s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a high

📛 Threat Title

Unknown: PDA-Domains.zip

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: zip. Size: 1174 bytes. Tags: zip. Reporter: smica83. First seen: 2026-09-25 10:27:08.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a

IOC database

Type
hash_sha256
Value
c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a

hash_sha1 9240a10c37fdbce79e7b2c5212862c4e43c168fd VT 0 / 75

IOC database

Type
hash_sha1
Value
9240a10c37fdbce79e7b2c5212862c4e43c168fd
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
MD53a229bcdb79c145113ccf6408a3cd9d2
SHA-19240a10c37fdbce79e7b2c5212862c4e43c168fd
SHA-256c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a
VHash94588e4f5f5856c07768397fa6526ac5
SSDEEP24:9kgvzze1uj5736nPUHLliAJ7z0HBB9jWvZtrBPVuvdvYrf0fYE5:9kg3eS57EP2LsdD49PctYwfYE5
TLSHT17A21CA6110A41DB8C4B8E2320107EC0B07518CB9DC7DE526FB5624853483A725FD5F3F
File typeZIP
File type tagzip
File extensionzip
MagicZip archive data, at least v2.0 to extract, compression method=deflate
File size1.1 KB
History
First seen on VirusTotal2026-09-24 09:59 UTC
Last submission2026-09-24 09:59 UTC
Last analysis2026-09-24 09:59 UTC
Last modified on VirusTotal2026-09-25 11:14 UTC
Known Names
  • rrgdvdc82.exe
  • PDA-Domains.zip
hash_md5 3a229bcdb79c145113ccf6408a3cd9d2 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/3a229bcdb79c145113ccf6408a3cd9d2

IOC database

Type
hash_md5
Value
3a229bcdb79c145113ccf6408a3cd9d2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/3a229bcdb79c145113ccf6408a3cd9d2

References (1)

Remediations (10)

  • web:knowledgebase.paloaltonetworks.com

    Answer The introduction of Top Level Domains (TLDs) such as .zip and .mov by Google on May 3, 2023, has raised significant concerns within the cybersecurity community. Extensive coverage on this topic exists, and while this article will not delve into exhaustive details, it aims to underscore the inherent risks associated with these new domains and provide guidance for safeguarding oneself ...

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:learn.microsoft.com

    Learn how to detect and limit or disable RC4 usage in Kerberos to enhance security in Active Directory domain environments.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:www.alitajran.com

    Learn how to configure Download Domains to address CVE-2021-1730 vulnerability in Exchange Server and fix Download Domains are not configured.

  • web:www.bleepingcomputer.com

    The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into ...

  • web:www.fortinet.com

    One technique used by threat actors is to disguise their phishing attacks with creative names that look legitimate to the casual reader but that link to malicious sites. In this blog, we will look into a new threat resulting from the addition of a new Top-Level Domain (TLD), '.ZIP'.

  • web:www.m3aawg.org

    Effective prevention, remediation , and mitigation strategies are needed to formulate a defense-in-depth approach to addressing DNS Abuse threats. Fighting DNS Abuse presents unique challenges for any organizations working to keep the Internet safe and secure.

  • web:www.microsoft.com

    Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives and fake image shortcut files to deliver a persistent Node.js implant and evade detection.

  • web:www.microsoft.com

    Active Directory Domain Services is central to enterprise identity and access management, making it a frequent focus for cyberattacks. Proactive detection and remediation are essential to reduce risk. If you suspect a compromise, rapid containment is critical. Microsoft Incident Response can help before, during, and after a cybersecurity incident.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.