Classification: Malicious
libcef.dll is a malicious file sample. Linked to Apt29 activity. Reported by 3 threat sources, last seen 2026-08-07. Detected by 49 antivirus engines.
Detection summary
- 49 antivirus detections (2% detection ratio)
- 0 IDS alerts
- 2 processes observed
- 1 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-08-07 10:04:03 |
2026-08-07 10:04:03 |
malicious-activity
|
|
| Apt 29 |
Maltiverse |
2023-08-18 04:15:27 |
2023-08-19 20:21:54 |
malicious-activity
|
G0016 APT29
|
| Generic Malware |
Hybrid-Analysis |
2023-05-19 09:30:04 |
2023-05-19 11:00:10 |
|
|
Sample information
- Filenames
- libcef.dll
- File type
- PE32+ executable (DLL) (GUI) x86-64 (stripped to e ...
- Size
- 28672 bytes
- MD5
d817f36361f7ac80aba95f98fe5d337d
- SHA-1
6837abcb19ac56e311a6eeda2429dcb451b611a1
- SHA-256
4c7d0e8478a0a8df824c391ebee227c42930f258d2d55b06f8969931cb07a31e
- First indexed
- 2023-05-19 09:16:00
- Last updated
- 2025-12-22 00:41:49
Antivirus detections
| Engine | Detection |
| ALYac | Trojan.Agent.Wacatac |
| AVG | Win64:Trojan-gen |
| AhnLab-V3 | Trojan/Win.Leonem.C5471498 |
| Arcabit | Trojan.Tedy.D5CF7A |
| Avast | Win64:Trojan-gen |
| Avira | TR/DLLhijack.snanh |
| BitDefender | Gen:Variant.Tedy.380794 |
| Bkav | W64.AIDetectMalware |
| CTX | dll.trojan.dllhijack |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DrWeb | Trojan.Siggen21.1032 |
| ESET-NOD32 | Win64/Dukes.I trojan |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Tedy.380794 (B) |
| F-Secure | Trojan.TR/DLLhijack.snanh |
| Fortinet | W64/Dukes.I!tr |
| GData | Gen:Variant.Tedy.380794 |
| Google | Detected |
| Ikarus | Trojan.Agent |
| Jiangmin | Trojan.DLLhijack.mw |
| K7AntiVirus | Trojan ( 005f08561 ) |
| K7GW | Trojan ( 005f08561 ) |
| Kaspersky | Trojan.Win64.DllHijack.dp |
| Kingsoft | Win32.Troj.Unknown.a |
| Lionic | Trojan.Win32.DLLhijack.4!c |
| Malwarebytes | Malware.AI.4032198396 |
| MaxSecure | Trojan.Malware.210826218.susgen |
| McAfeeD | ti!4C7D0E8478A0 |
| MicroWorld-eScan | Gen:Variant.Tedy.380794 |
| Microsoft | TrojanDownloader:Win64/VaporRage.H!dha |
| Paloalto | generic.ml |
| Panda | Trj/Chgt.AD |
| Rising | Downloader.VaporRage!8.12BEA (CLOUD) |
| SentinelOne | Static AI - Suspicious PE |
| Skyhigh | BehavesLike.Win64.Injector.mm |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Malware.Win32.Gencirc.13ec67f4 |
| TrellixENS | Trojan-FVCB!D817F36361F7 |
| TrendMicro | Trojan.Win64.DLLHIJACK.VSNW1DA24 |
| TrendMicro-HouseCall | Trojan.Win64.DLLHIJACK.VSNW1DA24 |
| VBA32 | Trojan.Leonem |
| VIPRE | Gen:Variant.Tedy.380794 |
| Varist | W64/ABTrojan.YGML-5949 |
| ViRobot | Trojan.Win.S.Agent.28672 |
| Zillya | Trojan.DllHijack.Win64.2 |
| alibabacloud | Trojan:Win/Dukes.I |
Process list
| Name | Command line |
| <Ignored Process> | |
| rundll32.exe | "C:\libcef.dll",#1 |