s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-fbde93278c6b68302a0b0980d4e89cda1b8fd56efbfc0a15fa4c29903b4fbda6 high

📛 Threat Title

Mirai: bot.sh4

Category: Mirai First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 114080 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-13 20:53:20.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 fbde93278c6b68302a0b0980d4e89cda1b8fd56efbfc0a15fa4c29903b4fbda6 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/fbde93278c6b68302a0b0980d4e89cda1b8fd56efbfc0a15fa4c29903b4fbda6
1 feed

IOC database

Type
hash_sha256
Value
fbde93278c6b68302a0b0980d4e89cda1b8fd56efbfc0a15fa4c29903b4fbda6
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Abuse.ch. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/fbde93278c6b68302a0b0980d4e89cda1b8fd56efbfc0a15fa4c29903b4fbda6

hash_sha1 80947341dd51277a26916e0a8339c0dede30c60b VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/80947341dd51277a26916e0a8339c0dede30c60b
2 feeds

IOC database

Type
hash_sha1
Value
80947341dd51277a26916e0a8339c0dede30c60b
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/80947341dd51277a26916e0a8339c0dede30c60b

hash_md5 6db196b886ab40d4bc598ea9b2243e69 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6db196b886ab40d4bc598ea9b2243e69
2 feeds

IOC database

Type
hash_md5
Value
6db196b886ab40d4bc598ea9b2243e69
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 2 threat-intel feed vendors: Abuse.ch, threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/files/6db196b886ab40d4bc598ea9b2243e69

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 114080 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-05-13 20:53:20.

Remediations (8)

  • web:arxiv.org

    Paras Jha and Josiah White created Mirai , co-founders of Protraf Solutions, which offered mitigation services for DDoS attacks [28]. Mirai has created the basis for many botnets that exist today.

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:westoahu.hawaii.edu

    Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.

  • web:www.akamai.com

    Akamai has uncovered two zero-day vulnerabilities that are being actively exploited to spread a Mirai variant in the wild. Read on for details and mitigation .

  • web:www.cisecurity.org

    The Mirai botnet soon spread to infect thousands of internet of things (IoT) devices and evolved to conduct full, large-scale attacks. After noticing an increase in infections, Mirai caught the attention of the nonprofit organization MalwareMustDie in August 2016, who then started to research, analyze, and track the botnet [2].

  • web:www.extremenetworks.com

    The first step in detecting Mirai botnet scanning is to look for port sweeps on ports 23 and 2323. However, in a quirk unique to Mirai , scanning nodes do not scan for these two ports on an equal basis. As you can see from the connection counter "i" in the following code snippet, Mirai scans for port 23 vs. 2323 in a 1/10 th ratio.

  • web:www.quorumcyber.com

    Mirai initially infected and weaponised devices such as smart cameras and Realtek routers2. The botnet variant was created in a racketeering attempt by the cofounders of Protraf Solutions, an organisation offering DDoS mitigation services.

  • web:www.semanticscholar.org

    This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.