MB-e39cc7e781577bb4e9ab68cd0817030e107b3ccc3e49df2f0ee75e2aac2cf4ad
high
📛 Threat Title
Unknown: wethhist.org_42134006_onedrive-update.exe
Description
File type: exe. Size: 23040 bytes. Reporter: mgoku. First seen: 2026-05-20 04:06:38.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
update.exe
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/update.exe
IOC database
- Type
- domain
- Value
update.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-e39cc7e781577bb4e9ab68cd0817030e107b3ccc3e49df2f0ee75e2aac2cf4ad
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/update.exe
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 647 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
e39cc7e781577bb4e9ab68cd0817030e107b3ccc3e49df2f0ee75e2aac2cf4ad
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/e39cc7e781577bb4e9ab68cd0817030e107b3ccc3e49df2f0ee75e2aac2cf4ad
IOC database
- Type
- hash_sha256
- Value
e39cc7e781577bb4e9ab68cd0817030e107b3ccc3e49df2f0ee75e2aac2cf4ad- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/e39cc7e781577bb4e9ab68cd0817030e107b3ccc3e49df2f0ee75e2aac2cf4ad
hash_sha1
8f4be15ed4cb2962983b8270b88ad060eb2eab5a
VT 48 / 75
IOC database
- Type
- hash_sha1
- Value
8f4be15ed4cb2962983b8270b88ad060eb2eab5a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 48 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win32.RL_Coinminer.C3480319 |
| Alibaba | malicious | Trojan:MSIL/NanoCore.1f9a51f3 |
| alibabacloud | malicious | Trojan[dropper]:MSIL/NanoCore.Q |
| ALYac | malicious | Gen:Variant.Ransom.Agent.26 |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Ransom.Agent.26 |
| Avast | malicious | MSIL:Tiny-C [Trj] |
| AVG | malicious | MSIL:Tiny-C [Trj] |
| Avira | malicious | TR/Dropper.Gen |
| BitDefender | malicious | Gen:Variant.Ransom.Agent.26 |
| Bkav | malicious | W32.Malware.7FF4812C |
| ClamAV | malicious | Win.Trojan.Barys-1 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.ransomware.generic |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.InjectNET.14 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Gen:Variant.Ransom.Agent.26 (B) |
| ESET-NOD32 | malicious | MSIL/NanoCore.Q trojan |
| F-Secure | malicious | Trojan.TR/Dropper.Gen |
| Fortinet | malicious | MSIL/Injector.CKF!tr |
| GData | malicious | Gen:Variant.Ransom.Agent.26 |
| malicious | Detected |
|
| huorong | malicious | HEUR:Trojan/MSIL.Injector.a |
| Ikarus | malicious | Win32.Outbreak |
| Kaspersky | malicious | HEUR:Trojan.Win32.Generic |
| Kingsoft | malicious | malware.kb.c.1000 |
| Lionic | malicious | Trojan.Win32.Generic.4!c |
| McAfeeD | malicious | Real Protect-LS!F4701C74E8F6 |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Gen:Variant.Ransom.Agent.26 |
| Paloalto | malicious | generic.ml |
| Rising | malicious | Backdoor.LiteHttpBot!1.B709 (CLASSIC) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | GenericRXFD-CA!F4701C74E8F6 |
| Sophos | malicious | Mal/MSIL-AZ |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Win32.Trojan.Generic.Psmw |
| Trapmine | malicious | suspicious.low.ml.score |
| TrellixENS | malicious | GenericRXFD-CA!F4701C74E8F6 |
| TrendMicro | malicious | TROJ_NETBOT.SMA |
| TrendMicro-HouseCall | malicious | TROJ_NETBOT.SMA |
| VIPRE | malicious | Gen:Variant.Ransom.Agent.26 |
| VirIT | malicious | Trojan.Win32.MSIL_Heur.A |
| Xcitium | malicious | TrojWare.MSIL.NanoCore.Q@8a8gsw |
| ZoneAlarm | malicious | Mal/MSIL-AZ |
Details From VirusTotal
Basic Properties
| MD5 | f4701c74e8f64ee14e7a4aef9539f6d8 |
| SHA-1 | 8f4be15ed4cb2962983b8270b88ad060eb2eab5a |
| SHA-256 | e39cc7e781577bb4e9ab68cd0817030e107b3ccc3e49df2f0ee75e2aac2cf4ad |
| VHash | 22403655151d0a6ee0020 |
| SSDEEP | 384:b4zd9rh29OPLSabEQ6d0dyVwTlDCjPOhZwlk90goJc8b:b4zd9rs9uGabj6ducPc903 |
| TLSH | T1F3A23A05F7D98314E6FD8B79ACB713444172F24B9807EB9E0CDA905E6A763A0C710FA6 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 22.5 KB |
History
| Creation date | 2026-05-20 02:38 UTC |
| First seen on VirusTotal | 2026-05-20 04:06 UTC |
| Last submission | 2026-05-20 04:06 UTC |
| Last analysis | 2026-05-20 06:03 UTC |
| Last modified on VirusTotal | 2026-05-21 06:26 UTC |
Known Names
wethhist.org_onedrive-update.exewethhist.org_42134006_onedrive-update.exefxpbk9.exe
hash_md5
f4701c74e8f64ee14e7a4aef9539f6d8
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/f4701c74e8f64ee14e7a4aef9539f6d8
IOC database
- Type
- hash_md5
- Value
f4701c74e8f64ee14e7a4aef9539f6d8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/f4701c74e8f64ee14e7a4aef9539f6d8
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 23040 bytes. Reporter: mgoku. First seen: 2026-05-20 04:06:38.
Remediations (8)
-
web:any.run
Online sandbox report for OneDrive.exe, verdict: Malicious activity
-
web:learn.microsoft.com
It seems you're encountering a High Risk recommendation from Microsoft Defender regarding outdated OpenSSL libraries associated with older OneDrive versions installed on your server. This can definitely be concerning, but I'm happy to guide you through some potential options to remediate this. Here's what you can consider doing: Update OneDrive: The quickest remediation might be to update ...
-
web:onedrive.live.com
Login to OneDrive with your Microsoft or Office 365 account.
-
web:support.microsoft.com
Learn about fixes and workarounds for the latest OneDrive issues.
-
web:thehackernews.com
Discover the latest OneDrive phishing scam targeting users worldwide. Learn how cybercriminals exploit social engineering to spread malware through cl
-
web:www.askwoody.com
A better description is that that OneDrive.exe was updated at the time I allowed the KB5044285 update to be processed. I am on the Current channel for Microsoft 365 family subscription.
-
web:www.microsoft.com
Submit a file for malware analysis Microsoft security researchers analyze suspicious files to determine if they are threats, unwanted applications, or normal files. Submit files you think are malware or files that you believe have been incorrectly classified as malware. For more information, read the submission guidelines.
-
web:www.techradar.com
Pro Security Watch out — that Microsoft OneDrive security warning could actually be a malware scam News By Sead Fadilpašić published July 30, 2024
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.