s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-399ef79f1146f1f96c589d061b4c6d7b1b5bdba9b7bd679abd9b5a2653e52abf high

📛 Threat Title

Unknown: 399ef79f1146f1f96c589d061b4c6d7b1b5bdba9b7bd679abd9b5a2653e52abf.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 3584 bytes. Tags: exe. Reporter: Tuxxin. First seen: 2026-09-25 12:09:33.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash e82dd51b077167be63c004bed23d0c1e

IOC database

Type
hash_imphash
Value
e82dd51b077167be63c004bed23d0c1e
First seen
Last seen
Attached to this threat
Appears in
106 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 399ef79f1146f1f96c589d061b4c6d7b1b5bdba9b7bd679abd9b5a2653e52abf VT 55 / 75

IOC database

Type
hash_sha256
Value
399ef79f1146f1f96c589d061b4c6d7b1b5bdba9b7bd679abd9b5a2653e52abf
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 55 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.R706966
Alibaba malicious Trojan:Win32/Mikey.4621679e
alibabacloud malicious Trojan:Win/Rozena.7352d04f
ALYac malicious Gen:Variant.Rozena.60
Antiy-AVL malicious Trojan/Win32.Mikey
APEX malicious Malicious
Arcabit malicious Trojan.Rozena.60
Avast malicious Win64:MalwareX-gen [Trj]
AVG malicious Win64:MalwareX-gen [Trj]
Avira malicious TR/W64.MalwareX
BitDefender malicious Gen:Variant.Rozena.60
Bkav malicious W32.Malware.6814CD9
ClamAV malicious Win.Malware.Mikey-10044490-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.rozena
Cylance malicious Unsafe
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.DownLoader48.12277
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Variant.Rozena.60 (B)
ESET-NOD32 malicious Win64/Rozena.ZA trojan
F-Secure malicious Trojan.TR/W64.MalwareX
Fortinet malicious W64/HelloKitty.PNG!tr.ransom
GData malicious Gen:Variant.Rozena.60
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Downloader.sa
huorong malicious TrojanDownloader/Small.hr
Ikarus malicious Trojan.Win64.Shelm
Jiangmin malicious Trojan.Generic.hsgtv
K7AntiVirus malicious Trojan ( 005c2d751 )
K7GW malicious Trojan ( 005c2d751 )
Kaspersky malicious HEUR:Trojan.Win32.Generic
Kingsoft malicious Win32.Troj.mikey.v
Lionic malicious Trojan.Win32.Rozena.4!c
Malwarebytes malicious Trojan.ShellCode.Generic
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious ti!399EF79F1146
Microsoft malicious Trojan:Win32/Mikey.HNC!MTB
MicroWorld-eScan malicious Gen:Variant.Rozena.60
Paloalto malicious generic.ml
Panda malicious Trj/GeneticOnn.gen
Rising malicious Backdoor.VShell/x64!1.13127 (CLASSIC)
Sangfor malicious Trojan.Win32.Rozena.V9sv
Skyhigh malicious Trojan-JAED!45BC663EDB57
Sophos malicious Troj/Loader-IY
SUPERAntiSpyware malicious Trojan.Agent/Gen-Mikey
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Trojan.Win32.Rozena.cbq
TrellixENS malicious Trojan-JAED!45BC663EDB57
Varist malicious W64/Rozena.IC.gen!Eldorado
VIPRE malicious Gen:Variant.Rozena.60
VirIT malicious Trojan.Win64.Genus.GAI
Webroot malicious Win.Trojan.Gen
ZoneAlarm malicious Troj/Loader-IY

Details From VirusTotal

Basic Properties
MD545bc663edb57c6afad58945c5c7077fb
SHA-11186b4b2f9380d918363a63b17ae680a513a3dfe
SHA-256399ef79f1146f1f96c589d061b4c6d7b1b5bdba9b7bd679abd9b5a2653e52abf
VHash03303655151bz1!z
SSDEEP48:6IZUBQYxZul2EywS6DVlvjk7QLzgzIzQz4zAzo157D9N9XM/geu3ahr0/x:2BQMZ7EywS6DVl7++D9vXeg
TLSHT13371B541605456F2D94DE37F8487B895FD4FB28CA2C80B0B0798981B2F7107BB1DEA13
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size3.5 KB
History
Creation date2023-10-26 14:40 UTC
First seen on VirusTotal2026-09-25 11:15 UTC
Last submission2026-09-25 14:31 UTC
Last analysis2026-09-25 14:31 UTC
Last modified on VirusTotal2026-09-25 16:31 UTC
Known Names
  • 222x64b.exe
  • windows_amd64.exe
  • ybmsw.exe
hash_sha1 1186b4b2f9380d918363a63b17ae680a513a3dfe VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/1186b4b2f9380d918363a63b17ae680a513a3dfe

IOC database

Type
hash_sha1
Value
1186b4b2f9380d918363a63b17ae680a513a3dfe
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/1186b4b2f9380d918363a63b17ae680a513a3dfe

hash_md5 45bc663edb57c6afad58945c5c7077fb VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/45bc663edb57c6afad58945c5c7077fb

IOC database

Type
hash_md5
Value
45bc663edb57c6afad58945c5c7077fb
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/45bc663edb57c6afad58945c5c7077fb

References (1)

Remediations (10)

  • web:howtoremove.guide

    How to Fully Get Rid of OneBUpdate The full guide starts with two preparation steps that make the rest of the removal possible. First, you need Windows to show hidden items, because OneBUpdate may place files in locations that are not normally visible. Second, install a tool that can force-delete files when malicious processes keep them locked.

  • web:learn.microsoft.com

    When Microsoft released the remediation steps for this vulnerability, the data type of registry value "EnableCertPaddingCheck" = 1 as REG_SZ and we set this value as "REG_SZ" across all computers.

  • web:learn.microsoft.com

    I'm running into a problem with securing windows 11 23r2 systems and wanted to know if there is a workaround for the following issue: Security Context: CVE-2013-1609 CVE-2014-0759 CVE-2014-5455 Nessus found the following service with an untrusted…

  • web:malwaretips.com

    Removal Instructions for HxTsr.exe Trojan This malware removal guide may appear overwhelming due to the number of steps and numerous programs that are being used. We have only written it this way to provide clear, detailed, and easy-to-understand instructions that anyone can use to remove malware for free.

  • web:support.guardz.com

    SentinelOneInstaller.exe is the full package name. -a installer_arguments : Installer arguments are optional. If there is a web proxy between the endpoints and the Console, you must use the installer arguments to configure the proxy for the Agent in the installation command. -t site_Token or group_Token is the site token or group token.

  • web:windowsforum.com

    Microsoft has published CVE-2026-45585 as a Windows BitLocker security feature bypass vulnerability, with mitigation guidance that tells administrators to mount each device's Windows Recovery Environment image, remove an autofstx.exe entry from WinRE's BootExecute registry value, commit the image, and reestablish BitLocker trust for WinRE. That is a strikingly specific workaround for a ...

  • web:www.dell.com

    About once a day I see in the Windows 11 Diagnostic Data viewer that the Dell. Remediation .Agent.exe program has crashed. No other problems detected. Do I need to worry about this and is there a fix...

  • web:www.dell.com

    How to uninstall the Dell SupportAssist Remediation?Got an error, it means can't find the DellSupportAssistRemediationInstaller.exe. And it also affect me to ...

  • web:www.hackingarticles.in

    Explore AD CS ESC1 Certificate Exploitation, misconfigurations, privilege escalation, and effective mitigation strategies for better security.

  • web:www.youtube.com

    Everything will change animation by dafuqboom designs development/help by: @StriderZ47 (51MP Cameraman, Sound Design) @DeerFromOhio (WOD, Scenebuild) @Zacdoor (Speakermen Base) music: Kelly Bailey ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.