MB-9dfbe92313bc0d309a0fb07cb6461d6c17f18b9b66842b101593373c1bf9fff7
high
📛 Threat Title
Unknown: b.7z
Description
File type: 7z. Size: 1624642 bytes. Tags: 7z, ClickFix, dressagelaval-com, file-pumped, LegionLoader, pw-666. Reporter: iamaachum. First seen: 2026-08-04 17:53:18.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
9dfbe92313bc0d309a0fb07cb6461d6c17f18b9b66842b101593373c1bf9fff7
IOC database
- Type
- hash_sha256
- Value
9dfbe92313bc0d309a0fb07cb6461d6c17f18b9b66842b101593373c1bf9fff7- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
d62b69b2191388faf5722f51a0c7433eb1a70bfd
IOC database
- Type
- hash_sha1
- Value
d62b69b2191388faf5722f51a0c7433eb1a70bfd- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
6e98c42d96b51f943091ddb291c61d88
IOC database
- Type
- hash_md5
- Value
6e98c42d96b51f943091ddb291c61d88- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: 7z. Size: 1624642 bytes. Tags: 7z, ClickFix, dressagelaval-com, file-pumped, LegionLoader, pw-666. Reporter: iamaachum. First seen: 2026-08-04 17:53:18.
Remediations (10)
-
web:7-zip.org
We must create new "good" 7z archive with same method as in bad.7z, and new archive must be much larger than bad.7z So we select some big file for that new archive.
-
web:blog.avotrix.com
Mitigation Script To mitigate the CVE-2025-0411 vulnerability in 7-Zip, you need to address the issue of Mark-of-the-Web (MOTW) bypass and ensure that extracted files are properly flagged as untrusted.
-
web:cyberreplay.com
This guidance focuses on 7-zip rce mitigation and practical steps that reduce the attack surface quickly. For hands-on support to run a focused 24-72 hour remediation plan, choose a next step now: Book a free security assessment, Schedule a 15-minute intake, or Request managed response.
-
web:cybersecuritynews.com
A newly disclosed vulnerability in 7-Zip, one of the most widely used open-source file archiving tools, could allow remote attackers to execute arbitrary code on affected systems.
-
web:dailysecurityreview.com
7-Zip flaw CVE-2025-11001 is now under active exploitation. The RCE issue is fixed in version 25.00, which users are urged to install.
-
web:socprime.com
CVE-2026-48095 Mitigation The primary response is to upgrade immediately to 7-Zip 26.01 or later. GitHub Security Lab's disclosure timeline shows that the fix shipped on April 27, 2026, and 7-Zip's official history confirms that version 26.01 was released on that date with bug fixes.
-
web:www.penligent.ai
A practical technical breakdown of major 7-Zip CVEs, including CVE-2026-48095, MotW bypass, ZIP symlink traversal, detection logic, patching, and hardening.
-
web:www.penligent.ai
This definitive "7-Zip CVE" guide breaks down the highest-impact 7-Zip vulnerabilities in recent years—Mark-of-the-Web (MotW) bypass, ZIP directory traversal to code execution, and parser-class memory corruption—and turns them into an enterprise playbook: inventory, patch thresholds, hardening patterns, and practical detections with PowerShell, KQL, and Sigma examples.
-
web:www.vicarius.io
📜This script mitigates potential vulnerabilities in systems running older versions of 7-Zip (e.g., those affected by CVE-2025-0411) by completely disabling 7-Zip to prevent users from manually opening and extracting potentially malicious archives. It does so by removing 7-Zip from the context menu, blocking execution, and removing Start Menu shortcuts to ensure it cannot be accessed through ...
-
web:www.vicarius.io
Running this mitigation script helps strengthen your system's defenses against CVE-2025-11001 by neutralizing vulnerable 7z.exe binaries without applying patches or modifying installed packages.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.