MB-d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a
high
📛 Threat Title
Unknown: armv5l
Description
File type: elf. Size: 7405752 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-15 11:41:17.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a
1 feed
IOC database
- Type
- hash_sha256
- Value
d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Unknown
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
cd5920db463c61b7483459cae02c099ac57b2109
1 feed
IOC database
- Type
- hash_sha1
- Value
cd5920db463c61b7483459cae02c099ac57b2109- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
fa570e5d4f89e5e667c0818d6d897e5c
VT 32 / 75
1 feed
IOC database
- Type
- hash_md5
- Value
fa570e5d4f89e5e667c0818d6d897e5c- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 32 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Agent.JJ |
| ALYac | malicious | Trojan.Generic.39957984 |
| Antiy-AVL | malicious | Trojan[DDoS]/Linux.Agent |
| Arcabit | malicious | Trojan.Generic.D261B5E0 |
| Avast | malicious | ELF:DDOSAgent-FN [Rtk] |
| AVG | malicious | ELF:DDOSAgent-FN [Rtk] |
| BitDefender | malicious | Trojan.Generic.39957984 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056451-0 |
| CTX | malicious | elf.trojan.generic |
| DrWeb | malicious | Linux.DDoS.2726 |
| Emsisoft | malicious | Trojan.Generic.39957984 (B) |
| ESET-NOD32 | malicious | Linux/DDoS.Agent.JH trojan |
| Fortinet | malicious | Linux/DDoS_Agent.JH!tr |
| GData | malicious | Trojan.Generic.39957984 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.DDos.bv |
| Ikarus | malicious | Trojan.Linux.DDoS |
| Kaspersky | malicious | HEUR:Trojan-DDoS.Linux.Agent.av |
| Kingsoft | malicious | Linux.Trojan-DDoS.Agent.av |
| Lionic | malicious | Trojan.Linux.DDoS.9!c |
| McAfeeD | malicious | Trojan:Script/GenericY.FA |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Trojan.Generic.39957984 |
| Rising | malicious | Trojan.DDoS/Linux!8.1337A (TFE:28:aRpEK7Ig6jR) |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Malware.Linux.Generic.1c0807e5 |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLEB26 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLEB26 |
| Varist | malicious | E32/ABTrojan.BWKT- |
| VIPRE | malicious | Trojan.Generic.39957984 |
Details From VirusTotal
Basic Properties
| MD5 | fa570e5d4f89e5e667c0818d6d897e5c |
| SHA-1 | cd5920db463c61b7483459cae02c099ac57b2109 |
| SHA-256 | d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a |
| VHash | 218621da7e1a5374644f320da7fd8c3f |
| SSDEEP | 49152:avQ3F8K4V6I9k6QE3Qd9hjxw513d0+q04BGvSyP4GFsbmyWkduG5Ev+:Qb6I9klEgd9hjxw51D4GFsKVcE2 |
| TLSH | T1A5762A97B8924952C4E43637BCBE81C432630EBA9BC7165B6D05EE383EBE1D90E35744 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, BuildID[sha1]=9c5de473af1d07568c002e601a02ca2e361cd7c1, stripped |
| File size | 7.1 MB |
History
| First seen on VirusTotal | 2026-05-11 16:37 UTC |
| Last submission | 2026-05-15 12:01 UTC |
| Last analysis | 2026-05-29 02:24 UTC |
| Last modified on VirusTotal | 2026-05-29 04:30 UTC |
Known Names
armv5ld840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a.elfqy62v.exe45.202.247.123_sample.binqbwk0hjewcmz9qk2yyj.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 7405752 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-15 11:41:17.
Remediations (10)
-
web:community.ibm.com
Allocate resources and budget for vulnerability management and mitigation initiatives, prioritizing high-risk areas Foster an ongoing culture of security awareness, proactiveness and continuous improvement within the organization in regards to fixing vulnerabilities.
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:microsoft.github.io
This capability supports the "Assume Breach" principle of Zero Trust by ensuring continuous detection and mitigation of weaknesses. Reference Remediate machine vulnerability findings - Microsoft Defender for Cloud Vulnerability scanning in Defender for Servers Remediate vulnerabilities with Microsoft Defender Vulnerability Management
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:scloud.work
When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]
-
web:windowsforum.com
Microsoft's Security Update Guide is the canonical place to verify which specific Windows builds and KBs include the fix for CVE-2025-53803; the general remediation pattern for kernel information-disclosure CVEs is: vendor advisory → cumulative update or security-only KB → distribution via Windows Update/WSUS and the Microsoft Update Catalog.
-
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.How to use the KEV ...
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.rapid7.com
Vulnerability management programs look different depending on the available resources and specific risks your organization faces. While both identifying and evaluating possible threats are important steps, the most time-consuming step is actually treating the vulnerability. Here's where remediation and mitigation come into play. Both are different approaches to dealing with a vulnerability ...
-
web:www.sentinelone.com
Learn best practices and essential tools for effective vulnerability remediation tracking to improve your security process and minimize risks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.