s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-ff602817eb50e8e361871af7c6dd1351c06671f310a3eb2a0692f89df6eb3a9e high

📛 Threat Title

Unknown: iran.x86_64

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 101431 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-08-06 20:43:51.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 ff602817eb50e8e361871af7c6dd1351c06671f310a3eb2a0692f89df6eb3a9e

IOC database

Type
hash_sha256
Value
ff602817eb50e8e361871af7c6dd1351c06671f310a3eb2a0692f89df6eb3a9e
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 1847543325c1f4cb3569c382daa629b618bfcdd8

IOC database

Type
hash_sha1
Value
1847543325c1f4cb3569c382daa629b618bfcdd8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 4cf3e8bed9ffc1acc16c2317ed716b3c

IOC database

Type
hash_md5
Value
4cf3e8bed9ffc1acc16c2317ed716b3c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 101431 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-08-06 20:43:51.

Remediations (10)

  • web:askubuntu.com

    Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.

  • web:blog.toolslib.net

    CVE-2026-31431 ("Copy Fail") is a critical Linux kernel flaw allowing privilege escalation and container escape. Discover impact, risk, and how to patch or mitigate it quickly.

  • web:forums.rockylinux.org

    Situation: A vulnerability was recently discovered in the Linux Kernel named "Dirty Frag", which allows for Local Privilege Escalation (LPE) to the root user. "Dirty Frag" is a similar exploit to the recent "Copy/Fail" (CVE-2026-31431) vulnerability disclosed recently and is a continuation of a previous vulnerability named "Dirty Pipe" (CVE-2022-0847). This vulnerability is ...

  • web:github.com

    CVE-2026-31431 Mitigation Script This repository provides a temporary mitigation and revert script for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability. Disclaimer This is a temporary workaround, not a permanent fix. Use at your own risk. Always test in a non-production environment before applying to production systems.

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:nvd.nist.gov

    Description In the Linux kernel, the following vulnerability has been resolved: x86/vmscape: Add conditional IBPB mitigation VMSCAPE is a vulnerability that exploits insufficient branch predictor isolation between a guest and a userspace hypervisor (like QEMU). Existing mitigations already protect kernel/KVM from a malicious guest. Userspace can additionally be protected by flushing the branch ...

  • web:www.cisa.gov

    Iran Threat Overview and Advisories CISA works to ensure U.S. critical infrastructure, government partners, and others have the information and guidance to defend themselves against Iran State-Sponsored cybersecurity risks.

  • web:www.deepwatch.com

    Expert analysis on elevated Iranian cyber threats following 2026 events. Learn TTPs and proactive strategies to protect your environment.

  • web:www.joesandbox.com

    Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Sample is packed with UPX iran.x86_64.elf started python3.8 dpkg started

  • web:www.joesandbox.com

    General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1919966 Start date and time: 2026-05-28 21:10:26 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 4m 54s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.