MB-de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218
high
📛 Threat Title
Mirai: iran.mipsrouter
Description
File type: elf. Size: 246219 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:25.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218
VT 22 / 75
IOC database
- Type
- hash_sha256
- Value
de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 22 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDOS:Linux/Mirai |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Gafgyt |
| Avast | malicious | ELF:Gafgyt-DZ [Trj] |
| AVG | malicious | ELF:Gafgyt-DZ [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-8041698-0 |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.B!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Gafgyt.bj |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Microsoft | malicious | Backdoor:Linux/Mirai.GL!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 9372ba684dbdfb07439baf707e737089 |
| SHA-1 | 0d46437286715d64df2e791e21e4077f284d9651 |
| SHA-256 | de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218 |
| VHash | a9c056ce78f4e43f4d59dc3386cf9650 |
| SSDEEP | 6144:p5n4F842iQbY1dplvtKTf1p1J8JG8WYkQsxNenndQ:gF84s+0f1p1J8JG8WYkQsxNenndQ |
| TLSH | T15C34B91A3E228FBEF268C77047F34A31976976D627E2D684E26CD5101F1438D681FB68 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, with debug_info, not stripped |
| File size | 240.4 KB |
History
| First seen on VirusTotal | 2026-09-07 17:53 UTC |
| Last submission | 2026-09-07 17:53 UTC |
| Last analysis | 2026-09-07 17:53 UTC |
| Last modified on VirusTotal | 2026-09-07 19:54 UTC |
Known Names
hfvxgp8p.exeiran.mipsrouter.elfiran.mipsrouter
hash_md5
9372ba684dbdfb07439baf707e737089
VT 22 / 75
IOC database
- Type
- hash_md5
- Value
9372ba684dbdfb07439baf707e737089- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 22 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDOS:Linux/Mirai |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Gafgyt |
| Avast | malicious | ELF:Gafgyt-DZ [Trj] |
| AVG | malicious | ELF:Gafgyt-DZ [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-8041698-0 |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.B!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Gafgyt.bj |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Microsoft | malicious | Backdoor:Linux/Mirai.GL!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 9372ba684dbdfb07439baf707e737089 |
| SHA-1 | 0d46437286715d64df2e791e21e4077f284d9651 |
| SHA-256 | de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218 |
| VHash | a9c056ce78f4e43f4d59dc3386cf9650 |
| SSDEEP | 6144:p5n4F842iQbY1dplvtKTf1p1J8JG8WYkQsxNenndQ:gF84s+0f1p1J8JG8WYkQsxNenndQ |
| TLSH | T15C34B91A3E228FBEF268C77047F34A31976976D627E2D684E26CD5101F1438D681FB68 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, with debug_info, not stripped |
| File size | 240.4 KB |
History
| First seen on VirusTotal | 2026-09-07 17:53 UTC |
| Last submission | 2026-09-07 17:53 UTC |
| Last analysis | 2026-09-07 17:53 UTC |
| Last modified on VirusTotal | 2026-09-07 19:54 UTC |
Known Names
hfvxgp8p.exeiran.mipsrouter.elfiran.mipsrouter
hash_sha1
0d46437286715d64df2e791e21e4077f284d9651
VT 22 / 75
IOC database
- Type
- hash_sha1
- Value
0d46437286715d64df2e791e21e4077f284d9651- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 22 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDOS:Linux/Mirai |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Gafgyt |
| Avast | malicious | ELF:Gafgyt-DZ [Trj] |
| AVG | malicious | ELF:Gafgyt-DZ [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Trojan.Mirai-8041698-0 |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.B!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Gafgyt.bj |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Microsoft | malicious | Backdoor:Linux/Mirai.GL!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 9372ba684dbdfb07439baf707e737089 |
| SHA-1 | 0d46437286715d64df2e791e21e4077f284d9651 |
| SHA-256 | de8fcf8fb26e6fffe21211674362ffdd3d92b139dc4693b00bd7d3bdb8999218 |
| VHash | a9c056ce78f4e43f4d59dc3386cf9650 |
| SSDEEP | 6144:p5n4F842iQbY1dplvtKTf1p1J8JG8WYkQsxNenndQ:gF84s+0f1p1J8JG8WYkQsxNenndQ |
| TLSH | T15C34B91A3E228FBEF268C77047F34A31976976D627E2D684E26CD5101F1438D681FB68 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, with debug_info, not stripped |
| File size | 240.4 KB |
History
| First seen on VirusTotal | 2026-09-07 17:53 UTC |
| Last submission | 2026-09-07 17:53 UTC |
| Last analysis | 2026-09-07 17:53 UTC |
| Last modified on VirusTotal | 2026-09-07 19:54 UTC |
Known Names
hfvxgp8p.exeiran.mipsrouter.elfiran.mipsrouter
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 246219 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:25.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices.
-
web:blog.cloudflare.com
This post offers a retrospective on Mirai , the infamous IoT botnet that disrupted major websites with massive DDoS attacks, leveraging hundreds of thousands of compromised Internet-of-Things devices.
-
web:cybersecuritynews.com
A new wave of cyberattacks has surfaced, with a Mirai -based botnet exploiting a number of significant vulnerabilities in routers and smart devices.
-
web:dailysecurityreview.com
A new Mirai botnet is using zero-day exploits to target industrial routers and smart home devices, launching high-intensity DDoS attacks. Learn about the vulnerabilities and how to protect your systems.
-
web:radar.offseq.com
Detailed information about Mirai Botnet Targets Flaw in Discontinued D-Link Routers. Get real-time updates, technical details, and mitigation strategies.
-
web:radar.offseq.com
Detailed information about Mirai : The IoT Botnet. Get real-time updates, technical details, and mitigation strategies.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:urlhaus.abuse.ch
Payload delivery The table below documents all payloads that URLhaus retrieved from this particular URL.
-
web:www.akamai.com
Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .
-
web:www.crowell.com
What You Need to Know Key takeaway#1 Iran-affiliated threat actors are actively targeting and exploiting programmable logic controllers (PLCs) used in internet-connected operational technology (OT) devices across the water and waste, energy, and government services and facilities sectors. Key takeaway#2 Multiple organizations in U.S. critical infrastructure sectors have experienced operational ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.