s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-1ae69db09035542cafb9ae06eb1e85858743973541e894dfb3a5158ac848d1e0 high

📛 Threat Title

Unknown: CrossDNS_Setup.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3329448 bytes. Tags: dropper, exe, miner, signed. Reporter: Alex_sev. First seen: 2026-08-04 18:23:20.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 88016fcdef7f227c62171d0afad9aae4

IOC database

Type
hash_imphash
Value
88016fcdef7f227c62171d0afad9aae4
First seen
Last seen
Attached to this threat
Appears in
68 threats
Description
imphash of URLhaus payload 5f76fc369f3f759a…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 1ae69db09035542cafb9ae06eb1e85858743973541e894dfb3a5158ac848d1e0

IOC database

Type
hash_sha256
Value
1ae69db09035542cafb9ae06eb1e85858743973541e894dfb3a5158ac848d1e0
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 429e9744e6d080edffa42b55e3d33a177daf9855

IOC database

Type
hash_sha1
Value
429e9744e6d080edffa42b55e3d33a177daf9855
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 0d3bd4a4f60c63cbb01837ce81800b42

IOC database

Type
hash_md5
Value
0d3bd4a4f60c63cbb01837ce81800b42
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 3329448 bytes. Tags: dropper, exe, miner, signed. Reporter: Alex_sev. First seen: 2026-08-04 18:23:20.

Remediations (10)

  • web:cybersecuritynews.com

    A new evolution in the ClickFix social engineering campaign, which now employs a custom DNS hijacking technique to deliver malware.

  • web:github.com

    Ready-to-use Microsoft Intune Endpoint Analytics Proactive Remediation detection and remediation scripts. - JayRHa/EndpointAnalyticsRemediationScripts

  • web:github.com

    Tool to publish lan discovery to remote dns zones (or perform other mad operations) - rtreffer/crossdns

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Learn more about Remediations in Microsoft Intune, including what Remediations are and view any prerequisites and licensing requirements. Also, learn how to deploy built-in and custom remediation scripts, and learn how to monitor your scripts.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what happened and why. For some samples and an introduction to ...

  • web:www.acquisition.gov

    (a) Definition. "Modification," as used in this subpart, means a minor change in the details of a provision or clause that is specifically authorized by the FAR and does not alter

  • web:www.microsoft.com

    The ClickFix social engineering technique has been growing in popularity, with campaigns targeting thousands of enterprise and end-user devices daily. This technique exploits users' tendency to resolve technical issues by tricking them into running malicious commands. These commands, in turn, deliver payloads that ultimately lead to information theft and exfiltration.

  • web:www.microsoft.com

    Threat actors are abusing external Microsoft Teams collaboration to impersonate IT helpdesk staff and convince users to grant remote access. Once inside, attackers can abuse legitimate tools and standard admin protocols to move laterally and exfiltrate data while appearing as routine IT support—activity Microsoft Defender helps detect across Teams, endpoint, and identity telemetry.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.