MB-417759d58ed424b4a6af6be1472107b959b8125b9a3fa1e0b6072f76849cf180
high
📛 Threat Title
Unknown: 20260514_182031_quickwebdevops_courses_417759d58e.dat
Description
File type: exe. Size: 7744864 bytes. Tags: ClearFake, exe, signed. Reporter: anonymous. First seen: 2026-05-14 18:51:51.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
417759d58ed424b4a6af6be1472107b959b8125b9a3fa1e0b6072f76849cf180
1 feed
IOC database
- Type
- hash_sha256
- Value
417759d58ed424b4a6af6be1472107b959b8125b9a3fa1e0b6072f76849cf180- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
682fecac4d9e6586ff8558dd61d136293834219b
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/682fecac4d9e6586ff8558dd61d136293834219b
1 feed
IOC database
- Type
- hash_sha1
- Value
682fecac4d9e6586ff8558dd61d136293834219b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/682fecac4d9e6586ff8558dd61d136293834219b
hash_md5
0a14dff035f4808abaf976e0e231f195
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0a14dff035f4808abaf976e0e231f195
1 feed
IOC database
- Type
- hash_md5
- Value
0a14dff035f4808abaf976e0e231f195- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0a14dff035f4808abaf976e0e231f195
hash_imphash
d6c19ce52e7a53024dfe85f4bb02cea9
IOC database
- Type
- hash_imphash
- Value
d6c19ce52e7a53024dfe85f4bb02cea9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 7744864 bytes. Tags: ClearFake, exe, signed. Reporter: anonymous. First seen: 2026-05-14 18:51:51.
Remediations (10)
-
web:askubuntu.com
9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:forums.prajwaldesai.com
Good afternoon, Just got SCCM 1802 up and running and have pushed clients to a couple of computers. The client installs and I can see the configuration manager in the control panel. In the client activity in the console I can see it checking for policy requests and doing hardware scans. But when I look at the General Information I get the Client check result is FAILED and Remediation is FAIL ...
-
web:github.com
This repository contains PowerShell scripts and supporting files to detect, remove, and optionally schedule a reboot when uninstalling McAfee products in a Windows environment. These scripts are designed primarily for use with Microsoft Intune or SCCM, but they can be adapted to other deployment tools.
-
web:learn.microsoft.com
Learn about the AADSTS error codes that are returned from the Microsoft Entra security token service (STS).
-
web:my.f5.com
By default, the HTTP profile Known Methods contains a list of the most common HTTP request methods, including TRACE, and the Unknown Method option is set to Allow, which allows all methods regardless of whether they are known.
-
web:owasp.org
Certain classes of errors should be logged to help detect implementation flaws in the site and/or hacking attempts. Very few sites have any intrusion detection capabilities in their web application, but it is certainly conceivable that a web application could track repeated failed attempts and generate alerts.
-
web:support.managementstudio.com
TABLE OF CONTENTS Introduction Symptoms Cause Identify Affected Machines Remediation Step 1 Step 2 Step 3 Step 4 Verify the Fix Resources Introduction ManagementStudio collects data from Microsoft System Center Configuration Manager (SCCM) regarding application and hardware usage to assess user and application readiness during migrations. Issues with SCCM agents may not be apparent until data ...
-
web:threatfox.abuse.ch
ClearFake IOC: quickwebdevops.courses (domain) You are viewing the ThreatFox database entry for domain quickwebdevops.courses.
-
web:www.reddit.com
This is the remediation we're using. Luckily the devices were still syncing remediations even though Intune was saying they're not checking in. Ensure the script is set to run in 64bit Powershell Detection (Also adds additional information to the remediation output to assist troubleshooting)
-
web:www.reddit.com
If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.