MB-cc73561480591baee4c47ce8b44cf37e22a326f9f2ccb8cce224407fcb0c0044
high
📛 Threat Title
Unknown: 004911_MT103_001_rejection_000223346.exe
Description
File type: exe. Size: 348328 bytes. Tags: exe, signed. Reporter: lowmal3. First seen: 2026-09-25 06:31:26.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
7eae418c7423834ffc3d79b4300bd6fb
IOC database
- Type
- hash_imphash
- Value
7eae418c7423834ffc3d79b4300bd6fb- First seen
- Last seen
- Attached to this threat
- Appears in
- 4 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
cc73561480591baee4c47ce8b44cf37e22a326f9f2ccb8cce224407fcb0c0044
IOC database
- Type
- hash_sha256
- Value
cc73561480591baee4c47ce8b44cf37e22a326f9f2ccb8cce224407fcb0c0044- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
4ce03eb543a34b1a6b054d3af50a854d546edd44
IOC database
- Type
- hash_sha1
- Value
4ce03eb543a34b1a6b054d3af50a854d546edd44- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
27371b0d504f1df1e9ba9a11aa31c295
IOC database
- Type
- hash_md5
- Value
27371b0d504f1df1e9ba9a11aa31c295- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 348328 bytes. Tags: exe, signed. Reporter: lowmal3. First seen: 2026-09-25 06:31:26.
Remediations (10)
-
web:ohmyfin.org
Most MT103 rejects fall into five categories: missing BIC, malformed IBAN, empty field 70, charge-code mismatch, and value-date in the past. Diagnosis and fixes.
-
web:ohmyfin.org
MS03 (NotSpecifiedReasonAgentGenerated) is an ISO 20022 ExternalReturnReason code used in pacs.002 / MT103 STP rejection messages on the SWIFT network. Generic rejection — agent rejected without disclosing the reason.
-
web:paymentbrief.com
Field-by-field MT103 reference: mandatory/optional status, format specs, and failure modes for fields 20 through 77T, plus MT103 vs MT103+ vs REMIT.
-
web:paymentbrief.com
Field-by-field mapping of MT103 to ISO 20022 pacs.008 for payment operators: UETR, EndToEndId, party fields, charges, and post-migration investigation flow.
-
web:paymentsinfintech.com
That's where MT103 Return messages come into play—and their modern ISO 20022 (MX) equivalents like pacs.004. Understand return messages.
-
web:walllet.com
Learn which payment proof to request, who must start the trace and how MT103, pacs.008 and UETR help locate an international wire.
-
web:www.hiwipay.com
Below, we'll cover what is MT103, how to read MT103 fields 20, 32A, 59, and walk through an SWIFT MT103 example field by field. The Fast Idea: Reading MT103 at a Glance When you open an MT103, your eyes can go straight to five anchors: :20: Sender's Reference - the transfer's "order number" from the sending bank.
-
web:www.iotafinance.com
SWIFT ISO15022 Standard Detail view for message MT103 - Single Customer Credit Transfer Description of the message MT103 The MT 103 is a General Use message, that is, no registration in a Message User Group (MUG) is necessary to send and receive this message.
-
web:www.swift.com
Pre ISO migration, an MT103/202 message with a code word present within the free format field (F72) would be used to return payments. The MT format for returns would be heavily reliant on the presence of multiple code words within field 72 used to provide the return details to the receiver.
-
web:www.swiftmxbridge.com
Find the payment rejection, NACK, or schema mismatch behind your SWIFT/ISO 20022 failure. Search for the exact issue your operations team is seeing: MT103 and MT202 validation failures, pacs.008 conversion breaks, NACK responses, account detail rejects, and field-level parsing errors that can delay settlement.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.