s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426 high

📛 Threat Title

Mirai: iran.sh4

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 142140 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:36.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426 VT 27 / 75

IOC database

Type
hash_sha256
Value
7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 27 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Backdoor:Linux/Gafgyt.BBB
Antiy-AVL malicious Trojan[Backdoor]/Linux.Gafgyt
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Dropper.Mirai-7136288-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.LT!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Trojan/Linux.Mirai.co
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQH
Microsoft malicious Backdoor:Linux/Gafgyt.P!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Trojan.Linux.Mirai.zk
TrellixENS malicious LINUX/Mirai-FPL!0D2F2976A534
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD50d2f2976a53484e1fcd34fe95d4c4dd3
SHA-1e7f67c3cef7baa2c824db54b23e39a669d838803
SHA-2567111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426
VHash92533318fb6f0365eefd25090e7df146
SSDEEP3072:5WbCJEOdQ29RHrmP71xmbdspxYNWtrcVhQT55:5WReQuRHrmjebmo4trkQF5
TLSHT133D35BB3D825AF58C564E6B1B0318F781B939A6082471FBE19B7C6748087DCDF6163B8
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
File size138.8 KB
History
First seen on VirusTotal2026-08-31 16:24 UTC
Last submission2026-08-31 16:24 UTC
Last analysis2026-08-31 18:03 UTC
Last modified on VirusTotal2026-08-31 23:59 UTC
Known Names
  • pz527v2r.exe
  • sh4
  • iran.sh4
hash_sha1 e7f67c3cef7baa2c824db54b23e39a669d838803 VT 27 / 75

IOC database

Type
hash_sha1
Value
e7f67c3cef7baa2c824db54b23e39a669d838803
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 27 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Backdoor:Linux/Gafgyt.BBB
Antiy-AVL malicious Trojan[Backdoor]/Linux.Gafgyt
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Dropper.Mirai-7136288-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.LT!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Trojan/Linux.Mirai.co
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQH
Microsoft malicious Backdoor:Linux/Gafgyt.P!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Trojan.Linux.Mirai.zk
TrellixENS malicious LINUX/Mirai-FPL!0D2F2976A534
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD50d2f2976a53484e1fcd34fe95d4c4dd3
SHA-1e7f67c3cef7baa2c824db54b23e39a669d838803
SHA-2567111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426
VHash92533318fb6f0365eefd25090e7df146
SSDEEP3072:5WbCJEOdQ29RHrmP71xmbdspxYNWtrcVhQT55:5WReQuRHrmjebmo4trkQF5
TLSHT133D35BB3D825AF58C564E6B1B0318F781B939A6082471FBE19B7C6748087DCDF6163B8
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
File size138.8 KB
History
First seen on VirusTotal2026-08-31 16:24 UTC
Last submission2026-08-31 16:24 UTC
Last analysis2026-08-31 18:03 UTC
Last modified on VirusTotal2026-08-31 23:59 UTC
Known Names
  • pz527v2r.exe
  • sh4
  • iran.sh4
hash_md5 0d2f2976a53484e1fcd34fe95d4c4dd3 VT 27 / 75

IOC database

Type
hash_md5
Value
0d2f2976a53484e1fcd34fe95d4c4dd3
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 27 of 75 VirusTotal vendors

VendorVerdictDetection
alibabacloud malicious Backdoor:Linux/Gafgyt.BBB
Antiy-AVL malicious Trojan[Backdoor]/Linux.Gafgyt
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Dropper.Mirai-7136288-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9874
ESET-NOD32 malicious Linux/Gafgyt.BST trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Gafgyt.LT!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Trojan/Linux.Mirai.co
Kaspersky malicious HEUR:Backdoor.Linux.Agent.ei
Kingsoft malicious Script.Troj.Shell.2052936
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQH
Microsoft malicious Backdoor:Linux/Gafgyt.P!MTB
Rising malicious Backdoor.Mirai/Linux!1.13313 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Mal/Generic-S
Symantec malicious Linux.Mirai
Tencent malicious Trojan.Linux.Mirai.zk
TrellixENS malicious LINUX/Mirai-FPL!0D2F2976A534
TrendMicro malicious Backdoor.Linux.MIRAI.USBLHV26
Varist malicious E32/Mirai.EN.gen!Camelot

Details From VirusTotal

Basic Properties
MD50d2f2976a53484e1fcd34fe95d4c4dd3
SHA-1e7f67c3cef7baa2c824db54b23e39a669d838803
SHA-2567111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426
VHash92533318fb6f0365eefd25090e7df146
SSDEEP3072:5WbCJEOdQ29RHrmP71xmbdspxYNWtrcVhQT55:5WReQuRHrmjebmo4trkQF5
TLSHT133D35BB3D825AF58C564E6B1B0318F781B939A6082471FBE19B7C6748087DCDF6163B8
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped
File size138.8 KB
History
First seen on VirusTotal2026-08-31 16:24 UTC
Last submission2026-08-31 16:24 UTC
Last analysis2026-08-31 18:03 UTC
Last modified on VirusTotal2026-08-31 23:59 UTC
Known Names
  • pz527v2r.exe
  • sh4
  • iran.sh4

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 142140 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:36.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:arxiv.org

    Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...

  • web:arxiv.org

    Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:rruzi.github.io

    The C2 port is randomly selected between 25596 and 25616. In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01 when Mirai goes online is modified to a fixed 8-byte: \x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than ...

  • web:threatfox.abuse.ch

    Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.joesandbox.com

    Automated Malware Analysis - Joe Sandbox Analysis Report • AV Detection • Networking • System Summary • Hooking and other Techniques for Hiding and Protection • Malware Analysis System Evasion • Stealing of Sensitive Information • Remote Access Functionality

  • web:www.joesandbox.com

    File: /tmp/iran.sh4.elf Jump to behavior Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/iran.sh4.elf (PID: 5836) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.