MB-f383a4b24a8af5f3611abe94ffb9091812f8f82faf90d5b3829eba31d0e295c4
high
📛 Threat Title
Mirai: stub.armv6l
Description
File type: elf. Size: 626425 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 04:33:04.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
f383a4b24a8af5f3611abe94ffb9091812f8f82faf90d5b3829eba31d0e295c4
IOC database
- Type
- hash_sha256
- Value
f383a4b24a8af5f3611abe94ffb9091812f8f82faf90d5b3829eba31d0e295c4- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
98a95e3dc1a043f989c4332d8c5c3e31f9c76511
IOC database
- Type
- hash_sha1
- Value
98a95e3dc1a043f989c4332d8c5c3e31f9c76511- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
8800d081d10363bdb49aa740028c86c2
IOC database
- Type
- hash_md5
- Value
8800d081d10363bdb49aa740028c86c2- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 626425 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 04:33:04.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:arxiv.org
Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices ...
-
web:dailysecurityreview.com
The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.
-
web:dailysecurityreview.com
A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of vulnerable devices are exposed online.
-
web:github.com
IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.
-
web:github.com
Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.
-
web:tria.ge
Check this mirai report bin[.]armv6l, with a score of 10 out of 10.
-
web:unit42.paloaltonetworks.com
Mirai is a still-active botnet with new variants. We highlight observed exploitation of IoT vulnerabilities — due to low complexity and high impact.
-
web:westoahu.hawaii.edu
A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Yara detected Mirai Contains symbols with names commonly found in malware Detected TCP or UDP traffic on non-standard ports Sample listens on a socket Tries to connect to HTTP servers, but all servers are down (expired dropper ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.