s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-5892541e8901d5ea993dc7fe55726e90556e84e92f8cb10dbb10cf6d1e3d4705 high

📛 Threat Title

Unknown: composer.dat

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: exe. Size: 14223671 bytes. Tags: ClickFix, Efimer, exe. Reporter: iamaachum. First seen: 2026-08-04 17:52:32.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_imphash dcaf48c1f10b0efa0a4472200f3850ed

IOC database

Type
hash_imphash
Value
dcaf48c1f10b0efa0a4472200f3850ed
First seen
Last seen
Attached to this threat
Appears in
487 threats
Description
imphash of URLhaus payload baf0cf4d7a024bec…

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 5892541e8901d5ea993dc7fe55726e90556e84e92f8cb10dbb10cf6d1e3d4705

IOC database

Type
hash_sha256
Value
5892541e8901d5ea993dc7fe55726e90556e84e92f8cb10dbb10cf6d1e3d4705
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 f7536add9afb7556f00588b84217dc5131916fb7

IOC database

Type
hash_sha1
Value
f7536add9afb7556f00588b84217dc5131916fb7
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 1ce46fad92380ed788416c722264a876

IOC database

Type
hash_md5
Value
1ce46fad92380ed788416c722264a876
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: exe. Size: 14223671 bytes. Tags: ClickFix, Efimer, exe. Reporter: iamaachum. First seen: 2026-08-04 17:52:32.

Remediations (10)

  • web:cyberpress.org

    A sudden format change by GitHub has inadvertently turned a routine validation check into a critical security risk for PHP developers.

  • web:getcomposer.org

    Ensure you're installing vendors straight from your composer.json via rm -rf vendor && composer update -v when troubleshooting, excluding any possible interferences with existing vendor installations or composer.lock entries.

  • web:github.com

    Try clearing Composer's cache by running composer clear-cache. Ensure you're installing vendors straight from your composer.json via rm -rf vendor && composer update -v when troubleshooting, excluding any possible interferences with existing vendor installations or composer.lock entries.

  • web:github.com

    Dependency Manager for PHP. Contribute to composer/composer development by creating an account on GitHub.

  • web:nesbitt.io

    Composer POSTs the project's dependency PURLs and the configured list names to each source URL and gets back filter entries in the same shape Packagist serves.

  • web:www.michalspacek.com

    For composer audit to work properly the packages must be installed by default. But if you use --locked (composer audit --locked) then the audit is based just on the composer.lock file and there's no need to install the packages beforehand. Use --no-dev if, for whatever reason, you'd like to disable auditing packages listed in require-dev.

  • web:www.progressiverobot.com

    Issues that commonly surface alongside composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide: apt lock contention, broken dpkg state, systemd ordering cycles, AppArmor denials, and UFW rule drift.

  • web:www.vicarius.io

    CVE-2024-35241 is a critical vulnerability affecting Composer when interacting with Git repositories. When Composer executes commands like status or remove, it may parse branch names from Git. If these names are crafted maliciously, they can result in unintended shell execution. This mitigation script programmatically inserts or updates the "preferred-install" key inside the "config" section ...

  • web:www.vicarius.io

    CVE-2026-40176 allows an attacker to achieve arbitrary command execution through a crafted composer.json file that exploits unsanitized Perforce connection parameters in Composer's shell command construction.

  • web:www.wiz.io

    Understand the critical aspects of CVE-2025-67746 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.