MB-07fbbc1009760a79fa59fd87d4930f0ca8b027922306edb55e7069b4e36bb9f7
high
📛 Threat Title
Mirai: dlr.arm7
Description
File type: elf. Size: 1500 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:36.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
07fbbc1009760a79fa59fd87d4930f0ca8b027922306edb55e7069b4e36bb9f7
1 feed
IOC database
- Type
- hash_sha256
- Value
07fbbc1009760a79fa59fd87d4930f0ca8b027922306edb55e7069b4e36bb9f7- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
5478cf1de18cb286b4cdb537e58b27328fd36955
VT 42 / 75
1 feed
IOC database
- Type
- hash_sha1
- Value
5478cf1de18cb286b4cdb537e58b27328fd36955- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 42 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Linux/MiraiDown.Exp |
| alibabacloud | malicious | DDoS:Linux/Mirai.HF8PHU |
| ALYac | malicious | Trojan.Generic.39963222 |
| Antiy-AVL | malicious | Trojan[Downloader]/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D261CA56 |
| Avast | malicious | ELF:MiraiDownloader-QZ [Drp] |
| Avast-Mobile | malicious | ELF:MiraiDownloader-QZ [Drp] |
| AVG | malicious | ELF:MiraiDownloader-QZ [Drp] |
| Avira | malicious | DR/LINUX.MiraiDown.QZ |
| BitDefender | malicious | Trojan.Generic.39963222 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.DownLoader.507 |
| Elastic | malicious | Linux.Generic.Threat |
| Emsisoft | malicious | Trojan.Generic.39963222 (B) |
| ESET-NOD32 | malicious | Linux/TrojanDownloader.Mirai.FQ trojan |
| F-Secure | malicious | Dropper.DR/LINUX.MiraiDown.QZ |
| Fortinet | malicious | ELF/Mirai.D!tr |
| GData | malicious | Trojan.Generic.39963222 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Agent.ax!crit |
| Ikarus | malicious | Trojan-Downloader.Linux.Mirai |
| Jiangmin | malicious | TrojanDownloader.Linux.hm |
| K7GW | malicious | Trojan ( 00410c261 ) |
| Kaspersky | malicious | HEUR:Trojan-Downloader.Linux.Mirai.d |
| Kingsoft | malicious | Linux.Trojan-Downloader.Mirai.d |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | ti!07FBBC100976 |
| Microsoft | malicious | Backdoor:Linux/Mirai.HD!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.39963222 |
| Rising | malicious | Backdoor.Mirai/Linux!8.13285 (TFE:14:veCGiUCFGKH) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| Skyhigh | malicious | GenericRXIB-TR!73B66E70A503 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Trojan.Linux.Mirai.iatra |
| TrellixENS | malicious | GenericRXIB-TR!73B66E70A503 |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLEN26 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLEN26 |
| Varist | malicious | E32/Mirai.IE.gen!Eldorado |
| VIPRE | malicious | Trojan.Generic.39963222 |
| VirIT | malicious | Linux.DownLoader.UD |
Details From VirusTotal
Basic Properties
| MD5 | 73b66e70a5036a14f3255612bf3e6a82 |
| SHA-1 | 5478cf1de18cb286b4cdb537e58b27328fd36955 |
| SHA-256 | 07fbbc1009760a79fa59fd87d4930f0ca8b027922306edb55e7069b4e36bb9f7 |
| VHash | 9def90f2209a0c111aaf5d061c869c46 |
| SSDEEP | 24:uAd9KGpa7Urz/jlfA+rXK1hH9Vev3gRGaJ9iBBBuLl59gD10yd:uA9KGpa7UrLZ8I+JiBuHE10yd |
| TLSH | T16B31DF91A7D15DBDC4E411BEBD4B4314B374AF40E0CE7222832C73686D2AE3DAD2704A |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped |
| File size | 1.5 KB |
History
| First seen on VirusTotal | 2026-05-15 12:00 UTC |
| Last submission | 2026-05-15 12:03 UTC |
| Last analysis | 2026-06-07 22:22 UTC |
| Last modified on VirusTotal | 2026-06-08 00:22 UTC |
Known Names
dlr.arm7m2tr404l.exe417276618
hash_md5
73b66e70a5036a14f3255612bf3e6a82
1 feed
IOC database
- Type
- hash_md5
- Value
73b66e70a5036a14f3255612bf3e6a82- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 1500 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:36.
Remediations (10)
-
web:any.run
MALICIOUS MIRAI has been detected (SURICATA)dlr.arm7.elf (deleted) (PID: 2083) MIRAI has been detected (SURICATA) dlr.arm7.elf (deleted) (PID: 2083) dlr.arm7.elf (deleted) (PID: 2083) SUSPICIOUS Modifies file or directory ownersudo (PID: 2071)Connects to unusual portdlr.arm7.elf (deleted) (PID: 2083)Starts itself from another locationdlr.arm7.elf (PID: 2077)Contacting a server suspected of ...
-
web:arxiv.org
Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.
-
web:deepwiki.com
Cross-Architecture Support Relevant source files Purpose and Scope This document details how the Mirai botnet's downloader component (dlr) provides support for multiple CPU architectures, enabling the malware to infect a wide variety of IoT device types. This cross-architecture capability is a critical feature that allows Mirai to spread across diverse hardware platforms commonly found in IoT ...
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:github.com
Leaked Mirai Source Code for Research/IoC Development Purposes - jgamblin/ Mirai -Source-Code
-
web:trainsec.net
Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...
-
web:unit42.paloaltonetworks.com
The only effective remediation is complete uninstallation. Brand Impersonator: AI Photo and Video Editor A brand impersonator is malware that mimics legitimate software brands to exploit user trust and bypass skepticism during installation. This case study is for an extension named that impersonates a popular graphics editing brand.
-
web:www.akamai.com
The Akamai Security Intelligence and Response Team (SIRT) has identified active exploitation of command injection vulnerabilities CVE-2024-6047 and CVE-2024-11120 against discontinued GeoVision Internet of Things (IoT) devices. The SIRT first identified activity in our honeypots in April 2025. This is the first reported active exploitation of these vulnerabilities since the initial disclosure ...
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai HTTP GET or POST without a user agent Sample has stripped symbol table Uses the "uname" system call to query kernel version information (possible evasion)
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.