s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19 high

📛 Threat Title

Mirai: iran.armv4l

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 157368 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:46:53.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19

IOC database

Type
hash_sha256
Value
a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19

hash_sha1 5f982f9b1b5a6185d9c6e033247e3e0aba902475 VT 26 / 74

IOC database

Type
hash_sha1
Value
5f982f9b1b5a6185d9c6e033247e3e0aba902475
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 26 of 74 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Mirai-CYM [Trj]
AVG malicious ELF:Mirai-CYM [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-10056448-0
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
Elastic malicious Linux.Generic.Threat
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.WN!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Ikarus malicious Linux.Bot
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
McAfeeD malicious Trojan:Linux/Mirai.EQQ
Microsoft malicious Trojan:Linux/Mirai.Z!MTB
Rising malicious Backdoor.Mirai/Linux!1.11724 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!909FC3854E4C
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!909FC3854E4C
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD5909fc3854e4c3a6951403e93ab887e93
SHA-15f982f9b1b5a6185d9c6e033247e3e0aba902475
SHA-256a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19
VHash426177b03c790aee4e600a6d3ca1675e
SSDEEP3072:1GpaNJnxpej2YmzCD2N2ijwPR4JzpQNqNcjGxv8:1GpaNJnxpejq/sijwPSJzpSqKGxv8
TLSHT150F30755BD519B16C6C262BBFF4D428C7B2A1768D2EE3103DD296F20378B96B0E3B141
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
File size153.7 KB
History
First seen on VirusTotal2026-09-19 06:03 UTC
Last submission2026-09-19 06:03 UTC
Last analysis2026-09-19 06:03 UTC
Last modified on VirusTotal2026-09-19 11:16 UTC
Known Names
  • qfjgu.exe
  • armv4l
  • 433364439
hash_md5 909fc3854e4c3a6951403e93ab887e93 VT 26 / 74

IOC database

Type
hash_md5
Value
909fc3854e4c3a6951403e93ab887e93
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 26 of 74 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Mirai-CYM [Trj]
AVG malicious ELF:Mirai-CYM [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-10056448-0
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
Elastic malicious Linux.Generic.Threat
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.WN!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Ikarus malicious Linux.Bot
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
McAfeeD malicious Trojan:Linux/Mirai.EQQ
Microsoft malicious Trojan:Linux/Mirai.Z!MTB
Rising malicious Backdoor.Mirai/Linux!1.11724 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!909FC3854E4C
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!909FC3854E4C
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD5909fc3854e4c3a6951403e93ab887e93
SHA-15f982f9b1b5a6185d9c6e033247e3e0aba902475
SHA-256a0bcb0034f6e546b1a386c3848019277f39717eaa629c5bb9df539f0b3244a19
VHash426177b03c790aee4e600a6d3ca1675e
SSDEEP3072:1GpaNJnxpej2YmzCD2N2ijwPR4JzpQNqNcjGxv8:1GpaNJnxpejq/sijwPSJzpSqKGxv8
TLSHT150F30755BD519B16C6C262BBFF4D428C7B2A1768D2EE3103DD296F20378B96B0E3B141
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
File size153.7 KB
History
First seen on VirusTotal2026-09-19 06:03 UTC
Last submission2026-09-19 06:03 UTC
Last analysis2026-09-19 06:03 UTC
Last modified on VirusTotal2026-09-19 11:16 UTC
Known Names
  • qfjgu.exe
  • armv4l
  • 433364439

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 157368 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:46:53.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:any.run

    Online sandbox report for armv4l, tagged as auto, mirai , botnet, verdict: Malicious activity

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    Kimwolf-IOCS / iran.armv4l Syn2Much Captured Mirai variants attempting to spread through port 5555 7890d68 · 5 months ago History 151 KB

  • web:maltiverse.com

    Hashes Filename: iran.armv4l md5: 7cfe783644890e8714cb248113499af0 sha1: 192ad5e58666c4c1f5c56c9e9565096826233ca9 sha256: 2a878369fc31716e19c37b89a0dcbd2569c536672ab085624edc6f45aca20cc3 sha512: In depth details Filetype: Architecture: Compiler: Size (Bytes): Classification: malicious Mutex mutex: Dates Indexed: 2026-04-06 08:22:25 (2026-04-06 ...

  • web:threatfox.abuse.ch

    Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.joesandbox.com

    Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

  • web:www.yazoul.net

    Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.