MB-dfe708e560b26a38d6f633e4faadcd86cf387456f5e2d3753b1ccdf946d3291d
high
📛 Threat Title
Mirai: x86
Description
File type: elf. Size: 7270584 bytes. Tags: DDoSAgent, elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-15 11:41:14.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
dfe708e560b26a38d6f633e4faadcd86cf387456f5e2d3753b1ccdf946d3291d
1 feed
IOC database
- Type
- hash_sha256
- Value
dfe708e560b26a38d6f633e4faadcd86cf387456f5e2d3753b1ccdf946d3291d- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
55b16183d78879cf04e57674490d3566442e35f4
VT 36 / 75
1 feed
IOC database
- Type
- hash_sha1
- Value
55b16183d78879cf04e57674490d3566442e35f4- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 36 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Agent.JJ |
| ALYac | malicious | Trojan.Generic.40035855 |
| Antiy-AVL | malicious | Trojan/Linux.Multiverze |
| Arcabit | malicious | Trojan.Linux.DDoS.423 |
| Avast | malicious | ELF:DDOSAgent-FN [Rtk] |
| AVG | malicious | ELF:DDOSAgent-FN [Rtk] |
| Avira | malicious | TR/LINUX.DDOSAgent.GA |
| BitDefender | malicious | Trojan.Linux.DDoS.423 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056451-0 |
| CTX | malicious | elf.trojan.multiverze |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.DDoS.2724 |
| Emsisoft | malicious | Trojan.Linux.DDoS.423 (B) |
| ESET-NOD32 | malicious | Linux/DDoS.Agent.JH trojan |
| F-Secure | malicious | Trojan.TR/LINUX.DDOSAgent.GA |
| Fortinet | malicious | Linux/DDoS_Agent.JH!tr |
| GData | malicious | Trojan.Linux.DDoS.423 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.DDos.bv |
| Jiangmin | malicious | Backdoor.Multi.gl |
| K7GW | malicious | Trojan ( 00410f2e1 ) |
| Kaspersky | malicious | HEUR:Trojan-DDoS.Linux.Agent.av |
| Kingsoft | malicious | Linux.Trojan-DDoS.Agent.av |
| Lionic | malicious | Trojan.Linux.DDoS.9!c |
| McAfeeD | malicious | Trojan:Script/GenericY.FB |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Trojan.Linux.DDoS.423 |
| Rising | malicious | Malware.Undefined!8.C (TFE:28:eMo3vhtDMsO) |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Trojan.Gen.NPE |
| Tencent | malicious | Malware.Linux.Generic.1c08079a |
| TrendMicro | malicious | Trojan.Linux.MULTIVERZE.TL0101EG26ZZ |
| TrendMicro-HouseCall | malicious | Trojan.Linux.MULTIVERZE.TL0101EG26ZZ |
| Varist | malicious | E32/ABTrojan.CJYW- |
| VIPRE | malicious | Trojan.Linux.DDoS.423 |
Details From VirusTotal
Basic Properties
| MD5 | 9caf86ae923db92ef657275aaff52d08 |
| SHA-1 | 55b16183d78879cf04e57674490d3566442e35f4 |
| SHA-256 | dfe708e560b26a38d6f633e4faadcd86cf387456f5e2d3753b1ccdf946d3291d |
| VHash | bed0051c03c0b002224d3a09f64bb907 |
| SSDEEP | 49152:ZDcg444mBP+v3bUbRSkJiZu50cwOXT2VDDD4EvEuN2SD8LJ+WUGQEl/mCLpK5ELf:d+4vq3QbRSP9ODiDoEv3mvg7ELf |
| TLSH | T15B762711FE8B50F2E9031D3105ABB26F63325D054F29EBE3EA407F29F97B691193A149 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, BuildID[sha1]=efb19ac3bd86957073dae79e1edf9e4590100413, stripped |
| File size | 6.9 MB |
History
| First seen on VirusTotal | 2026-05-14 22:28 UTC |
| Last submission | 2026-05-15 12:02 UTC |
| Last analysis | 2026-06-15 11:07 UTC |
| Last modified on VirusTotal | 2026-06-19 09:49 UTC |
Known Names
i686x86dfe708e560b26a38d6f633e4faadcd86cf387456f5e2d3753b1ccdf946d3291d.elf15x0x.exe42lwji45.202.247.123_sample.bin1duoo5mzp7ucbqo8j34ht9k30.exe
hash_md5
9caf86ae923db92ef657275aaff52d08
1 feed
IOC database
- Type
- hash_md5
- Value
9caf86ae923db92ef657275aaff52d08- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 7270584 bytes. Tags: DDoSAgent, elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-15 11:41:14.
Remediations (10)
-
web:arxiv.org
Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:elie.net
These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:media.defense.gov
Summary The Federal Bureau of Investigation (FBI), Cyber National Mission Force (CNMF), and National Security Agency (NSA) assess that People's Republic of China (PRC)-linked cyber actors have compromised thousands of Internet-connected devices, including small office/home office (SOHO) routers, firewalls, network-attached storage (NAS) and Internet of Things (IoT) devices with the goal of ...
-
web:rruzi.github.io
In-depth Analysis of a New Mirai Variant 7 minute read Published: December 28, 2024 I. Background Recently, NSFOCUS [1], National Cyber Security Center (NCSC) [2], and 360 Security Brain [3] detected a batch of botnet samples that integrate the TEA algorithm for encryption based on the leaked source code of Mirai , targeting IoT/Linux devices of various architectures such as ARM, MIPS, and x86 ...
-
web:securityaffairs.com
A Mirai variant called Nexcorium exploits a flaw in TBK DVRs to infect devices and use them in DDoS attacks, along with outdated TP-Link routers.
-
web:thehackernews.com
Cybersecurity researchers have exposed a new Mirai -derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist them in a network capable of carrying out distributed denial-of-service (DDoS) attacks.
-
web:www.akamai.com
Conclusion Mirai -based botnets continue to be a call for divorce for many organizations, and the prevalence of outdated IoT devices help propagate this threat. Like security researchers, some threat actors keep up to date on the latest vulnerability disclosures relevant to their illicit activities.
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.