MB-f692af11faa6ec2919d9269d28c7a962ee970f6199e92ad85676255bd5f8b91c
high
📛 Threat Title
Mirai: iran.armv4l
Description
File type: elf. Size: 157400 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:18.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
f692af11faa6ec2919d9269d28c7a962ee970f6199e92ad85676255bd5f8b91c
VT 25 / 75
IOC database
- Type
- hash_sha256
- Value
f692af11faa6ec2919d9269d28c7a962ee970f6199e92ad85676255bd5f8b91c- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 25 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Generic.40381028 |
| Antiy-AVL | malicious | Trojan/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D2682A64 |
| Avira | malicious | EXP/ELF.Mirai.W |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Generic.Threat |
| Emsisoft | malicious | Trojan.Generic.40381028 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Trojan:Linux/Mirai.Z!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40381028 |
| Rising | malicious | Backdoor.Mirai/Linux!1.11724 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
| VIPRE | malicious | Trojan.Generic.40381028 |
Details From VirusTotal
Basic Properties
| MD5 | 5925ca46e3f602f92b96abbf242989c9 |
| SHA-1 | ae2ed7ec46196ea2d5430cd67e4d605b61bf2b1f |
| SHA-256 | f692af11faa6ec2919d9269d28c7a962ee970f6199e92ad85676255bd5f8b91c |
| VHash | 426177b03c790aee4e600a6d3ca1675e |
| SSDEEP | 3072:smpaNJnxpej0LmzYqNyB6wvk4JX1DRextqziQcS:smpaNJnxpejlVwB6wvxJX1teH+iQcS |
| TLSH | T1DCF30745BD518B16C6D262BBFF4D428C7B2A1768D3EE31039D295F60378B96B0E3B142 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped |
| File size | 153.7 KB |
History
| First seen on VirusTotal | 2026-09-07 07:53 UTC |
| Last submission | 2026-09-07 07:53 UTC |
| Last analysis | 2026-09-07 07:53 UTC |
| Last modified on VirusTotal | 2026-09-07 20:29 UTC |
Known Names
51nq0uo.exearmv4liran.armv4l
hash_md5
5925ca46e3f602f92b96abbf242989c9
VT 25 / 75
IOC database
- Type
- hash_md5
- Value
5925ca46e3f602f92b96abbf242989c9- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 25 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Generic.40381028 |
| Antiy-AVL | malicious | Trojan/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D2682A64 |
| Avira | malicious | EXP/ELF.Mirai.W |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Generic.Threat |
| Emsisoft | malicious | Trojan.Generic.40381028 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Trojan:Linux/Mirai.Z!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40381028 |
| Rising | malicious | Backdoor.Mirai/Linux!1.11724 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
| VIPRE | malicious | Trojan.Generic.40381028 |
Details From VirusTotal
Basic Properties
| MD5 | 5925ca46e3f602f92b96abbf242989c9 |
| SHA-1 | ae2ed7ec46196ea2d5430cd67e4d605b61bf2b1f |
| SHA-256 | f692af11faa6ec2919d9269d28c7a962ee970f6199e92ad85676255bd5f8b91c |
| VHash | 426177b03c790aee4e600a6d3ca1675e |
| SSDEEP | 3072:smpaNJnxpej0LmzYqNyB6wvk4JX1DRextqziQcS:smpaNJnxpejlVwB6wvxJX1teH+iQcS |
| TLSH | T1DCF30745BD518B16C6D262BBFF4D428C7B2A1768D3EE31039D295F60378B96B0E3B142 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped |
| File size | 153.7 KB |
History
| First seen on VirusTotal | 2026-09-07 07:53 UTC |
| Last submission | 2026-09-07 07:53 UTC |
| Last analysis | 2026-09-07 07:53 UTC |
| Last modified on VirusTotal | 2026-09-07 20:29 UTC |
Known Names
51nq0uo.exearmv4liran.armv4l
hash_sha1
ae2ed7ec46196ea2d5430cd67e4d605b61bf2b1f
VT 25 / 75
IOC database
- Type
- hash_sha1
- Value
ae2ed7ec46196ea2d5430cd67e4d605b61bf2b1f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 25 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Generic.40381028 |
| Antiy-AVL | malicious | Trojan/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D2682A64 |
| Avira | malicious | EXP/ELF.Mirai.W |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Generic.Threat |
| Emsisoft | malicious | Trojan.Generic.40381028 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Trojan:Linux/Mirai.Z!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40381028 |
| Rising | malicious | Backdoor.Mirai/Linux!1.11724 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
| VIPRE | malicious | Trojan.Generic.40381028 |
Details From VirusTotal
Basic Properties
| MD5 | 5925ca46e3f602f92b96abbf242989c9 |
| SHA-1 | ae2ed7ec46196ea2d5430cd67e4d605b61bf2b1f |
| SHA-256 | f692af11faa6ec2919d9269d28c7a962ee970f6199e92ad85676255bd5f8b91c |
| VHash | 426177b03c790aee4e600a6d3ca1675e |
| SSDEEP | 3072:smpaNJnxpej0LmzYqNyB6wvk4JX1DRextqziQcS:smpaNJnxpejlVwB6wvxJX1teH+iQcS |
| TLSH | T1DCF30745BD518B16C6D262BBFF4D428C7B2A1768D3EE31039D295F60378B96B0E3B142 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped |
| File size | 153.7 KB |
History
| First seen on VirusTotal | 2026-09-07 07:53 UTC |
| Last submission | 2026-09-07 07:53 UTC |
| Last analysis | 2026-09-07 07:53 UTC |
| Last modified on VirusTotal | 2026-09-07 20:29 UTC |
Known Names
51nq0uo.exearmv4liran.armv4l
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 157400 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:18.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices.
-
web:any.run
Online sandbox report for armv4l, tagged as auto, mirai , botnet, verdict: Malicious activity
-
web:en.wikipedia.org
Toggle the table of contents Mirai (malware)
-
web:github.com
Kimwolf-IOCS / iran.armv4l Syn2Much Captured Mirai variants attempting to spread through port 5555 7890d68 · 5 months ago History 151 KB
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.akamai.com
Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
-
web:www.joesandbox.com
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.