s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-9dfbe92313bc0d309a0fb07cb6461d6c17f18b9b66842b101593373c1bf9fff7 high

📛 Threat Title

Unknown: b.7z

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: 7z. Size: 1624642 bytes. Tags: 7z, ClickFix, dressagelaval-com, file-pumped, LegionLoader, pw-666. Reporter: iamaachum. First seen: 2026-08-04 17:53:18.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 9dfbe92313bc0d309a0fb07cb6461d6c17f18b9b66842b101593373c1bf9fff7

IOC database

Type
hash_sha256
Value
9dfbe92313bc0d309a0fb07cb6461d6c17f18b9b66842b101593373c1bf9fff7
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 d62b69b2191388faf5722f51a0c7433eb1a70bfd

IOC database

Type
hash_sha1
Value
d62b69b2191388faf5722f51a0c7433eb1a70bfd
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 6e98c42d96b51f943091ddb291c61d88

IOC database

Type
hash_md5
Value
6e98c42d96b51f943091ddb291c61d88
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: 7z. Size: 1624642 bytes. Tags: 7z, ClickFix, dressagelaval-com, file-pumped, LegionLoader, pw-666. Reporter: iamaachum. First seen: 2026-08-04 17:53:18.

Remediations (10)

  • web:7-zip.org

    We must create new "good" 7z archive with same method as in bad.7z, and new archive must be much larger than bad.7z So we select some big file for that new archive.

  • web:blog.avotrix.com

    Mitigation Script To mitigate the CVE-2025-0411 vulnerability in 7-Zip, you need to address the issue of Mark-of-the-Web (MOTW) bypass and ensure that extracted files are properly flagged as untrusted.

  • web:cyberreplay.com

    This guidance focuses on 7-zip rce mitigation and practical steps that reduce the attack surface quickly. For hands-on support to run a focused 24-72 hour remediation plan, choose a next step now: Book a free security assessment, Schedule a 15-minute intake, or Request managed response.

  • web:cybersecuritynews.com

    A newly disclosed vulnerability in 7-Zip, one of the most widely used open-source file archiving tools, could allow remote attackers to execute arbitrary code on affected systems.

  • web:dailysecurityreview.com

    7-Zip flaw CVE-2025-11001 is now under active exploitation. The RCE issue is fixed in version 25.00, which users are urged to install.

  • web:socprime.com

    CVE-2026-48095 Mitigation The primary response is to upgrade immediately to 7-Zip 26.01 or later. GitHub Security Lab's disclosure timeline shows that the fix shipped on April 27, 2026, and 7-Zip's official history confirms that version 26.01 was released on that date with bug fixes.

  • web:www.penligent.ai

    A practical technical breakdown of major 7-Zip CVEs, including CVE-2026-48095, MotW bypass, ZIP symlink traversal, detection logic, patching, and hardening.

  • web:www.penligent.ai

    This definitive "7-Zip CVE" guide breaks down the highest-impact 7-Zip vulnerabilities in recent years—Mark-of-the-Web (MotW) bypass, ZIP directory traversal to code execution, and parser-class memory corruption—and turns them into an enterprise playbook: inventory, patch thresholds, hardening patterns, and practical detections with PowerShell, KQL, and Sigma examples.

  • web:www.vicarius.io

    📜This script mitigates potential vulnerabilities in systems running older versions of 7-Zip (e.g., those affected by CVE-2025-0411) by completely disabling 7-Zip to prevent users from manually opening and extracting potentially malicious archives. It does so by removing 7-Zip from the context menu, blocking execution, and removing Start Menu shortcuts to ensure it cannot be accessed through ...

  • web:www.vicarius.io

    Running this mitigation script helps strengthen your system's defenses against CVE-2025-11001 by neutralizing vulnerable 7z.exe binaries without applying patches or modifying installed packages.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.