MB-093a07c0ccfda1228beba7aa42911ebb3cbf725ae8c74558822ebdaa01d4dc48
high
📛 Threat Title
Unknown: stub.x86-64
Description
File type: elf. Size: 890197 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-24 00:11:54.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
093a07c0ccfda1228beba7aa42911ebb3cbf725ae8c74558822ebdaa01d4dc48
IOC database
- Type
- hash_sha256
- Value
093a07c0ccfda1228beba7aa42911ebb3cbf725ae8c74558822ebdaa01d4dc48- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
af58a67f560883bb40f804fa3f2512f6
IOC database
- Type
- hash_md5
- Value
af58a67f560883bb40f804fa3f2512f6- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 890197 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-24 00:11:54.
Remediations (10)
-
web:askubuntu.com
Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:github.com
When the Cybersecurity and Infrastructure Security Agency (CISA) adds critical Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, an urgent operational clock starts ticking for infrastructure teams and SRE leads: The Upstream Patch Gap: The duration between the public weaponization of an in-the-wild zero-day and the availability of tested, signed binary kernel ...
-
web:learn.microsoft.com
Proved the fix. Microsoft stated that they have re-published the CVE-2013-3900 to inform customers about the availability of EnableCertPaddingCheck. This behavior remains available as an opt-in feature via the registry key setting and is available on all supported editions of Windows released since December 10, 2013. <P> Microsoft recommends that executable authors consider conforming all ...
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what happened and why. For some samples and an introduction to ...
-
web:www.automox.com
Patch CVE-2023-38175 by removing the orphaned MpSigStub.exe binary on Windows endpoints running third-party antivirus with Microsoft Defender disabled.
-
web:www.bugcrowd.com
Understand vulnerability remediation vs. mitigation , when to use each approach, and how to reduce security risk while working toward a permanent fix.
-
web:www.kernel.org
29.1.1. Mechanics ¶ Refer to < The EFI Boot Stub > to learn how to use the EFI stub. Below are general EFI setup guidelines on the x86_64 platform, regardless of whether you use the EFI stub or a separate bootloader.
-
web:www.majorgeeks.com
Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.
-
web:www.vicarius.io
CVE-2026-33824 (BlueHammer) enables zero-click, unauthenticated remote code execution against any Windows host with the IKEEXT service active. Because the vulnerability is pre-authentication and wormable in nature, unpatched VPN gateways, DirectAccess servers, and IPsec-enabled endpoints are at immediate risk of complete compromise, credential theft, and lateral movement.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.