MB-51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18
high
📛 Threat Title
Mirai: iran.armv5l
Description
File type: elf. Size: 154360 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:18.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18
IOC database
- Type
- hash_sha256
- Value
51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18
hash_md5
f3231196d4c967f538e5d9b1352d7b80
VT 32 / 75
IOC database
- Type
- hash_md5
- Value
f3231196d4c967f538e5d9b1352d7b80- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 32 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Generic.40381104 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D2682AB0 |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| BitDefender | malicious | Trojan.Generic.40381104 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Generic.Threat |
| Emsisoft | malicious | Trojan.Generic.40381104 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Backdoor:Linux/Mirai.FO!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40381104 |
| Rising | malicious | Backdoor.Mirai/Linux!1.11724 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!F3231196D4C9 |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!F3231196D4C9 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
| VIPRE | malicious | Trojan.Generic.40381104 |
Details From VirusTotal
Basic Properties
| MD5 | f3231196d4c967f538e5d9b1352d7b80 |
| SHA-1 | 5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c |
| SHA-256 | 51ac3c75c8583cffc3f61777a7af6e4b068dcf7698ab89c89a57f15fab59bf18 |
| VHash | 426177b03c790aee4e600a6d3ca1675e |
| SSDEEP | 3072:3OtstuCDxzd9TOBDZf9Qq94cZwiSXUtgKh8J7/8ZMEhB8:3+stuCDxzd9qFfDCcZwiAUtgKqJIZHh+ |
| TLSH | T1ACE30845FC518B16C6C662BBFF4E428D772A5768D3EE320399256F20378B96B0E3B141 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, version 1 (ARM), statically linked, stripped |
| File size | 150.7 KB |
History
| First seen on VirusTotal | 2026-09-07 07:55 UTC |
| Last submission | 2026-09-07 07:55 UTC |
| Last analysis | 2026-09-07 07:55 UTC |
| Last modified on VirusTotal | 2026-09-07 18:05 UTC |
Known Names
h7sh4odf.exearmv5liran.armv5l
hash_sha1
5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c
IOC database
- Type
- hash_sha1
- Value
5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/5e7931a7ce9e97f9c44f2b54b027c34c6e40ca4c
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 154360 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:18.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices.
-
web:any.run
Online sandbox report for armv5l, tagged as auto, mirai , botnet, verdict: Malicious activity
-
web:trainsec.net
Mirai Botnet ARM reverse engineering walkthrough with static analysis, key code paths, and practical notes for malware analysts. Learn more >>
-
web:westoahu.hawaii.edu
A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.
-
web:www.akamai.com
In this SIRT advisory, learn how CVE-2023-26801 was exploited in the wild to spread Mirai .
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.yazoul.net
Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
-
web:www.yazoul.net
100 new Mirai samples detected — Rising trend (17%). IOCs, hashes, C2 servers, and detection rates. View full report.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.