s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-1df80ce06971c31a0d332fd7ebe7d6c74a7e7bb3485298004c1c4e9482763532 high

📛 Threat Title

Mirai: arm7

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 141648 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-09-24 08:59:20.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 1df80ce06971c31a0d332fd7ebe7d6c74a7e7bb3485298004c1c4e9482763532

IOC database

Type
hash_sha256
Value
1df80ce06971c31a0d332fd7ebe7d6c74a7e7bb3485298004c1c4e9482763532
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 da7b093b0ca24c53450363a701a1d320a7b097f3

IOC database

Type
hash_sha1
Value
da7b093b0ca24c53450363a701a1d320a7b097f3
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 58cc8bd86049342b0964f3b2c358be4c

IOC database

Type
hash_md5
Value
58cc8bd86049342b0964f3b2c358be4c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 141648 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-09-24 08:59:20.

Remediations (10)

  • web:arxiv.org

    Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices ...

  • web:cyberpress.org

    Remote, unauthenticated attackers are able to inject arbitrary system commands, enabling full device compromise without user interaction. Investigation revealed that threat actors are leveraging the compromised endpoint to download and execute Mirai -based ARM malware, notably a variant referred to as "LZRD" (typically named boatnet. arm7 ). Upon execution, this Mirai variant displays a ...

  • web:dailysecurityreview.com

    A new Mirai botnet is using zero-day exploits to target industrial routers and smart home devices, launching high-intensity DDoS attacks. Learn about the vulnerabilities and how to protect your systems.

  • web:deepwiki.com

    The distinction between generic ARM and ARMv7 is significant: ARMv7 introduced Thumb-2, improved instruction sets, and performance enhancements. By providing an ARMv7-specific binary, Mirai can leverage these capabilities on newer devices while maintaining backward compatibility through the generic ARM binary. Sources: loader/bins/dlr.arm loader/bins/dlr. arm7 Architecture Detection and ...

  • web:github.com

    IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:trainsec.net

    Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    Uses the "uname" system call to query kernel version information (possible evasion)

  • web:www.joesandbox.com

    Behavior Graph ID: 481779 Sample: mirai.arm7 Startdate: 12/09/2021 Architecture: LINUX Score: 80 Malicious sample detected (through community Yara rule) Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.