MB-ff602817eb50e8e361871af7c6dd1351c06671f310a3eb2a0692f89df6eb3a9e
high
📛 Threat Title
Unknown: iran.x86_64
Description
File type: elf. Size: 101431 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-08-06 20:43:51.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
ff602817eb50e8e361871af7c6dd1351c06671f310a3eb2a0692f89df6eb3a9e
IOC database
- Type
- hash_sha256
- Value
ff602817eb50e8e361871af7c6dd1351c06671f310a3eb2a0692f89df6eb3a9e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
1847543325c1f4cb3569c382daa629b618bfcdd8
IOC database
- Type
- hash_sha1
- Value
1847543325c1f4cb3569c382daa629b618bfcdd8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
4cf3e8bed9ffc1acc16c2317ed716b3c
IOC database
- Type
- hash_md5
- Value
4cf3e8bed9ffc1acc16c2317ed716b3c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 101431 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-08-06 20:43:51.
Remediations (10)
-
web:askubuntu.com
Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:blog.toolslib.net
CVE-2026-31431 ("Copy Fail") is a critical Linux kernel flaw allowing privilege escalation and container escape. Discover impact, risk, and how to patch or mitigate it quickly.
-
web:forums.rockylinux.org
Situation: A vulnerability was recently discovered in the Linux Kernel named "Dirty Frag", which allows for Local Privilege Escalation (LPE) to the root user. "Dirty Frag" is a similar exploit to the recent "Copy/Fail" (CVE-2026-31431) vulnerability disclosed recently and is a continuation of a previous vulnerability named "Dirty Pipe" (CVE-2022-0847). This vulnerability is ...
-
web:github.com
CVE-2026-31431 Mitigation Script This repository provides a temporary mitigation and revert script for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability. Disclaimer This is a temporary workaround, not a permanent fix. Use at your own risk. Always test in a non-production environment before applying to production systems.
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:nvd.nist.gov
Description In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that exploits insufficient branch predictor isolation between a guest and a userspace hypervisor (like QEMU). Existing mitigations already protect kernel/KVM from a malicious guest. Userspace can additionally be protected by flushing the branch ...
-
web:www.cisa.gov
Iran Threat Overview and Advisories CISA works to ensure U.S. critical infrastructure, government partners, and others have the information and guidance to defend themselves against Iran State-Sponsored cybersecurity risks.
-
web:www.deepwatch.com
Expert analysis on elevated Iranian cyber threats following 2026 events. Learn TTPs and proactive strategies to protect your environment.
-
web:www.joesandbox.com
Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Sample is packed with UPX iran.x86_64.elf started python3.8 dpkg started
-
web:www.joesandbox.com
General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1919966 Start date and time: 2026-05-28 21:10:26 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 4m 54s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.