s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d high

📛 Threat Title

Unknown: bd7d85741a3801d8fe7a725061249337.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 2507264 bytes. Tags: apt, exe, Kazuar, Turla. Reporter: smica83. First seen: 2026-05-14 10:39:08.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain bd7d85741a3801d8fe7a725061249337.exe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/bd7d85741a3801d8fe7a725061249337.exe

IOC database

Type
domain
Value
bd7d85741a3801d8fe7a725061249337.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/bd7d85741a3801d8fe7a725061249337.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
656 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d
1 feed

IOC database

Type
hash_sha256
Value
6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6eb31006ca318a21eb619d008226f08e287f753aec9042269203290462eaa00d

hash_sha1 fb5eb1cad3444d7a1647bb906fff3200d8a707f3 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/fb5eb1cad3444d7a1647bb906fff3200d8a707f3
2 feeds

IOC database

Type
hash_sha1
Value
fb5eb1cad3444d7a1647bb906fff3200d8a707f3
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/fb5eb1cad3444d7a1647bb906fff3200d8a707f3

hash_md5 bd7d85741a3801d8fe7a725061249337 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/bd7d85741a3801d8fe7a725061249337
2 feeds

IOC database

Type
hash_md5
Value
bd7d85741a3801d8fe7a725061249337
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/bd7d85741a3801d8fe7a725061249337

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 2507264 bytes. Tags: apt, exe, Kazuar, Turla. Reporter: smica83. First seen: 2026-05-14 10:39:08.

Remediations (10)

  • web:isgovern.com

    At times you will find that some applications and/or services are not configured correctly, and when performing a vulnerability scan on your machine you may see a vulnerability listed as "Microsoft Windows Unquoted Service Path". This can also pop up if you are going for a Cyber Essentials Plus certification. So what does this vulnerability

  • web:malwaretips.com

    This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.

  • web:publiccloudimagechangeinfo.suse.com

    While upgrading is the most secure and recommended path, users can mitigate the vulnerability using one of the following methods: Use a validating interceptor (recommended mitigation ); infrastructure-level normalization; and/or policy hardening. Packages affected:

  • web:windowsforum.com

    Microsoft's February Patch Tuesday closed a dangerous loophole in the modern Notepad app that could let an attacker turn a simple Markdown (.md) file into a remote code execution (RCE) trap — a single click on a crafted link inside Notepad's Markdown view could launch unverified protocols and...

  • web:www.bleepingcomputer.com

    Windows 11 Possible Infection, Unsigned EXE Files Run without Prompt - posted in Virus, Trojan, Spyware, and Malware Removal Help: OS Name: Window 11 Home Version: 10.0.22631 Build 22631 What I ...

  • web:www.dell.com

    About once a day I see in the Windows 11 Diagnostic Data viewer that the Dell. Remediation .Agent.exe program has crashed. No other problems detected. Do I need to worry about this and is there a fix...

  • web:www.microsoft.com

    A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain. The attack leverages renamed Windows tools and cloud-hosted payloads to install MSI backdoors and maintain persistent access to compromised systems.

  • web:www.reddit.com

    If you don't have the in house staff to perform the threat analysis or threat hunting, you need a SOC. You could look at black point cyber since your are a PAX 8 customer. You currently have the detection portion of EDR, but not the analysis and remediation piece. You can't compare Symantec to Sentinel One, they aren't the same. Sentinel One IMO, is a far superior product, and in the years we ...

  • web:www.virustotal.com

    VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.

  • web:www.windowsdigitals.com

    Can't install or run an app from unknown publisher? Here's how to allow unknown publisher in Windows 11/10, and how to disable the warning.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.