s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-ddb73c805e2f965512affd129db044f127f90d3b164e14b6e68332a28ca10c5d high

📛 Threat Title

Mirai: stub.armv7l

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 625888 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 04:42:16.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 ddb73c805e2f965512affd129db044f127f90d3b164e14b6e68332a28ca10c5d

IOC database

Type
hash_sha256
Value
ddb73c805e2f965512affd129db044f127f90d3b164e14b6e68332a28ca10c5d
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 f2ebc8c03cb403ccbb2f703f971b5ef67657c333

IOC database

Type
hash_sha1
Value
f2ebc8c03cb403ccbb2f703f971b5ef67657c333
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 d331f0da486dfdbbdafc6658a64b3a10

IOC database

Type
hash_md5
Value
d331f0da486dfdbbdafc6658a64b3a10
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 625888 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 04:42:16.

Remediations (10)

  • web:github.com

    This repository contains the leaked source code of the Mirai botnet, originally created to infect IoT devices and launch large-scale DDoS attacks. This code is provided strictly for cybersecurity research, reverse engineering, malware analysis, and detection development purposes only.

  • web:github.com

    Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.

  • web:support.microsoft.com

    Updates for Windows released on April 9, 2024, and later updates, add the following: Three new mitigation controls that replace the mitigations released in 2023. The new mitigations controls are: A control to deploy the "Windows UEFI CA 2023" certificate to the Secure Boot DB to add trust for Windows boot managers signed by this certificate.

  • web:trainsec.net

    Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...

  • web:tria.ge

    Check this mirai report armv7l[.]elf, with a score of 10 out of 10.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.jisem-journal.com

    Presenting an in-depth security analysis of Mirai botnet, a malware that affected the availability of banking systems and put in evidence a new form of DDoS attack that works with IoT devices compromised by malware. The methods presented are generic and can be used to mitigate any malware of the same nature.

  • web:www.mira-project.org

    Contents Prepare MIRA system requirements Setup cross compiling toolchain Copy libraries of target system to the build system Cross compile MIRA Generate manifest files on target system Basics Cross compiling can become interesting if one wants to run MIRA on a device that is hardly capable of compiling MIRA on its own (e.g. due to CPU or MEMORY limitation). Cross compile can greatly help in ...

  • web:xdaforums.com

    Help needed with t950s ARMv7l ROM/firmware fernandohsch Mar 12, 2025 amlogic kernel armv7 cheap android mobile custom rom firmware hy300 malware in root system projector issue t950s

  • web:xdaforums.com

    Components runbook.sh (method), scripts/helpers.sh (shared), scripts/gpt_verify.py (payload-vs-device GPT verification), scripts/fetch_mifirm.js (stock-ROM fetch helper, optional) config.sh (generic, parametrized; no device-specific identifiers) payloads/README.md (per-SoC payload files + the GPT-rename trick), docs/sources.md (documented method) tools/ (fastboot/adb) is gitignored — fetch ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.