s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a high

📛 Threat Title

Unknown: SecuriteInfo.com.FileRepMalware.77452617

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 20480 bytes. Tags: exe. Reporter: SecuriteInfoCom. First seen: 2026-05-14 14:23:32.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain securiteinfo.com.filerepmalware VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/securiteinfo.com.filerepmalware

IOC database

Type
domain
Value
securiteinfo.com.filerepmalware
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/securiteinfo.com.filerepmalware

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
648 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a VT 50 / 75 1 feed

IOC database

Type
hash_sha256
Value
4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 50 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win.Generic.C5884122
Alibaba malicious TrojanBanker:MSIL/ClipBanker.df15674d
alibabacloud malicious Trojan[stealer]:MSIL/ClipBanker.AZX
ALYac malicious Trojan.GenericKD.80129211
Antiy-AVL malicious Trojan[Banker]/MSIL.ClipBanker
APEX malicious Malicious
Arcabit malicious Trojan.Generic.D4C6ACBB
Avast malicious Win32:MalwareX-gen [Misc]
AVG malicious Win32:MalwareX-gen [Misc]
Avira malicious TR/W32.Agent
BitDefender malicious Trojan.GenericKD.80129211
Bkav malicious W32.Malware.F86BBBAA
CAT-QuickHeal malicious Trojan.MSIL
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.msil
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.Clipper.1049
Elastic malicious malicious (high confidence)
Emsisoft malicious Trojan.GenericKD.80129211 (B)
ESET-NOD32 malicious MSIL/ClipBanker.AMO trojan
F-Secure malicious Trojan.TR/W32.Agent
Fortinet malicious PossibleThreat
GData malicious Trojan.GenericKD.80129211
Google malicious Detected
huorong malicious TrojanSpy/MSIL.ClipBanker.a!crit
K7AntiVirus malicious Trojan ( 006dfd881 )
K7GW malicious Trojan ( 006dfd881 )
Kaspersky malicious HEUR:Trojan-Banker.MSIL.ClipBanker.gen
Kingsoft malicious malware.kb.c.999
Lionic malicious Trojan.Win32.ClipBanker.Z!c
Malwarebytes malicious Generic.Malware/Suspicious
MaxSecure malicious Trojan.Malware.73489558.susgen
McAfeeD malicious ti!4B7A0879CF0A
Microsoft malicious Trojan:MSIL/Clipbanker!MTB
MicroWorld-eScan malicious Trojan.GenericKD.80129211
Paloalto malicious generic.ml
Panda malicious Trj/PhxBzA.A
Rising malicious Spyware.ClipBanker!8.12E6C (CLOUD)
Sangfor malicious Banker.Msil.Clipbanker.Vu9u
Skyhigh malicious BehavesLike.Win32.Infected.mm
Sophos malicious Mal/Generic-S
Symantec malicious ML.Attribute.HighConfidence
Tencent malicious Msil.Trojan-Banker.Clipbanker.Kqil
TrellixENS malicious Artemis!7FDB8886EB8B
TrendMicro malicious Trojan.MSIL.CLIPBANKER.TL0101EE26ZY
TrendMicro-HouseCall malicious Trojan.MSIL.CLIPBANKER.TL0101EE26ZY
Varist malicious W32/ABmApplication.UCXR-6857
VBA32 malicious TScope.Trojan.MSIL
VIPRE malicious Trojan.GenericKD.80129211
VirIT malicious Trojan.Win32.MSIL.JQO

Details From VirusTotal

Basic Properties
MD57fdb8886eb8b149af6bb26d6dafdfac8
SHA-171aa40b3e6e290b0cdc2f28be6f3368ba4fd8985
SHA-2564b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a
VHash2240366515113082d112020
SSDEEP384:jVz3Jq+XSUJb+JTHPSl3C53yrITlSgCLlyLsrCStgzQs0Vzo:jVjJDXSUYT063ykz+UEyQs0q
TLSHT1B592E848AB546669D27E067C2DDE8320CBB2430B7453DB3B2EE66CE90C112D9D151EFB
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size20.0 KB
History
Creation date2082-07-01 09:27 UTC
First seen on VirusTotal2026-05-13 01:05 UTC
Last submission2026-05-21 16:33 UTC
Last analysis2026-06-04 06:03 UTC
Last modified on VirusTotal2026-06-04 08:04 UTC
Known Names
  • WindowsFormsApp13.exe
  • 7fdb8886eb8b149af6bb26d6dafdfac8
  • ClipClap.exe
  • clipclap.exe
  • 4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a.exe
  • aaowciksz.exe
  • olzxmjizm.exe
  • q0fmg.exe
hash_sha1 71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985
2 feeds

IOC database

Type
hash_sha1
Value
71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985

hash_md5 7fdb8886eb8b149af6bb26d6dafdfac8 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/7fdb8886eb8b149af6bb26d6dafdfac8
2 feeds

IOC database

Type
hash_md5
Value
7fdb8886eb8b149af6bb26d6dafdfac8
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/7fdb8886eb8b149af6bb26d6dafdfac8

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 20480 bytes. Tags: exe. Reporter: SecuriteInfoCom. First seen: 2026-05-14 14:23:32.

Remediations (10)

  • web:appuals.com

    What is FileRepMalware? FileRepMalware is simply a tag that several 3rd party antivirus suites will assign to a file. It's often associated with a fraudulent KMSPICO - a 3rd-party tool that is used to activate Windows without purchasing the OS. This security threat exists for several years now - It was previously called Win32:Evo-gen [Susp].

  • web:community.norton.com

    AI Overview FileRepMalware is a type of malware that infects computer systems and can cause significant damage. It's a combination of the words "file reputation" and "malware". How it works FileRepMalware is a potentially unwanted program (PUP) that can masquerade as legitimate files.

  • web:fone.tips

    FileRepMalware is a reputation-based label Avast and AVG apply to uncommon, unsigned executables, and it's often a false positive on legitimate tools rather than a confirmed virus. Upload the file to VirusTotal, check the Avast Threat Labs false positive submission page, and remove it only if multiple engines confirm the detection. #Windows # ...

  • web:malwaretips.com

    FileRepMalware is a heuristic detection designed to generically detect a Trojan Horse.

  • web:www.expressvpn.com

    Learn what FileRepMalware means, why security tools flag it, and when it's safe (or necessary) to remove it from your device.

  • web:www.getdroidtips.com

    So with that being said, here are the steps to remove FileRepMalware from your PC. To uninstall the FileRepMalware Malware, you can use the Windows Defender or any other trusted anti-virus or anti-malware application. Malware Bytes is recommended because it has a huge virus database and can recognize any adware, Malware with just one scan.

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file System process connects to network (likely due to code injection or exploit) Creates a process in suspended mode (likely to inject code) IP address seen in connection with other malware JA3 SSL client fingerprint seen in connection with other malware Sample execution stops while process ...

  • web:www.pcrisk.com

    FileRepMalware is a malicious file, and it is considered to be a potential threat to devices. The presence of this file on an operating system (OS) can be an indicator of other issues, such as the presence of trojans, adware, or other harmful content - since it is commonly proliferated alongside unwanted/malicious supplements.

  • web:www.superantispyware.com

    Mitigation Efforts: Security researchers, software developers, and cybersecurity organizations are actively working to combat FileRepMalware. Collaboration among these entities plays a crucial role in developing effective countermeasures and sharing threat intelligence to mitigate the impact of FileRepMalware attacks.

  • web:www.thewindowsclub.com

    The FileRepMalware tag signifies potentially malicious software in your system. We discuss what Filerepmalware is and how to handle it.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.