s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-47a300898c707806733bd82a1c0b63e47d62a28ceb62e3cc556382dca8d9564a high

📛 Threat Title

Unknown: k.php

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: sh. Size: 45514 bytes. Tags: sh. Reporter: abuse_ch. First seen: 2026-05-15 04:16:00.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain k.php VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/k.php

IOC database

Type
domain
Value
k.php
First seen
Last seen
Attached to this threat
Appears in
14 threats
Description
Extracted from Threat MB-8cbc78702771f69eb7942d6476a214673d8f36ae1055d6610af0c48137af30c0

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/k.php

hash_sha256 47a300898c707806733bd82a1c0b63e47d62a28ceb62e3cc556382dca8d9564a 1 feed

IOC database

Type
hash_sha256
Value
47a300898c707806733bd82a1c0b63e47d62a28ceb62e3cc556382dca8d9564a
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 9153e72d5331531fe8779097d3aa1711df20189c VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9153e72d5331531fe8779097d3aa1711df20189c
1 feed

IOC database

Type
hash_sha1
Value
9153e72d5331531fe8779097d3aa1711df20189c
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/9153e72d5331531fe8779097d3aa1711df20189c

hash_md5 2f3367ffc905152727199b6fca4580f4 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2f3367ffc905152727199b6fca4580f4
1 feed

IOC database

Type
hash_md5
Value
2f3367ffc905152727199b6fca4580f4
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2f3367ffc905152727199b6fca4580f4

References (1)

Remediations (10)

  • web:community.freepbx.org

    If you were impacted by the restapps security regression a week or two ago, it is possible you were hit with a php script that is currently labeled " k.php " If you want to see if you were compromised by this script, I've included some content below that you can check. I do not claim to have identified everything, but I'm hoping this might help someone. Anyways, here are the places you ...

  • web:cyrisk.com

    Addressing PHP Vulnerabilities in Common Technologies In the ever-evolving landscape of cybersecurity, keeping software up to date is crucial for maintaining the security and functionality of your systems. A common issue faced by many organizations is outdated PHP installations, which can leave systems vulnerable to security risks. This article provides remediation instructions for upgrading ...

  • web:dipsylala.github.io

    Primary Defence: Use json_decode () for untrusted data deserialization instead of unserialize (). If you must use unserialize (), use allowed_classes as a last-resort mitigation (PHP 7.0+).

  • web:github.com

    The official PHP remediation engine for CrowdSec. Contribute to crowdsecurity/php- remediation -engine development by creating an account on GitHub.

  • web:www.8isoft.com

    For a step-by-step guide on PHP remediation using 8iSoft YODA, don't miss our exclusive tutorial. Click here to watch the video and enhance your understanding of effective vulnerability management.

  • web:www.netsolutions.com

    In this blow, we discuss PHP vulnerabilities like SQL injection attacks, cross-site scripting, session hijacking and how to fix them.

  • web:www.siteguarding.com

    Detecting and Removing PHP Webshells: Tools, Indicators & Real Case Studies Compromised PHP sites often hide webshells - small scripts that give attackers remote command execution, file management, database access, and persistence.

  • web:www.vicarius.io

    CVE-2026-40176 - Remediation Script for PHP Composer Command Injection Workaround. .DESCRIPTION This script implements a non-patch workaround to mitigate CVE-2026-40176, a command injection vulnerability in PHP Composer 's Perforce VCS driver. Since the vulnerability is triggered when Composer processes Perforce repository declarations in ...

  • web:www.wiz.io

    Understand the critical aspects of CVE-2025-1861 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.

  • web:www.zend.com

    Find an expert overview of common PHP vulnerabilities, including how vulnerabilities are scored, how they are disclosed to the community, and mitigation steps.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.