s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218 high

📛 Threat Title

Mirai: iran.mipsrouter

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 246219 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:25.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218 VT 22 / 75

IOC database

Type
hash_sha256
Value
de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 22 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDOS:Linux/Mirai
Antiy-AVL malicious Trojan[Backdoor]/Linux.Gafgyt
Avast malicious ELF:Gafgyt-DZ [Trj]
AVG malicious ELF:Gafgyt-DZ [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-8041698-0
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Mirai.B!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Gafgyt.bj
Kingsoft malicious Script.Troj.Shell.2052936
Microsoft malicious Backdoor:Linux/Mirai.GL!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD59372ba684dbdfb07439baf707e737089
SHA-10d46437286715d64df2e791e21e4077f284d9651
SHA-256de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218
VHasha9c056ce78f4e43f4d59dc3386cf9650
SSDEEP6144:p5n4F842iQbY1dplvtKTf1p1J8JG8WYkQsxNenndQ:gF84s+0f1p1J8JG8WYkQsxNenndQ
TLSHT15C34B91A3E228FBEF268C77047F34A31976976D627E2D684E26CD5101F1438D681FB68
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, with debug_info, not stripped
File size240.4 KB
History
First seen on VirusTotal2026-09-07 17:53 UTC
Last submission2026-09-07 17:53 UTC
Last analysis2026-09-07 17:53 UTC
Last modified on VirusTotal2026-09-07 19:54 UTC
Known Names
  • hfvxgp8p.exe
  • iran.mipsrouter.elf
  • iran.mipsrouter
hash_md5 9372ba684dbdfb07439baf707e737089 VT 22 / 75

IOC database

Type
hash_md5
Value
9372ba684dbdfb07439baf707e737089
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URLhaus payload hash attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 22 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDOS:Linux/Mirai
Antiy-AVL malicious Trojan[Backdoor]/Linux.Gafgyt
Avast malicious ELF:Gafgyt-DZ [Trj]
AVG malicious ELF:Gafgyt-DZ [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-8041698-0
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Mirai.B!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Gafgyt.bj
Kingsoft malicious Script.Troj.Shell.2052936
Microsoft malicious Backdoor:Linux/Mirai.GL!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD59372ba684dbdfb07439baf707e737089
SHA-10d46437286715d64df2e791e21e4077f284d9651
SHA-256de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218
VHasha9c056ce78f4e43f4d59dc3386cf9650
SSDEEP6144:p5n4F842iQbY1dplvtKTf1p1J8JG8WYkQsxNenndQ:gF84s+0f1p1J8JG8WYkQsxNenndQ
TLSHT15C34B91A3E228FBEF268C77047F34A31976976D627E2D684E26CD5101F1438D681FB68
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, with debug_info, not stripped
File size240.4 KB
History
First seen on VirusTotal2026-09-07 17:53 UTC
Last submission2026-09-07 17:53 UTC
Last analysis2026-09-07 17:53 UTC
Last modified on VirusTotal2026-09-07 19:54 UTC
Known Names
  • hfvxgp8p.exe
  • iran.mipsrouter.elf
  • iran.mipsrouter
hash_sha1 0d46437286715d64df2e791e21e4077f284d9651 VT 22 / 75

IOC database

Type
hash_sha1
Value
0d46437286715d64df2e791e21e4077f284d9651
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 22 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious DDOS:Linux/Mirai
Antiy-AVL malicious Trojan[Backdoor]/Linux.Gafgyt
Avast malicious ELF:Gafgyt-DZ [Trj]
AVG malicious ELF:Gafgyt-DZ [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Trojan.Mirai-8041698-0
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Mirai.B!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Gafgyt.bs
Kaspersky malicious HEUR:Backdoor.Linux.Gafgyt.bj
Kingsoft malicious Script.Troj.Shell.2052936
Microsoft malicious Backdoor:Linux/Mirai.GL!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Tencent malicious Backdoor.Linux.Gafgyt.mbxra
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD59372ba684dbdfb07439baf707e737089
SHA-10d46437286715d64df2e791e21e4077f284d9651
SHA-256de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218
VHasha9c056ce78f4e43f4d59dc3386cf9650
SSDEEP6144:p5n4F842iQbY1dplvtKTf1p1J8JG8WYkQsxNenndQ:gF84s+0f1p1J8JG8WYkQsxNenndQ
TLSHT15C34B91A3E228FBEF268C77047F34A31976976D627E2D684E26CD5101F1438D681FB68
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, with debug_info, not stripped
File size240.4 KB
History
First seen on VirusTotal2026-09-07 17:53 UTC
Last submission2026-09-07 17:53 UTC
Last analysis2026-09-07 17:53 UTC
Last modified on VirusTotal2026-09-07 19:54 UTC
Known Names
  • hfvxgp8p.exe
  • iran.mipsrouter.elf
  • iran.mipsrouter

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 246219 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:25.

Remediations (10)

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.