s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-0b5884d061c71436042721d629499147e7b949f53aa22f0cb7cc952af066beb6 high

📛 Threat Title

Unknown: 0b5884d061c71436042721d629499147e7b949f53aa22f0cb7cc952af066beb6.rar

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: rar. Size: 34388 bytes. Tags: 45-133-174-90, rar. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:32:34.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 0b5884d061c71436042721d629499147e7b949f53aa22f0cb7cc952af066beb6 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0b5884d061c71436042721d629499147e7b949f53aa22f0cb7cc952af066beb6
1 feed

IOC database

Type
hash_sha256
Value
0b5884d061c71436042721d629499147e7b949f53aa22f0cb7cc952af066beb6
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0b5884d061c71436042721d629499147e7b949f53aa22f0cb7cc952af066beb6

hash_sha1 1ee441fe7854ce38e79a256337221e0b8e3a131b VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1ee441fe7854ce38e79a256337221e0b8e3a131b
2 feeds

IOC database

Type
hash_sha1
Value
1ee441fe7854ce38e79a256337221e0b8e3a131b
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1ee441fe7854ce38e79a256337221e0b8e3a131b

hash_md5 39d5e94b72d0963c7bdd232ed431a21c VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/39d5e94b72d0963c7bdd232ed431a21c
2 feeds

IOC database

Type
hash_md5
Value
39d5e94b72d0963c7bdd232ed431a21c
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/39d5e94b72d0963c7bdd232ed431a21c

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: rar. Size: 34388 bytes. Tags: 45-133-174-90, rar. Reporter: JAMESWT_WT. First seen: 2026-05-14 07:32:34.

Remediations (10)

  • web:blog.qualys.com

    WinRAR CVE-2025-8088 is actively exploited. Learn how Qualys TruRisk™ Eliminate helps patch, mitigate, or uninstall vulnerable versions fast, in one platform.

  • web:cyberpress.org

    The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical remote code execution (RCE) vulnerability affecting WinRAR to its Known Exploited Vulnerabilities catalog, signaling an immediate threat to the widely used file compression software. The vulnerability, tracked as CVE-2025-6218, is actively being exploited in real-world attacks and requires urgent patching. WinRAR ...

  • web:cybersecuritynews.com

    The U.S. Cybersecurity and Infrastructure Security Agency has added this vulnerability to its Known Exploited Vulnerabilities catalog, with a due date of September 2, 2025, for federal agencies to apply mitigations . WinRAR has released version 7.13 to address a critical security vulnerability that has been actively exploited by cybercriminals, marking another significant security incident for ...

  • web:fidelissecurity.com

    CVE-2025-6218 is a critical WinRAR flaw enabling RCE via directory traversal. See impact, exploitation risk, and how to mitigate the threat.

  • web:thehackernews.com

    CISA warns WinRAR CVE-2025-6218 is under active attack by multiple threat groups, requiring federal fixes by Dec. 30, 2025.

  • web:vulert.com

    Mitigation : how to protect yourself and your organisation Update to WinRAR 7.13 immediately: The single most effective mitigation is to upgrade to WinRAR version 7.13 or later. This release addresses the path‑traversal vulnerability by sanitising extraction paths and preventing malicious archives from overriding the destination directory.

  • web:windowsforum.com

    CISA's decision to add two recently disclosed flaws — a WinRAR path‑traversal bug (CVE-2025-6218) and a Windows Cloud Files mini‑filter use‑after‑free (CVE-2025-62221) — to the Known Exploited Vulnerabilities (KEV) Catalog crystallizes a simple reality for defenders: time-to-fix is shrinking and the federal remediation clock is unforgiving. The technical facts are straightforward ...

  • web:www.gopher.security

    This article details the active exploitation of WinRAR vulnerability CVE-2025-6218, a path traversal flaw allowing remote code execution. CISA has added it to its Known Exploited Vulnerabilities catalog, with threat actors like Bitter and Gamaredon leveraging it in attacks. The vulnerability was patched by RARLAB in WinRAR version 7.12.

  • web:www.greenbone.net

    Critical WinRAR flaw CVE-2025-8088 actively exploited. Update to version 7.13 now to protect your systems.

  • web:www.vicarius.io

    This PowerShell script applies a non-patch workaround for CVE-2025-8088 in WinRAR by combining Software Restriction Policies (SRP) with Image File Execution Options (IFEO) to block winrar.exe, rar.exe, and unrar.exe—even if SRP is bypassed.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.