s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-1bcf52ca1c3638e76d59ffb879cdc673f990743459243954e54af84e3ada6a96 high

📛 Threat Title

Mirai: iran.mipsrouter

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 246219 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:33.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 1bcf52ca1c3638e76d59ffb879cdc673f990743459243954e54af84e3ada6a96 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/1bcf52ca1c3638e76d59ffb879cdc673f990743459243954e54af84e3ada6a96

IOC database

Type
hash_sha256
Value
1bcf52ca1c3638e76d59ffb879cdc673f990743459243954e54af84e3ada6a96
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/1bcf52ca1c3638e76d59ffb879cdc673f990743459243954e54af84e3ada6a96

hash_sha1 568560c0714fece29a9203f5b4b56d8430582e6c VT 28 / 75

IOC database

Type
hash_sha1
Value
568560c0714fece29a9203f5b4b56d8430582e6c
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 28 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDOS:Linux/Mirai
Antiy-AVL malicious Trojan[Backdoor]/Linux.Gafgyt
Avast malicious ELF:Gafgyt-DZ [Trj]
AVG malicious ELF:Gafgyt-DZ [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-8041698-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Mirai.B!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Gafgyt.bj
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQH
Microsoft malicious Backdoor:Linux/Mirai.GL!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Symantec malicious Worm.Mirai!ATN
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
TrendMicro-HouseCall malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD50e51f21907ee112c8d5274c2cf63cf83
SHA-1568560c0714fece29a9203f5b4b56d8430582e6c
SHA-2561bcf52ca1c3638e76d59ffb879cdc673f990743459243954e54af84e3ada6a96
VHasha9c056ce78f4e43f4d59dc3386cf9650
SSDEEP6144:pjn4F842iQbY1dplvtKWf1p1J8JG8WYkQsxNenndQ:iF84s+Ff1p1J8JG8WYkQsxNenndQ
TLSHT16334B91A3E228FBEF268C77047F34A31976976D627E2D684E26CD5101F1438D681FB68
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, with debug_info, not stripped
File size240.4 KB
History
First seen on VirusTotal2026-08-31 16:18 UTC
Last submission2026-08-31 23:26 UTC
Last analysis2026-08-31 23:26 UTC
Last modified on VirusTotal2026-08-31 23:37 UTC
Known Names
  • uzn2ln7.exe
  • iran.mipsrouter
hash_md5 0e51f21907ee112c8d5274c2cf63cf83 VT 28 / 75

IOC database

Type
hash_md5
Value
0e51f21907ee112c8d5274c2cf63cf83
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 28 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDOS:Linux/Mirai
Antiy-AVL malicious Trojan[Backdoor]/Linux.Gafgyt
Avast malicious ELF:Gafgyt-DZ [Trj]
AVG malicious ELF:Gafgyt-DZ [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-8041698-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Mirai.B!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Gafgyt.bj
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQH
Microsoft malicious Backdoor:Linux/Mirai.GL!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Symantec malicious Worm.Mirai!ATN
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
TrendMicro-HouseCall malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD50e51f21907ee112c8d5274c2cf63cf83
SHA-1568560c0714fece29a9203f5b4b56d8430582e6c
SHA-2561bcf52ca1c3638e76d59ffb879cdc673f990743459243954e54af84e3ada6a96
VHasha9c056ce78f4e43f4d59dc3386cf9650
SSDEEP6144:pjn4F842iQbY1dplvtKWf1p1J8JG8WYkQsxNenndQ:iF84s+Ff1p1J8JG8WYkQsxNenndQ
TLSHT16334B91A3E228FBEF268C77047F34A31976976D627E2D684E26CD5101F1438D681FB68
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, with debug_info, not stripped
File size240.4 KB
History
First seen on VirusTotal2026-08-31 16:18 UTC
Last submission2026-08-31 23:26 UTC
Last analysis2026-08-31 23:26 UTC
Last modified on VirusTotal2026-08-31 23:37 UTC
Known Names
  • uzn2ln7.exe
  • iran.mipsrouter

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 246219 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:33.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:cybersecuritynews.com

    A new wave of cyberattacks has surfaced, with a Mirai -based botnet exploiting a number of significant vulnerabilities in routers and smart devices.

  • web:dailysecurityreview.com

    A new Mirai botnet is using zero-day exploits to target industrial routers and smart home devices, launching high-intensity DDoS attacks. Learn about the vulnerabilities and how to protect your systems.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:westoahu.hawaii.edu

    Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.sonicwall.com

    It spreads by continuously seeking new targets and adapts dynamically to evade detection and mitigation efforts as explained in Figure 1. Figure 1: Mirai attack chain Honeypot Insights Sonicwall's honeypots found Mirai leveraging exploits targeting old vulnerabilities in routers like Zyxel, Netgear, D-Link and TP-Link to spread Mirai .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.