MB-dfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed
high
📛 Threat Title
Unknown: dfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed.exe
Description
File type: exe. Size: 4994282 bytes. Tags: exe. Reporter: Tuxxin. First seen: 2026-09-25 12:09:27.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
46ce5c12b293febbeb513b196aa7f843
IOC database
- Type
- hash_imphash
- Value
46ce5c12b293febbeb513b196aa7f843- First seen
- Last seen
- Attached to this threat
- Appears in
- 14 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
dfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed
VT 3 / 75
IOC database
- Type
- hash_sha256
- Value
dfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| APEX | malicious | Malicious |
| Cylance | malicious | Unsafe |
| Sophos | malicious | Generic ML PUA (PUA) |
Details From VirusTotal
Basic Properties
| MD5 | faa72c741a4cba77eccdc425e5556fe0 |
| SHA-1 | dbb18532be5764730a4d1fc59825de86fbf0ccb0 |
| SHA-256 | dfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed |
| VHash | 046056655d1c0550c043z800417z57z52z4gz |
| SSDEEP | 98304:98JAkwBMH8xiaI7PTj25G6JFyiwfxyO1YnfZvUkjjJ/kuehHB:9y7cUdPfoNJFiEOCfFUkPZk |
| TLSH | T11D36338483D09F93EF3BDB75197E0244BFA8C62A3965110B1BC9B76C78416879BD84F8 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| File size | 4.8 MB |
History
| Creation date | 2025-03-08 23:05 UTC |
| First seen on VirusTotal | 2026-09-25 11:15 UTC |
| Last submission | 2026-09-25 14:00 UTC |
| Last analysis | 2026-09-25 11:15 UTC |
| Last modified on VirusTotal | 2026-09-25 23:22 UTC |
Known Names
u6110k.exedfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed.exetu8cq261.exePaneMark_0.3.3_x64-setup.exe
hash_sha1
dbb18532be5764730a4d1fc59825de86fbf0ccb0
VT 3 / 75
IOC database
- Type
- hash_sha1
- Value
dbb18532be5764730a4d1fc59825de86fbf0ccb0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| APEX | malicious | Malicious |
| Cylance | malicious | Unsafe |
| Sophos | malicious | Generic ML PUA (PUA) |
Details From VirusTotal
Basic Properties
| MD5 | faa72c741a4cba77eccdc425e5556fe0 |
| SHA-1 | dbb18532be5764730a4d1fc59825de86fbf0ccb0 |
| SHA-256 | dfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed |
| VHash | 046056655d1c0550c043z800417z57z52z4gz |
| SSDEEP | 98304:98JAkwBMH8xiaI7PTj25G6JFyiwfxyO1YnfZvUkjjJ/kuehHB:9y7cUdPfoNJFiEOCfFUkPZk |
| TLSH | T11D36338483D09F93EF3BDB75197E0244BFA8C62A3965110B1BC9B76C78416879BD84F8 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| File size | 4.8 MB |
History
| Creation date | 2025-03-08 23:05 UTC |
| First seen on VirusTotal | 2026-09-25 11:15 UTC |
| Last submission | 2026-09-25 14:00 UTC |
| Last analysis | 2026-09-25 11:15 UTC |
| Last modified on VirusTotal | 2026-09-25 23:22 UTC |
Known Names
u6110k.exedfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed.exetu8cq261.exePaneMark_0.3.3_x64-setup.exe
hash_md5
faa72c741a4cba77eccdc425e5556fe0
VT 3 / 75
IOC database
- Type
- hash_md5
- Value
faa72c741a4cba77eccdc425e5556fe0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| APEX | malicious | Malicious |
| Cylance | malicious | Unsafe |
| Sophos | malicious | Generic ML PUA (PUA) |
Details From VirusTotal
Basic Properties
| MD5 | faa72c741a4cba77eccdc425e5556fe0 |
| SHA-1 | dbb18532be5764730a4d1fc59825de86fbf0ccb0 |
| SHA-256 | dfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed |
| VHash | 046056655d1c0550c043z800417z57z52z4gz |
| SSDEEP | 98304:98JAkwBMH8xiaI7PTj25G6JFyiwfxyO1YnfZvUkjjJ/kuehHB:9y7cUdPfoNJFiEOCfFUkPZk |
| TLSH | T11D36338483D09F93EF3BDB75197E0244BFA8C62A3965110B1BC9B76C78416879BD84F8 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| File size | 4.8 MB |
History
| Creation date | 2025-03-08 23:05 UTC |
| First seen on VirusTotal | 2026-09-25 11:15 UTC |
| Last submission | 2026-09-25 14:00 UTC |
| Last analysis | 2026-09-25 11:15 UTC |
| Last modified on VirusTotal | 2026-09-25 23:22 UTC |
Known Names
u6110k.exedfd648a590b649e47d5dda5ecd10235fca95684f3b8cb64f12def4cefb856bed.exetu8cq261.exePaneMark_0.3.3_x64-setup.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 4994282 bytes. Tags: exe. Reporter: Tuxxin. First seen: 2026-09-25 12:09:27.
Remediations (8)
-
web:learn.microsoft.com
Here are a few steps you can take to try to identify and deal with the unknown app in Windows 11: Check Task Manager: Right-click on the taskbar and select Task Manager. Look for any unfamiliar processes in the Processes tab. Right-click on these processes and select Open File Location to determine their source. Scan for malware:
-
web:learn.microsoft.com
I have an "Account Unknown" in my User Profiles. There are no numbers after it. I understand that Windows often has hidden accounts to perform various administrative tasks. I would like to see about deleting it, because this post…
-
web:maclookup.app
Fast and easy MAC address lookup on IEEE directory and Wireshark manufacturer database. Search vendor, manufacturer or organization of a device by MAC/OUI address. Fast REST API
-
web:malwaretips.com
This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.
-
web:recoverit.wondershare.com
How to resolve an unknown USB device? To address the problem, uninstall the Unknown USB Device (Device Descriptor Request Failed) Windows and then reinstall them. To reinstall the USB drivers, follow these steps: Access the Device Manager by pressing Win + X and choosing Device Manager. Expand the Universal Serial Bus controllers category.
-
web:www.macvendorlookup.com
MAC Address Lookup Enter any MAC address, OUI, or IAB below to lookup the manufacturer, location, and more
-
web:www.speedguide.net
SG MAC Address OUI Search About the SG MAC Address lookup tool The MAC Adderss OUI search helps identify unknown devices on your local network by simply typing their MAC address (or its OUI prefix), commonly listed by your NAT/Wireless router. It can be useful in identifying network adapter manufacturers, IoT devices, wireless clients, etc. MAC address (media access control address) is a ...
-
web:www.whatsmyip.org
MAC Address Lookups, search by full address, OUI prefix or by vendor name. Database updated daily.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.