s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-80d5c57843523754b5fce827c12d3c922810f2175a8d6189ef944e294c76d49c high

📛 Threat Title

Unknown: file

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 11270656 bytes. Tags: A, dropped-by-GCleaner, exe, MIX5.file. Reporter: Bitsight. First seen: 2026-09-25 09:31:20.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 80d5c57843523754b5fce827c12d3c922810f2175a8d6189ef944e294c76d49c VT 12 / 75

IOC database

Type
hash_sha256
Value
80d5c57843523754b5fce827c12d3c922810f2175a8d6189ef944e294c76d49c
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 12 of 75 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan/Win64.GenKryptik
CrowdStrike malicious win/malicious_confidence_60% (D)
Cylance malicious Unsafe
Elastic malicious malicious (high confidence)
ESET-NOD32 malicious Win64/GenKryptik.HVED trojan
GData malicious Win64.Trojan.Agent.PYRCXY
Google malicious Detected
Malwarebytes malicious Malware.AI.1200155471
Microsoft malicious Trojan:Win32/Wacatac.B!ml
Rising malicious Stealer.Agensla!8.13266 (TFE:3:CXIrhBgY1SO)
TrellixENS malicious Artemis!9926FEB76C3B
Varist malicious W64/ABmRisk.GCDD-4769

Details From VirusTotal

Basic Properties
MD59926feb76c3bf72ea7131a3588c42b80
SHA-1922c1d22bfe3e81e801debcb399efd03c1f2c199
SHA-25680d5c57843523754b5fce827c12d3c922810f2175a8d6189ef944e294c76d49c
VHash017076556d755d0555503041z104004b7z27z2011z903dz
SSDEEP98304:bFLdkOHX+g6k2DE7+aQGpkKQxsHPe/GnU90YJdRV8rxcZjM:bFOs+gq8pXQoPG10YJ7V8r2Z
TLSHT1CFB62E21D12C02D5F82BF3BF4AC93FF96A143B28A134141DA7DE55936102EABA7F5385
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size10.7 MB
History
Creation date2017-11-19 03:45 UTC
First seen on VirusTotal2026-09-25 09:31 UTC
Last submission2026-09-25 10:16 UTC
Last analysis2026-09-25 20:09 UTC
Last modified on VirusTotal2026-09-25 22:10 UTC
Known Names
  • fairitineraryplus.exe
  • fairitineraryplus
  • 3shou.exe
hash_sha1 922c1d22bfe3e81e801debcb399efd03c1f2c199 VT 12 / 75

IOC database

Type
hash_sha1
Value
922c1d22bfe3e81e801debcb399efd03c1f2c199
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 12 of 75 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan/Win64.GenKryptik
CrowdStrike malicious win/malicious_confidence_60% (D)
Cylance malicious Unsafe
Elastic malicious malicious (high confidence)
ESET-NOD32 malicious Win64/GenKryptik.HVED trojan
GData malicious Win64.Trojan.Agent.PYRCXY
Google malicious Detected
Malwarebytes malicious Malware.AI.1200155471
Microsoft malicious Trojan:Win32/Wacatac.B!ml
Rising malicious Stealer.Agensla!8.13266 (TFE:3:CXIrhBgY1SO)
TrellixENS malicious Artemis!9926FEB76C3B
Varist malicious W64/ABmRisk.GCDD-4769

Details From VirusTotal

Basic Properties
MD59926feb76c3bf72ea7131a3588c42b80
SHA-1922c1d22bfe3e81e801debcb399efd03c1f2c199
SHA-25680d5c57843523754b5fce827c12d3c922810f2175a8d6189ef944e294c76d49c
VHash017076556d755d0555503041z104004b7z27z2011z903dz
SSDEEP98304:bFLdkOHX+g6k2DE7+aQGpkKQxsHPe/GnU90YJdRV8rxcZjM:bFOs+gq8pXQoPG10YJ7V8r2Z
TLSHT1CFB62E21D12C02D5F82BF3BF4AC93FF96A143B28A134141DA7DE55936102EABA7F5385
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size10.7 MB
History
Creation date2017-11-19 03:45 UTC
First seen on VirusTotal2026-09-25 09:31 UTC
Last submission2026-09-25 10:16 UTC
Last analysis2026-09-25 20:09 UTC
Last modified on VirusTotal2026-09-25 22:10 UTC
Known Names
  • fairitineraryplus.exe
  • fairitineraryplus
  • 3shou.exe
hash_md5 9926feb76c3bf72ea7131a3588c42b80 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/9926feb76c3bf72ea7131a3588c42b80

IOC database

Type
hash_md5
Value
9926feb76c3bf72ea7131a3588c42b80
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/9926feb76c3bf72ea7131a3588c42b80

hash_imphash 1442464b7105ce91b566f9ce1f47b75c

IOC database

Type
hash_imphash
Value
1442464b7105ce91b566f9ce1f47b75c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 11270656 bytes. Tags: A, dropped-by-GCleaner, exe, MIX5.file. Reporter: Bitsight. First seen: 2026-09-25 09:31:20.

Remediations (9)

  • web:github.com

    RedSun — Technical Analysis Summary RedSun exploits a logic flaw in Windows Defender's file remediation path (MpSvc.dll). When Defender detects a malicious file with Cloud Files attributes, it attempts to restore the file to its original detection path without validating whether that path has been redirected via a junction point.

  • web:learn.microsoft.com

    Configure what Microsoft Defender Antivirus should do when it detects a threat, and how long quarantined files should be retained in the quarantine folder.

  • web:learn.microsoft.com

    Take response actions on file -related alerts by stopping and quarantining a file or blocking a file and checking activity details.

  • web:mimecastsupport.zendesk.com

    Threat Remediation allows: Automatic remediation of any newly found, zero-day attachment-based malware detected in your users' mailboxes, leveraging global threat intelligence to continuously monitor files post-delivery.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:windowsforum.com

    Microsoft's February Patch Tuesday closed a dangerous loophole in the modern Notepad app that could let an attacker turn a simple Markdown (.md) file into a remote code execution (RCE) trap — a single click on a crafted link inside Notepad's Markdown view could launch unverified protocols and cause arbitrary code to run with the user's privileges. (msrc.microsoft.com) Background ...

  • web:www.bitdefender.com

    Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.

  • web:www.crowdstrike.com

    Here, we can see the details of the remediation actions, such as any files quarantined, processes killed, and registry values deleted. We can also release any quarantined files as well. When we navigate to remediation , a list of all the remediation activities across the entire organization is available.

  • web:www.harness.io

    Vulnerability remediation vs mitigation : clear definitions, when to choose each, and how both fit inside a risk-based vulnerability management program.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.