s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-43efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c high

📛 Threat Title

Unknown: 43efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 242512 bytes. Tags: elf, wraith. Reporter: c2hunter. First seen: 2026-09-25 09:24:59.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 43efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/43efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c

IOC database

Type
hash_sha256
Value
43efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/43efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c

hash_sha1 f81711816fda9251ae1f7388718ade11e328923d VT 3 / 75

IOC database

Type
hash_sha1
Value
f81711816fda9251ae1f7388718ade11e328923d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 3 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Linux/Mirai.Gen21
ESET-NOD32 malicious Linux/Mirai.AR trojan
Microsoft malicious Trojan:Script/Wacatac.B!ml

Details From VirusTotal

Basic Properties
MD56bf662c155f01bd14b9fe504da168c8c
SHA-1f81711816fda9251ae1f7388718ade11e328923d
SHA-25643efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c
VHashe677de2dfae2764367f2416681e39a0a
SSDEEP3072:XclO8040IQp/iPuSYrTbguRrlOETqjAYEshoo2RCVpM6ZEMaCM6BTu4E/H8:GOrIO/Cuj9llHTqFwRCo6aCM6BTuN
TLSHT1BC346A17F99150B8D189C6308BAFE133E772F05D5130BA4B27E62E227D27B90BB0A755
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
File size236.8 KB
History
First seen on VirusTotal2026-09-25 09:23 UTC
Last submission2026-09-25 09:31 UTC
Last analysis2026-09-25 09:31 UTC
Last modified on VirusTotal2026-09-25 14:39 UTC
Known Names
  • tadashi.x64
  • 43efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c.elf
  • 0cuuwrh.exe
hash_md5 6bf662c155f01bd14b9fe504da168c8c VT 3 / 75

IOC database

Type
hash_md5
Value
6bf662c155f01bd14b9fe504da168c8c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 3 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Linux/Mirai.Gen21
ESET-NOD32 malicious Linux/Mirai.AR trojan
Microsoft malicious Trojan:Script/Wacatac.B!ml

Details From VirusTotal

Basic Properties
MD56bf662c155f01bd14b9fe504da168c8c
SHA-1f81711816fda9251ae1f7388718ade11e328923d
SHA-25643efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c
VHashe677de2dfae2764367f2416681e39a0a
SSDEEP3072:XclO8040IQp/iPuSYrTbguRrlOETqjAYEshoo2RCVpM6ZEMaCM6BTu4E/H8:GOrIO/Cuj9llHTqFwRCo6aCM6BTuN
TLSHT1BC346A17F99150B8D189C6308BAFE133E772F05D5130BA4B27E62E227D27B90BB0A755
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped
File size236.8 KB
History
First seen on VirusTotal2026-09-25 09:23 UTC
Last submission2026-09-25 09:31 UTC
Last analysis2026-09-25 09:31 UTC
Last modified on VirusTotal2026-09-25 14:39 UTC
Known Names
  • tadashi.x64
  • 43efb4f01b17c9a2b9c52f926113493b0e896778e1f4d547ce20b00432d76f4c.elf
  • 0cuuwrh.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 242512 bytes. Tags: elf, wraith. Reporter: c2hunter. First seen: 2026-09-25 09:24:59.

Remediations (10)

  • web:maclookup.app

    Fast and easy MAC address lookup on IEEE directory and Wireshark manufacturer database. Search vendor, manufacturer or organization of a device by MAC/OUI address. Fast REST API

  • web:maclookup.app

    Use our MAC Address Search to find manufacturer details and vendor information in real-time. Enhance your network security with maclookup.app.

  • web:radar.offseq.com

    Mitigation Recommendations Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid processing untrusted EXR files or implement input validation to detect and reject files with unknown -type attributes having zero dataSize.

  • web:radar.offseq.com

    Detailed information about CVE-2026-94426: Cross Site Scripting in xuxueli xxl-job affecting xuxueli xxl-job. Get real-time updates, technical details, and miti

  • web:socprime.com

    Check Point has released emergency security updates for a critical zero-day vulnerability affecting its Security Management infrastructure after confirming exploitation in targeted attacks. Tracked as CVE-2026-93616 and rated 9.8 on the CVSS scale, the flaw enables an unauthenticated attacker with network access to the vulnerable management service to upload and execute arbitrary scripts. The ...

  • web:windowsforum.com

    CISA added four actively exploited Check Point, Arista VeloCloud and F5 vulnerabilities to its KEV catalog, requiring federal agencies to patch and perform forensic triage by September 25.

  • web:windowsforum.com

    Practical mitigation and remediation guidance If you're responsible for a PC, workstation fleet, or enterprise environment, the following prioritized actions will reduce risk quickly.

  • web:www.facebook.com

    Connect and share with friends, family, and the world on Facebook.

  • web:www.instagram.com

    Create an account or log in to Instagram - Share what you're into with the people who get you.

  • web:www.macvendorlookup.com

    MAC Address Lookup Enter any MAC address, OUI, or IAB below to lookup the manufacturer, location, and more

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.