s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-e73cc325529d9cc0db1a8f76f6231cb37f3f30fe4e22008a99ea9792f37dc105 medium

📛 Threat Title

File hash (SHA256): e73cc325529d9cc0db1a8f76f6231cb37f3f30fe4e22008a99ea9792f37dc105

Category: malware-hash Published: Source updated: First seen: Last updated:

Description

Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA256 hashes: Recent additions

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain abuse.ch VT 0 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
abuse.ch
First seen
Last seen
Attached to this threat
Appears in
4019 threats
Description
Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDch
History
Last analysis2026-05-24 09:28 UTC
Last modified on VirusTotal2026-05-24 16:38 UTC
WHOIS record date2026-03-29 11:09 UTC
hash_sha256 e73cc325529d9cc0db1a8f76f6231cb37f3f30fe4e22008a99ea9792f37dc105 VT 54 / 75 1 feed

IOC database

Type
hash_sha256
Value
e73cc325529d9cc0db1a8f76f6231cb37f3f30fe4e22008a99ea9792f37dc105
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 54 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Basic.C5882397
Alibaba malicious TrojanPSW:MSIL/Agensla.a85904dd
alibabacloud malicious Trojan[stealer]:MSIL/Agensla.gyf
ALYac malicious Trojan.MSIL.Basic.8.Gen
Antiy-AVL malicious Trojan[PSW]/MSIL.Agensla
APEX malicious Malicious
Arcabit malicious Trojan.MSIL.Basic.8.Gen
Avast malicious Win32:MalwareX-gen [Misc]
AVG malicious Win32:MalwareX-gen [Misc]
Avira malicious TR/W32.Agent
BitDefender malicious Trojan.MSIL.Basic.8.Gen
Bkav malicious W32.Malware.711CC5AE
CAT-QuickHeal malicious Trojanpws.Msil
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.MSIL.Basic.8.Gen (B)
ESET-NOD32 malicious MSIL/Kryptik.AQEA trojan
F-Secure malicious Trojan.TR/W32.Agent
Fortinet malicious MSIL/Kryptik.ALAA!tr
GData malicious Trojan.MSIL.Basic.8.Gen
Google malicious Detected
Gridinsoft malicious Trojan.Win32.Agent.sa
huorong malicious Trojan/MSIL.Injector.nj
Ikarus malicious Trojan.MSIL.Crypt
K7AntiVirus malicious Password-Stealer ( 005ce0261 )
K7GW malicious Password-Stealer ( 005ce0261 )
Kaspersky malicious HEUR:Trojan-PSW.MSIL.Agensla.gen
Kingsoft malicious MSIL.Trojan-PSW.Agensla.gen
Lionic malicious Trojan.Win32.Basic.i!c
Malwarebytes malicious Trojan.Downloader.MSIL
MaxSecure malicious Trojan.Malware.325828137.susgen
McAfeeD malicious Trojan:Win/XWorm.NEN
Microsoft malicious Trojan:Win32/Acll!rfn
MicroWorld-eScan malicious Trojan.MSIL.Basic.8.Gen
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:0qQpMzctky01ZD/uSy2ZNQ)
Sangfor malicious Infostealer.Msil.Kryptik.Vypn
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious BehavesLike.Win32.Infected.th
Sophos malicious Mal/Generic-S
Tencent malicious Msil.Trojan.LummaStealer.Tsmw
TrellixENS malicious Artemis!F68A81A8DCF5
TrendMicro malicious Trojan.MSIL.BASIC.TL0101EF26ZZ
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CA3
Varist malicious W32/MSIL_Agent.KBL.gen!Eldorado
VBA32 malicious Malware-Cryptor.MSIL.Fuzzy.Heur
VIPRE malicious Trojan.MSIL.Basic.8.Gen
VirIT malicious Trojan.Win32.MSIL_Heur.A
ViRobot malicious Trojan.Win.Z.Kryptik.1641472
Yandex malicious Trojan.Igent.b6xoKK.2

Details From VirusTotal

Basic Properties
MD5f68a81a8dcf57ce0dbb5f4853b0bf95e
SHA-13758be222203d10284c89e01006f660f03ab02e6
SHA-256e73cc325529d9cc0db1a8f76f6231cb37f3f30fe4e22008a99ea9792f37dc105
VHash2160366515177087383e6460
SSDEEP24576:YFqYflPCmQui1rBgc+9io4nc/I887O9GL52AXTg7yo:IBYus3o4czGO9GtZ
TLSHT1D775D02E2ACF445CD0D1DF789B3237D407B0943758F2D3577B8C53B8EA266A56A8C292
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size1.6 MB
History
Creation date2020-08-03 14:52 UTC
First seen on VirusTotal2026-05-13 16:44 UTC
Last submission2026-05-15 09:05 UTC
Last analysis2026-05-21 15:27 UTC
Last modified on VirusTotal2026-05-21 17:28 UTC
Known Names
  • uehdtrege.exe
  • _e73cc325529d9cc0db1a8f76f6231cb37f3f30fe4e22008a99ea9792f37dc105.exe
  • efi0a.exe
  • NEW_SUPPLY_ORDER.scr

References (1)

  • VirusTotal report

    Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.