if.dll
Classification: Malicious
if.dll is a malicious file sample. Linked to Hancitor malware. Reported by 1 threat source, last seen 2022-01-31. Detected by 75 antivirus engines.
Detection summary
- 75 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: HANCITOR (S0499)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Hancitor | MalwareBazaar Abuse.ch | 2022-01-31 15:54:40 | 2022-01-31 15:54:40 | malicious-activity | S0499 Hancitor |
Sample information
- Filenames
- if.dll
- File type
- application/x-dosexec
- MD5
deef80792ae5c52d3553453d124c0457- SHA-1
b809c0a54e70d8d2377fc37a17d952ec98698670- SHA-256
ebe7a2c72e2e89732d435a7d491c9cd85f125b1584bb807f921b03dff9d16b94- First indexed
- 2022-01-31 17:15:05
- Last updated
- 2026-05-24 12:00:44
Antivirus detections
| Engine | Detection |
|---|---|
| Lionic | Trojan.Win32.Hancitor.4!c |
| MicroWorld-eScan | Trojan.GenericKD.48202804 |
| McAfee | Artemis!DEEF80792AE5 |
| Sangfor | Trojan.Win32.Hancitor.gen |
| BitDefender | Trojan.GenericKD.48202804 |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Generik.MTLPARQ |
| APEX | Malicious |
| Paloalto | generic.ml |
| Kaspersky | HEUR:Trojan.Win32.Hancitor.gen |
| Ad-Aware | Trojan.GenericKD.48202804 |
| Sophos | Mal/EncPk-APY |
| TrendMicro | Trojan.Win32.HANCITOR.YXCBAZ |
| McAfee-GW-Edition | BehavesLike.Win32.Worm.th |
| FireEye | Trojan.GenericKD.48202804 |
| Jiangmin | AdWare/Ejik.ed |
| Webroot | W32.Trojan.Hancitor |
| Kingsoft | Win32.Troj.Undef.(kcloud) |
| Microsoft | Trojan:Win32/Casdet!rfn |
| ZoneAlarm | HEUR:Trojan.Win32.Hancitor.gen |
| GData | Win32.Trojan.Kryptik.1ZQV6I |
| VBA32 | BScope.Exploit.Shellcode |
| MAX | malware (ai score=81) |
| Malwarebytes | Malware.AI.46833062 |
| TrendMicro-HouseCall | Trojan.Win32.HANCITOR.YXCBAZ |
| Rising | Trojan.Casdet!8.FAA9 (CLOUD) |
| MaxSecure | Trojan.Malware.300983.susgen |
| Fortinet | W32/Kryptik.EPIZ!tr |
| AVG | Win32:Trojan-gen |
| Avast | Win32:Trojan-gen |
| ALYac | Gen:Variant.Tedy.169155 |
| AVG | Win32:TrojanX-gen [Trj] |
| AhnLab-V3 | Trojan/Win.Generic.C4952738 |
| Antiy-AVL | Trojan/Win32.Hancitor |
| Arcabit | Trojan.Tedy.D294C3 |
| Avast | Win32:TrojanX-gen [Trj] |
| Avira | HEUR/AGEN.1329410 |
| BitDefender | Gen:Variant.Tedy.169155 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.16452552044c0457 |
| CTX | dll.trojan.hancitor |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 100) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Siggen23.38734 |
| ESET-NOD32 | a variant of Win32/Injector.ERCN |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Tedy.169155 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1329410 |
| FireEye | Gen:Variant.Tedy.169155 |
| Fortinet | W32/Kryptik.HLAY!tr |
| GData | Gen:Variant.Tedy.169155 |
| Detected | |
| Ikarus | Trojan.Win32.Crypt |
| K7AntiVirus | Trojan ( 0058e5201 ) |
| K7GW | Trojan ( 0058e5201 ) |
| Malwarebytes | Malware.AI.2242206485 |
| MaxSecure | Trojan.Malware.73753771.susgen |
| McAfeeD | ti!EBE7A2C72E2E |
| MicroWorld-eScan | Gen:Variant.Tedy.169155 |
| Microsoft | Trojan:Win32/Qakbot.GP!MTB |
| NANO-Antivirus | Trojan.Win32.Hancitor.kgypns |
| Panda | Trj/GdSda.A |
| Rising | Trojan.Hancitor!8.B197 (TFE:5:bpbnaBaiJF) |
| Sangfor | Trojan.Win32.Injector.ERCN |
| Skyhigh | Artemis!Trojan |
| Symantec | Backdoor.Hancitor!gm |
| Tencent | Malware.Win32.Gencirc.13ad6302 |
| Trapmine | suspicious.low.ml.score |
| VIPRE | Gen:Variant.Tedy.169155 |
| Varist | W32/Hancitor.JDAU-0494 |
| Yandex | Trojan.Hancitor!RxH8GvV93LU |
| Zillya | Trojan.Hancitor.Win32.83 |
| alibabacloud | Trojan:Win/Qakbot.GX8PHU |