s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-39e3b9134f5edf604d12e8ccf502d5af62947e4b7770d32682db53ab114925b5 high

📛 Threat Title

Unknown: x64

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 280472 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-24 00:02:28.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 39e3b9134f5edf604d12e8ccf502d5af62947e4b7770d32682db53ab114925b5

IOC database

Type
hash_sha256
Value
39e3b9134f5edf604d12e8ccf502d5af62947e4b7770d32682db53ab114925b5
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 dc09d0e7c70add99774c125ed5ed2529

IOC database

Type
hash_md5
Value
dc09d0e7c70add99774c125ed5ed2529
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 b37075d883f2b109e02adb093d2394942c351ea8

IOC database

Type
hash_sha1
Value
b37075d883f2b109e02adb093d2394942c351ea8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 280472 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-24 00:02:28.

Remediations (10)

  • web:github.com

    A comprehensive collection of Microsoft Intune remediation scripts and configurations designed for enterprise endpoint management, device compliance enforcement, and automated system fixes. This repository provides production-ready PowerShell scripts that integrate seamlessly with Intune's remediation framework.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:learn.microsoft.com

    Learn more about Remediations in Microsoft Intune, including what Remediations are and view any prerequisites and licensing requirements. Also, learn how to deploy built-in and custom remediation scripts, and learn how to monitor your scripts.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:research.checkpoint.com

    Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 - without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full […]

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what happened and why. For some samples and an introduction to ...

  • web:stackoverflow.com

    Failed remediation script in Intune while "run script 64-bit PowerShell" option is turned on Ask Question Asked 2 years, 2 months ago Modified 2 years, 2 months ago

  • web:support.microsoft.com

    More information Both the Exchange Server Emergency Mitigation Service (EMS) and the Microsoft Exchange Flighting Service depend on Office Config Service (OCS) files that are signed with a digital certificate. Exchange Server versions that have not been updated with the June 2026 (or later) updates validate these signatures against a specific expected certificate issuer. Because the ...

  • web:support.microsoft.com

    Updates for Windows released on April 9, 2024, and later updates, add the following: Three new mitigation controls that replace the mitigations released in 2023. The new mitigations controls are: A control to deploy the "Windows UEFI CA 2023" certificate to the Secure Boot DB to add trust for Windows boot managers signed by this certificate.

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.