MB-2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e
high
📛 Threat Title
Mirai: iran.mipsel
Description
File type: elf. Size: 211648 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:38.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e
IOC database
- Type
- hash_sha256
- Value
2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e
hash_sha1
2a9a1f1502dd1f328ba2d7b653e91f7191f9c3b5
VT 26 / 75
IOC database
- Type
- hash_sha1
- Value
2a9a1f1502dd1f328ba2d7b653e91f7191f9c3b5- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Gafgyt.BBB |
| Antiy-AVL | malicious | GrayWare[AdWare]/Linux.Puwaders |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.LT!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Linux.Backdoor.Agent.ei |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQH |
| Microsoft | malicious | Backdoor:Linux/Multiverze!rfn |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!1DF2EDBD0C04 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!1DF2EDBD0C04 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 1df2edbd0c044d11c6889d19001083db |
| SHA-1 | 2a9a1f1502dd1f328ba2d7b653e91f7191f9c3b5 |
| SHA-256 | 2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e |
| VHash | fd8d61116e2bf5a724a94e7a3be4ff8d |
| SSDEEP | 3072:PN/6gT7DbU28Mn0NawZ5aMBjv+7GYNRtO1:PNND1f08wZ5Fj6GY3tO |
| TLSH | T1C624C60AAF610FFBD8AFDD3746E90B0635CC650722A83B3A3674D924F54A54B49D3C68 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped |
| File size | 206.7 KB |
History
| First seen on VirusTotal | 2026-08-31 16:18 UTC |
| Last submission | 2026-08-31 16:18 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:44 UTC |
Known Names
mipsel4iyuahcd4.exeiran.mipsel
hash_md5
1df2edbd0c044d11c6889d19001083db
VT 26 / 75
IOC database
- Type
- hash_md5
- Value
1df2edbd0c044d11c6889d19001083db- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 26 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Gafgyt.BBB |
| Antiy-AVL | malicious | GrayWare[AdWare]/Linux.Puwaders |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.LT!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Linux.Backdoor.Agent.ei |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQH |
| Microsoft | malicious | Backdoor:Linux/Multiverze!rfn |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!1DF2EDBD0C04 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!1DF2EDBD0C04 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 1df2edbd0c044d11c6889d19001083db |
| SHA-1 | 2a9a1f1502dd1f328ba2d7b653e91f7191f9c3b5 |
| SHA-256 | 2865abd41c17e7c2ca709d3eb1379c1f0d131aad747f7a5ca35d1577aaa8d51e |
| VHash | fd8d61116e2bf5a724a94e7a3be4ff8d |
| SSDEEP | 3072:PN/6gT7DbU28Mn0NawZ5aMBjv+7GYNRtO1:PNND1f08wZ5Fj6GY3tO |
| TLSH | T1C624C60AAF610FFBD8AFDD3746E90B0635CC650722A83B3A3674D924F54A54B49D3C68 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped |
| File size | 206.7 KB |
History
| First seen on VirusTotal | 2026-08-31 16:18 UTC |
| Last submission | 2026-08-31 16:18 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:44 UTC |
Known Names
mipsel4iyuahcd4.exeiran.mipsel
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 211648 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:38.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:arxiv.org
Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:rruzi.github.io
In-depth Analysis of a New Mirai Variant 7 minute read Published: December 28, 2024 I. Background Recently, NSFOCUS [1], National Cyber Security Center (NCSC) [2], and 360 Security Brain [3] detected a batch of botnet samples that integrate the TEA algorithm for encryption based on the leaked source code of Mirai , targeting IoT/Linux devices of various architectures such as ARM, MIPS, and x86 ...
-
web:threatfox.abuse.ch
Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers
-
web:www.ic3.gov
Iranian-affiliated APT targeting campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran, and the United States and Israel. (New, July 22, 2026) At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software.
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
-
web:www.sciencedirect.com
In the specific context of Mirai botnet detection and mitigation , several approaches have been presented in the literature. Some works focus on studying the behavior of the Mirai botnet, examining and monitoring its propagation and impact within networked systems [85], [86], [87].
-
web:www.semanticscholar.org
This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.