s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0 high

📛 Threat Title

Mirai: iran.i486

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 100420 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:32.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0 VT 23 / 75

IOC database

Type
hash_sha256
Value
7127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 23 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Mirai.BC8PHU
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avira malicious TR/LINUX.Mirai.CYM
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
Elastic malicious Linux.Trojan.Mirai
F-Secure malicious Trojan.TR/LINUX.Mirai.CYM
Fortinet malicious ELF/Mirai.9821!tr
GData malicious Linux.Trojan.Agent.OHX83X
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Script/Mirai.EAW
Microsoft malicious Backdoor:Linux/Mirai.BU!MTB
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD5215ce7c366bc5a4fc24253c16b1b79a1
SHA-1f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1
SHA-2567127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0
VHash9d6a0272b8ca2941b408019146e236a0
SSDEEP1536:rw1BTbdwbo8tZx6Z8+c3Ra/oLDQ9VPJU3310vntiZvnwl7/4qKU7yDu7r:qSbxtZxyc3A/oLDYiClSCQq
TLSHT1B2A34C86FB93E0F0D94605B1111FF77D9634EE625024DE5AEBD4BEB2AD32602921B31C
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
File size98.1 KB
History
First seen on VirusTotal2026-08-31 16:18 UTC
Last submission2026-08-31 16:43 UTC
Last analysis2026-08-31 18:03 UTC
Last modified on VirusTotal2026-08-31 23:46 UTC
Known Names
  • hf0nav.exe
  • i486
  • iran.i486
hash_sha1 f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1 VT 23 / 75

IOC database

Type
hash_sha1
Value
f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 23 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Mirai.BC8PHU
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avira malicious TR/LINUX.Mirai.CYM
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
Elastic malicious Linux.Trojan.Mirai
F-Secure malicious Trojan.TR/LINUX.Mirai.CYM
Fortinet malicious ELF/Mirai.9821!tr
GData malicious Linux.Trojan.Agent.OHX83X
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Script/Mirai.EAW
Microsoft malicious Backdoor:Linux/Mirai.BU!MTB
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD5215ce7c366bc5a4fc24253c16b1b79a1
SHA-1f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1
SHA-2567127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0
VHash9d6a0272b8ca2941b408019146e236a0
SSDEEP1536:rw1BTbdwbo8tZx6Z8+c3Ra/oLDQ9VPJU3310vntiZvnwl7/4qKU7yDu7r:qSbxtZxyc3A/oLDYiClSCQq
TLSHT1B2A34C86FB93E0F0D94605B1111FF77D9634EE625024DE5AEBD4BEB2AD32602921B31C
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
File size98.1 KB
History
First seen on VirusTotal2026-08-31 16:18 UTC
Last submission2026-08-31 16:43 UTC
Last analysis2026-08-31 18:03 UTC
Last modified on VirusTotal2026-08-31 23:46 UTC
Known Names
  • hf0nav.exe
  • i486
  • iran.i486
hash_md5 215ce7c366bc5a4fc24253c16b1b79a1 VT 23 / 75

IOC database

Type
hash_md5
Value
215ce7c366bc5a4fc24253c16b1b79a1
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 23 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDoS:Linux/Mirai.BC8PHU
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avira malicious TR/LINUX.Mirai.CYM
ClamAV malicious Unix.Trojan.Mirai-10056448-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
Elastic malicious Linux.Trojan.Mirai
F-Secure malicious Trojan.TR/LINUX.Mirai.CYM
Fortinet malicious ELF/Mirai.9821!tr
GData malicious Linux.Trojan.Agent.OHX83X
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Script/Mirai.EAW
Microsoft malicious Backdoor:Linux/Mirai.BU!MTB
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD5215ce7c366bc5a4fc24253c16b1b79a1
SHA-1f737bc6ce69f7cb5d9969dcaa82c5c14d98c01d1
SHA-2567127ded6917a21c3870d60ff2fb01c1aad65b7988f459b36c12c7c15657162e0
VHash9d6a0272b8ca2941b408019146e236a0
SSDEEP1536:rw1BTbdwbo8tZx6Z8+c3Ra/oLDQ9VPJU3310vntiZvnwl7/4qKU7yDu7r:qSbxtZxyc3A/oLDYiClSCQq
TLSHT1B2A34C86FB93E0F0D94605B1111FF77D9634EE625024DE5AEBD4BEB2AD32602921B31C
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
File size98.1 KB
History
First seen on VirusTotal2026-08-31 16:18 UTC
Last submission2026-08-31 16:43 UTC
Last analysis2026-08-31 18:03 UTC
Last modified on VirusTotal2026-08-31 23:46 UTC
Known Names
  • hf0nav.exe
  • i486
  • iran.i486

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 100420 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:32.

Remediations (10)

  • web:academic.oup.com

    The ISP has been mitigating IoT infections of the Mirai family based on the abuse data it receives. We briefly discuss Mirai and then describe the notification mechanisms of the ISP, as well as the remediation steps that the users are asked to perform. Mirai malware.

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:arxiv.org

    Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...

  • web:dailysecurityreview.com

    The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.

  • web:github.com

    IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:rruzi.github.io

    The C2 port is randomly selected between 25596 and 25616. In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01 when Mirai goes online is modified to a fixed 8-byte: \x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than ...

  • web:www.joesandbox.com

    Matched rule: Linux_Trojan_Mirai_dab39a25 reference_sample = 3e02fb63803110cabde08e809cf4acc1b8fb474ace531959a311858fdd578bab, os = linux, severity = x86, creation_date = 2022-01-05, scan_context = file, memory, license = Elastic License v2, threat_name = Linux.Trojan. Mirai , fingerprint ...

  • web:www.joesandbox.com

    General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1922867 Start date and time: 2026-06-04 12:40:13 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 5m 6s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.