MB-b0e84da839f0fbaaf40b46ce556ff59716630d7d8f6301e53dc2e455d8c93f3b
high
📛 Threat Title
Mirai: iran.armv7l
Description
File type: elf. Size: 144228 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:08:57.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
b0e84da839f0fbaaf40b46ce556ff59716630d7d8f6301e53dc2e455d8c93f3b
IOC database
- Type
- hash_sha256
- Value
b0e84da839f0fbaaf40b46ce556ff59716630d7d8f6301e53dc2e455d8c93f3b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
c47b0900bfa7425aad9f762cf132579f646917d3
IOC database
- Type
- hash_sha1
- Value
c47b0900bfa7425aad9f762cf132579f646917d3- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
c9720aa9dd4285d9f14eea3553b575a0
IOC database
- Type
- hash_md5
- Value
c9720aa9dd4285d9f14eea3553b575a0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 144228 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:08:57.
Remediations (10)
-
web:any.run
Online sandbox report for armv7l, tagged as auto, mirai , botnet, verdict: Malicious activity
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:trainsec.net
Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...
-
web:tria.ge
Check this mirai report ARMV7L, with a score of 10 out of 10.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.cisa.gov
Cybersecurity Advisory: Provides detailed information on cyber threats, including threat actor tactics, techniques, and procedures and indicators of compromise, along with recommended actions for detection, mitigation , and response.
-
web:www.joesandbox.com
Executes the "rm" command used to delete files or directories
-
web:www.joesandbox.com
Uses the "uname" system call to query kernel version information (possible evasion)
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.