s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-76fc3352f925411aaed817a6e00d4e3c467d2765f533966560693bc7dc3f8e11 high

📛 Threat Title

Mirai: iran.mipsrouter

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 246187 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-06 20:32:59.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 76fc3352f925411aaed817a6e00d4e3c467d2765f533966560693bc7dc3f8e11

IOC database

Type
hash_sha256
Value
76fc3352f925411aaed817a6e00d4e3c467d2765f533966560693bc7dc3f8e11
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 5917aa985b962245bf83b9107fd19d54eb990f7f

IOC database

Type
hash_sha1
Value
5917aa985b962245bf83b9107fd19d54eb990f7f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 dc599e2e98cb5f28d33919df0719fd07

IOC database

Type
hash_md5
Value
dc599e2e98cb5f28d33919df0719fd07
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 246187 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-06 20:32:59.

Remediations (10)

  • web:cyberpress.org

    U.S. federal agencies have issued an urgent warning that Iranian-affiliated threat actors are targeting internet-exposed programmable logic controllers (PLCs) used across critical infrastructure. The activity has disrupted industrial operations by tampering with PLC project files and altering information shown to operators through human-machine interface (HMI) and supervisory control and data ...

  • web:cybersecuritynews.com

    Iran-linked hackers target exposed PLCs in U.S. critical infrastructure, altering control logic in water, energy, and government systems.

  • web:cybersecuritynews.com

    A new wave of cyberattacks has surfaced, with a Mirai -based botnet exploiting a number of significant vulnerabilities in routers and smart devices.

  • web:dailysecurityreview.com

    A new Mirai botnet is using zero-day exploits to target industrial routers and smart home devices, launching high-intensity DDoS attacks. Learn about the vulnerabilities and how to protect your systems.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.cisa.gov

    WASHINGTON - The Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Environmental Protection Agency (EPA) and other U.S. government partners published an update today to a joint Cybersecurity Advisory, originally published in April 2026, Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers (PLC) Across US Critical Infrastructure ...

  • web:www.joesandbox.com

    Uses the "uname" system call to query kernel version information (possible evasion)

  • web:www.techtimes.com

    Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.