MB-a8ae2492cac7901938e1e12b81d858b96f9b10609bda4678dfb63a0be56473e7
high
📛 Threat Title
Mirai: data_powerpc
Description
File type: elf. Size: 129776 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:57:39.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
a8ae2492cac7901938e1e12b81d858b96f9b10609bda4678dfb63a0be56473e7
IOC database
- Type
- hash_sha256
- Value
a8ae2492cac7901938e1e12b81d858b96f9b10609bda4678dfb63a0be56473e7- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
c6090d84f3ccccd3d3902921f640dfc9
IOC database
- Type
- hash_md5
- Value
c6090d84f3ccccd3d3902921f640dfc9- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
2ffb8b05eb6f599abf3dae5e6eb5e6f07289aeca
IOC database
- Type
- hash_sha1
- Value
2ffb8b05eb6f599abf3dae5e6eb5e6f07289aeca- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 129776 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-08-04 21:57:39.
Remediations (10)
-
web:cve.armis.com
This CVE describes a race that could cause a kernel crash on PowerPC systems when a PCI device is removed during the EEH reporting flow (eeh_pe_report_edev). The mitigation involves holding the PCI rescan/remove lock while copying the bus reference from edev->pdev to avoid edev->pdev changing mid-operation.
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:github.com
Cross-Architecture Mirai Configuration Extractor Utilizing Standalone Ghidra Script - iij/ mirai -toushi
-
web:github.com
Malware Analysis Lab — Mirai Botnet (ELF/PowerPC) Static analysis of a real Mirai botnet sample targeting IoT devices (PowerPC architecture).
-
web:link.springer.com
Following the public release of its source code in 2016, numerous variants have proliferated, broadening its attack surface and complicating detection and mitigation efforts. Despite extensive research on Mirai , existing analyses remain fragmented and informal, lacking a structured representation of its attack patterns.
-
web:securityarsenal.com
JPCERT/CC FY2025 data highlights persistent Mirai -like scanning activity targeting TCP/23. Immediate remediation of exposed Telnet services is critical.
-
web:tidyverse.org
We're excited to announce mirai 2.5.0, bringing production-grade async computing to R! This milestone release delivers enhanced observability through OpenTelemetry, reproducible parallel RNG, and key user interface improvements. We've also packed in twice as many changes as usual - going all out in delivering a round of quality-of-life fixes to make your use of mirai even smoother! You can ...
-
web:www.joesandbox.com
Source: mirai .powerpc.elf, type: SAMPLE Matched rule: Linux_Trojan_Mirai_0bce98a2 reference_sample = 1b20df8df7f84ad29d81ccbe276f49a6488c2214077b13da858656c027531c80
-
web:www.sciencedirect.com
The target of Mirai was Linux-based IoT devices that operate in various processor architectures such as advanced reduced instruction set computer (RISC) machine (ARM), microprocessor without interlocked pipeline stages (MIPS), and PowerPC (PPC) through cross-compilation.
-
web:www.techtimes.com
Tengu botnet, a newly disclosed Mirai variant, weaponizes the hardware watchdog timer in routers and IP cameras to force a reboot when a responder kills the process — erasing forensic evidence ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.