MB-ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7
high
📛 Threat Title
Unknown: ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7
Description
File type: dll. Size: 3449344 bytes. Tags: dll, Gansu-Shishida-Information-Technology-Co-Ltd, signed. Reporter: JAMESWT_WT. First seen: 2026-05-15 06:52:23.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7
1 feed
IOC database
- Type
- hash_sha256
- Value
ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
3661fb18c7d36a77f6fc683683e9efa3d1672156
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3661fb18c7d36a77f6fc683683e9efa3d1672156
1 feed
IOC database
- Type
- hash_sha1
- Value
3661fb18c7d36a77f6fc683683e9efa3d1672156- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3661fb18c7d36a77f6fc683683e9efa3d1672156
hash_md5
4fbb8142992edbfb0a7e90004ff1c3d2
VT 38 / 75
1 feed
IOC database
- Type
- hash_md5
- Value
4fbb8142992edbfb0a7e90004ff1c3d2- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 38 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Alibaba | malicious | Trojan:Win32/MalwareX.44cf5862 |
| alibabacloud | malicious | Trojan:Win/Delf.VAV |
| ALYac | malicious | Trojan.GenericKD.80141116 |
| Arcabit | malicious | Trojan.Generic.D4C6DB3C |
| Avast | malicious | MalwareX-gen [Trj] |
| AVG | malicious | MalwareX-gen [Trj] |
| Avira | malicious | TR/W32.MalwareX |
| BitDefender | malicious | Trojan.GenericKD.80141116 |
| CTX | malicious | dll.trojan.malwarex |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| Emsisoft | malicious | Trojan.GenericKD.80141116 (B) |
| ESET-NOD32 | malicious | Win32/Delf.VEQ trojan |
| F-Secure | malicious | Trojan.TR/W32.MalwareX |
| GData | malicious | Trojan.GenericKD.80141116 |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win32.Agent.sa |
| Ikarus | malicious | Trojan.Win32.Delf |
| K7AntiVirus | malicious | Trojan ( 006dfe5e1 ) |
| K7GW | malicious | Trojan ( 006dfe5e1 ) |
| Kaspersky | malicious | HEUR:Trojan.Win32.Agent.gen |
| Kingsoft | malicious | Win32.Trojan.Agent.gen |
| Lionic | malicious | Trojan.Win32.Agent.Y!c |
| MaxSecure | malicious | Trojan.Malware.325019807.susgen |
| Microsoft | malicious | Trojan:Win32/Yomal!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericKD.80141116 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Trojan.Delf!8.67 (LESS:bWQ1Onu8WzpaRNFo) |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.MBT |
| TrellixENS | malicious | Artemis!4FBB8142992E |
| TrendMicro | malicious | TROJ_GEN.R002C0DEJ26 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R002C0DEJ26 |
| Varist | malicious | W32/ABmRisk.VPOF-1395 |
| VIPRE | malicious | Trojan.GenericKD.80141116 |
| VirIT | malicious | Trojan.Win32.DelphGen.JQP |
| Xcitium | malicious | Malware@#2i4nuf69lv96f |
Details From VirusTotal
Basic Properties
| MD5 | 4fbb8142992edbfb0a7e90004ff1c3d2 |
| SHA-1 | 3661fb18c7d36a77f6fc683683e9efa3d1672156 |
| SHA-256 | ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7 |
| VHash | 136096665d5c0d5d55156$z3dz14 |
| SSDEEP | 98304:3eQKB27ezUdZrzX66r+i6GNQO702nTbzYW:e2hK6KONQW0sd |
| TLSH | T1A2F5BF339082913AC2B71976092B7394E57AB5312BE31D97FEDC4D2C4F39781A928367 |
| File type | Win32 DLL |
| File type tag | pedll |
| File extension | dll |
| Magic | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows |
| File size | 3.3 MB |
History
| Creation date | 2026-05-14 10:05 UTC |
| First seen on VirusTotal | 2026-05-14 14:12 UTC |
| Last submission | 2026-05-15 06:53 UTC |
| Last analysis | 2026-05-20 12:09 UTC |
| Last modified on VirusTotal | 2026-05-20 14:11 UTC |
Known Names
ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7.dll0nouw.exe_ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7.dllTRUST_IMITATE_DLL.dllTID.DLL
hash_imphash
1ed12568fd746db5ef08a39c630c3160
IOC database
- Type
- hash_imphash
- Value
1ed12568fd746db5ef08a39c630c3160- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: dll. Size: 3449344 bytes. Tags: dll, Gansu-Shishida-Information-Technology-Co-Ltd, signed. Reporter: JAMESWT_WT. First seen: 2026-05-15 06:52:23.
Remediations (10)
-
web:access.redhat.com
Remediation Timeline Given the interest in how this vulnerability was disclosed and remediated, the following timeline outlines the key events. 2026-03-23 Reporter privately contacts upstream 2026-03-24 Upstream acknowledges receiving the report 2026-03-25 Upstream/Reporter propose and review patches 2026-04-01 Upstream commits patch to ...
-
web:askubuntu.com
9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:blog.qualys.com
Written by Mukesh Choudhary, Principal SME, Remediation and FIM Write to Mukesh at mchoudhary@qualys.com LPE vulnerability Windows, Microsoft Defender zero-day, mitigate without patch, RedSun vulnerability, TruRisk Eliminate, vulnerability mitigation , vulnerability remediation Show Comments (2)
-
web:learn.microsoft.com
This article provides an overview of Microsoft Defender for Identity's certificate security posture assessment report.
-
web:patchmypc.com
Clients stuck in unknown ? Use these steps to troubleshoot and validate update state in SCCM.
-
web:www.majorgeeks.com
Unknown Device Identifier enables you to identify the yellow question mark labeled Unknown Devices in Device Manager and reports you a detailed summary for the manufacturer name, OEM name, device type, device model and even the exact name of the unknown devices. With the collected information, you might contact your hardware manufacturer for support or search the Internet for the corresponding ...
-
web:www.reddit.com
Pulling my hair out for this one. What's happening- When I deploy a VPP app (Microsoft Teams for example) and scope it to all users with user license…
-
web:www.thewindowsclub.com
Learn how to identify and fix Unknown Device in Device Manager of Windows 11/10. Use Unknown Device Identifier to troubleshoot a device listed as Unknown Device Driver.
-
web:www.toolsley.com
Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!
-
web:www.windowsdigitals.com
Can't install or run an app from unknown publisher? Here's how to allow unknown publisher in Windows 11/10, and how to disable the warning.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.