MB-189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66
high
📛 Threat Title
Mirai: stub.aarch64_be
Description
File type: elf. Size: 777520 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:31:14.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66
VT 12 / 75
IOC database
- Type
- hash_sha256
- Value
189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 12 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Arcabit | malicious | Trojan.Linux.Generic.D3946B03 |
| BitDefender | malicious | Trojan.Linux.GenericKD.60058371 |
| CTX | malicious | elf.trojan.generic |
| Emsisoft | malicious | Trojan.Linux.GenericKD.60058371 (B) |
| ESET-NOD32 | malicious | Linux/Agent.BMJ trojan |
| GData | malicious | Trojan.Linux.GenericKD.60058371 |
| huorong | malicious | Trojan/Linux.Agent.es |
| Lionic | malicious | Trojan.ELF.Mirai.4!c |
| McAfeeD | malicious | Trojan:Script/Dirtydecrypt.EAA |
| Microsoft | malicious | Trojan:Script/Wacatac.C!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.60058371 |
| VIPRE | malicious | Trojan.Linux.GenericKD.60058371 |
Details From VirusTotal
Basic Properties
| MD5 | e0335a09973e3cf2e8b6decdfdd956a0 |
| SHA-1 | 6571f5dbff22631813645ab94b117ba193c0b209 |
| SHA-256 | 189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66 |
| VHash | 202226c535fcdaef51692e5ac8a0c32f |
| SSDEEP | 12288:qaOMNE5N3B76xF+y0ZdNd7JOSwa5YAmdlStnWtVfkHzZ:qaReBKRU9r1aOnQfkH9 |
| TLSH | T178F46C5DFD5F3D43C2C6E23ADB8AC3957227B0D8D61311A321C1021DE6CADAD8B5299E |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, ARM aarch64, version 1 (GNU/Linux), statically linked, for GNU/Linux 3.7.0, not stripped |
| File size | 759.3 KB |
History
| First seen on VirusTotal | 2026-09-25 11:08 UTC |
| Last submission | 2026-09-25 11:08 UTC |
| Last analysis | 2026-09-25 11:08 UTC |
| Last modified on VirusTotal | 2026-09-25 13:08 UTC |
Known Names
xotsl8.execopy
hash_sha1
6571f5dbff22631813645ab94b117ba193c0b209
VT 12 / 75
IOC database
- Type
- hash_sha1
- Value
6571f5dbff22631813645ab94b117ba193c0b209- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 12 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Arcabit | malicious | Trojan.Linux.Generic.D3946B03 |
| BitDefender | malicious | Trojan.Linux.GenericKD.60058371 |
| CTX | malicious | elf.trojan.generic |
| Emsisoft | malicious | Trojan.Linux.GenericKD.60058371 (B) |
| ESET-NOD32 | malicious | Linux/Agent.BMJ trojan |
| GData | malicious | Trojan.Linux.GenericKD.60058371 |
| huorong | malicious | Trojan/Linux.Agent.es |
| Lionic | malicious | Trojan.ELF.Mirai.4!c |
| McAfeeD | malicious | Trojan:Script/Dirtydecrypt.EAA |
| Microsoft | malicious | Trojan:Script/Wacatac.C!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.60058371 |
| VIPRE | malicious | Trojan.Linux.GenericKD.60058371 |
Details From VirusTotal
Basic Properties
| MD5 | e0335a09973e3cf2e8b6decdfdd956a0 |
| SHA-1 | 6571f5dbff22631813645ab94b117ba193c0b209 |
| SHA-256 | 189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66 |
| VHash | 202226c535fcdaef51692e5ac8a0c32f |
| SSDEEP | 12288:qaOMNE5N3B76xF+y0ZdNd7JOSwa5YAmdlStnWtVfkHzZ:qaReBKRU9r1aOnQfkH9 |
| TLSH | T178F46C5DFD5F3D43C2C6E23ADB8AC3957227B0D8D61311A321C1021DE6CADAD8B5299E |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, ARM aarch64, version 1 (GNU/Linux), statically linked, for GNU/Linux 3.7.0, not stripped |
| File size | 759.3 KB |
History
| First seen on VirusTotal | 2026-09-25 11:08 UTC |
| Last submission | 2026-09-25 11:08 UTC |
| Last analysis | 2026-09-25 11:08 UTC |
| Last modified on VirusTotal | 2026-09-25 13:08 UTC |
Known Names
xotsl8.execopy
hash_md5
e0335a09973e3cf2e8b6decdfdd956a0
VT 12 / 75
IOC database
- Type
- hash_md5
- Value
e0335a09973e3cf2e8b6decdfdd956a0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 12 of 75 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Arcabit | malicious | Trojan.Linux.Generic.D3946B03 |
| BitDefender | malicious | Trojan.Linux.GenericKD.60058371 |
| CTX | malicious | elf.trojan.generic |
| Emsisoft | malicious | Trojan.Linux.GenericKD.60058371 (B) |
| ESET-NOD32 | malicious | Linux/Agent.BMJ trojan |
| GData | malicious | Trojan.Linux.GenericKD.60058371 |
| huorong | malicious | Trojan/Linux.Agent.es |
| Lionic | malicious | Trojan.ELF.Mirai.4!c |
| McAfeeD | malicious | Trojan:Script/Dirtydecrypt.EAA |
| Microsoft | malicious | Trojan:Script/Wacatac.C!ml |
| MicroWorld-eScan | malicious | Trojan.Linux.GenericKD.60058371 |
| VIPRE | malicious | Trojan.Linux.GenericKD.60058371 |
Details From VirusTotal
Basic Properties
| MD5 | e0335a09973e3cf2e8b6decdfdd956a0 |
| SHA-1 | 6571f5dbff22631813645ab94b117ba193c0b209 |
| SHA-256 | 189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66 |
| VHash | 202226c535fcdaef51692e5ac8a0c32f |
| SSDEEP | 12288:qaOMNE5N3B76xF+y0ZdNd7JOSwa5YAmdlStnWtVfkHzZ:qaReBKRU9r1aOnQfkH9 |
| TLSH | T178F46C5DFD5F3D43C2C6E23ADB8AC3957227B0D8D61311A321C1021DE6CADAD8B5299E |
| File type | ELF |
| File type tag | elf |
| Magic | ELF 64-bit LSB executable, ARM aarch64, version 1 (GNU/Linux), statically linked, for GNU/Linux 3.7.0, not stripped |
| File size | 759.3 KB |
History
| First seen on VirusTotal | 2026-09-25 11:08 UTC |
| Last submission | 2026-09-25 11:08 UTC |
| Last analysis | 2026-09-25 11:08 UTC |
| Last modified on VirusTotal | 2026-09-25 13:08 UTC |
Known Names
xotsl8.execopy
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 777520 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:31:14.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:bazaar.abuse.ch
You are currently viewing the MalwareBazaar entry for SHA256 4295229d2dd361f13fc411094a164518ac281ba6a49af47f8ce7c2a7c9977e8f. While MalwareBazaar tries to identify ...
-
web:docs.kernel.org
The Linux kernel provides a sysfs interface to enumerate the current mitigation status of the system for Spectre: whether the system is vulnerable, and which mitigations are active.
-
web:github.com
IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.
-
web:github.com
This repository contains the leaked source code of the Mirai botnet, originally created to infect IoT devices and launch large-scale DDoS attacks. This code is provided strictly for cybersecurity research, reverse engineering, malware analysis, and detection development purposes only.
-
web:rruzi.github.io
The C2 port is randomly selected between 25596 and 25616. In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01 when Mirai goes online is modified to a fixed 8-byte: \x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than ...
-
web:www.joesandbox.com
Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Executes the "rm" command used to delete files or directories Found strings indicative of a multi-platform dropper Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable Sample has stripped symbol table Uses the "uname ...
-
web:www.joesandbox.com
Source: /tmp/stub.aarch64.elf (PID: 4022) Directory: /tmp/.sk Jump to behavior ... Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/stub.aarch64.elf (PID: 4022) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings ...
-
web:www.yazoul.net
Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
-
web:xdaforums.com
Components runbook.sh (method), scripts/helpers.sh (shared), scripts/gpt_verify.py (payload-vs-device GPT verification), scripts/fetch_mifirm.js (stock-ROM fetch helper, optional) config.sh (generic, parametrized; no device-specific identifiers) payloads/README.md (per-SoC payload files + the GPT-rename trick), docs/sources.md (documented method) tools/ (fastboot/adb) is gitignored — fetch ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.