s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b high

📛 Threat Title

Unknown: file

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 2067072 bytes. Tags: C, dropped-by-GCleaner, exe, MIX1.file, signed. Reporter: Bitsight. First seen: 2026-05-14 13:58:22.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain mix1.file VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/mix1.file

IOC database

Type
domain
Value
mix1.file
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Extracted from Threat MB-95a22e67b75eea2ba37141a3681177d2a48fed51727bcd292444205afc02130f

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/mix1.file

hash_imphash d42595b695fc008ef2c56aabd8efd68e

IOC database

Type
hash_imphash
Value
d42595b695fc008ef2c56aabd8efd68e
First seen
Last seen
Attached to this threat
Appears in
465 threats
Description
imphash of URLhaus payload a7b9f3dda435b7f2…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b VT 33 / 74 1 feed

IOC database

Type
hash_sha256
Value
31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 33 of 74 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R770656
Alibaba malicious Backdoor:Win64/Kryptik.cee33218
Avast malicious Win64:Evo-gen [Trj]
AVG malicious Win64:Evo-gen [Trj]
Avira malicious TR/W64.Evo
Bkav malicious W32.Malware.E3ACBDC8
CrowdStrike malicious win/malicious_confidence_90% (W)
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
Elastic malicious malicious (high confidence)
ESET-NOD32 malicious WinGo/Kryptik.PL trojan
F-Secure malicious Trojan.TR/W64.Evo
Fortinet malicious W64/MALD2.3659!tr
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Agent.sa
huorong malicious Trojan/W64.Obfuscated.h!crit
Ikarus malicious Trojan.WinGo.Crypt
K7AntiVirus malicious Trojan ( 006de6a71 )
K7GW malicious Trojan ( 006de6a71 )
Kaspersky malicious UDS:Backdoor.Win64.Gsb.aya
Kingsoft malicious Win64.Backdoor.Gsb.gen
Lionic malicious Trojan.Win32.Agent.Y!c
Malwarebytes malicious Malware.AI.2832754406
McAfeeD malicious ti!31AB874B4635
Microsoft malicious Trojan:Win32/Wacatac.B!ml
Paloalto malicious generic.ml
Rising malicious Backdoor.Agent!8.C5D (CLOUD)
Sangfor malicious Trojan.Win32.Evo.Vvo9
Skyhigh malicious Artemis!Trojan
Sophos malicious Mal/Generic-S
Tencent malicious Win32.Trojan.FalseSign.Zchl
TrellixENS malicious Artemis!021C6CBFC905
Varist malicious W64/Agent.MDZ.gen!Eldorado

Details From VirusTotal

Basic Properties
MD5021c6cbfc905f7c10c932ba4d5ab5f11
SHA-12e2cfdd7befaa3a5a37eb45d7237c24c76a8797d
SHA-25631ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b
VHash026086656d15551d15545az2e!z
SSDEEP24576:Pt57QzXRkzDS5dijhdSALwXLHj9mMyA1bcV9y9xeKIxdIMrbFhele5n923ql4ZV0:PtVIRkC5ditAAO9m9A1bO9y9wHLDcrQ
TLSHT1F8A57C5B7C9144F6D4AAA33388B761827BB1F8480B3223D72E50A6783F767D4AD79704
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size2.0 MB
History
First seen on VirusTotal2026-05-14 13:58 UTC
Last submission2026-05-14 14:05 UTC
Last analysis2026-05-14 18:02 UTC
Last modified on VirusTotal2026-05-20 16:18 UTC
Known Names
  • 31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b.exe
  • _31ab874b463588727ebd9635124f3f02125c87b6cb93dd348bf2f60d0d12ac1b.exe
  • rbtgiznp.exe
hash_sha1 2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d
2 feeds

IOC database

Type
hash_sha1
Value
2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2e2cfdd7befaa3a5a37eb45d7237c24c76a8797d

hash_md5 021c6cbfc905f7c10c932ba4d5ab5f11 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/021c6cbfc905f7c10c932ba4d5ab5f11
2 feeds

IOC database

Type
hash_md5
Value
021c6cbfc905f7c10c932ba4d5ab5f11
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/021c6cbfc905f7c10c932ba4d5ab5f11

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 2067072 bytes. Tags: C, dropped-by-GCleaner, exe, MIX1.file, signed. Reporter: Bitsight. First seen: 2026-05-14 13:58:22.

Remediations (10)

  • web:blackswan-cybersecurity.com

    Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.

  • web:blog.qualys.com

    How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.

  • web:learn.microsoft.com

    Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:mimecastsupport.zendesk.com

    Threat Remediation allows: Automatic remediation of any newly found, zero-day attachment-based malware detected in your users' mailboxes, leveraging global threat intelligence to continuously monitor files post-delivery.

  • web:windowsforum.com

    CISA's decision to add two recently disclosed flaws — a WinRAR path‑traversal bug (CVE-2025-6218) and a Windows Cloud Files mini‑filter use‑after‑free (CVE-2025-62221) — to the Known Exploited Vulnerabilities (KEV) Catalog crystallizes a simple reality for defenders: time-to-fix is shrinking and the federal remediation clock is unforgiving. The technical facts are straightforward ...

  • web:www.bitdefender.com

    Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.

  • web:www.cisa.gov

    General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.

  • web:www.crowdstrike.com

    Remediate faster Execute built-in commands or custom scripts to easily carry out complex remediation actions on any managed endpoint remotely. Connect to and quickly isolate the impacted endpoint, then remove malicious files to immediately shut down the attack.

  • web:www.esd.whs.mil

    Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.

  • web:www.sonicwall.com

    NOTE: The "Last Download Date" indicates when the preferences file was last downloaded (via MySonicWall or firewall UI) or is blank if the date is unknown . If the file was not downloaded on any specified date by the administrator, please take immediate action and follow the remediation steps outlined in the articles.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.