s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b high

📛 Threat Title

Unknown: file

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 18944 bytes. Tags: dropped-by-phorpiex, exe. Reporter: Bitsight. First seen: 2026-05-20 23:11:59.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash b8b034a37970476c0e8791d5941c31e3

IOC database

Type
hash_imphash
Value
b8b034a37970476c0e8791d5941c31e3
First seen
Last seen
Attached to this threat
Appears in
25 threats
Description
imphash of URLhaus payload 0c8dffc78085cbbe…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b

IOC database

Type
hash_sha256
Value
0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 048b96ef603873e543484d13eff75ada VT 50 / 75

IOC database

Type
hash_md5
Value
048b96ef603873e543484d13eff75ada
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 50 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Phorpiex.R601456
Alibaba malicious TrojanDropper:Win32/Phorpiex.bf4a23aa
alibabacloud malicious Trojan:Win/Phorpiex.RK8PHU
Antiy-AVL malicious Trojan/Win32.Patched
APEX malicious Malicious
Arcabit malicious Trojan.Mint.Zard.39
Avast malicious Win32:MalwareX-gen [Bot]
AVG malicious Win32:MalwareX-gen [Bot]
Avira malicious TR/W32.MalwareX
BitDefender malicious Gen:Heur.Mint.Zard.39
Bkav malicious W32.Malware.7A294514
CrowdStrike malicious win/malicious_confidence_100% (D)
CTX malicious exe.unknown.mint
Cylance malicious Unsafe
Cynet malicious Malicious (score: 100)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.DownLoader46.474
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Heur.Mint.Zard.39 (B)
ESET-NOD32 malicious Win32/Phorpiex_AGen.U worm
F-Secure malicious Trojan.TR/W32.MalwareX
GData malicious Gen:Heur.Mint.Zard.39
Google malicious Detected
huorong malicious Worm/Phorpiex.o
Ikarus malicious Worm.Win32.Phorpiex
K7AntiVirus malicious EmailWorm ( 005df7d61 )
K7GW malicious EmailWorm ( 005df7d61 )
Kaspersky malicious HEUR:Trojan-Dropper.Win32.Phorpiex.gen
Kingsoft malicious Win32.Trojan-Dropper.Phorpiex.gen
Malwarebytes malicious Spyware.Phorpiex
McAfeeD malicious ti!0C8DFFC78085
Microsoft malicious Trojan:Win32/Phorpiex.BF!MTB
MicroWorld-eScan malicious Gen:Heur.Mint.Zard.39
Paloalto malicious generic.ml
Panda malicious Trj/Genetic.gen
Rising malicious Worm.Phorpiex!1.13E48 (CLASSIC)
Sangfor malicious Trojan.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious Trojan-JBBB!048B96EF6038
Sophos malicious W32/Phorpiex-BC
SUPERAntiSpyware malicious Trojan.Agent/Gen-Downloader
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious OB:Worm.Win32.Phorpiex.ha
TrellixENS malicious Trojan-JBBB!048B96EF6038
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CA3
Varist malicious W32/S-c70f2e64!Eldorado
VBA32 malicious BScope.TrojanDropper.Phorpiex
VIPRE malicious Gen:Heur.Mint.Zard.39
Xcitium malicious TrojWare.Win32.Injector.UOL@4q80ri
ZoneAlarm malicious W32/Phorpiex-BC

Details From VirusTotal

Basic Properties
MD5048b96ef603873e543484d13eff75ada
SHA-1f00d28512f510fb28b889155cdbcf97224ec5869
SHA-2560c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b
VHash014056555d15555az1ejz31z21z61zc2z2a1z
SSDEEP384:RCIJlVYeR+HY4wfb0tu9JRSOPTNav8U9c2/:84B0Y99a0UF
TLSHT1DC824C0FB9864316C0E100B05576963BDA799CB2338464EFF7D48A991B686E5FC3325F
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows
File size18.5 KB
History
Creation date2026-05-20 01:58 UTC
First seen on VirusTotal2026-05-20 23:15 UTC
Last submission2026-05-21 00:08 UTC
Last analysis2026-05-21 00:08 UTC
Last modified on VirusTotal2026-05-22 20:56 UTC
Known Names
  • 0c8dffc78085cbbed6cd8cc85a396dfa554e92d038b616558da211d07968b62b.exe
  • 13[1].exe
  • 2864436615.exe
  • 13.exe
  • file.exe
hash_sha1 f00d28512f510fb28b889155cdbcf97224ec5869

IOC database

Type
hash_sha1
Value
f00d28512f510fb28b889155cdbcf97224ec5869
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 18944 bytes. Tags: dropped-by-phorpiex, exe. Reporter: Bitsight. First seen: 2026-05-20 23:11:59.

Remediations (10)

  • web:blog.qualys.com

    How Does the RedSun Vulnerability Exploit Chain Work? At its core, RedSun abuses a logic flaw in how Defender handles cloud-tagged files during remediation . When Defender detects a malicious file carrying a cloud tag, it attempts to restore the file back to its original location rather than simply quarantining or deleting it.

  • web:docs.trendmicro.com

    Use Predictive Machine Learning to detect unknown or low-prevalence malware. For more information, see Predictive Machine Learning. Predictive Machine Learning uses the Advanced Threat Scan Engine (ATSE) to extract file features and sends the report to the Predictive Machine Learning engine on the Trend Micro Smart Protection Network.

  • web:learn.microsoft.com

    Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:learn.microsoft.com

    Take response actions on file -related alerts by stopping and quarantining a file or blocking a file and checking activity details.

  • web:mimecastsupport.zendesk.com

    Incidents correspond to a Remediation event and display all the associated messages by the recipient. After viewing an incident, you can perform the following actions: Remove an attachment/message...

  • web:sc1.checkpoint.com

    Analysis & Remediation Automated Attack Analysis (Forensics) Endpoint Security Forensics analyzes attacks detected by other detection features like Anti-Ransomware or Behavioral Guard, and some third-party security products. On detection of a malicious event or file , Forensics is informed and a Forensics analysis is automatically initiated. After the analysis is completed, the entire attack ...

  • web:securityboulevard.com

    Choosing between remediation and mitigation depends on several factors, including the severity of the vulnerability, available resources, and potential impact on business operations. Here are some considerations to help guide the decision: Urgency and Risk Level When a vulnerability poses a high risk and requires immediate attention, remediation is the preferred choice. By directly fixing the ...

  • web:www.bitdefender.com

    Ransomware Mitigation uses detection and remediation technologies to keep your data safe from ransomware attacks. Whether the ransomware is known or new, GravityZone detects abnormal encryption attempts and blocks the process.

  • web:www.cisa.gov

    General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.

  • web:www.reddit.com

    If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.