s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-4384da0552f022d58ad333a0b9944a214aa5dcc26dba6a955568241c14ed5179 high

📛 Threat Title

Mirai: iran.sh4

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 142140 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:09:06.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 4384da0552f022d58ad333a0b9944a214aa5dcc26dba6a955568241c14ed5179

IOC database

Type
hash_sha256
Value
4384da0552f022d58ad333a0b9944a214aa5dcc26dba6a955568241c14ed5179
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 86215604a35a02a844b4d3b00d2d8536ffce7e8b

IOC database

Type
hash_sha1
Value
86215604a35a02a844b4d3b00d2d8536ffce7e8b
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 800f2a9585ced8f5b3c03276cdac5378

IOC database

Type
hash_md5
Value
800f2a9585ced8f5b3c03276cdac5378
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 142140 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:09:06.

Remediations (10)

  • web:cybersecuritynews.com

    Mirai botnet variants target IoT devices via weak creds, driving rising DDoS threats and infecting millions worldwide.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:threatfox.abuse.ch

    Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.cisa.gov

    Cybersecurity Advisory: Provides detailed information on cyber threats, including threat actor tactics, techniques, and procedures and indicators of compromise, along with recommended actions for detection, mitigation , and response.

  • web:www.joesandbox.com

    File: /tmp/iran.sh4.elf Jump to behavior Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/iran.sh4.elf (PID: 5435) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)

  • web:www.joesandbox.com

    5 other IPs or domains Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file iran.sh4.elf started dash rm started

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.