MB-378cfed93e93094c5044aea2894454222beaa0ca92fb2ef1a2ce6e37df36eebc
high
📛 Threat Title
Unknown: file
Description
File type: exe. Size: 5646872 bytes. Tags: B, dropped-by-GCleaner, exe, MIX10.file, signed. Reporter: Bitsight. First seen: 2026-09-25 12:06:48.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
9771ee6344923fa220489ab01239bdfd
IOC database
- Type
- hash_imphash
- Value
9771ee6344923fa220489ab01239bdfd- First seen
- Last seen
- Attached to this threat
- Appears in
- 210 threats
- Description
- imphash of URLhaus payload 997a09b5cbbebd7e…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
378cfed93e93094c5044aea2894454222beaa0ca92fb2ef1a2ce6e37df36eebc
VT 23 / 75
IOC database
- Type
- hash_sha256
- Value
378cfed93e93094c5044aea2894454222beaa0ca92fb2ef1a2ce6e37df36eebc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 23 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Bkav | malicious | W32.Malware.497FF923 |
| Cylance | malicious | Unsafe |
| DrWeb | malicious | Trojan.Siggen31.30777 |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | Win32/RemoteAdmin.ConnectWiseControl.E potentially unsafe application |
| malicious | Detected |
|
| huorong | malicious | HackTool/ConnectWiseControl.i |
| Ikarus | malicious | PUA.ConnectWise |
| Jiangmin | malicious | Trojan.Agent.edgo |
| K7AntiVirus | malicious | Unwanted-Program ( 005c6d501 ) |
| K7GW | malicious | Unwanted-Program ( 005c6d501 ) |
| Kaspersky | malicious | not-a-virus:UDS:RemoteAdmin.MSIL.ConnectWise.gen |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| Rising | malicious | Trojan.RemoteAdmin!8.D7F6 (RDMK:cmRtazrdJKWPAhj+d5c241eRCvcq) |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Skyhigh | malicious | BehavesLike.Win32.ScreenConnect.tc |
| Tencent | malicious | Trojan.Win32.Agent.16004532 |
| TrellixENS | malicious | PUP-IPR |
| Varist | malicious | W32/ConnectWise.B.gen!Eldorado |
| VBA32 | malicious | BScope.Riskware.ConnectWise |
| VirIT | malicious | Trojan.Win32.GenusC.JJJ |
| Yandex | malicious | Riskware.RemoteAdmin!O4vT/8AeK2A |
| Zillya | malicious | Tool.Convagent.Win32.869 |
Details From VirusTotal
Basic Properties
| MD5 | 3975ce77c80ac874df861bb06fa60fec |
| SHA-1 | 0d70b16c48e172acf6336456bb9c6c64d81b273e |
| SHA-256 | 378cfed93e93094c5044aea2894454222beaa0ca92fb2ef1a2ce6e37df36eebc |
| VHash | 056056655d15756az459z6tz |
| SSDEEP | 49152:7fmLDKJkGYYpT0+TFiH7efP4yfy3Ys6vPHYs00Yrxl/jgq36+hKls/LG2XwygONw:ors6efPRy3BIvY44TnDTGvyEvgVxe7l |
| TLSH | T18646F141B3D695B5D0BF0638D87A42666A34BC109712C7EF57A4BD292D33BC08E327B6 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 5.4 MB |
History
| Creation date | 2022-11-18 20:10 UTC |
| First seen on VirusTotal | 2026-09-25 12:06 UTC |
| Last submission | 2026-09-25 12:06 UTC |
| Last analysis | 2026-09-25 12:06 UTC |
| Last modified on VirusTotal | 2026-09-25 23:24 UTC |
Known Names
f91z0vb7n.exekonr4q.exe
hash_sha1
0d70b16c48e172acf6336456bb9c6c64d81b273e
VT 23 / 75
IOC database
- Type
- hash_sha1
- Value
0d70b16c48e172acf6336456bb9c6c64d81b273e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 23 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Bkav | malicious | W32.Malware.497FF923 |
| Cylance | malicious | Unsafe |
| DrWeb | malicious | Trojan.Siggen31.30777 |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | Win32/RemoteAdmin.ConnectWiseControl.E potentially unsafe application |
| malicious | Detected |
|
| huorong | malicious | HackTool/ConnectWiseControl.i |
| Ikarus | malicious | PUA.ConnectWise |
| Jiangmin | malicious | Trojan.Agent.edgo |
| K7AntiVirus | malicious | Unwanted-Program ( 005c6d501 ) |
| K7GW | malicious | Unwanted-Program ( 005c6d501 ) |
| Kaspersky | malicious | not-a-virus:UDS:RemoteAdmin.MSIL.ConnectWise.gen |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| Rising | malicious | Trojan.RemoteAdmin!8.D7F6 (RDMK:cmRtazrdJKWPAhj+d5c241eRCvcq) |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Skyhigh | malicious | BehavesLike.Win32.ScreenConnect.tc |
| Tencent | malicious | Trojan.Win32.Agent.16004532 |
| TrellixENS | malicious | PUP-IPR |
| Varist | malicious | W32/ConnectWise.B.gen!Eldorado |
| VBA32 | malicious | BScope.Riskware.ConnectWise |
| VirIT | malicious | Trojan.Win32.GenusC.JJJ |
| Yandex | malicious | Riskware.RemoteAdmin!O4vT/8AeK2A |
| Zillya | malicious | Tool.Convagent.Win32.869 |
Details From VirusTotal
Basic Properties
| MD5 | 3975ce77c80ac874df861bb06fa60fec |
| SHA-1 | 0d70b16c48e172acf6336456bb9c6c64d81b273e |
| SHA-256 | 378cfed93e93094c5044aea2894454222beaa0ca92fb2ef1a2ce6e37df36eebc |
| VHash | 056056655d15756az459z6tz |
| SSDEEP | 49152:7fmLDKJkGYYpT0+TFiH7efP4yfy3Ys6vPHYs00Yrxl/jgq36+hKls/LG2XwygONw:ors6efPRy3BIvY44TnDTGvyEvgVxe7l |
| TLSH | T18646F141B3D695B5D0BF0638D87A42666A34BC109712C7EF57A4BD292D33BC08E327B6 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 5.4 MB |
History
| Creation date | 2022-11-18 20:10 UTC |
| First seen on VirusTotal | 2026-09-25 12:06 UTC |
| Last submission | 2026-09-25 12:06 UTC |
| Last analysis | 2026-09-25 12:06 UTC |
| Last modified on VirusTotal | 2026-09-25 23:24 UTC |
Known Names
f91z0vb7n.exekonr4q.exe
hash_md5
3975ce77c80ac874df861bb06fa60fec
VT 23 / 75
IOC database
- Type
- hash_md5
- Value
3975ce77c80ac874df861bb06fa60fec- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 23 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Bkav | malicious | W32.Malware.497FF923 |
| Cylance | malicious | Unsafe |
| DrWeb | malicious | Trojan.Siggen31.30777 |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | Win32/RemoteAdmin.ConnectWiseControl.E potentially unsafe application |
| malicious | Detected |
|
| huorong | malicious | HackTool/ConnectWiseControl.i |
| Ikarus | malicious | PUA.ConnectWise |
| Jiangmin | malicious | Trojan.Agent.edgo |
| K7AntiVirus | malicious | Unwanted-Program ( 005c6d501 ) |
| K7GW | malicious | Unwanted-Program ( 005c6d501 ) |
| Kaspersky | malicious | not-a-virus:UDS:RemoteAdmin.MSIL.ConnectWise.gen |
| MaxSecure | malicious | Trojan.Malware.121218.susgen |
| Rising | malicious | Trojan.RemoteAdmin!8.D7F6 (RDMK:cmRtazrdJKWPAhj+d5c241eRCvcq) |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Skyhigh | malicious | BehavesLike.Win32.ScreenConnect.tc |
| Tencent | malicious | Trojan.Win32.Agent.16004532 |
| TrellixENS | malicious | PUP-IPR |
| Varist | malicious | W32/ConnectWise.B.gen!Eldorado |
| VBA32 | malicious | BScope.Riskware.ConnectWise |
| VirIT | malicious | Trojan.Win32.GenusC.JJJ |
| Yandex | malicious | Riskware.RemoteAdmin!O4vT/8AeK2A |
| Zillya | malicious | Tool.Convagent.Win32.869 |
Details From VirusTotal
Basic Properties
| MD5 | 3975ce77c80ac874df861bb06fa60fec |
| SHA-1 | 0d70b16c48e172acf6336456bb9c6c64d81b273e |
| SHA-256 | 378cfed93e93094c5044aea2894454222beaa0ca92fb2ef1a2ce6e37df36eebc |
| VHash | 056056655d15756az459z6tz |
| SSDEEP | 49152:7fmLDKJkGYYpT0+TFiH7efP4yfy3Ys6vPHYs00Yrxl/jgq36+hKls/LG2XwygONw:ors6efPRy3BIvY44TnDTGvyEvgVxe7l |
| TLSH | T18646F141B3D695B5D0BF0638D87A42666A34BC109712C7EF57A4BD292D33BC08E327B6 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 5.4 MB |
History
| Creation date | 2022-11-18 20:10 UTC |
| First seen on VirusTotal | 2026-09-25 12:06 UTC |
| Last submission | 2026-09-25 12:06 UTC |
| Last analysis | 2026-09-25 12:06 UTC |
| Last modified on VirusTotal | 2026-09-25 23:24 UTC |
Known Names
f91z0vb7n.exekonr4q.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 5646872 bytes. Tags: B, dropped-by-GCleaner, exe, MIX10.file, signed. Reporter: Bitsight. First seen: 2026-09-25 12:06:48.
Remediations (9)
-
web:docs.cloud.google.com
This page provides recommended strategies for identifying and remediating data risk in your organization. Protecting your data starts with understanding what data you are handling, where sensitive data is located, and how this data is secured and used. When you have a comprehensive view of your data and its security posture, you can take the appropriate measures to protect it and continuously ...
-
web:learn.microsoft.com
Configure what Microsoft Defender Antivirus should do when it detects a threat, and how long quarantined files should be retained in the quarantine folder.
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:mimecastsupport.zendesk.com
Threat Remediation allows: Automatic remediation of any newly found, zero-day attachment-based malware detected in your users' mailboxes, leveraging global threat intelligence to continuously monitor files post-delivery.
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:windowsforum.com
Microsoft's February Patch Tuesday closed a dangerous loophole in the modern Notepad app that could let an attacker turn a simple Markdown (.md) file into a remote code execution (RCE) trap — a single click on a crafted link inside Notepad's Markdown view could launch unverified protocols and cause arbitrary code to run with the user's privileges. (msrc.microsoft.com) Background ...
-
web:www.crowdstrike.com
Here, we can see the details of the remediation actions, such as any files quarantined, processes killed, and registry values deleted. We can also release any quarantined files as well. When we navigate to remediation , a list of all the remediation activities across the entire organization is available.
-
web:www.rapid7.com
Automation can be a big help in effective vulnerability management, both when it comes to remediation and mitigation . For remediation , you'll want to adopt a vulnerability management solution, like Rapid7's InsightVM, that eliminates the need for manual reporting, complex spreadsheets, and confusing back-and-forth email tags.
-
web:www.rescana.com
Given the active exploitation and the high impact potential, urgent remediation is required for all organizations utilizing affected Microsoft Office products. This advisory provides a comprehensive technical breakdown, exploitation context, and actionable mitigation guidance to help organizations defend against this evolving threat.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.