s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-b6469a522cd971eb693ba58772970a62fa6f0fe328d22c49c760e0946d500ca9 high

📛 Threat Title

Unknown: atjozltp.x86_64

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1131618 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:34.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 b6469a522cd971eb693ba58772970a62fa6f0fe328d22c49c760e0946d500ca9

IOC database

Type
hash_sha256
Value
b6469a522cd971eb693ba58772970a62fa6f0fe328d22c49c760e0946d500ca9
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 d175250d4768dc048bfab6b925a8dc74f5204508

IOC database

Type
hash_sha1
Value
d175250d4768dc048bfab6b925a8dc74f5204508
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 dd1c28bdf8a74627799cdd4650c85b55

IOC database

Type
hash_md5
Value
dd1c28bdf8a74627799cdd4650c85b55
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1131618 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:34.

Remediations (10)

  • web:askubuntu.com

    Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.

  • web:blog.cloudlinux.com

    CVE-2026-31431 (Copy Fail) is a Linux kernel privilege escalation. Apply the grubby mitigation now while patched kernels and KernelCare livepatches are prepared.

  • web:blog.toolslib.net

    CVE-2026-31431 ("Copy Fail") is a critical Linux kernel flaw allowing privilege escalation and container escape. Discover impact, risk, and how to patch or mitigate it quickly.

  • web:forums.rockylinux.org

    Situation: A vulnerability was recently discovered in the Linux Kernel named "Dirty Frag", which allows for Local Privilege Escalation (LPE) to the root user. "Dirty Frag" is a similar exploit to the recent "Copy/Fail" (CVE-2026-31431) vulnerability disclosed recently and is a continuation of a previous vulnerability named "Dirty Pipe" (CVE-2022-0847). This vulnerability is ...

  • web:github.com

    CVE-2026-31431 Mitigation Script This repository provides a temporary mitigation and revert script for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability.

  • web:learn.microsoft.com

    Exploit protection provides advanced protections for applications that enterprise admins and IT pros can apply after a developer compiles and distributes software. This article helps you understand how exploit protection works, both at the policy level and at the individual mitigation level, to help you successfully build and apply exploit protection policies.

  • web:learn.microsoft.com

    Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.

  • web:support.microsoft.com

    Updates for Windows released on April 9, 2024, and later updates, add the following: Three new mitigation controls that replace the mitigations released in 2023. The new mitigations controls are: A control to deploy the "Windows UEFI CA 2023" certificate to the Secure Boot DB to add trust for Windows boot managers signed by this certificate.

  • web:www.joesandbox.com

    General Information Joe Sandbox version: 45.0.0 Green Opal Analysis ID: 1977289 Start date and time: 2026-09-24 09:13:34 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 4m 19s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...

  • web:www.microsoft.com

    On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet. Although the malicious versions are no longer available for download, since Axios is one of the most widely ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.