MB-ddf8521dbe928d6d6e65e93e78cb4489f7c8b3a42c3dd052cba3bbeb47f332c2
high
📛 Threat Title
Mirai: iran.x86_64
Description
File type: elf. Size: 164272 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:37.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
ddf8521dbe928d6d6e65e93e78cb4489f7c8b3a42c3dd052cba3bbeb47f332c2
VT 28 / 75
IOC database
- Type
- hash_sha256
- Value
ddf8521dbe928d6d6e65e93e78cb4489f7c8b3a42c3dd052cba3bbeb47f332c2- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Gafgyt.BBB |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Dropper.Mirai-7540662-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Trojan.Gafgyt |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQH |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!62C4CED3DDC3 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrendMicro-HouseCall | malicious | Backdoor.Linux.GAFGYT.SMMR1 |
| Varist | malicious | E64/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 62c4ced3ddc37cc0aedf9997d86b2f46 |
| SHA-1 | 6ebb1aa6907a51f37393873d11424520c9d8edf6 |
| SHA-256 | ddf8521dbe928d6d6e65e93e78cb4489f7c8b3a42c3dd052cba3bbeb47f332c2 |
| VHash | d7fc4392055a95734f653572be6cf82b |
| SSDEEP | 3072:wQUbIcHn4VklB1Imd10qb8ODAhH4y1jFgOS1BQE:w59H/wOB2xdGQE |
| TLSH | T173F35A1279D0D4FEC8E5C2B84BEFA136DA32F4595134721F23C8AE262E5DF212B6D650 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped |
| File size | 160.4 KB |
History
| First seen on VirusTotal | 2026-08-31 16:18 UTC |
| Last submission | 2026-08-31 16:18 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:39 UTC |
Known Names
iran.x86_64rkcbhpa.exex86_64
hash_sha1
6ebb1aa6907a51f37393873d11424520c9d8edf6
VT 28 / 75
IOC database
- Type
- hash_sha1
- Value
6ebb1aa6907a51f37393873d11424520c9d8edf6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Gafgyt.BBB |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Dropper.Mirai-7540662-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Trojan.Gafgyt |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQH |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!62C4CED3DDC3 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrendMicro-HouseCall | malicious | Backdoor.Linux.GAFGYT.SMMR1 |
| Varist | malicious | E64/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 62c4ced3ddc37cc0aedf9997d86b2f46 |
| SHA-1 | 6ebb1aa6907a51f37393873d11424520c9d8edf6 |
| SHA-256 | ddf8521dbe928d6d6e65e93e78cb4489f7c8b3a42c3dd052cba3bbeb47f332c2 |
| VHash | d7fc4392055a95734f653572be6cf82b |
| SSDEEP | 3072:wQUbIcHn4VklB1Imd10qb8ODAhH4y1jFgOS1BQE:w59H/wOB2xdGQE |
| TLSH | T173F35A1279D0D4FEC8E5C2B84BEFA136DA32F4595134721F23C8AE262E5DF212B6D650 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped |
| File size | 160.4 KB |
History
| First seen on VirusTotal | 2026-08-31 16:18 UTC |
| Last submission | 2026-08-31 16:18 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:39 UTC |
Known Names
iran.x86_64rkcbhpa.exex86_64
hash_md5
62c4ced3ddc37cc0aedf9997d86b2f46
VT 28 / 75
IOC database
- Type
- hash_md5
- Value
62c4ced3ddc37cc0aedf9997d86b2f46- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Gafgyt.BBB |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Dropper.Mirai-7540662-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Elastic | malicious | Linux.Trojan.Gafgyt |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQH |
| Microsoft | malicious | Trojan:Linux/Multiverze!rfn |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!62C4CED3DDC3 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrendMicro-HouseCall | malicious | Backdoor.Linux.GAFGYT.SMMR1 |
| Varist | malicious | E64/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 62c4ced3ddc37cc0aedf9997d86b2f46 |
| SHA-1 | 6ebb1aa6907a51f37393873d11424520c9d8edf6 |
| SHA-256 | ddf8521dbe928d6d6e65e93e78cb4489f7c8b3a42c3dd052cba3bbeb47f332c2 |
| VHash | d7fc4392055a95734f653572be6cf82b |
| SSDEEP | 3072:wQUbIcHn4VklB1Imd10qb8ODAhH4y1jFgOS1BQE:w59H/wOB2xdGQE |
| TLSH | T173F35A1279D0D4FEC8E5C2B84BEFA136DA32F4595134721F23C8AE262E5DF212B6D650 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, stripped |
| File size | 160.4 KB |
History
| First seen on VirusTotal | 2026-08-31 16:18 UTC |
| Last submission | 2026-08-31 16:18 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:39 UTC |
Known Names
iran.x86_64rkcbhpa.exex86_64
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 164272 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:37.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:github.com
Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.
-
web:malpedia.caad.fkie.fraunhofer.de
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the ...
-
web:rruzi.github.io
In-depth Analysis of a New Mirai Variant 7 minute read Published: December 28, 2024 I. Background Recently, NSFOCUS [1], National Cyber Security Center (NCSC) [2], and 360 Security Brain [3] detected a batch of botnet samples that integrate the TEA algorithm for encryption based on the leaked source code of Mirai , targeting IoT/Linux devices of various architectures such as ARM, MIPS, and x86 ...
-
web:unit42.paloaltonetworks.com
We discovered ongoing attacks leveraging IoT vulnerabilities, including in network security devices, to serve a Mirai variant.
-
web:unit42.paloaltonetworks.com
Mirai is a still-active botnet with new variants. We highlight observed exploitation of IoT vulnerabilities — due to low complexity and high impact.
-
web:www.joesandbox.com
Linux Analysis Report iran.x86_64.elf Overview General Information ... Detection Gafgyt, Mirai
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.