MB-344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3
high
📛 Threat Title
Mirai: m68k
Description
File type: elf. Size: 84308 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-14 08:51:26.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3
1 feed
IOC database
- Type
- hash_sha256
- Value
344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3
hash_sha1
a8acf01d83e2c6777fcbd1ec4c29adb03fa855e9
VT 36 / 75
2 feeds
IOC database
- Type
- hash_sha1
- Value
a8acf01d83e2c6777fcbd1ec4c29adb03fa855e9- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Flagged by 36 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Linux/Mirai03.Exp |
| alibabacloud | malicious | DDoS:Linux/Mirai.CMC |
| ALYac | malicious | Trojan.Linux.Mirai.1 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Arcabit | malicious | Trojan.Linux.Mirai.1 |
| Avast | malicious | ELF:Mirai-CEQ [Trj] |
| Avast-Mobile | malicious | ELF:Mirai-CGR [Trj] |
| AVG | malicious | ELF:Mirai-CEQ [Trj] |
| Avira | malicious | TR/LINUX.Mirai.PB |
| BitDefender | malicious | Trojan.Linux.Mirai.1 |
| ClamAV | malicious | Unix.Trojan.Mirai-6981989-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9786 |
| Emsisoft | malicious | Trojan.Linux.Mirai.1 (B) |
| ESET-NOD32 | malicious | Linux/Mirai.CAG trojan |
| F-Secure | malicious | Trojan.TR/LINUX.Mirai.PB |
| Fortinet | malicious | Linux/Mirai.CAG!tr |
| GData | malicious | Linux.Trojan.Mirai.D |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Mirai.dz |
| Ikarus | malicious | Backdoor.Linux.Mirai |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Mirai.ew |
| Kingsoft | malicious | Linux.Backdoor.Mirai.ew |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | ti!344908AADF0B |
| Microsoft | malicious | Backdoor:Linux/Mirai.BO!xp |
| MicroWorld-eScan | malicious | Trojan.Linux.Mirai.1 |
| Rising | malicious | Backdoor.Mirai/Linux!8.13285 (CLOUD) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Mirai.wba |
| TrendMicro | malicious | Trojan.Win32.ZYX.USBLEE26 |
| TrendMicro-HouseCall | malicious | Trojan.Win32.ZYX.USBLEE26 |
| VIPRE | malicious | Trojan.Linux.Mirai.1 |
Details From VirusTotal
Basic Properties
| MD5 | e08842d8a260a2690c60bee07fb9a4e6 |
| SHA-1 | a8acf01d83e2c6777fcbd1ec4c29adb03fa855e9 |
| SHA-256 | 344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3 |
| VHash | e0a969d35494c0bd6d6ec1e1984e1d1a |
| SSDEEP | 1536:Y6WcuX0G1fx2jUSveVWi49G8bqvL8MCYFOxJImOOW/mTXhxPxgog:Yft1fx2gSm3ynbqvKtwm7WuNlg |
| TLSH | T157834A9FF400CD7DF84AD7BE8063060AB531B3A51A530E2B9697FC9778721A81967F42 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped |
| File size | 82.3 KB |
History
| First seen on VirusTotal | 2026-05-14 08:51 UTC |
| Last submission | 2026-05-14 09:01 UTC |
| Last analysis | 2026-05-15 03:09 UTC |
| Last modified on VirusTotal | 2026-05-15 07:24 UTC |
Known Names
m68kt3ahg4x.exe176.65.149.254_sample.binm68k.elf
hash_md5
e08842d8a260a2690c60bee07fb9a4e6
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e08842d8a260a2690c60bee07fb9a4e6
2 feeds
IOC database
- Type
- hash_md5
- Value
e08842d8a260a2690c60bee07fb9a4e6- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e08842d8a260a2690c60bee07fb9a4e6
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 84308 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-14 08:51:26.
Remediations (10)
-
web:academic.oup.com
In short, Mirai is still a relevant threat and it provides a representative case study for understanding if and how end users can perform remediation . Notification mechanisms. Our partnering ISP and its subsidiary brand have slightly different user populations and their own abuse handling procedures.
-
web:westoahu.hawaii.edu
Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Yara detected Mirai Sample deletes itself Executes the "rm" command used to delete files or directories Sample has stripped symbol table Sample listens on a socket Uses the "uname" system call to query kernel version information ...
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Analysis Report Overview Overview General Information Process Tree Malware Threat Intel Malware Configuration Behavior Graph Antivirus and ML Detection Joe Sandbox View / Context Signatures Signatures Yara Suricata Joe Sandbox Mitre Att&ck Matrix Process Tree Dropped Domains / IPs Network Network TCP Packets Static Behavior Behavior miraint. m68k .elf ...
-
web:www.joesandbox.com
Multi AV Scanner detection for submitted file Yara detected Mirai Contains symbols with names commonly found in malware dash rm mirai . m68k .elf started dash rm started
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Analysis Report Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source ...
-
web:www.joesandbox.com
Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai mirai . m68k .elf started python3.8 dpkg started
-
web:www.joesandbox.com
Yara detected Mirai Sample deletes itself Detected TCP or UDP traffic on non-standard ports Executes the "rm" command used to delete files or directories Sample has stripped symbol table Sample listens on a socket Uses the "uname" system call to query kernel version information (possible evasion) Yara signature match
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.sciencedirect.com
Mirai , which means 'future' in Japanese, foreshadowing a more than a one time event, modeled the future of significant attacks to come. Mitigation efforts include patching the vulnerabilities that are leveraged by the Mirai malware family and detecting/preventing Mirai from entering IoT networks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.