s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-8047431f29196d8664be94cf8dee1831eea95a588cbfdb3d1ed6bf844401f426 high

📛 Threat Title

Unknown: 0.sh

Category: Unknown First seen: Last updated: Source: Abuse.ch

Description

File type: unknown. Size: 238640 bytes. Reporter: BlinkzSec. First seen: 2026-05-13 18:50:52.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain 0.sh VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/0.sh
UrlVoid 0 / 35

IOC database

Type
domain
Value
0.sh
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-8047431f29196d8664be94cf8dee1831eea95a588cbfdb3d1ed6bf844401f426

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/0.sh

hash_sha256 8047431f29196d8664be94cf8dee1831eea95a588cbfdb3d1ed6bf844401f426 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8047431f29196d8664be94cf8dee1831eea95a588cbfdb3d1ed6bf844401f426
1 feed

IOC database

Type
hash_sha256
Value
8047431f29196d8664be94cf8dee1831eea95a588cbfdb3d1ed6bf844401f426
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8047431f29196d8664be94cf8dee1831eea95a588cbfdb3d1ed6bf844401f426

hash_md5 3dd2fb9cb13e892558eca12028ddfa4a VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3dd2fb9cb13e892558eca12028ddfa4a
2 feeds

IOC database

Type
hash_md5
Value
3dd2fb9cb13e892558eca12028ddfa4a
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3dd2fb9cb13e892558eca12028ddfa4a

References (1)

Remediations (10)

  • web:access.redhat.com

    Remediation Timeline Given the interest in how this vulnerability was disclosed and remediated, the following timeline outlines the key events. 2026-03-23 Reporter privately contacts upstream 2026-03-24 Upstream acknowledges receiving the report 2026-03-25 Upstream/Reporter propose and review patches 2026-04-01 Upstream commits patch to ...

  • web:carthageelectronics.com

    May 19, 2026 CVE bulletin: Microsoft Exchange CVE-2026-42897 zero-day (CVSS 8.1), Linux Fragnesia CVE-2026-46300 privilege escalation with public PoC, and 130+ May Patch Tuesday fixes. Full remediation steps included.

  • web:cyberpress.org

    Fragnesia is a universal local privilege escalation (LPE) exploit targeting the Linux kernel's XFRM ESP-in-TCP subsystem.

  • web:github.com

    # # The remediation is idempotent — running it repeatedly has no # additional effect once the blacklist file is in place and the # modules are unloaded. # # WARNING # This mitigation disables IPsec ESP (esp4 / esp6), IPsec # IP-Compression (ipcomp4 / ipcomp6), and RxRPC (rxrpc) kernel # modules.

  • web:github.com

    MrAriaNet / cPanel-Fix Public Notifications You must be signed in to change notification settings Fork 1 Star 0 Code Projects Security and quality0 Insights Code Issues Pull requests Actions Projects Security and quality Insights Files Expand file tree main cPanel-Fix / security- remediation .sh More file actions

  • web:knowledge.broadcom.com

    CVE-2026-22719 has direct impact to Aria Operations 8.18.x, and Aria Operations 9.0.x This vulnerability and its impact on the mentioned VMware products are documented in the following VMware Security Advisory (VMSA), please review this document before continuing: CVE-2026-22719 - VMSA-2026-0001 See the Change log at the end of this article for all changes and subscribe to the article for updates.

  • web:safeguard.sh

    Detect and absorb breaking changes during vulnerability remediation so fix PRs land cleanly. A 2026 playbook for safe automated upgrades.

  • web:www.cisa.gov

    High Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info

  • web:www.tenable.com

    Dirty Frag (CVE-2026-43284, CVE-2026-43500) is a Linux kernel local privilege escalation exploit chain with a public PoC affecting major Linux distributions.

  • web:www.upguard.com

    Remediation , mitigation , and patching represent distinct operational choices. Remediation targets the root cause for permanent finality. Patching provides a specific vendor-supplied code update. Mitigation serves as a vital "defense-in-depth" measure to buy time when a patch is unavailable or deployment risk is high.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.