MB-96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848
high
📛 Threat Title
Unknown: wethhist.org_6e231697_firefox-setup.exe
Description
File type: exe. Size: 139264 bytes. Reporter: mgoku. First seen: 2026-05-20 04:06:53.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
setup.exe
VT: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/setup.exe
IOC database
- Type
- domain
- Value
setup.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 5 threats
- Description
- Extracted from Threat MB-4dc6f64b03a38e9824f257115cbdcbfb1ced916138325450b62c69094bbd53ec
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 400 Client Error: Bad Request for url: https://www.virustotal.com/api/v3/domains/setup.exe
hash_imphash
f34d5f2d4577ed6d9ceec516c1f5a744
IOC database
- Type
- hash_imphash
- Value
f34d5f2d4577ed6d9ceec516c1f5a744- First seen
- Last seen
- Attached to this threat
- Appears in
- 647 threats
- Description
- imphash of URLhaus payload 61d424c2e3c5d8db…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848
VT 57 / 75
IOC database
- Type
- hash_sha256
- Value
96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 57 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win32.RL_Downeks.C4135590 |
| Alibaba | malicious | Backdoor:MSIL/Quasar.c61a5510 |
| alibabacloud | malicious | Backdoor:MSIL/Quasar.A |
| ALYac | malicious | Gen:Variant.Application.Jalapeno.145 |
| Antiy-AVL | malicious | Trojan[Spy]/MSIL.Downeks |
| Arcabit | malicious | Trojan.Application.Jalapeno.145 |
| Avast | malicious | MSIL:Quasar-A [Rat] |
| AVG | malicious | MSIL:Quasar-A [Rat] |
| Avira | malicious | TR/Quasar.A |
| BitDefender | malicious | Gen:Variant.Application.Jalapeno.145 |
| Bkav | malicious | W32.Malware.A1562A2A |
| ClamAV | malicious | Win.Malware.Generic-9883083-0 |
| CrowdStrike | malicious | win/malicious_confidence_100% (W) |
| CTX | malicious | exe.trojan.quasar |
| Cylance | malicious | Unsafe |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | BackDoor.QuasarNET.3 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Gen:Variant.Application.Jalapeno.145 (B) |
| ESET-NOD32 | malicious | MSIL/Spy.Keylogger.DQJ trojan |
| F-Secure | malicious | Trojan.TR/Quasar.A |
| Fortinet | malicious | MSIL/Agent.DCT!tr |
| GData | malicious | MSIL.Backdoor.Quasar.B |
| malicious | Detected |
|
| Gridinsoft | malicious | Spy.Win32.Keylogger.dd!n |
| huorong | malicious | Backdoor/Quasar.f |
| Ikarus | malicious | Backdoor.QuasarRat |
| K7AntiVirus | malicious | Spyware ( 005c7b1d1 ) |
| K7GW | malicious | Spyware ( 005c7b1d1 ) |
| Kaspersky | malicious | HEUR:Trojan-Spy.MSIL.Downeks.gen |
| Kingsoft | malicious | MSIL.Trojan-Spy.Downeks.gen |
| Lionic | malicious | Trojan.Win32.Quasar.l!c |
| Malwarebytes | malicious | Backdoor.Quasar |
| MaxSecure | malicious | Trojan.Malware.300983.susgen |
| McAfeeD | malicious | Real Protect-LS!E9A6E61C54AE |
| Microsoft | malicious | Backdoor:MSIL/Quasar!atmn |
| MicroWorld-eScan | malicious | Gen:Variant.Application.Jalapeno.145 |
| NANO-Antivirus | malicious | Trojan.Win32.Quasar.lelzaq |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/CI.A |
| Rising | malicious | Backdoor.Quasar!1.E5F1 (CLASSIC) |
| Sangfor | malicious | Trojan.Win32.Save.a |
| SentinelOne | malicious | Static AI - Malicious PE |
| Skyhigh | malicious | GenericRXQL-TK!E9A6E61C54AE |
| Sophos | malicious | Mal/Quasar-A |
| Symantec | malicious | ML.Attribute.HighConfidence |
| TACHYON | malicious | Trojan-Spy/W32.DN-Downeks.139264.L |
| Tencent | malicious | Backdoor.Msil.Quasar.16001392 |
| TrellixENS | malicious | GenericRXQL-TK!E9A6E61C54AE |
| TrendMicro | malicious | Backdoor.Win32.QUASARRAT.YXGETZ |
| TrendMicro-HouseCall | malicious | Trojan.Win32.VSX.PE04CA3 |
| Varist | malicious | W32/MSIL_Agent.FTF.gen!Eldorado |
| VBA32 | malicious | Trojan.MSIL.Quasar.Heur |
| VIPRE | malicious | Gen:Variant.Application.Jalapeno.145 |
| ViRobot | malicious | Trojan.Win.Z.Quasar.139264.RH |
| Webroot | malicious | W32.Trojan.Quasar |
| ZoneAlarm | malicious | Mal/Quasar-A |
Details From VirusTotal
Basic Properties
| MD5 | e9a6e61c54aee2f358c4d0983aeca851 |
| SHA-1 | 1e64e8f0ff1dd1d06202957ddc0d61b65c59c32c |
| SHA-256 | 96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848 |
| VHash | 21503655551350832dc8cc91a3c |
| SSDEEP | 3072:JHAL5stwS3AntIcRh3c4gBClZpbNGFk62MfWTOL:UsCKcRW4dZpbNG0s |
| TLSH | T10CD33A1437ECCA27E2BE6BBAEC7440010372EA17E567E78D5D8C24ED1A627D191817B3 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| File size | 136.0 KB |
History
| Creation date | 2089-10-06 02:59 UTC |
| First seen on VirusTotal | 2026-05-20 04:06 UTC |
| Last submission | 2026-05-20 08:24 UTC |
| Last analysis | 2026-05-21 09:19 UTC |
| Last modified on VirusTotal | 2026-05-27 01:40 UTC |
Known Names
firefox-setup.exe96a789ec906e41c8c6f8c9c3b15c44ea1c49d12c1e3641342407bfec2ee56848.exe7wiu3f.exe
hash_sha1
1e64e8f0ff1dd1d06202957ddc0d61b65c59c32c
IOC database
- Type
- hash_sha1
- Value
1e64e8f0ff1dd1d06202957ddc0d61b65c59c32c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
e9a6e61c54aee2f358c4d0983aeca851
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/e9a6e61c54aee2f358c4d0983aeca851
IOC database
- Type
- hash_md5
- Value
e9a6e61c54aee2f358c4d0983aeca851- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/e9a6e61c54aee2f358c4d0983aeca851
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 139264 bytes. Reporter: mgoku. First seen: 2026-05-20 04:06:53.
Remediations (8)
-
web:github.com
This detection and remediation script pair is designed to identify and fully uninstall Mozilla Firefox from a Windows device, including residual files, shortcuts, registry entries, and Microsoft Store installations.
-
web:learn.microsoft.com
I am serving some msi file on local intranet website. Everytime a user clicks the link it shows the warning: "File is not commonly downloaded. Make sure you trust file before you open it" most users don't know that they can click three dots and…
-
web:malwaretips.com
This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.
-
web:www.experts-exchange.com
If you work on vulnerability patching and remediation , there are new issues constantly arising. Recently, one called "Windows Unquoted/Trusted Service Paths Privilege Escalation" started showing up. In most cases, this is a mid-level vulnerability, but it still needs to be resolved. In most cased, the application and path are different for various servers, so this makes correcting via a ...
-
web:www.majorgeeks.com
Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.
-
web:www.reddit.com
If you go to one of the computers with the 'different source' Firefox, what is the uninstall command in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\<GUID of Firefox> and does it match the uninstall command you have in Intune? Or better yet, do you have it scoped to uninstall? Or are you running an uninstall script as an install? Because it sounds like that might be ...
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
-
web:www.wintips.org
This tutorial contains detailed instructions on how to resolve the "Cannot Run Any Program" issue - .exe extensions changed by virus.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.