s1
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-3c56921620092160263dc354aa64c1669473f54ff1c1cf952547a83af06f1558 high

📛 Threat Title

Mirai: iran.armv5l

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 125632 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-06-13 15:09:49.

Remediations (10)

  • web:arxiv.org

    Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...

  • web:arxiv.org

    Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.

  • web:bazaar.abuse.ch

    Malware samples associated with tag armv5l MalwareBazaar Database Samples on MalwareBazaar are usually associated with certain tags. Every sample can associated with one or more tags. Using tags, it is easy to navigate through the huge amount of malware samples in the MalwareBazaar corpus. The page below gives you an overview on malware samples that are tagged with armv5l. Database Entry

  • web:github.com

    This repository contains the leaked source code of the Mirai botnet, originally created to infect IoT devices and launch large-scale DDoS attacks. This code is provided strictly for cybersecurity research, reverse engineering, malware analysis, and detection development purposes only.

  • web:github.com

    Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.

  • web:unit42.paloaltonetworks.com

    Mirai is a still-active botnet with new variants. We highlight observed exploitation of IoT vulnerabilities — due to low complexity and high impact.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.joesandbox.com

    ELF contains segments with high entropy indicating compressed/encrypted content

  • web:www.joesandbox.com

    Found malware configuration Multi AV Scanner detection for submitted file Yara detected Gafgyt Yara detected Mirai iran.armv5l.elf started iran.armv5l.elf

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 3c56921620092160263dc354aa64c1669473f54ff1c1cf952547a83af06f1558

IOC database

Type
hash_sha256
Value
3c56921620092160263dc354aa64c1669473f54ff1c1cf952547a83af06f1558
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 fea304c40d862ccf66cd5c916fb841cc5c478a85

IOC database

Type
hash_sha1
Value
fea304c40d862ccf66cd5c916fb841cc5c478a85
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 d9507b100369d770757fd123f5631f92

IOC database

Type
hash_md5
Value
d9507b100369d770757fd123f5631f92
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 125632 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-06-13 15:09:49.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.