s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-7c9826bd66e3acaf4b2442c8ae5b391fdec3318cbc7fa8030ca32674d66af075 high

📛 Threat Title

FleetDeck: 7c9826bd66e3acaf4b2442c8ae5b391fdec3318cbc7fa8030ca32674d66af075.exe

Category: FleetDeck Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 4398568 bytes. Tags: exe, FleetDeck, signed. Reporter: Tuxxin. First seen: 2026-09-25 05:50:11.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash 9cbefe68f395e67356e2a5d8d1b285c0

IOC database

Type
hash_imphash
Value
9cbefe68f395e67356e2a5d8d1b285c0
First seen
Last seen
Attached to this threat
Appears in
111 threats
Description
imphash of URLhaus payload 828405d66881b770…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 7c9826bd66e3acaf4b2442c8ae5b391fdec3318cbc7fa8030ca32674d66af075

IOC database

Type
hash_sha256
Value
7c9826bd66e3acaf4b2442c8ae5b391fdec3318cbc7fa8030ca32674d66af075
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
FleetDeck

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 50a3fa219d21768707f8f361f419ca7ea634e413

IOC database

Type
hash_sha1
Value
50a3fa219d21768707f8f361f419ca7ea634e413
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 4c771d29935ceec3c76df5794b3ca4e0

IOC database

Type
hash_md5
Value
4c771d29935ceec3c76df5794b3ca4e0
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 4398568 bytes. Tags: exe, FleetDeck, signed. Reporter: Tuxxin. First seen: 2026-09-25 05:50:11.

Remediations (10)

  • web:fleetdeck.com

    fleetdeck .com

  • web:fleetdeck.eu

    FleetDeck Sign in to your account Email

  • web:fleetdeck.io

    FleetDeck is a new Remote Desktop & Virtual Terminal solution, tailored for techs to securely manage large fleets of computers.

  • web:fleetdeck.io

    Stay signed in Next

  • web:forums.malwarebytes.com

    We are developing a remote desktop application: https:// fleetdeck .io We have received reports from our clients that the following dns names are blocked: agentupdate. fleetdeck .io agentmqtt. fleetdeck .io a2oyfiw9bzanl4-ats.iot.us-west-2.amazonaws.com Would it be possible to unblock these please? Tha...

  • web:gridinsoft.com

    Trojan Agent malware disguises itself as legitimate software while performing unauthorized activities including data theft and providing remote system access to threat actors.

  • web:gridinsoft.com

    Trojan Agent malware disguises itself as legitimate software while performing unauthorized activities including data theft and providing remote system access to threat actors.

  • web:ismalicious.com

    15 indicators of compromise attributed to the FleetDeck malware family — domains, IPs, URLs and file hashes, from abuse.ch feeds.

  • web:www.joesandbox.com

    Source: fleetdeck -agent-Cj6FHZ3oLsN5ZbMiiZGcf5.exe Static PE information: certificate valid Contains modern PE file flags such as dynamic base (ASLR) or NX Source: fleetdeck -agent-Cj6FHZ3oLsN5ZbMiiZGcf5.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE Binary contains paths to debug symbols Source:

  • web:www.securitricks.com

    Fleetdeck on Securitricks: related threat intelligence, IOCs, and MITRE context.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.