s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

AI-IOC-dc46fb4e85e0 medium

📛 Threat Title

Suspicious SHA-256 Hash

Category: ai-validated First seen: Last updated:

Description

The provided string appears to be a hashed value, which could potentially indicate malicious activity. Further analysis is required to determine the hash's origin and context.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 ea70895620f955b0712b85c3fee41de7437d5068267966f0b4fb6fa2704c3a50 VT 8 / 75

IOC database

Type
hash_sha256
Value
ea70895620f955b0712b85c3fee41de7437d5068267966f0b4fb6fa2704c3a50
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
AI-validated IOC. The provided string appears to be a hashed value, which could potentially indicate malicious activity. Further analysis is required to determine the hash's origin and context.

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 8 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Trojan/Python.Dropper
alibabacloud malicious Trojan:Python/Agent.CAD
ESET-NOD32 malicious Python/Agent.CEP trojan
Google malicious Detected
Ikarus malicious Trojan.Python.Agent
McAfeeD malicious ti!EA70895620F9
Symantec malicious Trojan Horse
ViRobot malicious BIN.S.Encoded.127934

Details From VirusTotal

Basic Properties
MD56bbd25fdafff6057b6b78e548e12d95d
SHA-1cb6920bf05d6fee989a26171b794f42d41a865a6
SHA-256ea70895620f955b0712b85c3fee41de7437d5068267966f0b4fb6fa2704c3a50
SSDEEP3072:k9L9gWtbOV8yz0yBm4tSvg40At6jIWLCYGn/NOglx4QCBbaTi5GKKT9JPm:aRgWtbOh5BJS44R6TPONJdC7ZKHu
TLSHT162C39EBC76147DD62A7F176BC9A6ACDC13A52A33D99B94CC80647BC304A3375EE0680D
File typeVBA
File type tagvba
MagicASCII text, with very long lines (65471u), with CRLF line terminators
File size124.9 KB
History
First seen on VirusTotal2026-07-22 08:07 UTC
Last submission2026-07-22 08:07 UTC
Last analysis2026-08-06 16:22 UTC
Last modified on VirusTotal2026-08-06 18:23 UTC
Known Names
  • 7ugwzbxds.exe
  • is-t9wcjdm5rw.tmp
  • run.pyw
  • is-qi3e21ng7z.tmp

References (0)

No references collected yet.

Remediations (10)

  • web:cyberpress.org

    Dell has fixed the issue on newer platforms using a SHA - 256 -based SIVB vault, but DSA-2026-197's initial patch list excludes all four confirmed-vulnerable devices; Dell has targeted broader remediation for the end of July 2026.

  • web:dipsylala.github.io

    Test the hash migration thoroughly Verify weak hashes are no longer used (grep for MD5, SHA1 in codebase) Test password verification with new hash algorithm (login should work) Test migration path for existing users (old passwords should upgrade on login) Verify file integrity checks use strong hashes ( SHA -256+)

  • web:inventivehq.com

    Free file hash checker & malicious hash lookup. Drag-drop a file to hash it in your browser, or bulk-check MD5/ SHA -1/ SHA - 256 hashes against malware databases — VirusTotal & MalwareBazaar links included.

  • web:ismalicious.com

    Learn how cryptographic file hashes power malware identification, why SHA-256 dominates security tooling, and how to combine hash lookups with broader threat intelligence for fewer false positives.

  • web:learn.microsoft.com

    Enhance Windows security by disabling weak crypto algorithms including MD5, SHA1, and RSA 1024-bit keys through comprehensive policy configuration and logging setup.

  • web:learn.microsoft.com

    Learn how to detect and limit or disable RC4 usage in Kerberos to enhance security in Active Directory domain environments.

  • web:shattered.io

    The SHA-256 Hash Cracking Operation Behind FortiBleed The technical core of FortiBleed is an offline password cracking operation that exploited a legacy weakness in FortiOS credential storage. Fortinet switched from SHA-256 with salt to the more hardened PBKDF2 scheme in early 2025 for newly set passwords.

  • web:support.sophos.com

    In these circumstances, we suggest using the file SHA-256 hash . For Sophos Central customers, locating the SHA-256 hash of a detected or suspicious file can be done by following the steps in Sophos Central Admin: How to find out a file's SHA-256 hash .

  • web:talosintelligence.com

    Use Talos' File Reputation lookup to find the reputation, file name, weighted reputation score, and detection information available for a given SHA256 .

  • web:www.microsoft.com

    Threat actors abused trusted Trivy distribution channels to inject credential‑stealing malware into CI/CD pipelines worldwide. This analysis walks through the Trivy supply‑chain compromise, attacker techniques, and concrete steps security teams can take to detect and defend against similar attacks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.