MB-c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702
high
📛 Threat Title
Mirai: iran.arc
Description
File type: elf. Size: 157332 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:30.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702
IOC database
- Type
- hash_sha256
- Value
c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702
hash_sha1
da8eb8b4e177474723fd864087b41d785dc1615a
VT 30 / 75
IOC database
- Type
- hash_sha1
- Value
da8eb8b4e177474723fd864087b41d785dc1615a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 30 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Mirai |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CSC [Trj] |
| AVG | malicious | ELF:Mirai-CSC [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Mirai.EQT trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EKD |
| Microsoft | malicious | Backdoor:Linux/Mirai.GS!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!FF69D9CD3FD0 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!FF69D9CD3FD0 |
| TrendMicro | malicious | Backdoor.Linux.MIRAI.USBLHV26 |
| Varist | malicious | E32/Gafgyt.C.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | ff69d9cd3fd005462c7c03485ced70ee |
| SHA-1 | da8eb8b4e177474723fd864087b41d785dc1615a |
| SHA-256 | c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702 |
| VHash | 869444bd87201b6e689a30d0d504c423 |
| SSDEEP | 3072:Fxv5yfUhfN8RtoZnGhTNLhs7LTT+RCQX3XqbpygZCBrWOG4u5Dtq:FpEfUhfW3oMJLi7L+B3a9FCBrY4Ktq |
| TLSH | T1DBF3AF67B34B5050C4E44AF41BCF5BAD292721008E7B99E77C6E723A6A775CB28073E1 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Synopsys ARCompact ARC700 cores, version 1 (SYSV), statically linked, stripped |
| File size | 153.6 KB |
History
| First seen on VirusTotal | 2026-08-31 16:24 UTC |
| Last submission | 2026-08-31 21:19 UTC |
| Last analysis | 2026-08-31 21:19 UTC |
| Last modified on VirusTotal | 2026-08-31 23:20 UTC |
Known Names
iran.arcarc650c2b938bcbeea9a1d727505f2e7c228b348486314333dfc583b2d6f79e5dc2zd73m99hf.exe
hash_md5
ff69d9cd3fd005462c7c03485ced70ee
VT 30 / 75
IOC database
- Type
- hash_md5
- Value
ff69d9cd3fd005462c7c03485ced70ee- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 30 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Mirai |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CSC [Trj] |
| AVG | malicious | ELF:Mirai-CSC [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Mirai.EQT trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EKD |
| Microsoft | malicious | Backdoor:Linux/Mirai.GS!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!FF69D9CD3FD0 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!FF69D9CD3FD0 |
| TrendMicro | malicious | Backdoor.Linux.MIRAI.USBLHV26 |
| Varist | malicious | E32/Gafgyt.C.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | ff69d9cd3fd005462c7c03485ced70ee |
| SHA-1 | da8eb8b4e177474723fd864087b41d785dc1615a |
| SHA-256 | c05b30ad48093af5e1106d500aa72e3d3169ba8853c664e99afe8924535b9702 |
| VHash | 869444bd87201b6e689a30d0d504c423 |
| SSDEEP | 3072:Fxv5yfUhfN8RtoZnGhTNLhs7LTT+RCQX3XqbpygZCBrWOG4u5Dtq:FpEfUhfW3oMJLi7L+B3a9FCBrY4Ktq |
| TLSH | T1DBF3AF67B34B5050C4E44AF41BCF5BAD292721008E7B99E77C6E723A6A775CB28073E1 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Synopsys ARCompact ARC700 cores, version 1 (SYSV), statically linked, stripped |
| File size | 153.6 KB |
History
| First seen on VirusTotal | 2026-08-31 16:24 UTC |
| Last submission | 2026-08-31 21:19 UTC |
| Last analysis | 2026-08-31 21:19 UTC |
| Last modified on VirusTotal | 2026-08-31 23:20 UTC |
Known Names
iran.arcarc650c2b938bcbeea9a1d727505f2e7c228b348486314333dfc583b2d6f79e5dc2zd73m99hf.exe
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 157332 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:30.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:arxiv.org
Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...
-
web:cybersecuritynews.com
Mirai botnet variants target IoT devices via weak creds, driving rising DDoS threats and infecting millions worldwide.
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks. It primarily targets online consumer devices such as IP cameras and home routers. [1] The Mirai botnet was first found in August 2016 [2] by MalwareMustDie, [3] a white hat malware research ...
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:www.cloudflare.com
Learn how Mirai malware turns IoT devices running on the ARC processor and the Linux OS, into botnets. Mirai is commonly used to launch DDoS attacks, and perform click fraud.
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Found strings indicative of a multi-platform dropper Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable
-
web:www.joesandbox.com
Behavior Graph ID: 1937812 Sample: iran.arc.elf Startdate: 06/07/2026 Architecture: LINUX Score: 80 Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.radware.com
What is the Mirai Botnet? Mirai is a pervasive Internet-of-Things (IoT) botnet that first surfaced in 2016 and rapidly evolved into a foundational DDoS framework. By scanning for devices with default or weak credentials and installing a lightweight in-memory agent, Mirai and its descendants have mounted some of the largest and most disruptive volumetric and application-layer DDoS campaigns in ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.