s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4 high

📛 Threat Title

Mirai: pppc

Category: Mirai First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 201616 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-13 19:10:41.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4
1 feed

IOC database

Type
hash_sha256
Value
c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4

hash_sha1 d00fa585f46f36afc57e4addb87b228cf5a0d02f VT 30 / 75 2 feeds

IOC database

Type
hash_sha1
Value
d00fa585f46f36afc57e4addb87b228cf5a0d02f
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Flagged by 30 of 75 VirusTotal vendors

VendorVerdictDetection
AhnLab-V3 malicious Linux/Mirai.Gen35
alibabacloud malicious DDoS:Linux/Mirai.CGK
Antiy-AVL malicious Trojan[Backdoor]/Linux.Mirai
Avast malicious ELF:Gafgyt-MV [Trj]
AVG malicious ELF:Gafgyt-MV [Trj]
Avira malicious EXP/ELF.Mirai.W
ClamAV malicious Unix.Dropper.Mirai-7135957-0
Cynet malicious Malicious (score: 99)
DrWeb malicious Linux.Mirai.9829
ESET-NOD32 malicious Linux/Mirai.CJS trojan
F-Secure malicious Exploit.EXP/ELF.Mirai.W
Fortinet malicious ELF/Mirai.A!tr
GData malicious Linux.Trojan.Gafgyt.B
Google malicious Detected
huorong malicious Backdoor/Linux.Mirai.ht
Ikarus malicious Trojan-Downloader.Linux.Agent
Kaspersky malicious HEUR:Backdoor.Linux.Mirai.b
Kingsoft malicious Linux.Backdoor.Mirai.b
Lionic malicious Trojan.Linux.Mirai.K!c
McAfeeD malicious Trojan:Linux/Mirai.EQY
Microsoft malicious Trojan:Linux/Mirai.HAV!MTB
Rising malicious Backdoor.Mirai/Linux!1.12BC2 (CLASSIC)
Sangfor malicious Suspicious.Linux.Save.a
SentinelOne malicious Static AI - Malicious ELF
Sophos malicious Linux/DDoS-CI
Tencent malicious Linux.Backdoor.Mirai.Azlw
TrendMicro malicious Possible_MIRAI.SMLBRA53
TrendMicro-HouseCall malicious Possible_MIRAI.SMLBRA53
Varist malicious E32/Mirai.DO.gen!Eldorado
ZoneAlarm malicious Linux/DDoS-CI

Details From VirusTotal

Basic Properties
MD5216e5278078231602e1e59ed1c02ed66
SHA-1d00fa585f46f36afc57e4addb87b228cf5a0d02f
SHA-256c63cd4f058daedfca2435584edfefd7c966c54e9313fbbb7d0933ff04dba27d4
VHash0b5c275a50e655cfa829779903c9b5b3
SSDEEP3072:n05gh0/q9bMkvnzzsy5fqAHlxSaDeRPGMEDVwIgUl:c6JlxSaiRPGNDV3l
TLSHT104145B06B31C084BD1632DB42A3F17E093EF9AA134F4B645755F9B8A8272D361589ECE
File typeELF
File type tagelf
MagicELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, stripped
File size196.9 KB
History
First seen on VirusTotal2026-05-13 18:42 UTC
Last submission2026-05-13 18:42 UTC
Last analysis2026-05-14 02:43 UTC
Last modified on VirusTotal2026-05-14 05:27 UTC
Known Names
  • hgaoobyz7.exe
hash_md5 216e5278078231602e1e59ed1c02ed66 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/216e5278078231602e1e59ed1c02ed66
2 feeds

IOC database

Type
hash_md5
Value
216e5278078231602e1e59ed1c02ed66
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/216e5278078231602e1e59ed1c02ed66

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 201616 bytes. Tags: elf, Mirai, upx-dec. Reporter: abuse_ch. First seen: 2026-05-13 19:10:41.

Remediations (10)

  • web:arxiv.org

    Angela Famera, Ben Hilger, Suman Bhunia, Patrick Heil Abstract—Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed its predecessors. Its developers released the source code, which triggered the development of several vari-ants that combined the old code ...

  • web:cipherssecurity.com

    Huge Networks ran Mirai attacks against ISPs it claimed to protect. A framework for detecting a DDoS mitigation provider compromise and vetting vendors.

  • web:ellio.tech

    An open directory is serving a Mirai variant across 14 CPU architectures - all updated yesterday. It kills competitors by SHA256 hash, persists through six layers, and hides as a kernel thread. Here's what's inside.

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:westoahu.hawaii.edu

    Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.

  • web:windowsforum.com

    Microsoft says Azure's DDoS protection automatically detected and absorbed an unprecedented cloud-scale flood on October 24 that peaked at 15.72 terabits per second (Tbps) and nearly 3.64 billion packets per second (pps) — an event the company describes as the largest DDoS attack ever observed in the cloud and one that originated from the Aisuru IoT botnet. Background Aisuru is a Mirai ...

  • web:www.amiga-news.de

    30.Apr.2025 New PPC hardware announced: "Mirari" featuring USB3, NVME, FPGA (Update 3) Dave "Skateman" Koelman presented a new PPC motherboard developed by Harald 'Geennaam' Kanning in the "Hardware" channel of the Amigans Discord server. Some time later, Kanning himself started posting in our comments section and supplied a pretty extensive overview over the project: The full specifications ...

  • web:www.joesandbox.com

    Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese.

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.semanticscholar.org

    This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.