s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-58602c7eac4ff6033cdc9303b709d010770d15ec771870ae32009a42a85ef7de high

📛 Threat Title

Unknown: iran.x86_64

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 135048 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-06-13 15:09:45.

Remediations (10)

  • web:askubuntu.com

    9 Update: Kernel 6.8.-117.117 is released now and features a kernel-level fix for CVE-2026-31431. While the website may be down, the security email list continues to work apparently and they have emailed about a mitigation there in an email from 30.04.2026 18:06 CET. The issue should be mitigated for now thanks to USN-8226-1 and USN-8226-2.

  • web:blog.cloudlinux.com

    Dirty Frag is a Linux kernel local privilege escalation in the xfrm subsystem. Apply the mitigation now while patched kernels and KernelCare livepatches are prepared.

  • web:blog.toolslib.net

    CVE-2026-31431 ("Copy Fail") is a critical Linux kernel flaw allowing privilege escalation and container escape. Discover impact, risk, and how to patch or mitigate it quickly.

  • web:radar.offseq.com

    This Red Hat security advisory (RHSA-2026:22934) covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, specifically updating multiple Rust-related packages to version 1.96.0-1.hum1 across several architectures (aarch64, x86_64, noarch).

  • web:ubuntu.com

    Ubuntu is an open source software operating system that runs from the desktop, to the cloud, to all your internet connected things.

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Sample deletes itself Detected TCP or UDP traffic on non-standard ports Enumerates processes within the "proc" file system Executes the "rm" command used to delete files or directories Sample has stripped symbol table Yara signature ...

  • web:www.joesandbox.com

    Signatures Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Sample deletes itself Sample is packed with UPX Detected TCP or UDP traffic on non-standard ports ELF contains segments with high entropy indicating compressed/encrypted content Enumerates processes within the "proc" file system Sample contains only a LOAD segment without any ...

  • web:www.kodemsecurity.com

    CVE-2026-31431, the Copy Fail Linux kernel LPE, lets authenticated users gain root. See affected kernels, exploit details, IOCs and patches.

  • web:www.redhat.com

    Learn about CVE-2026-31431, a Linux kernel issue affecting Red Hat OpenShift containers. Discover how Red Hat Advanced Cluster Security can help detect and respond to this exploit, and find out about remediation steps.

  • web:www.spinics.net

    Command line options which force-enable a mitigation on an unaffected processor provide arguably no security value but do create the potential for problems due to the increased set of mitigation interactions.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 58602c7eac4ff6033cdc9303b709d010770d15ec771870ae32009a42a85ef7de

IOC database

Type
hash_sha256
Value
58602c7eac4ff6033cdc9303b709d010770d15ec771870ae32009a42a85ef7de
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 318509737365171fc976b9e04d0ea9f375b3f4b2

IOC database

Type
hash_sha1
Value
318509737365171fc976b9e04d0ea9f375b3f4b2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 9a345b743ae8981876eb017bd1a2fefc

IOC database

Type
hash_md5
Value
9a345b743ae8981876eb017bd1a2fefc
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 135048 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-06-13 15:09:45.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.