IOC LOOKUP
// SEARCH IP, DOMAIN, HASH, OR URL AGAINST OTX THREAT INTELLIGENCE
Indicator of Compromise Search
✦ IPv4 Address
✦ Domain
✦ MD5/SHA1/SHA256 Hash
✦ URL
INDICATOR
fc1ba79eacfbe205603ab9bd2233e01ff4bb3aaf072c3625d744d6e3a0aa8399
55
/100
HIGH
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
HIGH
55/100 confidence
Strong evidence of malicious activity across multiple sources. Prioritise investigation.
CLEAN
LOW
MED
HIGH
CRIT
0
25
50
75
100
OTX
10/30
1 pulses
VIRUSTOTAL
35/35
39/76 detected
ABUSEIPDB
—/25
IPv4 only
URLHAUS
10/10
LISTED
General Information
| Hash | fc1ba79eacfbe205603ab9bd2233e01ff4bb3aaf072c3625d744d6e3a0aa8399 |
| File Type | FileHash-SHA256 |
AlienVault OTX Analysis
↗ View on OTX
1
PULSE HITS
| Pulse Hits | 1 |
| Indicator Type | SHA256 |
| Threat Level | |
| Source | ⚡ CACHED |
ASSOCIATED PULSES
| PULSE NAME | DATE |
|---|---|
| 2025-05-26 |
VirusTotal Analysis
↗ View on VirusTotal
39/76
DETECTIONS
MALICIOUS
| Malicious | 39 |
| Suspicious | 0 |
| Harmless | 0 |
| Undetected | 32 |
| Reputation | 0 |
| File Name | e4VwdF8.exe |
| File Type | Win32 EXE |
| File Size | 5559.2 KB |
TOP DETECTIONS
| VENDOR | RESULT |
|---|---|
| ALYac | Application.Scam.Sconnect.GenericKD.42 |
| AVG | Other:Malware-gen [Trj] |
| Arcabit | Application.Scam.Sconnect.Generic.42 |
| Avast | Other:Malware-gen [Trj] |
| BitDefender | Application.Scam.Sconnect.GenericKD.42 |
| Bkav | W32.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.1762070835d21f69 |
| CTX | exe.trojan.connectwise |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
URLhaus (abuse.ch)
↗ View on URLhaus
⚠ LISTED
URLHAUS
| URLs Found | 2 |
| First Seen | 2025-05-26 |
| Malware | ConnectWise |
| File Type | exe |
ASSOCIATED URLs
| URL | STATUS / TYPE | DATE |
|---|---|---|
| http://185.156.72.2/files/6012304042/e4VwdF8.exe | offline | — |
| http://185.156.72.2/files/6012304042/MW9if06.exe | offline | — |