s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-b0e84da839f0fbaaf40b46ce556ff59716630d7d8f6301e53dc2e455d8c93f3b high

📛 Threat Title

Mirai: iran.armv7l

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 144228 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:08:57.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 b0e84da839f0fbaaf40b46ce556ff59716630d7d8f6301e53dc2e455d8c93f3b

IOC database

Type
hash_sha256
Value
b0e84da839f0fbaaf40b46ce556ff59716630d7d8f6301e53dc2e455d8c93f3b
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 c47b0900bfa7425aad9f762cf132579f646917d3

IOC database

Type
hash_sha1
Value
c47b0900bfa7425aad9f762cf132579f646917d3
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 c9720aa9dd4285d9f14eea3553b575a0

IOC database

Type
hash_md5
Value
c9720aa9dd4285d9f14eea3553b575a0
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 144228 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:08:57.

Remediations (10)

  • web:any.run

    Online sandbox report for armv7l, tagged as auto, mirai , botnet, verdict: Malicious activity

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:trainsec.net

    Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...

  • web:tria.ge

    Check this mirai report ARMV7L, with a score of 10 out of 10.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.cisa.gov

    Cybersecurity Advisory: Provides detailed information on cyber threats, including threat actor tactics, techniques, and procedures and indicators of compromise, along with recommended actions for detection, mitigation , and response.

  • web:www.joesandbox.com

    Executes the "rm" command used to delete files or directories

  • web:www.joesandbox.com

    Uses the "uname" system call to query kernel version information (possible evasion)

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.