s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e high

📛 Threat Title

Mirai: iran.mipsel

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 211648 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:38.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e

IOC database

Type
hash_sha256
Value
2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e

hash_sha1 2a9a1f1502dd1f328ba2d7b653e91f7191f9c3b5 VT 26 / 75

IOC database

Type
hash_sha1
Value
2a9a1f1502dd1f328ba2d7b653e91f7191f9c3b5
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 26 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Gafgyt.BBB
Antiy-AVL malicious GrayWare[AdWare]/Linux.Puwaders
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.LT!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Linux.Backdoor.Agent.ei
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQH
Microsoft malicious Backdoor:Linux/Multiverze!rfn
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!1DF2EDBD0C04
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!1DF2EDBD0C04
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD51df2edbd0c044d11c6889d19001083db
SHA-12a9a1f1502dd1f328ba2d7b653e91f7191f9c3b5
SHA-2562865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e
VHashfd8d61116e2bf5a724a94e7a3be4ff8d
SSDEEP3072:PN/6gT7DbU28Mn0NawZ5aMBjv+7GYNRtO1:PNND1f08wZ5Fj6GY3tO
TLSHT1C624C60AAF610FFBD8AFDD3746E90B0635CC650722A83B3A3674D924F54A54B49D3C68
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
File size206.7 KB
History
First seen on VirusTotal2026-08-31 16:18 UTC
Last submission2026-08-31 16:18 UTC
Last analysis2026-08-31 18:03 UTC
Last modified on VirusTotal2026-08-31 23:44 UTC
Known Names
  • mipsel
  • 4iyuahcd4.exe
  • iran.mipsel
hash_md5 1df2edbd0c044d11c6889d19001083db VT 26 / 75

IOC database

Type
hash_md5
Value
1df2edbd0c044d11c6889d19001083db
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 26 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Gafgyt.BBB
Antiy-AVL malicious GrayWare[AdWare]/Linux.Puwaders
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.LT!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Linux.Backdoor.Agent.ei
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQH
Microsoft malicious Backdoor:Linux/Multiverze!rfn
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!1DF2EDBD0C04
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!1DF2EDBD0C04
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD51df2edbd0c044d11c6889d19001083db
SHA-12a9a1f1502dd1f328ba2d7b653e91f7191f9c3b5
SHA-2562865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e
VHashfd8d61116e2bf5a724a94e7a3be4ff8d
SSDEEP3072:PN/6gT7DbU28Mn0NawZ5aMBjv+7GYNRtO1:PNND1f08wZ5Fj6GY3tO
TLSHT1C624C60AAF610FFBD8AFDD3746E90B0635CC650722A83B3A3674D924F54A54B49D3C68
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
File size206.7 KB
History
First seen on VirusTotal2026-08-31 16:18 UTC
Last submission2026-08-31 16:18 UTC
Last analysis2026-08-31 18:03 UTC
Last modified on VirusTotal2026-08-31 23:44 UTC
Known Names
  • mipsel
  • 4iyuahcd4.exe
  • iran.mipsel

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 211648 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:38.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:arxiv.org

    Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:rruzi.github.io

    In-depth Analysis of a New Mirai Variant 7 minute read Published: December 28, 2024 I. Background Recently, NSFOCUS [1], National Cyber Security Center (NCSC) [2], and 360 Security Brain [3] detected a batch of botnet samples that integrate the TEA algorithm for encryption based on the leaked source code of Mirai , targeting IoT/Linux devices of various architectures such as ARM, MIPS, and x86 ...

  • web:threatfox.abuse.ch

    Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers

  • web:www.ic3.gov

    Iranian-affiliated APT targeting campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran, and the United States and Israel. (New, July 22, 2026) At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software.

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.sciencedirect.com

    In the specific context of Mirai botnet detection and mitigation , several approaches have been presented in the literature. Some works focus on studying the behavior of the Mirai botnet, examining and monitoring its propagation and impact within networked systems [85], [86], [87].

  • web:www.semanticscholar.org

    This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.