MB-6a4790b20723e72658973cc0f0611ac27ff804043a96910a66b977c8c5a8b060
high
📛 Threat Title
Mirai: pmpsl
Description
File type: elf. Size: 267520 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-13 19:34:29.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
6a4790b20723e72658973cc0f0611ac27ff804043a96910a66b977c8c5a8b060
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6a4790b20723e72658973cc0f0611ac27ff804043a96910a66b977c8c5a8b060
1 feed
IOC database
- Type
- hash_sha256
- Value
6a4790b20723e72658973cc0f0611ac27ff804043a96910a66b977c8c5a8b060- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6a4790b20723e72658973cc0f0611ac27ff804043a96910a66b977c8c5a8b060
hash_sha1
0edccd552be4557f99d8cf2f1602c7a1f14377f6
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0edccd552be4557f99d8cf2f1602c7a1f14377f6
2 feeds
IOC database
- Type
- hash_sha1
- Value
0edccd552be4557f99d8cf2f1602c7a1f14377f6- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/0edccd552be4557f99d8cf2f1602c7a1f14377f6
hash_md5
19a4203464bc693ce27d947176e3ee2c
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/19a4203464bc693ce27d947176e3ee2c
2 feeds
IOC database
- Type
- hash_md5
- Value
19a4203464bc693ce27d947176e3ee2c- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/19a4203464bc693ce27d947176e3ee2c
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 267520 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-13 19:34:29.
Remediations (10)
-
web:academic.oup.com
In short, Mirai is still a relevant threat and it provides a representative case study for understanding if and how end users can perform remediation . Notification mechanisms. Our partnering ISP and its subsidiary brand have slightly different user populations and their own abuse handling procedures.
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:link.springer.com
Although the mechanism of attacks and implementation of Mirai seems easy, its implementation is challenging. The following paper provides a guided way to understand Mirai malware's functionality and launch it in an isolated environment to do further research on it.
-
web:www.cisecurity.org
The Mirai botnet soon spread to infect thousands of internet of things (IoT) devices and evolved to conduct full, large-scale attacks. After noticing an increase in infections, Mirai caught the attention of the nonprofit organization MalwareMustDie in August 2016, who then started to research, analyze, and track the botnet [2].
-
web:www.jisem-journal.com
Presenting an in-depth security analysis of Mirai botnet, a malware that affected the availability of banking systems and put in evidence a new form of DDoS attack that works with IoT devices compromised by malware. The methods presented are generic and can be used to mitigate any malware of the same nature.
-
web:www.joesandbox.com
Yara detected Mirai Sample deletes itself Sample tries to kill multiple processes (SIGKILL) Creates hidden files and/or directories Detected TCP or UDP traffic on non-standard ports Enumerates processes within the "proc" file system Executes the "rm" command used to delete files or directories Found strings indicative of a multi-platform dropper
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.researchgate.net
Presenting an in-depth security analysis of Mirai botnet, a malware that affected the availability of banking systems and put in evidence a new form of DDoS attack that works with IoT devices ...
-
web:www.sciencedirect.com
Mirai , which means 'future' in Japanese, foreshadowing a more than a one time event, modeled the future of significant attacks to come. Mitigation efforts include patching the vulnerabilities that are leveraged by the Mirai malware family and detecting/preventing Mirai from entering IoT networks.
-
web:www.usenix.org
These unique datasets enable us to conduct the first comprehensive analysis of Mirai and posit technical and non-technical defenses that may stymie future attacks. We track the outbreak of Mirai and find the botnet infected nearly 65,000 IoT devices in its first 20 hours before reaching a steady state population of 200,000- 300,000 infections.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.