s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-5500d5daec3a18a6aaf3ab5724d98276003d912834a5961c2eaa651e6d6d1eac high

📛 Threat Title

Mirai: tpijtvcr.aarch64

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1098885 bytes. Tags: elf, Gafgyt, Mirai. Reporter: abuse_ch. First seen: 2026-09-23 23:14:23.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 5500d5daec3a18a6aaf3ab5724d98276003d912834a5961c2eaa651e6d6d1eac

IOC database

Type
hash_sha256
Value
5500d5daec3a18a6aaf3ab5724d98276003d912834a5961c2eaa651e6d6d1eac
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 80f82fb398d7d9592770ff3e308939f5ebfdbad2

IOC database

Type
hash_sha1
Value
80f82fb398d7d9592770ff3e308939f5ebfdbad2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 be6df044bfc9bc7dab4917086305510e

IOC database

Type
hash_md5
Value
be6df044bfc9bc7dab4917086305510e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1098885 bytes. Tags: elf, Gafgyt, Mirai. Reporter: abuse_ch. First seen: 2026-09-23 23:14:23.

Remediations (10)

  • web:cybersecuritynews.com

    EOL TP-Link routers hit by CVE-2023-33538, letting hackers install Mirai botnet via web flaws with no official patches available.

  • web:dailysecurityreview.com

    A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of vulnerable devices are exposed online.

  • web:dailysecurityreview.com

    A new Mirai botnet is using zero-day exploits to target industrial routers and smart home devices, launching high-intensity DDoS attacks. Learn about the vulnerabilities and how to protect your systems.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.netscout.com

    Arbor Networks - DDoS Experts ASERT Threat Summary: Aisuru and Related TurboMirai Botnet DDoS Attack Mitigation and Suppression—October 2025—v1.0

  • web:www.yazoul.net

    Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.