s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-5baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0 high

📛 Threat Title

Unknown: file

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 2599584 bytes. Tags: A, dropped-by-GCleaner, exe, PMIX0.file, signed. Reporter: Bitsight. First seen: 2026-05-14 11:05:49.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain pmix0.file VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/pmix0.file

IOC database

Type
domain
Value
pmix0.file
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-5baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/pmix0.file

hash_sha256 5baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/5baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0
1 feed

IOC database

Type
hash_sha256
Value
5baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/5baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0

hash_sha1 99e3dcc3b41e2022a310d91952581fbb83c91f4a VT 23 / 75 1 feed

IOC database

Type
hash_sha1
Value
99e3dcc3b41e2022a310d91952581fbb83c91f4a
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 23 of 75 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan/Win64.MALD2
Avast malicious MalwareX-gen [Bd]
AVG malicious MalwareX-gen [Bd]
Avira malicious BDS/W64.MalwareX
Bkav malicious W32.Malware.55D87C7B
CrowdStrike malicious win/malicious_confidence_90% (W)
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.80128727 (B)
ESET-NOD32 malicious Generik.LBNNXVN trojan
F-Secure malicious Backdoor.BDS/W64.MalwareX
Fortinet malicious W64/MALD2.3659!tr
GData malicious Win32.Malware.KillAV.Z0PFFK@gen
Google malicious Detected
huorong malicious Trojan/W64.Obfuscated.h!crit
Ikarus malicious Trojan.WinGo.Crypt
Kaspersky malicious Backdoor.Win64.AdaptixC2.bvy
McAfeeD malicious ti!5BAA0E116CC1
Microsoft malicious Trojan:Win32/Wacatac.B!ml
Paloalto malicious generic.ml
Rising malicious Trojan.Obfuscated!8.4C (CLOUD)
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
Varist malicious W64/ABmRisk.KKGE-3660

Details From VirusTotal

Basic Properties
MD598df79320b346b1559dd396964eccc41
SHA-199e3dcc3b41e2022a310d91952581fbb83c91f4a
SHA-2565baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0
VHash026086657d15551d15541az2e!z
SSDEEP49152:QQo/+5F1JDr9+5UJj6AW1HcNNbR7mVZKDQLm2FD4JZLjYrFcK/7wwBtxxDWfJfc2:Q5WFNCLiIWKnQf3
TLSHT13BC58C07B8A144FAD4BDA231997A30047E61B8482B7533C32EA57BBC2F3A7D05C76756
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size2.5 MB
History
First seen on VirusTotal2026-05-14 11:05 UTC
Last submission2026-05-14 11:08 UTC
Last analysis2026-05-15 03:11 UTC
Last modified on VirusTotal2026-05-29 13:05 UTC
Known Names
  • 5baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0.exe
  • gx9l7Ktpwa.exe
  • g9r0iy.exe
  • _5baa0e116cc110d7232ace92d612f92cba0a97e1ec6c0125bab8bd0452f06ed0.exe
hash_md5 98df79320b346b1559dd396964eccc41 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/98df79320b346b1559dd396964eccc41
2 feeds

IOC database

Type
hash_md5
Value
98df79320b346b1559dd396964eccc41
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/98df79320b346b1559dd396964eccc41

hash_imphash d42595b695fc008ef2c56aabd8efd68e

IOC database

Type
hash_imphash
Value
d42595b695fc008ef2c56aabd8efd68e
First seen
Last seen
Attached to this threat
Appears in
469 threats
Description
imphash of URLhaus payload a7b9f3dda435b7f2…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 2599584 bytes. Tags: A, dropped-by-GCleaner, exe, PMIX0.file, signed. Reporter: Bitsight. First seen: 2026-05-14 11:05:49.

Remediations (10)

  • web:blackswan-cybersecurity.com

    Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.

  • web:blog.qualys.com

    How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.

  • web:docs.trendmicro.com

    Use Predictive Machine Learning to detect unknown or low-prevalence malware. For more information, see Predictive Machine Learning. Predictive Machine Learning uses the Advanced Threat Scan Engine (ATSE) to extract file features and sends the report to the Predictive Machine Learning engine on the Trend Micro Smart Protection Network.

  • web:learn.microsoft.com

    Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:learn.microsoft.com

    Take response actions on file -related alerts by stopping and quarantining a file or blocking a file and checking activity details.

  • web:learn.microsoft.com

    Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.

  • web:mimecastsupport.zendesk.com

    Threat Remediation allows: Automatic remediation of any newly found, zero-day attachment-based malware detected in your users' mailboxes, leveraging global threat intelligence to continuously monitor files post-delivery.

  • web:sc1.checkpoint.com

    Analysis & Remediation Automated Attack Analysis (Forensics) Endpoint Security Forensics analyzes attacks detected by other detection features like Anti-Ransomware or Behavioral Guard, and some third-party security products. On detection of a malicious event or file , Forensics is informed and a Forensics analysis is automatically initiated. After the analysis is completed, the entire attack ...

  • web:www.bitdefender.com

    Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.

  • web:www.cisa.gov

    General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
1 / 1
IPs scored
0 / 0
Flagged
1
IndicatorTypeVerdictScore
pmix0.file domain high 44