s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

VT-1ba217222d40804e8034a3583d9ad69c32fd9694 medium

📛 Threat Title

File hash (SHA1): 1ba217222d40804e8034a3583d9ad69c32fd9694

Category: malware-hash Published: Source updated: First seen: Last updated:

Description

Hash IOC ingested from threat-intel feed 'Abuse.ch'. See VirusTotal for vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, dropped files, etc.). Feed description: SHA1 hashes: Recent additions

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain abuse.ch VT 0 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
abuse.ch
First seen
Last seen
Attached to this threat
Appears in
4019 threats
Description
Extracted from Threat VT-0bc58e58275d6ecca05335aac681a0352173e19d8718230c1902c2bf99d8782f

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDch
History
Last analysis2026-05-24 09:28 UTC
Last modified on VirusTotal2026-05-24 16:38 UTC
WHOIS record date2026-03-29 11:09 UTC
hash_sha1 1ba217222d40804e8034a3583d9ad69c32fd9694 VT 54 / 75 2 feeds

IOC database

Type
hash_sha1
Value
1ba217222d40804e8034a3583d9ad69c32fd9694
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Imported from threat-intel feed: Abuse.ch

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Flagged by 54 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Infostealer/Win.Remus.R762015
Alibaba malicious Backdoor:Win64/Stealer.f372d3ef
alibabacloud malicious Backdoor:Win/Agent.AJH
ALYac malicious Gen:Variant.Stealer.37
Antiy-AVL malicious Trojan[PSW]/Win32.ReaderDB
APEX malicious Malicious
Arcabit malicious Trojan.Stealer.37
Avira malicious TR/W64.Evo
BitDefender malicious Gen:Variant.Stealer.37
Bkav malicious W32.Malware.C886A551
CAT-QuickHeal malicious Trojan.Stealer
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.stealer
Cylance malicious Unsafe
Cynet malicious Malicious (score: 99)
DeepInstinct malicious MALICIOUS
DrWeb malicious Trojan.PWS.Stealer.45272
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Variant.Stealer.37 (B)
ESET-NOD32 malicious Win64/Spy.Agent.AHB trojan
F-Secure malicious Trojan.TR/W64.Evo
Fortinet malicious W64/Agent.AHB!tr
GData malicious Gen:Variant.Stealer.37
Google malicious Detected
Gridinsoft malicious Trojan.Win64.Agent.sa
huorong malicious TrojanSpy/W64.Stealer.am
Ikarus malicious Trojan.Win64.Spy
K7AntiVirus malicious Spyware ( 006dd6f81 )
K7GW malicious Spyware ( 006dd6f81 )
Kingsoft malicious Win32.Trojan.Agent.gen
Lionic malicious Trojan.Win32.Agent.Y!c
Malwarebytes malicious Spyware.Agent
MaxSecure malicious Trojan.Malware.681451513.susgen
McAfeeD malicious ti!0C659AEBE2BD
Microsoft malicious Trojan:Win64/Stealer.NVH!MTB
MicroWorld-eScan malicious Gen:Variant.Stealer.37
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Trojan.Lazy!8.8EC3 (TFE:3:8S33Cm7oz0Q)
Sangfor malicious Suspicious.Win32.Save.a
SentinelOne malicious Static AI - Suspicious PE
Skyhigh malicious BehavesLike.Win64.Infected.dh
Sophos malicious Troj/Steal-FIX
Symantec malicious Trojan.Gen.MBT
Tencent malicious Backdoor.Win64.Spy.16003784
Trapmine malicious suspicious.low.ml.score
TrellixENS malicious Artemis!0DC52660CEC8
TrendMicro malicious TrojanSpy.Win64.REMUS.YXGEBZ
TrendMicro-HouseCall malicious TrojanSpy.Win64.REMUS.YXGEBZ
Varist malicious W64/Agent.LWN.gen!Eldorado
VBA32 malicious Backdoor.Agent
VIPRE malicious Gen:Variant.Stealer.37
ViRobot malicious Trojan.Win.Z.Stealer.232448.BK
ZoneAlarm malicious Troj/Steal-FIX

Details From VirusTotal

Basic Properties
MD50dc52660cec8b365a5612ef786b6be71
SHA-11ba217222d40804e8034a3583d9ad69c32fd9694
SHA-2560c659aebe2bd9098f1d9a731deafdf83e8643bcad7562529f0d2582ff06f4c3d
VHash0250466d7d155025z91z67z504bzbfz
SSDEEP3072:r3oQmWOp4o3VmiTC2NjynD1MvJsrex8Xc2W11E8XJ/JRSGHt+0cY06VyM:8Q6Co3VmiTB82varexALwsGM0RV
TLSHT10F34296BC29331FCD553C078926A6222BB72B63D47709EEB0293D3319E21ED06E7D525
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32+ executable (GUI) x86-64, for MS Windows
File size227.0 KB
History
Creation date2026-04-25 19:27 UTC
First seen on VirusTotal2026-05-02 15:01 UTC
Last submission2026-05-14 12:11 UTC
Last analysis2026-05-17 05:48 UTC
Last modified on VirusTotal2026-05-17 07:52 UTC
Known Names
  • 0c659aebe2bd9098f1d9a731deafdf83e8643bcad7562529f0d2582ff06f4c3d.exe
  • _0c659aebe2bd9098f1d9a731deafdf83e8643bcad7562529f0d2582ff06f4c3d.exe
  • pbn4i.exe

References (1)

  • VirusTotal report

    Vendor verdicts, file metadata, sandbox behaviour, and relationships (contacted IPs / domains / URLs, execution parents, dropped files).

Remediations (10)

  • web:check.town

    Free file hash checker. Upload a file and compute MD5, SHA-1 , SHA-256, and SHA-512 checksums client-side.

  • web:emn178.github.io

    This SHA1 online tool helps you calculate the hash of a file from local or URL using SHA1 without uploading the file . It also supports HMAC.

  • web:inventivehq.com

    Free hash lookup tool. Search MD5, SHA-1 , SHA-256 hashes in breach databases to identify compromised passwords, malware, and file integrity.

  • web:punchbit.com

    Upload a file and instantly see its SHA-256, SHA-384, SHA-512, and SHA-1 hashes. Verify file integrity by comparing against a known hash . Free and private.

  • web:talosintelligence.com

    Use Talos' File Reputation lookup to find the reputation, file name, weighted reputation score, and detection information available for a given SHA256.

  • web:windowsloop.com

    Want to check SHA1 , SHA256, SHA384, SHA512, or MD5 hash for a file ? You can do it without using any third-party tools in Windows. Here's how.

  • web:www.freecodeformat.com

    Verify file integrity online. Calculate MD5, SHA1 , SHA256, SHA512, SHA3, RIPEMD-160, and CRC32 hashes for any file . Fast, secure, and supports multiple files .

  • web:www.getzenquery.com

    Verify file integrity instantly with our free online File Hash Checker. Upload any file to compute MD5, SHA-1 , SHA-256, and SHA-512 hashes—then compare with original or expected checksums. Perfect for ensuring downloaded files are intact, validating software authenticity, or detecting corruption. All processing happens locally in your browser for privacy.

  • web:www.howtohaven.com

    How to Get the Hash (MD5, SHA1 , SHA256, SHA512) of a File on Windows Without Installing Anything Sometimes, when you go to a website to download a program or some other file , the page lists a series of letters and numbers, known as a hash , for that file .

  • web:www.toolsley.com

    Calculate the hash for any file online. Generate MD5, SHA1 , SHA256 or CRC32 instantly in your browser using JavaScript. Make share-able links to validate files . No need to install anything, just drag & drop.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.