s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-12942bba4b7c24f3c9b37d972caea2d769c1882375faf5dc4b265a5dacdd63b3 high

📛 Threat Title

Unknown: belom-ready.txt

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: php. Size: 11430 bytes. Tags: cpanel, kamp4ng, php, php-loader. Reporter: boredchilada2. First seen: 2026-09-25 03:14:52.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 12942bba4b7c24f3c9b37d972caea2d769c1882375faf5dc4b265a5dacdd63b3

IOC database

Type
hash_sha256
Value
12942bba4b7c24f3c9b37d972caea2d769c1882375faf5dc4b265a5dacdd63b3
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 850bcbc2fe6d1bdda2bdbf3385e339836fd23122

IOC database

Type
hash_sha1
Value
850bcbc2fe6d1bdda2bdbf3385e339836fd23122
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 3f8605229517688c51f13b950a07b5a7

IOC database

Type
hash_md5
Value
3f8605229517688c51f13b950a07b5a7
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: php. Size: 11430 bytes. Tags: cpanel, kamp4ng, php, php-loader. Reporter: boredchilada2. First seen: 2026-09-25 03:14:52.

Remediations (9)

  • web:github.com

    Contribute to Kamp4ng/cilako development by creating an account on GitHub.

  • web:github.com

    A comprehensive collection of Microsoft Intune remediation scripts and configurations designed for enterprise endpoint management, device compliance enforcement, and automated system fixes. This repository provides production-ready PowerShell scripts that integrate seamlessly with Intune's remediation framework.

  • web:knowledge.broadcom.com

    Host status 'unknown' in vLCM Scenario 1: The ESXi host status is showing as 'unknown' after remediation : ACTIONS ⇓ ? Host status is unknown Info: The host will be rebooted during remediation . Info: Quick Boot is supported on the host. Firmware compliance Scenario 2: Or the ESXi host stops part-way through remediation and produces the error:

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:scloud.work

    Summary Troubleshooting Intune proactive remediation scripts locally saves time and reduces uncertainty. You get full visibility into the script files, logs and registry data. With this approach, I can test, debug and optimize scripts before pushing them to production.

  • web:windowsforum.com

    Microsoft's March cumulative update for Windows 11, KB5079473 (released March 10, 2026), is rolling out with a familiar mix of new features and security fixes — but a growing number of users now say the patch is also triggering severe instability on some machines, including hard freezes...

  • web:www.vicarius.io

    CVE-2026-31431 "Copy Fail" is a critical Linux kernel privilege escalation vulnerability affecting virtually every major distribution shipped since 2017. A simple 732-byte Python script allows any unprivileged local user to reliably gain root access by exploiting the algif_aead cryptographic module's in-place operation flaw, with no race conditions or version-specific requirements. CVE-2026 ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.