MB-bf94b7278ed33a993b98dc03afc34c60e2c5adb143a27300e7b8ad62c06b4b36
high
📛 Threat Title
Unknown: dollar.exe
Description
File type: exe. Size: 4922224 bytes. Tags: exe, signed, Vidar. Reporter: iamaachum. First seen: 2026-08-04 18:27:43.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
d42595b695fc008ef2c56aabd8efd68e
IOC database
- Type
- hash_imphash
- Value
d42595b695fc008ef2c56aabd8efd68e- First seen
- Last seen
- Attached to this threat
- Appears in
- 423 threats
- Description
- imphash of URLhaus payload a7b9f3dda435b7f2…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
bf94b7278ed33a993b98dc03afc34c60e2c5adb143a27300e7b8ad62c06b4b36
IOC database
- Type
- hash_sha256
- Value
bf94b7278ed33a993b98dc03afc34c60e2c5adb143a27300e7b8ad62c06b4b36- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
36acc98848aa867e04492c1d027aed416074657e
IOC database
- Type
- hash_sha1
- Value
36acc98848aa867e04492c1d027aed416074657e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
d4573907e0cb58da89a0780ab9f3b9cf
IOC database
- Type
- hash_md5
- Value
d4573907e0cb58da89a0780ab9f3b9cf- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 4922224 bytes. Tags: exe, signed, Vidar. Reporter: iamaachum. First seen: 2026-08-04 18:27:43.
Remediations (10)
-
web:any.run
Online sandbox report for dollar.exe , verdict: No threats detected
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:learn.microsoft.com
Remediation actions can include removing a file, sending it to quarantine, or allowing it to remain. This article includes information and links to resources about specifying what actions should be taken when threats are detected on devices. You can choose from several methods, such as: Configure remediation for Microsoft Defender Antivirus ...
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:malwaretips.com
This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.
-
web:support.microsoft.com
Solve problems with detecting and removing malware with Windows Security, including incomplete scans, detection errors, and persistent malware.
-
web:urlquery.net
urlquery is a service for scanning, identifying and categorizing potentially harmful elements on a webpage, checking for malware infections and assessing overall reputation.
-
web:www.joesandbox.com
Signatures Found malware configuration Multi AV Scanner detection for submitted file Suricata IDS alerts for network traffic Yara detected Vidar stealer C2 URLs / IPs found in malware configuration Found direct / indirect Syscall (likely to bypass EDR) Found many strings related to Crypto-Wallets (likely being stolen) Hides threads from debuggers Joe Sandbox ML detected suspicious sample Tries ...
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Management Report Matched rule: Identifies Metasploit 64 bit reverse tcp shellcode. Author: unknown Uses 32bit PE files Source: dollar.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE Yara signature match Source: dollar.exe , type: SAMPLE Matched rule: Windows_Trojan_Metasploit_4a1c4da8 ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.