s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-5170053acce4fe85e58ad8311bf54d54926e72489d9a7d36ec2caa2c07faea2c high

📛 Threat Title

Unknown: 5170053acce4fe85e58ad8311bf54d54926e72489d9a7d36ec2caa2c07faea2c

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 8721920 bytes. Tags: exe, Gansu-Shishida-Information-Technology-Co-Ltd, signed. Reporter: JAMESWT_WT. First seen: 2026-05-15 06:43:08.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash dddd95789c6d117404c7c3c56ab141f3

IOC database

Type
hash_imphash
Value
dddd95789c6d117404c7c3c56ab141f3
First seen
Last seen
Attached to this threat
Appears in
10 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 5170053acce4fe85e58ad8311bf54d54926e72489d9a7d36ec2caa2c07faea2c 1 feed

IOC database

Type
hash_sha256
Value
5170053acce4fe85e58ad8311bf54d54926e72489d9a7d36ec2caa2c07faea2c
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 94d64eb09883c817b422f680bbc57d3ea0f7f09d VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/94d64eb09883c817b422f680bbc57d3ea0f7f09d
1 feed

IOC database

Type
hash_sha1
Value
94d64eb09883c817b422f680bbc57d3ea0f7f09d
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/94d64eb09883c817b422f680bbc57d3ea0f7f09d

hash_md5 933c67a74d1b47c2679233fc7975fc68 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/933c67a74d1b47c2679233fc7975fc68
1 feed

IOC database

Type
hash_md5
Value
933c67a74d1b47c2679233fc7975fc68
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/933c67a74d1b47c2679233fc7975fc68

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 8721920 bytes. Tags: exe, Gansu-Shishida-Information-Technology-Co-Ltd, signed. Reporter: JAMESWT_WT. First seen: 2026-05-15 06:43:08.

Remediations (10)

  • web:askubuntu.com

    9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.

  • web:learn.microsoft.com

    Learn about the AADSTS error codes that are returned from the Microsoft Entra security token service (STS).

  • web:maclookup.app

    Fast and easy MAC address lookup on IEEE directory and Wireshark manufacturer database. Search vendor, manufacturer or organization of a device by MAC/OUI address. Fast REST API

  • web:miniwebtool.com

    MAC Address Lookup - Instantly identify network device manufacturers and vendors by MAC address. Search by full or partial MAC address, or look up MAC prefixes by company name with our comprehensive OUI database.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]

  • web:windowsforum.com

    Microsoft's Security Update Guide is the canonical place to verify which specific Windows builds and KBs include the fix for CVE-2025-53803; the general remediation pattern for kernel information-disclosure CVEs is: vendor advisory → cumulative update or security-only KB → distribution via Windows Update/WSUS and the Microsoft Update Catalog.

  • web:www.17track.net

    Enter your tracking number to track Unknown packages and get real-time updates on delivery status. Discover more about FQAs in this guide on Unknown tracking.

  • web:www.esd.whs.mil

    Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.

  • web:www.reddit.com

    Pulling my hair out for this one. What's happening- When I deploy a VPP app (Microsoft Teams for example) and scope it to all users with user license…

  • web:www.stocktitan.net

    The CISO supervises both our internal cybersecurity personnel and our retained managed service providers, who among other things, operate security tooling that is deployed in the IT environment and monitor the prevention, detection, mitigation and remediation of cybersecurity incidents.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.