s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848 high

📛 Threat Title

Unknown: wethhist.org_6e231697_firefox-setup.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 139264 bytes. Reporter: mgoku. First seen: 2026-05-20 04:06:53.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain setup.exe VT: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/setup.exe

IOC database

Type
domain
Value
setup.exe
First seen
Last seen
Attached to this threat
Appears in
5 threats
Description
Extracted from Threat MB-4dc6f64b03a38e9824f257115cbdcbfb1ced916138325450b62c69094bbd53ec

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/setup.exe

hash_imphash f34d5f2d4577ed6d9ceec516c1f5a744

IOC database

Type
hash_imphash
Value
f34d5f2d4577ed6d9ceec516c1f5a744
First seen
Last seen
Attached to this threat
Appears in
647 threats
Description
imphash of URLhaus payload 61d424c2e3c5d8db…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848 VT 57 / 75

IOC database

Type
hash_sha256
Value
96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 57 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Win32.RL_Downeks.C4135590
Alibaba malicious Backdoor:MSIL/Quasar.c61a5510
alibabacloud malicious Backdoor:MSIL/Quasar.A
ALYac malicious Gen:Variant.Application.Jalapeno.145
Antiy-AVL malicious Trojan[Spy]/MSIL.Downeks
Arcabit malicious Trojan.Application.Jalapeno.145
Avast malicious MSIL:Quasar-A [Rat]
AVG malicious MSIL:Quasar-A [Rat]
Avira malicious TR/Quasar.A
BitDefender malicious Gen:Variant.Application.Jalapeno.145
Bkav malicious W32.Malware.A1562A2A
ClamAV malicious Win.Malware.Generic-9883083-0
CrowdStrike malicious win/malicious_confidence_100% (W)
CTX malicious exe.trojan.quasar
Cylance malicious Unsafe
DeepInstinct malicious MALICIOUS
DrWeb malicious BackDoor.QuasarNET.3
Elastic malicious malicious (high confidence)
Emsisoft malicious Gen:Variant.Application.Jalapeno.145 (B)
ESET-NOD32 malicious MSIL/Spy.Keylogger.DQJ trojan
F-Secure malicious Trojan.TR/Quasar.A
Fortinet malicious MSIL/Agent.DCT!tr
GData malicious MSIL.Backdoor.Quasar.B
Google malicious Detected
Gridinsoft malicious Spy.Win32.Keylogger.dd!n
huorong malicious Backdoor/Quasar.f
Ikarus malicious Backdoor.QuasarRat
K7AntiVirus malicious Spyware ( 005c7b1d1 )
K7GW malicious Spyware ( 005c7b1d1 )
Kaspersky malicious HEUR:Trojan-Spy.MSIL.Downeks.gen
Kingsoft malicious MSIL.Trojan-Spy.Downeks.gen
Lionic malicious Trojan.Win32.Quasar.l!c
Malwarebytes malicious Backdoor.Quasar
MaxSecure malicious Trojan.Malware.300983.susgen
McAfeeD malicious Real Protect-LS!E9A6E61C54AE
Microsoft malicious Backdoor:MSIL/Quasar!atmn
MicroWorld-eScan malicious Gen:Variant.Application.Jalapeno.145
NANO-Antivirus malicious Trojan.Win32.Quasar.lelzaq
Paloalto malicious generic.ml
Panda malicious Trj/CI.A
Rising malicious Backdoor.Quasar!1.E5F1 (CLASSIC)
Sangfor malicious Trojan.Win32.Save.a
SentinelOne malicious Static AI - Malicious PE
Skyhigh malicious GenericRXQL-TK!E9A6E61C54AE
Sophos malicious Mal/Quasar-A
Symantec malicious ML.Attribute.HighConfidence
TACHYON malicious Trojan-Spy/W32.DN-Downeks.139264.L
Tencent malicious Backdoor.Msil.Quasar.16001392
TrellixENS malicious GenericRXQL-TK!E9A6E61C54AE
TrendMicro malicious Backdoor.Win32.QUASARRAT.YXGETZ
TrendMicro-HouseCall malicious Trojan.Win32.VSX.PE04CA3
Varist malicious W32/MSIL_Agent.FTF.gen!Eldorado
VBA32 malicious Trojan.MSIL.Quasar.Heur
VIPRE malicious Gen:Variant.Application.Jalapeno.145
ViRobot malicious Trojan.Win.Z.Quasar.139264.RH
Webroot malicious W32.Trojan.Quasar
ZoneAlarm malicious Mal/Quasar-A

Details From VirusTotal

Basic Properties
MD5e9a6e61c54aee2f358c4d0983aeca851
SHA-11e64e8f0ff1dd1d06202957ddc0d61b65c59c32c
SHA-25696a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848
VHash21503655551350832dc8cc91a3c
SSDEEP3072:JHAL5stwS3AntIcRh3c4gBClZpbNGFk62MfWTOL:UsCKcRW4dZpbNG0s
TLSHT10CD33A1437ECCA27E2BE6BBAEC7440010372EA17E567E78D5D8C24ED1A627D191817B3
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size136.0 KB
History
Creation date2089-10-06 02:59 UTC
First seen on VirusTotal2026-05-20 04:06 UTC
Last submission2026-05-20 08:24 UTC
Last analysis2026-05-21 09:19 UTC
Last modified on VirusTotal2026-05-27 01:40 UTC
Known Names
  • firefox-setup.exe
  • 96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848.exe
  • 7wiu3f.exe
hash_sha1 1e64e8f0ff1dd1d06202957ddc0d61b65c59c32c

IOC database

Type
hash_sha1
Value
1e64e8f0ff1dd1d06202957ddc0d61b65c59c32c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 e9a6e61c54aee2f358c4d0983aeca851 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/e9a6e61c54aee2f358c4d0983aeca851

IOC database

Type
hash_md5
Value
e9a6e61c54aee2f358c4d0983aeca851
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/e9a6e61c54aee2f358c4d0983aeca851

References (1)

Remediations (8)

  • web:github.com

    This detection and remediation script pair is designed to identify and fully uninstall Mozilla Firefox from a Windows device, including residual files, shortcuts, registry entries, and Microsoft Store installations.

  • web:learn.microsoft.com

    I am serving some msi file on local intranet website. Everytime a user clicks the link it shows the warning: "File is not commonly downloaded. Make sure you trust file before you open it" most users don't know that they can click three dots and…

  • web:malwaretips.com

    This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.

  • web:www.experts-exchange.com

    If you work on vulnerability patching and remediation , there are new issues constantly arising. Recently, one called "Windows Unquoted/Trusted Service Paths Privilege Escalation" started showing up. In most cases, this is a mid-level vulnerability, but it still needs to be resolved. In most cased, the application and path are different for various servers, so this makes correcting via a ...

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

  • web:www.reddit.com

    If you go to one of the computers with the 'different source' Firefox, what is the uninstall command in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\<GUID of Firefox> and does it match the uninstall command you have in Intune? Or better yet, do you have it scoped to uninstall? Or are you running an uninstall script as an install? Because it sounds like that might be ...

  • web:www.virustotal.com

    VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.

  • web:www.wintips.org

    This tutorial contains detailed instructions on how to resolve the "Cannot Run Any Program" issue - .exe extensions changed by virus.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.