MB-0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b
high
📛 Threat Title
Unknown: file
Description
File type: exe. Size: 18944 bytes. Tags: dropped-by-phorpiex, exe. Reporter: Bitsight. First seen: 2026-05-20 23:11:59.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
b8b034a37970476c0e8791d5941c31e3
IOC database
- Type
- hash_imphash
- Value
b8b034a37970476c0e8791d5941c31e3- First seen
- Last seen
- Attached to this threat
- Appears in
- 25 threats
- Description
- imphash of URLhaus payload 0c8dffc78085cbbe…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b
IOC database
- Type
- hash_sha256
- Value
0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
048b96ef603873e543484d13eff75ada
VT 50 / 75
IOC database
- Type
- hash_md5
- Value
048b96ef603873e543484d13eff75ada- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Phorpiex.R601456 |
| Alibaba | malicious | TrojanDropper:Win32/Phorpiex.bf4a23aa |
| alibabacloud | malicious | Trojan:Win/Phorpiex.RK8PHU |
| Antiy-AVL | malicious | Trojan/Win32.Patched |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Mint.Zard.39 |
| Avast | malicious | Win32:MalwareX-gen [Bot] |
| AVG | malicious | Win32:MalwareX-gen [Bot] |
| Avira | malicious | TR/W32.MalwareX |
| BitDefender | malicious | Gen:Heur.Mint.Zard.39 |
| Bkav | malicious | W32.Malware.7A294514 |
| CrowdStrike | malicious | win/malicious_confidence_100% (D) |
| CTX | malicious | exe.unknown.mint |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 100) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.DownLoader46.474 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Gen:Heur.Mint.Zard.39 (B) |
| ESET-NOD32 | malicious | Win32/Phorpiex_AGen.U worm |
| F-Secure | malicious | Trojan.TR/W32.MalwareX |
| GData | malicious | Gen:Heur.Mint.Zard.39 |
| malicious | Detected |
|
| huorong | malicious | Worm/Phorpiex.o |
| Ikarus | malicious | Worm.Win32.Phorpiex |
| K7AntiVirus | malicious | EmailWorm ( 005df7d61 ) |
| K7GW | malicious | EmailWorm ( 005df7d61 ) |
| Kaspersky | malicious | HEUR:Trojan-Dropper.Win32.Phorpiex.gen |
| Kingsoft | malicious | Win32.Trojan-Dropper.Phorpiex.gen |
| Malwarebytes | malicious | Spyware.Phorpiex |
| McAfeeD | malicious | ti!0C8DFFC78085 |
| Microsoft | malicious | Trojan:Win32/Phorpiex.BF!MTB |
| MicroWorld-eScan | malicious | Gen:Heur.Mint.Zard.39 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/Genetic.gen |
| Rising | malicious | Worm.Phorpiex!1.13E48 (CLASSIC) |
| Sangfor | malicious | Trojan.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | Trojan-JBBB!048B96EF6038 |
| Sophos | malicious | W32/Phorpiex-BC |
| SUPERAntiSpyware | malicious | Trojan.Agent/Gen-Downloader |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | OB:Worm.Win32.Phorpiex.ha |
| TrellixENS | malicious | Trojan-JBBB!048B96EF6038 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA3 |
| Varist | malicious | W32/S-c70f2e64!Eldorado |
| VBA32 | malicious | BScope.TrojanDropper.Phorpiex |
| VIPRE | malicious | Gen:Heur.Mint.Zard.39 |
| Xcitium | malicious | TrojWare.Win32.Injector.UOL@4q80ri |
| ZoneAlarm | malicious | W32/Phorpiex-BC |
Details From VirusTotal
Basic Properties
| MD5 | 048b96ef603873e543484d13eff75ada |
| SHA-1 | f00d28512f510fb28b889155cdbcf97224ec5869 |
| SHA-256 | 0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b |
| VHash | 014056555d15555az1ejz31z21z61zc2z2a1z |
| SSDEEP | 384:RCIJlVYeR+HY4wfb0tu9JRSOPTNav8U9c2/:84B0Y99a0UF |
| TLSH | T1DC824C0FB9864316C0E100B05576963BDA799CB2338464EFF7D48A991B686E5FC3325F |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
| File size | 18.5 KB |
History
| Creation date | 2026-05-20 01:58 UTC |
| First seen on VirusTotal | 2026-05-20 23:15 UTC |
| Last submission | 2026-05-21 00:08 UTC |
| Last analysis | 2026-05-21 00:08 UTC |
| Last modified on VirusTotal | 2026-05-22 20:56 UTC |
Known Names
0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b.exe13[1].exe2864436615.exe13.exefile.exe
hash_sha1
f00d28512f510fb28b889155cdbcf97224ec5869
IOC database
- Type
- hash_sha1
- Value
f00d28512f510fb28b889155cdbcf97224ec5869- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 18944 bytes. Tags: dropped-by-phorpiex, exe. Reporter: Bitsight. First seen: 2026-05-20 23:11:59.
Remediations (10)
-
web:blog.qualys.com
How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.
-
web:docs.trendmicro.com
Use Predictive Machine Learning to detect unknown or low-prevalence malware. For more information, see Predictive Machine Learning. Predictive Machine Learning uses the Advanced Threat Scan Engine (ATSE) to extract file features and sends the report to the Predictive Machine Learning engine on the Trend Micro Smart Protection Network.
-
web:learn.microsoft.com
Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:learn.microsoft.com
Take response actions on file -related alerts by stopping and quarantining a file or blocking a file and checking activity details.
-
web:mimecastsupport.zendesk.com
Incidents correspond to a Remediation event and display all the associated messages by the recipient. After viewing an incident, you can perform the following actions: Remove an attachment/message...
-
web:sc1.checkpoint.com
Analysis & Remediation Automated Attack Analysis (Forensics) Endpoint Security Forensics analyzes attacks detected by other detection features like Anti-Ransomware or Behavioral Guard, and some third-party security products. On detection of a malicious event or file , Forensics is informed and a Forensics analysis is automatically initiated. After the analysis is completed, the entire attack ...
-
web:securityboulevard.com
Choosing between remediation and mitigation depends on several factors, including the severity of the vulnerability, available resources, and potential impact on business operations. Here are some considerations to help guide the decision: Urgency and Risk Level When a vulnerability poses a high risk and requires immediate attention, remediation is the preferred choice. By directly fixing the ...
-
web:www.bitdefender.com
Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.
-
web:www.cisa.gov
General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.
-
web:www.reddit.com
If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.