MB-4794369d13f654f8e7d5865733d21e0c34607672c14c3c058846e782ffe118fa
high
📛 Threat Title
Unknown: file
Description
File type: exe. Size: 2934272 bytes. Tags: 81a64890ca97bd87f0c9d35bc6501f4d, dropped-by-remus, exe. Reporter: Bitsight. First seen: 2026-08-04 20:12:25.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
f5bec796b7b3c2932293afa8281cdeed
IOC database
- Type
- hash_imphash
- Value
f5bec796b7b3c2932293afa8281cdeed- First seen
- Last seen
- Attached to this threat
- Appears in
- 18 threats
- Description
- imphash of URLhaus payload 91361016c42d3ebc…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
4794369d13f654f8e7d5865733d21e0c34607672c14c3c058846e782ffe118fa
IOC database
- Type
- hash_sha256
- Value
4794369d13f654f8e7d5865733d21e0c34607672c14c3c058846e782ffe118fa- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
b03709ce79d8d1870a80a07f6208c9ed97f1fec6
IOC database
- Type
- hash_sha1
- Value
b03709ce79d8d1870a80a07f6208c9ed97f1fec6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
1cb5cb6866494b92d87b79827d26f2f7
IOC database
- Type
- hash_md5
- Value
1cb5cb6866494b92d87b79827d26f2f7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 2934272 bytes. Tags: 81a64890ca97bd87f0c9d35bc6501f4d, dropped-by-remus, exe. Reporter: Bitsight. First seen: 2026-08-04 20:12:25.
Remediations (10)
-
web:learn.microsoft.com
Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:learn.microsoft.com
Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:windowsforum.com
Microsoft's February Patch Tuesday closed a dangerous loophole in the modern Notepad app that could let an attacker turn a simple Markdown (.md) file into a remote code execution (RCE) trap — a single click on a crafted link inside Notepad's Markdown view could launch unverified protocols and...
-
web:www.acquisition.gov
(a) Definition. "Modification," as used in this subpart, means a minor change in the details of a provision or clause that is specifically authorized by the FAR and does not alter
-
web:www.bugcrowd.com
Mitigation solutions include isolating a set of vulnerable resources from the rest of the network with segmentation, temporarily disabling an application, or blocking a port that could provide access to a vulnerable resource. Your choice usually isn't a straightforward either/or decision between vulnerability remediation and mitigation .
-
web:www.cisa.gov
General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.
-
web:www.crowdstrike.com
Here, we can see the details of the remediation actions, such as any files quarantined, processes killed, and registry values deleted. We can also release any quarantined files as well. When we navigate to remediation , a list of all the remediation activities across the entire organization is available.
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.sonicwall.com
NOTE: The "Last Download Date" indicates when the preferences file was last downloaded (via MySonicWall or firewall UI) or is blank if the date is unknown . If the file was not downloaded on any specified date by the administrator, please take immediate action and follow the remediation steps outlined in the articles.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.