s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-e0b150c4d0bed9180963b29642e4d541a71bb0cecfcd850a7aae54cb4730a48b high

📛 Threat Title

Mirai: iran.powerpc

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 158924 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 05:58:34.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 e0b150c4d0bed9180963b29642e4d541a71bb0cecfcd850a7aae54cb4730a48b

IOC database

Type
hash_sha256
Value
e0b150c4d0bed9180963b29642e4d541a71bb0cecfcd850a7aae54cb4730a48b
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 d921bc6b0c7c549a5c75d482ef77800f

IOC database

Type
hash_md5
Value
d921bc6b0c7c549a5c75d482ef77800f
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 d8a0ee968fcbf37616f4e88ace18fd9728173047

IOC database

Type
hash_sha1
Value
d8a0ee968fcbf37616f4e88ace18fd9728173047
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 158924 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 05:58:34.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:any.run

    Online sandbox report for iran.powerpc , tagged as auto, mirai , botnet, verdict: Malicious activity

  • web:maltiverse.com

    Filename: iran.powerpc md5: 6f64a9e2f890db0bc2dbf45ca283814d sha1: cfbcc78b6f014eef19353dbcc7bc446c6db533a3 sha256: 0ed6e7b9ef5bfe8367a747b87d3abc2a32977262a474c06dc82b5cc9ce20267f sha512: In depth details Filetype: elf Architecture: Compiler: Size (Bytes): Classification: malicious Mutex mutex: Dates Indexed: 2025-12-30 21:39:37 (2025-12-30 21 ...

  • web:maltiverse.com

    Hashes Filename: iran.powerpc md5: 90d758a392a304984983d17396f1a06a sha1: b8c9088dab72a866978e3cdd60f5d75da79eda15 sha256: 6ed3d010b652e550ac99d4b147503795133ca0f610046ae95f8b3750bec3b2f9 sha512: In depth details Filetype: Architecture: Compiler: Size (Bytes): Classification: malicious Mutex mutex: Dates Indexed: 2026-04-22 16:23:20 (2026-04-22 ...

  • web:threatfox.abuse.ch

    Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.joesandbox.com

    Found malware configuration Multi AV Scanner detection for submitted file Yara detected Gafgyt Yara detected Mirai Drops files in suspicious directories Sample tries to set files in /etc globally writable Detected TCP or UDP traffic on non-standard ports Enumerates processes within the "proc" file system Found strings indicative of a multi ...

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.yazoul.net

    Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.