s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42 high

📛 Threat Title

Unknown: bot.aarch64

Category: Unknown First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 82928 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-13 20:53:26.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42 VT 32 / 75 1 feed

IOC database

Type
hash_sha256
Value
56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 32 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Backdoor:Linux/Gafgyt_AGen.IL
Arcabit malicious Trojan.Generic.D261BD89
Avast malicious Other:Malware-gen [Trj]
AVG malicious Other:Malware-gen [Trj]
Avira malicious TR/Malware
BitDefender malicious Trojan.Generic.39959945
CTX malicious elf.trojan.gafgyt
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.DDoS.2637
Emsisoft malicious Trojan.Generic.39959945 (B)
ESET-NOD32 malicious Linux/Gafgyt.BSP trojan
F-Secure malicious Trojan.TR/Malware
Fortinet malicious Linux/Gafgyt_AGen.II!tr
GData malicious Trojan.Generic.39959945
Google malicious Detected
huorong malicious Trojan/Linux.Mirai.l!crit
Ikarus malicious Trojan.Linux.Gafgyt
Kaspersky malicious HEUR:Backdoor.Linux.Gafgyt.bj
Kingsoft malicious Linux.Backdoor.Gafgyt.bj
Lionic malicious Trojan.Linux.Gafgyt.4!c
McAfeeD malicious ti!56DFFC636AA0
Microsoft malicious Backdoor:Linux/Mirai!MSR
MicroWorld-eScan malicious Trojan.Generic.39959945
Rising malicious Malware.Undefined!8.C (TFE:14:dXqhJLc5KjI)
Sangfor malicious Trojan.Linux.Mirai.Vz4k
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
TrendMicro malicious Trojan.Linux.GAFGYT.TL0101EF26ZZ
TrendMicro-HouseCall malicious Trojan.Linux.GAFGYT.TL0101EF26ZZ
Varist malicious E64/ABBackdoor.APME-
VIPRE malicious Trojan.Generic.39959945

Details From VirusTotal

Basic Properties
MD5415bb341906ae36f16d842466c001f4b
SHA-11535deacd449d016fdb39ded8b21a90342350f71
SHA-25656dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42
VHashfa8717567470e1eaeba7511765fe150f
SSDEEP1536:5I0rNXsKxIgE9wDBmT8i1Jt7ZZ8OAIbxbm8/V1Wf1+gv/rmbpx69:ycxsKlBrA7P8Ol0nrm
TLSHT141838D808C1DFCB3CBC6B47D4D480E50326B7CF42678D74A0A25668EDC49A586FE5BA7
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, ARM aarch64, version 1 (SYSV), statically linked, stripped
File size81.0 KB
History
First seen on VirusTotal2026-05-13 19:24 UTC
Last submission2026-05-13 19:24 UTC
Last analysis2026-05-15 16:27 UTC
Last modified on VirusTotal2026-05-15 18:36 UTC
Known Names
  • 56dffc636aa06a4a6c000f8cc1692b5294f35fb890be81461e5ddcfd678e0b42.elf
  • bot.aarch64
  • wsfo0b.exe
hash_sha1 1535deacd449d016fdb39ded8b21a90342350f71 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1535deacd449d016fdb39ded8b21a90342350f71
2 feeds

IOC database

Type
hash_sha1
Value
1535deacd449d016fdb39ded8b21a90342350f71
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/1535deacd449d016fdb39ded8b21a90342350f71

hash_md5 415bb341906ae36f16d842466c001f4b VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/415bb341906ae36f16d842466c001f4b
2 feeds

IOC database

Type
hash_md5
Value
415bb341906ae36f16d842466c001f4b
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/415bb341906ae36f16d842466c001f4b

References (3)

Remediations (8)

  • web:askubuntu.com

    We are running a bunch of containers for a cyber security teaching environment, where students can execute arbitrary commands (unprivileged). Our system (Ubuntu 24.04.4 LTS) is affected by the recently-published "Copy Fail" vulnerability (CVE-2026-31431). Unfortunately, updating did not produce any new kernel packages, and we are still stuck with 6.8.0-110: # uname -a Linux teaching-host 6.8.0 ...

  • web:blog.mindcore.dk

    Step‑by‑step guide to automating the Windows Secure Boot certificate update using Microsoft Intune remediations , including fallback logic, telemetry requirements, and real‑world results.

  • web:github.com

    We just need to turn them on :) Edit: 23.06 uses aarch64-linux-gnu-gcc version 7.5 as the linker driver, and that version of GCC has been shown to turn the mitigation on. The issue will be changing the target to use rust-lld directly, which will mean we need to turn the mitigation on ourselves.

  • web:support.microsoft.com

    The detection script collects Secure Boot and certificate status from each device and reports it back to the Intune portal — no remediation action is taken on devices. This gives administrators a centralized, exportable view of certificate update progress across their Intune enrolled Windows devices. Why use this approach?

  • web:www.joesandbox.com

    General Information Sample name: re.bot.aarch64.elf Analysis ID: 1635835 MD5: c8935764b59ccf61503e48d0c0087277 SHA1: 9d336276e9d45889167f698261e8d600ebf5b92a SHA256 ...

  • web:www.joesandbox.com

    Executes the "iptables" command used for managing IP filtering and manipulation

  • web:www.tbone.se

    Blog post has a new update here Update Secure Boot Certificate by using Intune Remediation - Take 2 - Mr T-Bone´s Blog If you manage Windows devices, there's a "quiet" platform change you really don't want to meet at the last minute. The Microsoft Secure Boot certificates that have been broadly embedded in PC firmware since the Windows 8 are now reaching the end of their lifetime ...

  • web:www.tbone.se

    I have had some time to test my scripts and method described in the old blog Update Secure Boot Certificate by using Intune Remediation And found a lot of small issues with my previous scripts.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.