MB-4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a
high
📛 Threat Title
Unknown: SecuriteInfo.com.FileRepMalware.77452617
Description
File type: exe. Size: 20480 bytes. Tags: exe. Reporter: SecuriteInfoCom. First seen: 2026-05-14 14:23:32.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
securiteinfo.com.filerepmalware
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/securiteinfo.com.filerepmalware
IOC database
- Type
- domain
- Value
securiteinfo.com.filerepmalware- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat MB-4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/securiteinfo.com.filerepmalware
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 648 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a
VT 50 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 50 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.C5884122 |
| Alibaba | malicious | TrojanBanker:MSIL/ClipBanker.df15674d |
| alibabacloud | malicious | Trojan[stealer]:MSIL/ClipBanker.AZX |
| ALYac | malicious | Trojan.GenericKD.80129211 |
| Antiy-AVL | malicious | Trojan[Banker]/MSIL.ClipBanker |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.Generic.D4C6ACBB |
| Avast | malicious | Win32:MalwareX-gen [Misc] |
| AVG | malicious | Win32:MalwareX-gen [Misc] |
| Avira | malicious | TR/W32.Agent |
| BitDefender | malicious | Trojan.GenericKD.80129211 |
| Bkav | malicious | W32.Malware.F86BBBAA |
| CAT-QuickHeal | malicious | Trojan.MSIL |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.msil |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.Clipper.1049 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericKD.80129211 (B) |
| ESET-NOD32 | malicious | MSIL/ClipBanker.AMO trojan |
| F-Secure | malicious | Trojan.TR/W32.Agent |
| Fortinet | malicious | PossibleThreat |
| GData | malicious | Trojan.GenericKD.80129211 |
| malicious | Detected |
|
| huorong | malicious | TrojanSpy/MSIL.ClipBanker.a!crit |
| K7AntiVirus | malicious | Trojan ( 006dfd881 ) |
| K7GW | malicious | Trojan ( 006dfd881 ) |
| Kaspersky | malicious | HEUR:Trojan-Banker.MSIL.ClipBanker.gen |
| Kingsoft | malicious | malware.kb.c.999 |
| Lionic | malicious | Trojan.Win32.ClipBanker.Z!c |
| Malwarebytes | malicious | Generic.Malware/Suspicious |
| MaxSecure | malicious | Trojan.Malware.73489558.susgen |
| McAfeeD | malicious | ti!4B7A0879CF0A |
| Microsoft | malicious | Trojan:MSIL/Clipbanker!MTB |
| MicroWorld-eScan | malicious | Trojan.GenericKD.80129211 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxBzA.A |
| Rising | malicious | Spyware.ClipBanker!8.12E6C (CLOUD) |
| Sangfor | malicious | Banker.Msil.Clipbanker.Vu9u |
| Skyhigh | malicious | BehavesLike.Win32.Infected.mm |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Msil.Trojan-Banker.Clipbanker.Kqil |
| TrellixENS | malicious | Artemis!7FDB8886EB8B |
| TrendMicro | malicious | Trojan.MSIL.CLIPBANKER.TL0101EE26ZY |
| TrendMicro-HouseCall | malicious | Trojan.MSIL.CLIPBANKER.TL0101EE26ZY |
| Varist | malicious | W32/ABmApplication.UCXR-6857 |
| VBA32 | malicious | TScope.Trojan.MSIL |
| VIPRE | malicious | Trojan.GenericKD.80129211 |
| VirIT | malicious | Trojan.Win32.MSIL.JQO |
Details From VirusTotal
Basic Properties
| MD5 | 7fdb8886eb8b149af6bb26d6dafdfac8 |
| SHA-1 | 71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985 |
| SHA-256 | 4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a |
| VHash | 2240366515113082d112020 |
| SSDEEP | 384:jVz3Jq+XSUJb+JTHPSl3C53yrITlSgCLlyLsrCStgzQs0Vzo:jVjJDXSUYT063ykz+UEyQs0q |
| TLSH | T1B592E848AB546669D27E067C2DDE8320CBB2430B7453DB3B2EE66CE90C112D9D151EFB |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 20.0 KB |
History
| Creation date | 2082-07-01 09:27 UTC |
| First seen on VirusTotal | 2026-05-13 01:05 UTC |
| Last submission | 2026-05-21 16:33 UTC |
| Last analysis | 2026-06-04 06:03 UTC |
| Last modified on VirusTotal | 2026-06-04 08:04 UTC |
Known Names
WindowsFormsApp13.exe7fdb8886eb8b149af6bb26d6dafdfac8ClipClap.execlipclap.exe4b7a0879cf0a7ab62b248281e4075ada4988501fe8e5c6fb7b42d79e1e5b2a8a.exeaaowciksz.exeolzxmjizm.exeq0fmg.exe
hash_sha1
71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985
2 feeds
IOC database
- Type
- hash_sha1
- Value
71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/71aa40b3e6e290b0cdc2f28be6f3368ba4fd8985
hash_md5
7fdb8886eb8b149af6bb26d6dafdfac8
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/7fdb8886eb8b149af6bb26d6dafdfac8
2 feeds
IOC database
- Type
- hash_md5
- Value
7fdb8886eb8b149af6bb26d6dafdfac8- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/7fdb8886eb8b149af6bb26d6dafdfac8
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 20480 bytes. Tags: exe. Reporter: SecuriteInfoCom. First seen: 2026-05-14 14:23:32.
Remediations (10)
-
web:appuals.com
What is FileRepMalware? FileRepMalware is simply a tag that several 3rd party antivirus suites will assign to a file. It's often associated with a fraudulent KMSPICO - a 3rd-party tool that is used to activate Windows without purchasing the OS. This security threat exists for several years now - It was previously called Win32:Evo-gen [Susp].
-
web:community.norton.com
AI Overview FileRepMalware is a type of malware that infects computer systems and can cause significant damage. It's a combination of the words "file reputation" and "malware". How it works FileRepMalware is a potentially unwanted program (PUP) that can masquerade as legitimate files.
-
web:fone.tips
FileRepMalware is a reputation-based label Avast and AVG apply to uncommon, unsigned executables, and it's often a false positive on legitimate tools rather than a confirmed virus. Upload the file to VirusTotal, check the Avast Threat Labs false positive submission page, and remove it only if multiple engines confirm the detection. #Windows # ...
-
web:malwaretips.com
FileRepMalware is a heuristic detection designed to generically detect a Trojan Horse.
-
web:www.expressvpn.com
Learn what FileRepMalware means, why security tools flag it, and when it's safe (or necessary) to remove it from your device.
-
web:www.getdroidtips.com
So with that being said, here are the steps to remove FileRepMalware from your PC. To uninstall the FileRepMalware Malware, you can use the Windows Defender or any other trusted anti-virus or anti-malware application. Malware Bytes is recommended because it has a huge virus database and can recognize any adware, Malware with just one scan.
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file System process connects to network (likely due to code injection or exploit) Creates a process in suspended mode (likely to inject code) IP address seen in connection with other malware JA3 SSL client fingerprint seen in connection with other malware Sample execution stops while process ...
-
web:www.pcrisk.com
FileRepMalware is a malicious file, and it is considered to be a potential threat to devices. The presence of this file on an operating system (OS) can be an indicator of other issues, such as the presence of trojans, adware, or other harmful content - since it is commonly proliferated alongside unwanted/malicious supplements.
-
web:www.superantispyware.com
Mitigation Efforts: Security researchers, software developers, and cybersecurity organizations are actively working to combat FileRepMalware. Collaboration among these entities plays a crucial role in developing effective countermeasures and sharing threat intelligence to mitigate the impact of FileRepMalware attacks.
-
web:www.thewindowsclub.com
The FileRepMalware tag signifies potentially malicious software in your system. We discuss what Filerepmalware is and how to handle it.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.