MB-9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a
high
📛 Threat Title
Unknown: file
Description
File type: exe. Size: 3087360 bytes. Tags: A, dropped-by-GCleaner, exe, MIX6.file. Reporter: Bitsight. First seen: 2026-05-14 20:30:16.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
mix6.file
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/mix6.file
IOC database
- Type
- domain
- Value
mix6.file- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- Extracted from Threat MB-c574b3c0a63ae972441cf84819edb1b8f3addfec6f051e8989a443d95cdeae04
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/mix6.file
hash_sha256
9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a
1 feed
IOC database
- Type
- hash_sha256
- Value
9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
1e6aea14cf046185099b3d5730f7cccfc88e6f57
VT 20 / 75
1 feed
IOC database
- Type
- hash_sha1
- Value
1e6aea14cf046185099b3d5730f7cccfc88e6f57- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 20 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R771219 |
| alibabacloud | malicious | VirTool:Win/Wacatac.B9nj |
| APEX | malicious | Malicious |
| Avast | malicious | FileRepMalware [Misc] |
| AVG | malicious | FileRepMalware [Misc] |
| CrowdStrike | malicious | win/malicious_confidence_90% (W) |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | Win64/Packed.Themida.L suspicious application |
| Kaspersky | malicious | UDS:Trojan.Win32.GenericML.xnet |
| Malwarebytes | malicious | Malware.Heuristic.2025 |
| McAfeeD | malicious | ti!9D5A4FCBA60A |
| Microsoft | malicious | Trojan:Win32/Sabsik.FL.A!ml |
| Paloalto | malicious | generic.ml |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!14D81E6ED3AF |
| Zoner | malicious | Probably Heur.ExeHeaderL |
Details From VirusTotal
Basic Properties
| MD5 | 14d81e6ed3af1a48185defcfb74441bd |
| SHA-1 | 1e6aea14cf046185099b3d5730f7cccfc88e6f57 |
| SHA-256 | 9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a |
| VHash | 036086757d75157d1f0777z11z1nz1fz |
| SSDEEP | 49152:w2piMLrClTZH83P5hVtrdCMrOufQHxaPwzuB0+vXMQN1mi6aJPDCmUnp2l6cBzTK:Wyrw8rVNsMrsHxuiWrvcQSi6GP2mq2l9 |
| TLSH | T14FE533218D57ED82D363B4B6B0717B3108F6ED1021C67FB5421ADE9A8D70D8AE1AF4B1 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 2.9 MB |
History
| Creation date | 2021-03-14 19:06 UTC |
| First seen on VirusTotal | 2026-05-14 20:30 UTC |
| Last submission | 2026-05-14 20:34 UTC |
| Last analysis | 2026-05-15 00:03 UTC |
| Last modified on VirusTotal | 2026-05-16 19:42 UTC |
Known Names
python.exe9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a.exe_9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a.exetr2073hac.exe
hash_md5
14d81e6ed3af1a48185defcfb74441bd
VT 20 / 75
1 feed
IOC database
- Type
- hash_md5
- Value
14d81e6ed3af1a48185defcfb74441bd- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 20 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.R771219 |
| alibabacloud | malicious | VirTool:Win/Wacatac.B9nj |
| APEX | malicious | Malicious |
| Avast | malicious | FileRepMalware [Misc] |
| AVG | malicious | FileRepMalware [Misc] |
| CrowdStrike | malicious | win/malicious_confidence_90% (W) |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| Elastic | malicious | malicious (high confidence) |
| ESET-NOD32 | malicious | Win64/Packed.Themida.L suspicious application |
| Kaspersky | malicious | UDS:Trojan.Win32.GenericML.xnet |
| Malwarebytes | malicious | Malware.Heuristic.2025 |
| McAfeeD | malicious | ti!9D5A4FCBA60A |
| Microsoft | malicious | Trojan:Win32/Sabsik.FL.A!ml |
| Paloalto | malicious | generic.ml |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Trapmine | malicious | malicious.high.ml.score |
| TrellixENS | malicious | Artemis!14D81E6ED3AF |
| Zoner | malicious | Probably Heur.ExeHeaderL |
Details From VirusTotal
Basic Properties
| MD5 | 14d81e6ed3af1a48185defcfb74441bd |
| SHA-1 | 1e6aea14cf046185099b3d5730f7cccfc88e6f57 |
| SHA-256 | 9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a |
| VHash | 036086757d75157d1f0777z11z1nz1fz |
| SSDEEP | 49152:w2piMLrClTZH83P5hVtrdCMrOufQHxaPwzuB0+vXMQN1mi6aJPDCmUnp2l6cBzTK:Wyrw8rVNsMrsHxuiWrvcQSi6GP2mq2l9 |
| TLSH | T14FE533218D57ED82D363B4B6B0717B3108F6ED1021C67FB5421ADE9A8D70D8AE1AF4B1 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 2.9 MB |
History
| Creation date | 2021-03-14 19:06 UTC |
| First seen on VirusTotal | 2026-05-14 20:30 UTC |
| Last submission | 2026-05-14 20:34 UTC |
| Last analysis | 2026-05-15 00:03 UTC |
| Last modified on VirusTotal | 2026-05-16 19:42 UTC |
Known Names
python.exe9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a.exe_9d5a4fcba60a9f9459570417411e8d4a90da4d274de8f352ef5d4ff6d50c2b9a.exetr2073hac.exe
hash_imphash
8f104ac81ea8802600956811d68df5a5
IOC database
- Type
- hash_imphash
- Value
8f104ac81ea8802600956811d68df5a5- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 3087360 bytes. Tags: A, dropped-by-GCleaner, exe, MIX6.file. Reporter: Bitsight. First seen: 2026-05-14 20:30:16.
Remediations (10)
-
web:blackswan-cybersecurity.com
Cloud Files API activity originating outside legitimate OneDrive/sync processes. Mitigation Steps: Apply all Windows updates immediately (monitor MSRC for an emergency RedSun-specific patch. None released as of April 17, 2026). Supplement Defender with a secondary EDR solution (e.g., Huntress) capable of detecting Defender bypasses.
-
web:blog.qualys.com
How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.
-
web:learn.microsoft.com
Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:mimecastsupport.zendesk.com
Threat Remediation allows: Automatic remediation of any newly found, zero-day attachment-based malware detected in your users' mailboxes, leveraging global threat intelligence to continuously monitor files post-delivery.
-
web:windowsforum.com
CISA's decision to add two recently disclosed flaws — a WinRAR path‑traversal bug (CVE-2025-6218) and a Windows Cloud Files mini‑filter use‑after‑free (CVE-2025-62221) — to the Known Exploited Vulnerabilities (KEV) Catalog crystallizes a simple reality for defenders: time-to-fix is shrinking and the federal remediation clock is unforgiving. The technical facts are straightforward ...
-
web:www.bitdefender.com
Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.
-
web:www.cisa.gov
General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.
-
web:www.crowdstrike.com
Remediate faster Execute built-in commands or custom scripts to easily carry out complex remediation actions on any managed endpoint remotely. Connect to and quickly isolate the impacted endpoint, then remove malicious files to immediately shut down the attack.
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.sonicwall.com
NOTE: The "Last Download Date" indicates when the preferences file was last downloaded (via MySonicWall or firewall UI) or is blank if the date is unknown . If the file was not downloaded on any specified date by the administrator, please take immediate action and follow the remediation steps outlined in the articles.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.