s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3 high

📛 Threat Title

Mirai: m68k

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 84308 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-14 08:51:26.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3
1 feed

IOC database

Type
hash_sha256
Value
344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3

hash_sha1 a8acf01d83e2c6777fcbd1ec4c29adb03fa855e9 VT 36 / 75 2 feeds

IOC database

Type
hash_sha1
Value
a8acf01d83e2c6777fcbd1ec4c29adb03fa855e9
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Flagged by 36 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Linux/Mirai03.Exp
alibabacloud malicious DDoS:Linux/Mirai.CMC
ALYac malicious Trojan.Linux.Mirai.1
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Arcabit malicious Trojan.Linux.Mirai.1
Avast malicious ELF:Mirai-CEQ [Trj]
Avast-Mobile malicious ELF:Mirai-CGR [Trj]
AVG malicious ELF:Mirai-CEQ [Trj]
Avira malicious TR/LINUX.Mirai.PB
BitDefender malicious Trojan.Linux.Mirai.1
ClamAV malicious Unix.Trojan.Mirai-6981989-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9786
Emsisoft malicious Trojan.Linux.Mirai.1 (B)
ESET-NOD32 malicious Linux/Mirai.CAG trojan
F-Secure malicious Trojan.TR/LINUX.Mirai.PB
Fortinet malicious Linux/Mirai.CAG!tr
GData malicious Linux.Trojan.Mirai.D
Google malicious Detected
huorong malicious Backdoor/Linux.Mirai.dz
Ikarus malicious Backdoor.Linux.Mirai
Kaspersky malicious HEUR:Backdoor.Linux.Mirai.ew
Kingsoft malicious Linux.Backdoor.Mirai.ew
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious ti!344908AADF0B
Microsoft malicious Backdoor:Linux/Mirai.BO!xp
MicroWorld-eScan malicious Trojan.Linux.Mirai.1
Rising malicious Backdoor.Mirai/Linux!8.13285 (CLOUD)
Sangfor malicious Suspicious.Linux.Save.a
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Mirai.wba
TrendMicro malicious Trojan.Win32.ZYX.USBLEE26
TrendMicro-HouseCall malicious Trojan.Win32.ZYX.USBLEE26
VIPRE malicious Trojan.Linux.Mirai.1

Details From VirusTotal

Basic Properties
MD5e08842d8a260a2690c60bee07fb9a4e6
SHA-1a8acf01d83e2c6777fcbd1ec4c29adb03fa855e9
SHA-256344908aadf0b72e8bb68969338f9b7af7e19469c6920fe6880a04431604b94f3
VHashe0a969d35494c0bd6d6ec1e1984e1d1a
SSDEEP1536:Y6WcuX0G1fx2jUSveVWi49G8bqvL8MCYFOxJImOOW/mTXhxPxgog:Yft1fx2gSm3ynbqvKtwm7WuNlg
TLSHT157834A9FF400CD7DF84AD7BE8063060AB531B3A51A530E2B9697FC9778721A81967F42
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, Motorola m68k, 68020, version 1 (SYSV), statically linked, stripped
File size82.3 KB
History
First seen on VirusTotal2026-05-14 08:51 UTC
Last submission2026-05-14 09:01 UTC
Last analysis2026-05-15 03:09 UTC
Last modified on VirusTotal2026-05-15 07:24 UTC
Known Names
  • m68k
  • t3ahg4x.exe
  • 176.65.149.254_sample.bin
  • m68k.elf
hash_md5 e08842d8a260a2690c60bee07fb9a4e6 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e08842d8a260a2690c60bee07fb9a4e6
2 feeds

IOC database

Type
hash_md5
Value
e08842d8a260a2690c60bee07fb9a4e6
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/e08842d8a260a2690c60bee07fb9a4e6

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 84308 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-14 08:51:26.

Remediations (10)

  • web:academic.oup.com

    In short, Mirai is still a relevant threat and it provides a representative case study for understanding if and how end users can perform remediation . Notification mechanisms. Our partnering ISP and its subsidiary brand have slightly different user populations and their own abuse handling procedures.

  • web:westoahu.hawaii.edu

    Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Yara detected Mirai Sample deletes itself Executes the "rm" command used to delete files or directories Sample has stripped symbol table Sample listens on a socket Uses the "uname" system call to query kernel version information ...

  • web:www.joesandbox.com

    Automated Malware Analysis - Joe Sandbox Analysis Report Overview Overview General Information Process Tree Malware Threat Intel Malware Configuration Behavior Graph Antivirus and ML Detection Joe Sandbox View / Context Signatures Signatures Yara Suricata Joe Sandbox Mitre Att&ck Matrix Process Tree Dropped Domains / IPs Network Network TCP Packets Static Behavior Behavior miraint. m68k .elf ...

  • web:www.joesandbox.com

    Multi AV Scanner detection for submitted file Yara detected Mirai Contains symbols with names commonly found in malware dash rm mirai . m68k .elf started dash rm started

  • web:www.joesandbox.com

    Automated Malware Analysis - Joe Sandbox Analysis Report Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source ...

  • web:www.joesandbox.com

    Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai mirai . m68k .elf started python3.8 dpkg started

  • web:www.joesandbox.com

    Yara detected Mirai Sample deletes itself Detected TCP or UDP traffic on non-standard ports Executes the "rm" command used to delete files or directories Sample has stripped symbol table Sample listens on a socket Uses the "uname" system call to query kernel version information (possible evasion) Yara signature match

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.sciencedirect.com

    Mirai , which means 'future' in Japanese, foreshadowing a more than a one time event, modeled the future of significant attacks to come. Mitigation efforts include patching the vulnerabilities that are leveraged by the Mirai malware family and detecting/preventing Mirai from entering IoT networks.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.