s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-de7093bea296ce216d953a260aecafa83586e82a7367a1c0b749bfda848c1d64 high

📛 Threat Title

Unknown: file

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 18944 bytes. Tags: dropped-by-phorpiex, exe. Reporter: Bitsight. First seen: 2026-05-20 23:11:54.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash b8b034a37970476c0e8791d5941c31e3

IOC database

Type
hash_imphash
Value
b8b034a37970476c0e8791d5941c31e3
First seen
Last seen
Attached to this threat
Appears in
25 threats
Description
imphash of URLhaus payload 0c8dffc78085cbbe…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 de7093bea296ce216d953a260aecafa83586e82a7367a1c0b749bfda848c1d64

IOC database

Type
hash_sha256
Value
de7093bea296ce216d953a260aecafa83586e82a7367a1c0b749bfda848c1d64
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 dcf9dc6625126497efd20331f14ba7bd

IOC database

Type
hash_md5
Value
dcf9dc6625126497efd20331f14ba7bd
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 28bb8271dcb8ee9ad19443b3b51572ac343f2908

IOC database

Type
hash_sha1
Value
28bb8271dcb8ee9ad19443b3b51572ac343f2908
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 18944 bytes. Tags: dropped-by-phorpiex, exe. Reporter: Bitsight. First seen: 2026-05-20 23:11:54.

Remediations (10)

  • web:blog.qualys.com

    How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.

  • web:learn.microsoft.com

    Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:learn.microsoft.com

    Take response actions on file -related alerts by stopping and quarantining a file or blocking a file and checking activity details.

  • web:mimecastsupport.zendesk.com

    Incidents correspond to a Remediation event and display all the associated messages by the recipient. After viewing an incident, you can perform the following actions: Remove an attachment/message...

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:sc1.checkpoint.com

    Analysis & Remediation Automated Attack Analysis (Forensics) Endpoint Security Forensics analyzes attacks detected by other detection features like Anti-Ransomware or Behavioral Guard, and some third-party security products. On detection of a malicious event or file , Forensics is informed and a Forensics analysis is automatically initiated. After the analysis is completed, the entire attack ...

  • web:securityboulevard.com

    Choosing between remediation and mitigation depends on several factors, including the severity of the vulnerability, available resources, and potential impact on business operations. Here are some considerations to help guide the decision: Urgency and Risk Level When a vulnerability poses a high risk and requires immediate attention, remediation is the preferred choice. By directly fixing the ...

  • web:www.bitdefender.com

    Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.

  • web:www.cisa.gov

    General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.

  • web:www.cisa.gov

    OVERVIEW This joint advisory is the result of a collaborative research effort by the cybersecurity authorities of five nations: Australia, Canada, New Zealand, the United Kingdom, and the United States.1 It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.