ab2a474c3fd276095d7db5d78df356a572b1eee397ef1977facd8df214db3db0
Classification: Malicious
ab2a474c3fd276095d7db5d78df356a572b1eee397ef1977facd8df214db3db0 is a malicious file sample. Linked to Hancitor malware. Detected by 87 antivirus engines.
Detection summary
- 87 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: HANCITOR (S0499)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Hancitor | MalwareBazaar Abuse.ch | 2022-03-20 19:55:14 | 2022-03-20 19:55:14 | malicious-activity | S0499 Hancitor |
Sample information
- Filenames
- ab2a474c3fd276095d7db5d78df356a572b1eee397ef1977facd8df214db3db0
- File type
- application/x-dosexec
- MD5
a2dd642315f3cc6b44241c31ec964ea3- SHA-1
6a2426de100f63c884a54ed12013e3094e6fe10b- SHA-256
ab2a474c3fd276095d7db5d78df356a572b1eee397ef1977facd8df214db3db0- First indexed
- 2022-03-20 21:15:03
- Last updated
- 2026-05-27 06:15:59
Antivirus detections
| Engine | Detection |
|---|---|
| Bkav | W32.AIDetect.malware1 |
| Lionic | Trojan.Win32.Geral.a!c |
| Elastic | malicious (high confidence) |
| MicroWorld-eScan | Gen:Variant.Ransom.Magniber.13 |
| FireEye | Generic.mg.a2dd642315f3cc6b |
| CAT-QuickHeal | Trojan.Hancitor |
| ALYac | Gen:Variant.Ransom.Magniber.13 |
| Cylance | Unsafe |
| Sangfor | Suspicious.Win32.Save.a |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Alibaba | TrojanDownloader:Win32/Hancitor.a7de52aa |
| K7GW | Trojan-Downloader ( 005727781 ) |
| K7AntiVirus | Trojan-Downloader ( 005727781 ) |
| BitDefenderTheta | Gen:NN.ZedlaF.34062.bq4@amkFNxd |
| Cyren | W32/Trojan.WTSS-1018 |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Win32/TrojanDownloader.Hancitor.P |
| TrendMicro-HouseCall | Trojan.Win32.HANCITOR.YXBK3Z |
| Paloalto | generic.ml |
| Kaspersky | Trojan.Win32.Hancitor.gw |
| BitDefender | Gen:Variant.Ransom.Magniber.13 |
| Avast | Win32:DropperX-gen [Drp] |
| Tencent | Win32.Trojan.Ransom.Lnej |
| Ad-Aware | Gen:Variant.Ransom.Magniber.13 |
| Emsisoft | Gen:Variant.Ransom.Magniber.13 (B) |
| Comodo | Application.Win32.Amonetize.II@5w7wi7 |
| DrWeb | DLOADER.Trojan |
| TrendMicro | Trojan.Win32.HANCITOR.YXBK3Z |
| McAfee-GW-Edition | BehavesLike.Win32.Injector.mc |
| SentinelOne | Static AI - Malicious PE |
| Sophos | Mal/Generic-R + Mal/Emogen-Y |
| APEX | Malicious |
| Avira | TR/Hijacker.Gen |
| MAX | malware (ai score=83) |
| Kingsoft | Win32.Troj.Hancitor.gw.(kcloud) |
| Microsoft | Trojan:Win32/Hancitor.ARK!MTB |
| GData | Gen:Variant.Ransom.Magniber.13 |
| Cynet | Malicious (score: 100) |
| AhnLab-V3 | Trojan/Win.Hancitor.C4758671 |
| Acronis | suspicious |
| McAfee | RDN/Generic Downloader.x |
| VBA32 | TrojanDownloader.Geral |
| Ikarus | Trojan-Downloader.Win32.Hancitor |
| eGambit | Unsafe.AI_Score_90% |
| Fortinet | W32/Hancitor.P!tr.dldr |
| AVG | Win32:DropperX-gen [Drp] |
| Panda | Trj/GdSda.A |
| ALYac | Trojan.Agent.Hancitor |
| AVG | Win32:MalwareX-gen [Drp] |
| Alibaba | TrojanDownloader:Win32/Hancitor.e74c57bf |
| Antiy-AVL | Trojan[Downloader]/Win32.Hancitor |
| Arcabit | Trojan.Ransom.Magniber.13 |
| Avast | Win32:MalwareX-gen [Drp] |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.1675856368964ea3 |
| CTX | dll.trojan.hancitor |
| ClamAV | Win.Downloader.Hancitor-10020154-0 |
| DeepInstinct | MALICIOUS |
| Elastic | Windows.Trojan.Hancitor |
| F-Secure | Trojan.TR/Hijacker.Gen |
| Fortinet | W32/Hancitor.P!tr |
| Detected | |
| Jiangmin | Trojan.Hancitor.cb |
| Kingsoft | malware.kb.a.1000 |
| Lionic | Trojan.Win32.Hancitor.4!c |
| Malwarebytes | Trojan.Downloader |
| MaxSecure | Trojan.Malware.131173817.susgen |
| McAfeeD | ti!AB2A474C3FD2 |
| NANO-Antivirus | Trojan.Win32.Hancitor.jpkypt |
| Rising | Downloader.Hancitor!8.A19 (TFE:5:JuACwxShjKR) |
| Skyhigh | BehavesLike.Win32.Agent.mc |
| Sophos | Mal/Emogen-Y |
| Symantec | Trojan.Gen.MBT |
| Tencent | Malware.Win32.Gencirc.10bdd93d |
| Trapmine | malicious.high.ml.score |
| TrellixENS | GenericRXQX-IK!A2DD642315F3 |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9d |
| VIPRE | Gen:Variant.Ransom.Magniber.13 |
| Varist | W32/ABTrojan.WTSS-1018 |
| ViRobot | Trojan.Win.Z.Hancitor.20992 |
| Webroot | W32.Trojan.Hancitor |
| Xcitium | Application.Win32.Amonetize.II@5w7wi7 |
| Yandex | Trojan.Hancitor!VP6wZFAqNfg |
| Zillya | Trojan.Hancitor.Win32.78 |
| ZoneAlarm | Mal/Emogen-Y |
| alibabacloud | RansomWare |
| huorong | Trojan/Injector.ait |