Verdict
Only an isolated detection, which is not enough to call it malicious. That does not prove it is safe: it may simply be new.
- No rule raised or lowered concern; the evidence is insufficient.
Key indicators
- MD5
- f36eb756889f377f934b8a6099e248de
- File name
- OktaVerifySetup.exe
- File type
- Win32 EXE
- First submitted
- 2026-09-24
- First seen
- 2026-09-24 (5 days before · VirusTotal)
- Last seen
- 2026-09-29 (0 days before)
Relationship graph
Expand| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration; label trojan.. Sandboxes: 0 of 1 sandboxes: malicious. | 1/75 | 0 days recent | Neutral |
Coverage · checked, no record: MalwareBazaar, ThreatFox, AlienVault OTX, CIRCL hashlookup · failed: none
Analyst summary
Consistent with engineUnknown: nothing links this indicator to malicious or benign activity.
Evidence pointing the other way
- [VirusTotal] Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration; label trojan.. Sandboxes: 0 of 1 sandboxes: malicious.
Attribution
The evidence does not establish who operates this indicator.
Threat context
Context onlyNo group is directly linked to this indicator by any source.
All evidence
5 sources queried · click a row for its raw fields · ages computed by the engine| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration; label trojan.. Sandboxes: 0 of 1 sandboxes: malicious. | 1/75 | 0 days recent | Neutral | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record |
Engine rules applied
- VT_ISOLATED_DETECTIONOnly 1-2 VirusTotal vendors (under 3%) flag the indicator.
- NO_POSITIVE_EVIDENCENo source provides malicious or benign evidence; absence is not proof either way.
Analyst summary
Consistent with engineUnknown: nothing links this indicator to malicious or benign activity.
Evidence pointing the other way
- [VirusTotal] Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration; label trojan.. Sandboxes: 0 of 1 sandboxes: malicious.
Attribution
The evidence does not establish who operates this indicator.
Key indicators
- MD5
- f36eb756889f377f934b8a6099e248de
- File name
- OktaVerifySetup.exe
- File type
- Win32 EXE
- First submitted
- 2026-09-24
- First seen
- 2026-09-24 (5 days before · VirusTotal)
- Last seen
- 2026-09-29 (0 days before)
By source
No infrastructure source returned a record.
Relationship graph
Click a node for details · edges are observed relationships, not ownershipContext
Attribution
The evidence does not establish who operates this indicator.
Relationship ≠ ownership. Shared IPs, ASNs or platforms never imply the same operator.
Threat context
Context onlyNo group is directly linked to this indicator by any source.
Evidence timeline
- 2026-09-29VirusTotal: Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration
- 2026-09-29Investigated
Run history
3 collections of this indicator- 2026-09-29LIKELY BENIGN10Live lookupsOpen · newest
- 2026-09-29LIKELY BENIGN10Live lookupsOpen
- 2026-09-29UNKNOWN25Live lookupsShown
Sources are checked again on every live run, so a source that has since dropped the indicator from its feed can change the verdict. Each run keeps the evidence exactly as it was collected.
Recommended next steps
- enrichDetonate the file in a sandbox outside IOCSCAPE.
- huntFind the parent process and delivery path on the host.
Pivot to other tools
Opens the indicator in the source's own site (new tab).

