s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-4171d455c5d92e5bce98bfb0b8aa138b05015add1bc1744bf5d54b94308940aa high

📛 Threat Title

Unknown: bot.armv4l

Category: Unknown First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 82356 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-13 19:33:35.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 4171d455c5d92e5bce98bfb0b8aa138b05015add1bc1744bf5d54b94308940aa VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/4171d455c5d92e5bce98bfb0b8aa138b05015add1bc1744bf5d54b94308940aa
1 feed

IOC database

Type
hash_sha256
Value
4171d455c5d92e5bce98bfb0b8aa138b05015add1bc1744bf5d54b94308940aa
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/4171d455c5d92e5bce98bfb0b8aa138b05015add1bc1744bf5d54b94308940aa

hash_sha1 937fb705954494e0add9cabe63da130567448ae5 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/937fb705954494e0add9cabe63da130567448ae5
2 feeds

IOC database

Type
hash_sha1
Value
937fb705954494e0add9cabe63da130567448ae5
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/937fb705954494e0add9cabe63da130567448ae5

hash_md5 8cb289a7113ad22f6087eb2558b038a5 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8cb289a7113ad22f6087eb2558b038a5
2 feeds

IOC database

Type
hash_md5
Value
8cb289a7113ad22f6087eb2558b038a5
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/8cb289a7113ad22f6087eb2558b038a5

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 82356 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-13 19:33:35.

Remediations (10)

  • web:github.com

    About 嵌入式 GCC 交叉编译镜像,当前大部分编译器是基于 uclibc的。产品已经上传至 docker-hub ,可自行参考 README 的相关描述使用。

  • web:my.f5.com

    A Bot Defense profile is attached to the virtual server AdvWAF Bot Defense, Support ID Cause Mitigations are needed to provide a way to workaround an issue. Sometimes it is a false/positive, and sometimes it may be something with the traffic that is not right but it needs to be allowed so a " mitigation " is provided.

  • web:support.microsoft.com

    The detection script collects Secure Boot and certificate status from each device and reports it back to the Intune portal — no remediation action is taken on devices. This gives administrators a centralized, exportable view of certificate update progress across their Intune enrolled Windows devices. Why use this approach?

  • web:tria.ge

    Check this report bot[.]armv4l , with a score of 1 out of 10.

  • web:virsec.com

    Mitigation , on the other hand, provides critical protection, acting as a vital defense against known and unknown threats until the advent of that final fix (if it ever comes). So, use them both. Don't make yourself a hostage to patching and slow remediation cycles. Reduce exposure with immediate and automated mitigation .

  • web:www.cisa.gov

    Best Practice Mitigation Recommendations Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (i.e., hard drive, storage device, the cloud) [CPG 2.O, 2.R, 5.A].

  • web:www.joesandbox.com

    Persistence and Installation Behavior Source: /tmp/bot.armv4l.elf (PID: 5555) Shell command executed: sh -c "uname -m" Jump to behavior

  • web:www.majorgeeks.com

    Windows Defender may try to remove a virus, trojan, or other malware and return a message stating Remediation incomplete. Remediation incomplete leads one to assume that a virus, trojan or malware was found, but not removed.

  • web:www.sentinelone.com

    Learn best practices and essential tools for effective vulnerability remediation tracking to improve your security process and minimize risks.

  • web:www.tbone.se

    Blog post has a new update here Update Secure Boot Certificate by using Intune Remediation - Take 2 - Mr T-Bone´s Blog If you manage Windows devices, there's a "quiet" platform change you really don't want to meet at the last minute. The Microsoft Secure Boot certificates that have been broadly embedded in PC firmware since the Windows 8 are now reaching the end of their lifetime ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.