MB-c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3
high
📛 Threat Title
Unknown: bot.armv7l
Description
File type: elf. Size: 80436 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-13 19:33:36.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3
1 feed
IOC database
- Type
- hash_sha256
- Value
c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3
hash_sha1
3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a
2 feeds
IOC database
- Type
- hash_sha1
- Value
3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a
hash_md5
cf1ed17c5295c5c849a265fd05334ccb
VT 35 / 75
2 feeds
IOC database
- Type
- hash_md5
- Value
cf1ed17c5295c5c849a265fd05334ccb- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Flagged by 35 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Gafgyt.BBD |
| ALYac | malicious | Trojan.Generic.39959985 |
| Antiy-AVL | malicious | Trojan/Linux.Agent |
| Arcabit | malicious | Trojan.Generic.D261BDB1 |
| Avast | malicious | Other:Malware-gen [Trj] |
| AVG | malicious | Other:Malware-gen [Trj] |
| Avira | malicious | TR/Malware |
| BitDefender | malicious | Trojan.Generic.39959985 |
| CTX | malicious | elf.trojan.gafgyt |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.DDoS.2637 |
| Emsisoft | malicious | Trojan.Generic.39959985 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BSP trojan |
| F-Secure | malicious | Trojan.TR/Malware |
| Fortinet | malicious | Linux/Gafgyt_AGen.II!tr |
| GData | malicious | Trojan.Generic.39959985 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Mirai.l!crit |
| Ikarus | malicious | Trojan.Linux.Gafgyt |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Gafgyt.bj |
| Kingsoft | malicious | Linux.Backdoor.Gafgyt.bj |
| Lionic | malicious | Trojan.Linux.Gafgyt.m!c |
| McAfeeD | malicious | ti!C9116F99A073 |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Trojan.Generic.39959985 |
| Rising | malicious | Backdoor.Gafgyt/Linux!8.132A2 (TFE:14:seXa5bPF3cP) |
| Sangfor | malicious | Backdoor.Linux.Gafgyt.Vt8f |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Linux.Backdoor.Gafgyt.Dzlw |
| TrendMicro | malicious | Trojan.Linux.GAFGYT.TL0101EF26ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Linux.GAFGYT.TL0101EF26ZZ |
| Varist | malicious | E32/ABTrojan.OESB- |
| VIPRE | malicious | Trojan.Generic.39959985 |
Details From VirusTotal
Basic Properties
| MD5 | cf1ed17c5295c5c849a265fd05334ccb |
| SHA-1 | 3bb82b93c7ad0c1cbf9a51bdcb1f6162429e649a |
| SHA-256 | c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3 |
| VHash | e83ba3b402e0c4db128fc25b7197bf6c |
| SSDEEP | 1536:GwRhrNjQGv5g/VtQfSv+vkIpWqW7LuxvFi1wWOS/Z2Qxqb7:pJ5gNKVMi/8utFuw0Rqb7 |
| TLSH | T142730991FE81D952C5D939BAFA5F41C8338303ACD3DF72028E019A35A6DF51A4E7AE41 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, stripped |
| File size | 78.6 KB |
History
| First seen on VirusTotal | 2026-05-13 20:04 UTC |
| Last submission | 2026-05-13 20:04 UTC |
| Last analysis | 2026-05-16 14:09 UTC |
| Last modified on VirusTotal | 2026-05-16 16:12 UTC |
Known Names
c9116f99a073f79a68e0239cf6d503f1009a27ca997bb660c72bfe1098021af3.elfzzj9hm.execopybot.armv7l
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 80436 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-13 19:33:36.
Remediations (10)
-
web:any.run
MALICIOUS MIRAI has been detected (SURICATA)bot.armv7l.elf (PID: 1277) MIRAI has been detected (SURICATA) bot.armv7l.elf (PID: 1277) bot.armv7l.elf (PID: 1277) SUSPICIOUS Modifies file or directory ownersudo (PID: 1263)Executes commands using command-line interpretersudo (PID: 1266)Gets active network interfacessudo (PID: 1266)Reads network configurationsudo (PID: 1266)Connects to unusual ...
-
web:any.run
Online sandbox report for bot.armv7l , tagged as botnet, mirai, scan, ssh, sshscan, verdict: Malicious activity
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:blog.mindcore.dk
Step‑by‑step guide to automating the Windows Secure Boot certificate update using Microsoft Intune remediations , including fallback logic, telemetry requirements, and real‑world results.
-
web:learn.microsoft.com
In addition, some types of remediation actions can occur automatically, whereas other types of remediation actions are taken manually by your organization's security team. When an automated investigation results in one or more remediation actions, the investigation completes only when the remediation actions are taken, approved, or rejected.
-
web:support.microsoft.com
The detection script collects Secure Boot and certificate status from each device and reports it back to the Intune portal — no remediation action is taken on devices. This gives administrators a centralized, exportable view of certificate update progress across their Intune enrolled Windows devices. Why use this approach?
-
web:www.joesandbox.com
You are using Microsoft Internet Explorer. Therefore the report might not work properly. We recommend using Chrome or Firefox for the best experience.
-
web:www.joesandbox.com
Behavior Graph ID: 1770071 Sample: bot.armv7l.elf Startdate: 03/09/2025 Architecture: LINUX Score: 52 199.245.57.10 ZNETUS United States 50.52.84.5, 23 ZIPLY-FIBER-LEGACY-ASNUS United States 99 other IPs or domains Multi AV Scanner detection for submitted file Connects to many ports of the same IP (likely port scanning) bot.armv7l.elf started ...
-
web:www.joesandbox.com
Persistence and Installation Behavior Source: /tmp/bot.armv7l.elf (PID: 5839) Shell command executed: sh -c "uname -m" Jump to behavior
-
web:www.tbone.se
I have had some time to test my scripts and method described in the old blog Update Secure Boot Certificate by using Intune Remediation And found a lot of small issues with my previous scripts.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.