MB-e29c40498d1e2b650e65855ab7051475e4aa6bc54e9b0d8352dda798c5aba339
high
📛 Threat Title
Mirai: iran.armv6l
Description
File type: elf. Size: 169012 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:18.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
e29c40498d1e2b650e65855ab7051475e4aa6bc54e9b0d8352dda798c5aba339
VT 31 / 75
IOC database
- Type
- hash_sha256
- Value
e29c40498d1e2b650e65855ab7051475e4aa6bc54e9b0d8352dda798c5aba339- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 31 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Generic.40381008 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D2682A50 |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| BitDefender | malicious | Trojan.Generic.40381008 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Emsisoft | malicious | Trojan.Generic.40381008 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Backdoor:Linux/Mirai.GJ!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40381008 |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!5A46AB023062 |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!5A46AB023062 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
| VIPRE | malicious | Trojan.Generic.40381008 |
Details From VirusTotal
Basic Properties
| MD5 | 5a46ab02306238eac697ba327079e449 |
| SHA-1 | 04084d2548f231c26cbc9be8275dbc5208f80ea6 |
| SHA-256 | e29c40498d1e2b650e65855ab7051475e4aa6bc54e9b0d8352dda798c5aba339 |
| VHash | 8392799d7739ad72225fd3b9fa512aa9 |
| SSDEEP | 3072:Oo0R0M1GwnMVqH8VMFU79wfmPtK93ura4hCG3yx67uk6nD2c62+hsz:Oo0R0M1GwnMVO+MFwCOPtU3oaKCMl7u3 |
| TLSH | T18DF31A56F9819B11C5C156BAFF0E528D73231B78E2DE72129E246B347B8A87B0E3B015 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped |
| File size | 165.1 KB |
History
| First seen on VirusTotal | 2026-09-07 07:55 UTC |
| Last submission | 2026-09-07 17:53 UTC |
| Last analysis | 2026-09-07 07:55 UTC |
| Last modified on VirusTotal | 2026-09-07 18:05 UTC |
Known Names
a01enbc3.exearmv6liran.armv6l
hash_md5
5a46ab02306238eac697ba327079e449
VT 31 / 75
IOC database
- Type
- hash_md5
- Value
5a46ab02306238eac697ba327079e449- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URLhaus payload hash attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 31 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Generic.40381008 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D2682A50 |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| BitDefender | malicious | Trojan.Generic.40381008 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Emsisoft | malicious | Trojan.Generic.40381008 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Backdoor:Linux/Mirai.GJ!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40381008 |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!5A46AB023062 |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!5A46AB023062 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
| VIPRE | malicious | Trojan.Generic.40381008 |
Details From VirusTotal
Basic Properties
| MD5 | 5a46ab02306238eac697ba327079e449 |
| SHA-1 | 04084d2548f231c26cbc9be8275dbc5208f80ea6 |
| SHA-256 | e29c40498d1e2b650e65855ab7051475e4aa6bc54e9b0d8352dda798c5aba339 |
| VHash | 8392799d7739ad72225fd3b9fa512aa9 |
| SSDEEP | 3072:Oo0R0M1GwnMVqH8VMFU79wfmPtK93ura4hCG3yx67uk6nD2c62+hsz:Oo0R0M1GwnMVO+MFwCOPtU3oaKCMl7u3 |
| TLSH | T18DF31A56F9819B11C5C156BAFF0E528D73231B78E2DE72129E246B347B8A87B0E3B015 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped |
| File size | 165.1 KB |
History
| First seen on VirusTotal | 2026-09-07 07:55 UTC |
| Last submission | 2026-09-07 17:53 UTC |
| Last analysis | 2026-09-07 07:55 UTC |
| Last modified on VirusTotal | 2026-09-07 18:05 UTC |
Known Names
a01enbc3.exearmv6liran.armv6l
hash_sha1
04084d2548f231c26cbc9be8275dbc5208f80ea6
VT 31 / 75
IOC database
- Type
- hash_sha1
- Value
04084d2548f231c26cbc9be8275dbc5208f80ea6- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 31 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Generic.40381008 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Arcabit | malicious | Trojan.Generic.D2682A50 |
| Avast | malicious | ELF:Mirai-CYM [Trj] |
| AVG | malicious | ELF:Mirai-CYM [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| BitDefender | malicious | Trojan.Generic.40381008 |
| ClamAV | malicious | Unix.Trojan.Mirai-10056448-0 |
| CTX | malicious | elf.trojan.generic |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| Emsisoft | malicious | Trojan.Generic.40381008 (B) |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.WN!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Gafgyt.bs |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQQ |
| Microsoft | malicious | Backdoor:Linux/Mirai.GJ!MTB |
| MicroWorld-eScan | malicious | Trojan.Generic.40381008 |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Skyhigh | malicious | LINUX/Mirai-FPL!5A46AB023062 |
| Tencent | malicious | Backdoor.Linux.Gafgyt.mbxra |
| TrellixENS | malicious | LINUX/Mirai-FPL!5A46AB023062 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
| VIPRE | malicious | Trojan.Generic.40381008 |
Details From VirusTotal
Basic Properties
| MD5 | 5a46ab02306238eac697ba327079e449 |
| SHA-1 | 04084d2548f231c26cbc9be8275dbc5208f80ea6 |
| SHA-256 | e29c40498d1e2b650e65855ab7051475e4aa6bc54e9b0d8352dda798c5aba339 |
| VHash | 8392799d7739ad72225fd3b9fa512aa9 |
| SSDEEP | 3072:Oo0R0M1GwnMVqH8VMFU79wfmPtK93ura4hCG3yx67uk6nD2c62+hsz:Oo0R0M1GwnMVO+MFwCOPtU3oaKCMl7u3 |
| TLSH | T18DF31A56F9819B11C5C156BAFF0E528D73231B78E2DE72129E246B347B8A87B0E3B015 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, ARM, EABI4 version 1 (SYSV), statically linked, stripped |
| File size | 165.1 KB |
History
| First seen on VirusTotal | 2026-09-07 07:55 UTC |
| Last submission | 2026-09-07 17:53 UTC |
| Last analysis | 2026-09-07 07:55 UTC |
| Last modified on VirusTotal | 2026-09-07 18:05 UTC |
Known Names
a01enbc3.exearmv6liran.armv6l
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 169012 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-09-07 17:50:18.
Remediations (10)
-
web:blog.cloudflare.com
This post offers a retrospective on Mirai , the infamous IoT botnet that disrupted major websites with massive DDoS attacks, leveraging hundreds of thousands of compromised Internet-of-Things devices.
-
web:github.com
This repository contains the leaked source code of the Mirai botnet, originally created to infect IoT devices and launch large-scale DDoS attacks. This code is provided strictly for cybersecurity research, reverse engineering, malware analysis, and detection development purposes only.
-
web:github.com
Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.
-
web:rruzi.github.io
In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01when Mirai goes online is modified to a fixed 8-byte:\x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than Mirai .
-
web:trainsec.net
Mirai Botnet ARM reverse engineering walkthrough with static analysis, key code paths, and practical notes for malware analysts. Learn more >>
-
web:undercodetesting.com
Introduction: A coordinated cyberattack campaign, attributed to Iranian-affiliated threat actors, has targeted programmable logic controllers (PLCs) across U.S. water and wastewater systems in at least 12 states, impacting more than 30 communities in Minnesota alone. The attackers exploited internet-exposed operational technology (OT) devices—including Rockwell Automation, Schneider Electric ...
-
web:www.ic3.gov
Iranian-affiliated APT targeting campaigns against U.S. critical infrastructure have recently escalated, likely in response to hostilities between Iran, and the United States and Israel. (New, July 22, 2026) At one U.S. victim, the FBI observed the APT actors download a malicious project file to a targeted PLC using configuration software.
-
web:www.joesandbox.com
General Information Joe Sandbox version: 44.0.0 Smoke Quartz Analysis ID: 1937818 Start date and time: 2026-07-06 13:08:07 +02:00 Joe Sandbox product: CloudBasic Overall analysis duration: 0h 4m 47s Hypervisor based Inspection enabled: false Report type: full Cookbook file name: defaultlinuxfilecookbook.jbs Analysis system description: Ubuntu Linux 20.04 x64 (Kernel 5.4.0-72, Firefox 91.0 ...
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Executes the "rm" command used to delete files or directories Found strings indicative of a multi-platform dropper Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable Sample has stripped symbol table Uses the "uname ...
-
web:www.yazoul.net
Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.