flex.xz.dll
Classification: Malicious
flex.xz.dll is a malicious file sample. Linked to Hancitor malware. Reported by 1 threat source, last seen 2021-09-21. Detected by 6 antivirus engines.
Detection summary
- 6 antivirus detections (9% detection ratio)
- 1 IDS alerts
- 4 processes observed
- 4 contacted hosts
- 4 DNS requests
MITRE ATT&CK associations
Malware families: HANCITOR (S0499)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Hancitor | Abuse.ch | 2021-09-21 14:37:22 | 2021-09-21 14:37:22 | malicious-activity | S0499 Hancitor |
Tags
chanitor hancitorSample information
- Filenames
- flex.xz.dll
- File type
- application/x-dosexec
- Size
- 194048 bytes
- MD5
79e1396b610fcf4eb089a33da56f12c9- SHA-1
e502e37ac85d7e50839b050780665bdb8eb558ed- SHA-256
4d215d88296651afc1c841323f0fe3d2b9b3302684eeec82ee23f6c2464b5601- First indexed
- 2021-09-21 14:46:01
- Last updated
- 2026-05-21 22:49:29
Antivirus detections
| Engine | Detection |
|---|---|
| Elastic | malicious (high confidence) |
| APEX | Malicious |
| Paloalto | generic.ml |
| SentinelOne | Static AI - Suspicious PE |
| eGambit | Unsafe.AI_Score_61% |
| BitDefenderTheta | Gen:NN.ZedlaF.34170.lq4@aO3tZon |
Network contacts
DNS requests
api.ipify.org ic-407c0c00-0ac7b9-windowsupdate48.s.loris.llnwd.net ic-407c0c00-1475e2-windowsupdate48.s.loris.llnwd.net thembitores.com
Process list
| Name | Command line |
|---|---|
| <Ignored Process> | |
| rundll32.exe | "C:\flex.xz.dll",#1 |
| rundll32.exe | "C:\flex.xz.dll",#2 |
| rundll32.exe | "C:\flex.xz.dll",#3 |