MB-efd9c53cbbec73120a2bbf16c553d5439356876f997a890888cb4e87389b8669
high
📛 Threat Title
Unknown: efd9c53cbbec73120a2bbf16c553d5439356876f997a890888cb4e87389b8669.exe
Description
File type: exe. Size: 642618 bytes. Tags: exe, injector, trojan. Reporter: Kejult. First seen: 2026-09-25 11:28:46.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
efd9c53cbbec73120a2bbf16c553d5439356876f997a890888cb4e87389b8669
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/efd9c53cbbec73120a2bbf16c553d5439356876f997a890888cb4e87389b8669
IOC database
- Type
- hash_sha256
- Value
efd9c53cbbec73120a2bbf16c553d5439356876f997a890888cb4e87389b8669- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/efd9c53cbbec73120a2bbf16c553d5439356876f997a890888cb4e87389b8669
hash_sha1
de4a0c9884f2ed953701645a3fb89efa9e4a3d9d
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/de4a0c9884f2ed953701645a3fb89efa9e4a3d9d
IOC database
- Type
- hash_sha1
- Value
de4a0c9884f2ed953701645a3fb89efa9e4a3d9d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/de4a0c9884f2ed953701645a3fb89efa9e4a3d9d
hash_md5
55ba25ea6b060f6487ad8e8aaf34f6c6
VT 43 / 75
IOC database
- Type
- hash_md5
- Value
55ba25ea6b060f6487ad8e8aaf34f6c6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 43 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Trojan/Win.Generic.C5949058 |
| alibabacloud | malicious | Trojan:Win/Wacatac.B9nj |
| Antiy-AVL | malicious | Trojan/Win64.Kryptik |
| APEX | malicious | Malicious |
| Arcabit | malicious | Trojan.GenericFCA.D36B6 |
| Avast | malicious | Win64:MalwareX-gen [Cryp] |
| AVG | malicious | Win64:MalwareX-gen [Cryp] |
| Avira | malicious | TR/W64.MalwareX |
| BitDefender | malicious | Trojan.GenericFCA.14006 |
| Bkav | malicious | W32.Malware.DABCB05C |
| CrowdStrike | malicious | win/malicious_confidence_100% (D) |
| CTX | malicious | exe.trojan.kryptik |
| Cylance | malicious | Unsafe |
| Cynet | malicious | Malicious (score: 99) |
| DeepInstinct | malicious | MALICIOUS |
| DrWeb | malicious | Trojan.DownLoader50.23888 |
| Elastic | malicious | malicious (high confidence) |
| Emsisoft | malicious | Trojan.GenericFCA.14006 (B) |
| ESET-NOD32 | malicious | Win64/Kryptik.HPF trojan |
| F-Secure | malicious | Trojan.TR/W64.MalwareX |
| Fortinet | malicious | W64/Kryptik.HPF!tr |
| GData | malicious | Trojan.GenericFCA.14006 |
| malicious | Detected |
|
| Gridinsoft | malicious | Trojan.Win64.Kryptik.oa!s1 |
| Lionic | malicious | Trojan.Win32.GenericFCA.4!c |
| Malwarebytes | malicious | Trojan.Injector |
| MaxSecure | malicious | Trojan.Malware.722058176.susgen |
| McAfeeD | malicious | ti!EFD9C53CBBEC |
| Microsoft | malicious | Trojan:Win32/Ravartar!rfn |
| MicroWorld-eScan | malicious | Trojan.GenericFCA.14006 |
| Paloalto | malicious | generic.ml |
| Panda | malicious | Trj/PhxGD.A |
| Rising | malicious | Trojan.Kryptik!8.8 (CLOUD) |
| Sangfor | malicious | Trojan.Win64.Kryptik.V8yr |
| SentinelOne | malicious | Static AI - Suspicious PE |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | ML.Attribute.HighConfidence |
| Tencent | malicious | Win32.Trojan.W64.Gwnw |
| TrellixENS | malicious | Artemis!55BA25EA6B06 |
| TrendMicro | malicious | Trojan.Win64.KRYPTIK.USBLIO26 |
| TrendMicro-HouseCall | malicious | Trojan.Win64.KRYPTIK.USBLIO26 |
| Varist | malicious | W64/ABTrojan.MBAD-9134 |
| VIPRE | malicious | Trojan.GenericFCA.14006 |
Details From VirusTotal
Basic Properties
| MD5 | 55ba25ea6b060f6487ad8e8aaf34f6c6 |
| SHA-1 | de4a0c9884f2ed953701645a3fb89efa9e4a3d9d |
| SHA-256 | efd9c53cbbec73120a2bbf16c553d5439356876f997a890888cb4e87389b8669 |
| VHash | 065086655d155d1515555az623z3hz5fz |
| SSDEEP | 12288:NOvv+ri6oFUuKXZFK3Y+prIXW26CQdBQXkDFfEjWaYS5whKv9TsC+usW:NHvrZF7fsuXkR8jl5w6TsWL |
| TLSH | T1C1D4E028FDAC40E5D025CE3FC2791601AB65F6225B31EEDB067806513D22BBD5D3EB82 |
| File type | Win32 EXE |
| File type tag | peexe |
| File extension | exe |
| Magic | PE32+ executable (GUI) x86-64, for MS Windows |
| File size | 627.6 KB |
History
| Creation date | 2026-08-30 15:46 UTC |
| First seen on VirusTotal | 2026-09-23 16:44 UTC |
| Last submission | 2026-09-25 12:15 UTC |
| Last analysis | 2026-09-25 20:01 UTC |
| Last modified on VirusTotal | 2026-09-25 22:22 UTC |
Known Names
hosku.exeu7vc2.exev6m9r8.exeefd9c53cbbec73120a2bbf16c553d5439356876f997a890888cb4e87389b8669.exe
hash_imphash
004340d8729cb4da47fce53d7da3c842
IOC database
- Type
- hash_imphash
- Value
004340d8729cb4da47fce53d7da3c842- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 642618 bytes. Tags: exe, injector, trojan. Reporter: Kejult. First seen: 2026-09-25 11:28:46.
Remediations (10)
-
web:forums.malwarebytes.com
Malware Removal Help Windows Malware Removal Help & Support Resolved Malware Removal Logs malicious exe files constantly generating inside my programdata folder
-
web:isgovern.com
At times you will find that some applications and/or services are not configured correctly, and when performing a vulnerability scan on your machine you may see a vulnerability listed as "Microsoft Windows Unquoted Service Path". This can also pop up if you are going for a Cyber Essentials Plus certification. So what does this vulnerability
-
web:learn.microsoft.com
Proved the fix. Microsoft stated that they have re-published the CVE-2013-3900 to inform customers about the availability of EnableCertPaddingCheck. This behavior remains available as an opt-in feature via the registry key setting and is available on all supported editions of Windows released since December 10, 2013. <P> Microsoft recommends that executable authors consider conforming all ...
-
web:learn.microsoft.com
Learn more about the diagnostic data gathered for Windows 11, versions 25H2 and 24H2.
-
web:maclookup.app
Use our MAC Address Search to find manufacturer details and vendor information in real-time. Enhance your network security with maclookup.app.
-
web:malwaretips.com
This guide teaches you how to remove Unknown .exe virus for free by following easy step-by-step instructions.
-
web:www.17track.net
Track your Unknown package instantly with 17TRACK. Get real-time updates, shipment status and delivery progress. Free tracking, no login required.
-
web:www.elevenforum.com
Hi everyone. So I was looking around on my OEM Win 11 Home 23h2 computer a few minutes ago. I clicked to see the properties of my C drive. And I discovered that under the Security tab, under 'Group or user names', the very first thing listed was "Account Unknown (S-1-15-3-65536-.....)" It turned out to be a long string of number clusters with hyphens in between them, about 99 or 100 characters ...
-
web:www.macvendorlookup.com
MAC Address Lookup Enter any MAC address, OUI, or IAB below to lookup the manufacturer, location, and more
-
web:www.whatsmyip.org
MAC Address Lookups, search by full address, OUI prefix or by vendor name. Database updated daily.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.