MB-e0b566f6434bc418ab3d8dea59e574338b22a15d66123fe1fb2b4438e27eb18a
high
📛 Threat Title
Unknown: file
Description
File type: exe. Size: 15360 bytes. Tags: 5a4378fb90db39f09c7b18d1f314e645, dropped-by-remus, exe. Reporter: Bitsight. First seen: 2026-09-23 23:40:44.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
c64a9aaa58707c34f0569020880351cb
IOC database
- Type
- hash_imphash
- Value
c64a9aaa58707c34f0569020880351cb- First seen
- Last seen
- Attached to this threat
- Appears in
- 639 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
e0b566f6434bc418ab3d8dea59e574338b22a15d66123fe1fb2b4438e27eb18a
IOC database
- Type
- hash_sha256
- Value
e0b566f6434bc418ab3d8dea59e574338b22a15d66123fe1fb2b4438e27eb18a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
dcc883080a5fd00c7a51f726f99a949a06cfd525
IOC database
- Type
- hash_sha1
- Value
dcc883080a5fd00c7a51f726f99a949a06cfd525- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
41427b5b868d3cd11f6da742be20e104
IOC database
- Type
- hash_md5
- Value
41427b5b868d3cd11f6da742be20e104- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 15360 bytes. Tags: 5a4378fb90db39f09c7b18d1f314e645, dropped-by-remus, exe. Reporter: Bitsight. First seen: 2026-09-23 23:40:44.
Remediations (10)
-
web:learn.microsoft.com
Configure what Microsoft Defender Antivirus should do when it detects a threat, and how long quarantined files should be retained in the quarantine folder.
-
web:learn.microsoft.com
Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.
-
web:microsoft.github.io
This capability supports the "Assume Breach" principle of Zero Trust by ensuring continuous detection and mitigation of weaknesses. Reference Remediate machine vulnerability findings - Microsoft Defender for Cloud Vulnerability scanning in Defender for Servers Remediate vulnerabilities with Microsoft Defender Vulnerability Management
-
web:orca.security
Microsoft patches CVE-2026-21509, a high-severity Office zero-day actively exploited in the wild. Learn about the OLE bypass, affected versions, and remediation .
-
web:research.checkpoint.com
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 - without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full […]
-
web:windowsforum.com
Microsoft's February Patch Tuesday closed a dangerous loophole in the modern Notepad app that could let an attacker turn a simple Markdown (.md) file into a remote code execution (RCE) trap — a single click on a crafted link inside Notepad's Markdown view could launch unverified protocols and cause arbitrary code to run with the user's privileges. (msrc.microsoft.com) Background ...
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.herodevs.com
Understand CVE-2026-66066: a critical RCE vulnerability in Ruby on Rails Active Storage. Learn how an unsafe libvips default enables arbitrary file read and how to secure your application.
-
web:www.rescana.com
Active exploitation of CVE-2026-21509 has been confirmed by both Microsoft and the Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability's addition to the CISA KEV catalog underscores its criticality and the urgency of remediation . Observed tactics, techniques, and procedures (TTPs) include the delivery of malicious Office documents via phishing and spear-phishing ...
-
web:www.sentinelone.com
A vulnerability remediation program helps you identify, analyze, prioritize, and eliminate security weaknesses before cyber attackers could exploit them.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.