TF-1932728
high
📛 Threat Title
Unknown malware: SHA256 hash of a malware sample (payload) 1921fbac7491fd43f197b13d471e7faab8fd41273115ce36ba3731b74934d01b
Description
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Unknown malware. Confidence: 75. First seen: 2026-09-25 08:34:32 UTC. Reporter: Portfwd. Tags: cowrie, elf, ssh-honeypot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
1921fbac7491fd43f197b13d471e7faab8fd41273115ce36ba3731b74934d01b
VT 28 / 75
IOC database
- Type
- hash_sha256
- Value
1921fbac7491fd43f197b13d471e7faab8fd41273115ce36ba3731b74934d01b- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 28 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | DDoS:Linux/Mirai.QZ |
| Arcabit | malicious | Trojan.Linux.Generic.D3946B94 |
| Avira | malicious | PUA/LINUX.Agent.BQZ |
| BitDefender | malicious | Trojan.Linux.GenericKD.60058516 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.11245 |
| Emsisoft | malicious | Trojan.Linux.GenericKD.60058516 (B) |
| ESET-NOD32 | malicious | Linux/Mirai.FLG trojan |
| F-Secure | malicious | PotentialRisk.PUA/LINUX.Agent.BQZ |
| Fortinet | malicious | Adware/Mirai |
| GData | malicious | Linux.Trojan.Agent.4LLOUM |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Mirai.q |
| Ikarus | malicious | Trojan.Linux.Mirai |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Mirai.ml |
| Kingsoft | malicious | Linux.Backdoor.Mirai.ml |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | ti!1921FBAC7491 |
| Microsoft | malicious | Backdoor:Linux/Multiverze!rfn |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.60058516 |
| Rising | malicious | Backdoor.Mirai/Linux!1.14537 (CLOUD) |
| Sangfor | malicious | PUP.Linux.Mirai.Vyq7 |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | PUA.Gen.2 |
| Tencent | malicious | Linux.Backdoor.Mirai.Pjgl |
| TrendMicro-HouseCall | malicious | Backdoor.Linux.MIRAI.USBLIP26 |
| Varist | malicious | E32/ABApplication.WEI |
Details From VirusTotal
Basic Properties
| MD5 | 568866b60ad0df439e72cac79a29d733 |
| SHA-1 | 7020c045e98a32fd9fcafc229d61db3587a2098e |
| SHA-256 | 1921fbac7491fd43f197b13d471e7faab8fd41273115ce36ba3731b74934d01b |
| VHash | ea73b7e8c01fd8e53b7e4f1937c0a056 |
| SSDEEP | 3072:chKcSKzL1SXvsxpuhNqancadgUNHLtlshLFH3G9mLxRozfSjy9QItTWMcblshnVS:cqKv18KUhNqHUBLA33G4LxRYR+ItTWM8 |
| TLSH | T18DE3124C12828DF6D1528F7512EF522FEF2EEE506B0DFC4248D494CA1D8F56B397A862 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, MIPS, MIPS-I version 1 (SYSV), statically linked, no section header |
| File size | 143.1 KB |
History
| First seen on VirusTotal | 2026-09-24 21:54 UTC |
| Last submission | 2026-09-24 21:54 UTC |
| Last analysis | 2026-09-26 00:43 UTC |
| Last modified on VirusTotal | 2026-09-26 00:57 UTC |
Known Names
yze4ougay.exemips
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Unknown malware. Confidence: 75. First seen: 2026-09-25 08:34:32 UTC. Reporter: Portfwd. Tags: cowrie, elf, ssh-honeypot.
Remediations (10)
-
web:bazaar.abuse.ch
MalwareBazaar MalwareBazaar is a platform from abuse.ch and Spamhaus, dedicated to sharing malware samples with the infosec community, antivirus vendors, and threat intelligence providers. Upload malware samples and explore the database for valuable intelligence. Set alerts to track newly observed malware , use APIs to seamlessly push or pull signals, and automate bulk queries. With this ...
-
web:bazaar.abuse.ch
Browse malware samples MalwareBazaar Database You are browsing the malware sample database of MalwareBazaar. If you would like to contribute malware samples to the corpus, you can do so through either using the web upload or the API.
-
web:cipherssecurity.com
What it does When you encounter an unknown executable, the fastest triage step is hash reputation: compute its cryptographic fingerprint and check threat-intel feeds for prior submissions. Our checker queries MalwareBazaar (abuse.ch's curated malicious- sample database) and VirusTotal, returning the aggregated verdict plus per-source details.
-
web:github.com
A public repository that provides regularly updated lists of malicious file hashes (MD5, SHA-1, SHA-256 ) and related metadata for use in firewall, gateway endpoint or other security device blocking...
-
web:hash.cymru.com
Malware Hash Registry (MHR) This web form provides a manual interface for checking hashes against our malware data. Type in one or more hashes into the box below, then press "submit" to see if we recognize the hash as malicious.
-
web:inventivehq.com
Check any file hash in seconds. Paste an MD5, SHA-1 or SHA-256 hash , or drop a file to hash it locally, then check it against live malware feeds.
-
web:ismalicious.com
Database of known malware file hashes. MD5, SHA1, and SHA256 hashes with malware family classification. Updated daily from sandbox analysis and vendor feeds.
-
web:ismalicious.com
File Hash Reputation MD5, SHA1, and SHA256 malware hash lookup Check a file hash before it becomes a manual investigation bottleneck. Enrich MD5, SHA1, and SHA256 indicators with reputation, malware context, related infrastructure, and API-ready evidence for SOC queues and incident response.
-
web:polyswarm.io
Search millions of analyzed artifacts by hash , IOC, or 1000+ metadata fields. Instant threat intelligence lookups from scan and sandbox results. API-first for SOC automation.
-
web:talosintelligence.com
Use Talos' File Reputation lookup to find the reputation, file name, weighted reputation score, and detection information available for a given SHA256 .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.