MB-a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19
high
📛 Threat Title
Mirai: iran.armv4l
Description
File type: elf. Size: 157368 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:46:53.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19
IOC database
- Type
- hash_sha256
- Value
a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19
hash_sha1
5f982f9b1b5a6185d9c6e033247e3e0aba902475
VT 26 / 74
IOC database
- Type
- hash_sha1
- Value
5f982f9b1b5a6185d9c6e033247e3e0aba902475- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Generic.Threat |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Ikarus | malicious | Linux.Bot |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Trojan:Linux/Mirai.Z!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.11724 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!909FC3854E4C |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!909FC3854E4C |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 909fc3854e4c3a6951403e93ab887e93 |
| SHA-1 | 5f982f9b1b5a6185d9c6e033247e3e0aba902475 |
| SHA-256 | a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19 |
| VHash | 426177b03c790aee4e600a6d3ca1675e |
| SSDEEP | 3072:1GpaNJnxpej2YmzCD2N2ijwPR4JzpQNqNcjGxv8:1GpaNJnxpejq/sijwPSJzpSqKGxv8 |
| TLSH | T150F30755BD519B16C6C262BBFF4D428C7B2A1768D2EE3103DD296F20378B96B0E3B141 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped |
| File size | 153.7 KB |
History
| First seen on VirusTotal | 2026-09-19 06:03 UTC |
| Last submission | 2026-09-19 06:03 UTC |
| Last analysis | 2026-09-19 06:03 UTC |
| Last modified on VirusTotal | 2026-09-19 11:16 UTC |
Known Names
qfjgu.exearmv4l433364439
hash_md5
909fc3854e4c3a6951403e93ab887e93
VT 26 / 74
IOC database
- Type
- hash_md5
- Value
909fc3854e4c3a6951403e93ab887e93- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Generic.Threat |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Ikarus | malicious | Linux.Bot |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Trojan:Linux/Mirai.Z!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.11724 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!909FC3854E4C |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!909FC3854E4C |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 909fc3854e4c3a6951403e93ab887e93 |
| SHA-1 | 5f982f9b1b5a6185d9c6e033247e3e0aba902475 |
| SHA-256 | a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19 |
| VHash | 426177b03c790aee4e600a6d3ca1675e |
| SSDEEP | 3072:1GpaNJnxpej2YmzCD2N2ijwPR4JzpQNqNcjGxv8:1GpaNJnxpejq/sijwPSJzpSqKGxv8 |
| TLSH | T150F30755BD519B16C6C262BBFF4D428C7B2A1768D2EE3103DD296F20378B96B0E3B141 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped |
| File size | 153.7 KB |
History
| First seen on VirusTotal | 2026-09-19 06:03 UTC |
| Last submission | 2026-09-19 06:03 UTC |
| Last analysis | 2026-09-19 06:03 UTC |
| Last modified on VirusTotal | 2026-09-19 11:16 UTC |
Known Names
qfjgu.exearmv4l433364439
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 157368 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:46:53.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:any.run
Online sandbox report for armv4l, tagged as auto, mirai , botnet, verdict: Malicious activity
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:github.com
Kimwolf-IOCS / iran.armv4l Syn2Much Captured Mirai variants attempting to spread through port 5555 7890d68 · 5 months ago History 151 KB
-
web:maltiverse.com
Hashes Filename: iran.armv4l md5: 7cfe783644890e8714cb248113499af0 sha1: 192ad5e58666c4c1f5c56c9e9565096826233ca9 sha256: 2a878369fc31716e19c37b89a0dcbd2569c536672ab085624edc6f45aca20cc3 sha512: In depth details Filetype: Architecture: Compiler: Size (Bytes): Classification: malicious Mutex mutex: Dates Indexed: 2026-04-06 08:22:25 (2026-04-06 ...
-
web:threatfox.abuse.ch
Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
-
web:www.joesandbox.com
Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
-
web:www.yazoul.net
Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.