Verdict
- VALID_CODE_SIGNATURE The file carries a valid code signature: the signer's certificate chain verifies.
Key indicators
- MD5
- f36eb756889f377f934b8a6099e248de
- File name
- OktaVerifySetup.exe
- File type
- Win32 EXE
- Signature
- Valid · Okta, Inc.
- First submitted
- 2026-09-24
- First seen
- 2026-09-24 (5 days before · VirusTotal)
- Last seen
- 2026-09-29 (0 days before)
Relationship graph
Expand| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| Code signature | Validly signed by Okta, Inc. (certificate from DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1): this shows who published the file, not that it is safe. | — | — | Benign |
| Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration; label trojan.. Sandboxes: 0 of 1 sandboxes: malicious. | 1/75 | 0 days recent | Neutral |
Coverage · checked, no record: MalwareBazaar, ThreatFox, AlienVault OTX, CIRCL hashlookup · failed: none
Analyst summary
Consistent with engineThis file is likely benign (medium confidence): it is validly signed by Okta, Inc. and no source reports it as malicious. A signature identifies the publisher; it does not prove the file is safe.
Why the evidence points to likely benign
- [Code signature] Validly signed by Okta, Inc. (certificate from DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1): this shows who published the file, not that it is safe.
Evidence pointing the other way
- [VirusTotal] Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration; label trojan.. Sandboxes: 0 of 1 sandboxes: malicious.
Attribution
The evidence does not establish who operates this indicator.
Threat context
Context onlyNo group is directly linked to this indicator by any source.
All evidence
6 sources queried · click a row for its raw fields · ages computed by the engine| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| Code signature | Validly signed by Okta, Inc. (certificate from DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1): this shows who published the file, not that it is safe. | — | — | Benign |
| Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration; label trojan.. Sandboxes: 0 of 1 sandboxes: malicious. | 1/75 | 0 days recent | Neutral | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record |
Engine rules applied
- VALID_CODE_SIGNATUREThe file carries a valid code signature: the signer's certificate chain verifies.
- VT_ISOLATED_DETECTIONOnly 1-2 VirusTotal vendors (under 3%) flag the indicator.
Analyst summary
Consistent with engineThis file is likely benign (medium confidence): it is validly signed by Okta, Inc. and no source reports it as malicious. A signature identifies the publisher; it does not prove the file is safe.
Why the evidence points to likely benign
- [Code signature] Validly signed by Okta, Inc. (certificate from DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1): this shows who published the file, not that it is safe.
Evidence pointing the other way
- [VirusTotal] Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration; label trojan.. Sandboxes: 0 of 1 sandboxes: malicious.
Attribution
The evidence does not establish who operates this indicator.
Key indicators
- MD5
- f36eb756889f377f934b8a6099e248de
- File name
- OktaVerifySetup.exe
- File type
- Win32 EXE
- Signature
- Valid · Okta, Inc.
- First submitted
- 2026-09-24
- First seen
- 2026-09-24 (5 days before · VirusTotal)
- Last seen
- 2026-09-29 (0 days before)
By source
No infrastructure source returned a record.
Relationship graph
Click a node for details · edges are observed relationships, not ownershipContext
Attribution
The evidence does not establish who operates this indicator.
Relationship ≠ ownership. Shared IPs, ASNs or platforms never imply the same operator.
Threat context
Context onlyNo group is directly linked to this indicator by any source.
Evidence timeline
- 2026-09-29VirusTotal: Only 1/75 vendors (1.3%) flag it: an isolated detection, not corroboration
- 2026-09-29Investigated
Run history
3 collections of this indicator- 2026-09-29LIKELY BENIGN10Live lookupsOpen · newest
- 2026-09-29LIKELY BENIGN10Live lookupsShown
- 2026-09-29UNKNOWN25Live lookupsOpen
Sources are checked again on every live run, so a source that has since dropped the indicator from its feed can change the verdict. Each run keeps the evidence exactly as it was collected.
Recommended next steps
- contextIf the alert involved unusual behaviour, check the command line and parent process.
- enrichConfirm the file path matches the legitimate installation location.
- enrichCompare the hash with the vendor's published download to confirm this exact build.
Pivot to other tools
Opens the indicator in the source's own site (new tab).

