7.5/325mg,
    - Ritalin 10mg,
    - buy Super Meth online ,
    - Roxicodone 30mg,
    - Vyvanse 50, 70mg,
    - Alprazolam 2mg / Green Bars / Green hulk bars/ S 90 3 bars,
    - MDMD capsules 180mg pure

    Contact us Securely : keys2inquiries {at }gmail (.)com |

  11. Very informative blog, and beautifully elaborating the complete information about the topic. We are from the same domain emerging as the top mobile app development company for versatile app creation services. You can email us at or Phone Number: +91-9717270746

  12. Buy Methylone(Carfentanil)Buy Ketamine/Order 2fdck,1cp-Isd.

    If you are looking for a place to buy Pain killers,Sex Pills and Bromadol,Ephendrine,1p-Lsd,Alprazolam,Etizolam Ephendrine,Clonazolam R-30490 4-Methoxymethyl fentanyl powder online where you can order the product easily and safely, then this is the best place for you to buy R-30490 4-Methoxymethyl fentanyl and several other R-30490 powder analogs for sale,We offer you an easy,use the website so that you can buy R-30490 4-Methoxymethyl fentanyl at wholesale prices from R-30490 (4-Methoxymethyl fentanyl powder manufacturers and suppliers.
    More info
    Whtatsapp +8619182014046
    Wickr Me: asia247

  13. Get great discounted deals on #Steroids,#Human Growth Hormones,#ORAL STEROIDS,#Sex Supplements,#Sleeping pills,#Weight loss pills,#Fat burners, #sleeping pills,#Injectable Steroids,#Pharmaceutical assorted #Pain-Medications, #Anxiety-Medications, #Benzodiazepines, #Pain-Relief-medications, #Insomnia-Medications, #Stimulants, #Opiate/Opioid,We provide all bodybuilders and Fitness Men and Women with the best products with 100% positive response after use. Delivery is 100% safe and secure.

    We have the following medications and more available:

    Norco 325 mg / 5 mg
    Vicodin 500 mg / 5 mg
    Vigra 100 mg
    Xanax 2 mg longbars
    Seconal (Secobarbital Sodium Capsules) 100 mg
    Nembutal (In pill, liquid and powder form)
    Quaalude (lemmon 714 300mg)
    Ketamine Crystal
    Dilaudid 8 mg
    Adderall 30 mg
    Oxycontin 20 mg / 80 mg
    Klonopin 0.5 mg
    Ritalin 10 mg
    Actavis: promethazine/codeine syrup
    Ambien ( Zolpidem, Stilnox) 10 mg
    Clonazepam 2 mg ( Rivotril)
    Lorazepam 2.5 mg ( Ativan)
    Roxicodone 15 mg, 30 mg
    Hydro 10 mg / 500 mg
    Percocet 10/325mg
    Opana 10 mg / 40 mg
    Subutex - Suboxone
    Fentanyl patches
    Diazepam Roche 10mg
    Aprazolam/Xanax 0.5mg
    Zopiclone 7.5mg
    Diazepam Shalina 10mg
    Diazepam Teva 5mg
    Zolpidem 10mg
    Tramadol 200mg
    Ketamine liquid 50mg/10ml

    -Stealth Packages
    -Vacuum sealed thick plastic
    -Fast and Reliable delivery -#Tracking Available!
    -No signature required upon arrival of parcel
    -We offer safe and discreet overnight shipping (24/h) to clients within the US, and 3-4 business days shipping to clients in EU.
    -We also offer the best discount for bulk purchase on any of our products.
    -We offer the best of services to all our clients, and make sure they are
    treated like family.
    -We offer a FULL REFUND on any package that doesn't make it to its
    Contact us:
    WhatsApp:....................+1(312) 379-9621
    Wickr App:..........................Genlabs
    SnacpChat ID:......................Medsplugging

  14. Airlines Gethuman is a platform where you can get help from a live person to Make Flight Reservations . We Assist you in managing your flights. In this way you save both, your money and your time.

    For the latest flight deals and offers visit:

    delta book a flight
    delta unaccompanied minor fee
    southwest airlines reservations

  15. Good day! I could have sworn I’ve been to this blog before but after going through some of the
    articles I realized it’s new to me. Nonetheless, I’m
    certainly happy I discovered it and I’ll be bookmarking it and checking back often!
    worst Web design

  16. Thank you for the Post-it is nice to Keep it up. I like to read such an informative blog.
    ClicktoSolved Technical Team provides an end solution for each error you face in Norton products. In this blog, we are going to tell you How to Resolve Norton 360 Error 8504, 104 in Windows 10 on your PC. There might be chances that you have checked out multiple articles or tutorials on the web to fix this but if you are reading this then do not worry, we are going to fix your problem anyhow because we have a group of experts who are going to help you anytime.

  17. Southwest Reservations are the best option for the people and you can reserve Southwest airlines tickets Under the very affordable budget for the reservations. Reservations are no expensive thing for you once you're opting Southwest flights.

    Visit on the given links for flight booking:

    American Airlines Basic Economy

    Delta First Class Flights

    Delta Unaccompanied Minors

    You can cancel your reservation within 24 hours with Qatar Airways Cancellation without any penalty before the departure of your flight. If your flight is canceled or delayed by more than 3 hours, you can request a refund.

    Qatar airways refund

  18. Hello Guys,
    I am Sahil or You can call me a Digital Marketer who loves to find Digital Marketing Loops on the Internet. So, let talk about some of the Best Digital Marketing Categories.

    Digital Marketing Expert in Dwarka Mor

  19. Your post is well-written. It is a really fascinating post. Thanks for share a lot of information through this post.
    Some important errors of the Roadrunner email account can affect your actions in various ways. This does not mean that you should not use roadrunner mail services. You should find a solution to why this error occurs, how does it happen? Inside the blog section by visiting our site, you can easily find solutions to How To Fix Common Roadrunner Email Problems? Otherwise, you can take the help of our technical expertise related to your issues.

  20. Thank you for sharing your thoughts. I really appreciate your efforts and I will be waiting for your further post thank you once again.

    Online Essay Help

  21. GBL (gamma butyrolactone) is medication or compound that, after administration, is metabolized into a pharmacologically active product. Inactive products are pharmacologically inactive medications that are metabolized into an active form within the body. Order GBL Powder online now for recreational purposes. You can either take the GBL and wait for your system to synthesis it for you or go directly for GHB Powder, GHB Liquid.
    -- VV1ckr : imdasource --
    -- VVhatsapp : +1 213-357-5684 --
    gbl tire cleaner,
    griot's garage wheel cleaner gbl,
    griots wheel cleaner gbl,
    gamma butyrolactone wheel cleaner,
    gbl wheel brite,
    gbl wheel cleaner kopen,
    gbl cleaner amazon,
    magic wheel cleaner gbl,
    p21s wheel cleaner gbl,
    trinova wheel cleaner gbl,
    gbl alloy wheel cleaner uk,
    gbl wheel cleaner 99 96%,
    wheel cleaner (gbl 99.99%),
    gbl liquid price,

  22. We have pharma ghb, gbl liquid, gaba caps and more.
    GHB is also a naturally-occurring metabolite of the inhibitory neurotransmitter gamma-aminobutyric acid (GABA) found in the brain.
    ** **
    ** VVhatsapp : +1 213-357-5684 **
    buy ghb online reddit,
    buy ghb online ship to usa,
    buy ghb online uk,
    buy ghb online canada,
    buy ghb poland,
    buy ghb paypal,
    buy pure ghb,
    buy ghb sydney,
    buy ghb spain,
    buy ghb thailand,
    buy ghb in the uk,
    GHB (gamma-hydroxybutyric acid),
    Buy GHB liquid online,
    where to buy GHB online,
    buy cheap ghb,
    where to buy ghb,
    buy ghb online canada,

  23. 1,4-Butanediol Tech and pharma grade.
    CAS: 110-63-4
    EC number: 203-786-5
    Purity: 99,5%
    Color: Colorless
    Appearance: Liquid
    ** **
    ** VVhatsapp : +1 213-357-5684 **
    Buy 1,4-Butanediol,
    1,4-Butanediol price,
    Buy 1,4-Butanediol (Tetramethylene Glycol),
    1,4-Butanediol Analytical Standards,
    Buy 1,4-Butanediol Tech Grade 99.5%,
    1,4-Butanediol ReagentPlus for sale,
    Butanediol Cleaner for sale,
    1,4-butanediol cas,
    buy 1 4 butanediol California,
    buy 1 4 butanediol Spain,
    buy 1 4 butanediol Saudi Arabia,
    buy 1 4 butanediol Europe,

  24. QuickBooks FILE DOCTOR
    If you have used the Quickbooks tool hub for accounting purpose then surely this QuickBooks File Doctor will help you out to repair your bugs and issues in a easiest way.

  25. Buy Palbace 125mg Lemon Quaaludes 714\'s,XANAX,VA,

    We have medications for the treatment of chronic back pains, cough, anxiety,panic disorder, depression, erectile dysfunction, dysfunction,adhd,narcolepsy, obesity,depression, fatigue,Weight Loss supplement and more online (no prescription required).
    We sell quality medications online at affordable and discount prices. Fast and secure overnight delivery.
    We are ready to sell minimum quantities and large supplies of our product worldwide (SHIPPING IS WORLDWIDE).

    Below is a list of some of our product :

    Klonopin 1mg,2mg

    Opama 10mg,20mg,30mg,40mg


    Soma 350mg





    Lorazepam 2.5 mg (Ativan)

    Clonazepam 2 mg (Rivotril)

    Valium 2mg,5mg 10mg

    Fentalyn patches

    Tramadol (Ultram) 50mg etc........

    We offer:

    -Good quality Medications
    - Good and affordable prices.

    - Fast and Reliable delivery
    -Tracking Available!

    -Tracking numbers available with references.

    - Various shipping option (Overnight and Airmail).

    -Shipping secure and discreet ,Delivery time OVERNIGHT & 1-5 days depending on location.

    - Buy with and without Prescription Required!

    -Additional Discounts on Bulk Orders

    - Buy Direct and Save Time and Money!

    - 100% Customer Satisfaction Guaranteed

    Contact via details below:

    CONTACT NUMBER...+13367151012

  26. We offer you the best deals & offers that you can hardly find anywhere else. We help you with all the available options with the lowest airfares.

    Visit here for cheap flight booking:

    American Airlines Basic Economy

    Qatar Airways Manage Booking

    Airlines Gethuman

    Southwest Wanna Get Away

    Delta Cancellation Policy

  27. So, if you've got an idea to order a flight ticket online, you'll have valid tips to pick the opposite features like flight change, bag baggage process, seat selection and reservation, flight schedule then on. There are a variety of individuals who understand the higher concept of Delta reservations during which they receive more benefits, sort of a delicious meal, free WI-FI, entertainment and far more. It's most vital to pick the flight that's necessary to book but don’t please forget to say the right information about the passengers and its flight service during a valid manner.

    Southwest Airlines Reservations

    Air Canada Reservations

  28. Nice & Informative Blog! If you are looking for the best lawyer to perform Tatkal Marriage in Bijnor , Rajput & Legal Law Firm is the right place for you. Just call us on +91-9613134200 & solve any query related to court Marriage & marriage registration in Bijnor in less time. Our expert lawyer team makes sure to give you a reliable marriage certificate for same-day court marriage at an economized rate.