s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f high

📛 Threat Title

EpsilonStealer: winhost.exe

Category: EpsilonStealer Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 84625707 bytes. Tags: EpsilonStealer, exe. Reporter: smica83. First seen: 2026-09-25 10:16:40.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash b34f154ec913d2d2c435cbd644e91687

IOC database

Type
hash_imphash
Value
b34f154ec913d2d2c435cbd644e91687
First seen
Last seen
Attached to this threat
Appears in
171 threats
Description
imphash of URLhaus payload 6b10f4383fd8de21…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f

IOC database

Type
hash_sha256
Value
070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
EpsilonStealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f

hash_sha1 fdb736d1d22e76b8fb47b0fa2f11a1a1af00b423 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/fdb736d1d22e76b8fb47b0fa2f11a1a1af00b423

IOC database

Type
hash_sha1
Value
fdb736d1d22e76b8fb47b0fa2f11a1a1af00b423
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/fdb736d1d22e76b8fb47b0fa2f11a1a1af00b423

hash_md5 ab604354f690db061319959aec4073a2 VT 7 / 75

IOC database

Type
hash_md5
Value
ab604354f690db061319959aec4073a2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 7 of 75 VirusTotal vendors

VendorVerdictDetection
GData malicious Win32.Malware.Antis.FBYT86
Kaspersky malicious not-a-virus:NetTool.Win32.TryCloud.ds
McAfeeD malicious ti!070A9B480495
Rising malicious Hacktool.TryCloud!8.1E0E3 (CLOUD)
Sangfor malicious Trojan.Win32.Agent.V68g
Sophos malicious Mal/Generic-S
Webroot malicious W32.Malware.Gen

Details From VirusTotal

Basic Properties
MD5ab604354f690db061319959aec4073a2
SHA-1fdb736d1d22e76b8fb47b0fa2f11a1a1af00b423
SHA-256070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f
VHash087056655d1c0510d043z800417z47z62z41fz
SSDEEP1572864:9t9IKPM2xNA5uqoRWYnGvyUk/d5pHX9M6l4g3XLx+orcCta9mYl+eg1+fgf4dA7:9UKPNAgqoRWU/d5p3Nl4g3b9rja9mQ+X
TLSHT19708332EA171C704C46D02F60B621993D3ADBAAF8FA248075F5ABBC17E4D14951FF31A
File typeWin32 EXE
File type tagpeexe
File extensionexe
MagicPE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
File size80.7 MB
History
Creation date2018-12-15 22:26 UTC
First seen on VirusTotal2026-09-24 23:10 UTC
Last submission2026-09-25 11:47 UTC
Last analysis2026-09-25 14:17 UTC
Last modified on VirusTotal2026-09-26 00:27 UTC
Known Names
  • 070a9b480495c7f53b78518c35f96a6b961ba0ec29dfd77679d83eb71d95f82f.exe
  • p3kkxo6.exe
  • winhost.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 84625707 bytes. Tags: EpsilonStealer, exe. Reporter: smica83. First seen: 2026-09-25 10:16:40.

Remediations (10)

  • web:any.run

    Online sandbox report for winhost.exe , tagged as ransomware, dharma, verdict: Malicious activity

  • web:bazaar.abuse.ch

    Malware samples associated with tag EpsilonStealer MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with EpsilonStealer ...

  • web:hunt.io

    Discover how Epsilon Stealer targets gamers and cryptocurrency users, its methods of infection, and ways to protect your sensitive information.

  • web:learn.microsoft.com

    Configure what Microsoft Defender Antivirus should do when it detects a threat, and how long quarantined files should be retained in the quarantine folder.

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:malpedia.caad.fkie.fraunhofer.de

    Epsilon Stealer is an information stealer sold as Malware as a Service by a new french actor called "Epsilon". This malware is distributed as a game, mainly on discord, but steals user credentials, crypto wallets, and stored cookies. It evades static detection by being packed with NSIS, which then launches a malicious Electron package.

  • web:www.file.net

    What is winhost.exe ? The genuine winhost.exe file is a software component of W32.Beagle.CL/K@mm Worm. " winhost.exe " is a falsifying file in Windows, posing as a legitimate Windows file with its name, icon, and false developer name labeled as Microsoft. The file is a Trojan virus that claims to be the Windows Host Support Service. It runs in the background, displaying pop-ups and pop-unders on ...

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.pcrisk.com

    What kind of malware is Epsilon? Epsilon is the name of a malware designed to steal sensitive information. This stealer targets data from browsers, gaming-related and various other applications, as well as cryptocurrency wallets. Epsilon stealer has been observed being proliferated via campaigns targeting video game players. Epsilon malware overview After successfully infiltrating a system ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.