MB-31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b
high
📛 Threat Title
Unknown: file
Description
File type: exe. Size: 2067072 bytes. Tags: C, dropped-by-GCleaner, exe, MIX1.file, signed. Reporter: Bitsight. First seen: 2026-05-14 13:58:22.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
mix1.file
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/mix1.file
IOC database
- Type
- domain
- Value
mix1.file- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Extracted from Threat MB-95a22e67b75eea2ba37141a3681177d2a48fed51727bcd292444205afc02130f
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/mix1.file
hash_imphash
d42595b695fc008ef2c56aabd8efd68e
IOC database
- Type
- hash_imphash
- Value
d42595b695fc008ef2c56aabd8efd68e- First seen
- Last seen
- Attached to this threat
- Appears in
- 465 threats
- Description
- imphash of URLhaus payload a7b9f3dda435b7f2…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b
VT 33 / 74
1 feed
IOC database
- Type
- hash_sha256
- Value
31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 33 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R770656 |
| Alibaba | malicious | Backdoor:Win64/Kryptik.cee33218 |
| Avast | malicious | Win64:Evo-gen [Trj] |
| AVG | malicious | Win64:Evo-gen [Trj] |
| Avira | malicious | TR/W64.Evo |
| Bkav | malicious | W32.Malware.E3ACBDC8 |
| CrowdStrike | malicious | win/malicious_confidence_90% (W) |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | WinGo/Kryptik.PL trojan |
| F-Secure | malicious | Trojan.TR/W64.Evo |
| Fortinet | malicious | W64/MALD2.3659!tr |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Agent.sa |
| huorong | malicious | Trojan/W64.Obfuscated.h!crit |
| Ikarus | malicious | Trojan.WinGo.Crypt |
| K7AntiVirus | malicious | Trojan ( 006de6a71 ) |
| K7GW | malicious | Trojan ( 006de6a71 ) |
| Kaspersky | malicious | UDS:Backdoor.Win64.Gsb.aya |
| Kingsoft | malicious | Win64.Backdoor.Gsb.gen |
| Lionic | malicious | Trojan.Win32.Agent.Y!c |
| Malwarebytes | malicious | Malware.AI.2832754406 |
| McAfeeD | malicious | ti!31AB874B4635 |
| Microsoft | malicious | Trojan:Win32/Wacatac.B!ml |
| Paloalto | malicious | generic.ml |
| Rising | malicious | Backdoor.Agent!8.C5D (CLOUD) |
| Sangfor | malicious | Trojan.Win32.Evo.Vvo9 |
| Skyhigh | malicious | Artemis!Trojan |
| Sophos | malicious | Mal/Generic-S |
| Tencent | malicious | Win32.Trojan.FalseSign.Zchl |
| TrellixENS | malicious | Artemis!021C6CBFC905 |
| Varist | malicious | W64/Agent.MDZ.gen!Eldorado |
Details From VirusTotal
Basic Properties
| MD5 | 021c6cbfc905f7c10c932ba4d5ab5f11 |
| SHA-1 | 2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d |
| SHA-256 | 31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b |
| VHash | 026086656d15551d15545az2e!z |
| SSDEEP | 24576:Pt57QzXRkzDS5dijhdSALwXLHj9mMyA1bcV9y9xeKIxdIMrbFhele5n923ql4ZV0:PtVIRkC5ditAAO9m9A1bO9y9wHLDcrQ |
| TLSH | T1F8A57C5B7C9144F6D4AAA33388B761827BB1F8480B3223D72E50A6783F767D4AD79704 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 2.0 MB |
History
| First seen on VirusTotal | 2026-05-14 13:58 UTC |
| Last submission | 2026-05-14 14:05 UTC |
| Last analysis | 2026-05-14 18:02 UTC |
| Last modified on VirusTotal | 2026-05-20 16:18 UTC |
Known Names
31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b.exe_31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b.exerbtgiznp.exe
hash_sha1
2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d
2 feeds
IOC database
- Type
- hash_sha1
- Value
2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d
hash_md5
021c6cbfc905f7c10c932ba4d5ab5f11
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/021c6cbfc905f7c10c932ba4d5ab5f11
2 feeds
IOC database
- Type
- hash_md5
- Value
021c6cbfc905f7c10c932ba4d5ab5f11- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/021c6cbfc905f7c10c932ba4d5ab5f11
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 2067072 bytes. Tags: C, dropped-by-GCleaner, exe, MIX1.file, signed. Reporter: Bitsight. First seen: 2026-05-14 13:58:22.
Remediations (10)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
-
web:blog.qualys.com
How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.
-
web:learn.microsoft.com
Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:mimecastsupport.zendesk.com
Threat Remediation allows: Automatic remediation of any newly found, zero-day attachment-based malware detected in your users' mailboxes, leveraging global threat intelligence to continuously monitor files post-delivery.
-
web:windowsforum.com
CISA's decision to add two recently disclosed flaws — a WinRAR path‑traversal bug (CVE-2025-6218) and a Windows Cloud Files mini‑filter use‑after‑free (CVE-2025-62221) — to the Known Exploited Vulnerabilities (KEV) Catalog crystallizes a simple reality for defenders: time-to-fix is shrinking and the federal remediation clock is unforgiving. The technical facts are straightforward ...
-
web:www.bitdefender.com
Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.
-
web:www.cisa.gov
General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.
-
web:www.crowdstrike.com
Remediate faster Execute built-in commands or custom scripts to easily carry out complex remediation actions on any managed endpoint remotely. Connect to and quickly isolate the impacted endpoint, then remove malicious files to immediately shut down the attack.
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.sonicwall.com
NOTE: The "Last Download Date" indicates when the preferences file was last downloaded (via MySonicWall or firewall UI) or is blank if the date is unknown . If the file was not downloaded on any specified date by the administrator, please take immediate action and follow the remediation steps outlined in the articles.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.