MB-47db897ff8ee59a7caa16b8b06e8bf45a376be9e3f581587d8fcaeda6d7d75d0
high
📛 Threat Title
Mirai: data_arm6
Description
File type: elf. Size: 132976 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:54:34.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
47db897ff8ee59a7caa16b8b06e8bf45a376be9e3f581587d8fcaeda6d7d75d0
IOC database
- Type
- hash_sha256
- Value
47db897ff8ee59a7caa16b8b06e8bf45a376be9e3f581587d8fcaeda6d7d75d0- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
20d8300b6ac1237261d0b08bb2369f14
IOC database
- Type
- hash_md5
- Value
20d8300b6ac1237261d0b08bb2369f14- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
e4d2799428e03c671dba52cf5b01f50cf8e1892e
IOC database
- Type
- hash_sha1
- Value
e4d2799428e03c671dba52cf5b01f50cf8e1892e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 132976 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:54:34.
Remediations (10)
-
web:any.run
Online sandbox report for data.arm6 , tagged as mirai , botnet, verdict: Malicious activity
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:github.com
This repository contains a comprehensive malware analysis report focusing on the Mirai IoT botnet. The project details the setup of a secure malware analysis laboratory and presents a research-based analysis of the Mirai malware. It covers the critical aspects of establishing an isolated analysis environment, the selection of appropriate tools, and a thorough investigation of Mirai's ...
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:tria.ge
Check this mirai report arm6[.]elf, with a score of 10 out of 10.
-
web:tria.ge
Check this mirai report arm6, with a score of 10 out of 10.
-
web:www.joesandbox.com
File: /tmp/ mirai .arm6.elf Jump to behavior Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/ mirai .arm6.elf (PID: 6260) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Performs DNS TXT record lookups Creates hidden files and/or directories Creates hidden files without content (potentially used as a mutex) Detected TCP or UDP traffic on non-standard ports Enumerates processes within the "proc" file system Executes the "rm" command ...
-
web:www.pwndefend.com
Observed in-the-wild chain: CVE-2026-34908 (access-control/traversal bypass to the localhost updater) → CVE-2026-34910 (command injection via pkg_name) → Mirai loader (zok) drop. So they use part of a CVE and part of another CVE to achieve the outcome, but I'd suggest that they could have just used either CVE if they had full knowledge.
-
web:www.techtimes.com
Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.