s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-cfbd3a7d10326d93e345c79d36f44e28a39f3fb2631a3666db36e8d2d3f0d793 high

📛 Threat Title

Mirai: dlr.arm6

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1456 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:36.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 cfbd3a7d10326d93e345c79d36f44e28a39f3fb2631a3666db36e8d2d3f0d793 1 feed

IOC database

Type
hash_sha256
Value
cfbd3a7d10326d93e345c79d36f44e28a39f3fb2631a3666db36e8d2d3f0d793
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 80a3fd23c82ebc666cd3e3ac10b961d7b2999159 1 feed

IOC database

Type
hash_sha1
Value
80a3fd23c82ebc666cd3e3ac10b961d7b2999159
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 15ee1169fafe0c73763f1f792992584b 1 feed

IOC database

Type
hash_md5
Value
15ee1169fafe0c73763f1f792992584b
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1456 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-05-15 11:52:36.

Remediations (10)

  • web:deepwiki.com

    This document describes the multi-architecture support system in Cosmic- Mirai , covering the 11 supported CPU architectures, cross-compilation toolchain configuration, binary compilation process, and architecture-specific optimizations.

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:isc.sans.edu

    The mitigation advice is the same, these devices probably shouldn't have internet facing admin panels but unfortunately the class of device suggests the people running them are also not likely reading such guidance much less have the ability or wherewithall to fix the issue and/or update their firmware.

  • web:unit42.paloaltonetworks.com

    The only effective remediation is complete uninstallation. Brand Impersonator: AI Photo and Video Editor A brand impersonator is malware that mimics legitimate software brands to exploit user trust and bypass skepticism during installation. This case study is for an extension named that impersonates a popular graphics editing brand.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.joesandbox.com

    Signatures Multi AV Scanner detection for submitted file HTTP GET or POST without a user agent Sample has stripped symbol table Uses the "uname" system call to query kernel version information (possible evasion)

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.sciencedirect.com

    In the specific context of Mirai botnet detection and mitigation , several approaches have been presented in the literature. Some works focus on studying the behavior of the Mirai botnet, examining and monitoring its propagation and impact within networked systems [85], [86], [87].

  • web:www.usenix.org

    These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.