s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-9f47d69c21e6131b0055331232c3e8f6fbdead4ff6e2c50c71ebbebb8cf3feaa high

📛 Threat Title

Mirai: axis.x86

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 123356 bytes. Tags: Gafgyt, Mirai. Reporter: BlinkzSec. First seen: 2026-05-14 19:23:11.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 9f47d69c21e6131b0055331232c3e8f6fbdead4ff6e2c50c71ebbebb8cf3feaa 1 feed

IOC database

Type
hash_sha256
Value
9f47d69c21e6131b0055331232c3e8f6fbdead4ff6e2c50c71ebbebb8cf3feaa
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 08847afb47de3925019a5f05335a11a765feb58e VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/08847afb47de3925019a5f05335a11a765feb58e
1 feed

IOC database

Type
hash_sha1
Value
08847afb47de3925019a5f05335a11a765feb58e
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/08847afb47de3925019a5f05335a11a765feb58e

hash_md5 2fdc66c89449e304368453ae05e187fe VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2fdc66c89449e304368453ae05e187fe
1 feed

IOC database

Type
hash_md5
Value
2fdc66c89449e304368453ae05e187fe
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/2fdc66c89449e304368453ae05e187fe

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 123356 bytes. Tags: Gafgyt, Mirai. Reporter: BlinkzSec. First seen: 2026-05-14 19:23:11.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:rruzi.github.io

    In-depth Analysis of a New Mirai Variant 7 minute read Published: December 28, 2024 I. Background Recently, NSFOCUS [1], National Cyber Security Center (NCSC) [2], and 360 Security Brain [3] detected a batch of botnet samples that integrate the TEA algorithm for encryption based on the leaked source code of Mirai , targeting IoT/Linux devices of various architectures such as ARM, MIPS, and x86 ...

  • web:trainsec.net

    In this particular case, I found an ARM-compiled Mirai botnet sample. The anti-virus checks labeled it as " Mirai ," matching what I found in the documentation, sandbox analyses, and community threat intelligence sources. Mirai is known to compile variants for multiple architectures (ARM, MIPS, x86, x64, etc.), making it adaptable and widespread.

  • web:www.akamai.com

    Mirai -based botnets continue to be a call for divorce for many organizations, and the prevalence of outdated IoT devices help propagate this threat. Like security researchers, some threat actors keep up to date on the latest vulnerability disclosures relevant to their illicit activities.

  • web:www.fortinet.com

    Conclusion While Gayfemboy inherits structural elements from Mirai , it introduces notable modifications that enhance both its complexity and ability to evade detection. This evolution reflects the increasing sophistication of modern malware and reinforces the need for proactive, intelligence-driven defense strategies.

  • web:www.indusface.com

    The Mirai botnet is a network of compromised IoT devices used to launch massive DDoS attacks, exploiting weak credentials & vulnerabilities to disrupt services.

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.radware.com

    Mirai is a pervasive Internet-of-Things (IoT) botnet that first surfaced in 2016 and rapidly evolved into a foundational DDoS framework. By scanning for devices with default or weak credentials and installing a lightweight in-memory agent, Mirai and its descendants have mounted some of the largest and most disruptive volumetric and application-layer DDoS campaigns in recent history ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.