IOC Radar Logo
IOCRadar
IOC Radar Logo
IOCRadar

0471e7979a38464845a1860e059cbce2

Hash
18%
SIGNAL STRENGTHSlightly Noisy
FIRST SEEN2025-03-31 09:40:05
LAST SEEN2025-04-22 20:36:21
CATEGORY
malware
database spesific attack(postgresql)
port scanning and brute force attempts
database spesific attack(mysql)
operation system spesific attack(windows os)
win32 malware
telnet threat
ssh attack
port scan
protocol spesific attack(rdp)
MITRE
T1595 - Active Scanning
T1499.002 - Endpoint DoS
T1499.003 - Network DoS
T1496 - Resource Hijacking
T1190 - Exploit Public-Facing Application
T1059.003 - SQL Injection
T1505.002 - Server Software Component
T1110.002 - Brute Force
T1076 - Remote Desktop Protocol
T1563 - Remote Services
TAGS
windows malware
malicious software
server exploitation
credential access
protocol exploitation
distributed attacks
command and control
network security
database security
remote services
Eye Icon
SOCRadar
AI Insight

The presence of the MD5 hash 0471e7979a38464845a1860e059cbce2 is a critical Indicator of Compromise (IOC) due to its strong association with potentially malicious files, particularly those masquerading as legitimate Windows Defender components, such as MPGEAR.DLL, mpengine.dll, mrt.exe, and mrtstub.exe. This suggests a possible attempt to evade detection or facilitate unauthorized actions on the compromised system. The high score (18.0) and presence in multiple threat feeds (SOCRadar Threat Exchange Services, AlienVault OTX Feeds) reinforce the severity of this finding, indicating a need for immediate investigation and remediation to prevent further compromise or data exfiltration.

Summary

Hash Type:
md5
MD5:
-
SHA-1:
-
SHA-256:
-
Files:
mrtstub.exe
File Type:
exe

Top Classifications

Campaign:
-
Industry:
-
Country:
-
Region:
-
Threat Actors:
-
Malware:
-

Feed Sources

Feed Source
Count
Date
SOCRadar Threat Exchange Services
1
2025-04-22
AlienVault OTX Feeds
2
2025-04-03

Threat Activity Timeline

Last 24 hours
Minimal Activity
Last 7 Days
Minimal Activity
Last Month
Minimal Activity
Last 3 Months
Minimal Activity
Extended Threat Intelligence
Free Trial

Stay ahead with proactive cyber threat warnings

Discover how SOCRadar's all-in-one platform can help protect your digital assets with extended threat intelligence, digital risk protection, and attack surface management.