s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-a26e60693dadcc06a106fb2cb339f2b438d1c0e1a3e630cbf73a4cc00954b364 high

📛 Threat Title

Unknown: dollar.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 1233920 bytes. Tags: 78-153-130-98, AsgardProtector, exe. Reporter: iamaachum. First seen: 2026-08-04 18:26:58.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 013c74198fc6e42dcf33737d6c40c012

IOC database

Type
hash_imphash
Value
013c74198fc6e42dcf33737d6c40c012
First seen
Last seen
Attached to this threat
Appears in
27 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 a26e60693dadcc06a106fb2cb339f2b438d1c0e1a3e630cbf73a4cc00954b364

IOC database

Type
hash_sha256
Value
a26e60693dadcc06a106fb2cb339f2b438d1c0e1a3e630cbf73a4cc00954b364
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 8ac859dc9d3b94b592c04b1b52283f23cbc69c8d

IOC database

Type
hash_sha1
Value
8ac859dc9d3b94b592c04b1b52283f23cbc69c8d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 e7794ad578908b5416c0ee609231825a

IOC database

Type
hash_md5
Value
e7794ad578908b5416c0ee609231825a
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 1233920 bytes. Tags: 78-153-130-98, AsgardProtector, exe. Reporter: iamaachum. First seen: 2026-08-04 18:26:58.

Remediations (10)

  • web:any.run

    Online sandbox report for dollar.exe , verdict: No threats detected

  • web:app.any.run

    Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

  • web:app.any.run

    Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

  • web:learn.microsoft.com

    Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:malwaretips.com

    This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.

  • web:support.microsoft.com

    Solve problems with detecting and removing malware with Windows Security, including incomplete scans, detection errors, and persistent malware.

  • web:www.joesandbox.com

    Signatures Detected unpacking (creates a PE file in dynamic memory) Early bird code injection technique detected Multi AV Scanner detection for submitted file AI detected suspicious PE / MSI digital signature Connects to many ports of the same IP (likely port scanning) Contains functionality to registers a callback to get notified when the system is suspended or resumed (often done by Miners ...

  • web:www.joesandbox.com

    Automated Malware Analysis - Joe Sandbox Management Report Matched rule: Identifies Metasploit 64 bit reverse tcp shellcode. Author: unknown Uses 32bit PE files Source: dollar.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE Yara signature match Source: dollar.exe , type: SAMPLE Matched rule: Windows_Trojan_Metasploit_4a1c4da8 ...

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.