s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-bb8c834d4066f900b01783087299e5da97ee27ac1d6a09bd7c231eabc2b77569 high

📛 Threat Title

Unknown: support.client.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 312552 bytes. Tags: signed. Reporter: BlinkzSec. First seen: 2026-05-14 12:53:39.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain support.client.exe VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe

IOC database

Type
domain
Value
support.client.exe
First seen
Last seen
Attached to this threat
Appears in
10 threats
Description
Extracted from Threat MB-d9fbcad42aaf846845c6c04550e5c010903112eedccd901c43c0a7a9be1bf2eb

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/support.client.exe

hash_imphash c2fe6927e1db8cf00400dbef9e5d35be

IOC database

Type
hash_imphash
Value
c2fe6927e1db8cf00400dbef9e5d35be
First seen
Last seen
Attached to this threat
Appears in
118 threats
Description
imphash of URLhaus payload 75b337e70eed4a26…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 bb8c834d4066f900b01783087299e5da97ee27ac1d6a09bd7c231eabc2b77569 1 feed

IOC database

Type
hash_sha256
Value
bb8c834d4066f900b01783087299e5da97ee27ac1d6a09bd7c231eabc2b77569
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 863fb13f3e6ed6a2aaa2592021512941d4346e96 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/863fb13f3e6ed6a2aaa2592021512941d4346e96
2 feeds

IOC database

Type
hash_sha1
Value
863fb13f3e6ed6a2aaa2592021512941d4346e96
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/863fb13f3e6ed6a2aaa2592021512941d4346e96

hash_md5 8ce48800305cf11428ceb85b90a7e253 2 feeds

IOC database

Type
hash_md5
Value
8ce48800305cf11428ceb85b90a7e253
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 312552 bytes. Tags: signed. Reporter: BlinkzSec. First seen: 2026-05-14 12:53:39.

Remediations (10)

  • web:learn.microsoft.com

    How to delete support.client.exe after running it. On 2/19/25 I got a suspicious email saying I subscribed to $500 Norton virus protection. And like a nut I went online to get the real Norton tel# and choose a sponsored link which was fraudulent by the…

  • web:windowsforum.com

    Check whether Dell SupportAssist Remediation or Alienware SupportAssist Remediation version 5.5.16.0 is installed on any crashing Dell or Alienware Windows 11 system. Disable the "Dell SupportAssist Remediation " service from an elevated command prompt if you need a fast mitigation that can be reversed later.

  • web:www.dell.com

    I updated my Dell Software - Bios, dock etc. From that moment laptop kept randomly rebooting (around every 30 minutes).  I Removed/Uninstalled all Dell Support assist software and remediation ...

  • web:www.dell.com

    My question is this: Is this all a function of Dell Support Assist and Dell SA Remediation resetting or changing my PC settings? If not, what do you think it could be?

  • web:www.dell.com

    About once a day I see in the Windows 11 Diagnostic Data viewer that the Dell. Remediation .Agent.exe program has crashed. No other problems detected. Do I need to worry about this and is there a fix...

  • web:www.dell.com

    The laptop is getting BSOD and from the WinDiag and we found out it is the dell support assist remediation from the dell command update, after we uninstall it that's all good until dell command update push it back into the system because it was marked as critical update.

  • web:www.reddit.com

    Anyone getting 'Sensitive information theft Activity using SAM' alerts for Dell Support Assist Remediation or other Dell SupportAssist products recently?

  • web:www.reddit.com

    Yes some firewalls aren't as advanced, but sometimes when you are taking over a client and they just bought a firewall you don't have to immediately replace it.

  • web:www.reddit.com

    Started with an unblocked pdf that maliciously called dell support assist to download trojan from web. Along with using osprofilecollector.exe to exfiltrate stored edge credentials.

  • web:www.redditmedia.com

    General Discussion Dell Support Assist Remediation causing bluescreens (self.sysadmin) submitted 18 hours ago * by L3veLUP L1 & L2 support technician Recently we've had a couple of dell devices start to blue screen every few hours with the Bugcheck code: CRITICAL_PROCESS_DIED

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.