s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-bf94b7278ed33a993b98dc03afc34c60e2c5adb143a27300e7b8ad62c06b4b36 high

📛 Threat Title

Unknown: dollar.exe

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 4922224 bytes. Tags: exe, signed, Vidar. Reporter: iamaachum. First seen: 2026-08-04 18:27:43.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash d42595b695fc008ef2c56aabd8efd68e

IOC database

Type
hash_imphash
Value
d42595b695fc008ef2c56aabd8efd68e
First seen
Last seen
Attached to this threat
Appears in
423 threats
Description
imphash of URLhaus payload a7b9f3dda435b7f2…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 bf94b7278ed33a993b98dc03afc34c60e2c5adb143a27300e7b8ad62c06b4b36

IOC database

Type
hash_sha256
Value
bf94b7278ed33a993b98dc03afc34c60e2c5adb143a27300e7b8ad62c06b4b36
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 36acc98848aa867e04492c1d027aed416074657e

IOC database

Type
hash_sha1
Value
36acc98848aa867e04492c1d027aed416074657e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 d4573907e0cb58da89a0780ab9f3b9cf

IOC database

Type
hash_md5
Value
d4573907e0cb58da89a0780ab9f3b9cf
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 4922224 bytes. Tags: exe, signed, Vidar. Reporter: iamaachum. First seen: 2026-08-04 18:27:43.

Remediations (10)

  • web:any.run

    Online sandbox report for dollar.exe , verdict: No threats detected

  • web:app.any.run

    Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

  • web:app.any.run

    Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

  • web:learn.microsoft.com

    Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:malwaretips.com

    This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.

  • web:support.microsoft.com

    Solve problems with detecting and removing malware with Windows Security, including incomplete scans, detection errors, and persistent malware.

  • web:urlquery.net

    urlquery is a service for scanning, identifying and categorizing potentially harmful elements on a webpage, checking for malware infections and assessing overall reputation.

  • web:www.joesandbox.com

    Signatures Found malware configuration Multi AV Scanner detection for submitted file Suricata IDS alerts for network traffic Yara detected Vidar stealer C2 URLs / IPs found in malware configuration Found direct / indirect Syscall (likely to bypass EDR) Found many strings related to Crypto-Wallets (likely being stolen) Hides threads from debuggers Joe Sandbox ML detected suspicious sample Tries ...

  • web:www.joesandbox.com

    Automated Malware Analysis - Joe Sandbox Management Report Matched rule: Identifies Metasploit 64 bit reverse tcp shellcode. Author: unknown Uses 32bit PE files Source: dollar.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE Yara signature match Source: dollar.exe , type: SAMPLE Matched rule: Windows_Trojan_Metasploit_4a1c4da8 ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.