s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-f383a4b24a8af5f3611abe94ffb9091812f8f82faf90d5b3829eba31d0e295c4 high

📛 Threat Title

Mirai: stub.armv6l

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 626425 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 04:33:04.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 f383a4b24a8af5f3611abe94ffb9091812f8f82faf90d5b3829eba31d0e295c4

IOC database

Type
hash_sha256
Value
f383a4b24a8af5f3611abe94ffb9091812f8f82faf90d5b3829eba31d0e295c4
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 98a95e3dc1a043f989c4332d8c5c3e31f9c76511

IOC database

Type
hash_sha1
Value
98a95e3dc1a043f989c4332d8c5c3e31f9c76511
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 8800d081d10363bdb49aa740028c86c2

IOC database

Type
hash_md5
Value
8800d081d10363bdb49aa740028c86c2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 626425 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 04:33:04.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:arxiv.org

    Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices ...

  • web:dailysecurityreview.com

    The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.

  • web:dailysecurityreview.com

    A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of vulnerable devices are exposed online.

  • web:github.com

    IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.

  • web:github.com

    Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.

  • web:tria.ge

    Check this mirai report bin[.]armv6l, with a score of 10 out of 10.

  • web:unit42.paloaltonetworks.com

    Mirai is a still-active botnet with new variants. We highlight observed exploitation of IoT vulnerabilities — due to low complexity and high impact.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Yara detected Mirai Contains symbols with names commonly found in malware Detected TCP or UDP traffic on non-standard ports Sample listens on a socket Tries to connect to HTTP servers, but all servers are down (expired dropper ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.