MB-5892541e8901d5ea993dc7fe55726e90556e84e92f8cb10dbb10cf6d1e3d4705
high
📛 Threat Title
Unknown: composer.dat
Description
File type: exe. Size: 14223671 bytes. Tags: ClickFix, Efimer, exe. Reporter: iamaachum. First seen: 2026-08-04 17:52:32.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
dcaf48c1f10b0efa0a4472200f3850ed
IOC database
- Type
- hash_imphash
- Value
dcaf48c1f10b0efa0a4472200f3850ed- First seen
- Last seen
- Attached to this threat
- Appears in
- 487 threats
- Description
- imphash of URLhaus payload baf0cf4d7a024bec…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
5892541e8901d5ea993dc7fe55726e90556e84e92f8cb10dbb10cf6d1e3d4705
IOC database
- Type
- hash_sha256
- Value
5892541e8901d5ea993dc7fe55726e90556e84e92f8cb10dbb10cf6d1e3d4705- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
f7536add9afb7556f00588b84217dc5131916fb7
IOC database
- Type
- hash_sha1
- Value
f7536add9afb7556f00588b84217dc5131916fb7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
1ce46fad92380ed788416c722264a876
IOC database
- Type
- hash_md5
- Value
1ce46fad92380ed788416c722264a876- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 14223671 bytes. Tags: ClickFix, Efimer, exe. Reporter: iamaachum. First seen: 2026-08-04 17:52:32.
Remediations (10)
-
web:cyberpress.org
A sudden format change by GitHub has inadvertently turned a routine validation check into a critical security risk for PHP developers.
-
web:getcomposer.org
Ensure you're installing vendors straight from your composer.json via rm -rf vendor && composer update -v when troubleshooting, excluding any possible interferences with existing vendor installations or composer.lock entries.
-
web:github.com
Try clearing Composer's cache by running composer clear-cache. Ensure you're installing vendors straight from your composer.json via rm -rf vendor && composer update -v when troubleshooting, excluding any possible interferences with existing vendor installations or composer.lock entries.
-
web:github.com
Dependency Manager for PHP. Contribute to composer/composer development by creating an account on GitHub.
-
web:nesbitt.io
Composer POSTs the project's dependency PURLs and the configured list names to each source URL and gets back filter entries in the same shape Packagist serves.
-
web:www.michalspacek.com
For composer audit to work properly the packages must be installed by default. But if you use --locked (composer audit --locked) then the audit is based just on the composer.lock file and there's no need to install the packages beforehand. Use --no-dev if, for whatever reason, you'd like to disable auditing packages listed in require-dev.
-
web:www.progressiverobot.com
Issues that commonly surface alongside composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide: apt lock contention, broken dpkg state, systemd ordering cycles, AppArmor denials, and UFW rule drift.
-
web:www.vicarius.io
CVE-2024-35241 is a critical vulnerability affecting Composer when interacting with Git repositories. When Composer executes commands like status or remove, it may parse branch names from Git. If these names are crafted maliciously, they can result in unintended shell execution. This mitigation script programmatically inserts or updates the "preferred-install" key inside the "config" section ...
-
web:www.vicarius.io
CVE-2026-40176 allows an attacker to achieve arbitrary command execution through a crafted composer.json file that exploits unsanitized Perforce connection parameters in Composer's shell command construction.
-
web:www.wiz.io
Understand the critical aspects of CVE-2025-67746 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.