MB-b6469a522cd971eb693ba58772970a62fa6f0fe328d22c49c760e0946d500ca9
high
📛 Threat Title
Unknown: atjozltp.x86_64
Description
File type: elf. Size: 1131618 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:34.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
b6469a522cd971eb693ba58772970a62fa6f0fe328d22c49c760e0946d500ca9
IOC database
- Type
- hash_sha256
- Value
b6469a522cd971eb693ba58772970a62fa6f0fe328d22c49c760e0946d500ca9- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
d175250d4768dc048bfab6b925a8dc74f5204508
IOC database
- Type
- hash_sha1
- Value
d175250d4768dc048bfab6b925a8dc74f5204508- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
dd1c28bdf8a74627799cdd4650c85b55
IOC database
- Type
- hash_md5
- Value
dd1c28bdf8a74627799cdd4650c85b55- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 1131618 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-09-25 00:12:34.
Remediations (10)
-
web:askubuntu.com
Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.
-
web:blog.cloudlinux.com
CVE-2026-31431 (Copy Fail) is a Linux kernel privilege escalation. Apply the grubby mitigation now while patched kernels and KernelCare livepatches are prepared.
-
web:blog.toolslib.net
CVE-2026-31431 ("Copy Fail") is a critical Linux kernel flaw allowing privilege escalation and container escape. Discover impact, risk, and how to patch or mitigate it quickly.
-
web:forums.rockylinux.org
Situation: A vulnerability was recently discovered in the Linux Kernel named "Dirty Frag", which allows for Local Privilege Escalation (LPE) to the root user. "Dirty Frag" is a similar exploit to the recent "Copy/Fail" (CVE-2026-31431) vulnerability disclosed recently and is a continuation of a previous vulnerability named "Dirty Pipe" (CVE-2022-0847). This vulnerability is ...
-
web:github.com
CVE-2026-31431 Mitigation Script This repository provides a temporary mitigation and revert script for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability.
-
web:learn.microsoft.com
Exploit protection provides advanced protections for applications that enterprise admins and IT pros can apply after a developer compiles and distributes software. This article helps you understand how exploit protection works, both at the policy level and at the individual mitigation level, to help you successfully build and apply exploit protection policies.
-
web:learn.microsoft.com
Learn how to deal with unwanted mitigations in Windows Security, including a process to remove all mitigations and import a baseline configuration file instead.
-
web:support.microsoft.com
Updates for Windows released on April 9, 2024, and later updates, add the following: Three new mitigation controls that replace the mitigations released in 2023. The new mitigations controls are: A control to deploy the "Windows UEFI CA 2023" certificate to the Secure Boot DB to add trust for Windows boot managers signed by this certificate.
-
web:www.joesandbox.com
General Information Joe Sandbox version: 45.0.0 Green Opal Analysis ID: 1977289 Start date and time: 2026-09-24 09:13:34 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 4m 19s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...
-
web:www.microsoft.com
On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet. Although the malicious versions are no longer available for download, since Axios is one of the most widely ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.