MB-179a46eef9e1da06ecc371f6ed9c6b220a0f2c725440fdac696976aebdf7ab48
high
📛 Threat Title
Mirai: iran.mips
Description
File type: elf. Size: 209344 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:36:47.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
179a46eef9e1da06ecc371f6ed9c6b220a0f2c725440fdac696976aebdf7ab48
VT 22 / 74
IOC database
- Type
- hash_sha256
- Value
179a46eef9e1da06ecc371f6ed9c6b220a0f2c725440fdac696976aebdf7ab48- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 22 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-8041698-0 |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Ikarus | malicious | Trojan.Linux.MiraiTR |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.ERM |
| Microsoft | malicious | Backdoor:Linux/Mirai.GL!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | aa67c1c3474b7981205b00bd39832512 |
| SHA-1 | b03dff7a65d1d466bd0e5656d45d8378ba26b9be |
| SHA-256 | 179a46eef9e1da06ecc371f6ed9c6b220a0f2c725440fdac696976aebdf7ab48 |
| VHash | fc7e3765fca30728af4e7f15eb3a548f |
| SSDEEP | 3072:xvPriLe76ygG4jOn9zPZidj9BJA4AnpSrObgr4:xLiLe76pG4jeBGjJwpSrwgr4 |
| TLSH | T18A14855E6A328F7DF368873447B74A34975D22D627E1DA84E2ACC1041F6434E681FFA8 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped |
| File size | 204.4 KB |
History
| First seen on VirusTotal | 2026-09-19 06:10 UTC |
| Last submission | 2026-09-19 06:10 UTC |
| Last analysis | 2026-09-19 06:10 UTC |
| Last modified on VirusTotal | 2026-09-19 11:08 UTC |
Known Names
a4anvr.exerehuaocn.exemipsiran.mips
hash_sha1
b03dff7a65d1d466bd0e5656d45d8378ba26b9be
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/b03dff7a65d1d466bd0e5656d45d8378ba26b9be
IOC database
- Type
- hash_sha1
- Value
b03dff7a65d1d466bd0e5656d45d8378ba26b9be- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/b03dff7a65d1d466bd0e5656d45d8378ba26b9be
hash_md5
aa67c1c3474b7981205b00bd39832512
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/aa67c1c3474b7981205b00bd39832512
IOC database
- Type
- hash_md5
- Value
aa67c1c3474b7981205b00bd39832512- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/aa67c1c3474b7981205b00bd39832512
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 209344 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:36:47.
Remediations (10)
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:tria.ge
Check this report iran [.]mips [.]elf, with a score of 1 out of 10.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:westoahu.hawaii.edu
Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.
-
web:www.joesandbox.com
Uses the "uname" system call to query kernel version information (possible evasion)
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Sample deletes itself Detected TCP or UDP traffic on non-standard ports Enumerates processes within the "proc" file system Sample has stripped symbol table Tries to connect to HTTP servers, but all servers are down (expired dropper behavior) Uses the "uname" system call to query kernel ...
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.yazoul.net
Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.