s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-129920ec14a26075d60b2c7cd717067460b4a201d8ee775036a9975364d6b388 high

📛 Threat Title

Mirai: axis.arm6

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 100876 bytes. Tags: Hajime, Mirai. Reporter: BlinkzSec. First seen: 2026-05-14 19:23:00.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 129920ec14a26075d60b2c7cd717067460b4a201d8ee775036a9975364d6b388 1 feed

IOC database

Type
hash_sha256
Value
129920ec14a26075d60b2c7cd717067460b4a201d8ee775036a9975364d6b388
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 30ff1385c748bb4c2ed0742cb8aa93f3682e8c14 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/30ff1385c748bb4c2ed0742cb8aa93f3682e8c14
1 feed

IOC database

Type
hash_sha1
Value
30ff1385c748bb4c2ed0742cb8aa93f3682e8c14
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/30ff1385c748bb4c2ed0742cb8aa93f3682e8c14

hash_md5 cf1d811704d5d61aeff11068ab1979ce VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/cf1d811704d5d61aeff11068ab1979ce
1 feed

IOC database

Type
hash_md5
Value
cf1d811704d5d61aeff11068ab1979ce
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/cf1d811704d5d61aeff11068ab1979ce

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 100876 bytes. Tags: Hajime, Mirai. Reporter: BlinkzSec. First seen: 2026-05-14 19:23:00.

Remediations (10)

  • web:blog.darkgen.io

    Mirai is an infamous malware that was found in 2016 and is intended to target Internet of Things (IoT) devices like IP cameras, routers and DVRs. It searches the internet to identify those systems running on weak or default usernames and passwords, subsequently commandeers them into a huge botnet whose initial use is usually to carry out ...

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:github.com

    AXIS- Mirai is probably one of the greatest botnet sources there is, public or private - nyzxor/AXIS- Mirai

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:shhaos.github.io

    These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.

  • web:trainsec.net

    Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...

  • web:tria.ge

    Check this mirai report arm6[.]elf, with a score of 10 out of 10.

  • web:www.joesandbox.com

    Warnings Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data. VT rate limit hit for: mirai .arm6.elf

  • web:www.microsoft.com

    On March 31, 2026, the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control (C2) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet. Although the malicious versions are no longer available for download, since Axios is one of the most widely ...

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.