MB-4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3
high
📛 Threat Title
Unknown: file
Description
File type: exe. Size: 48640 bytes. Tags: D, dropped-by-GCleaner, EU0.file, exe. Reporter: Bitsight. First seen: 2026-05-20 23:43:20.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
eu0.file
VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/eu0.file (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
IOC database
- Type
- domain
- Value
eu0.file- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/eu0.file (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 647 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3
VT 43 / 75
IOC database
- Type
- hash_sha256
- Value
4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 43 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win32.RL_Generic.C4300960 |
| alibabacloud | malicious | Trojan[downloader]:Win/Wacatac.B9nj |
| Antiy-AVL | malicious | Trojan/MSIL.Cobalt |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.D4C74229 |
| Avast | malicious | FileRepMalware [Misc] |
| AVG | malicious | FileRepMalware [Misc] |
| Avira | malicious | TR/W32.Malware |
| BitDefender | malicious | Trojan.GenericKD.80167465 |
| Bkav | malicious | W32.Malware.2A9C1680 |
| CAT-QuickHeal | malicious | Trojan.Generic.TRFH1565 |
| CrowdStrike | malicious | win/malicious_confidence_70% (W) |
| CTX | malicious | exe.trojan.cobalt |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.80167465 (B) |
| ESET-NOD32 | malicious | PowerShell/TrojanDownloader.Agent.QOG trojan |
| F-Secure | malicious | Trojan.TR/W32.Malware |
| Fortinet | malicious | PossibleThreat |
| GData | malicious | Win32.Trojan.Agent.1GLB91 |
| malicious | Detected |
|
| Kaspersky | malicious | Trojan.MSIL.Cobalt.uz |
| Kingsoft | malicious | malware.kb.c.666 |
| Lionic | malicious | Trojan.Win32.Cobalt.4!c |
| Malwarebytes | malicious | Generic.Malware/Suspicious |
| MaxSecure | malicious | Trojan.Malware.685585295.susgen |
| McAfeeD | malicious | ti!4D2F99C36E0E |
| Microsoft | malicious | Trojan:Win32/Kepavll!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericKD.80167465 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/Agent.EVL |
| Rising | malicious | Trojan.Cobalt!8.C4EF (LESS:bWQ1OqwkS0rWiFN+) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | BehavesLike.Win32.Infected.pm |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Win32.Trojan-Downloader.Downloader.Mqil |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!7F7DB47BC48F |
| TrendMicro-HouseCall | malicious | Trojan.MSIL.Gen.TL0101EM26ZZ |
| Varist | malicious | W32/MSIL_Agent.HYO.gen!Eldorado |
Details From VirusTotal
Basic Properties
| MD5 | 7f7db47bc48f9463042600fb437d2eb6 |
| SHA-1 | 95b6094747032fc7f8efabc5430118a4fd453e95 |
| SHA-256 | 4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3 |
| VHash | 2440365515114072603f5083 |
| SSDEEP | 768:WCIFqetUhFKNB0Xo86I21Z3lCFQXoJXbOfq1ok55l:WC4qeCF6BTv1Z3lCFQgbOq55l |
| TLSH | T1D723A486679887EED6AE4DFD1025261300F2C2663D2AD3C9EED1455FB43FB403A257B2 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 47.5 KB |
History
| Creation date | 2026-05-15 19:02 UTC |
| First seen on VirusTotal | 2026-05-20 23:43 UTC |
| Last submission | 2026-05-21 04:19 UTC |
| Last analysis | 2026-05-22 16:21 UTC |
| Last modified on VirusTotal | 2026-05-25 19:22 UTC |
Known Names
gmail.enc.exe4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe_4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exel6hbu.exe
hash_sha1
95b6094747032fc7f8efabc5430118a4fd453e95
VT 43 / 75
IOC database
- Type
- hash_sha1
- Value
95b6094747032fc7f8efabc5430118a4fd453e95- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 43 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win32.RL_Generic.C4300960 |
| alibabacloud | malicious | Trojan[downloader]:Win/Wacatac.B9nj |
| Antiy-AVL | malicious | Trojan/MSIL.Cobalt |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.D4C74229 |
| Avast | malicious | FileRepMalware [Misc] |
| AVG | malicious | FileRepMalware [Misc] |
| Avira | malicious | TR/W32.Malware |
| BitDefender | malicious | Trojan.GenericKD.80167465 |
| Bkav | malicious | W32.Malware.2A9C1680 |
| CAT-QuickHeal | malicious | Trojan.Generic.TRFH1565 |
| CrowdStrike | malicious | win/malicious_confidence_70% (W) |
| CTX | malicious | exe.trojan.cobalt |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.80167465 (B) |
| ESET-NOD32 | malicious | PowerShell/TrojanDownloader.Agent.QOG trojan |
| F-Secure | malicious | Trojan.TR/W32.Malware |
| Fortinet | malicious | PossibleThreat |
| GData | malicious | Win32.Trojan.Agent.1GLB91 |
| malicious | Detected |
|
| Kaspersky | malicious | Trojan.MSIL.Cobalt.uz |
| Kingsoft | malicious | malware.kb.c.666 |
| Lionic | malicious | Trojan.Win32.Cobalt.4!c |
| Malwarebytes | malicious | Generic.Malware/Suspicious |
| MaxSecure | malicious | Trojan.Malware.685585295.susgen |
| McAfeeD | malicious | ti!4D2F99C36E0E |
| Microsoft | malicious | Trojan:Win32/Kepavll!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericKD.80167465 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/Agent.EVL |
| Rising | malicious | Trojan.Cobalt!8.C4EF (LESS:bWQ1OqwkS0rWiFN+) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | BehavesLike.Win32.Infected.pm |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Win32.Trojan-Downloader.Downloader.Mqil |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!7F7DB47BC48F |
| TrendMicro-HouseCall | malicious | Trojan.MSIL.Gen.TL0101EM26ZZ |
| Varist | malicious | W32/MSIL_Agent.HYO.gen!Eldorado |
Details From VirusTotal
Basic Properties
| MD5 | 7f7db47bc48f9463042600fb437d2eb6 |
| SHA-1 | 95b6094747032fc7f8efabc5430118a4fd453e95 |
| SHA-256 | 4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3 |
| VHash | 2440365515114072603f5083 |
| SSDEEP | 768:WCIFqetUhFKNB0Xo86I21Z3lCFQXoJXbOfq1ok55l:WC4qeCF6BTv1Z3lCFQgbOq55l |
| TLSH | T1D723A486679887EED6AE4DFD1025261300F2C2663D2AD3C9EED1455FB43FB403A257B2 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 47.5 KB |
History
| Creation date | 2026-05-15 19:02 UTC |
| First seen on VirusTotal | 2026-05-20 23:43 UTC |
| Last submission | 2026-05-21 04:19 UTC |
| Last analysis | 2026-05-22 16:21 UTC |
| Last modified on VirusTotal | 2026-05-25 19:22 UTC |
Known Names
gmail.enc.exe4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe_4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exel6hbu.exe
hash_md5
7f7db47bc48f9463042600fb437d2eb6
VT 43 / 75
IOC database
- Type
- hash_md5
- Value
7f7db47bc48f9463042600fb437d2eb6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 43 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Malware/Win32.RL_Generic.C4300960 |
| alibabacloud | malicious | Trojan[downloader]:Win/Wacatac.B9nj |
| Antiy-AVL | malicious | Trojan/MSIL.Cobalt |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.D4C74229 |
| Avast | malicious | FileRepMalware [Misc] |
| AVG | malicious | FileRepMalware [Misc] |
| Avira | malicious | TR/W32.Malware |
| BitDefender | malicious | Trojan.GenericKD.80167465 |
| Bkav | malicious | W32.Malware.2A9C1680 |
| CAT-QuickHeal | malicious | Trojan.Generic.TRFH1565 |
| CrowdStrike | malicious | win/malicious_confidence_70% (W) |
| CTX | malicious | exe.trojan.cobalt |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.80167465 (B) |
| ESET-NOD32 | malicious | PowerShell/TrojanDownloader.Agent.QOG trojan |
| F-Secure | malicious | Trojan.TR/W32.Malware |
| Fortinet | malicious | PossibleThreat |
| GData | malicious | Win32.Trojan.Agent.1GLB91 |
| malicious | Detected |
|
| Kaspersky | malicious | Trojan.MSIL.Cobalt.uz |
| Kingsoft | malicious | malware.kb.c.666 |
| Lionic | malicious | Trojan.Win32.Cobalt.4!c |
| Malwarebytes | malicious | Generic.Malware/Suspicious |
| MaxSecure | malicious | Trojan.Malware.685585295.susgen |
| McAfeeD | malicious | ti!4D2F99C36E0E |
| Microsoft | malicious | Trojan:Win32/Kepavll!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericKD.80167465 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/Agent.EVL |
| Rising | malicious | Trojan.Cobalt!8.C4EF (LESS:bWQ1OqwkS0rWiFN+) |
| Sangfor | malicious | Suspicious.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | BehavesLike.Win32.Infected.pm |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.MBT |
| Tencent | malicious | Win32.Trojan-Downloader.Downloader.Mqil |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!7F7DB47BC48F |
| TrendMicro-HouseCall | malicious | Trojan.MSIL.Gen.TL0101EM26ZZ |
| Varist | malicious | W32/MSIL_Agent.HYO.gen!Eldorado |
Details From VirusTotal
Basic Properties
| MD5 | 7f7db47bc48f9463042600fb437d2eb6 |
| SHA-1 | 95b6094747032fc7f8efabc5430118a4fd453e95 |
| SHA-256 | 4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3 |
| VHash | 2440365515114072603f5083 |
| SSDEEP | 768:WCIFqetUhFKNB0Xo86I21Z3lCFQXoJXbOfq1ok55l:WC4qeCF6BTv1Z3lCFQgbOq55l |
| TLSH | T1D723A486679887EED6AE4DFD1025261300F2C2663D2AD3C9EED1455FB43FB403A257B2 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 47.5 KB |
History
| Creation date | 2026-05-15 19:02 UTC |
| First seen on VirusTotal | 2026-05-20 23:43 UTC |
| Last submission | 2026-05-21 04:19 UTC |
| Last analysis | 2026-05-22 16:21 UTC |
| Last modified on VirusTotal | 2026-05-25 19:22 UTC |
Known Names
gmail.enc.exe4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exe_4d2f99c36e0e68851dfa890a0af7ce9fed7afdc7de3b03c7bd186e38aca2fab3.exel6hbu.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 48640 bytes. Tags: D, dropped-by-GCleaner, EU0.file, exe. Reporter: Bitsight. First seen: 2026-05-20 23:43:20.
Remediations (8)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
-
web:blog.qualys.com
How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.
-
web:blog.rsisecurity.com
Risk mitigation for widespread malware infection Implementing effective policies for malware remediation processes will strengthen your organization's malware protection. Best Practices for Malware Eradication Eradication of infected malware is critical to restoring normal business operations, especially for critical systems or applications.
-
web:docs.trendmicro.com
Use Predictive Machine Learning to detect unknown or low-prevalence malware. For more information, see Predictive Machine Learning. Predictive Machine Learning uses the Advanced Threat Scan Engine (ATSE) to extract file features and sends the report to the Predictive Machine Learning engine on the Trend Micro Smart Protection Network.
-
web:learn.microsoft.com
Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:learn.microsoft.com
Take response actions on file -related alerts by stopping and quarantining a file or blocking a file and checking activity details.
-
web:sc1.checkpoint.com
Analysis & Remediation Automated Attack Analysis (Forensics) Endpoint Security Forensics analyzes attacks detected by other detection features like Anti-Ransomware or Behavioral Guard, and some third-party security products. On detection of a malicious event or file , Forensics is informed and a Forensics analysis is automatically initiated. After the analysis is completed, the entire attack ...
-
web:www.cisa.gov
General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.