VT-4e106c973f28acfc4461caec3179319e784afa9cd939e3eda41ee7426e60
medium
📛 Threat Title
VirusTotal: 4e106c973f28acfc4461caec3179319e784afa9cd939e3eda41ee7426e60989f
Description
VirusTotal verdict: 4 malicious / 0 suspicious of 74 engines.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
4e106c973f28acfc4461caec3179319e784afa9cd939e3eda41ee7426e60989f
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/4e106c973f28acfc4461caec3179319e784afa9cd939e3eda41ee7426e60989f
IOC database
- Type
- hash_sha256
- Value
4e106c973f28acfc4461caec3179319e784afa9cd939e3eda41ee7426e60989f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat VT-4e106c973f28acfc4461caec3179319e784afa9cd939e3eda41ee7426e60
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/4e106c973f28acfc4461caec3179319e784afa9cd939e3eda41ee7426e60989f
References (1)
-
VirusTotal report
VirusTotal verdict: 4 malicious / 0 suspicious of 74 engines.
Remediations (8)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
-
web:blog.virustotal.com
The VirusTotal dataset, the backbone of the platform, structures artifact-related information into objects and represents relevant relationships between them, providing contextual links between various artifacts. This makes VirusTotal a valuable resource for threat research, enabling users to perform activities such as clustering artifacts related to specific threat actors or campaigns ...
-
web:docs.virustotal.com
VirusTotal's developers hub, the place to learn about VirusTotal's public and private APIs in order to programmatically scan files, check URLs, discover malicious domains, etc.
-
web:socradar.io
BlueHammer is a local privilege escalation flaw rooted in a race condition within Defender's threat remediation engine. When Defender detects a malicious file and begins cleanup, it performs privileged file operations without validating the target path at write time.
-
web:www.cisa.gov
VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a variety of tools, to extract signals from the studied content.
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
-
web:www.virustotal.com
VirusTotal is a free online service for scanning files and URLs for viruses, malware, and other malicious content using multiple antivirus solutions.
-
web:www.virustotal.com
VirusTotal is a free virus, malware and URL online scanning service. File checking is done with more than 40 antivirus solutions. Files and URLs can be sent via web interface upload, email API or making use of VirusTotal's browser extensions and desktop applications.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.