s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-7bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff high

📛 Threat Title

Mirai: iran.i486

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 100420 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:28.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 7bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff VT 23 / 75

IOC database

Type
hash_sha256
Value
7bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 23 of 75 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Mirai-CYM [Trj]
AVG malicious ELF:Mirai-CYM [Trj]
Avira malicious TR/LINUX.Mirai.CYM
ClamAV malicious Unix.Trojan.Mirai-10056448-0
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
Elastic malicious Linux.Trojan.Mirai
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Trojan.TR/LINUX.Mirai.CYM
Fortinet malicious ELF/Mirai.9821!tr
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
Microsoft malicious Backdoor:Linux/Mirai.BU!MTB
Rising malicious Backdoor.Mirai/Linux!1.11723 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!63D793118A93
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!63D793118A93
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD563d793118a9378ecb7367a3e838f332d
SHA-10c37e97705968c9d581af3ac5e177c8929d4e4aa
SHA-2567bc4b2aef74456cca1499e1c6e3ce28827aa3c2d6e4a1f18cad547ad47e0b8ff
VHash9d6a0272b8ca2941b408019146e236a0
SSDEEP1536:rw1BTbd/0hDtZx6O/0c3Ra/oLDQ9VPJU3310vntiZvnwl7/4qKU7yHY7r:qx09tZxac3A/oLDYiClSCaY
TLSHT144A34C86FB93E0F0D94605B1111FF77D9634EE625024DE5AEBD4BEB2AD32602921B31C
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
File size98.1 KB
History
First seen on VirusTotal2026-09-07 07:53 UTC
Last submission2026-09-07 07:53 UTC
Last analysis2026-09-07 07:53 UTC
Last modified on VirusTotal2026-09-07 18:05 UTC
Known Names
  • raakkgfkc.exe
  • i486
  • iran.i486
hash_md5 63d793118a9378ecb7367a3e838f332d VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/63d793118a9378ecb7367a3e838f332d

IOC database

Type
hash_md5
Value
63d793118a9378ecb7367a3e838f332d
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/63d793118a9378ecb7367a3e838f332d

hash_sha1 0c37e97705968c9d581af3ac5e177c8929d4e4aa VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0c37e97705968c9d581af3ac5e177c8929d4e4aa

IOC database

Type
hash_sha1
Value
0c37e97705968c9d581af3ac5e177c8929d4e4aa
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0c37e97705968c9d581af3ac5e177c8929d4e4aa

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 100420 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:28.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices.

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 fa3bdf69d0bb54f6b734fb8f79c23b8f17d85764e0386b447c04870396643201. While MalwareBazaar tries to identify ...

  • web:blog.cloudflare.com

    This post offers a retrospective on Mirai , the infamous IoT botnet that disrupted major websites with massive DDoS attacks, leveraging hundreds of thousands of compromised Internet-of-Things devices.

  • web:shhaos.github.io

    These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.ic3.gov

    Iranian-affiliated APT targeting campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran, and the United States and Israel. (New, July 22, 2026) At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software.

  • web:www.joesandbox.com

    General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1896248 Start date and time: 2026-04-09 23:24:41 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 7m 27s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 16.04 x64 (Kernel 4.4.0-116, Firefox 88.0 ...

  • web:www.joesandbox.com

    System Summary Malicious sample detected (through community Yara rule) Source: iran.i486.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_3a56423b Author: unknown Source: iran.i486.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_dab39a25 Author: unknown Source: 6233.1.0000000008048000.000000000805b000.r-x.sdmp, type: MEMORY Matched rule: Linux_Trojan_Mirai_3a56423b Author: unknown Source ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.