s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-8b40a7652af4b2195f37dc49682d459f791b94fba7aa5a193892412f60aa13c5 high

📛 Threat Title

Unknown: 8b40a7652af4b2195f37dc49682d459f791b94fba7aa5a193892412f60aa13c5.sh

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: sh. Size: 7527 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-05-14 12:54:44.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 8b40a7652af4b2195f37dc49682d459f791b94fba7aa5a193892412f60aa13c5 1 feed

IOC database

Type
hash_sha256
Value
8b40a7652af4b2195f37dc49682d459f791b94fba7aa5a193892412f60aa13c5
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 1f81662c292db99ad799ee2a1d083fc43f4fffe0 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1f81662c292db99ad799ee2a1d083fc43f4fffe0
2 feeds

IOC database

Type
hash_sha1
Value
1f81662c292db99ad799ee2a1d083fc43f4fffe0
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1f81662c292db99ad799ee2a1d083fc43f4fffe0

hash_md5 7ca94d1cd635ebf08ba8fef161c13193 2 feeds

IOC database

Type
hash_md5
Value
7ca94d1cd635ebf08ba8fef161c13193
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

Remediations (8)

  • web:access.redhat.com

    Your OpenShift Container Platform 4 managed cluster is confirmed as affected by CVE-2026-31431 ("Copy Fail"), which has been classified as an important vulnerability. We recommend that you take the steps outlined below to immediately secure your clusters and mitigate the risk. This article provides you with list of steps to ensure your clusters are patched and protected

  • web:askubuntu.com

    We are running a bunch of containers for a cyber security teaching environment, where students can execute arbitrary commands (unprivileged). Our system (Ubuntu 24.04.4 LTS) is affected by the recently-published "Copy Fail" vulnerability (CVE-2026-31431). Unfortunately, updating did not produce any new kernel packages, and we are still stuck with 6.8.0-110: # uname -a Linux teaching-host 6.8.0 ...

  • web:github.com

    One security- remediation .sh for CVE-2026-41940 (cPanel), CVE-2026-31431 (kernel "Copy Fail"), CSF, optional domain/proxy cleanup, and optional operator hardening. - cPanel-Fix/security- remediation .sh at main · MrAriaNet/cPanel-Fix

  • web:github.com

    CVE-2026-31431 Mitigation Script This repository provides a temporary mitigation and revert script for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability.

  • web:knowledge.broadcom.com

    CVE-2026-22719 has direct impact to Aria Operations 8.18.x, and Aria Operations 9.0.x This vulnerability and its impact on the mentioned VMware products are documented in the following VMware Security Advisory (VMSA), please review this document before continuing: CVE-2026-22719 - VMSA-2026-0001 See the Change log at the end of this article for all changes and subscribe to the article for updates.

  • web:techcommunity.microsoft.com

    After some time, this is replaced by 0x87D127DB (" Unknown "). I have purchased new apps via Apple Business Manager, successfully synced them to Intune, and assigned them to test devices — but unfortunately, the apps are not being installed.

  • web:www.rfxn.com

    CVE-2026-31431 ("Copy Fail") is an algif_aead AEAD scratch-write bug that gives any unprivileged tenant a 4-byte page-cache write to any readable file at attacker-chosen offset. On RHEL-family kernels the modules are builtin, so modprobe blacklists are no-ops and userspace cuts are the only defense that bites the running kernel. We dissect the primitive, lay out the five-rung defense ladder ...

  • web:www.winfr.org

    Learn how to pen unknown file types in Windows. Simple methods to find the right app — even if you don't know the file extension!

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.