MB-1c7ad501640d714c25d5c283704dcb181efe112ef2d6086718ab380a83a9341b
high
📛 Threat Title
Mirai: dlr.m68k
Description
File type: elf. Size: 1248 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:38.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
1c7ad501640d714c25d5c283704dcb181efe112ef2d6086718ab380a83a9341b
1 feed
IOC database
- Type
- hash_sha256
- Value
1c7ad501640d714c25d5c283704dcb181efe112ef2d6086718ab380a83a9341b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
6bf7a4c2d78071882a8b1e7b7e9d8fb8a071f7d3
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6bf7a4c2d78071882a8b1e7b7e9d8fb8a071f7d3
1 feed
IOC database
- Type
- hash_sha1
- Value
6bf7a4c2d78071882a8b1e7b7e9d8fb8a071f7d3- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6bf7a4c2d78071882a8b1e7b7e9d8fb8a071f7d3
hash_md5
e3bf7a927edca8f33334a0e9cc700a8c
1 feed
IOC database
- Type
- hash_md5
- Value
e3bf7a927edca8f33334a0e9cc700a8c- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 1248 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:38.
Remediations (10)
-
web:arxiv.org
Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.
-
web:deepwiki.com
Cross-Architecture Support Relevant source files Purpose and Scope This document details how the Mirai botnet's downloader component (dlr) provides support for multiple CPU architectures, enabling the malware to infect a wide variety of IoT device types. This cross-architecture capability is a critical feature that allows Mirai to spread across diverse hardware platforms commonly found in IoT ...
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:github.com
Leaked Mirai Source Code for Research/IoC Development Purposes - jgamblin/ Mirai -Source-Code
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:westoahu.hawaii.edu
A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.
-
web:www.hybrid-analysis.com
Submit malware for free analysis with Falcon Sandbox and Hybrid Analysis technology. Hybrid Analysis develops and licenses analysis tools to fight malware.
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Sample has stripped symbol table Tries to connect to HTTP servers, but all servers are down (expired dropper behavior) Uses the "uname" system call to query kernel version information (possible evasion)
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.usenix.org
These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.