s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-4790c081099c7c17b2bc1e9dc0f35fa3b2b036b2ce4a2b4044e94486ba807b1b high

📛 Threat Title

Mirai: iran.mips

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 206652 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:09:02.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 4790c081099c7c17b2bc1e9dc0f35fa3b2b036b2ce4a2b4044e94486ba807b1b

IOC database

Type
hash_sha256
Value
4790c081099c7c17b2bc1e9dc0f35fa3b2b036b2ce4a2b4044e94486ba807b1b
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 2bea4afb18b6c43f9916af9bbc4e615b1358771e

IOC database

Type
hash_sha1
Value
2bea4afb18b6c43f9916af9bbc4e615b1358771e
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 ed31f62261d1aeed15bee7b724e99b1a

IOC database

Type
hash_md5
Value
ed31f62261d1aeed15bee7b724e99b1a
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 206652 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:09:02.

Remediations (10)

  • web:foresiet.com

    The Mirai botnet has resurged. Learn about the Jackskid variant, its 40,000+ active bots, and the critical IoT Threats.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.cisa.gov

    Iran Threat Overview and Advisories CISA works to ensure U.S. critical infrastructure, government partners, and others have the information and guidance to defend themselves against Iran State-Sponsored cybersecurity risks.

  • web:www.ic3.gov

    The FBI further assesses these Iran-based cyber actors are associated with the Government of Iran (GOI) and—separate from the ransomware activity—conduct computer network exploitation activity in support of the GOI (such as intrusions enabling the theft of sensitive technical data against organizations in Israel and Azerbaijan).

  • web:www.joesandbox.com

    Uses the "uname" system call to query kernel version information (possible evasion)

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.yazoul.net

    The emphasis on .mpsl and .mips variants suggests operators are focusing on exploiting outdated firmware in networking equipment. Defensive recommendation: Immediately block outbound connections from non-essential IoT and embedded devices on ports 23 (Telnet) and 2222 (SSH), which are common Mirai infection vectors.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.