s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-2de06f87872b10982bc7e1423582d8ebc44f44774f92cf3c3ab6b1f5fb0552cf high

📛 Threat Title

Unknown: bot.amd64

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1131371 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:58.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 2de06f87872b10982bc7e1423582d8ebc44f44774f92cf3c3ab6b1f5fb0552cf

IOC database

Type
hash_sha256
Value
2de06f87872b10982bc7e1423582d8ebc44f44774f92cf3c3ab6b1f5fb0552cf
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 2e04030eea3409171ecf9b4d7e3cd07c

IOC database

Type
hash_md5
Value
2e04030eea3409171ecf9b4d7e3cd07c
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 96286385fd0a5da9b96599e1060084f5aa35dd67

IOC database

Type
hash_sha1
Value
96286385fd0a5da9b96599e1060084f5aa35dd67
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1131371 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:58.

Remediations (10)

  • web:github.com

    These guys have actually a powerful product, and a link to this repo, which makes me wanna test their product. Make sure you use a "clean"ip for this one. ... Check both saved screenhots here Custom Selenium Chromedriver | Zero-Config | Passes ALL bot mitigation systems (like Distil / Imperva/ Datadadome / CloudFlare IUAM)

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Remediation actions can also be applied automatically by Microsoft Defender's automatic attack disruption. When an active attack is detected, attack disruption uses Defender for Identity remediation capabilities to contain the threat without manual intervention. For details, see automatic attack disruption.

  • web:my.f5.com

    A Bot Defense profile is attached to the virtual server AdvWAF Bot Defense, Support ID Cause Mitigations are needed to provide a way to workaround an issue. Sometimes it is a false/positive, and sometimes it may be something with the traffic that is not right but it needs to be allowed so a " mitigation " is provided.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what happened and why. For some samples and an introduction to ...

  • web:seon.io

    Below we compare nine leading bot detection and mitigation tools, their core features, pricing model and best-fit use cases, so you can choose the right one. For the underlying concept, see our primer on bot detection. Features to look for in bot detection tool Tools vary in approach, but the strongest solutions share a common set of capabilities.

  • web:support.microsoft.com

    The detection script collects Secure Boot and certificate status from each device and reports it back to the Intune portal — no remediation action is taken on devices. This gives administrators a centralized, exportable view of certificate update progress across their Intune enrolled Windows devices. Why use this approach?

  • web:support.microsoft.com

    Updates for Windows released on April 9, 2024, and later updates, add the following: Three new mitigation controls that replace the mitigations released in 2023. The new mitigations controls are: A control to deploy the "Windows UEFI CA 2023" certificate to the Secure Boot DB to add trust for Windows boot managers signed by this certificate.

  • web:techdocs.f5.com

    A bot defense microservice allows you to use specific verification and mitigation actions based on a request's URL and hostname. Microservices provide protection from OWASP Automated Threats by hardening mitigation and verification settings for a set of URLs and hostname.

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.