MB-7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0
high
📛 Threat Title
Mirai: iran.i486
Description
File type: elf. Size: 100420 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:32.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0
VT 23 / 75
IOC database
- Type
- hash_sha256
- Value
7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 23 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Mirai.BC8PHU |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avira | malicious | TR/LINUX.Mirai.CYM |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| Elastic | malicious | Linux.Trojan.Mirai |
| F-Secure | malicious | Trojan.TR/LINUX.Mirai.CYM |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Agent.OHX83X |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Script/Mirai.EAW |
| Microsoft | malicious | Backdoor:Linux/Mirai.BU!MTB |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrendMicro | malicious | Backdoor.Linux.MIRAI.USBLHV26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 215ce7c366bc5a4fc24253c16b1b79a1 |
| SHA-1 | f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1 |
| SHA-256 | 7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0 |
| VHash | 9d6a0272b8ca2941b408019146e236a0 |
| SSDEEP | 1536:rw1BTbdwbo8tZx6Z8+c3Ra/oLDQ9VPJU3310vntiZvnwl7/4qKU7yDu7r:qSbxtZxyc3A/oLDYiClSCQq |
| TLSH | T1B2A34C86FB93E0F0D94605B1111FF77D9634EE625024DE5AEBD4BEB2AD32602921B31C |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped |
| File size | 98.1 KB |
History
| First seen on VirusTotal | 2026-08-31 16:18 UTC |
| Last submission | 2026-08-31 16:43 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:46 UTC |
Known Names
hf0nav.exei486iran.i486
hash_sha1
f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1
VT 23 / 75
IOC database
- Type
- hash_sha1
- Value
f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 23 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Mirai.BC8PHU |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avira | malicious | TR/LINUX.Mirai.CYM |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| Elastic | malicious | Linux.Trojan.Mirai |
| F-Secure | malicious | Trojan.TR/LINUX.Mirai.CYM |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Agent.OHX83X |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Script/Mirai.EAW |
| Microsoft | malicious | Backdoor:Linux/Mirai.BU!MTB |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrendMicro | malicious | Backdoor.Linux.MIRAI.USBLHV26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 215ce7c366bc5a4fc24253c16b1b79a1 |
| SHA-1 | f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1 |
| SHA-256 | 7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0 |
| VHash | 9d6a0272b8ca2941b408019146e236a0 |
| SSDEEP | 1536:rw1BTbdwbo8tZx6Z8+c3Ra/oLDQ9VPJU3310vntiZvnwl7/4qKU7yDu7r:qSbxtZxyc3A/oLDYiClSCQq |
| TLSH | T1B2A34C86FB93E0F0D94605B1111FF77D9634EE625024DE5AEBD4BEB2AD32602921B31C |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped |
| File size | 98.1 KB |
History
| First seen on VirusTotal | 2026-08-31 16:18 UTC |
| Last submission | 2026-08-31 16:43 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:46 UTC |
Known Names
hf0nav.exei486iran.i486
hash_md5
215ce7c366bc5a4fc24253c16b1b79a1
VT 23 / 75
IOC database
- Type
- hash_md5
- Value
215ce7c366bc5a4fc24253c16b1b79a1- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 23 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Mirai.BC8PHU |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avira | malicious | TR/LINUX.Mirai.CYM |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| Elastic | malicious | Linux.Trojan.Mirai |
| F-Secure | malicious | Trojan.TR/LINUX.Mirai.CYM |
| Fortinet | malicious | ELF/Mirai.9821!tr |
| GData | malicious | Linux.Trojan.Agent.OHX83X |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Script/Mirai.EAW |
| Microsoft | malicious | Backdoor:Linux/Mirai.BU!MTB |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrendMicro | malicious | Backdoor.Linux.MIRAI.USBLHV26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 215ce7c366bc5a4fc24253c16b1b79a1 |
| SHA-1 | f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1 |
| SHA-256 | 7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0 |
| VHash | 9d6a0272b8ca2941b408019146e236a0 |
| SSDEEP | 1536:rw1BTbdwbo8tZx6Z8+c3Ra/oLDQ9VPJU3310vntiZvnwl7/4qKU7yDu7r:qSbxtZxyc3A/oLDYiClSCQq |
| TLSH | T1B2A34C86FB93E0F0D94605B1111FF77D9634EE625024DE5AEBD4BEB2AD32602921B31C |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped |
| File size | 98.1 KB |
History
| First seen on VirusTotal | 2026-08-31 16:18 UTC |
| Last submission | 2026-08-31 16:43 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:46 UTC |
Known Names
hf0nav.exei486iran.i486
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 100420 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:32.
Remediations (10)
-
web:academic.oup.com
The ISP has been mitigating IoT infections of the Mirai family based on the abuse data it receives. We briefly discuss Mirai and then describe the notification mechanisms of the ISP, as well as the remediation steps that the users are asked to perform. Mirai malware.
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:arxiv.org
Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...
-
web:dailysecurityreview.com
The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.
-
web:github.com
IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:rruzi.github.io
The C2 port is randomly selected between 25596 and 25616. In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01 when Mirai goes online is modified to a fixed 8-byte: \x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than ...
-
web:www.joesandbox.com
Matched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan. Mirai , fingerprint ...
-
web:www.joesandbox.com
General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1922867 Start date and time: 2026-06-04 12:40:13 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 5m 6s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.