s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5 high

📛 Threat Title

Mirai: iran.mipsel

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 211616 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:36:48.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5 VT 29 / 74

IOC database

Type
hash_sha256
Value
402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 29 of 74 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Mirai-CYM [Trj]
AVG malicious ELF:Mirai-CYM [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.LT!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Ikarus malicious Trojan.Linux.Gafgyt
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.ERM
Microsoft malicious Trojan:Linux/Multiverze!rfn
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!144197A390E6
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!144197A390E6
TrendMicro-HouseCall malicious TROJ_GEN.R002H06IJ26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD5144197a390e6336dd0e832e7095e145b
SHA-1bd9cc610ea3280830b520c7fbd9554672951f49d
SHA-256402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5
VHashfd8d61116e2bf5a724a94e7a3be4ff8d
SSDEEP3072:K/+gojDrAjMsbpqTIKRsqjPt7qD8pfNoh:K4DgDgTIKRj1qDgfNo
TLSHT1EC24C50AAF610FFBD8AFDD3746E90B0235CC650722A83B3A3674D924F54A54B49D3C68
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
File size206.7 KB
History
First seen on VirusTotal2026-09-19 06:02 UTC
Last submission2026-09-19 06:02 UTC
Last analysis2026-09-19 23:22 UTC
Last modified on VirusTotal2026-09-19 23:25 UTC
Known Names
  • tb66x.exe
  • mipsel
  • 433364447
hash_sha1 bd9cc610ea3280830b520c7fbd9554672951f49d VT 29 / 74

IOC database

Type
hash_sha1
Value
bd9cc610ea3280830b520c7fbd9554672951f49d
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 29 of 74 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Mirai-CYM [Trj]
AVG malicious ELF:Mirai-CYM [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.LT!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Ikarus malicious Trojan.Linux.Gafgyt
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.ERM
Microsoft malicious Trojan:Linux/Multiverze!rfn
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Skyhigh malicious LINUX/Mirai-FPL!144197A390E6
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrellixENS malicious LINUX/Mirai-FPL!144197A390E6
TrendMicro-HouseCall malicious TROJ_GEN.R002H06IJ26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD5144197a390e6336dd0e832e7095e145b
SHA-1bd9cc610ea3280830b520c7fbd9554672951f49d
SHA-256402987e53dd5e2b3c3aac8093b717de0a4b642d2e8b88518fde9b68b2ffd0da5
VHashfd8d61116e2bf5a724a94e7a3be4ff8d
SSDEEP3072:K/+gojDrAjMsbpqTIKRsqjPt7qD8pfNoh:K4DgDgTIKRj1qDgfNo
TLSHT1EC24C50AAF610FFBD8AFDD3746E90B0235CC650722A83B3A3674D924F54A54B49D3C68
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped
File size206.7 KB
History
First seen on VirusTotal2026-09-19 06:02 UTC
Last submission2026-09-19 06:02 UTC
Last analysis2026-09-19 23:22 UTC
Last modified on VirusTotal2026-09-19 23:25 UTC
Known Names
  • tb66x.exe
  • mipsel
  • 433364447
hash_md5 144197a390e6336dd0e832e7095e145b VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/144197a390e6336dd0e832e7095e145b

IOC database

Type
hash_md5
Value
144197a390e6336dd0e832e7095e145b
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/144197a390e6336dd0e832e7095e145b

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 211616 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-19 10:36:48.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:maltiverse.com

    Hashes Filename: iran.mipsel md5: 4a5a5b500a26471264171e76addc13b0 sha1: 6c79a0a60851e2edc7f3321e93d99f9b7ffdad93 sha256: a069d39c3027613df89acf77c57d19fc05b1ddb8fa1429f3b9ce6213260e3d75 sha512: In depth details Filetype: Architecture: Compiler: Size (Bytes): Classification: malicious Mutex mutex: Dates Indexed: 2026-03-06 15:41:39 (2026-03-06 ...

  • web:threatfox.abuse.ch

    Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers

  • web:thrivenextgen.com

    2.1 The Iran Conflict: Strategic Cyber Implications The current military conflict involving Iran has fundamentally altered the cyber threat landscape across the Middle East and globally. Historically, Iranian military pressure has been directly coupled with escalated cyber operations — Iran's APT ecosystem functions as an instrument of state power, enabling asymmetric retaliation ...

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.joesandbox.com

    Linux Analysis Report iran.mipsel.elf Overview General Information ... Detection Gafgyt, Mirai

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.