MB-402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5
high
📛 Threat Title
Mirai: iran.mipsel
Description
File type: elf. Size: 211616 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:36:48.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5
VT 29 / 74
IOC database
- Type
- hash_sha256
- Value
402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 29 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.LT!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Ikarus | malicious | Trojan.Linux.Gafgyt |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.ERM |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!144197A390E6 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!144197A390E6 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R002H06IJ26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 144197a390e6336dd0e832e7095e145b |
| SHA-1 | bd9cc610ea3280830b520c7fbd9554672951f49d |
| SHA-256 | 402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5 |
| VHash | fd8d61116e2bf5a724a94e7a3be4ff8d |
| SSDEEP | 3072:K/+gojDrAjMsbpqTIKRsqjPt7qD8pfNoh:K4DgDgTIKRj1qDgfNo |
| TLSH | T1EC24C50AAF610FFBD8AFDD3746E90B0235CC650722A83B3A3674D924F54A54B49D3C68 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped |
| File size | 206.7 KB |
History
| First seen on VirusTotal | 2026-09-19 06:02 UTC |
| Last submission | 2026-09-19 06:02 UTC |
| Last analysis | 2026-09-19 23:22 UTC |
| Last modified on VirusTotal | 2026-09-19 23:25 UTC |
Known Names
tb66x.exemipsel433364447
hash_sha1
bd9cc610ea3280830b520c7fbd9554672951f49d
VT 29 / 74
IOC database
- Type
- hash_sha1
- Value
bd9cc610ea3280830b520c7fbd9554672951f49d- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 29 of 74 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.LT!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Ikarus | malicious | Trojan.Linux.Gafgyt |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.ERM |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!144197A390E6 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!144197A390E6 |
| TrendMicro-HouseCall | malicious | TROJ_GEN.R002H06IJ26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 144197a390e6336dd0e832e7095e145b |
| SHA-1 | bd9cc610ea3280830b520c7fbd9554672951f49d |
| SHA-256 | 402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5 |
| VHash | fd8d61116e2bf5a724a94e7a3be4ff8d |
| SSDEEP | 3072:K/+gojDrAjMsbpqTIKRsqjPt7qD8pfNoh:K4DgDgTIKRj1qDgfNo |
| TLSH | T1EC24C50AAF610FFBD8AFDD3746E90B0235CC650722A83B3A3674D924F54A54B49D3C68 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped |
| File size | 206.7 KB |
History
| First seen on VirusTotal | 2026-09-19 06:02 UTC |
| Last submission | 2026-09-19 06:02 UTC |
| Last analysis | 2026-09-19 23:22 UTC |
| Last modified on VirusTotal | 2026-09-19 23:25 UTC |
Known Names
tb66x.exemipsel433364447
hash_md5
144197a390e6336dd0e832e7095e145b
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/144197a390e6336dd0e832e7095e145b
IOC database
- Type
- hash_md5
- Value
144197a390e6336dd0e832e7095e145b- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/144197a390e6336dd0e832e7095e145b
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 211616 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:36:48.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:maltiverse.com
Hashes Filename: iran.mipsel md5: 4a5a5b500a26471264171e76addc13b0 sha1: 6c79a0a60851e2edc7f3321e93d99f9b7ffdad93 sha256: a069d39c3027613df89acf77c57d19fc05b1ddb8fa1429f3b9ce6213260e3d75 sha512: In depth details Filetype: Architecture: Compiler: Size (Bytes): Classification: malicious Mutex mutex: Dates Indexed: 2026-03-06 15:41:39 (2026-03-06 ...
-
web:threatfox.abuse.ch
Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers
-
web:thrivenextgen.com
2.1 The Iran Conflict: Strategic Cyber Implications The current military conflict involving Iran has fundamentally altered the cyber threat landscape across the Middle East and globally. Historically, Iranian military pressure has been directly coupled with escalated cyber operations — Iran's APT ecosystem functions as an instrument of state power, enabling asymmetric retaliation ...
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.akamai.com
Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
-
web:www.joesandbox.com
Linux Analysis Report iran.mipsel.elf Overview General Information ... Detection Gafgyt, Mirai
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.