MB-e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb
high
📛 Threat Title
Unknown: zlalala.exe
Description
File type: exe. Size: 92160 bytes. Tags: exe. Reporter: BastianHein_. First seen: 2026-05-13 19:53:54.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
zlalala.exe
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/zlalala.exe
IOC database
- Type
- domain
- Value
zlalala.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/zlalala.exe
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 650 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb
1 feed
IOC database
- Type
- hash_sha256
- Value
e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb
hash_sha1
eb12676362f51d71ffcc76a7e947d3e9804e2965
VT 57 / 75
2 feeds
IOC database
- Type
- hash_sha1
- Value
eb12676362f51d71ffcc76a7e947d3e9804e2965- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Flagged by 57 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Adware/Win.Cerbu.C5844242 |
| Alibaba | malicious | Trojan:MSIL/AsyncRAT.1782c420 |
| alibabacloud | malicious | Trojan:MSIL/AsyncRAT.Gen |
| ALYac | malicious | Trojan.GenericAD.RAT |
| Antiy-AVL | malicious | Trojan/MSIL.AsyncRAT |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Adware.MSILHeracles.D62C |
| Avast | malicious | Win32:MalwareX-gen [Adw] |
| AVG | malicious | Win32:MalwareX-gen [Adw] |
| Avira | malicious | TR/W32.Agent |
| BitDefender | malicious | Gen:Variant.Adware.MSILHeracles.1580 |
| Bkav | malicious | W32.Malware.7A51F23C |
| CAT-QuickHeal | malicious | Trojan.Asyncrat |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.DownLoader49.34723 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Gen:Variant.Adware.MSILHeracles.1580 (B) |
| ESET-NOD32 | malicious | MSIL/Agent.FQI trojan |
| F-Secure | malicious | Trojan.TR/W32.Agent |
| Fortinet | malicious | MSIL/Agent.FQI!tr |
| GData | malicious | Gen:Variant.Adware.MSILHeracles.1580 |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win32.Agent.sa |
| huorong | malicious | Trojan/MSIL.Obfuscated.kx |
| Ikarus | malicious | Trojan-Spy.StormKitty |
| K7AntiVirus | malicious | Trojan ( 700000201 ) |
| K7GW | malicious | Trojan ( 700000201 ) |
| Kaspersky | malicious | HEUR:Trojan.MSIL.Agent.gen |
| Kingsoft | malicious | MSIL.Trojan.Agent.gen |
| Lionic | malicious | Trojan.Win32.AsyncRAT.4!c |
| Malwarebytes | malicious | Trojan.Crypt.MSIL |
| MaxSecure | malicious | Trojan.Malware.684974154.susgen |
| McAfeeD | malicious | Real Protect-LS!E7427C042689 |
| Microsoft | malicious | Trojan:MSIL/AsyncRAT!atmn |
| MicroWorld-eScan | malicious | Gen:Variant.Adware.MSILHeracles.1580 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/CI.A |
| Rising | malicious | Trojan.Agent!8.B1E (CLOUD) |
| Sangfor | malicious | Virus.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | BehavesLike.Win32.Infected.nh |
| Sophos | malicious | Troj/MSIL-TKP |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Msil.Trojan.Agent.Tsmw |
| Trapmine | malicious | suspicious.low.ml.score |
| TrellixENS | malicious | GenericRXWV-ME!E7427C042689 |
| TrendMicro | malicious | TROJ_GEN.R014C0DED26 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R014C0DED26 |
| Varist | malicious | W32/MSIL_Agent.KBU.gen!Eldorado |
| VBA32 | malicious | Trojan.MSIL.Agent |
| VIPRE | malicious | Gen:Variant.Adware.MSILHeracles.1580 |
| VirIT | malicious | Trojan.Win32.MSIL_Heur.A |
| ViRobot | malicious | Trojan.Win.Z.Agent.92160.BMW |
| ZoneAlarm | malicious | Troj/MSIL-TKP |
Details From VirusTotal
Basic Properties
| MD5 | e7427c042689b62d480478955aae924e |
| SHA-1 | eb12676362f51d71ffcc76a7e947d3e9804e2965 |
| SHA-256 | e7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb |
| VHash | 29403665151210d9401820737 |
| SSDEEP | 1536:p3r/cI+xJISqFubM79vVTsqa4tsi5WQf+1LGyamlbTKhCsmswk:p3Dc7pCAX4tn4QWRG9mlbTK8smlk |
| TLSH | T1FA936C0033EC621AFAFF8B7DACB520054A737A1BAD71E64D4C86519D0972B81D924F6B |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 90.0 KB |
History
| Creation date | 2061-02-13 16:05 UTC |
| First seen on VirusTotal | 2026-05-13 19:23 UTC |
| Last submission | 2026-05-13 20:20 UTC |
| Last analysis | 2026-05-20 06:05 UTC |
| Last modified on VirusTotal | 2026-05-20 08:07 UTC |
Known Names
Client.exee7f0b76e70282a3b03e38955d3559660c55f757320930aaf3c413b0951941bcb.exemalware.exefk41d07e9.exeoeb31z6.exezlalala.exe
hash_md5
e7427c042689b62d480478955aae924e
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e7427c042689b62d480478955aae924e
2 feeds
IOC database
- Type
- hash_md5
- Value
e7427c042689b62d480478955aae924e- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e7427c042689b62d480478955aae924e
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 92160 bytes. Tags: exe. Reporter: BastianHein_. First seen: 2026-05-13 19:53:54.
Remediations (10)
-
web:learn.microsoft.com
Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:malwaretips.com
This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.
-
web:windowsforum.com
Microsoft's February Patch Tuesday closed a dangerous loophole in the modern Notepad app that could let an attacker turn a simple Markdown (.md) file into a remote code execution (RCE) trap — a single click on a crafted link inside Notepad's Markdown view could launch unverified protocols and...
-
web:www.bleepingcomputer.com
Page 1 of 4 - Unknown exe file - posted in Virus, Trojan, Spyware, and Malware Removal Help: I recently had a virus in my PC (W7). I had to use 3 different scanners to clean it out (Kaspersky ...
-
web:www.dell.com
Again, Dell Engineering is aware of the BSOD issue and is working towards a resolution. As many have noted, v ersion 5.5.16.0 of the Dell SupportAssist Remediation service or Alienware SupportAssist Remediation service can cause the BSODs. This service operates independently of the primary Dell SupportAssist application.
-
web:www.dell.com
About once a day I see in the Windows 11 Diagnostic Data viewer that the Dell. Remediation .Agent.exe program has crashed. No other problems detected. Do I need to worry about this and is there a fix...
-
web:www.howtogeek.com
If you suspect your PC is infected with malware, or you get a legitimate warning from a tool like Microsoft Defender telling you as such, there are steps you should take immediately to minimize the impact and cure your computer. Whether you're running Windows 10 or 11, here's what you need to do. Turn Off Your Internet and Disconnect Devices The first thing you should do is disconnect your ...
-
web:www.reddit.com
How Do I Fix " Remediation Incomplete"? I recently downloaded a trojan by accident a couple of days ago and when i ran window defender, this showed up. I did multiple quick scans on malwarebytes and 2 full scans (both i manually canceled because they were taking too long, 8 hours for one and 1 full day for the other) and nothing came up.
-
web:www.reddit.com
I have seen the entire string of events on a system. Started with an unblocked pdf that maliciously called dell support assist to download trojan from web. Along with using osprofilecollector.exe to exfiltrate stored edge credentials. By no means do I see this as a false positive. ATP blocked the trojan but not the credential stealing.
-
web:www.redditmedia.com
General Discussion Dell Support Assist Remediation causing bluescreens (self.sysadmin) submitted 18 hours ago * by L3veLUP L1 & L2 support technician Recently we've had a couple of dell devices start to blue screen every few hours with the Bugcheck code: CRITICAL_PROCESS_DIED
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.