MB-37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c
high
📛 Threat Title
Unknown: tadashi.x64
Description
File type: elf. Size: 280376 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 09:10:21.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c
IOC database
- Type
- hash_sha256
- Value
37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c
hash_sha1
21f457ec8a49df84586fe7fde37ed83b6be6d250
VT 2 / 75
IOC database
- Type
- hash_sha1
- Value
21f457ec8a49df84586fe7fde37ed83b6be6d250- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Linux/Mirai.AR trojan |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
Details From VirusTotal
Basic Properties
| MD5 | 8aaffd87436ac808730aaa7e290b8123 |
| SHA-1 | 21f457ec8a49df84586fe7fde37ed83b6be6d250 |
| SHA-256 | 37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c |
| SSDEEP | 3072:WClO821GTv4Th0Fg1MUhl2QmEY7kqMOu/rFyIlEFh4qkR5GA0YqAPICZ6br6woX1:ROzGTQTmF8hlXm0cu/rkA0LgICZ6brQ |
| TLSH | T149546A17BD9150F8D199C63487AFE133E7B1F05D5130BA4A23E62E123E27B90BB0A795 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header |
| File size | 273.8 KB |
History
| First seen on VirusTotal | 2026-09-25 08:59 UTC |
| Last submission | 2026-09-25 09:41 UTC |
| Last analysis | 2026-09-25 09:41 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c.elftadashi.x64rnjqyif4o.exe
hash_md5
8aaffd87436ac808730aaa7e290b8123
VT 2 / 75
IOC database
- Type
- hash_md5
- Value
8aaffd87436ac808730aaa7e290b8123- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ESET-NOD32 | malicious | Linux/Mirai.AR trojan |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
Details From VirusTotal
Basic Properties
| MD5 | 8aaffd87436ac808730aaa7e290b8123 |
| SHA-1 | 21f457ec8a49df84586fe7fde37ed83b6be6d250 |
| SHA-256 | 37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c |
| SSDEEP | 3072:WClO821GTv4Th0Fg1MUhl2QmEY7kqMOu/rFyIlEFh4qkR5GA0YqAPICZ6br6woX1:ROzGTQTmF8hlXm0cu/rkA0LgICZ6brQ |
| TLSH | T149546A17BD9150F8D199C63487AFE133E7B1F05D5130BA4A23E62E123E27B90BB0A795 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header |
| File size | 273.8 KB |
History
| First seen on VirusTotal | 2026-09-25 08:59 UTC |
| Last submission | 2026-09-25 09:41 UTC |
| Last analysis | 2026-09-25 09:41 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
37df850b8685225f95cd3e02f8bd78a6e4628b5fc9a65c4da713fe8f8eeb571c.elftadashi.x64rnjqyif4o.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 280376 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 09:10:21.
Remediations (10)
-
web:cybersecuritynews.com
A new phishing operation, tracked as Operation BlueDash, is tricking users into installing a fake Microsoft Teams update that silently hands attackers not one but two independent ways to remotely control infected computers.
-
web:knowledgebase.42gears.com
Contents Overview A critical zero-day vulnerability named YellowKey, tracked as CVE-2026-45585 (CVSS score: 6.8), has been publicly disclosed, affecting Windows BitLocker encryption. Microsoft has released an emergency mitigation guidance for this vulnerability following its public proof-of-concept release. SureMDM helps IT administrators immediately identify at-risk devices across their fleet ...
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what happened and why. For some samples and an introduction to ...
-
web:tech-insider.org
Lazarus Group exploited Windows zero-day CVE-2026-68820 for 5 weeks to deploy FudModule rootkit v3.1 against defense targets. Full breakdown.
-
web:windowsforum.com
Microsoft has published guidance and an immediate mitigation for CVE-2026-21509 — a security-feature-bypass vulnerability that affects Microsoft Office — and administrators should apply the recommended protections now while patches are rolled out.
-
web:www.elevenforum.com
Hi, I've just upgraded from 23H2 to 24H2 using Rufus and the 24H2 ISO, but now get a message saying a vulnerable driver can't load (see screenshot), What should I do to remove this?
-
web:www.majorgeeks.com
Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.
-
web:www.rescana.com
Given the active exploitation and the high impact potential, urgent remediation is required for all organizations utilizing affected Microsoft Office products. This advisory provides a comprehensive technical breakdown, exploitation context, and actionable mitigation guidance to help organizations defend against this evolving threat.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.