s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-96b09d3c8deac6e7694c8a37ce45b5359fb7345f13e824c808831321eefd5f01 high

📛 Threat Title

Unknown: java-qEKUrj.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 69153890 bytes. Tags: electron, exe, infostealer. Reporter: Flechaa. First seen: 2026-08-04 23:45:52.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash b34f154ec913d2d2c435cbd644e91687

IOC database

Type
hash_imphash
Value
b34f154ec913d2d2c435cbd644e91687
First seen
Last seen
Attached to this threat
Appears in
119 threats
Description
imphash of URLhaus payload 6b10f4383fd8de21…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 96b09d3c8deac6e7694c8a37ce45b5359fb7345f13e824c808831321eefd5f01

IOC database

Type
hash_sha256
Value
96b09d3c8deac6e7694c8a37ce45b5359fb7345f13e824c808831321eefd5f01
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 52574c16aa7af67ea08be9ed4fde7b0e74602cf2

IOC database

Type
hash_sha1
Value
52574c16aa7af67ea08be9ed4fde7b0e74602cf2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 eaa14a38f0f9d65a9db6f0cceee1a914

IOC database

Type
hash_md5
Value
eaa14a38f0f9d65a9db6f0cceee1a914
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 69153890 bytes. Tags: electron, exe, infostealer. Reporter: Flechaa. First seen: 2026-08-04 23:45:52.

Remediations (9)

  • web:blog.qualys.com

    Older Java installations pose a significant security risk, particularly when developers install them in non-standard locations without any version control. These unmanaged installations often go undetected, silently expanding the organization's attack surface and leaving critical vulnerabilities unpatched.

  • web:github.com

    Description Summary Insufficient clearing of the output buffer in Java -based decompressor implementations in lz4- java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data.

  • web:github.com

    The following library contains a collection of remediation scripts designed to remove common unwanted software, adware, and malware found in the wild. If you come across a particular program you'd like to remediate, feel free to download the corresponding script and use it in your environment.

  • web:intunewithintune.com

    As a remediation Combined with the detection script provided in Part 2, you can use this script as the remediation part of the proactive remediation (refer to part 2). Just make sure this runs in the system context as well! As mentioned in the "as an app" section, the script has transcription for the purpose of detecting as an app.

  • NVD
    web:nvd.nist.gov

    The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables aut

  • web:portal.microfocus.com

    Find out vulnerabilities for Oracle Java when using a security tool to scan the system. The warning message shows: Installed version : 17.0.8 / build 17.0.8 Fixed version : Upgrade to version 17.0.11 or greater

  • web:www.java.com

    Terminology: Java is the general term used to denote the software and its components, which include 'Java Runtime Environment' (JRE), 'Java Virtual Machine' (JVM) and also 'Plug-in'.

  • web:www.rockenroll.tech

    In this case the detection script will detect Java and the remediation script is used to download and run the uninstallation package. As the detection script will run on a schedule, any new installations will be detected and remediated.

  • web:www.tenable.com

    Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.