s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-ddde0babbdb0ce68b2588f67084d5e07bd50e6a1af2c7ee5e75d87843c4fcb69 high

📛 Threat Title

Unknown: ddde0babbdb0ce68b2588f67084d5e07bd50e6a1af2c7ee5e75d87843c4fcb69

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 8724480 bytes. Tags: exe, Gansu-Shishida-Information-Technology-Co-Ltd, signed. Reporter: JAMESWT_WT. First seen: 2026-05-15 06:38:50.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash dddd95789c6d117404c7c3c56ab141f3

IOC database

Type
hash_imphash
Value
dddd95789c6d117404c7c3c56ab141f3
First seen
Last seen
Attached to this threat
Appears in
10 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 ddde0babbdb0ce68b2588f67084d5e07bd50e6a1af2c7ee5e75d87843c4fcb69 1 feed

IOC database

Type
hash_sha256
Value
ddde0babbdb0ce68b2588f67084d5e07bd50e6a1af2c7ee5e75d87843c4fcb69
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 2ab79ae2a0ae88f87d3501634656efc247866bb8 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2ab79ae2a0ae88f87d3501634656efc247866bb8
1 feed

IOC database

Type
hash_sha1
Value
2ab79ae2a0ae88f87d3501634656efc247866bb8
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2ab79ae2a0ae88f87d3501634656efc247866bb8

hash_md5 effcb18274d69a37e268b3386d6d675d VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/effcb18274d69a37e268b3386d6d675d
1 feed

IOC database

Type
hash_md5
Value
effcb18274d69a37e268b3386d6d675d
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/effcb18274d69a37e268b3386d6d675d

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 8724480 bytes. Tags: exe, Gansu-Shishida-Information-Technology-Co-Ltd, signed. Reporter: JAMESWT_WT. First seen: 2026-05-15 06:38:50.

Remediations (10)

  • web:askubuntu.com

    9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.

  • web:learn.microsoft.com

    Learn about the AADSTS error codes that are returned from the Microsoft Entra security token service (STS).

  • web:malwaretips.com

    Scam Overview What the "Tax Resolution Team" scam is, in plain English This scam is a fraudulent phone outreach campaign where callers, robocalls, or voicemails claim to represent a "tax resolution team," "IRS resolution department," "tax debt relief unit," or a similarly named group. They suggest you've been "flagged," "marked," or "selected" for special IRS ...

  • web:woshub.com

    After a clean installation or reinstalling Windows, many unknown devices may appear in Device Manager. This article explains how to identify unknown devices in Windows, find the latest up-to-date drivers,…

  • web:www.cisa.gov

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.How to use the KEV ...

  • web:www.manageengine.com

    Steps to follow when software deployment fails due to unknown error code.

  • web:www.reddit.com

    Pulling my hair out for this one. What's happening- When I deploy a VPP app (Microsoft Teams for example) and scope it to all users with user license…

  • web:www.thewindowsclub.com

    Get a more generic solution to identifying unknown or unrecognized file types & extensions with these free tools for Windows 11/10 computer.

  • web:www.toolsley.com

    Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!

  • web:www.windowsdigitals.com

    Can't install or run an app from unknown publisher? Here's how to allow unknown publisher in Windows 11/10, and how to disable the warning.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.