s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.mirai

📛 Threat Title

Malware family: Mirai

Category: Mirai First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.mirai`. Printable name: Mirai. Aliases: Katana.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.mirai VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.mirai

IOC database

Type
domain
Value
elf.mirai
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.mirai

References (1)

Remediations (10)

  • web:academic.oup.com

    We briefly discuss Mirai and then describe the notification mechanisms of the ISP, as well as the remediation steps that the users are asked to perform. Mirai malware . Mirai emerged in 2016 and became the malware family that demonstrated the threat posed by insecure IoT [6].

  • web:arxiv.org

    Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:malpedia.caad.fkie.fraunhofer.de

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the ...

  • web:media.defense.gov

    A functioning botnet can be used for a variety of purposes, including malware delivery, distributed denial of service (DDoS) attacks, or routing nefarious Internet traffic. The botnet uses the Mirai family of malware , designed to hijack IoT devices such as webcams, DVRs, IP cameras, and routers running Linux-based operating systems.

  • web:www.akamai.com

    The botnet has been engaged in a long-running campaign that Akamai SIRT has been monitoring since late 2022 on our custom-built honeypots. It leverages the popular malware family Mirai . The payload targets routers and network video recorder (NVR) devices with default admin credentials and installs Mirai variants when successful.

  • web:www.cisecurity.org

    IoT devices built for convenience over security complicate mitigation efforts for the Mirai malware family . Mirai Technical Details Mirai starts as a self-propagating worm (T0866 [5]) replicating itself once it infects and locates another vulnerable IoT device [3].

  • web:www.quorumcyber.com

    Mirai Botnet Overview Mirai is a botnet malware variant that compromises smart devices that operate on ARC processors, the aim of which is to formulate a network of bot machines to carry out distributed denial-of-service (DDoS) attacks1. Mirai scans the internet for Internet of Things (IoT) devices that operate on the ARC processor.

  • web:www.semanticscholar.org

    This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.