s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a high

📛 Threat Title

Unknown: armv5l

Category: Unknown Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 7405752 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-15 11:41:17.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a 1 feed

IOC database

Type
hash_sha256
Value
d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Unknown

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 cd5920db463c61b7483459cae02c099ac57b2109 1 feed

IOC database

Type
hash_sha1
Value
cd5920db463c61b7483459cae02c099ac57b2109
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 fa570e5d4f89e5e667c0818d6d897e5c VT 32 / 75 1 feed

IOC database

Type
hash_md5
Value
fa570e5d4f89e5e667c0818d6d897e5c
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 32 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Agent.JJ
ALYac malicious Trojan.Generic.39957984
Antiy-AVL malicious Trojan[DDoS]/Linux.Agent
Arcabit malicious Trojan.Generic.D261B5E0
Avast malicious ELF:DDOSAgent-FN [Rtk]
AVG malicious ELF:DDOSAgent-FN [Rtk]
BitDefender malicious Trojan.Generic.39957984
ClamAV malicious Unix.Trojan.Mirai-10056451-0
CTX malicious elf.trojan.generic
DrWeb malicious Linux.DDoS.2726
Emsisoft malicious Trojan.Generic.39957984 (B)
ESET-NOD32 malicious Linux/DDoS.Agent.JH trojan
Fortinet malicious Linux/DDoS_Agent.JH!tr
GData malicious Trojan.Generic.39957984
Google malicious Detected
huorong malicious Trojan/Linux.DDos.bv
Ikarus malicious Trojan.Linux.DDoS
Kaspersky malicious HEUR:Trojan-DDoS.Linux.Agent.av
Kingsoft malicious Linux.Trojan-DDoS.Agent.av
Lionic malicious Trojan.Linux.DDoS.9!c
McAfeeD malicious Trojan:Script/GenericY.FA
Microsoft malicious Trojan:Linux/Multiverze!rfn
MicroWorld-eScan malicious Trojan.Generic.39957984
Rising malicious Trojan.DDoS/Linux!8.1337A (TFE:28:aRpEK7Ig6jR)
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Trojan.Gen.NPE
Tencent malicious Malware.Linux.Generic.1c0807e5
TrendMicro malicious Trojan.Win32.ZYX.USBLEB26
TrendMicro-HouseCall malicious Trojan.Win32.ZYX.USBLEB26
Varist malicious E32/ABTrojan.BWKT-
VIPRE malicious Trojan.Generic.39957984

Details From VirusTotal

Basic Properties
MD5fa570e5d4f89e5e667c0818d6d897e5c
SHA-1cd5920db463c61b7483459cae02c099ac57b2109
SHA-256d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a
VHash218621da7e1a5374644f320da7fd8c3f
SSDEEP49152:avQ3F8K4V6I9k6QE3Qd9hjxw513d0+q04BGvSyP4GFsbmyWkduG5Ev+:Qb6I9klEgd9hjxw51D4GFsKVcE2
TLSHT1A5762A97B8924952C4E43637BCBE81C432630EBA9BC7165B6D05EE383EBE1D90E35744
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, ARM, EABI5 version 1 (SYSV), statically linked, BuildID[sha1]=9c5de473af1d07568c002e601a02ca2e361cd7c1, stripped
File size7.1 MB
History
First seen on VirusTotal2026-05-11 16:37 UTC
Last submission2026-05-15 12:01 UTC
Last analysis2026-05-29 02:24 UTC
Last modified on VirusTotal2026-05-29 04:30 UTC
Known Names
  • armv5l
  • d840e0277d804fa0dfead89bf2b35ce77642f8b65985f5bc1516d0aafbd1328a.elf
  • qy62v.exe
  • 45.202.247.123_sample.bin
  • qbwk0h
  • jewcmz
  • 9qk2yyj.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 7405752 bytes. Tags: elf. Reporter: abuse_ch. First seen: 2026-05-15 11:41:17.

Remediations (10)

  • web:community.ibm.com

    Allocate resources and budget for vulnerability management and mitigation initiatives, prioritizing high-risk areas Foster an ongoing culture of security awareness, proactiveness and continuous improvement within the organization in regards to fixing vulnerabilities.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:microsoft.github.io

    This capability supports the "Assume Breach" principle of Zero Trust by ensuring continuous detection and mitigation of weaknesses. Reference Remediate machine vulnerability findings - Microsoft Defender for Cloud Vulnerability scanning in Defender for Servers Remediate vulnerabilities with Microsoft Defender Vulnerability Management

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:scloud.work

    When a proactive remediation script fails to work as expected, it's much faster to test it locally than wait for the next sync from Intune. In this post, I'll show you how I troubleshoot Intune remediation scripts directly on a Windows device. This includes script locations, relevant logs, and registry entries that help verify what […]

  • web:windowsforum.com

    Microsoft's Security Update Guide is the canonical place to verify which specific Windows builds and KBs include the fix for CVE-2025-53803; the general remediation pattern for kernel information-disclosure CVEs is: vendor advisory → cumulative update or security-only KB → distribution via Windows Update/WSUS and the Microsoft Update Catalog.

  • web:www.cisa.gov

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.How to use the KEV ...

  • web:www.esd.whs.mil

    Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.

  • web:www.rapid7.com

    Vulnerability management programs look different depending on the available resources and specific risks your organization faces. While both identifying and evaluating possible threats are important steps, the most time-consuming step is actually treating the vulnerability. Here's where remediation and mitigation come into play. Both are different approaches to dealing with a vulnerability ...

  • web:www.sentinelone.com

    Learn best practices and essential tools for effective vulnerability remediation tracking to improve your security process and minimize risks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.