s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-565e8f5df51db5368bd78124457415d410bfc52b69ef30cc127cbad47e818a18 high

📛 Threat Title

Mirai: stub.aarch64_be

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 775697 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-24 00:02:19.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 565e8f5df51db5368bd78124457415d410bfc52b69ef30cc127cbad47e818a18

IOC database

Type
hash_sha256
Value
565e8f5df51db5368bd78124457415d410bfc52b69ef30cc127cbad47e818a18
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 02e0269b5e6438f79f5e9b92a73c2180da8107b2

IOC database

Type
hash_sha1
Value
02e0269b5e6438f79f5e9b92a73c2180da8107b2
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 89991273f124c4a7d9cc0a50cbed3892

IOC database

Type
hash_md5
Value
89991273f124c4a7d9cc0a50cbed3892
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 775697 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-24 00:02:19.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 01da3d4345bde3a0b1966927091f65edfced03a16af8985374603ecf9efab2f6. While MalwareBazaar tries to identify ...

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 4295229d2dd361f13fc411094a164518ac281ba6a49af47f8ce7c2a7c9977e8f. While MalwareBazaar tries to identify ...

  • web:dailysecurityreview.com

    A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of vulnerable devices are exposed online.

  • web:github.com

    CVE-2026-31431 Mitigation Script This repository provides a temporary mitigation and revert script for CVE-2026-31431, a Linux kernel local privilege escalation vulnerability.

  • web:github.com

    This repository contains the leaked source code of the Mirai botnet, originally created to infect IoT devices and launch large-scale DDoS attacks. This code is provided strictly for cybersecurity research, reverse engineering, malware analysis, and detection development purposes only.

  • web:rruzi.github.io

    The C2 port is randomly selected between 25596 and 25616. In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01 when Mirai goes online is modified to a fixed 8-byte: \x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than ...

  • web:westoahu.hawaii.edu

    Practicing proper mitigation techniques and being proactive can help reduce device vulnerabilities, and prevent the creation of more bots and limit the resources botnet operators have. References [1] Cloudflare. (2017, December 14). Inside the Infamous Mirai IoT Botnet: A Retrospective.

  • web:www.joesandbox.com

    Source: stub.aarch64.elf, 4022.1.00007ffc6e246000.00007ffc6e267000.rw-.sdmp Binary or memory string: /usr/bin/qemu-aarch64

  • web:www.joesandbox.com

    Source: /tmp/stub.aarch64.elf (PID: 4022) Directory: /tmp/.sk Jump to behavior ... Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/stub.aarch64.elf (PID: 4022) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.