MB-1d406685758010d9fa7d36b213f91cc9ff1c4096bfd5a841b7549e8e54ae6d67
high
📛 Threat Title
Mirai: iran.armv5l
Description
File type: elf. Size: 154360 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:09:09.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
1d406685758010d9fa7d36b213f91cc9ff1c4096bfd5a841b7549e8e54ae6d67
IOC database
- Type
- hash_sha256
- Value
1d406685758010d9fa7d36b213f91cc9ff1c4096bfd5a841b7549e8e54ae6d67- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
dd32f5cbc6bf90a6b10c32aec24b1ebd443c54d6
IOC database
- Type
- hash_sha1
- Value
dd32f5cbc6bf90a6b10c32aec24b1ebd443c54d6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
15331e3cefd2056e5e730a54aa9952f2
IOC database
- Type
- hash_md5
- Value
15331e3cefd2056e5e730a54aa9952f2- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 154360 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:09:09.
Remediations (10)
-
web:any.run
Online sandbox report for armv5l, tagged as auto, mirai , botnet, verdict: Malicious activity
-
web:tria.ge
Check this mirai report ARMV5L, with a score of 10 out of 10.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.aha.org
Introduction Note: This advisory was originally published on April 7, 2026, to provide tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) related to ongoing cyber exploitation of internet-connected operational technology (OT) devices by Iranian-affiliated advanced persistent threat (APT) actors. The authoring agencies updated this advisory on July 22, 2026, to add ...
-
web:www.ic3.gov
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Publication: April 7, 2026
-
web:www.joesandbox.com
Linux Analysis Report iran.armv5l.elf Overview General Information ... Detection Gafgyt, Mirai
-
web:www.joesandbox.com
Executes the "rm" command used to delete files or directories
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.waterisac.org
Summary: Today, CISA and its partner agencies updated the joint Cybersecurity Advisory (CSA) AA26-097A " Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure. " The original advisory was published on April 7, 2026, and warns of ongoing Iranian-affiliated state-sponsored targeting of internet-connected OT devices, including programmable ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.