MB-c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4
high
📛 Threat Title
Mirai: pppc
Description
File type: elf. Size: 201616 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-13 19:10:41.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4
1 feed
IOC database
- Type
- hash_sha256
- Value
c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Mirai
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4
hash_sha1
d00fa585f46f36afc57e4addb87b228cf5a0d02f
VT 30 / 75
2 feeds
IOC database
- Type
- hash_sha1
- Value
d00fa585f46f36afc57e4addb87b228cf5a0d02f- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Flagged by 30 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| AhnLab-V3 | malicious | Linux/Mirai.Gen35 |
| alibabacloud | malicious | DDoS:Linux/Mirai.CGK |
| Antiy-AVL | malicious | Trojan[Backdoor]/Linux.Mirai |
| Avast | malicious | ELF:Gafgyt-MV [Trj] |
| AVG | malicious | ELF:Gafgyt-MV [Trj] |
| Avira | malicious | EXP/ELF.Mirai.W |
| ClamAV | malicious | Unix.Dropper.Mirai-7135957-0 |
| Cynet | malicious | Malicious (score: 99) |
| DrWeb | malicious | Linux.Mirai.9829 |
| ESET-NOD32 | malicious | Linux/Mirai.CJS trojan |
| F-Secure | malicious | Exploit.EXP/ELF.Mirai.W |
| Fortinet | malicious | ELF/Mirai.A!tr |
| GData | malicious | Linux.Trojan.Gafgyt.B |
| malicious | Detected |
|
| huorong | malicious | Backdoor/Linux.Mirai.ht |
| Ikarus | malicious | Trojan-Downloader.Linux.Agent |
| Kaspersky | malicious | HEUR:Backdoor.Linux.Mirai.b |
| Kingsoft | malicious | Linux.Backdoor.Mirai.b |
| Lionic | malicious | Trojan.Linux.Mirai.K!c |
| McAfeeD | malicious | Trojan:Linux/Mirai.EQY |
| Microsoft | malicious | Trojan:Linux/Mirai.HAV!MTB |
| Rising | malicious | Backdoor.Mirai/Linux!1.12BC2 (CLASSIC) |
| Sangfor | malicious | Suspicious.Linux.Save.a |
| SentinelOne | malicious | Static AI - Malicious ELF |
| Sophos | malicious | Linux/DDoS-CI |
| Tencent | malicious | Linux.Backdoor.Mirai.Azlw |
| TrendMicro | malicious | Possible_MIRAI.SMLBRA53 |
| TrendMicro-HouseCall | malicious | Possible_MIRAI.SMLBRA53 |
| Varist | malicious | E32/Mirai.DO.gen!Eldorado |
| ZoneAlarm | malicious | Linux/DDoS-CI |
Details From VirusTotal
Basic Properties
| MD5 | 216e5278078231602e1e59ed1c02ed66 |
| SHA-1 | d00fa585f46f36afc57e4addb87b228cf5a0d02f |
| SHA-256 | c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4 |
| VHash | 0b5c275a50e655cfa829779903c9b5b3 |
| SSDEEP | 3072:n05gh0/q9bMkvnzzsy5fqAHlxSaDeRPGMEDVwIgUl:c6JlxSaiRPGNDV3l |
| TLSH | T104145B06B31C084BD1632DB42A3F17E093EF9AA134F4B645755F9B8A8272D361589ECE |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped |
| File size | 196.9 KB |
History
| First seen on VirusTotal | 2026-05-13 18:42 UTC |
| Last submission | 2026-05-13 18:42 UTC |
| Last analysis | 2026-05-14 02:43 UTC |
| Last modified on VirusTotal | 2026-05-14 05:27 UTC |
Known Names
hgaoobyz7.exe
hash_md5
216e5278078231602e1e59ed1c02ed66
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/216e5278078231602e1e59ed1c02ed66
2 feeds
IOC database
- Type
- hash_md5
- Value
216e5278078231602e1e59ed1c02ed66- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/216e5278078231602e1e59ed1c02ed66
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 201616 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-13 19:10:41.
Remediations (10)
-
web:arxiv.org
Angela Famera, Ben Hilger, Suman Bhunia, Patrick Heil Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several vari-ants that combined the old code ...
-
web:cipherssecurity.com
Huge Networks ran Mirai attacks against ISPs it claimed to protect. A framework for detecting a DDoS mitigation provider compromise and vetting vendors.
-
web:ellio.tech
An open directory is serving a Mirai variant across 14 CPU architectures - all updated yesterday. It kills competitors by SHA256 hash, persists through six layers, and hides as a kernel thread. Here's what's inside.
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:westoahu.hawaii.edu
Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.
-
web:windowsforum.com
Microsoft says Azure's DDoS protection automatically detected and absorbed an unprecedented cloud-scale flood on October 24 that peaked at 15.72 terabits per second (Tbps) and nearly 3.64 billion packets per second (pps) — an event the company describes as the largest DDoS attack ever observed in the cloud and one that originated from the Aisuru IoT botnet. Background Aisuru is a Mirai ...
-
web:www.amiga-news.de
30.Apr.2025 New PPC hardware announced: "Mirari" featuring USB3, NVME, FPGA (Update 3) Dave "Skateman" Koelman presented a new PPC motherboard developed by Harald 'Geennaam' Kanning in the "Hardware" channel of the Amigans Discord server. Some time later, Kanning himself started posting in our comments section and supplied a pretty extensive overview over the project: The full specifications ...
-
web:www.joesandbox.com
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.
-
web:www.quorumcyber.com
Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.
-
web:www.semanticscholar.org
This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.