s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66 high

📛 Threat Title

Mirai: stub.aarch64_be

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 777520 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:31:14.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66 VT 12 / 75

IOC database

Type
hash_sha256
Value
189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 12 of 75 VirusTotal vendors

VendorVerdictDetection
Arcabit malicious Trojan.Linux.Generic.D3946B03
BitDefender malicious Trojan.Linux.GenericKD.60058371
CTX malicious elf.trojan.generic
Emsisoft malicious Trojan.Linux.GenericKD.60058371 (B)
ESET-NOD32 malicious Linux/Agent.BMJ trojan
GData malicious Trojan.Linux.GenericKD.60058371
huorong malicious Trojan/Linux.Agent.es
Lionic malicious Trojan.ELF.Mirai.4!c
McAfeeD malicious Trojan:Script/Dirtydecrypt.EAA
Microsoft malicious Trojan:Script/Wacatac.C!ml
MicroWorld-eScan malicious Trojan.Linux.GenericKD.60058371
VIPRE malicious Trojan.Linux.GenericKD.60058371

Details From VirusTotal

Basic Properties
MD5e0335a09973e3cf2e8b6decdfdd956a0
SHA-16571f5dbff22631813645ab94b117ba193c0b209
SHA-256189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66
VHash202226c535fcdaef51692e5ac8a0c32f
SSDEEP12288:qaOMNE5N3B76xF+y0ZdNd7JOSwa5YAmdlStnWtVfkHzZ:qaReBKRU9r1aOnQfkH9
TLSHT178F46C5DFD5F3D43C2C6E23ADB8AC3957227B0D8D61311A321C1021DE6CADAD8B5299E
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, ARM aarch64, version 1 (GNU/Linux), statically linked, for GNU/Linux 3.7.0, not stripped
File size759.3 KB
History
First seen on VirusTotal2026-09-25 11:08 UTC
Last submission2026-09-25 11:08 UTC
Last analysis2026-09-25 11:08 UTC
Last modified on VirusTotal2026-09-25 13:08 UTC
Known Names
  • xotsl8.exe
  • copy
hash_sha1 6571f5dbff22631813645ab94b117ba193c0b209 VT 12 / 75

IOC database

Type
hash_sha1
Value
6571f5dbff22631813645ab94b117ba193c0b209
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 12 of 75 VirusTotal vendors

VendorVerdictDetection
Arcabit malicious Trojan.Linux.Generic.D3946B03
BitDefender malicious Trojan.Linux.GenericKD.60058371
CTX malicious elf.trojan.generic
Emsisoft malicious Trojan.Linux.GenericKD.60058371 (B)
ESET-NOD32 malicious Linux/Agent.BMJ trojan
GData malicious Trojan.Linux.GenericKD.60058371
huorong malicious Trojan/Linux.Agent.es
Lionic malicious Trojan.ELF.Mirai.4!c
McAfeeD malicious Trojan:Script/Dirtydecrypt.EAA
Microsoft malicious Trojan:Script/Wacatac.C!ml
MicroWorld-eScan malicious Trojan.Linux.GenericKD.60058371
VIPRE malicious Trojan.Linux.GenericKD.60058371

Details From VirusTotal

Basic Properties
MD5e0335a09973e3cf2e8b6decdfdd956a0
SHA-16571f5dbff22631813645ab94b117ba193c0b209
SHA-256189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66
VHash202226c535fcdaef51692e5ac8a0c32f
SSDEEP12288:qaOMNE5N3B76xF+y0ZdNd7JOSwa5YAmdlStnWtVfkHzZ:qaReBKRU9r1aOnQfkH9
TLSHT178F46C5DFD5F3D43C2C6E23ADB8AC3957227B0D8D61311A321C1021DE6CADAD8B5299E
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, ARM aarch64, version 1 (GNU/Linux), statically linked, for GNU/Linux 3.7.0, not stripped
File size759.3 KB
History
First seen on VirusTotal2026-09-25 11:08 UTC
Last submission2026-09-25 11:08 UTC
Last analysis2026-09-25 11:08 UTC
Last modified on VirusTotal2026-09-25 13:08 UTC
Known Names
  • xotsl8.exe
  • copy
hash_md5 e0335a09973e3cf2e8b6decdfdd956a0 VT 12 / 75

IOC database

Type
hash_md5
Value
e0335a09973e3cf2e8b6decdfdd956a0
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 12 of 75 VirusTotal vendors

VendorVerdictDetection
Arcabit malicious Trojan.Linux.Generic.D3946B03
BitDefender malicious Trojan.Linux.GenericKD.60058371
CTX malicious elf.trojan.generic
Emsisoft malicious Trojan.Linux.GenericKD.60058371 (B)
ESET-NOD32 malicious Linux/Agent.BMJ trojan
GData malicious Trojan.Linux.GenericKD.60058371
huorong malicious Trojan/Linux.Agent.es
Lionic malicious Trojan.ELF.Mirai.4!c
McAfeeD malicious Trojan:Script/Dirtydecrypt.EAA
Microsoft malicious Trojan:Script/Wacatac.C!ml
MicroWorld-eScan malicious Trojan.Linux.GenericKD.60058371
VIPRE malicious Trojan.Linux.GenericKD.60058371

Details From VirusTotal

Basic Properties
MD5e0335a09973e3cf2e8b6decdfdd956a0
SHA-16571f5dbff22631813645ab94b117ba193c0b209
SHA-256189b86c11ba1d53815f08a2fdece876b2582027fcb35ca0cbc6765d5b6f96f66
VHash202226c535fcdaef51692e5ac8a0c32f
SSDEEP12288:qaOMNE5N3B76xF+y0ZdNd7JOSwa5YAmdlStnWtVfkHzZ:qaReBKRU9r1aOnQfkH9
TLSHT178F46C5DFD5F3D43C2C6E23ADB8AC3957227B0D8D61311A321C1021DE6CADAD8B5299E
File typeELF
File type tagelf
MagicELF 64-bit LSB executable, ARM aarch64, version 1 (GNU/Linux), statically linked, for GNU/Linux 3.7.0, not stripped
File size759.3 KB
History
First seen on VirusTotal2026-09-25 11:08 UTC
Last submission2026-09-25 11:08 UTC
Last analysis2026-09-25 11:08 UTC
Last modified on VirusTotal2026-09-25 13:08 UTC
Known Names
  • xotsl8.exe
  • copy

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 777520 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:31:14.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:bazaar.abuse.ch

    You are currently viewing the MalwareBazaar entry for SHA256 4295229d2dd361f13fc411094a164518ac281ba6a49af47f8ce7c2a7c9977e8f. While MalwareBazaar tries to identify ...

  • web:docs.kernel.org

    The Linux kernel provides a sysfs interface to enumerate the current mitigation status of the system for Spectre: whether the system is vulnerable, and which mitigations are active.

  • web:github.com

    IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.

  • web:github.com

    This repository contains the leaked source code of the Mirai botnet, originally created to infect IoT devices and launch large-scale DDoS attacks. This code is provided strictly for cybersecurity research, reverse engineering, malware analysis, and detection development purposes only.

  • web:rruzi.github.io

    The C2 port is randomly selected between 25596 and 25616. In terms of the communication mechanism, Mirai .CatDDoS basically follows the original design of Mirai , except that the fixed 4-byte \x00\x00\x00\x01 when Mirai goes online is modified to a fixed 8-byte: \x31\x73\x13\x93\x04\x83\x32\x04 In terms of the ATTACK_VECTOR, Mirai .CatDDoS implements a richer variety of DDoS attack types than ...

  • web:www.joesandbox.com

    Signatures Antivirus / Scanner detection for submitted sample Multi AV Scanner detection for submitted file Yara detected Mirai Executes the "rm" command used to delete files or directories Found strings indicative of a multi-platform dropper Sample contains strings indicative of BusyBox which embeds multiple Unix commands in a single executable Sample has stripped symbol table Uses the "uname ...

  • web:www.joesandbox.com

    Source: /tmp/stub.aarch64.elf (PID: 4022) Directory: /tmp/.sk Jump to behavior ... Uses the "uname" system call to query kernel version information (possible evasion) Source: /tmp/stub.aarch64.elf (PID: 4022) Queries kernel information via 'uname': Jump to behavior May try to detect the virtual machine to hinder analysis (VM artifact strings ...

  • web:www.yazoul.net

    Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.

  • web:xdaforums.com

    Components runbook.sh (method), scripts/helpers.sh (shared), scripts/gpt_verify.py (payload-vs-device GPT verification), scripts/fetch_mifirm.js (stock-ROM fetch helper, optional) config.sh (generic, parametrized; no device-specific identifiers) payloads/README.md (per-SoC payload files + the GPT-rename trick), docs/sources.md (documented method) tools/ (fastboot/adb) is gitignored — fetch ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.