MB-4dc6f64b03a38e9824f257115cbdcbfb1ced916138325450b62c69094bbd53ec
high
📛 Threat Title
Unknown: Setup.exe
Description
File type: exe. Size: 5618384 bytes. Tags: exe, signed, Vidar. Reporter: iam_py_test. First seen: 2026-05-14 18:06:09.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
setup.exe
VT: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/setup.exe
IOC database
- Type
- domain
- Value
setup.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- Extracted from Threat MB-4dc6f64b03a38e9824f257115cbdcbfb1ced916138325450b62c69094bbd53ec
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/setup.exe
hash_imphash
d42595b695fc008ef2c56aabd8efd68e
IOC database
- Type
- hash_imphash
- Value
d42595b695fc008ef2c56aabd8efd68e- First seen
- Last seen
- Attached to this threat
- Appears in
- 469 threats
- Description
- imphash of URLhaus payload a7b9f3dda435b7f2…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
4dc6f64b03a38e9824f257115cbdcbfb1ced916138325450b62c69094bbd53ec
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4dc6f64b03a38e9824f257115cbdcbfb1ced916138325450b62c69094bbd53ec
1 feed
IOC database
- Type
- hash_sha256
- Value
4dc6f64b03a38e9824f257115cbdcbfb1ced916138325450b62c69094bbd53ec- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/4dc6f64b03a38e9824f257115cbdcbfb1ced916138325450b62c69094bbd53ec
hash_sha1
ce5e58d1934d41b538ecacfbf091e2d96ad29cdc
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/ce5e58d1934d41b538ecacfbf091e2d96ad29cdc
1 feed
IOC database
- Type
- hash_sha1
- Value
ce5e58d1934d41b538ecacfbf091e2d96ad29cdc- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/ce5e58d1934d41b538ecacfbf091e2d96ad29cdc
hash_md5
26ebf0896e5343d8922ead8f80174642
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/26ebf0896e5343d8922ead8f80174642
1 feed
IOC database
- Type
- hash_md5
- Value
26ebf0896e5343d8922ead8f80174642- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/26ebf0896e5343d8922ead8f80174642
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 5618384 bytes. Tags: exe, signed, Vidar. Reporter: iam_py_test. First seen: 2026-05-14 18:06:09.
Remediations (9)
-
web:appuals.com
Windows Setup Remediation (KB4023057) is a Windows servicing stack update and includes reliability improvements. This update includes files and resources that address issues that affect the update processes in Windows 10.
-
web:bhtnews.com
Here is another hack by applying which you can trick the Windows system to not find/recognize the folder to run the remediation service. Simply, change the name of the folder "rempl" found in the C disk programs of your computer, or remove it.
-
web:learn.microsoft.com
What is this? I've tried to uninstall it but it doesn't do anything. Wondering if it's Malware because I can't seem to find anything about it online.
-
web:softwarekeep.com
Windows Setup Remediations is a Windows servicing stack update. It is designed to handle Windows update functions such as freeing up space on your computer, ensuring the computer remains awake for updates and fixing any corrupt updates. Usually, it's a red flag to find an unknown application listed in your installed apps. After a wave of Windows updates, many users noticed a program called ...
-
web:support.microsoft.com
The Program Install and Uninstall troubleshooter helps you automatically repair issues when you're blocked from installing or removing programs.
-
web:whatsabyte.com
In this article, I will get into more details about the function of Windows Setup Remediations , such as why it was created, by who, and why it is considered safe. If users want to uninstall Windows Setup Remediations , I provide a how-to guide on how to do so.
-
web:windowsreport.com
Windows Setup Remediation might seem to be a mysterious program, but it is actually native to Windows 10. Here we provide further details for what Windows Setup Remediation is and how you can uninstall it.
-
web:www.majorgeeks.com
While uninstalling apps or cleaning your computer, you might have noticed Windows Setup Remediations with a KB number KB4023057. There are no details, vendor information and it can be on your computer for months on end. So, what is Windows Setup Remediations and can you uninstall it?
-
web:www.thewindowsclub.com
Windows Setup Remediation installs the Windows Remediation Service sedsvc.exe proces. It is a Servicing Stack Update which makes sure the Windows Update process is handled smoothly.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.