s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-45880839303fe491b2676a37faaa1fe6192917b3e64de1d46858563f16518e2f high

📛 Threat Title

BlakcSeeStealer: vsdbg.dll

Category: BlakcSeeStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 2404352 bytes. Tags: 94-183-168-16, BlakcSeeStealer, dll, exe. Reporter: iamaachum. First seen: 2026-08-04 19:26:42.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 7c15ad67c5cfe43a17beff396750ae2c

IOC database

Type
hash_imphash
Value
7c15ad67c5cfe43a17beff396750ae2c
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 45880839303fe491b2676a37faaa1fe6192917b3e64de1d46858563f16518e2f

IOC database

Type
hash_sha256
Value
45880839303fe491b2676a37faaa1fe6192917b3e64de1d46858563f16518e2f
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
BlakcSeeStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 4319a638252be2141e4878d709a60ac61168ccc2

IOC database

Type
hash_sha1
Value
4319a638252be2141e4878d709a60ac61168ccc2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 edf5eeed72c207be16d9119f87b6a70c

IOC database

Type
hash_md5
Value
edf5eeed72c207be16d9119f87b6a70c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 2404352 bytes. Tags: 94-183-168-16, BlakcSeeStealer, dll, exe. Reporter: iamaachum. First seen: 2026-08-04 19:26:42.

Remediations (10)

  • web:gist.github.com

    Can you advise on how to change the signature of ms-vscode.cpptools-1.23.6-win32-x64 ( vsdbg.dll )? It would be great if modified DLL files could be provided. Thanks~ My instructions are already very clear. You just need to find yourself a hex editor, locate the patch offset, and modify a single byte according to the directions.

  • web:github.com

    Microsoft and the .NET community have created a new version of .NET, .NET Core, which is designed to be cross-platform, modular, and optimized for the cloud. If you want to debug on the target device itself, you can use Visual Studio Code by following these instructions. But it is also possible to stay in Visual Studio and still debug to Linux or OSX. For day-to-day development, especially if ...

  • web:gridinsoft.com

    This detection name identifies suspicious files displaying Trojan-like behavior patterns. It represents malware that masquerades as benign programs while executing unauthorized activities on the infected system.

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Debug a Visual Studio application that has been deployed on a different computer by using the Visual Studio remote debugger.

  • web:threatinfo.net

    GridinSoft detects vsdbg.dll as Trojan.Downloader. Review MD5 edaa1278e859f7ca218838e2379afb39, Trojan context, publisher data, observed locations, and removal steps.

  • web:threatinfo.net

    GridinSoft detects vsdbg.dll as Trojan.Packed. Review MD5 f622b82ab4ecac11c217ded50a928022, Trojan context, publisher data, observed locations, and removal steps.

  • web:tria.ge

    Check this blakcsee_stealer report malware sample 4059caf0b7cde8dd3b9d3178764d305ba91bdf44c7c9febd2ea7014f7fba279d, with a score of 10 out of 10.

  • web:www.joesandbox.com

    vsdbg.dll.dll Status: finished Submission Time: 2026-07-23 09:23:33 +02:00 Malicious

  • web:www.joesandbox.com

    Deep Malware Analysis - Joe Sandbox Analysis Report Loading Joe Sandbox Report ... Play interactive tourEdit tour Windows Analysis Report vsdbg.dll.dll

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.