MB-7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426
high
📛 Threat Title
Mirai: iran.sh4
Description
File type: elf. Size: 142140 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:36.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426
VT 27 / 75
IOC database
- Type
- hash_sha256
- Value
7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 27 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Backdoor:Linux/Gafgyt.BBB |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Gafgyt |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Dropper.Mirai-7136288-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.LT!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Mirai.co |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQH |
| Microsoft | malicious | Backdoor:Linux/Gafgyt.P!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Trojan.Linux.Mirai.zk |
| TrellixENS | malicious | LINUX/Mirai-FPL!0D2F2976A534 |
| TrendMicro | malicious | Backdoor.Linux.MIRAI.USBLHV26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 0d2f2976a53484e1fcd34fe95d4c4dd3 |
| SHA-1 | e7f67c3cef7baa2c824db54b23e39a669d838803 |
| SHA-256 | 7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426 |
| VHash | 92533318fb6f0365eefd25090e7df146 |
| SSDEEP | 3072:5WbCJEOdQ29RHrmP71xmbdspxYNWtrcVhQT55:5WReQuRHrmjebmo4trkQF5 |
| TLSH | T133D35BB3D825AF58C564E6B1B0318F781B939A6082471FBE19B7C6748087DCDF6163B8 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped |
| File size | 138.8 KB |
History
| First seen on VirusTotal | 2026-08-31 16:24 UTC |
| Last submission | 2026-08-31 16:24 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:59 UTC |
Known Names
pz527v2r.exesh4iran.sh4
hash_sha1
e7f67c3cef7baa2c824db54b23e39a669d838803
VT 27 / 75
IOC database
- Type
- hash_sha1
- Value
e7f67c3cef7baa2c824db54b23e39a669d838803- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 27 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Backdoor:Linux/Gafgyt.BBB |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Gafgyt |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Dropper.Mirai-7136288-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.LT!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Mirai.co |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQH |
| Microsoft | malicious | Backdoor:Linux/Gafgyt.P!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Trojan.Linux.Mirai.zk |
| TrellixENS | malicious | LINUX/Mirai-FPL!0D2F2976A534 |
| TrendMicro | malicious | Backdoor.Linux.MIRAI.USBLHV26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 0d2f2976a53484e1fcd34fe95d4c4dd3 |
| SHA-1 | e7f67c3cef7baa2c824db54b23e39a669d838803 |
| SHA-256 | 7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426 |
| VHash | 92533318fb6f0365eefd25090e7df146 |
| SSDEEP | 3072:5WbCJEOdQ29RHrmP71xmbdspxYNWtrcVhQT55:5WReQuRHrmjebmo4trkQF5 |
| TLSH | T133D35BB3D825AF58C564E6B1B0318F781B939A6082471FBE19B7C6748087DCDF6163B8 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped |
| File size | 138.8 KB |
History
| First seen on VirusTotal | 2026-08-31 16:24 UTC |
| Last submission | 2026-08-31 16:24 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:59 UTC |
Known Names
pz527v2r.exesh4iran.sh4
hash_md5
0d2f2976a53484e1fcd34fe95d4c4dd3
VT 27 / 75
IOC database
- Type
- hash_md5
- Value
0d2f2976a53484e1fcd34fe95d4c4dd3- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 27 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alibabacloud | malicious | Backdoor:Linux/Gafgyt.BBB |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Gafgyt |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Dropper.Mirai-7136288-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9874 |
| ESET-NOD32 | malicious | Linux/Gafgyt.BST trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Gafgyt.LT!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Trojan/Linux.Mirai.co |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Agent.ei |
| Kingsoft | malicious | Script.Troj.Shell.2052936 |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQH |
| Microsoft | malicious | Backdoor:Linux/Gafgyt.P!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.13313 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Mal/Generic-S |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Trojan.Linux.Mirai.zk |
| TrellixENS | malicious | LINUX/Mirai-FPL!0D2F2976A534 |
| TrendMicro | malicious | Backdoor.Linux.MIRAI.USBLHV26 |
| Varist | malicious | E32/Mirai.EN.gen!Camelot |
Details From VirusTotal
Basic Properties
| MD5 | 0d2f2976a53484e1fcd34fe95d4c4dd3 |
| SHA-1 | e7f67c3cef7baa2c824db54b23e39a669d838803 |
| SHA-256 | 7111537e12bc687f39e26784758fb300eec35abd5a87deab520fed68d1bf6426 |
| VHash | 92533318fb6f0365eefd25090e7df146 |
| SSDEEP | 3072:5WbCJEOdQ29RHrmP71xmbdspxYNWtrcVhQT55:5WReQuRHrmjebmo4trkQF5 |
| TLSH | T133D35BB3D825AF58C564E6B1B0318F781B939A6082471FBE19B7C6748087DCDF6163B8 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Renesas SH, version 1 (SYSV), statically linked, stripped |
| File size | 138.8 KB |
History
| First seen on VirusTotal | 2026-08-31 16:24 UTC |
| Last submission | 2026-08-31 16:24 UTC |
| Last analysis | 2026-08-31 18:03 UTC |
| Last modified on VirusTotal | 2026-08-31 23:59 UTC |
Known Names
pz527v2r.exesh4iran.sh4
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 142140 bytes. Tags: Mirai. Reporter: BlinkzSec. First seen: 2026-08-31 16:14:36.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:arxiv.org
Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...
-
web:arxiv.org
Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:rruzi.github.io
The C2 port is randomly selected between 25596 and 25616. In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01 when Mirai goes online is modified to a fixed 8-byte: \x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than ...
-
web:threatfox.abuse.ch
Anonymous Http Payload Delivery On Port 80 At 103.83.87.122 Bash Script Dropper "telnet.sh" Downloads All Binaries with the prefix iran.arch and chmod 777 * then executes them with the string "telnet" indicating The Dropper Script Is Intended Use For Telnet Bruted Devices Such As Routers , Dvrs , Servers
-
web:www.akamai.com
Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .
-
web:www.joesandbox.com
Automated Malware Analysis - Joe Sandbox Analysis Report • AV Detection • Networking • System Summary • Hooking and other Techniques for Hiding and Protection • Malware Analysis System Evasion • Stealing of Sensitive Information • Remote Access Functionality
-
web:www.joesandbox.com
File: /tmp/iran.sh4.elf Jump to behavior Malware Analysis System Evasion Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/iran.sh4.elf (PID: 5836) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings found in memory)
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.