s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-7772e5d10ceeddd9a2bccb71ecfde6c7e88323fc2699749e9fee97ac503f4990 high

📛 Threat Title

Unknown: x86

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 25600 bytes. Tags: elf, upx-dec. Reporter: abuse_ch. First seen: 2026-09-23 23:37:46.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 7772e5d10ceeddd9a2bccb71ecfde6c7e88323fc2699749e9fee97ac503f4990

IOC database

Type
hash_sha256
Value
7772e5d10ceeddd9a2bccb71ecfde6c7e88323fc2699749e9fee97ac503f4990
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 c99177485a6d38527f782ef2e386aa78d471da48

IOC database

Type
hash_sha1
Value
c99177485a6d38527f782ef2e386aa78d471da48
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 f45146362097855d9c426741f1460b24

IOC database

Type
hash_md5
Value
f45146362097855d9c426741f1460b24
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 25600 bytes. Tags: elf, upx-dec. Reporter: abuse_ch. First seen: 2026-09-23 23:37:46.

Remediations (10)

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:orca.security

    Microsoft patches CVE-2026-21509, a high-severity Office zero-day actively exploited in the wild. Learn about the OLE bypass, affected versions, and remediation .

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:research.checkpoint.com

    Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 - without exploits, vulnerabilities, or memory corruption? In this publication, we present the first full […]

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what happened and why. For some samples and an introduction to ...

  • web:support.microsoft.com

    Learn more how to protect your Windows devices against silicon-based microarchitectural and speculative execution side-channel vulnerabilities

  • web:windowsforum.com

    Practical mitigation and remediation guidance If you're responsible for a PC, workstation fleet, or enterprise environment, the following prioritized actions will reduce risk quickly.

  • web:www.kodemsecurity.com

    CVE-2026-31431, the Copy Fail Linux kernel LPE, lets authenticated users gain root. See affected kernels, exploit details, IOCs and patches.

  • web:www.rescana.com

    Given the active exploitation and the high impact potential, urgent remediation is required for all organizations utilizing affected Microsoft Office products. This advisory provides a comprehensive technical breakdown, exploitation context, and actionable mitigation guidance to help organizations defend against this evolving threat.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.