s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-25be409d738a9c92bce57b0c3304837b119fc1d4c7b21c8508e66fe4ea411c6b high

📛 Threat Title

Mirai: iran.m68k

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 182212 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 11:22:46.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 25be409d738a9c92bce57b0c3304837b119fc1d4c7b21c8508e66fe4ea411c6b VT 30 / 74

IOC database

Type
hash_sha256
Value
25be409d738a9c92bce57b0c3304837b119fc1d4c7b21c8508e66fe4ea411c6b
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 30 of 74 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDOS:Linux/Mirai
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Mirai-CYM [Trj]
AVG malicious ELF:Mirai-CYM [Trj]
Avira malicious TR/LINUX.Mirai.CYM
ClamAV malicious Unix.Trojan.Mirai-6981989-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Trojan.TR/LINUX.Mirai.CYM
Fortinet malicious ELF/Mirai.9821!tr
GData malicious Linux.Trojan.Gafgyt.B
huorong malicious Backdoor/Linux.Gafgyt.bs
Ikarus malicious Trojan.Linux.Mirai
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQY
Microsoft malicious Backdoor:Linux/Mirai.HF!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!AB7A0A856EF4
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!AB7A0A856EF4
TrendMicro-HouseCall malicious Backdoor.Linux.MIRAI.USBLIJ26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD5ab7a0a856ef48bcdd6ce972af1552726
SHA-14cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b
SHA-25625be409d738a9c92bce57b0c3304837b119fc1d4c7b21c8508e66fe4ea411c6b
VHash9dc6c440aa0e7ddd1c9e1f9ca54bab9a
SSDEEP3072:DhTrT9VLOeO9HVNPVfka0y1SqXHzvkmD/Wx1Zv42xVpjbibLUJV69pKf:dOXjwy11XHz8mDiN42+L0IpKf
TLSHT15D042AC7FD00DEFAF809E33744134809B130B7A254929A777257356FED3A295186BE8A
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
File size177.9 KB
History
First seen on VirusTotal2026-09-19 06:10 UTC
Last submission2026-09-19 06:10 UTC
Last analysis2026-09-19 14:24 UTC
Last modified on VirusTotal2026-09-19 16:25 UTC
Known Names
  • vm7y8tol.exe
  • m68k
  • iran.m68k
hash_md5 ab7a0a856ef48bcdd6ce972af1552726 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/ab7a0a856ef48bcdd6ce972af1552726

IOC database

Type
hash_md5
Value
ab7a0a856ef48bcdd6ce972af1552726
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/ab7a0a856ef48bcdd6ce972af1552726

hash_sha1 4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b

IOC database

Type
hash_sha1
Value
4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 182212 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 11:22:46.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:radar.offseq.com

    Detailed information about ThreatFox IOCs for 2026-07-19. Get real-time updates, technical details, and mitigation strategies.

  • web:threatfox.abuse.ch

    Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers

  • web:thrivenextgen.com

    2.1 The Iran Conflict: Strategic Cyber Implications The current military conflict involving Iran has fundamentally altered the cyber threat landscape across the Middle East and globally. Historically, Iranian military pressure has been directly coupled with escalated cyber operations — Iran's APT ecosystem functions as an instrument of state power, enabling asymmetric retaliation ...

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.hybrid-analysis.com

    Submit malware for free analysis with Falcon Sandbox and Hybrid Analysis technology. Hybrid Analysis develops and licenses analysis tools to fight malware.

  • web:www.joesandbox.com

    File: /tmp/iran.m68k.elf Jump to behavior Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/iran.m68k.elf (PID: 5518) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)

  • web:www.joesandbox.com

    Linux Analysis Report iran.m68k.elf Overview General Information ... Detection Gafgyt, Mirai

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.