s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-3a7bf6f11d972b034f44222b21fad10de8ac30d197ee406f027e4fe38951f245 high

📛 Threat Title

Mirai: bot.mpsl

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1142308 bytes. Tags: elf, Gafgyt, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 04:42:12.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 3a7bf6f11d972b034f44222b21fad10de8ac30d197ee406f027e4fe38951f245

IOC database

Type
hash_sha256
Value
3a7bf6f11d972b034f44222b21fad10de8ac30d197ee406f027e4fe38951f245
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 75790370d4b000f840ff90c0ee85dcd9698d9d6f

IOC database

Type
hash_sha1
Value
75790370d4b000f840ff90c0ee85dcd9698d9d6f
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 a8d09d62b7de582b86b6a671a7a7d3d8

IOC database

Type
hash_md5
Value
a8d09d62b7de582b86b6a671a7a7d3d8
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1142308 bytes. Tags: elf, Gafgyt, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 04:42:12.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:arxiv.org

    Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks. It primarily targets online consumer devices such as IP cameras and home routers. [1] The Mirai botnet was first found in August 2016 [2] by MalwareMustDie, [3] a white hat malware research ...

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:unit42.paloaltonetworks.com

    We discovered ongoing attacks leveraging IoT vulnerabilities, including in network security devices, to serve a Mirai variant.

  • web:westoahu.hawaii.edu

    A botnet called Mirai infected hundreds of thousands of Internet of Things (IoT) devices, amassing a wide network of compromised devices. Mitigations against the Mirai botnet involve taking proactive security measures, properly hardening systems, and updating to the latest software to reduce the risk of compromise.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Attempts to enable/disable Ctrl-Alt-Delete system rebooting Detected TCP or UDP traffic on non-standard ports Found Tor onion address Found strings indicative of a multi-platform dropper Sample contains strings indicative of BusyBox which embeds multiple Unix commands ...

  • web:www.sciencedirect.com

    The proliferation of Internet of Things devices has resulted in an increase in security vulnerabilities and network attacks. The Mirai botnet is a well-known example of a network used for malicious activities, detected for the first time by the white-hat research group in August 2016. Since then, Mirai initiated massive DDoS attacks by scanning for and exploiting vulnerabilities in network ...

  • web:www.threatintelreport.com

    Akamai SIRT identifies Mirai variant campaign actively targeting critical RCE flaws in automation platforms and routers Mirai #Zerobot #Botnet #n8n #Tenda #CVE-2025-68613 #CVE-2025-7544 Affected products n8n workflow automation platform (versions 0.211.0 prior to 1.120.4, 1.121.1 and 1.122.0) and Tenda AC1206 routers (firmware 15.03.06.23) Campaign type Mirai -based botnet propagation via ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.