s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-bf9bb4c900cb9e7de5c0ee457455b8a06f0f44cced440550bf818655ba105ef0 high

📛 Threat Title

Mirai: arm7

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 61328 bytes. Tags: elf, upx. Reporter: abuse_ch. First seen: 2026-09-24 08:58:25.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 bf9bb4c900cb9e7de5c0ee457455b8a06f0f44cced440550bf818655ba105ef0

IOC database

Type
hash_sha256
Value
bf9bb4c900cb9e7de5c0ee457455b8a06f0f44cced440550bf818655ba105ef0
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 fe7a337f317be5ed800a770fb5a6df83

IOC database

Type
hash_md5
Value
fe7a337f317be5ed800a770fb5a6df83
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 83a2f2253efc10a30a362451d106266dd3991bde

IOC database

Type
hash_sha1
Value
83a2f2253efc10a30a362451d106266dd3991bde
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 61328 bytes. Tags: elf, upx. Reporter: abuse_ch. First seen: 2026-09-24 08:58:25.

Remediations (10)

  • web:arxiv.org

    Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices ...

  • web:cyberpress.org

    Remote, unauthenticated attackers are able to inject arbitrary system commands, enabling full device compromise without user interaction. Investigation revealed that threat actors are leveraging the compromised endpoint to download and execute Mirai -based ARM malware, notably a variant referred to as "LZRD" (typically named boatnet. arm7 ). Upon execution, this Mirai variant displays a ...

  • web:dailysecurityreview.com

    A new Mirai botnet is using zero-day exploits to target industrial routers and smart home devices, launching high-intensity DDoS attacks. Learn about the vulnerabilities and how to protect your systems.

  • web:deepwiki.com

    The distinction between generic ARM and ARMv7 is significant: ARMv7 introduced Thumb-2, improved instruction sets, and performance enhancements. By providing an ARMv7-specific binary, Mirai can leverage these capabilities on newer devices while maintaining backward compatibility through the generic ARM binary. Sources: loader/bins/dlr.arm loader/bins/dlr. arm7 Architecture Detection and ...

  • web:github.com

    IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.

  • web:trainsec.net

    Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...

  • web:unit42.paloaltonetworks.com

    We discovered ongoing attacks leveraging IoT vulnerabilities, including in network security devices, to serve a Mirai variant.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    Uses the "uname" system call to query kernel version information (possible evasion)

  • web:www.joesandbox.com

    Behavior Graph ID: 481779 Sample: mirai.arm7 Startdate: 12/09/2021 Architecture: LINUX Score: 80 Malicious sample detected (through community Yara rule) Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.