s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-dd9d754896001df78f96486b10729650e5957a08e4931d6b6a1a154753a26c63 high

📛 Threat Title

Unknown: file

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 35098547 bytes. Tags: d52f85, dropped-by-Amadey, exe. Reporter: Bitsight. First seen: 2026-08-04 23:48:30.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 70d2e884fa127843c5bcbb53da86b6c8

IOC database

Type
hash_imphash
Value
70d2e884fa127843c5bcbb53da86b6c8
First seen
Last seen
Attached to this threat
Appears in
8 threats
Description
imphash of URLhaus payload 9c5ccde7c7def1a5…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 dd9d754896001df78f96486b10729650e5957a08e4931d6b6a1a154753a26c63

IOC database

Type
hash_sha256
Value
dd9d754896001df78f96486b10729650e5957a08e4931d6b6a1a154753a26c63
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 e3f1a63acf8c12e1994da70dcc1b9508

IOC database

Type
hash_md5
Value
e3f1a63acf8c12e1994da70dcc1b9508
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 8b5a5b2eafac846e3995f2e80fa2e801df585519

IOC database

Type
hash_sha1
Value
8b5a5b2eafac846e3995f2e80fa2e801df585519
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 35098547 bytes. Tags: d52f85, dropped-by-Amadey, exe. Reporter: Bitsight. First seen: 2026-08-04 23:48:30.

Remediations (9)

  • web:learn.microsoft.com

    Remediation actions can include removing a file , sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:learn.microsoft.com

    Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:www.bugcrowd.com

    Mitigation solutions include isolating a set of vulnerable resources from the rest of the network with segmentation, temporarily disabling an application, or blocking a port that could provide access to a vulnerable resource. Your choice usually isn't a straightforward either/or decision between vulnerability remediation and mitigation .

  • web:www.cisa.gov

    General Mitigation Guidance Restrict or Discontinue Use of FTP and Telnet Services The FTP and Telnet protocols transmit credentials in cleartext, which are susceptible to being intercepted. To mitigate this risk, discontinue FTP and Telnet services by moving to more secure file storage/ file transfer and remote access services.

  • web:www.crowdstrike.com

    Here, we can see the details of the remediation actions, such as any files quarantined, processes killed, and registry values deleted. We can also release any quarantined files as well. When we navigate to remediation , a list of all the remediation activities across the entire organization is available.

  • web:www.isdecisions.com

    FileAudit automates remediation and response to file access events. Run automated scripts to shut down a machine, log off a user, and more.

  • web:www.majorgeeks.com

    How to Fix Windows Defender Remediation Incomplete From an Application If the file in question is from an installed program, you can allow it, as mentioned above, or uninstall the application if you don't need it.

  • web:www.rapid7.com

    Automation can be a big help in effective vulnerability management, both when it comes to remediation and mitigation . For remediation , you'll want to adopt a vulnerability management solution, like Rapid7's InsightVM, that eliminates the need for manual reporting, complex spreadsheets, and confusing back-and-forth email tags.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.