s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-f0cea16aa110cfa3a45be700377d19ab17510a8a148a042609cd6e06ca88f8a3 high

📛 Threat Title

Unknown: 20260513_150830_federated-runtime-network_wiki_f0cea16aa1.dat

Category: Unknown First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 7231976 bytes. Tags: ClearFake, exe, signed. Reporter: anonymous. First seen: 2026-05-13 20:26:37.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 2d1a2a3b2edbe3e08125b43db0ee5897

IOC database

Type
hash_imphash
Value
2d1a2a3b2edbe3e08125b43db0ee5897
First seen
Last seen
Attached to this threat
Appears in
3 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 f0cea16aa110cfa3a45be700377d19ab17510a8a148a042609cd6e06ca88f8a3 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f0cea16aa110cfa3a45be700377d19ab17510a8a148a042609cd6e06ca88f8a3
1 feed

IOC database

Type
hash_sha256
Value
f0cea16aa110cfa3a45be700377d19ab17510a8a148a042609cd6e06ca88f8a3
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f0cea16aa110cfa3a45be700377d19ab17510a8a148a042609cd6e06ca88f8a3

hash_sha1 2462c3da56be1e707d2c82c890d4ad763dc3f111 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2462c3da56be1e707d2c82c890d4ad763dc3f111
2 feeds

IOC database

Type
hash_sha1
Value
2462c3da56be1e707d2c82c890d4ad763dc3f111
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2462c3da56be1e707d2c82c890d4ad763dc3f111

hash_md5 006b71a7c851bcca51e58132d58d7046 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/006b71a7c851bcca51e58132d58d7046
2 feeds

IOC database

Type
hash_md5
Value
006b71a7c851bcca51e58132d58d7046
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/006b71a7c851bcca51e58132d58d7046

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 7231976 bytes. Tags: ClearFake, exe, signed. Reporter: anonymous. First seen: 2026-05-13 20:26:37.

Remediations (10)

  • web:community.citrix.com

    hi I deployed xenapp 7.14.1 with FAS for SAML sso adn storefront 3.11 (all latest version); everything works fine for domain users in domain A (where all the servers live); but users in domain B after sso-ing into storefront cannot open apps. I've already applied this fix for different domain use...

  • web:forums.prajwaldesai.com

    Good afternoon, Just got SCCM 1802 up and running and have pushed clients to a couple of computers. The client installs and I can see the configuration manager in the control panel. In the client activity in the console I can see it checking for policy requests and doing hardware scans. But when I look at the General Information I get the Client check result is FAILED and Remediation is FAIL ...

  • web:github.com

    Describe the bug Tried to run Federated runtime with tls enabled. During the federation run, system is picking random port and system hostname as fqdn instead of assigned port-50050 and fqdn-localh...

  • web:help.zscaler.com

    The Remediation job did not run because you have exceeded the maximum number of Remediation jobs. Wait to complete the other Remediation jobs and then re-run the job. To learn more, see Ranges & Limitations. Script execution failed due to Script Orchestrator Service is not started or unavailable. ZUPM_WORKFLOW_ECODE_SCRIPT_ORCHESTRATOR_RPC_FAILURE

  • web:learn.microsoft.com

    This page lists recent known issues with Microsoft Intune. For a list of weekly feature announcements, see What's new in Microsoft Intune in the Intune product documentation. Visit the Intune Customer Success blog for posts about best practices, support tips, and other tutorials, and a backlog of past known issues.

  • web:scloud.work

    Summary Troubleshooting Intune proactive remediation scripts locally saves time and reduces uncertainty. You get full visibility into the script files, logs and registry data. With this approach, I can test, debug and optimize scripts before pushing them to production.

  • web:support.microsoft.com

    The detection script collects Secure Boot and certificate status from each device and reports it back to the Intune portal — no remediation action is taken on devices. This gives administrators a centralized, exportable view of certificate update progress across their Intune enrolled Windows devices. Why use this approach?

  • web:techcommunity.microsoft.com

    Device Remediation status misleading Maybe I'm just missing something here, but when a Remediation script repeats on a schedule, how can we tell if devices were remediated? All devices report "Without Issues" and ZERO devices fixed, but I know the script ran and fixed the problem weeks ago. Say I have 100 devices assigned to the script:

  • web:www.reddit.com

    When sending a remediation script out to devices, what are the check-in requirements and other requirements for a machine to run that remediation script? The script that I'm working with is a simple detection/ remediation that updates a program. I have pushed it out to all devices to run at frequency "once" on two separate occasions.

  • web:www.reddit.com

    If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.