MB-e2a115fa809a871e506593b0304323f57b992e456ffe9bceced836893c414c4e
high
📛 Threat Title
Unknown: stub.mipsel
Description
File type: elf. Size: 732229 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:51.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
e2a115fa809a871e506593b0304323f57b992e456ffe9bceced836893c414c4e
IOC database
- Type
- hash_sha256
- Value
e2a115fa809a871e506593b0304323f57b992e456ffe9bceced836893c414c4e- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
8e8a3517a6ea1d2cddf18ea186e5ef9f
IOC database
- Type
- hash_md5
- Value
8e8a3517a6ea1d2cddf18ea186e5ef9f- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
4a2804caa44d67199e3c6ef3a61fd8e3a8b798b8
IOC database
- Type
- hash_sha1
- Value
4a2804caa44d67199e3c6ef3a61fd8e3a8b798b8- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 732229 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:51.
Remediations (10)
-
web:deepwiki.com
This document covers the decompression stub system for MIPS and PowerPC architectures in UPX, including both 32-bit and 64-bit variants with different endianness configurations.
-
web:github.com
When the Cybersecurity and Infrastructure Security Agency (CISA) adds critical Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, an urgent operational clock starts ticking for infrastructure teams and SRE leads: The Upstream Patch Gap: The duration between the public weaponization of an in-the-wild zero-day and the availability of tested, signed binary kernel ...
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:linux-mips.org
The tool allows to generate a toolchain for a variety of architectures, including MIPS and MIPSel. The tool allows to generate both a toolchain and a root filesystem for a variety of architectures, including MIPS and MIPSel.
-
web:lists.gnu.org
[Bug binutils/30569] MIPS16 function stub assertion fail for mipsel_24kc_24kf, cvs-commit at gcc dot gnu.org, 2024/04/01 [Bug binutils/30569] MIPS16 function stub assertion fail for mipsel_24kc_24kf, cvs-commit at gcc dot gnu.org <= [Bug binutils/30569] MIPS16 function stub assertion fail for mipsel_24kc_24kf, amodra at gmail dot com, 2024/04/01 [Bug binutils/30569] MIPS16 function stub ...
-
web:maskray.me
This article describes some notes about MIPS with a focus on the ELF object file format, GCC, binutils, and LLVM/Clang. In the llvm-project project, I sometimes find myself assigned as a reviewer for
-
web:osv.dev
Comprehensive vulnerability database for your open source projects and dependencies.
-
web:suchmememanyskill.github.io
READ THIS BEFORE CONTINUING This guide isn't called an "unbrick guide" for no reason, it shouldn't be treated as a way out of simple inconveniences and should NOT be followed without proper reason to do so. A "brick" indicates that a device is dysfunctional on a soft- and/or hardware level. The term "software brick" means that something is messed up at the internal storage/operating system ...
-
web:windowsforum.com
Microsoft's Security Response Center (MSRC) has assigned CVE‑2026‑21536 to a remote code execution (RCE) class vulnerability affecting the Microsoft Devices Pricing Program (the cloud-backed service used by Microsoft and authorized channel partners to manage device pricing and incentives).
-
web:www.joesandbox.com
General Information Joe Sandbox version: 45.0.0 Green Opal Analysis ID: 1976746 Start date and time: 2026-09-23 14:26:01 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 4m 16s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.