MB-25be409d738a9c92bce57b0c3304837b119fc1d4c7b21c8508e66fe4ea411c6b
high
📛 Threat Title
Mirai: iran.m68k
Description
File type: elf. Size: 182212 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 11:22:46.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
25be409d738a9c92bce57b0c3304837b119fc1d4c7b21c8508e66fe4ea411c6b
VT 30 / 74
IOC database
- Type
- hash_sha256
- Value
25be409d738a9c92bce57b0c3304837b119fc1d4c7b21c8508e66fe4ea411c6b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 30 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDOS:Linux/Mirai |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | TR/LINUX.Mirai.CYM |
| ClamAV | malicious | Unix.Trojan.Mirai-6981989-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Trojan.TR/LINUX.Mirai.CYM |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Ikarus | malicious | Trojan.Linux.Mirai |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQY |
| Microsoft | malicious | Backdoor:Linux/Mirai.HF!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!AB7A0A856EF4 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!AB7A0A856EF4 |
| TrendMicro-HouseCall | malicious | Backdoor.Linux.MIRAI.USBLIJ26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | ab7a0a856ef48bcdd6ce972af1552726 |
| SHA-1 | 4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b |
| SHA-256 | 25be409d738a9c92bce57b0c3304837b119fc1d4c7b21c8508e66fe4ea411c6b |
| VHash | 9dc6c440aa0e7ddd1c9e1f9ca54bab9a |
| SSDEEP | 3072:DhTrT9VLOeO9HVNPVfka0y1SqXHzvkmD/Wx1Zv42xVpjbibLUJV69pKf:dOXjwy11XHz8mDiN42+L0IpKf |
| TLSH | T15D042AC7FD00DEFAF809E33744134809B130B7A254929A777257356FED3A295186BE8A |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped |
| File size | 177.9 KB |
History
| First seen on VirusTotal | 2026-09-19 06:10 UTC |
| Last submission | 2026-09-19 06:10 UTC |
| Last analysis | 2026-09-19 14:24 UTC |
| Last modified on VirusTotal | 2026-09-19 16:25 UTC |
Known Names
vm7y8tol.exem68kiran.m68k
hash_md5
ab7a0a856ef48bcdd6ce972af1552726
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/ab7a0a856ef48bcdd6ce972af1552726
IOC database
- Type
- hash_md5
- Value
ab7a0a856ef48bcdd6ce972af1552726- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/ab7a0a856ef48bcdd6ce972af1552726
hash_sha1
4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b
IOC database
- Type
- hash_sha1
- Value
4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/4cf3fd0238b6a7c46e10c45ea1a6ac3d11d11f7b
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 182212 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 11:22:46.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:radar.offseq.com
Detailed information about ThreatFox IOCs for 2026-07-19. Get real-time updates, technical details, and mitigation strategies.
-
web:threatfox.abuse.ch
Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers
-
web:thrivenextgen.com
2.1 The Iran Conflict: Strategic Cyber Implications The current military conflict involving Iran has fundamentally altered the cyber threat landscape across the Middle East and globally. Historically, Iranian military pressure has been directly coupled with escalated cyber operations — Iran's APT ecosystem functions as an instrument of state power, enabling asymmetric retaliation ...
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.hybrid-analysis.com
Submit malware for free analysis with Falcon Sandbox and Hybrid Analysis technology. Hybrid Analysis develops and licenses analysis tools to fight malware.
-
web:www.joesandbox.com
File: /tmp/iran.m68k.elf Jump to behavior Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/iran.m68k.elf (PID: 5518) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)
-
web:www.joesandbox.com
Linux Analysis Report iran.m68k.elf Overview General Information ... Detection Gafgyt, Mirai
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.