MB-fb5aff6d737ab1bda82cbfaf4d73c612026f3cbc7321ddc44cffa899de2a6daa
high
📛 Threat Title
Mirai: px86
Description
File type: elf. Size: 151848 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-14 12:54:23.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
fb5aff6d737ab1bda82cbfaf4d73c612026f3cbc7321ddc44cffa899de2a6daa
VT 38 / 75
1 feed
IOC database
- Type
- hash_sha256
- Value
fb5aff6d737ab1bda82cbfaf4d73c612026f3cbc7321ddc44cffa899de2a6daa- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Flagged by 38 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Linux/Mirai.Gen35 |
| alibabacloud | malicious | DDoS:Linux/Mirai.CGK |
| ALYac | malicious | Trojan.Linux.GenericKD.79358 |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Arcabit | malicious | Trojan.Linux.Generic.D135FE |
| Avast | malicious | ELF:Gafgyt-MV [Trj] |
| AVG | malicious | ELF:Gafgyt-MV [Trj] |
| Avira | malicious | TR/LINUX.Gafgyt.MV |
| BitDefender | malicious | Trojan.Linux.GenericKD.79358 |
| ClamAV | malicious | Unix.Trojan.Mirai-9858729-0 |
| CTX | malicious | elf.trojan.mirai |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9829 |
| Elastic | malicious | Linux.Trojan.Mirai |
| Emsisoft | malicious | Trojan.Linux.GenericKD.79358 (B) |
| ESET-NOD32 | malicious | Linux/Mirai.CJS trojan |
| F-Secure | malicious | Trojan.TR/LINUX.Gafgyt.MV |
| Fortinet | malicious | ELF/UNSTABLE.AT!tr.botnet |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Mirai.ht |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Mirai.b |
| Kingsoft | malicious | Linux.Backdoor.Mirai.b |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.ERC |
| Microsoft | malicious | Backdoor:Linux/Mirai.AU!MTB |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.79358 |
| Rising | malicious | Backdoor.Mirai/Linux!1.12BC2 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Linux/DDoS-CI |
| Symantec | malicious | Linux.Mirai |
| Tencent | malicious | Backdoor.Linux.Mirai.wan |
| TrendMicro | malicious | Backdoor.Linux.BASHLITE.SMJC |
| TrendMicro-HouseCall | malicious | Backdoor.Linux.BASHLITE.SMJC |
| Varist | malicious | E32/Gafgyt.C.gen!Camelot |
| VIPRE | malicious | Trojan.Linux.GenericKD.79358 |
| ZoneAlarm | malicious | Linux/DDoS-CI |
Details From VirusTotal
Basic Properties
| MD5 | 0617602b01d12407ab9af601044db16a |
| SHA-1 | a9431a33d8ba820bc2557f54eeec972f47848cce |
| SHA-256 | fb5aff6d737ab1bda82cbfaf4d73c612026f3cbc7321ddc44cffa899de2a6daa |
| VHash | 7bb8336eb02c878841bb63e512d6698e |
| SSDEEP | 3072:7cZ0aEF+RjYDwroXEU9gJk3Eiln2OtNpLvEkTeEbKOpZuTk0ZyDGqCv6:YiaEF+RkDwoUcgJk3Eil2OjNvEgETRAj |
| TLSH | T135E36CC1F783D0F5D91A01B02067F737DA72E43A102BEE92D7A9DE32AC92651961B35C |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped |
| File size | 148.3 KB |
History
| First seen on VirusTotal | 2026-05-14 13:15 UTC |
| Last submission | 2026-05-14 13:15 UTC |
| Last analysis | 2026-06-15 11:07 UTC |
| Last modified on VirusTotal | 2026-06-17 14:10 UTC |
Known Names
8hf2kin.exe
hash_sha1
a9431a33d8ba820bc2557f54eeec972f47848cce
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/a9431a33d8ba820bc2557f54eeec972f47848cce
2 feeds
IOC database
- Type
- hash_sha1
- Value
a9431a33d8ba820bc2557f54eeec972f47848cce- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/a9431a33d8ba820bc2557f54eeec972f47848cce
hash_md5
0617602b01d12407ab9af601044db16a
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0617602b01d12407ab9af601044db16a
2 feeds
IOC database
- Type
- hash_md5
- Value
0617602b01d12407ab9af601044db16a- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0617602b01d12407ab9af601044db16a
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 151848 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-14 12:54:23.
Remediations (10)
-
web:academic.oup.com
In short, Mirai is still a relevant threat and it provides a representative case study for understanding if and how end users can perform remediation . Notification mechanisms. Our partnering ISP and its subsidiary brand have slightly different user populations and their own abuse handling procedures.
-
web:any.run
Online sandbox report for px86 , tagged as mirai , botnet, verdict: Malicious activity
-
web:arxiv.org
Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...
-
web:dailysecurityreview.com
The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:westoahu.hawaii.edu
Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.
-
web:www.crowdstrike.com
Mirai malware variants that target Linux devices have doubled on stronger Intel-powered chips in Q1 2022.
-
web:www.fortinet.com
FortiGuard Labs analyzes the botnet campaign, a Mirai variant targeting global sectors. Learn its tactics, C2 methods, and Fortinet defenses.…
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Found malware configuration Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Yara detected Gafgyt Yara detected Mirai Contains symbols with names commonly found in malware Sample tries to kill multiple processes (SIGKILL) Creates hidden files and/or directories Detected TCP or UDP ...
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.