flex.xz.dll

Classification: Malicious

flex.xz.dll is a malicious file sample. Linked to Hancitor malware. Reported by 1 threat source, last seen 2021-09-21. Detected by 6 antivirus engines.

Detection summary

  • 6 antivirus detections (9% detection ratio)
  • 1 IDS alerts
  • 4 processes observed
  • 4 contacted hosts
  • 4 DNS requests

MITRE ATT&CK associations

Malware families: HANCITOR (S0499)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Hancitor Abuse.ch 2021-09-21 14:37:22 2021-09-21 14:37:22 malicious-activity S0499 Hancitor

Tags

chanitor hancitor

Sample information

Filenames
flex.xz.dll
File type
application/x-dosexec
Size
194048 bytes
MD5
79e1396b610fcf4eb089a33da56f12c9
SHA-1
e502e37ac85d7e50839b050780665bdb8eb558ed
SHA-256
4d215d88296651afc1c841323f0fe3d2b9b3302684eeec82ee23f6c2464b5601
First indexed
2021-09-21 14:46:01
Last updated
2026-05-21 22:49:29

Antivirus detections

EngineDetection
Elasticmalicious (high confidence)
APEXMalicious
Paloaltogeneric.ml
SentinelOneStatic AI - Suspicious PE
eGambitUnsafe.AI_Score_61%
BitDefenderThetaGen:NN.ZedlaF.34170.lq4@aO3tZon

Network contacts

20.42.65.92 54.243.45.255 91.214.71.26 54.243.59.231

DNS requests

api.ipify.org ic-407c0c00-0ac7b9-windowsupdate48.s.loris.llnwd.net ic-407c0c00-1475e2-windowsupdate48.s.loris.llnwd.net thembitores.com

Process list

NameCommand line
<Ignored Process>
rundll32.exe"C:\flex.xz.dll",#1
rundll32.exe"C:\flex.xz.dll",#2
rundll32.exe"C:\flex.xz.dll",#3