s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-6b0f0118ddee42acf3daf0208b1ddc36e0038704d6e7193af0483066a69afd11 high

📛 Threat Title

Mirai: iran.x86_64

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 164272 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-06 20:32:58.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 6b0f0118ddee42acf3daf0208b1ddc36e0038704d6e7193af0483066a69afd11

IOC database

Type
hash_sha256
Value
6b0f0118ddee42acf3daf0208b1ddc36e0038704d6e7193af0483066a69afd11
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 7a8944748762030dd4c7b633c9e01f206105c4b8

IOC database

Type
hash_sha1
Value
7a8944748762030dd4c7b633c9e01f206105c4b8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 9143e638be77b59ba81232f7d9094966

IOC database

Type
hash_md5
Value
9143e638be77b59ba81232f7d9094966
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 164272 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-06 20:32:58.

Remediations (10)

  • web:any.run

    Online sandbox report for iran.x86_64 , tagged as mirai , botnet, ddos, gafgyt, verdict: Malicious activity

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    Executes the "rm" command used to delete files or directories

  • web:www.joesandbox.com

    Linux Analysis Report iran.x86_64.elf Overview General Information ... Detection Gafgyt, Mirai

  • web:www.pwndefend.com

    We pulled the x86-64 build and analysed it statically — no execution. It is a lean (67 KB) statically-linked, stripped ELF with the .ctors /.dtors layout and encoded-string table characteristic of the Mirai family.

  • web:www.techtimes.com

    Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...

  • web:www.zero-day.cz

    Zero-day (0day) vulnerability tracking project database. All zero-day vulnerabilities since 2006.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.