s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-b4e371b97e0e7d1e914861c27011cc04eacf7fd007d7ddc40138d5b2f83275c6 high

📛 Threat Title

Mirai: dlr.mips

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 2000 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:41.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain dlr.mips VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dlr.mips

IOC database

Type
domain
Value
dlr.mips
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-b4e371b97e0e7d1e914861c27011cc04eacf7fd007d7ddc40138d5b2f83275c6

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dlr.mips

hash_sha256 b4e371b97e0e7d1e914861c27011cc04eacf7fd007d7ddc40138d5b2f83275c6 1 feed

IOC database

Type
hash_sha256
Value
b4e371b97e0e7d1e914861c27011cc04eacf7fd007d7ddc40138d5b2f83275c6
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 617b469f553cbaeb01ce0b245a36456f2698e23e 1 feed

IOC database

Type
hash_sha1
Value
617b469f553cbaeb01ce0b245a36456f2698e23e
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 40fa9938f9c1947e7e3080d49ed4bef0 1 feed

IOC database

Type
hash_md5
Value
40fa9938f9c1947e7e3080d49ed4bef0
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 2000 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:41.

Remediations (10)

  • web:arxiv.org

    Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.

  • web:deepwiki.com

    Cross-Architecture Support Relevant source files Purpose and Scope This document details how the Mirai botnet's downloader component (dlr) provides support for multiple CPU architectures, enabling the malware to infect a wide variety of IoT device types. This cross-architecture capability is a critical feature that allows Mirai to spread across diverse hardware platforms commonly found in IoT ...

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:github.com

    Leaked Mirai Source Code for Research/IoC Development Purposes - jgamblin/ Mirai -Source-Code

  • web:malwareanalysisspace.blogspot.com

    Friday, January 31, 2025 Mirai botnet among different instruction sets: x86, ARM, PPC, and MIPS with static analysis Summary

  • web:trainsec.net

    In this particular case, I found an ARM-compiled Mirai botnet sample. The anti-virus checks labeled it as " Mirai ," matching what I found in the documentation, sandbox analyses, and community threat intelligence sources. Mirai is known to compile variants for multiple architectures (ARM, MIPS, x86, x64, etc.), making it adaptable and widespread.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.joesandbox.com

    Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Sample deletes itself Detected TCP or UDP traffic on non-standard ports Executes the "systemctl" command used for controlling the systemd system and service manager HTTP GET or POST without a user agent Reads system version ...

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.usenix.org

    These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.