s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-47d0b1785f854dd45302fd203bbafb5c7a98892a906078fe0c2d944177eec4e6 high

📛 Threat Title

Unknown: rev.sh

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: sh. Size: 1185 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-09-25 04:33:09.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 47d0b1785f854dd45302fd203bbafb5c7a98892a906078fe0c2d944177eec4e6

IOC database

Type
hash_sha256
Value
47d0b1785f854dd45302fd203bbafb5c7a98892a906078fe0c2d944177eec4e6
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 e97df414546c3cacfdd9424ba869db3e0fee1d82

IOC database

Type
hash_sha1
Value
e97df414546c3cacfdd9424ba869db3e0fee1d82
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 6b3440ed5f3c7bf7fa4c037cec7a7938

IOC database

Type
hash_md5
Value
6b3440ed5f3c7bf7fa4c037cec7a7938
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

Remediations (10)

  • web:docs.redhat.com

    Creating a remediation Bash script for a later application Use this procedure to create a Bash script containing remediations that align your system with a security profile such as HIPAA.

  • web:gist.github.com

    # This Bash Remediation Script is generated from an OpenSCAP profile without preliminary evaluation. # It attempts to fix every selected rule, even if the system is already compliant.

  • web:github.com

    Mitigation Approach The exploit relies on the AF_ALG kernel crypto interface. This unloads the vulnerable kernel modules and prevents them from loading again (blacklisting). It also blocks the exploit path. Repository Contents mitigate-cve-2026-31431.sh --> Applies mitigation . rev_mitigate-cve-2026-31431.sh --> Reverts mitigation after patching ...

  • web:github.com

    Contribute to cherinejoseph/programmatic-vulnerability- remediations development by creating an account on GitHub.

  • web:hacktricks.wiki

    LEE - Linux Exploitation Expert Energize your offensive security career with HackTricks Training LEE, proving your Linux exploitation skills across userland, heap, ARM, kernel, and browser targets. Shells - Linux Tip Learn & practice AWS Hacking: HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Learn & practice Az ...

  • web:jfrog.com

    Understand the new Terrapin Attack everyone's talking about! This post details everything you need to know.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:safeguard.sh

    Learn how to write and execute remediation steps that close vulnerabilities fast: triage, prioritize, fix, verify, and prevent regressions.

  • web:www.huntress.com

    A managed detection and response solution like Huntress can automate the detection and remediation process, saving you the headache and kicking the attacker out fast. Is Revshell Still Active? Yes, and it's not going anywhere. The reverse shell is a timeless, effective, and versatile technique.

  • web:www.penligent.ai

    CVE-2026-14191 is a WinRAR, RAR, and UnRAR heap overflow in RAR5 .rev recovery-volume handling. Learn what triggers it, what versions to patch, how to verify exposure, and how defenders should handle untrusted archive workflows.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.