s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb high

📛 Threat Title

Unknown: zlalala.exe

Category: Unknown First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 92160 bytes. Tags: exe. Reporter: BastianHein_. First seen: 2026-05-13 19:53:54.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain zlalala.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/zlalala.exe

IOC database

Type
domain
Value
zlalala.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/zlalala.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
650 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb
1 feed

IOC database

Type
hash_sha256
Value
e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb

hash_sha1 eb12676362f51d71ffcc76a7e947d3e9804e2965 VT 57 / 75 2 feeds

IOC database

Type
hash_sha1
Value
eb12676362f51d71ffcc76a7e947d3e9804e2965
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Flagged by 57 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Adware/Win.Cerbu.C5844242
Alibaba malicious Trojan:MSIL/AsyncRAT.1782c420
alibabacloud malicious Trojan:MSIL/AsyncRAT.Gen
ALYac malicious Trojan.GenericAD.RAT
Antiy-AVL malicious Trojan/MSIL.AsyncRAT
APEX malicious Malicious
Arcabit malicious Trojan.Adware.MSILHeracles.D62C
Avast malicious Win32:MalwareX-gen [Adw]
AVG malicious Win32:MalwareX-gen [Adw]
Avira malicious TR/W32.Agent
BitDefender malicious Gen:Variant.Adware.MSILHeracles.1580
Bkav malicious W32.Malware.7A51F23C
CAT-QuickHeal malicious Trojan.Asyncrat
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.DownLoader49.34723
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Variant.Adware.MSILHeracles.1580 (B)
ESET-NOD32 malicious MSIL/Agent.FQI trojan
F-Secure malicious Trojan.TR/W32.Agent
Fortinet malicious MSIL/Agent.FQI!tr
GData malicious Gen:Variant.Adware.MSILHeracles.1580
Google malicious Detected
Gridinsoft malicious Trojan.Win32.Agent.sa
huorong malicious Trojan/MSIL.Obfuscated.kx
Ikarus malicious Trojan-Spy.StormKitty
K7AntiVirus malicious Trojan ( 700000201 )
K7GW malicious Trojan ( 700000201 )
Kaspersky malicious HEUR:Trojan.MSIL.Agent.gen
Kingsoft malicious MSIL.Trojan.Agent.gen
Lionic malicious Trojan.Win32.AsyncRAT.4!c
Malwarebytes malicious Trojan.Crypt.MSIL
MaxSecure malicious Trojan.Malware.684974154.susgen
McAfeeD malicious Real Protect-LS!E7427C042689
Microsoft malicious Trojan:MSIL/AsyncRAT!atmn
MicroWorld-eScan malicious Gen:Variant.Adware.MSILHeracles.1580
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Trojan.Agent!8.B1E (CLOUD)
Sangfor malicious Virus.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious BehavesLike.Win32.Infected.nh
Sophos malicious Troj/MSIL-TKP
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Msil.Trojan.Agent.Tsmw
Trapmine malicious suspicious.low.ml.score
TrellixENS malicious GenericRXWV-ME!E7427C042689
TrendMicro malicious TROJ_GEN.R014C0DED26
TrendMicro-HouseCall malicious TROJ_GEN.R014C0DED26
Varist malicious W32/MSIL_Agent.KBU.gen!Eldorado
VBA32 malicious Trojan.MSIL.Agent
VIPRE malicious Gen:Variant.Adware.MSILHeracles.1580
VirIT malicious Trojan.Win32.MSIL_Heur.A
ViRobot malicious Trojan.Win.Z.Agent.92160.BMW
ZoneAlarm malicious Troj/MSIL-TKP

Details From VirusTotal

Basic Properties
MD5e7427c042689b62d480478955aae924e
SHA-1eb12676362f51d71ffcc76a7e947d3e9804e2965
SHA-256e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb
VHash29403665151210d9401820737
SSDEEP1536:p3r/cI+xJISqFubM79vVTsqa4tsi5WQf+1LGyamlbTKhCsmswk:p3Dc7pCAX4tn4QWRG9mlbTK8smlk
TLSHT1FA936C0033EC621AFAFF8B7DACB520054A737A1BAD71E64D4C86519D0972B81D924F6B
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size90.0 KB
History
Creation date2061-02-13 16:05 UTC
First seen on VirusTotal2026-05-13 19:23 UTC
Last submission2026-05-13 20:20 UTC
Last analysis2026-05-20 06:05 UTC
Last modified on VirusTotal2026-05-20 08:07 UTC
Known Names
  • Client.exe
  • e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb.exe
  • malware.exe
  • fk41d07e9.exe
  • oeb31z6.exe
  • zlalala.exe
hash_md5 e7427c042689b62d480478955aae924e VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e7427c042689b62d480478955aae924e
2 feeds

IOC database

Type
hash_md5
Value
e7427c042689b62d480478955aae924e
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e7427c042689b62d480478955aae924e

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 92160 bytes. Tags: exe. Reporter: BastianHein_. First seen: 2026-05-13 19:53:54.

Remediations (10)

  • web:learn.microsoft.com

    Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:malwaretips.com

    This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.

  • web:windowsforum.com

    Microsoft's February Patch Tuesday closed a dangerous loophole in the modern Notepad app that could let an attacker turn a simple Markdown (.md) file into a remote code execution (RCE) trap — a single click on a crafted link inside Notepad's Markdown view could launch unverified protocols and...

  • web:www.bleepingcomputer.com

    Page 1 of 4 - Unknown exe file - posted in Virus, Trojan, Spyware, and Malware Removal Help: I recently had a virus in my PC (W7). I had to use 3 different scanners to clean it out (Kaspersky ...

  • web:www.dell.com

    Again, Dell Engineering is aware of the BSOD issue and is working towards a resolution. As many have noted, v ersion 5.5.16.0 of the Dell SupportAssist Remediation service or Alienware SupportAssist Remediation service can cause the BSODs. This service operates independently of the primary Dell SupportAssist application.

  • web:www.dell.com

    About once a day I see in the Windows 11 Diagnostic Data viewer that the Dell. Remediation .Agent.exe program has crashed. No other problems detected. Do I need to worry about this and is there a fix...

  • web:www.howtogeek.com

    If you suspect your PC is infected with malware, or you get a legitimate warning from a tool like Microsoft Defender telling you as such, there are steps you should take immediately to minimize the impact and cure your computer. Whether you're running Windows 10 or 11, here's what you need to do. Turn Off Your Internet and Disconnect Devices The first thing you should do is disconnect your ...

  • web:www.reddit.com

    How Do I Fix " Remediation Incomplete"? I recently downloaded a trojan by accident a couple of days ago and when i ran window defender, this showed up. I did multiple quick scans on malwarebytes and 2 full scans (both i manually canceled because they were taking too long, 8 hours for one and 1 full day for the other) and nothing came up.

  • web:www.reddit.com

    I have seen the entire string of events on a system. Started with an unblocked pdf that maliciously called dell support assist to download trojan from web. Along with using osprofilecollector.exe to exfiltrate stored edge credentials. By no means do I see this as a false positive. ATP blocked the trojan but not the credential stealing.

  • web:www.redditmedia.com

    General Discussion Dell Support Assist Remediation causing bluescreens (self.sysadmin) submitted 18 hours ago * by L3veLUP L1 & L2 support technician Recently we've had a couple of dell devices start to blue screen every few hours with the Bugcheck code: CRITICAL_PROCESS_DIED

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.