s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-b3827b8ada00967779406c10e5a1a5581b73bf7fa78c0fc0b14a601c1258cea9 high

📛 Threat Title

Mirai: x86_64

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 116856 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 20:09:25.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 b3827b8ada00967779406c10e5a1a5581b73bf7fa78c0fc0b14a601c1258cea9

IOC database

Type
hash_sha256
Value
b3827b8ada00967779406c10e5a1a5581b73bf7fa78c0fc0b14a601c1258cea9
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 7f376808dc93ff13f51e0df5ac8267546cf1e9ee

IOC database

Type
hash_sha1
Value
7f376808dc93ff13f51e0df5ac8267546cf1e9ee
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 ecfe0dca3ab807e386949f172c156b01

IOC database

Type
hash_md5
Value
ecfe0dca3ab807e386949f172c156b01
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 116856 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 20:09:25.

Remediations (10)

  • web:dailysecurityreview.com

    A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of vulnerable devices are exposed online.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    This repository is a treasure trove of botnet implementations, ranging from infamous Mirai variants to unique configurations and enhancements. Below is a brief description of the main directories: - maxamin/Botnets

  • web:westoahu.hawaii.edu

    Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    2 other IPs or domains Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file mirai .x86-64.elf started dash rm started

  • web:www.joesandbox.com

    Adversaries may employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Despite the use of a secure algorithm, these implementations may be vulnerable to reverse engineering if secret keys are encoded and/or generated within malware samples/configuration files.

  • web:www.pwndefend.com

    We pulled the x86-64 build and analysed it statically — no execution. It is a lean (67 KB) statically-linked, stripped ELF with the .ctors /.dtors layout and encoded-string table characteristic of the Mirai family.

  • web:www.sonicwall.com

    It spreads by continuously seeking new targets and adapts dynamically to evade detection and mitigation efforts as explained in Figure 1. Figure 1: Mirai attack chain Honeypot Insights Sonicwall's honeypots found Mirai leveraging exploits targeting old vulnerabilities in routers like Zyxel, Netgear, D-Link and TP-Link to spread Mirai .

  • web:www.techtimes.com

    Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.