s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-69060d0657a35a5290e59c93e815075ada72fba5e9ada1a42cafbd9b6cb29a4f high

📛 Threat Title

Unknown: iran.powerpc

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 129700 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-06-13 15:09:50.

Remediations (10)

  • web:logisticsviewpoints.com

    Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable logic controllers (PLCs) manufactured by Rockwell Automation/Allen-Bradley.

  • web:media.defense.gov

    Since October 2023, Iranian actors have used brute force, such as password spraying, and multi-factor authentication (MFA) 'push bombing' to compromise user accounts and obtain access to organizations. The actors frequently modified MFA registrations, enabling persistent access. The actors performed discovery on the compromised networks to obtain additional credentials and identify other ...

  • web:radar.offseq.com

    Detailed information about Iran-Linked Hackers Disrupt US Critical Infrastructure via PLC Attacks. Get real-time updates, technical details, and mitigation stra

  • web:redskyalliance.org

    Release Date: 7 April 2026 CISA Alert Code: AA26-097A Title Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Original Publication 7 April 2026 Executive Summary Iran-affiliated advanced persistent threat (APT) actors are conducting exploitation activity targeting internet-facing operational technology (OT) devices, including programmable ...

  • web:unit42.paloaltonetworks.com

    For details on Unit 42's previous observations of cyber activity linked to Iran-backed groups and hacktivists, see the Threat Brief: Escalation of Cyber Risk Related to Iran (Updated June 30).

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.cisa.gov

    Background Information Similar Historical Activity Targeting Programmable Logic Controllers During a similar campaign beginning in November 2023, the IRGC CEC-affiliated cyber threat actors known as "CyberAv3ngers" targeted U.S.-based PLCs and HMIs, causing disruptive effects. Private industry and open sources also refer to this group as Hydro Kitten, Storm-0784, APT Iran, Bauxite, Mr. Soul ...

  • web:www.cisecurity.org

    Security leaders must give equal weight to the cyber dimension following U.S.-Israeli kinetic activity against Iran. Here's our recommendations.

  • web:www.ic3.gov

    Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Publication: April 7, 2026

  • web:www.joesandbox.com

    Executes the "rm" command used to delete files or directories

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 69060d0657a35a5290e59c93e815075ada72fba5e9ada1a42cafbd9b6cb29a4f

IOC database

Type
hash_sha256
Value
69060d0657a35a5290e59c93e815075ada72fba5e9ada1a42cafbd9b6cb29a4f
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 164a66c6f984c85c1f0d466bb6298892abd3e08b

IOC database

Type
hash_sha1
Value
164a66c6f984c85c1f0d466bb6298892abd3e08b
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 db8f5c4744329bb8ec386385698d5a8c

IOC database

Type
hash_md5
Value
db8f5c4744329bb8ec386385698d5a8c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 129700 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-06-13 15:09:50.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.