MB-0ee5fd727530366a8df72350ece5a43f10c340d907be54d440b2a0bfc26d6cf7
high
📛 Threat Title
Unknown: composer.dat
Description
File type: exe. Size: 14278327 bytes. Tags: ClickFix, Efimer, exe. Reporter: iamaachum. First seen: 2026-08-04 20:52:28.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_imphash
dcaf48c1f10b0efa0a4472200f3850ed
IOC database
- Type
- hash_imphash
- Value
dcaf48c1f10b0efa0a4472200f3850ed- First seen
- Last seen
- Attached to this threat
- Appears in
- 487 threats
- Description
- imphash of URLhaus payload baf0cf4d7a024bec…
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha256
0ee5fd727530366a8df72350ece5a43f10c340d907be54d440b2a0bfc26d6cf7
IOC database
- Type
- hash_sha256
- Value
0ee5fd727530366a8df72350ece5a43f10c340d907be54d440b2a0bfc26d6cf7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
d750e7576deef10b08a326a6da4f4adf57808579
IOC database
- Type
- hash_sha1
- Value
d750e7576deef10b08a326a6da4f4adf57808579- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
7fe6cabaa2651ef7838b7149c57dd938
IOC database
- Type
- hash_md5
- Value
7fe6cabaa2651ef7838b7149c57dd938- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: exe. Size: 14278327 bytes. Tags: ClickFix, Efimer, exe. Reporter: iamaachum. First seen: 2026-08-04 20:52:28.
Remediations (10)
-
web:cyberpress.org
A sudden format change by GitHub has inadvertently turned a routine validation check into a critical security risk for PHP developers.
-
web:getcomposer.org
Ensure you're installing vendors straight from your composer.json via rm -rf vendor && composer update -v when troubleshooting, excluding any possible interferences with existing vendor installations or composer.lock entries.
-
web:github.com
Dependency Manager for PHP. Contribute to composer/composer development by creating an account on GitHub.
-
web:nesbitt.io
Composer POSTs the project's dependency PURLs and the configured list names to each source URL and gets back filter entries in the same shape Packagist serves.
-
web:www.acunetix.com
The installed.json file generated by Composer, a PHP dependency management tool, is publicly accessible on the web server. This file contains a complete inventory of all installed packages, including their exact versions, installation paths, and dependency relationships.
-
web:www.michalspacek.com
For composer audit to work properly the packages must be installed by default. But if you use --locked (composer audit --locked) then the audit is based just on the composer.lock file and there's no need to install the packages beforehand. Use --no-dev if, for whatever reason, you'd like to disable auditing packages listed in require-dev.
-
web:www.progressiverobot.com
Issues that commonly surface alongside composer — multiple vulnerabilities (5 CVEs) — patch and remediation guide: apt lock contention, broken dpkg state, systemd ordering cycles, AppArmor denials, and UFW rule drift.
-
web:www.vicarius.io
CVE-2024-35241 is a critical vulnerability affecting Composer when interacting with Git repositories. When Composer executes commands like status or remove, it may parse branch names from Git. If these names are crafted maliciously, they can result in unintended shell execution. This mitigation script programmatically inserts or updates the "preferred-install" key inside the "config" section ...
-
web:www.vicarius.io
CVE-2026-40176 allows an attacker to achieve arbitrary command execution through a crafted composer.json file that exploits unsanitized Perforce connection parameters in Composer's shell command construction.
-
web:www.wiz.io
Understand the critical aspects of CVE-2025-67746 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.