MB-cb8959d2e8c49371739438995796bbbebad72aeac90fe3f386a2a3548e336477
high
📛 Threat Title
Mirai: stub.x86-64
Description
File type: elf. Size: 890234 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:58:40.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
cb8959d2e8c49371739438995796bbbebad72aeac90fe3f386a2a3548e336477
VT 16 / 75
IOC database
- Type
- hash_sha256
- Value
cb8959d2e8c49371739438995796bbbebad72aeac90fe3f386a2a3548e336477- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 16 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Linux.GenericKD.60057791 |
| Antiy-AVL | malicious | Trojan/Linux.Zapchast |
| Arcabit | malicious | Trojan.Linux.Generic.D3946A6E |
| BitDefender | malicious | Trojan.Linux.GenericKD.60058222 |
| CTX | malicious | elf.trojan.generic |
| Emsisoft | malicious | Trojan.Linux.GenericKD.60058222 (B) |
| ESET-NOD32 | malicious | Linux/Agent.BMJ trojan |
| GData | malicious | Trojan.Linux.GenericKD.60058222 |
| huorong | malicious | Trojan/Linux.Agent.es |
| Lionic | malicious | Trojan.ELF.Mirai.4!c |
| McAfeeD | malicious | Trojan:Script/Dirtydecrypt.EAA |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.60058222 |
| Rising | malicious | Trojan.Agent/Linux!8.13268 (CLOUD) |
| Tencent | malicious | Malware.Linux.Generic.1c0c123d |
| VIPRE | malicious | Trojan.Linux.GenericKD.60058222 |
Details From VirusTotal
Basic Properties
| MD5 | 0a340515df2182e15875e94ddd889823 |
| SHA-1 | e959589ba156bf6d4f9358734b74684816b77684 |
| SHA-256 | cb8959d2e8c49371739438995796bbbebad72aeac90fe3f386a2a3548e336477 |
| VHash | eec77128256b007eaf21ffa93e146bc4 |
| SSDEEP | 12288:ZugNP46S4QVs7a+6xGv/7VZji59IH0j/APyYiztSIHmxAowYRsXPi/B:7NP46S4QVs7l6A5Zji59k0jZz06FYRsy |
| TLSH | T11A157C5BB2F374BDC157C134479BCA72A935F46502122E7FA1C8C6302E2AE641B1AF76 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, BuildID[sha1]=254243f4644a531f0b1396c2dd32b9080165d855, for GNU/Linux 3.2.0, not stripped |
| File size | 869.4 KB |
History
| First seen on VirusTotal | 2026-09-25 11:36 UTC |
| Last submission | 2026-09-25 11:36 UTC |
| Last analysis | 2026-09-25 11:36 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
copy
hash_sha1
e959589ba156bf6d4f9358734b74684816b77684
VT 16 / 75
IOC database
- Type
- hash_sha1
- Value
e959589ba156bf6d4f9358734b74684816b77684- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 16 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Linux.GenericKD.60057791 |
| Antiy-AVL | malicious | Trojan/Linux.Zapchast |
| Arcabit | malicious | Trojan.Linux.Generic.D3946A6E |
| BitDefender | malicious | Trojan.Linux.GenericKD.60058222 |
| CTX | malicious | elf.trojan.generic |
| Emsisoft | malicious | Trojan.Linux.GenericKD.60058222 (B) |
| ESET-NOD32 | malicious | Linux/Agent.BMJ trojan |
| GData | malicious | Trojan.Linux.GenericKD.60058222 |
| huorong | malicious | Trojan/Linux.Agent.es |
| Lionic | malicious | Trojan.ELF.Mirai.4!c |
| McAfeeD | malicious | Trojan:Script/Dirtydecrypt.EAA |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.60058222 |
| Rising | malicious | Trojan.Agent/Linux!8.13268 (CLOUD) |
| Tencent | malicious | Malware.Linux.Generic.1c0c123d |
| VIPRE | malicious | Trojan.Linux.GenericKD.60058222 |
Details From VirusTotal
Basic Properties
| MD5 | 0a340515df2182e15875e94ddd889823 |
| SHA-1 | e959589ba156bf6d4f9358734b74684816b77684 |
| SHA-256 | cb8959d2e8c49371739438995796bbbebad72aeac90fe3f386a2a3548e336477 |
| VHash | eec77128256b007eaf21ffa93e146bc4 |
| SSDEEP | 12288:ZugNP46S4QVs7a+6xGv/7VZji59IH0j/APyYiztSIHmxAowYRsXPi/B:7NP46S4QVs7l6A5Zji59k0jZz06FYRsy |
| TLSH | T11A157C5BB2F374BDC157C134479BCA72A935F46502122E7FA1C8C6302E2AE641B1AF76 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, BuildID[sha1]=254243f4644a531f0b1396c2dd32b9080165d855, for GNU/Linux 3.2.0, not stripped |
| File size | 869.4 KB |
History
| First seen on VirusTotal | 2026-09-25 11:36 UTC |
| Last submission | 2026-09-25 11:36 UTC |
| Last analysis | 2026-09-25 11:36 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
copy
hash_md5
0a340515df2182e15875e94ddd889823
VT 16 / 75
IOC database
- Type
- hash_md5
- Value
0a340515df2182e15875e94ddd889823- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 16 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ALYac | malicious | Trojan.Linux.GenericKD.60057791 |
| Antiy-AVL | malicious | Trojan/Linux.Zapchast |
| Arcabit | malicious | Trojan.Linux.Generic.D3946A6E |
| BitDefender | malicious | Trojan.Linux.GenericKD.60058222 |
| CTX | malicious | elf.trojan.generic |
| Emsisoft | malicious | Trojan.Linux.GenericKD.60058222 (B) |
| ESET-NOD32 | malicious | Linux/Agent.BMJ trojan |
| GData | malicious | Trojan.Linux.GenericKD.60058222 |
| huorong | malicious | Trojan/Linux.Agent.es |
| Lionic | malicious | Trojan.ELF.Mirai.4!c |
| McAfeeD | malicious | Trojan:Script/Dirtydecrypt.EAA |
| Microsoft | malicious | Trojan:Script/Wacatac.B!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.60058222 |
| Rising | malicious | Trojan.Agent/Linux!8.13268 (CLOUD) |
| Tencent | malicious | Malware.Linux.Generic.1c0c123d |
| VIPRE | malicious | Trojan.Linux.GenericKD.60058222 |
Details From VirusTotal
Basic Properties
| MD5 | 0a340515df2182e15875e94ddd889823 |
| SHA-1 | e959589ba156bf6d4f9358734b74684816b77684 |
| SHA-256 | cb8959d2e8c49371739438995796bbbebad72aeac90fe3f386a2a3548e336477 |
| VHash | eec77128256b007eaf21ffa93e146bc4 |
| SSDEEP | 12288:ZugNP46S4QVs7a+6xGv/7VZji59IH0j/APyYiztSIHmxAowYRsXPi/B:7NP46S4QVs7l6A5Zji59k0jZz06FYRsy |
| TLSH | T11A157C5BB2F374BDC157C134479BCA72A935F46502122E7FA1C8C6302E2AE641B1AF76 |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, BuildID[sha1]=254243f4644a531f0b1396c2dd32b9080165d855, for GNU/Linux 3.2.0, not stripped |
| File size | 869.4 KB |
History
| First seen on VirusTotal | 2026-09-25 11:36 UTC |
| Last submission | 2026-09-25 11:36 UTC |
| Last analysis | 2026-09-25 11:36 UTC |
| Last modified on VirusTotal | 2026-09-25 18:09 UTC |
Known Names
copy
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 890234 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:58:40.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:dailysecurityreview.com
The Mirai botnet, a notorious piece of malware, launched devastating DDoS attacks in 2016. This blog post delves into its origins, spread, impact, and the ongoing threat it represents, providing crucial information on mitigating Mirai botnet risks.
-
web:deepwiki.com
Installation Guide Relevant source files Purpose and Scope This guide provides comprehensive instructions for setting up the Condi- Mirai botnet environment, including system dependencies, cross-compiler installation, database configuration, and service execution. This document covers the complete initial setup process needed to get the Condi- Mirai botnet operational. System Requirements The ...
-
web:github.com
This repository contains the leaked source code of the Mirai botnet, originally created to infect IoT devices and launch large-scale DDoS attacks. This code is provided strictly for cybersecurity research, reverse engineering, malware analysis, and detection development purposes only.
-
web:github.com
Contribute to malol01/cross-compiler-for- mirai -archive development by creating an account on GitHub.
-
web:malpedia.caad.fkie.fraunhofer.de
Mirai is one of the first significant botnets targeting exposed networking devices running Linux. Found in August 2016 by MalwareMustDie, its name means "future" in Japanese. Nowadays it targets a wide range of networked embedded devices such as IP cameras, home routers (many vendors involved), and other IoT devices. Since the source code was published on "Hack Forums" many variants of the ...
-
web:mirailovers.io
okay this is fixed tutorial for setup any mirai botnet on centos7, just keep in mind in some sources you need encrypt and replace hash string in table.c for cnc and scan domain ( also the others ip address with your own in main.go , main.c and etc.. } root~#@: setup tut for centos7 website~#@: https://mirailovers/ telegram~#@: https://t.me ...
-
web:rruzi.github.io
In-depth Analysis of a New Mirai Variant 7 minute read Published: December 28, 2024 I. Background Recently, NSFOCUS [1], National Cyber Security Center (NCSC) [2], and 360 Security Brain [3] detected a batch of botnet samples that integrate the TEA algorithm for encryption based on the leaked source code of Mirai , targeting IoT/Linux devices of various architectures such as ARM, MIPS, and x86 ...
-
web:unit42.paloaltonetworks.com
Mirai is a still-active botnet with new variants. We highlight observed exploitation of IoT vulnerabilities — due to low complexity and high impact.
-
web:www.bleepingcomputer.com
A new Mirai -based malware campaign is actively exploiting CVE-2025-29635, a high-severity command-injection vulnerability affecting D-Link DIR-823X routers, to enlist devices into the botnet.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.