f10d35fedb6aa986cef4c113edfdef26
Hash
- MD5: f10d35fedb6aa986cef4c113edfdef26
- SHA1: ed02996ba97457166406d1d3230ef177fec67913
- SHA256: 384255ba8bea8997dce5a6a9c4b4352279343000821128342e6960dbcc14bbe0
- First Seen: 2026-05-14
- Last Seen: 2026-05-14
-
1
Related Reports
-
0
Related IOCs
Additional Information
VirusTotal
{
"data": {
"id": "384255ba8bea8997dce5a6a9c4b4352279343000821128342e6960dbcc14bbe0",
"type": "file",
"links": {
"self": "https://www.virustotal.com/api/v3/files/384255ba8bea8997dce5a6a9c4b4352279343000821128342e6960dbcc14bbe0"
},
"attributes": {
"ssdeep": "1572864:iA+HvRH7H+pczQA4to7OMOegv2AVXVQC0eda63Arzrg2TQpD2bnI3G4zdlnk0eW:5KHuc0AFOFOAHv1dSLapiyFdlnkk",
"sandbox_verdicts": {
"Zenbox": {
"category": "harmless",
"malware_classification": [
"CLEAN"
],
"sandbox_name": "Zenbox",
"confidence": 98
}
},
"times_submitted": 2,
"popular_threat_classification": {
"popular_threat_category": [
{
"count": 2,
"value": "trojan"
}
],
"suggested_threat_label": "trojan."
},
"tags": [
"signed",
"msi",
"checks-usb-bus"
],
"type_extension": "msi",
"tlsh": "T12C38339BBC8B18D4E51A8EFA80B7E754552C5C96D62404972430BFA8CEF3ED13943EC6",
"creation_date": 1772738710,
"meaningful_name": "Setup.exe",
"magika": "MSI",
"trid": [
{
"file_type": "Microsoft Windows Installer",
"probability": 80.0
},
{
"file_type": "Windows SDK Setup Transform script",
"probability": 10.7
},
{
"file_type": "Windows Installer Patch",
"probability": 7.8
},
{
"file_type": "Generic OLE2 / Multistream Compound",
"probability": 1.4
}
],
"filecondis": {
"dhash": "0000001c0d1c0800",
"raw_md5": "acf596f62690b22347bd84297e975d44"
},
"total_votes": {
"harmless": 0,
"malicious": 1
},
"vhash": "7aafbb544e903136cfc63dcb5e1d76f6",
"sha256": "384255ba8bea8997dce5a6a9c4b4352279343000821128342e6960dbcc14bbe0",
"last_analysis_stats": {
"malicious": 4,
"suspicious": 0,
"undetected": 51,
"harmless": 0,
"timeout": 5,
"confirmed-timeout": 0,
"failure": 1,
"type-unsupported": 14
},
"names": [
"Setup.exe"
],
"last_submission_date": 1773673107,
"md5": "f10d35fedb6aa986cef4c113edfdef26",
"type_description": "Windows Installer",
"last_modification_date": 1779069743,
"last_analysis_results": {
"Lionic": {
"method": "blacklist",
"engine_name": "Lionic",
"engine_version": "8.16",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"MicroWorld-eScan": {
"method": "blacklist",
"engine_name": "MicroWorld-eScan",
"engine_version": "14.0.409.0",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"CMC": {
"method": "blacklist",
"engine_name": "CMC",
"engine_version": "2.4.2022.1",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"CAT-QuickHeal": {
"method": "blacklist",
"engine_name": "CAT-QuickHeal",
"engine_version": "22.00",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"ALYac": {
"method": "blacklist",
"engine_name": "ALYac",
"engine_version": "2.0.0.10",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Malwarebytes": {
"method": "blacklist",
"engine_name": "Malwarebytes",
"engine_version": "3.1.0.235",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Zillya": {
"method": "blacklist",
"engine_name": "Zillya",
"engine_version": "2.0.0.5603",
"engine_update": "20260515",
"category": "undetected",
"result": null
},
"Sangfor": {
"method": "blacklist",
"engine_name": "Sangfor",
"engine_version": "2.22.3.0",
"engine_update": "20260515",
"category": "undetected",
"result": null
},
"K7AntiVirus": {
"method": "blacklist",
"engine_name": "K7AntiVirus",
"engine_version": "14.52.59533",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"K7GW": {
"method": "blacklist",
"engine_name": "K7GW",
"engine_version": "14.52.59533",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"CrowdStrike": {
"method": "blacklist",
"engine_name": "CrowdStrike",
"engine_version": "1.0",
"engine_update": "20230417",
"category": "undetected",
"result": null
},
"Arcabit": {
"method": "blacklist",
"engine_name": "Arcabit",
"engine_version": "2025.0.0.23",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"VirIT": {
"method": "blacklist",
"engine_name": "VirIT",
"engine_version": "9.5.1208",
"engine_update": "20260515",
"category": "undetected",
"result": null
},
"Symantec": {
"method": "blacklist",
"engine_name": "Symantec",
"engine_version": "1.22.0.0",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"ESET-NOD32": {
"method": "blacklist",
"engine_name": "ESET-NOD32",
"engine_version": "18.2.18.0",
"engine_update": "20260517",
"category": "malicious",
"result": "JS/Kimsuky.H trojan"
},
"TrendMicro-HouseCall": {
"method": "blacklist",
"engine_name": "TrendMicro-HouseCall",
"engine_version": "24.550.0.1002",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"ClamAV": {
"method": "blacklist",
"engine_name": "ClamAV",
"engine_version": "1.5.2.0",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"BitDefender": {
"method": "blacklist",
"engine_name": "BitDefender",
"engine_version": "7.2",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"NANO-Antivirus": {
"method": "blacklist",
"engine_name": "NANO-Antivirus",
"engine_version": "1.0.170.26895",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"ViRobot": {
"method": "blacklist",
"engine_name": "ViRobot",
"engine_version": "2014.3.20.0",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Tencent": {
"method": "blacklist",
"engine_name": "Tencent",
"engine_version": "1.0.0.1",
"engine_update": "20260518",
"category": "undetected",
"result": null
},
"Sophos": {
"method": "blacklist",
"engine_name": "Sophos",
"engine_version": "3.5.1.0",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"F-Secure": {
"method": "blacklist",
"engine_name": "F-Secure",
"engine_version": "18.10.1547.307",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"DrWeb": {
"method": "blacklist",
"engine_name": "DrWeb",
"engine_version": "7.0.75.2070",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"VIPRE": {
"method": "blacklist",
"engine_name": "VIPRE",
"engine_version": "6.0.0.35",
"engine_update": "20260516",
"category": "undetected",
"result": null
},
"TrendMicro": {
"method": "blacklist",
"engine_name": "TrendMicro",
"engine_version": "24.550.0.1002",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"McAfeeD": {
"method": "blacklist",
"engine_name": "McAfeeD",
"engine_version": "1.2.0.14532",
"engine_update": "20260518",
"category": "undetected",
"result": null
},
"Trapmine": {
"method": "blacklist",
"engine_name": "Trapmine",
"engine_version": "4.0.12.0",
"engine_update": "20260504",
"category": "undetected",
"result": null
},
"CTX": {
"method": "blacklist",
"engine_name": "CTX",
"engine_version": "2024.8.29.1",
"engine_update": "20260518",
"category": "undetected",
"result": null
},
"Emsisoft": {
"method": "blacklist",
"engine_name": "Emsisoft",
"engine_version": "2024.8.0.61147",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Ikarus": {
"method": "blacklist",
"engine_name": "Ikarus",
"engine_version": "6.4.16.0",
"engine_update": "20260517",
"category": "malicious",
"result": "Trojan-Spy.MSI.Agent"
},
"Jiangmin": {
"method": "blacklist",
"engine_name": "Jiangmin",
"engine_version": "16.0.100",
"engine_update": "20260512",
"category": "undetected",
"result": null
},
"Varist": {
"method": "blacklist",
"engine_name": "Varist",
"engine_version": "6.6.1.3",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Avira": {
"method": "blacklist",
"engine_name": "Avira",
"engine_version": "8.3.3.24",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Antiy-AVL": {
"method": "blacklist",
"engine_name": "Antiy-AVL",
"engine_version": "3.0",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Kingsoft": {
"method": "blacklist",
"engine_name": "Kingsoft",
"engine_version": "None",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Gridinsoft": {
"method": "blacklist",
"engine_name": "Gridinsoft",
"engine_version": "1.0.245.174",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Xcitium": {
"method": "blacklist",
"engine_name": "Xcitium",
"engine_version": "38656",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Microsoft": {
"method": "blacklist",
"engine_name": "Microsoft",
"engine_version": "1.1.26030.3008",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"SUPERAntiSpyware": {
"method": "blacklist",
"engine_name": "SUPERAntiSpyware",
"engine_version": "5.6.0.1032",
"engine_update": "20260516",
"category": "undetected",
"result": null
},
"ZoneAlarm": {
"method": "blacklist",
"engine_name": "ZoneAlarm",
"engine_version": "6.24-114820978",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"GData": {
"method": "blacklist",
"engine_name": "GData",
"engine_version": "GD:27.44582AVA:64.31263",
"engine_update": "20260518",
"category": "undetected",
"result": null
},
"Google": {
"method": "blacklist",
"engine_name": "Google",
"engine_version": "1779058850",
"engine_update": "20260518",
"category": "malicious",
"result": "Detected"
},
"AhnLab-V3": {
"method": "blacklist",
"engine_name": "AhnLab-V3",
"engine_version": "3.30.0.10666",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Acronis": {
"method": "blacklist",
"engine_name": "Acronis",
"engine_version": "1.2.0.121",
"engine_update": "20240328",
"category": "undetected",
"result": null
},
"VBA32": {
"method": "blacklist",
"engine_name": "VBA32",
"engine_version": "5.6.1",
"engine_update": "20260515",
"category": "undetected",
"result": null
},
"TACHYON": {
"method": "blacklist",
"engine_name": "TACHYON",
"engine_version": "2026-05-17.02",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Zoner": {
"method": "blacklist",
"engine_name": "Zoner",
"engine_version": "2.2.2.0",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Rising": {
"method": "blacklist",
"engine_name": "Rising",
"engine_version": "25.0.0.28",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"Yandex": {
"method": "blacklist",
"engine_name": "Yandex",
"engine_version": "5.5.2.24",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"huorong": {
"method": "blacklist",
"engine_name": "huorong",
"engine_version": "85646e2:85646e2:d24df83:d24df83",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"MaxSecure": {
"method": "blacklist",
"engine_name": "MaxSecure",
"engine_version": "1.0.0.1",
"engine_update": "20260515",
"category": "undetected",
"result": null
},
"Fortinet": {
"method": "blacklist",
"engine_name": "Fortinet",
"engine_version": "7.0.30.0",
"engine_update": "20260517",
"category": "malicious",
"result": "PossibleThreat"
},
"Panda": {
"method": "blacklist",
"engine_name": "Panda",
"engine_version": "4.6.4.2",
"engine_update": "20260517",
"category": "undetected",
"result": null
},
"alibabacloud": {
"method": "blacklist",
"engine_name": "alibabacloud",
"engine_version": "2.2.0",
"engine_update": "20250321",
"category": "undetected",
"result": null
},
"Bkav": {
"method": "blacklist",
"engine_name": "Bkav",
"engine_version": null,
"engine_update": "20260516",
"category": "timeout",
"result": null
},
"Avast": {
"method": "blacklist",
"engine_name": "Avast",
"engine_version": "23.9.8494.0",
"engine_update": "20260515",
"category": "timeout",
"result": null
},
"AVG": {
"method": "blacklist",
"engine_name": "AVG",
"engine_version": "23.9.8494.0",
"engine_update": "20260515",
"category": "timeout",
"result": null
},
"TrellixENS": {
"method": "blacklist",
"engine_name": "TrellixENS",
"engine_version": "6.0.6.653",
"engine_update": "20260517",
"category": "timeout",
"result": null
},
"Kaspersky": {
"method": "blacklist",
"engine_name": "Kaspersky",
"engine_version": "22.0.1.28",
"engine_update": "20260517",
"category": "timeout",
"result": null
},
"Skyhigh": {
"method": "blacklist",
"engine_name": "Skyhigh",
"engine_version": null,
"engine_update": "20260517",
"category": "failure",
"result": null
},
"Avast-Mobile": {
"method": "blacklist",
"engine_name": "Avast-Mobile",
"engine_version": "260517-02",
"engine_update": "20260517",
"category": "type-unsupported",
"result": null
},
"SymantecMobileInsight": {
"method": "blacklist",
"engine_name": "SymantecMobileInsight",
"engine_version": "2.0",
"engine_update": "20260123",
"category": "type-unsupported",
"result": null
},
"BitDefenderFalx": {
"method": "blacklist",
"engine_name": "BitDefenderFalx",
"engine_version": "2.0.936",
"engine_update": "20251216",
"category": "type-unsupported",
"result": null
},
"DeepInstinct": {
"method": "blacklist",
"engine_name": "DeepInstinct",
"engine_version": "5.0.0.8",
"engine_update": "20260516",
"category": "type-unsupported",
"result": null
},
"Elastic": {
"method": "blacklist",
"engine_name": "Elastic",
"engine_version": "4.0.261",
"engine_update": "20260513",
"category": "type-unsupported",
"result": null
},
"APEX": {
"method": "blacklist",
"engine_name": "APEX",
"engine_version": "6.779",
"engine_update": "20260516",
"category": "type-unsupported",
"result": null
},
"Paloalto": {
"method": "blacklist",
"engine_name": "Paloalto",
"engine_version": "0.9.0.1003",
"engine_update": "20260518",
"category": "type-unsupported",
"result": null
},
"Cynet": {
"method": "blacklist",
"engine_name": "Cynet",
"engine_version": "4.0.3.4",
"engine_update": "20260517",
"category": "type-unsupported",
"result": null
},
"Alibaba": {
"method": "blacklist",
"engine_name": "Alibaba",
"engine_version": "0.3.0.5",
"engine_update": "20190527",
"category": "type-unsupported",
"result": null
},
"Webroot": {
"method": "blacklist",
"engine_name": "Webroot",
"engine_version": "1.9.0.8",
"engine_update": "20250227",
"category": "type-unsupported",
"result": null
},
"Cylance": {
"method": "blacklist",
"engine_name": "Cylance",
"engine_version": "3.0.0.0",
"engine_update": "20260514",
"category": "type-unsupported",
"result": null
},
"SentinelOne": {
"method": "blacklist",
"engine_name": "SentinelOne",
"engine_version": "7.6.2.19",
"engine_update": "20260324",
"category": "type-unsupported",
"result": null
},
"tehtris": {
"method": "blacklist",
"engine_name": "tehtris",
"engine_version": null,
"engine_update": "20260518",
"category": "type-unsupported",
"result": null
},
"Trustlook": {
"method": "blacklist",
"engine_name": "Trustlook",
"engine_version": "1.0",
"engine_update": "20260518",
"category": "type-unsupported",
"result": null
}
},
"size": 106598400,
"signature_info": {
"verified": "Signed",
"signing date": "07:51 PM 03/05/2026",
"signers": "AgilusTech LLC; SSL.com EV Code Signing Intermediate CA RSA R3; SSL.com EV Root Certification Authority RSA R2",
"counter signers details": [
{
"status": "Valid",
"valid usage": "Timestamp Signing",
"name": "SSL.com Timestamping Unit 2025 E1",
"algorithm": "sha256RSA",
"valid from": "04:32 PM 02/18/2025",
"valid to": "06:50 PM 11/12/2034",
"serial number": "1F 6B 16 62 D2 2E 1B 6C 5D F1 C0 C1 A0 60 0E 38",
"cert issuer": "SSL.com Timestamping Issuing RSA CA R1",
"thumbprint": "26BF9B09469C6976748F04A0DDEAA07AE7C81569"
},
{
"status": "Valid",
"valid usage": "Timestamp Signing",
"name": "SSL.com Timestamping Issuing RSA CA R1",
"algorithm": "sha256RSA",
"valid from": "06:50 PM 11/13/2019",
"valid to": "06:50 PM 11/12/2034",
"serial number": "6D 52 18 70 87 E8 23 4D 85 60 00 D0 80 8F 93 56",
"cert issuer": "SSL.com Root Certification Authority RSA",
"thumbprint": "84DC2F563A1AAA690C468F3B56EF2D63AEC7CA39"
},
{
"status": "Valid",
"valid usage": "Client Auth, Code Signing, Document Signing, EFS, Email Protection, Server Auth, Timestamp Signing",
"name": "SSL.com Root Certification Authority RSA",
"algorithm": "sha256RSA",
"valid from": "05:39 PM 02/12/2016",
"valid to": "05:39 PM 02/12/2041",
"serial number": "7B 2C 9B D3 16 80 32 99",
"cert issuer": "SSL.com Root Certification Authority RSA",
"thumbprint": "B7AB3308D1EA4477BA1480125A6FBDA936490CBB"
}
],
"counter signers": "SSL.com Timestamping Unit 2025 E1; SSL.com Timestamping Issuing RSA CA R1; SSL.com Root Certification Authority RSA",
"signers details": [
{
"status": "Valid",
"valid usage": "Code Signing",
"name": "AgilusTech LLC",
"algorithm": "sha256RSA",
"valid from": "12:53 AM 08/12/2025",
"valid to": "12:53 AM 08/12/2026",
"serial number": "4E 03 B0 A8 C7 16 A7 9C A7 BC 64 B4 DA DD E1 EA",
"cert issuer": "SSL.com EV Code Signing Intermediate CA RSA R3",
"thumbprint": "E42F6BED7E5C3F6007B1E6CE553F472944519EFA"
},
{
"status": "Valid",
"valid usage": "Code Signing",
"name": "SSL.com EV Code Signing Intermediate CA RSA R3",
"algorithm": "sha256RSA",
"valid from": "05:44 PM 03/26/2019",
"valid to": "05:44 PM 03/22/2034",
"serial number": "42 4B 6A 53 CE C7 66 14 1C 2A 63 B1 A5 1C 41 04",
"cert issuer": "SSL.com EV Root Certification Authority RSA R2",
"thumbprint": "D2953DBA95086FEB5805BEFC41283CA64C397DF5"
},
{
"status": "Valid",
"valid usage": "Client Auth, Code Signing, Document Signing, EFS, Email Protection, Server Auth, Timestamp Signing",
"name": "SSL.com EV Root Certification Authority RSA R2",
"algorithm": "sha256RSA",
"valid from": "06:14 PM 05/31/2017",
"valid to": "06:14 PM 05/30/2042",
"serial number": "56 B6 29 CD 34 BC 78 F6",
"cert issuer": "SSL.com EV Root Certification Authority RSA R2",
"thumbprint": "743AF0529BD032A0F44A83CDD4BAA97B7C2EC49A"
}
]
},
"type_tags": [
"installer",
"windows",
"msi"
],
"reputation": -1,
"unique_sources": 2,
"type_tag": "msi",
"sha1": "ed02996ba97457166406d1d3230ef177fec67913",
"first_submission_date": 1773638152,
"last_analysis_date": 1779062468,
"magic": "Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Tralert FX, Author: Yaro, Keywords: Installer, Comments: This installer database contains the logic and data required to install Tralert FX., Template: x64;1033, Revision Number: {BAEEF7FA-3568-4FB5-8D98-D5C9579F2F37}, Create Time/Date: Thu Mar 5 19:25:10 2026, Last Saved Time/Date: Thu Mar 5 19:25:10 2026, Number of Pages: 500, Number of Words: 2, Name of Creating Application: WiX Toolset (4.0.0.5512), Security: 2"
}
}
}