s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-f5a17e4f83f344894859dfcd004c3890380b2af37fb1d473d37c62aa416de3f4 high

📛 Threat Title

Unknown: ypezhbfg.i686

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1132198 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:56.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 f5a17e4f83f344894859dfcd004c3890380b2af37fb1d473d37c62aa416de3f4

IOC database

Type
hash_sha256
Value
f5a17e4f83f344894859dfcd004c3890380b2af37fb1d473d37c62aa416de3f4
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 673ffd804e004d731c71d0b35ffa0d11

IOC database

Type
hash_md5
Value
673ffd804e004d731c71d0b35ffa0d11
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 8263fcac1ebd675c22dbe9678fd2c60bb4b53985

IOC database

Type
hash_sha1
Value
8263fcac1ebd675c22dbe9678fd2c60bb4b53985
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1132198 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:56.

Remediations (9)

  • web:cybersecuritynews.com

    Microsoft has disclosed a critical zero-day vulnerability in Windows BitLocker, tracked as CVE-2026-45585, that allows threat actors with physical access to bypass full-disk encryption entirely, potentially exposing sensitive data within minutes.

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:nhimg.org

    Vulnerability remediation and mitigation are different responses to the same exposure problem. Remediation removes the flaw, while mitigation constrains the blast radius when a patch is delayed, unavailable, or too disruptive.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:radar.offseq.com

    Detailed information about URLhaus IOCs for 2025-03-26. Get real-time updates, technical details, and mitigation strategies.

  • web:securityaffairs.com

    Microsoft acknowledged the YellowKey BitLocker bypass flaw and released mitigations , urging admins to disable autofstx.exe and enable TPM+PIN. A week after Chaotic Eclipse publicly dropped the YellowKey vulnerability, Microsoft acknowledged it and published a mitigation . Not a patch, a mitigation . The distinction matters, and we will get to why. The flaw, tracked as CVE-2026-45585 (CVSS score ...

  • web:support.microsoft.com

    More information Both the Exchange Server Emergency Mitigation Service (EMS) and the Microsoft Exchange Flighting Service depend on Office Config Service (OCS) files that are signed with a digital certificate. Exchange Server versions that have not been updated with the June 2026 (or later) updates validate these signatures against a specific expected certificate issuer. Because the ...

  • web:windowsforum.com

    Microsoft has issued manual mitigation guidance for YellowKey, a publicly disclosed BitLocker bypass tracked as CVE-2026-45585, after proof-of-concept exploit code appeared online in May 2026 and before the company has shipped a full security update for affected Windows systems.

  • web:www.helpnetsecurity.com

    Microsoft is working on a fix for CVE-2026-45585 (aka "Yellowkey"), a vulnerability that can be used to bypass Windows' BitLocker protection.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.