s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-c7bd4d80516ea71241d4d554f8441bcf523a6d91a59e9e8ddf8b35918b852dc6 high

📛 Threat Title

Unknown: Setup.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 25986920 bytes. Tags: 130-12-180-211, exe, Stealc. Reporter: iamaachum. First seen: 2026-08-04 19:37:10.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash d42595b695fc008ef2c56aabd8efd68e

IOC database

Type
hash_imphash
Value
d42595b695fc008ef2c56aabd8efd68e
First seen
Last seen
Attached to this threat
Appears in
423 threats
Description
imphash of URLhaus payload a7b9f3dda435b7f2…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 c7bd4d80516ea71241d4d554f8441bcf523a6d91a59e9e8ddf8b35918b852dc6

IOC database

Type
hash_sha256
Value
c7bd4d80516ea71241d4d554f8441bcf523a6d91a59e9e8ddf8b35918b852dc6
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 30e056245ea158f2055b5221b961fb4be245ac82

IOC database

Type
hash_sha1
Value
30e056245ea158f2055b5221b961fb4be245ac82
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 948495eeda3c0f8589ee3932f5bbc006

IOC database

Type
hash_md5
Value
948495eeda3c0f8589ee3932f5bbc006
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 25986920 bytes. Tags: 130-12-180-211, exe, Stealc. Reporter: iamaachum. First seen: 2026-08-04 19:37:10.

Remediations (9)

  • web:forums.malwarebytes.com

    MalwareBytes has been blocking SearchIndex.exe since it keeps on trying to connect to a random site. I downloaded this file and unknowingly ran the setup.exe presumably causing the drainage of my steam wallet. Malwarebytes Website Blocked Report 2024-07-12 130120.txt Addition.txt FRST.txt

  • web:github.com

    A comprehensive collection of Microsoft Intune remediation scripts and configurations designed for enterprise endpoint management, device compliance enforcement, and automated system fixes. This repository provides production-ready PowerShell scripts that integrate seamlessly with Intune's remediation framework.

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:softwarekeep.com

    Windows Setup Remediations is a Windows servicing stack update. It is designed to handle Windows update functions such as freeing up space on your computer, ensuring the computer remains awake for updates and fixing any corrupt updates. Usually, it's a red flag to find an unknown application listed in your installed apps. After a wave of Windows updates, many users noticed a program called ...

  • web:www.bugcrowd.com

    Mitigation solutions include isolating a set of vulnerable resources from the rest of the network with segmentation, temporarily disabling an application, or blocking a port that could provide access to a vulnerable resource. Your choice usually isn't a straightforward either/or decision between vulnerability remediation and mitigation .

  • web:www.majorgeeks.com

    While uninstalling apps or cleaning your computer, you might have noticed Windows Setup Remediations with a KB number KB4023057. There are no details, vendor information and it can be on your computer for months on end. So, what is Windows Setup Remediations and can you uninstall it?

  • web:www.thewindowsclub.com

    Windows Setup Remediation installs the Windows Remediation Service sedsvc.exe proces. It is a Servicing Stack Update which makes sure the Windows Update process is handled smoothly.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.