MB-7cd10124c09f68da64a5021f7fcff05a0dce1128b4f0caf1a8d93a88ecaf5e26
high
📛 Threat Title
Unknown: stub.x64
Description
File type: elf. Size: 890506 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:31.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7cd10124c09f68da64a5021f7fcff05a0dce1128b4f0caf1a8d93a88ecaf5e26
IOC database
- Type
- hash_sha256
- Value
7cd10124c09f68da64a5021f7fcff05a0dce1128b4f0caf1a8d93a88ecaf5e26- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
cf6185c5274891eda762db71ae3787c7e21ff5b6
IOC database
- Type
- hash_sha1
- Value
cf6185c5274891eda762db71ae3787c7e21ff5b6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
9682ecfdb28c033b5a444da6e2fa5e0a
IOC database
- Type
- hash_md5
- Value
9682ecfdb28c033b5a444da6e2fa5e0a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 890506 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:31.
Remediations (10)
-
web:dortania.github.io
Kernel Issues Issues surrounding from initial booting the macOS installer to right before the install GUI pops up.
-
web:knowledgebase.42gears.com
Instead, Microsoft has currently provided mitigation guidance in the form of a PowerShell-based remediation script. Until an official KB update becomes available, administrators can use SureMDM's Run Script capability to remotely deploy and execute the mitigation script across affected Windows devices.
-
web:learn.microsoft.com
When Microsoft released the remediation steps for this vulnerability, the data type of registry value "EnableCertPaddingCheck" = 1 as REG_SZ and we set this value as "REG_SZ" across all computers.
-
web:learn.microsoft.com
Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.
-
web:static.threatlocker.com
#!ps #maxlength=50000 #timeout=90000 [Net.ServicePointManager]::SecurityProtocol = "Tls12" ## Variables $organizationName = 'Insert Organization Name' ## Check if C ...
-
web:support.microsoft.com
Updates for Windows released on April 9, 2024, and later updates, add the following: Three new mitigation controls that replace the mitigations released in 2023. The new mitigations controls are: A control to deploy the "Windows UEFI CA 2023" certificate to the Secure Boot DB to add trust for Windows boot managers signed by this certificate.
-
web:threatlocker.kb.help
ThreatLocker recommends using the Stub Installer over the MSI Installer whenever possible. The stub installer will install the version set as the default version for the group new computers are being installed into, and it also includes a Health Service that can repair potential problems and keep the ThreatLocker Service running.
-
web:windowsforum.com
Microsoft's Security Update Guide is the canonical place to verify which specific Windows builds and KBs include the fix for CVE-2025-53803; the general remediation pattern for kernel information-disclosure CVEs is: vendor advisory → cumulative update or security-only KB → distribution via Windows Update/WSUS and the Microsoft Update Catalog.
-
web:www.automox.com
The use of the Sysnative alias preserves the 64-bit System32 view even when PowerShell runs from a 32-bit host process. Remediation phase: The remediation script repeats the Defender check (so a state change between evaluation and remediation does not delete the stub on a now-protected endpoint), then calls [System.IO.File]::Delete ...
-
web:www.majorgeeks.com
Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.