s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-b038d9b928a355c583d0c64f5f32990e557a40117d9fa7b9c231022f540f40be high

📛 Threat Title

Mirai: data_arm5

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 121668 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:54:33.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 b038d9b928a355c583d0c64f5f32990e557a40117d9fa7b9c231022f540f40be

IOC database

Type
hash_sha256
Value
b038d9b928a355c583d0c64f5f32990e557a40117d9fa7b9c231022f540f40be
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 ca5fef9a891acf04dddfb9680ca652ae

IOC database

Type
hash_md5
Value
ca5fef9a891acf04dddfb9680ca652ae
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 dd00c1e11fd2dc34a78cff078e34639892bdf239

IOC database

Type
hash_sha1
Value
dd00c1e11fd2dc34a78cff078e34639892bdf239
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 121668 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:54:33.

Remediations (10)

  • web:github.com

    This repository contains a comprehensive malware analysis report focusing on the Mirai IoT botnet. The project details the setup of a secure malware analysis laboratory and presents a research-based analysis of the Mirai malware. It covers the critical aspects of establishing an isolated analysis environment, the selection of appropriate tools, and a thorough investigation of Mirai's ...

  • web:github.com

    This dataset is captured from a Mirai type botnet attack on an emulated IoT network in OpenStack. - kaysudheera/NSS_Mirai_Dataset

  • web:mirai.r-lib.org

    Core Concepts mirai = future in Japanese. Async evaluation framework for R built on NNG/nanonext. Hub architecture: host listens at a URL, daemons connect to it, enabling dynamic scaling. This is a cheatsheet. Refer to the mirai reference manual for a detailed introduction.

  • web:tria.ge

    Check this mirai report arm5, with a score of 10 out of 10.

  • web:tria.ge

    Check this mirai report debug[.]arm5, with a score of 10 out of 10.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.joesandbox.com

    Classification label: mal80.troj.linELF@0/0@3/ Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/ mirai .arm5n.elf (PID: 5526) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings found ...

  • web:www.joesandbox.com

    Executes the "grep" command used to find patterns in files or piped streams

  • web:www.pwndefend.com

    Observed in-the-wild chain: CVE-2026-34908 (access-control/traversal bypass to the localhost updater) → CVE-2026-34910 (command injection via pkg_name) → Mirai loader (zok) drop. So they use part of a CVE and part of another CVE to achieve the outcome, but I'd suggest that they could have just used either CVE if they had full knowledge.

  • web:www.techtimes.com

    Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.