MB-a26e60693dadcc06a106fb2cb339f2b438d1c0e1a3e630cbf73a4cc00954b364
high
📛 Threat Title
Unknown: dollar.exe
Description
File type: exe. Size: 1233920 bytes. Tags: 78-153-130-98, AsgardProtector, exe. Reporter: iamaachum. First seen: 2026-08-04 18:26:58.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
013c74198fc6e42dcf33737d6c40c012
IOC database
- Type
- hash_imphash
- Value
013c74198fc6e42dcf33737d6c40c012- First seen
- Last seen
- Attached to this threat
- Appears in
- 27 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
a26e60693dadcc06a106fb2cb339f2b438d1c0e1a3e630cbf73a4cc00954b364
IOC database
- Type
- hash_sha256
- Value
a26e60693dadcc06a106fb2cb339f2b438d1c0e1a3e630cbf73a4cc00954b364- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
8ac859dc9d3b94b592c04b1b52283f23cbc69c8d
IOC database
- Type
- hash_sha1
- Value
8ac859dc9d3b94b592c04b1b52283f23cbc69c8d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
e7794ad578908b5416c0ee609231825a
IOC database
- Type
- hash_md5
- Value
e7794ad578908b5416c0ee609231825a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 1233920 bytes. Tags: 78-153-130-98, AsgardProtector, exe. Reporter: iamaachum. First seen: 2026-08-04 18:26:58.
Remediations (10)
-
web:any.run
Online sandbox report for dollar.exe , verdict: No threats detected
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:learn.microsoft.com
Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:malwaretips.com
This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.
-
web:support.microsoft.com
Solve problems with detecting and removing malware with Windows Security, including incomplete scans, detection errors, and persistent malware.
-
web:www.joesandbox.com
Signatures Detected unpacking (creates a PE file in dynamic memory) Early bird code injection technique detected Multi AV Scanner detection for submitted file AI detected suspicious PE / MSI digital signature Connects to many ports of the same IP (likely port scanning) Contains functionality to registers a callback to get notified when the system is suspended or resumed (often done by Miners ...
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Management Report Matched rule: Identifies Metasploit 64 bit reverse tcp shellcode. Author: unknown Uses 32bit PE files Source: dollar.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE Yara signature match Source: dollar.exe , type: SAMPLE Matched rule: Windows_Trojan_Metasploit_4a1c4da8 ...
-
web:www.majorgeeks.com
Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.