s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7 high

📛 Threat Title

Unknown: ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: dll. Size: 3449344 bytes. Tags: dll, Gansu-Shishida-Information-Technology-Co-Ltd, signed. Reporter: JAMESWT_WT. First seen: 2026-05-15 06:52:23.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7 1 feed

IOC database

Type
hash_sha256
Value
ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 3661fb18c7d36a77f6fc683683e9efa3d1672156 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3661fb18c7d36a77f6fc683683e9efa3d1672156
1 feed

IOC database

Type
hash_sha1
Value
3661fb18c7d36a77f6fc683683e9efa3d1672156
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3661fb18c7d36a77f6fc683683e9efa3d1672156

hash_md5 4fbb8142992edbfb0a7e90004ff1c3d2 VT 38 / 75 1 feed

IOC database

Type
hash_md5
Value
4fbb8142992edbfb0a7e90004ff1c3d2
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 38 of 75 VirusTotal vendors

VendorVerdictDetection
Alibaba malicious Trojan:Win32/MalwareX.44cf5862
alibabacloud malicious Trojan:Win/Delf.VAV
ALYac malicious Trojan.GenericKD.80141116
Arcabit malicious Trojan.Generic.D4C6DB3C
Avast malicious MalwareX-gen [Trj]
AVG malicious MalwareX-gen [Trj]
Avira malicious TR/W32.MalwareX
BitDefender malicious Trojan.GenericKD.80141116
CTX malicious dll.trojan.malwarex
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
Emsisoft malicious Trojan.GenericKD.80141116 (B)
ESET-NOD32 malicious Win32/Delf.VEQ trojan
F-Secure malicious Trojan.TR/W32.MalwareX
GData malicious Trojan.GenericKD.80141116
Google malicious Detected
Gridinsoft malicious Trojan.Win32.Agent.sa
Ikarus malicious Trojan.Win32.Delf
K7AntiVirus malicious Trojan ( 006dfe5e1 )
K7GW malicious Trojan ( 006dfe5e1 )
Kaspersky malicious HEUR:Trojan.Win32.Agent.gen
Kingsoft malicious Win32.Trojan.Agent.gen
Lionic malicious Trojan.Win32.Agent.Y!c
MaxSecure malicious Trojan.Malware.325019807.susgen
Microsoft malicious Trojan:Win32/Yomal!rfn
MicroWorld-eScan malicious Trojan.GenericKD.80141116
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Trojan.Delf!8.67 (LESS:bWQ1Onu8WzpaRNFo)
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.MBT
TrellixENS malicious Artemis!4FBB8142992E
TrendMicro malicious TROJ_GEN.R002C0DEJ26
TrendMicro-HouseCall malicious TROJ_GEN.R002C0DEJ26
Varist malicious W32/ABmRisk.VPOF-1395
VIPRE malicious Trojan.GenericKD.80141116
VirIT malicious Trojan.Win32.DelphGen.JQP
Xcitium malicious Malware@#2i4nuf69lv96f

Details From VirusTotal

Basic Properties
MD54fbb8142992edbfb0a7e90004ff1c3d2
SHA-13661fb18c7d36a77f6fc683683e9efa3d1672156
SHA-256ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7
VHash136096665d5c0d5d55156$z3dz14
SSDEEP98304:3eQKB27ezUdZrzX66r+i6GNQO702nTbzYW:e2hK6KONQW0sd
TLSHT1A2F5BF339082913AC2B71976092B7394E57AB5312BE31D97FEDC4D2C4F39781A928367
File typeWin32 DLL
File type tagpedll
File extensiondll
MagicPE32 executable (DLL) (GUI) Intel 80386, for MS Windows
File size3.3 MB
History
Creation date2026-05-14 10:05 UTC
First seen on VirusTotal2026-05-14 14:12 UTC
Last submission2026-05-15 06:53 UTC
Last analysis2026-05-20 12:09 UTC
Last modified on VirusTotal2026-05-20 14:11 UTC
Known Names
  • ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7.dll
  • 0nouw.exe
  • _ed9d14377f89c918d250d5b8324ce85231ae92bc41dec334f6e331cbf50d92c7.dll
  • TRUST_IMITATE_DLL.dll
  • TID.DLL
hash_imphash 1ed12568fd746db5ef08a39c630c3160

IOC database

Type
hash_imphash
Value
1ed12568fd746db5ef08a39c630c3160
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: dll. Size: 3449344 bytes. Tags: dll, Gansu-Shishida-Information-Technology-Co-Ltd, signed. Reporter: JAMESWT_WT. First seen: 2026-05-15 06:52:23.

Remediations (10)

  • web:access.redhat.com

    Remediation Timeline Given the interest in how this vulnerability was disclosed and remediated, the following timeline outlines the key events. 2026-03-23 Reporter privately contacts upstream 2026-03-24 Upstream acknowledges receiving the report 2026-03-25 Upstream/Reporter propose and review patches 2026-04-01 Upstream commits patch to ...

  • web:askubuntu.com

    9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.

  • web:blog.qualys.com

    Written by Mukesh Choudhary, Principal SME, Remediation and FIM Write to Mukesh at mchoudhary@qualys.com LPE vulnerability Windows, Microsoft Defender zero-day, mitigate without patch, RedSun vulnerability, TruRisk Eliminate, vulnerability mitigation , vulnerability remediation Show Comments (2)

  • web:learn.microsoft.com

    This article provides an overview of Microsoft Defender for Identity's certificate security posture assessment report.

  • web:patchmypc.com

    Clients stuck in unknown ? Use these steps to troubleshoot and validate update state in SCCM.

  • web:www.majorgeeks.com

    Unknown Device Identifier enables you to identify the yellow question mark labeled Unknown Devices in Device Manager and reports you a detailed summary for the manufacturer name, OEM name, device type, device model and even the exact name of the unknown devices. With the collected information, you might contact your hardware manufacturer for support or search the Internet for the corresponding ...

  • web:www.reddit.com

    Pulling my hair out for this one. What's happening- When I deploy a VPP app (Microsoft Teams for example) and scope it to all users with user license…

  • web:www.thewindowsclub.com

    Learn how to identify and fix Unknown Device in Device Manager of Windows 11/10. Use Unknown Device Identifier to troubleshoot a device listed as Unknown Device Driver.

  • web:www.toolsley.com

    Free browser tool to identify unknown files based on their contents. Recognizes over 2000 file formats using libmagic. No installation necessary. Just drag & drop!

  • web:www.windowsdigitals.com

    Can't install or run an app from unknown publisher? Here's how to allow unknown publisher in Windows 11/10, and how to disable the warning.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.