s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-elf.owari

📛 Threat Title

Malware family: Owari

Category: Owari First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.owari`. Printable name: Owari.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.owari VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.owari

IOC database

Type
domain
Value
elf.owari
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.owari

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.owari

References (1)

Remediations (10)

  • web:any.run

    Online sandbox report for owari .x86, verdict: Malicious activity

  • web:bazaar.abuse.ch

    Malware samples associated with tag owari MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with owari . Database Entry

  • web:cybernews.com

    The FBI warns of a surge in ATM jackpotting attacks, with more than 700 incidents in 2025 alone. Hackers use Ploutus malware to force machines to dispense cash.

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks. It primarily targets online consumer devices such as IP cameras and home routers. [1] The Mirai botnet was first found in August 2016 [2] by MalwareMustDie, [3] a white hat malware research ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Mirai variant by actor "Anarchy" that used CVE-2017-17215 in July 2018 to compromise 18,000+ devices.

  • web:www.breachsense.com

    Complete malware remediation now requires addressing both the infected endpoint and the stolen authentication data. Your malware incident response playbook must account for both.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.joesandbox.com

    Automated Malware Analysis - Joe Sandbox Analysis Report Overview Overview General Information Process Tree Malware Configuration Behavior Graph Antivirus and ML Detection Joe Sandbox View / Context Signatures Signatures Yara Suricata Joe Sandbox Mitre Att&ck Matrix Process Tree Dropped Domains / IPs Network Network UDP Packets DNS Queries DNS Answers Static Behavior Behavior owari .arm5.elf ...

  • web:www.notebookcheck.net

    The FBI issued an IC3 FLASH advisory warning of increased malware -enabled ATM jackpotting in the U.S., naming Ploutus malware , sharing IOCs, and outlining mitigation steps.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.