MB-124cd5cb907ce33f0735647bb22236e0eee8a273caa0b3c8720ef4cc5d6a4ccc
high
📛 Threat Title
Mirai: arm7
Description
File type: elf. Size: 166936 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-13 18:50:51.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
124cd5cb907ce33f0735647bb22236e0eee8a273caa0b3c8720ef4cc5d6a4ccc
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/124cd5cb907ce33f0735647bb22236e0eee8a273caa0b3c8720ef4cc5d6a4ccc
1 feed
IOC database
- Type
- hash_sha256
- Value
124cd5cb907ce33f0735647bb22236e0eee8a273caa0b3c8720ef4cc5d6a4ccc- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/124cd5cb907ce33f0735647bb22236e0eee8a273caa0b3c8720ef4cc5d6a4ccc
hash_sha1
d3bb45117b2fd798a678b484bb25efc43c0af0ca
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d3bb45117b2fd798a678b484bb25efc43c0af0ca
2 feeds
IOC database
- Type
- hash_sha1
- Value
d3bb45117b2fd798a678b484bb25efc43c0af0ca- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/d3bb45117b2fd798a678b484bb25efc43c0af0ca
hash_md5
72e3996a1c3cc9ccae6bd0addf51da74
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/72e3996a1c3cc9ccae6bd0addf51da74
2 feeds
IOC database
- Type
- hash_md5
- Value
72e3996a1c3cc9ccae6bd0addf51da74- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/72e3996a1c3cc9ccae6bd0addf51da74
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 166936 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-13 18:50:51.
Remediations (10)
-
web:arxiv.org
Angela Famera, Ben Hilger, Suman Bhunia, Patrick Heil Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several vari-ants that combined the old code ...
-
web:blog.darkgen.io
Mirai -based attacks also put the technology into the spotlight when they were applied to disable key services such as Twitter, Netflix, and GitHub as part of Dyn DNS attack, one of the largest DDoS attacks on record at the time. Its source code was later published the same year resulting in an explosion of copycats and derivatives.
-
web:cyberpress.org
Remote, unauthenticated attackers are able to inject arbitrary system commands, enabling full device compromise without user interaction. Investigation revealed that threat actors are leveraging the compromised endpoint to download and execute Mirai -based ARM malware, notably a variant referred to as "LZRD" (typically named boatnet. arm7 ). Upon execution, this Mirai variant displays a ...
-
web:gbhackers.com
The latest wave of Mirai botnet activity has resurfaced with a refined attack chain exploiting CVE-2024-3721, a critical command injection vulnerability in TBK DVR-4104 and DVR-4216 devices. This campaign leverages unpatched firmware to deploy a modified Mirai variant designed for IoT device hijacking and DDoS operations.
-
web:thehackernews.com
Two critical CVEs exploited in GeoVision IoT and Samsung MagicINFO allow Mirai botnet deployment via RCE.
-
web:trainsec.net
Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...
-
web:westoahu.hawaii.edu
Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.
-
web:www.akamai.com
Conclusion Mirai -based botnets continue to be a call for divorce for many organizations, and the prevalence of outdated IoT devices help propagate this threat. Like security researchers, some threat actors keep up to date on the latest vulnerability disclosures relevant to their illicit activities.
-
web:www.broadcom.com
New campaigns distributing Mirai botnet have been reported in the wild. The malware exploits two command injection vulnerabilities affecting GeoVision IoT devices that have been disclosed last year - CVE-2024-6047 and CVE-2024-11120. Upon a successful exploitation, the attackers attempt to download and execute ARM-based Mirai payloads - among them a variant called LZRD. The observed ...
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Analysis Report Analysis Advice Static ELF header machine description suggests that the sample might not execute correctly on this machine.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.