s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-27c593a40a437810124f2f43a9d67365f1b91a3f52ab64e44d0f5b120ca78136 high

📛 Threat Title

Mirai: SecuriteInfo.com.ELF.Mirai-COW.97552716

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 555048 bytes. Tags: elf, Mirai. Reporter: SecuriteInfoCom. First seen: 2026-09-25 03:44:09.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 27c593a40a437810124f2f43a9d67365f1b91a3f52ab64e44d0f5b120ca78136

IOC database

Type
hash_sha256
Value
27c593a40a437810124f2f43a9d67365f1b91a3f52ab64e44d0f5b120ca78136
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 55bf21cc08ca4a06c8672f1143d3ada84a0cbe33

IOC database

Type
hash_sha1
Value
55bf21cc08ca4a06c8672f1143d3ada84a0cbe33
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 fce665ffd54fe009fce8626468fd2e38

IOC database

Type
hash_md5
Value
fce665ffd54fe009fce8626468fd2e38
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 555048 bytes. Tags: elf, Mirai. Reporter: SecuriteInfoCom. First seen: 2026-09-25 03:44:09.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:any.run

    Online sandbox report for SecuriteInfo.com.ELF. Mirai -CBI.38444756, tagged as mirai , botnet, verdict: Malicious activity

  • web:app.any.run

    Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.

  • web:dailysecurityreview.com

    A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of vulnerable devices are exposed online.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    This repository contains the leaked source code of the Mirai botnet, originally created to infect IoT devices and launch large-scale DDoS attacks. This code is provided strictly for cybersecurity research, reverse engineering, malware analysis, and detection development purposes only.

  • web:malpedia.caad.fkie.fraunhofer.de

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices.

  • web:miraisecurity.com

    Mirai Security is a cybersecurity services company that takes a business-first approach & focuses on people, processes, and technology.

  • web:www.joesandbox.com

    Network Map ⊘ No contacted IP infos ID: 1527609 Product: CloudBasic Start time: 06:23:12 Start date: 07.10.2024 Sample: SecuriteInfo.com.ELF. Mirai -COW.30071.12978.elf Cookbook: defaultlinuxfilecookbook.jbs System description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0, Evince Document Viewer 3.36.10, LibreOffice 6.4.7.2, OpenJDK 11.0.11) Architecture: LINUX MD5 ...

  • web:www.joesandbox.com

    Runtime Messages Command: /tmp/SecuriteInfo.com.ELF. Mirai -COW.6055.9040.elf PID: 5429 Exit Code: 0 Exit Code Info: Killed: False Standard Output: Firmware update in progress Standard Error:

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.