s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-6e7d98f590da5a91bf0285d31002b80fb373a88aa1c355e63da5f6a4bd8f46c1 high

📛 Threat Title

Mirai: boatnet.arm7

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 170150 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 21:16:59.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 6e7d98f590da5a91bf0285d31002b80fb373a88aa1c355e63da5f6a4bd8f46c1

IOC database

Type
hash_sha256
Value
6e7d98f590da5a91bf0285d31002b80fb373a88aa1c355e63da5f6a4bd8f46c1
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 f83615174d6e2cfe488fbf076310baf2b131cdbb

IOC database

Type
hash_sha1
Value
f83615174d6e2cfe488fbf076310baf2b131cdbb
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 4afa66fb709cfb1bd01ecc5d93cd2ac1

IOC database

Type
hash_md5
Value
4afa66fb709cfb1bd01ecc5d93cd2ac1
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 170150 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-08-04 21:16:59.

Remediations (10)

  • web:any.run

    Online sandbox report for boatnet.arm7 , tagged as auto, mirai , botnet, verdict: Malicious activity

  • web:cyberpress.org

    Remote, unauthenticated attackers are able to inject arbitrary system commands, enabling full device compromise without user interaction. Investigation revealed that threat actors are leveraging the compromised endpoint to download and execute Mirai -based ARM malware, notably a variant referred to as "LZRD" (typically named boatnet.arm7 ). Upon execution, this Mirai variant displays a ...

  • web:trainsec.net

    Final Thoughts: A Call to Continuous Mastery Unpacking an ARM-based Mirai sample exemplifies the thrill and challenge of modern cybersecurity work. As IoT devices and Linux-based systems become more ubiquitous in enterprise networks, staying on top of evolving threats is essential. Take this as your motivation to keep refining your reverse engineering, malware analysis, and forensics ...

  • web:tria.ge

    Check this mirai report boatnet[.]arm7 , with a score of 10 out of 10.

  • web:tria.ge

    Check this mirai report boatnet[.]arm7[.]elf, with a score of 10 out of 10.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.akamai.com

    Conclusion Mirai -based botnets continue to be a call for divorce for many organizations, and the prevalence of outdated IoT devices help propagate this threat. Like security researchers, some threat actors keep up to date on the latest vulnerability disclosures relevant to their illicit activities.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    Source: boatnet.arm7.elf Submission file: segment LOAD with 7.9534 entropy (max. 8.0) Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) ... May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Malicious sample detected (through community Yara rule) Yara detected Mirai Contains symbols with names commonly found in malware Sample tries to kill multiple processes (SIGKILL) Creates hidden files and/or directories

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.