s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3 high

📛 Threat Title

Unknown: bot.armv7l

Category: Unknown First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 80436 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-13 19:33:36.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3
1 feed

IOC database

Type
hash_sha256
Value
c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3

hash_sha1 3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a
2 feeds

IOC database

Type
hash_sha1
Value
3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a

hash_md5 cf1ed17c5295c5c849a265fd05334ccb VT 35 / 75 2 feeds

IOC database

Type
hash_md5
Value
cf1ed17c5295c5c849a265fd05334ccb
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Flagged by 35 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Gafgyt.BBD
ALYac malicious Trojan.Generic.39959985
Antiy-AVL malicious Trojan/Linux.Agent
Arcabit malicious Trojan.Generic.D261BDB1
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Trojan.Generic.39959985
CTX malicious elf.trojan.gafgyt
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.DDoS.2637
Emsisoft malicious Trojan.Generic.39959985 (B)
ESET-NOD32 malicious Linux/Gafgyt.BSP trojan
F-Secure malicious Trojan.TR/Malware
Fortinet malicious Linux/Gafgyt_AGen.II!tr
GData malicious Trojan.Generic.39959985
Google malicious Detected
huorong malicious Trojan/Linux.Mirai.l!crit
Ikarus malicious Trojan.Linux.Gafgyt
Kaspersky malicious HEUR:Backdoor.Linux.Gafgyt.bj
Kingsoft malicious Linux.Backdoor.Gafgyt.bj
Lionic malicious Trojan.Linux.Gafgyt.m!c
McAfeeD malicious ti!C9116F99A073
Microsoft malicious Trojan:Linux/Multiverze!rfn
MicroWorld-eScan malicious Trojan.Generic.39959985
Rising malicious Backdoor.Gafgyt/Linux!8.132A2 (TFE:14:seXa5bPF3cP)
Sangfor malicious Backdoor.Linux.Gafgyt.Vt8f
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
Tencent malicious Linux.Backdoor.Gafgyt.Dzlw
TrendMicro malicious Trojan.Linux.GAFGYT.TL0101EF26ZZ
TrendMicro-HouseCall malicious Trojan.Linux.GAFGYT.TL0101EF26ZZ
Varist malicious E32/ABTrojan.OESB-
VIPRE malicious Trojan.Generic.39959985

Details From VirusTotal

Basic Properties
MD5cf1ed17c5295c5c849a265fd05334ccb
SHA-13bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a
SHA-256c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3
VHashe83ba3b402e0c4db128fc25b7197bf6c
SSDEEP1536:GwRhrNjQGv5g/VtQfSv+vkIpWqW7LuxvFi1wWOS/Z2Qxqb7:pJ5gNKVMi/8utFuw0Rqb7
TLSHT142730991FE81D952C5D939BAFA5F41C8338303ACD3DF72028E019A35A6DF51A4E7AE41
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, stripped
File size78.6 KB
History
First seen on VirusTotal2026-05-13 20:04 UTC
Last submission2026-05-13 20:04 UTC
Last analysis2026-05-16 14:09 UTC
Last modified on VirusTotal2026-05-16 16:12 UTC
Known Names
  • c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3.elf
  • zzj9hm.exe
  • copy
  • bot.armv7l

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 80436 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-13 19:33:36.

Remediations (10)

  • web:any.run

    MALICIOUS MIRAI has been detected (SURICATA)bot.armv7l.elf (PID: 1277) MIRAI has been detected (SURICATA) bot.armv7l.elf (PID: 1277) bot.armv7l.elf (PID: 1277) SUSPICIOUS Modifies file or directory ownersudo (PID: 1263)Executes commands using command-line interpretersudo (PID: 1266)Gets active network interfacessudo (PID: 1266)Reads network configurationsudo (PID: 1266)Connects to unusual ...

  • web:any.run

    Online sandbox report for bot.armv7l , tagged as botnet, mirai, scan, ssh, sshscan, verdict: Malicious activity

  • web:app.any.run

    Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

  • web:blog.mindcore.dk

    Step‑by‑step guide to automating the Windows Secure Boot certificate update using Microsoft Intune remediations , including fallback logic, telemetry requirements, and real‑world results.

  • web:learn.microsoft.com

    In addition, some types of remediation actions can occur automatically, whereas other types of remediation actions are taken manually by your organization's security team. When an automated investigation results in one or more remediation actions, the investigation completes only when the remediation actions are taken, approved, or rejected.

  • web:support.microsoft.com

    The detection script collects Secure Boot and certificate status from each device and reports it back to the Intune portal — no remediation action is taken on devices. This gives administrators a centralized, exportable view of certificate update progress across their Intune enrolled Windows devices. Why use this approach?

  • web:www.joesandbox.com

    You are using Microsoft Internet Explorer. Therefore the report might not work properly. We recommend using Chrome or Firefox for the best experience.

  • web:www.joesandbox.com

    Behavior Graph ID: 1770071 Sample: bot.armv7l.elf Startdate: 03/09/2025 Architecture: LINUX Score: 52 199.245.57.10 ZNETUS United States 50.52.84.5, 23 ZIPLY-FIBER-LEGACY-ASNUS United States 99 other IPs or domains Multi AV Scanner detection for submitted file Connects to many ports of the same IP (likely port scanning) bot.armv7l.elf started ...

  • web:www.joesandbox.com

    Persistence and Installation Behavior Source: /tmp/bot.armv7l.elf (PID: 5839) Shell command executed: sh -c "uname -m" Jump to behavior

  • web:www.tbone.se

    I have had some time to test my scripts and method described in the old blog Update Secure Boot Certificate by using Intune Remediation And found a lot of small issues with my previous scripts.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.