s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-374af9317c9ca7ed429d9ce7ef4003901aed9f36f0356c3c0af8b97351a79b4e high

📛 Threat Title

Mirai: iran.armv6l

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 169012 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 05:58:30.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 374af9317c9ca7ed429d9ce7ef4003901aed9f36f0356c3c0af8b97351a79b4e

IOC database

Type
hash_sha256
Value
374af9317c9ca7ed429d9ce7ef4003901aed9f36f0356c3c0af8b97351a79b4e
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 32b047106b11faa384605e06407992a6

IOC database

Type
hash_md5
Value
32b047106b11faa384605e06407992a6
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 dab476b2549324e87f8f8aab35ecbb86eb1b09db

IOC database

Type
hash_sha1
Value
dab476b2549324e87f8f8aab35ecbb86eb1b09db
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 169012 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 05:58:30.

Remediations (10)

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.

  • web:maltiverse.com

    Hashes Filename: iran.armv6l md5: 760402c27085d03f3ce35dde15bb4f94 sha1: fd1446b2fe5ee2c470070d34cd2b0152076f5c13 sha256: 583de6a7260791059d03c84bf58b6f01f614b2220e42c278ef3117457dc4a11e sha512: In depth details Filetype: Architecture: Compiler: Size (Bytes): Classification: malicious Mutex mutex: Dates Indexed: 2026-03-23 05:05:16 (2026-03-23 ...

  • web:undercodetesting.com

    Introduction: A coordinated cyberattack campaign, attributed to Iranian-affiliated threat actors, has targeted programmable logic controllers (PLCs) across U.S. water and wastewater systems in at least 12 states, impacting more than 30 communities in Minnesota alone. The attackers exploited internet-exposed operational technology (OT) devices—including Rockwell Automation, Schneider Electric ...

  • web:unit42.paloaltonetworks.com

    Mirai is a still-active botnet with new variants. We highlight observed exploitation of IoT vulnerabilities — due to low complexity and high impact.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.joesandbox.com

    General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1947932 Start date and time: 2026-07-25 16:21:32 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 4m 59s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Found strings indicative of a multi-platform dropper HTTP GET or POST without a user agent Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable Sample has stripped symbol table Uses the "uname" system call to query ...

  • web:www.yazoul.net

    Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.