s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-6c65afb1eb421e192dd0b6ab9fa187b0973d43f10763279dd7f60098ec1acd69 high

📛 Threat Title

Mirai: data_mips

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 166408 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:33:40.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 6c65afb1eb421e192dd0b6ab9fa187b0973d43f10763279dd7f60098ec1acd69

IOC database

Type
hash_sha256
Value
6c65afb1eb421e192dd0b6ab9fa187b0973d43f10763279dd7f60098ec1acd69
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 e9e0d48babde7905f11ff1935b9b3a44

IOC database

Type
hash_md5
Value
e9e0d48babde7905f11ff1935b9b3a44
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 97e7dbc7907fbe703e3144234779a8b1067037db

IOC database

Type
hash_sha1
Value
97e7dbc7907fbe703e3144234779a8b1067037db
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 166408 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:33:40.

Remediations (10)

  • web:arxiv.org

    A heavy emphasis is placed on how the researchers extracted the data and used it to classify and track Mirai variants. The researchers take a more holistic approach to discuss the variants and provide details specifically on Masuta, Owari, and Wicked.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    The report provides a detailed analysis of the Mirai botnet, a prominent IoT malware targeting Linux-based devices. Key aspects covered include: Static Analysis: Utilizing tools like VirusTotal to identify the malware variant, its architecture (ELF 32-bit LSB, MIPS), and common detection names (e.g., DDoS:Linux/ Mirai .gen!c, Trojan.Linux. Mirai .B). The analysis also includes extracting printable ...

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:mirai.r-lib.org

    Core Concepts mirai = future in Japanese. Async evaluation framework for R built on NNG/nanonext. Hub architecture: host listens at a URL, daemons connect to it, enabling dynamic scaling. This is a cheatsheet. Refer to the mirai reference manual for a detailed introduction.

  • web:trainsec.net

    In this particular case, I found an ARM-compiled Mirai botnet sample. The anti-virus checks labeled it as " Mirai ," matching what I found in the documentation, sandbox analyses, and community threat intelligence sources. Mirai is known to compile variants for multiple architectures (ARM, MIPS, x86, x64, etc.), making it adaptable and widespread.

  • web:westoahu.hawaii.edu

    Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.

  • web:www.pwndefend.com

    Observed in-the-wild chain: CVE-2026-34908 (access-control/traversal bypass to the localhost updater) → CVE-2026-34910 (command injection via pkg_name) → Mirai loader (zok) drop. So they use part of a CVE and part of another CVE to achieve the outcome, but I'd suggest that they could have just used either CVE if they had full knowledge.

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.techtimes.com

    Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.