MB-c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a
high
📛 Threat Title
Unknown: PDA-Domains.zip
Description
File type: zip. Size: 1174 bytes. Tags: zip. Reporter: smica83. First seen: 2026-09-25 10:27:08.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a
IOC database
- Type
- hash_sha256
- Value
c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a
hash_sha1
9240a10c37fdbce79e7b2c5212862c4e43c168fd
VT 0 / 75
IOC database
- Type
- hash_sha1
- Value
9240a10c37fdbce79e7b2c5212862c4e43c168fd- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| MD5 | 3a229bcdb79c145113ccf6408a3cd9d2 |
| SHA-1 | 9240a10c37fdbce79e7b2c5212862c4e43c168fd |
| SHA-256 | c2fcfb7c509368f993142de09103a341f100ab4eb930fe889099a42b41beb83a |
| VHash | 94588e4f5f5856c07768397fa6526ac5 |
| SSDEEP | 24:9kgvzze1uj5736nPUHLliAJ7z0HBB9jWvZtrBPVuvdvYrf0fYE5:9kg3eS57EP2LsdD49PctYwfYE5 |
| TLSH | T17A21CA6110A41DB8C4B8E2320107EC0B07518CB9DC7DE526FB5624853483A725FD5F3F |
| File type | ZIP |
| File type tag | zip |
| File extension | zip |
| Magic | Zip archive data, at least v2.0 to extract, compression method=deflate |
| File size | 1.1 KB |
History
| First seen on VirusTotal | 2026-09-24 09:59 UTC |
| Last submission | 2026-09-24 09:59 UTC |
| Last analysis | 2026-09-24 09:59 UTC |
| Last modified on VirusTotal | 2026-09-25 11:14 UTC |
Known Names
rrgdvdc82.exePDA-Domains.zip
hash_md5
3a229bcdb79c145113ccf6408a3cd9d2
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/3a229bcdb79c145113ccf6408a3cd9d2
IOC database
- Type
- hash_md5
- Value
3a229bcdb79c145113ccf6408a3cd9d2- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/3a229bcdb79c145113ccf6408a3cd9d2
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: zip. Size: 1174 bytes. Tags: zip. Reporter: smica83. First seen: 2026-09-25 10:27:08.
Remediations (10)
-
web:knowledgebase.paloaltonetworks.com
Answer The introduction of Top Level Domains (TLDs) such as .zip and .mov by Google on May 3, 2023, has raised significant concerns within the cybersecurity community. Extensive coverage on this topic exists, and while this article will not delve into exhaustive details, it aims to underscore the inherent risks associated with these new domains and provide guidance for safeguarding oneself ...
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:learn.microsoft.com
Learn how to detect and limit or disable RC4 usage in Kerberos to enhance security in Active Directory domain environments.
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:www.alitajran.com
Learn how to configure Download Domains to address CVE-2021-1730 vulnerability in Exchange Server and fix Download Domains are not configured.
-
web:www.bleepingcomputer.com
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into ...
-
web:www.fortinet.com
One technique used by threat actors is to disguise their phishing attacks with creative names that look legitimate to the casual reader but that link to malicious sites. In this blog, we will look into a new threat resulting from the addition of a new Top-Level Domain (TLD), '.ZIP'.
-
web:www.m3aawg.org
Effective prevention, remediation , and mitigation strategies are needed to formulate a defense-in-depth approach to addressing DNS Abuse threats. Fighting DNS Abuse presents unique challenges for any organizations working to keep the Internet safe and secure.
-
web:www.microsoft.com
Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives and fake image shortcut files to deliver a persistent Node.js implant and evade detection.
-
web:www.microsoft.com
Active Directory Domain Services is central to enterprise identity and access management, making it a frequent focus for cyberattacks. Proactive detection and remediation are essential to reduce risk. If you suspect a compromise, rapid containment is critical. Microsoft Incident Response can help before, during, and after a cybersecurity incident.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.