s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c high

📛 Threat Title

Unknown: tadashi.x64

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 280376 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 09:10:21.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c

IOC database

Type
hash_sha256
Value
37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c

hash_sha1 21f457ec8a49df84586fe7fde37ed83b6be6d250 VT 2 / 75

IOC database

Type
hash_sha1
Value
21f457ec8a49df84586fe7fde37ed83b6be6d250
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Linux/Mirai.AR trojan
Microsoft malicious Trojan:Script/Wacatac.B!ml

Details From VirusTotal

Basic Properties
MD58aaffd87436ac808730aaa7e290b8123
SHA-121f457ec8a49df84586fe7fde37ed83b6be6d250
SHA-25637df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c
SSDEEP3072:WClO821GTv4Th0Fg1MUhl2QmEY7kqMOu/rFyIlEFh4qkR5GA0YqAPICZ6br6woX1:ROzGTQTmF8hlXm0cu/rkA0LgICZ6brQ
TLSHT149546A17BD9150F8D199C63487AFE133E7B1F05D5130BA4A23E62E123E27B90BB0A795
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
File size273.8 KB
History
First seen on VirusTotal2026-09-25 08:59 UTC
Last submission2026-09-25 09:41 UTC
Last analysis2026-09-25 09:41 UTC
Last modified on VirusTotal2026-09-25 18:09 UTC
Known Names
  • 37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c.elf
  • tadashi.x64
  • rnjqyif4o.exe
hash_md5 8aaffd87436ac808730aaa7e290b8123 VT 2 / 75

IOC database

Type
hash_md5
Value
8aaffd87436ac808730aaa7e290b8123
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 75 VirusTotal vendors

VendorVerdictDetection
ESET-NOD32 malicious Linux/Mirai.AR trojan
Microsoft malicious Trojan:Script/Wacatac.B!ml

Details From VirusTotal

Basic Properties
MD58aaffd87436ac808730aaa7e290b8123
SHA-121f457ec8a49df84586fe7fde37ed83b6be6d250
SHA-25637df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c
SSDEEP3072:WClO821GTv4Th0Fg1MUhl2QmEY7kqMOu/rFyIlEFh4qkR5GA0YqAPICZ6br6woX1:ROzGTQTmF8hlXm0cu/rkA0LgICZ6brQ
TLSHT149546A17BD9150F8D199C63487AFE133E7B1F05D5130BA4A23E62E123E27B90BB0A795
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header
File size273.8 KB
History
First seen on VirusTotal2026-09-25 08:59 UTC
Last submission2026-09-25 09:41 UTC
Last analysis2026-09-25 09:41 UTC
Last modified on VirusTotal2026-09-25 18:09 UTC
Known Names
  • 37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c.elf
  • tadashi.x64
  • rnjqyif4o.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 280376 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 09:10:21.

Remediations (10)

  • web:cybersecuritynews.com

    A new phishing operation, tracked as Operation BlueDash, is tricking users into installing a fake Microsoft Teams update that silently hands attackers not one but two independent ways to remotely control infected computers.

  • web:knowledgebase.42gears.com

    Contents Overview A critical zero-day vulnerability named YellowKey, tracked as CVE-2026-45585 (CVSS score: 6.8), has been publicly disclosed, affecting Windows BitLocker encryption. Microsoft has released an emergency mitigation guidance for this vulnerability following its public proof-of-concept release. SureMDM helps IT administrators immediately identify at-risk devices across their fleet ...

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what happened and why. For some samples and an introduction to ...

  • web:tech-insider.org

    Lazarus Group exploited Windows zero-day CVE-2026-68820 for 5 weeks to deploy FudModule rootkit v3.1 against defense targets. Full breakdown.

  • web:windowsforum.com

    Microsoft has published guidance and an immediate mitigation for CVE-2026-21509 — a security-feature-bypass vulnerability that affects Microsoft Office — and administrators should apply the recommended protections now while patches are rolled out.

  • web:www.elevenforum.com

    Hi, I've just upgraded from 23H2 to 24H2 using Rufus and the 24H2 ISO, but now get a message saying a vulnerable driver can't load (see screenshot), What should I do to remove this?

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

  • web:www.rescana.com

    Given the active exploitation and the high impact potential, urgent remediation is required for all organizations utilizing affected Microsoft Office products. This advisory provides a comprehensive technical breakdown, exploitation context, and actionable mitigation guidance to help organizations defend against this evolving threat.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.