MB-7a553ff8a21360626d7e41dff11d66f20490e1a2bace4f6f42393ddbafc1ba6a
high
📛 Threat Title
Mirai: bot.mipsel
Description
File type: elf. Size: 1141864 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:58:36.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7a553ff8a21360626d7e41dff11d66f20490e1a2bace4f6f42393ddbafc1ba6a
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/7a553ff8a21360626d7e41dff11d66f20490e1a2bace4f6f42393ddbafc1ba6a
IOC database
- Type
- hash_sha256
- Value
7a553ff8a21360626d7e41dff11d66f20490e1a2bace4f6f42393ddbafc1ba6a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/7a553ff8a21360626d7e41dff11d66f20490e1a2bace4f6f42393ddbafc1ba6a
hash_sha1
eece0d5b5a3cc9a8269a0c261b14a879bca1727c
VT 24 / 75
IOC database
- Type
- hash_sha1
- Value
eece0d5b5a3cc9a8269a0c261b14a879bca1727c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 24 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Gen:Variant.Linux.Gafgyt.13 |
| Antiy-AVL | malicious | Trojan[Exploit]/Linux.CVE-2018-10561 |
| Arcabit | malicious | Trojan.Linux.Gafgyt.13 |
| Avast | malicious | ELF:CVE-2021-36260-A [Expl] |
| Avast-Mobile | malicious | ELF:Mirai-QL [Trj] |
| AVG | malicious | ELF:CVE-2021-36260-A [Expl] |
| Avira | malicious | EXP/LINUX.CVE-2021-.A |
| BitDefender | malicious | Gen:Variant.Linux.Gafgyt.13 |
| CTX | malicious | elf.unknown.gafgyt |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Rootkit.420 |
| Emsisoft | malicious | Gen:Variant.Linux.Gafgyt.13 (B) |
| ESET-NOD32 | malicious | Linux/Mirai.FLD trojan |
| F-Secure | malicious | Exploit.EXP/LINUX.CVE-2021-.A |
| Fortinet | malicious | Linux/Mirai.REAL!tr |
| GData | malicious | Gen:Variant.Linux.Gafgyt.13 |
| huorong | malicious | Trojan/Linux.Mirai.f |
| Kaspersky | malicious | HEUR:Exploit.Linux.CVE-2018-10561.a |
| Microsoft | malicious | Backdoor:Linux/Gafgyt.BA!xp |
| MicroWorld-eScan | malicious | Gen:Variant.Linux.Gafgyt.13 |
| Rising | malicious | Backdoor.Mirai/Linux!1.BAFE (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| Tencent | malicious | Backdoor.Linux.Mirai.yar |
| VIPRE | malicious | Gen:Variant.Linux.Gafgyt.13 |
Details From VirusTotal
Basic Properties
| MD5 | ae84136792c29e620ed3d7c113be8084 |
| SHA-1 | eece0d5b5a3cc9a8269a0c261b14a879bca1727c |
| SHA-256 | 7a553ff8a21360626d7e41dff11d66f20490e1a2bace4f6f42393ddbafc1ba6a |
| VHash | 571c3e4bc2d0ca1bf150f8c3a7511a53 |
| SSDEEP | 24576:7BVL2UCtekP9MiCWKu/LoZespTm4C+xTCnOKW84:qUCBVUnusklMxTCnz4 |
| TLSH | T17D356C46EF406FEBC09FCD30492EC35721EDE8CA42C5A62971FC4A8C7A5D3594AD3698 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), statically linked, for GNU/Linux 3.2.0, not stripped |
| File size | 1.1 MB |
History
| First seen on VirusTotal | 2026-09-25 11:01 UTC |
| Last submission | 2026-09-25 11:01 UTC |
| Last analysis | 2026-09-25 11:01 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
qgg7kvq9.exebot.mipsel.elf
hash_md5
ae84136792c29e620ed3d7c113be8084
VT 24 / 75
IOC database
- Type
- hash_md5
- Value
ae84136792c29e620ed3d7c113be8084- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 24 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Gen:Variant.Linux.Gafgyt.13 |
| Antiy-AVL | malicious | Trojan[Exploit]/Linux.CVE-2018-10561 |
| Arcabit | malicious | Trojan.Linux.Gafgyt.13 |
| Avast | malicious | ELF:CVE-2021-36260-A [Expl] |
| Avast-Mobile | malicious | ELF:Mirai-QL [Trj] |
| AVG | malicious | ELF:CVE-2021-36260-A [Expl] |
| Avira | malicious | EXP/LINUX.CVE-2021-.A |
| BitDefender | malicious | Gen:Variant.Linux.Gafgyt.13 |
| CTX | malicious | elf.unknown.gafgyt |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Rootkit.420 |
| Emsisoft | malicious | Gen:Variant.Linux.Gafgyt.13 (B) |
| ESET-NOD32 | malicious | Linux/Mirai.FLD trojan |
| F-Secure | malicious | Exploit.EXP/LINUX.CVE-2021-.A |
| Fortinet | malicious | Linux/Mirai.REAL!tr |
| GData | malicious | Gen:Variant.Linux.Gafgyt.13 |
| huorong | malicious | Trojan/Linux.Mirai.f |
| Kaspersky | malicious | HEUR:Exploit.Linux.CVE-2018-10561.a |
| Microsoft | malicious | Backdoor:Linux/Gafgyt.BA!xp |
| MicroWorld-eScan | malicious | Gen:Variant.Linux.Gafgyt.13 |
| Rising | malicious | Backdoor.Mirai/Linux!1.BAFE (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| Tencent | malicious | Backdoor.Linux.Mirai.yar |
| VIPRE | malicious | Gen:Variant.Linux.Gafgyt.13 |
Details From VirusTotal
Basic Properties
| MD5 | ae84136792c29e620ed3d7c113be8084 |
| SHA-1 | eece0d5b5a3cc9a8269a0c261b14a879bca1727c |
| SHA-256 | 7a553ff8a21360626d7e41dff11d66f20490e1a2bace4f6f42393ddbafc1ba6a |
| VHash | 571c3e4bc2d0ca1bf150f8c3a7511a53 |
| SSDEEP | 24576:7BVL2UCtekP9MiCWKu/LoZespTm4C+xTCnOKW84:qUCBVUnusklMxTCnz4 |
| TLSH | T17D356C46EF406FEBC09FCD30492EC35721EDE8CA42C5A62971FC4A8C7A5D3594AD3698 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), statically linked, for GNU/Linux 3.2.0, not stripped |
| File size | 1.1 MB |
History
| First seen on VirusTotal | 2026-09-25 11:01 UTC |
| Last submission | 2026-09-25 11:01 UTC |
| Last analysis | 2026-09-25 11:01 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
qgg7kvq9.exebot.mipsel.elf
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 1141864 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:58:36.
Remediations (10)
-
web:arxiv.org
Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.
-
web:dailysecurityreview.com
The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.
-
web:foresiet.com
The Mirai botnet, first unleashed in 2016, continues to evolve into increasingly sophisticated variants, posing severe risks to the Internet of Things (IoT) ecosystem. This report examines the Jackskid Botnet—a newly identified Mirai derivative—characterized by its aggressive propagation via zero-day exploits and brute-force attacks, resulting in daily active bot IPs surpassing 40,000 as ...
-
web:shhaos.github.io
The service simulated a Mirai -infected device and communi-cated with the C2 server using a custom bot-to-C2 proto-col, which was reverse engineered from malware samples prior to source code release.
-
web:westoahu.hawaii.edu
Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.
-
web:www.cisecurity.org
The Mirai botnet soon spread to infect thousands of internet of things (IoT) devices and evolved to conduct full, large-scale attacks. After noticing an increase in infections, Mirai caught the attention of the nonprofit organization MalwareMustDie in August 2016, who then started to research, analyze, and track the botnet [2].
-
web:www.indusface.com
How Does AppTrana Defend Against the Mirai Botnet? AppTrana WAAP provides robust defence against DDoS attacks carried out by Mirai and other botnets. It protects websites and APIs from DDoS threats by using a combination of real-time traffic filtering, bot detection, rate limiting, and behaviour analysis.
-
web:www.merit.edu
Abstract The Mirai botnet, composed primarily of embedded and IoT devices, took the Internet by storm in late 2016 when it overwhelmed several high-profile targets with massive distributed denial-of-service (DDoS) attacks. In this paper, we provide a seven-month retrospective anal-ysis of Mirai's growth to a peak of 600k infections and a history of its DDoS victims. By combining a variety of ...
-
web:www.sciencedirect.com
In the specific context of Mirai botnet detection and mitigation , several approaches have been presented in the literature. Some works focus on studying the behavior of the Mirai botnet, examining and monitoring its propagation and impact within networked systems [85], [86], [87].
-
web:www.threatintelreport.com
Campaign type Mirai -based botnet propagation via command injection and buffer overflow Exploitation status Observed in the wild Severity Critical Patch / mitigation status Available for n8n since December 2025; Tenda firmware updates recommended Sectors at risk Organisations using self-hosted automation platforms and exposed IoT routers Regions ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.