MB-49b66b6e2b723bdc5517672393d0c691155bc4d41c9d12de4c0201dfad1a4009
high
📛 Threat Title
Mirai: mips
Description
File type: elf. Size: 156180 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-15 10:34:41.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
49b66b6e2b723bdc5517672393d0c691155bc4d41c9d12de4c0201dfad1a4009
1 feed
IOC database
- Type
- hash_sha256
- Value
49b66b6e2b723bdc5517672393d0c691155bc4d41c9d12de4c0201dfad1a4009- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
25bc8344bb9aaca4e7f0523eb2864dfa6890086e
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/25bc8344bb9aaca4e7f0523eb2864dfa6890086e
1 feed
IOC database
- Type
- hash_sha1
- Value
25bc8344bb9aaca4e7f0523eb2864dfa6890086e- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/25bc8344bb9aaca4e7f0523eb2864dfa6890086e
hash_md5
f45c9a3b7587679d8321cbbf55daa233
VT 33 / 75
1 feed
IOC database
- Type
- hash_md5
- Value
f45c9a3b7587679d8321cbbf55daa233- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 33 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Mirai.EYP |
| ALYac | malicious | Trojan.Generic.39963098 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D261C9DA |
| Avast | malicious | ELF:Mirai-AJJ [PUP] |
| AVG | malicious | ELF:Mirai-AJJ [PUP] |
| Avira | malicious | EXP/ELF.Agent.J.8 |
| BitDefender | malicious | Trojan.Generic.39963098 |
| CAT-QuickHeal | malicious | Elf.Trojan.A25688682 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Siggen.12522 |
| Emsisoft | malicious | Trojan.Generic.39963098 (B) |
| ESET-NOD32 | malicious | Linux/Mirai.EVZ trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Agent.J.8 |
| Fortinet | malicious | ELF/Mirai.B!tr |
| GData | malicious | Trojan.Generic.39963098 |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Mirai.ao!crit |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Mirai.gen |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.ERC |
| Microsoft | malicious | Trojan:Linux/Mirai.Y!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.39963098 |
| Rising | malicious | Backdoor.Mirai/Linux!8.13285 (CLOUD) |
| Sangfor | malicious | Backdoor.Linux.Mirai.V6pq |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Malware.Linux.Generic.1c0818ea |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLEP26 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLEP26 |
| Varist | malicious | E32/Mirai.DZ.gen!Eldorado |
| VIPRE | malicious | Trojan.Generic.39963098 |
Details From VirusTotal
Basic Properties
| MD5 | f45c9a3b7587679d8321cbbf55daa233 |
| SHA-1 | 25bc8344bb9aaca4e7f0523eb2864dfa6890086e |
| SHA-256 | 49b66b6e2b723bdc5517672393d0c691155bc4d41c9d12de4c0201dfad1a4009 |
| VHash | fc7e3765fca30728af4e7f15eb3a548f |
| SSDEEP | 3072:RjHqrVJNmdLGHZlw1mmUBUIb2Z9OwxRfiZ1DhENpxuA8SSsyq44gnQ2pR:sVzmdLGHZl+mmUBZ2nOwxhiZ1tygAHQz |
| TLSH | T1FBE3C50E2E258F7CF3A8C73847B38A35936923D636E1C645E17CE5122E6424D645FFA8 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, stripped |
| File size | 152.5 KB |
History
| First seen on VirusTotal | 2026-05-15 10:52 UTC |
| Last submission | 2026-05-15 10:52 UTC |
| Last analysis | 2026-06-15 11:10 UTC |
| Last modified on VirusTotal | 2026-06-17 22:51 UTC |
Known Names
49b66b6e2b723bdc5517672393d0c691155bc4d41c9d12de4c0201dfad1a4009.elfmips7toysl.exe193.32.162.218_sample.bin
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 156180 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-15 10:34:41.
Remediations (10)
-
web:arxiv.org
Angela Famera, Ben Hilger, Suman Bhunia, Patrick Heil Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several vari-ants that combined the old code ...
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:redpiranha.net
6. Recommendations for Mitigation Patch Systems Regularly: Ensure all hypervisors are up to date. Secure Remote Access: Limit access to essential services. Deploy Advanced Endpoint Protection: Use EDR solutions for threat detection. Backup Regularly: Store backups offline and validate integrity.
-
web:socprime.com
Explore the Mirai Botnet Digest: in-depth threat overview, analytics, and actionable remediation insights to detect and defend against Mirai -based IoT attacks.
-
web:www.cisecurity.org
The Mirai botnet soon spread to infect thousands of internet of things (IoT) devices and evolved to conduct full, large-scale attacks. After noticing an increase in infections, Mirai caught the attention of the nonprofit organization MalwareMustDie in August 2016, who then started to research, analyze, and track the botnet [2].
-
web:www.cs.umd.edu
These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.
-
web:www.netscout.com
Arbor Networks - DDoS Experts ASERT Threat Summary: Aisuru and Related TurboMirai Botnet DDoS Attack Mitigation and Suppression—October 2025—v1.0
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.researchgate.net
Molecularly imprinted polymers ( MIPs ) are emerging as efficient materials for environmental remediation due to their dual functionality in selective pollutant adsorption and catalytic degradation.
-
web:www.sciencedirect.com
In the specific context of Mirai botnet detection and mitigation , several approaches have been presented in the literature. Some works focus on studying the behavior of the Mirai botnet, examining and monitoring its propagation and impact within networked systems [85], [86], [87].
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.