MB-7bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff
high
📛 Threat Title
Mirai: iran.i486
Description
File type: elf. Size: 100420 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:28.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff
VT 23 / 75
IOC database
- Type
- hash_sha256
- Value
7bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 23 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | TR/LINUX.Mirai.CYM |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Trojan.Mirai |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Trojan.TR/LINUX.Mirai.CYM |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Microsoft | malicious | Backdoor:Linux/Mirai.BU!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.11723 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!63D793118A93 |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!63D793118A93 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 63d793118a9378ecb7367a3e838f332d |
| SHA-1 | 0c37e97705968c9d581af3ac5e177c8929d4e4aa |
| SHA-256 | 7bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff |
| VHash | 9d6a0272b8ca2941b408019146e236a0 |
| SSDEEP | 1536:rw1BTbd/0hDtZx6O/0c3Ra/oLDQ9VPJU3310vntiZvnwl7/4qKU7yHY7r:qx09tZxac3A/oLDYiClSCaY |
| TLSH | T144A34C86FB93E0F0D94605B1111FF77D9634EE625024DE5AEBD4BEB2AD32602921B31C |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped |
| File size | 98.1 KB |
History
| First seen on VirusTotal | 2026-09-07 07:53 UTC |
| Last submission | 2026-09-07 07:53 UTC |
| Last analysis | 2026-09-07 07:53 UTC |
| Last modified on VirusTotal | 2026-09-07 18:05 UTC |
Known Names
raakkgfkc.exei486iran.i486
hash_md5
63d793118a9378ecb7367a3e838f332d
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/63d793118a9378ecb7367a3e838f332d
IOC database
- Type
- hash_md5
- Value
63d793118a9378ecb7367a3e838f332d- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/63d793118a9378ecb7367a3e838f332d
hash_sha1
0c37e97705968c9d581af3ac5e177c8929d4e4aa
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0c37e97705968c9d581af3ac5e177c8929d4e4aa
IOC database
- Type
- hash_sha1
- Value
0c37e97705968c9d581af3ac5e177c8929d4e4aa- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0c37e97705968c9d581af3ac5e177c8929d4e4aa
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 100420 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:28.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices.
-
web:bazaar.abuse.ch
You are currently viewing the MalwareBazaar entry for SHA256 fa3bdf69d0bb54f6b734fb8f79c23b8f17d85764e0386b447c04870396643201. While MalwareBazaar tries to identify ...
-
web:blog.cloudflare.com
This post offers a retrospective on Mirai , the infamous IoT botnet that disrupted major websites with massive DDoS attacks, leveraging hundreds of thousands of compromised Internet-of-Things devices.
-
web:shhaos.github.io
These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:westoahu.hawaii.edu
A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.
-
web:www.ic3.gov
Iranian-affiliated APT targeting campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran, and the United States and Israel. (New, July 22, 2026) At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software.
-
web:www.joesandbox.com
General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1896248 Start date and time: 2026-04-09 23:24:41 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 7m 27s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0 ...
-
web:www.joesandbox.com
System Summary Malicious sample detected (through community Yara rule) Source: iran.i486.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_3a56423b Author: unknown Source: iran.i486.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown Source: 6233.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_3a56423b Author: unknown Source ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.