s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702 high

📛 Threat Title

Mirai: iran.arc

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 157332 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:30.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702

IOC database

Type
hash_sha256
Value
c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702

hash_sha1 da8eb8b4e177474723fd864087b41d785dc1615a VT 30 / 75

IOC database

Type
hash_sha1
Value
da8eb8b4e177474723fd864087b41d785dc1615a
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 30 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Mirai
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Mirai-CSC [Trj]
AVG malicious ELF:Mirai-CSC [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Mirai.EQT trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Mirai.9821!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EKD
Microsoft malicious Backdoor:Linux/Mirai.GS!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!FF69D9CD3FD0
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!FF69D9CD3FD0
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Gafgyt.C.gen!Camelot

Details From VirusTotal

Basic Properties
MD5ff69d9cd3fd005462c7c03485ced70ee
SHA-1da8eb8b4e177474723fd864087b41d785dc1615a
SHA-256c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702
VHash869444bd87201b6e689a30d0d504c423
SSDEEP3072:Fxv5yfUhfN8RtoZnGhTNLhs7LTT+RCQX3XqbpygZCBrWOG4u5Dtq:FpEfUhfW3oMJLi7L+B3a9FCBrY4Ktq
TLSHT1DBF3AF67B34B5050C4E44AF41BCF5BAD292721008E7B99E77C6E723A6A775CB28073E1
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Synopsys ARCompact ARC700 cores, version 1 (SYSV), statically linked, stripped
File size153.6 KB
History
First seen on VirusTotal2026-08-31 16:24 UTC
Last submission2026-08-31 21:19 UTC
Last analysis2026-08-31 21:19 UTC
Last modified on VirusTotal2026-08-31 23:20 UTC
Known Names
  • iran.arc
  • arc
  • 650c2b938bcbeea9a1d727505f2e7c228b348486314333dfc583b2d6f79e5dc2
  • zd73m99hf.exe
hash_md5 ff69d9cd3fd005462c7c03485ced70ee VT 30 / 75

IOC database

Type
hash_md5
Value
ff69d9cd3fd005462c7c03485ced70ee
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 30 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Mirai
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Mirai-CSC [Trj]
AVG malicious ELF:Mirai-CSC [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Mirai.EQT trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Mirai.9821!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EKD
Microsoft malicious Backdoor:Linux/Mirai.GS!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!FF69D9CD3FD0
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!FF69D9CD3FD0
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Gafgyt.C.gen!Camelot

Details From VirusTotal

Basic Properties
MD5ff69d9cd3fd005462c7c03485ced70ee
SHA-1da8eb8b4e177474723fd864087b41d785dc1615a
SHA-256c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702
VHash869444bd87201b6e689a30d0d504c423
SSDEEP3072:Fxv5yfUhfN8RtoZnGhTNLhs7LTT+RCQX3XqbpygZCBrWOG4u5Dtq:FpEfUhfW3oMJLi7L+B3a9FCBrY4Ktq
TLSHT1DBF3AF67B34B5050C4E44AF41BCF5BAD292721008E7B99E77C6E723A6A775CB28073E1
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Synopsys ARCompact ARC700 cores, version 1 (SYSV), statically linked, stripped
File size153.6 KB
History
First seen on VirusTotal2026-08-31 16:24 UTC
Last submission2026-08-31 21:19 UTC
Last analysis2026-08-31 21:19 UTC
Last modified on VirusTotal2026-08-31 23:20 UTC
Known Names
  • iran.arc
  • arc
  • 650c2b938bcbeea9a1d727505f2e7c228b348486314333dfc583b2d6f79e5dc2
  • zd73m99hf.exe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 157332 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:30.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:arxiv.org

    Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...

  • web:cybersecuritynews.com

    Mirai botnet variants target IoT devices via weak creds, driving rising DDoS threats and infecting millions worldwide.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks. It primarily targets online consumer devices such as IP cameras and home routers. [1] The Mirai botnet was first found in August 2016 [2] by MalwareMustDie, [3] a white hat malware research ...

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:www.cloudflare.com

    Learn how Mirai malware turns IoT devices running on the ARC processor and the Linux OS, into botnets. Mirai is commonly used to launch DDoS attacks, and perform click fraud.

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Found strings indicative of a multi-platform dropper Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable

  • web:www.joesandbox.com

    Behavior Graph ID: 1937812 Sample: iran.arc.elf Startdate: 06/07/2026 Architecture: LINUX Score: 80 Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.radware.com

    What is the Mirai Botnet? Mirai is a pervasive Internet-of-Things (IoT) botnet that first surfaced in 2016 and rapidly evolved into a foundational DDoS framework. By scanning for devices with default or weak credentials and installing a lightweight in-memory agent, Mirai and its descendants have mounted some of the largest and most disruptive volumetric and application-layer DDoS campaigns in ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.