MB-8c7a57bd6fb1c20e61c50a120ed5a92bea042e28b4ffe4255155816dbcbf91fd
high
📛 Threat Title
Unknown: file
Description
File type: exe. Size: 2926080 bytes. Tags: C, dropped-by-GCleaner, exe, MIX6.file. Reporter: Bitsight. First seen: 2026-05-14 09:59:35.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
mix6.file
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/mix6.file
IOC database
- Type
- domain
- Value
mix6.file- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- Extracted from Threat MB-c574b3c0a63ae972441cf84819edb1b8f3addfec6f051e8989a443d95cdeae04
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/mix6.file
hash_sha256
8c7a57bd6fb1c20e61c50a120ed5a92bea042e28b4ffe4255155816dbcbf91fd
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8c7a57bd6fb1c20e61c50a120ed5a92bea042e28b4ffe4255155816dbcbf91fd
1 feed
IOC database
- Type
- hash_sha256
- Value
8c7a57bd6fb1c20e61c50a120ed5a92bea042e28b4ffe4255155816dbcbf91fd- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8c7a57bd6fb1c20e61c50a120ed5a92bea042e28b4ffe4255155816dbcbf91fd
hash_sha1
f9fac11c82f63ce5d8e4af1641ed708a5065bae0
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f9fac11c82f63ce5d8e4af1641ed708a5065bae0
2 feeds
IOC database
- Type
- hash_sha1
- Value
f9fac11c82f63ce5d8e4af1641ed708a5065bae0- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/f9fac11c82f63ce5d8e4af1641ed708a5065bae0
hash_md5
b00643dd8b7e51def536d7722f5294bf
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/b00643dd8b7e51def536d7722f5294bf
2 feeds
IOC database
- Type
- hash_md5
- Value
b00643dd8b7e51def536d7722f5294bf- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/b00643dd8b7e51def536d7722f5294bf
hash_imphash
f7b51bb735b2e71ce456f116dafd834a
IOC database
- Type
- hash_imphash
- Value
f7b51bb735b2e71ce456f116dafd834a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 2926080 bytes. Tags: C, dropped-by-GCleaner, exe, MIX6.file. Reporter: Bitsight. First seen: 2026-05-14 09:59:35.
Remediations (10)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
-
web:blog.qualys.com
How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.
-
web:docs.trendmicro.com
Use Predictive Machine Learning to detect unknown or low-prevalence malware. For more information, see Predictive Machine Learning. Predictive Machine Learning uses the Advanced Threat Scan Engine (ATSE) to extract file features and sends the report to the Predictive Machine Learning engine on the Trend Micro Smart Protection Network.
-
web:learn.microsoft.com
Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:learn.microsoft.com
Take response actions on file -related alerts by stopping and quarantining a file or blocking a file and checking activity details.
-
web:learn.microsoft.com
Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.
-
web:mimecastsupport.zendesk.com
Threat Remediation allows: Automatic remediation of any newly found, zero-day attachment-based malware detected in your users' mailboxes, leveraging global threat intelligence to continuously monitor files post-delivery.
-
web:sc1.checkpoint.com
Analysis & Remediation Automated Attack Analysis (Forensics) Endpoint Security Forensics analyzes attacks detected by other detection features like Anti-Ransomware or Behavioral Guard, and some third-party security products. On detection of a malicious event or file , Forensics is informed and a Forensics analysis is automatically initiated. After the analysis is completed, the entire attack ...
-
web:www.bitdefender.com
Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.
-
web:www.cisa.gov
General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.