s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-e8dd6cdf0e6080389d02db9e85ccbf5512a6e04670428654c01e8e321e24acfe high

📛 Threat Title

Mirai: iran.x86_64

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 164272 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:08:59.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 e8dd6cdf0e6080389d02db9e85ccbf5512a6e04670428654c01e8e321e24acfe

IOC database

Type
hash_sha256
Value
e8dd6cdf0e6080389d02db9e85ccbf5512a6e04670428654c01e8e321e24acfe
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 dc6a4cf0d643cd5a470eb1f02596ef1970d5df93

IOC database

Type
hash_sha1
Value
dc6a4cf0d643cd5a470eb1f02596ef1970d5df93
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 0017820d57627a8709e4a4a46c33dce9

IOC database

Type
hash_md5
Value
0017820d57627a8709e4a4a46c33dce9
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 164272 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-07-28 15:08:59.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:any.run

    Online sandbox report for iran.x86_64 , tagged as mirai , botnet, ddos, gafgyt, verdict: Malicious activity

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:threatfox.abuse.ch

    Quick summary of what's in the report: Http Server Spreading Malware At port 80 With The iran.archprefix etc: iran.x86_64 C2 at 103.83.87.122 port 2222 telnet/raw socket

  • web:threatfox.abuse.ch

    Anonymous b1a6dba6636b519d76d7219f6264ac9f1456681c0855baef954fb435d3e25ce5 iran.x86_64 bf38b3e5d645c78377599a6c218a347312c5a3daef693c7931f2710806d85317 iran.aarch64 f5cb6dadaee4399a1f014ef5946d0a4c1af578d15ff078e725e0757f28dc8493 iran.m68k e987bb8b32facef51c3cc5a94bd51e01d8c3be8a19c106de70147ab5ce84dc66 iran.mips

  • web:urlhaus.abuse.ch

    Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.

  • web:www.fbi.gov

    The FBI assesses Iran MOIS cyber actors deployed multiple versions of the malware to infect machines running Windows operating systems, dating back to the Fall of 2023.

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.joesandbox.com

    Overview General Information Sample name: iran.x86_64.elf Analysis ID: 1919965 Has dependencies:

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.