MB-6e7d98f590da5a91bf0285d31002b80fb373a88aa1c355e63da5f6a4bd8f46c1
high
📛 Threat Title
Mirai: boatnet.arm7
Description
File type: elf. Size: 170150 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 21:16:59.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
6e7d98f590da5a91bf0285d31002b80fb373a88aa1c355e63da5f6a4bd8f46c1
IOC database
- Type
- hash_sha256
- Value
6e7d98f590da5a91bf0285d31002b80fb373a88aa1c355e63da5f6a4bd8f46c1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
f83615174d6e2cfe488fbf076310baf2b131cdbb
IOC database
- Type
- hash_sha1
- Value
f83615174d6e2cfe488fbf076310baf2b131cdbb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
4afa66fb709cfb1bd01ecc5d93cd2ac1
IOC database
- Type
- hash_md5
- Value
4afa66fb709cfb1bd01ecc5d93cd2ac1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 170150 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 21:16:59.
Remediations (10)
-
web:any.run
Online sandbox report for boatnet.arm7 , tagged as auto, mirai , botnet, verdict: Malicious activity
-
web:cyberpress.org
Remote, unauthenticated attackers are able to inject arbitrary system commands, enabling full device compromise without user interaction. Investigation revealed that threat actors are leveraging the compromised endpoint to download and execute Mirai -based ARM malware, notably a variant referred to as "LZRD" (typically named boatnet.arm7 ). Upon execution, this Mirai variant displays a ...
-
web:trainsec.net
Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...
-
web:tria.ge
Check this mirai report boatnet[.]arm7 , with a score of 10 out of 10.
-
web:tria.ge
Check this mirai report boatnet[.]arm7[.]elf, with a score of 10 out of 10.
-
web:westoahu.hawaii.edu
A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.
-
web:www.akamai.com
Conclusion Mirai -based botnets continue to be a call for divorce for many organizations, and the prevalence of outdated IoT devices help propagate this threat. Like security researchers, some threat actors keep up to date on the latest vulnerability disclosures relevant to their illicit activities.
-
web:www.akamai.com
Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .
-
web:www.joesandbox.com
Source: boatnet.arm7.elf Submission file: segment LOAD with 7.9534 entropy (max. 8.0) Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) ... May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Malicious sample detected (through community Yara rule) Yara detected Mirai Contains symbols with names commonly found in malware Sample tries to kill multiple processes (SIGKILL) Creates hidden files and/or directories
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.