s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18 high

📛 Threat Title

Mirai: iran.armv5l

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 154360 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:18.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18

IOC database

Type
hash_sha256
Value
51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18

hash_md5 f3231196d4c967f538e5d9b1352d7b80 VT 32 / 75

IOC database

Type
hash_md5
Value
f3231196d4c967f538e5d9b1352d7b80
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 32 of 75 VirusTotal vendors

VendorVerdictDetection
ALYac malicious Trojan.Generic.40381104
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Arcabit malicious Trojan.Generic.D2682AB0
Avast malicious ELF:Mirai-CYM [Trj]
AVG malicious ELF:Mirai-CYM [Trj]
Avira malicious EXP/ELF.Mirai.W
BitDefender malicious Trojan.Generic.40381104
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.generic
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
Elastic malicious Linux.Generic.Threat
Emsisoft malicious Trojan.Generic.40381104 (B)
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.WN!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
McAfeeD malicious Trojan:Linux/Mirai.EQQ
Microsoft malicious Backdoor:Linux/Mirai.FO!MTB
MicroWorld-eScan malicious Trojan.Generic.40381104
Rising malicious Backdoor.Mirai/Linux!1.11724 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!F3231196D4C9
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!F3231196D4C9
Varist malicious E32/Mirai.EN.gen!Camelot
VIPRE malicious Trojan.Generic.40381104

Details From VirusTotal

Basic Properties
MD5f3231196d4c967f538e5d9b1352d7b80
SHA-15e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c
SHA-25651ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18
VHash426177b03c790aee4e600a6d3ca1675e
SSDEEP3072:3OtstuCDxzd9TOBDZf9Qq94cZwiSXUtgKh8J7/8ZMEhB8:3+stuCDxzd9qFfDCcZwiAUtgKqJIZHh+
TLSHT1ACE30845FC518B16C6C662BBFF4E428D772A5768D3EE320399256F20378B96B0E3B141
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped
File size150.7 KB
History
First seen on VirusTotal2026-09-07 07:55 UTC
Last submission2026-09-07 07:55 UTC
Last analysis2026-09-07 07:55 UTC
Last modified on VirusTotal2026-09-07 18:05 UTC
Known Names
  • h7sh4odf.exe
  • armv5l
  • iran.armv5l
hash_sha1 5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c

IOC database

Type
hash_sha1
Value
5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 154360 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:18.

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.