MB-374af9317c9ca7ed429d9ce7ef4003901aed9f36f0356c3c0af8b97351a79b4e
high
📛 Threat Title
Mirai: iran.armv6l
Description
File type: elf. Size: 169012 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 05:58:30.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
374af9317c9ca7ed429d9ce7ef4003901aed9f36f0356c3c0af8b97351a79b4e
IOC database
- Type
- hash_sha256
- Value
374af9317c9ca7ed429d9ce7ef4003901aed9f36f0356c3c0af8b97351a79b4e- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
32b047106b11faa384605e06407992a6
IOC database
- Type
- hash_md5
- Value
32b047106b11faa384605e06407992a6- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
dab476b2549324e87f8f8aab35ecbb86eb1b09db
IOC database
- Type
- hash_sha1
- Value
dab476b2549324e87f8f8aab35ecbb86eb1b09db- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 169012 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 05:58:30.
Remediations (10)
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:github.com
Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.
-
web:maltiverse.com
Hashes Filename: iran.armv6l md5: 760402c27085d03f3ce35dde15bb4f94 sha1: fd1446b2fe5ee2c470070d34cd2b0152076f5c13 sha256: 583de6a7260791059d03c84bf58b6f01f614b2220e42c278ef3117457dc4a11e sha512: In depth details Filetype: Architecture: Compiler: Size (Bytes): Classification: malicious Mutex mutex: Dates Indexed: 2026-03-23 05:05:16 (2026-03-23 ...
-
web:undercodetesting.com
Introduction: A coordinated cyberattack campaign, attributed to Iranian-affiliated threat actors, has targeted programmable logic controllers (PLCs) across U.S. water and wastewater systems in at least 12 states, impacting more than 30 communities in Minnesota alone. The attackers exploited internet-exposed operational technology (OT) devices—including Rockwell Automation, Schneider Electric ...
-
web:unit42.paloaltonetworks.com
Mirai is a still-active botnet with new variants. We highlight observed exploitation of IoT vulnerabilities — due to low complexity and high impact.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.joesandbox.com
General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1947932 Start date and time: 2026-07-25 16:21:32 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 4m 59s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Found strings indicative of a multi-platform dropper HTTP GET or POST without a user agent Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable Sample has stripped symbol table Uses the "uname" system call to query ...
-
web:www.yazoul.net
Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.