s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-fb5aff6d737ab1bda82cbfaf4d73c612026f3cbc7321ddc44cffa899de2a6daa high

📛 Threat Title

Mirai: px86

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 151848 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-14 12:54:23.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 fb5aff6d737ab1bda82cbfaf4d73c612026f3cbc7321ddc44cffa899de2a6daa VT 38 / 75 1 feed

IOC database

Type
hash_sha256
Value
fb5aff6d737ab1bda82cbfaf4d73c612026f3cbc7321ddc44cffa899de2a6daa
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Flagged by 38 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Linux/Mirai.Gen35
alibabacloud malicious DDoS:Linux/Mirai.CGK
ALYac malicious Trojan.Linux.GenericKD.79358
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Arcabit malicious Trojan.Linux.Generic.D135FE
Avast malicious ELF:Gafgyt-MV [Trj]
AVG malicious ELF:Gafgyt-MV [Trj]
Avira malicious TR/LINUX.Gafgyt.MV
BitDefender malicious Trojan.Linux.GenericKD.79358
ClamAV malicious Unix.Trojan.Mirai-9858729-0
CTX malicious elf.trojan.mirai
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9829
Elastic malicious Linux.Trojan.Mirai
Emsisoft malicious Trojan.Linux.GenericKD.79358 (B)
ESET-NOD32 malicious Linux/Mirai.CJS trojan
F-Secure malicious Trojan.TR/LINUX.Gafgyt.MV
Fortinet malicious ELF/UNSTABLE.AT!tr.botnet
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Mirai.ht
Kaspersky malicious HEUR:Backdoor.Linux.Mirai.b
Kingsoft malicious Linux.Backdoor.Mirai.b
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.ERC
Microsoft malicious Backdoor:Linux/Mirai.AU!MTB
MicroWorld-eScan malicious Trojan.Linux.GenericKD.79358
Rising malicious Backdoor.Mirai/Linux!1.12BC2 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Linux/DDoS-CI
Symantec malicious Linux.Mirai
Tencent malicious Backdoor.Linux.Mirai.wan
TrendMicro malicious Backdoor.Linux.BASHLITE.SMJC
TrendMicro-HouseCall malicious Backdoor.Linux.BASHLITE.SMJC
Varist malicious E32/Gafgyt.C.gen!Camelot
VIPRE malicious Trojan.Linux.GenericKD.79358
ZoneAlarm malicious Linux/DDoS-CI

Details From VirusTotal

Basic Properties
MD50617602b01d12407ab9af601044db16a
SHA-1a9431a33d8ba820bc2557f54eeec972f47848cce
SHA-256fb5aff6d737ab1bda82cbfaf4d73c612026f3cbc7321ddc44cffa899de2a6daa
VHash7bb8336eb02c878841bb63e512d6698e
SSDEEP3072:7cZ0aEF+RjYDwroXEU9gJk3Eiln2OtNpLvEkTeEbKOpZuTk0ZyDGqCv6:YiaEF+RkDwoUcgJk3Eil2OjNvEgETRAj
TLSHT135E36CC1F783D0F5D91A01B02067F737DA72E43A102BEE92D7A9DE32AC92651961B35C
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, stripped
File size148.3 KB
History
First seen on VirusTotal2026-05-14 13:15 UTC
Last submission2026-05-14 13:15 UTC
Last analysis2026-06-15 11:07 UTC
Last modified on VirusTotal2026-06-17 14:10 UTC
Known Names
  • 8hf2kin.exe
hash_sha1 a9431a33d8ba820bc2557f54eeec972f47848cce VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/a9431a33d8ba820bc2557f54eeec972f47848cce
2 feeds

IOC database

Type
hash_sha1
Value
a9431a33d8ba820bc2557f54eeec972f47848cce
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/a9431a33d8ba820bc2557f54eeec972f47848cce

hash_md5 0617602b01d12407ab9af601044db16a VT: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0617602b01d12407ab9af601044db16a
2 feeds

IOC database

Type
hash_md5
Value
0617602b01d12407ab9af601044db16a
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for files/0617602b01d12407ab9af601044db16a

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 151848 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-14 12:54:23.

Remediations (10)

  • web:academic.oup.com

    In short, Mirai is still a relevant threat and it provides a representative case study for understanding if and how end users can perform remediation . Notification mechanisms. Our partnering ISP and its subsidiary brand have slightly different user populations and their own abuse handling procedures.

  • web:any.run

    Online sandbox report for px86 , tagged as mirai , botnet, verdict: Malicious activity

  • web:arxiv.org

    Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several variants that combined the old code with newer vulnerabilities found on popular IoT devices. The ...

  • web:dailysecurityreview.com

    The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:westoahu.hawaii.edu

    Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.

  • web:www.crowdstrike.com

    Mirai malware variants that target Linux devices have doubled on stronger Intel-powered chips in Q1 2022.

  • web:www.fortinet.com

    FortiGuard Labs analyzes the botnet campaign, a Mirai variant targeting global sectors. Learn its tactics, C2 methods, and Fortinet defenses.…

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Found malware configuration Malicious sample detected (through community Yara rule) Multi AV Scanner detection for submitted file Yara detected Gafgyt Yara detected Mirai Contains symbols with names commonly found in malware Sample tries to kill multiple processes (SIGKILL) Creates hidden files and/or directories Detected TCP or UDP ...

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.