MB-1ae69db09035542cafb9ae06eb1e85858743973541e894dfb3a5158ac848d1e0
high
📛 Threat Title
Unknown: CrossDNS_Setup.exe
Description
File type: exe. Size: 3329448 bytes. Tags: dropper, exe, miner, signed. Reporter: Alex_sev. First seen: 2026-08-04 18:23:20.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
88016fcdef7f227c62171d0afad9aae4
IOC database
- Type
- hash_imphash
- Value
88016fcdef7f227c62171d0afad9aae4- First seen
- Last seen
- Attached to this threat
- Appears in
- 68 threats
- Description
- imphash of URLhaus payload 5f76fc369f3f759a…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
1ae69db09035542cafb9ae06eb1e85858743973541e894dfb3a5158ac848d1e0
IOC database
- Type
- hash_sha256
- Value
1ae69db09035542cafb9ae06eb1e85858743973541e894dfb3a5158ac848d1e0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
429e9744e6d080edffa42b55e3d33a177daf9855
IOC database
- Type
- hash_sha1
- Value
429e9744e6d080edffa42b55e3d33a177daf9855- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
0d3bd4a4f60c63cbb01837ce81800b42
IOC database
- Type
- hash_md5
- Value
0d3bd4a4f60c63cbb01837ce81800b42- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 3329448 bytes. Tags: dropper, exe, miner, signed. Reporter: Alex_sev. First seen: 2026-08-04 18:23:20.
Remediations (10)
-
web:cybersecuritynews.com
A new evolution in the ClickFix social engineering campaign, which now employs a custom DNS hijacking technique to deliver malware.
-
web:github.com
Ready-to-use Microsoft Intune Endpoint Analytics Proactive Remediation detection and remediation scripts. - JayRHa/EndpointAnalyticsRemediationScripts
-
web:github.com
Tool to publish lan discovery to remote dns zones (or perform other mad operations) - rtreffer/crossdns
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:learn.microsoft.com
Learn more about Remediations in Microsoft Intune, including what Remediations are and view any prerequisites and licensing requirements. Also, learn how to deploy built-in and custom remediation scripts, and learn how to monitor your scripts.
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what happened and why. For some samples and an introduction to ...
-
web:www.acquisition.gov
(a) Definition. "Modification," as used in this subpart, means a minor change in the details of a provision or clause that is specifically authorized by the FAR and does not alter
-
web:www.microsoft.com
The ClickFix social engineering technique has been growing in popularity, with campaigns targeting thousands of enterprise and end-user devices daily. This technique exploits users' tendency to resolve technical issues by tricking them into running malicious commands. These commands, in turn, deliver payloads that ultimately lead to information theft and exfiltration.
-
web:www.microsoft.com
Threat actors are abusing external Microsoft Teams collaboration to impersonate IT helpdesk staff and convince users to grant remote access. Once inside, attackers can abuse legitimate tools and standard admin protocols to move laterally and exfiltrate data while appearing as routine IT support—activity Microsoft Defender helps detect across Teams, endpoint, and identity telemetry.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.