s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-ba68dbe66c6f0819300ccdb4f5cc5110591047bbdc01ae165f5b220dbbfc7252 high

📛 Threat Title

Mirai: boatnet.spc

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 88040 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:15:46.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 ba68dbe66c6f0819300ccdb4f5cc5110591047bbdc01ae165f5b220dbbfc7252

IOC database

Type
hash_sha256
Value
ba68dbe66c6f0819300ccdb4f5cc5110591047bbdc01ae165f5b220dbbfc7252
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 ce3bd8d104835d544ba879274067078a25ca9b76

IOC database

Type
hash_sha1
Value
ce3bd8d104835d544ba879274067078a25ca9b76
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 45e1e5d1575de1b6dc701113c3978db6

IOC database

Type
hash_md5
Value
45e1e5d1575de1b6dc701113c3978db6
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 88040 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:15:46.

Remediations (10)

  • web:arxiv.org

    Angela Famera, Ben Hilger, Suman Bhunia, Patrick Heil Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several vari-ants that combined the old code ...

  • web:github.com

    IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.

  • web:github.com

    Contribute to bfeeney6/ Mirai -Botnet- Mitigation - development by creating an account on GitHub.

  • web:socprime.com

    Explore the Mirai Botnet Digest: in-depth threat overview, analytics, and actionable remediation insights to detect and defend against Mirai -based IoT attacks.

  • web:tria.ge

    Check this mirai report boatnet[.]spc , with a score of 10 out of 10.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.joesandbox.com

    Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai boatnet.spc.elf started xfce4-panel wrapper-2.0 started

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices.

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.techtimes.com

    Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.