s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-72003a8cbe40a761f7c90940b63cb544bcd19a025614165db04bbb0ef81393f1 high

📛 Threat Title

Mirai: dlr.arm

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1164 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:36.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain dlr.arm VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dlr.arm

IOC database

Type
domain
Value
dlr.arm
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat MB-72003a8cbe40a761f7c90940b63cb544bcd19a025614165db04bbb0ef81393f1

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/dlr.arm

hash_sha256 72003a8cbe40a761f7c90940b63cb544bcd19a025614165db04bbb0ef81393f1 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/72003a8cbe40a761f7c90940b63cb544bcd19a025614165db04bbb0ef81393f1
1 feed

IOC database

Type
hash_sha256
Value
72003a8cbe40a761f7c90940b63cb544bcd19a025614165db04bbb0ef81393f1
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/72003a8cbe40a761f7c90940b63cb544bcd19a025614165db04bbb0ef81393f1

hash_sha1 0b57e173364af3da3795a4150149882126c41bcc 1 feed

IOC database

Type
hash_sha1
Value
0b57e173364af3da3795a4150149882126c41bcc
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 9e0af2a1685946623b4b0fb91d5cf43e 1 feed

IOC database

Type
hash_md5
Value
9e0af2a1685946623b4b0fb91d5cf43e
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1164 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:36.

Remediations (10)

  • web:arxiv.org

    Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.

  • web:blog.darkgen.io

    Supplement persistence layers: Mirai has nothing; only the re-infection scripts operate on the restart. On the whole, the disassembly clears up the case that Mirai is an efficient, straight, and goal-oriented ARM malware engaged in large botnet activity. I might drop a full breakdown video of the disassembly and analysis soon, so keep an eye out.

  • web:deepwiki.com

    Cross-Architecture Support Relevant source files Purpose and Scope This document details how the Mirai botnet's downloader component (dlr) provides support for multiple CPU architectures, enabling the malware to infect a wide variety of IoT device types. This cross-architecture capability is a critical feature that allows Mirai to spread across diverse hardware platforms commonly found in IoT ...

  • web:github.com

    Malware source code samples leaked online uploaded to GitHub for those who want to analyze the code. - Artogn/malware-1

  • web:link.springer.com

    Releasing its source code provides a way for the attackers to create its variants and provides researchers with a path in the right direction to tackle upcoming variants of Mirai malware. Although the mechanism of attacks and implementation of Mirai seems easy, its implementation is challenging.

  • web:trainsec.net

    In this particular case, I found an ARM-compiled Mirai botnet sample. The anti-virus checks labeled it as " Mirai ," matching what I found in the documentation, sandbox analyses, and community threat intelligence sources. Mirai is known to compile variants for multiple architectures (ARM, MIPS, x86, x64, etc.), making it adaptable and widespread.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.akamai.com

    The Akamai Security Intelligence and Response Team (SIRT) has identified active exploitation of command injection vulnerabilities CVE-2024-6047 and CVE-2024-11120 against discontinued GeoVision Internet of Things (IoT) devices. The SIRT first identified activity in our honeypots in April 2025. This is the first reported active exploitation of these vulnerabilities since the initial disclosure ...

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Executes the "rm" command used to delete files or directories Sample has stripped symbol table Uses the "uname" system call to query kernel version information (possible evasion)

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.