MB-bf9bb4c900cb9e7de5c0ee457455b8a06f0f44cced440550bf818655ba105ef0
high
📛 Threat Title
Mirai: arm7
Description
File type: elf. Size: 61328 bytes. Tags: elf, upx. Reporter: abuse_ch. First seen: 2026-09-24 08:58:25.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
bf9bb4c900cb9e7de5c0ee457455b8a06f0f44cced440550bf818655ba105ef0
IOC database
- Type
- hash_sha256
- Value
bf9bb4c900cb9e7de5c0ee457455b8a06f0f44cced440550bf818655ba105ef0- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
fe7a337f317be5ed800a770fb5a6df83
IOC database
- Type
- hash_md5
- Value
fe7a337f317be5ed800a770fb5a6df83- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
83a2f2253efc10a30a362451d106266dd3991bde
IOC database
- Type
- hash_sha1
- Value
83a2f2253efc10a30a362451d106266dd3991bde- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 61328 bytes. Tags: elf, upx. Reporter: abuse_ch. First seen: 2026-09-24 08:58:25.
Remediations (10)
-
web:arxiv.org
Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices ...
-
web:cyberpress.org
Remote, unauthenticated attackers are able to inject arbitrary system commands, enabling full device compromise without user interaction. Investigation revealed that threat actors are leveraging the compromised endpoint to download and execute Mirai -based ARM malware, notably a variant referred to as "LZRD" (typically named boatnet. arm7 ). Upon execution, this Mirai variant displays a ...
-
web:dailysecurityreview.com
A new Mirai botnet is using zero-day exploits to target industrial routers and smart home devices, launching high-intensity DDoS attacks. Learn about the vulnerabilities and how to protect your systems.
-
web:deepwiki.com
The distinction between generic ARM and ARMv7 is significant: ARMv7 introduced Thumb-2, improved instruction sets, and performance enhancements. By providing an ARMv7-specific binary, Mirai can leverage these capabilities on newer devices while maintaining backward compatibility through the generic ARM binary. Sources: loader/bins/dlr.arm loader/bins/dlr. arm7 Architecture Detection and ...
-
web:github.com
IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.
-
web:trainsec.net
Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...
-
web:unit42.paloaltonetworks.com
We discovered ongoing attacks leveraging IoT vulnerabilities, including in network security devices, to serve a Mirai variant.
-
web:www.akamai.com
Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .
-
web:www.joesandbox.com
Uses the "uname" system call to query kernel version information (possible evasion)
-
web:www.joesandbox.com
Behavior Graph ID: 481779 Sample: mirai.arm7 Startdate: 12/09/2021 Architecture: LINUX Score: 80 Malicious sample detected (through community Yara rule) Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.