s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3 high

📛 Threat Title

Unknown: file

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 48640 bytes. Tags: D, dropped-by-GCleaner, EU0.file, exe. Reporter: Bitsight. First seen: 2026-05-20 23:43:20.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain eu0.file VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/eu0.file (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

IOC database

Type
domain
Value
eu0.file
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/eu0.file (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
647 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3 VT 43 / 75

IOC database

Type
hash_sha256
Value
4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 43 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win32.RL_Generic.C4300960
alibabacloud malicious Trojan[downloader]:Win/Wacatac.B9nj
Antiy-AVL malicious Trojan/MSIL.Cobalt
APEX malicious Malicious
Arcabit malicious Trojan.Generic.D4C74229
Avast malicious FileRepMalware [Misc]
AVG malicious FileRepMalware [Misc]
Avira malicious TR/W32.Malware
BitDefender malicious Trojan.GenericKD.80167465
Bkav malicious W32.Malware.2A9C1680
CAT-QuickHeal malicious Trojan.Generic.TRFH1565
CrowdStrike malicious win/malicious_confidence_70% (W)
CTX malicious exe.trojan.cobalt
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.80167465 (B)
ESET-NOD32 malicious PowerShell/TrojanDownloader.Agent.QOG trojan
F-Secure malicious Trojan.TR/W32.Malware
Fortinet malicious PossibleThreat
GData malicious Win32.Trojan.Agent.1GLB91
Google malicious Detected
Kaspersky malicious Trojan.MSIL.Cobalt.uz
Kingsoft malicious malware.kb.c.666
Lionic malicious Trojan.Win32.Cobalt.4!c
Malwarebytes malicious Generic.Malware/Suspicious
MaxSecure malicious Trojan.Malware.685585295.susgen
McAfeeD malicious ti!4D2F99C36E0E
Microsoft malicious Trojan:Win32/Kepavll!rfn
MicroWorld-eScan malicious Trojan.GenericKD.80167465
Paloalto malicious generic.ml
Panda malicious Trj/Agent.EVL
Rising malicious Trojan.Cobalt!8.C4EF (LESS:bWQ1OqwkS0rWiFN+)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious BehavesLike.Win32.Infected.pm
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.MBT
Tencent malicious Win32.Trojan-Downloader.Downloader.Mqil
Trapmine malicious malicious.high.ml.score
TrellixENS malicious Artemis!7F7DB47BC48F
TrendMicro-HouseCall malicious Trojan.MSIL.Gen.TL0101EM26ZZ
Varist malicious W32/MSIL_Agent.HYO.gen!Eldorado

Details From VirusTotal

Basic Properties
MD57f7db47bc48f9463042600fb437d2eb6
SHA-195b6094747032fc7f8efabc5430118a4fd453e95
SHA-2564d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3
VHash2440365515114072603f5083
SSDEEP768:WCIFqetUhFKNB0Xo86I21Z3lCFQXoJXbOfq1ok55l:WC4qeCF6BTv1Z3lCFQgbOq55l
TLSHT1D723A486679887EED6AE4DFD1025261300F2C2663D2AD3C9EED1455FB43FB403A257B2
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size47.5 KB
History
Creation date2026-05-15 19:02 UTC
First seen on VirusTotal2026-05-20 23:43 UTC
Last submission2026-05-21 04:19 UTC
Last analysis2026-05-22 16:21 UTC
Last modified on VirusTotal2026-05-25 19:22 UTC
Known Names
  • gmail.enc.exe
  • 4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe
  • _4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe
  • l6hbu.exe
hash_sha1 95b6094747032fc7f8efabc5430118a4fd453e95 VT 43 / 75

IOC database

Type
hash_sha1
Value
95b6094747032fc7f8efabc5430118a4fd453e95
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 43 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win32.RL_Generic.C4300960
alibabacloud malicious Trojan[downloader]:Win/Wacatac.B9nj
Antiy-AVL malicious Trojan/MSIL.Cobalt
APEX malicious Malicious
Arcabit malicious Trojan.Generic.D4C74229
Avast malicious FileRepMalware [Misc]
AVG malicious FileRepMalware [Misc]
Avira malicious TR/W32.Malware
BitDefender malicious Trojan.GenericKD.80167465
Bkav malicious W32.Malware.2A9C1680
CAT-QuickHeal malicious Trojan.Generic.TRFH1565
CrowdStrike malicious win/malicious_confidence_70% (W)
CTX malicious exe.trojan.cobalt
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.80167465 (B)
ESET-NOD32 malicious PowerShell/TrojanDownloader.Agent.QOG trojan
F-Secure malicious Trojan.TR/W32.Malware
Fortinet malicious PossibleThreat
GData malicious Win32.Trojan.Agent.1GLB91
Google malicious Detected
Kaspersky malicious Trojan.MSIL.Cobalt.uz
Kingsoft malicious malware.kb.c.666
Lionic malicious Trojan.Win32.Cobalt.4!c
Malwarebytes malicious Generic.Malware/Suspicious
MaxSecure malicious Trojan.Malware.685585295.susgen
McAfeeD malicious ti!4D2F99C36E0E
Microsoft malicious Trojan:Win32/Kepavll!rfn
MicroWorld-eScan malicious Trojan.GenericKD.80167465
Paloalto malicious generic.ml
Panda malicious Trj/Agent.EVL
Rising malicious Trojan.Cobalt!8.C4EF (LESS:bWQ1OqwkS0rWiFN+)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious BehavesLike.Win32.Infected.pm
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.MBT
Tencent malicious Win32.Trojan-Downloader.Downloader.Mqil
Trapmine malicious malicious.high.ml.score
TrellixENS malicious Artemis!7F7DB47BC48F
TrendMicro-HouseCall malicious Trojan.MSIL.Gen.TL0101EM26ZZ
Varist malicious W32/MSIL_Agent.HYO.gen!Eldorado

Details From VirusTotal

Basic Properties
MD57f7db47bc48f9463042600fb437d2eb6
SHA-195b6094747032fc7f8efabc5430118a4fd453e95
SHA-2564d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3
VHash2440365515114072603f5083
SSDEEP768:WCIFqetUhFKNB0Xo86I21Z3lCFQXoJXbOfq1ok55l:WC4qeCF6BTv1Z3lCFQgbOq55l
TLSHT1D723A486679887EED6AE4DFD1025261300F2C2663D2AD3C9EED1455FB43FB403A257B2
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size47.5 KB
History
Creation date2026-05-15 19:02 UTC
First seen on VirusTotal2026-05-20 23:43 UTC
Last submission2026-05-21 04:19 UTC
Last analysis2026-05-22 16:21 UTC
Last modified on VirusTotal2026-05-25 19:22 UTC
Known Names
  • gmail.enc.exe
  • 4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe
  • _4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe
  • l6hbu.exe
hash_md5 7f7db47bc48f9463042600fb437d2eb6 VT 43 / 75

IOC database

Type
hash_md5
Value
7f7db47bc48f9463042600fb437d2eb6
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 43 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Malware/Win32.RL_Generic.C4300960
alibabacloud malicious Trojan[downloader]:Win/Wacatac.B9nj
Antiy-AVL malicious Trojan/MSIL.Cobalt
APEX malicious Malicious
Arcabit malicious Trojan.Generic.D4C74229
Avast malicious FileRepMalware [Misc]
AVG malicious FileRepMalware [Misc]
Avira malicious TR/W32.Malware
BitDefender malicious Trojan.GenericKD.80167465
Bkav malicious W32.Malware.2A9C1680
CAT-QuickHeal malicious Trojan.Generic.TRFH1565
CrowdStrike malicious win/malicious_confidence_70% (W)
CTX malicious exe.trojan.cobalt
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.80167465 (B)
ESET-NOD32 malicious PowerShell/TrojanDownloader.Agent.QOG trojan
F-Secure malicious Trojan.TR/W32.Malware
Fortinet malicious PossibleThreat
GData malicious Win32.Trojan.Agent.1GLB91
Google malicious Detected
Kaspersky malicious Trojan.MSIL.Cobalt.uz
Kingsoft malicious malware.kb.c.666
Lionic malicious Trojan.Win32.Cobalt.4!c
Malwarebytes malicious Generic.Malware/Suspicious
MaxSecure malicious Trojan.Malware.685585295.susgen
McAfeeD malicious ti!4D2F99C36E0E
Microsoft malicious Trojan:Win32/Kepavll!rfn
MicroWorld-eScan malicious Trojan.GenericKD.80167465
Paloalto malicious generic.ml
Panda malicious Trj/Agent.EVL
Rising malicious Trojan.Cobalt!8.C4EF (LESS:bWQ1OqwkS0rWiFN+)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious BehavesLike.Win32.Infected.pm
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.MBT
Tencent malicious Win32.Trojan-Downloader.Downloader.Mqil
Trapmine malicious malicious.high.ml.score
TrellixENS malicious Artemis!7F7DB47BC48F
TrendMicro-HouseCall malicious Trojan.MSIL.Gen.TL0101EM26ZZ
Varist malicious W32/MSIL_Agent.HYO.gen!Eldorado

Details From VirusTotal

Basic Properties
MD57f7db47bc48f9463042600fb437d2eb6
SHA-195b6094747032fc7f8efabc5430118a4fd453e95
SHA-2564d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3
VHash2440365515114072603f5083
SSDEEP768:WCIFqetUhFKNB0Xo86I21Z3lCFQXoJXbOfq1ok55l:WC4qeCF6BTv1Z3lCFQgbOq55l
TLSHT1D723A486679887EED6AE4DFD1025261300F2C2663D2AD3C9EED1455FB43FB403A257B2
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size47.5 KB
History
Creation date2026-05-15 19:02 UTC
First seen on VirusTotal2026-05-20 23:43 UTC
Last submission2026-05-21 04:19 UTC
Last analysis2026-05-22 16:21 UTC
Last modified on VirusTotal2026-05-25 19:22 UTC
Known Names
  • gmail.enc.exe
  • 4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe
  • _4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe
  • l6hbu.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 48640 bytes. Tags: D, dropped-by-GCleaner, EU0.file, exe. Reporter: Bitsight. First seen: 2026-05-20 23:43:20.

Remediations (8)

  • web:blackswan-cybersecurity.com

    Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.

  • web:blog.qualys.com

    How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.

  • web:blog.rsisecurity.com

    Risk mitigation for widespread malware infection Implementing effective policies for malware remediation processes will strengthen your organization's malware protection. Best Practices for Malware Eradication Eradication of infected malware is critical to restoring normal business operations, especially for critical systems or applications.

  • web:docs.trendmicro.com

    Use Predictive Machine Learning to detect unknown or low-prevalence malware. For more information, see Predictive Machine Learning. Predictive Machine Learning uses the Advanced Threat Scan Engine (ATSE) to extract file features and sends the report to the Predictive Machine Learning engine on the Trend Micro Smart Protection Network.

  • web:learn.microsoft.com

    Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:learn.microsoft.com

    Take response actions on file -related alerts by stopping and quarantining a file or blocking a file and checking activity details.

  • web:sc1.checkpoint.com

    Analysis & Remediation Automated Attack Analysis (Forensics) Endpoint Security Forensics analyzes attacks detected by other detection features like Anti-Ransomware or Behavioral Guard, and some third-party security products. On detection of a malicious event or file , Forensics is informed and a Forensics analysis is automatically initiated. After the analysis is completed, the entire attack ...

  • web:www.cisa.gov

    General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.