s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

MB-f83c7745c1c1451621047ffbd6c931e258a5557addfd1cfac2feec23cb1d1984 high

📛 Threat Title

Mirai: stub.mipsel

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 731791 bytes. Tags: elf, Gafgyt, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:44:49.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 f83c7745c1c1451621047ffbd6c931e258a5557addfd1cfac2feec23cb1d1984 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/f83c7745c1c1451621047ffbd6c931e258a5557addfd1cfac2feec23cb1d1984

IOC database

Type
hash_sha256
Value
f83c7745c1c1451621047ffbd6c931e258a5557addfd1cfac2feec23cb1d1984
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/f83c7745c1c1451621047ffbd6c931e258a5557addfd1cfac2feec23cb1d1984

hash_sha1 c489a57e626a68c4f926e52f0cdf85510ccdbb57 VT 11 / 75

IOC database

Type
hash_sha1
Value
c489a57e626a68c4f926e52f0cdf85510ccdbb57
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 11 of 75 VirusTotal vendors

VendorVerdictDetection
Antiy-AVL malicious Trojan[Exploit]/Linux.CVE-2018-10561
Arcabit malicious Trojan.Linux.Generic.D3946A8C
BitDefender malicious Trojan.Linux.GenericKD.60058252
CTX malicious elf.trojan.generic
Emsisoft malicious Trojan.Linux.GenericKD.60058252 (B)
ESET-NOD32 malicious Linux/Agent.BMJ trojan
GData malicious Trojan.Linux.GenericKD.60058252
Google malicious Detected
huorong malicious Trojan/Linux.Agent.es
Ikarus malicious Trojan.Linux.Gafgyt
MicroWorld-eScan malicious Trojan.Linux.GenericKD.60058252

Details From VirusTotal

Basic Properties
MD5d1e58b1dfc4693304c40d29b2b3cdfde
SHA-1c489a57e626a68c4f926e52f0cdf85510ccdbb57
SHA-256f83c7745c1c1451621047ffbd6c931e258a5557addfd1cfac2feec23cb1d1984
VHash99c81d9062cad66317bc378f0ab86e69
SSDEEP12288:cAsRZePvWEwcj1b4D7QAEjYHZ6fxd8mg2cSAH07FFMk/mKsuSxzOTl1aplHPPhGn:GZwv1jJ4/9UZnQ28N+0JTxG
TLSHT1D1F45B07FF815FEBC09FCD30852EC31721E9D48656C1A62A72FC4A8CBA5D6694BE3494
File typeELF
File type tagelf
MagicELF 32-bit LSB executable, MIPS, MIPS32 rel2 version 1 (SYSV), statically linked, for GNU/Linux 3.2.0, not stripped
File size714.6 KB
History
First seen on VirusTotal2026-09-25 10:48 UTC
Last submission2026-09-25 10:48 UTC
Last analysis2026-09-25 10:48 UTC
Last modified on VirusTotal2026-09-25 18:09 UTC
Known Names
  • ytxgl0vhn.exe
  • stub.mipsel.elf
hash_md5 d1e58b1dfc4693304c40d29b2b3cdfde VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/d1e58b1dfc4693304c40d29b2b3cdfde

IOC database

Type
hash_md5
Value
d1e58b1dfc4693304c40d29b2b3cdfde
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/files/d1e58b1dfc4693304c40d29b2b3cdfde

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 731791 bytes. Tags: elf, Gafgyt, Mirai. Reporter: abuse_ch. First seen: 2026-09-25 10:44:49.

Remediations (10)

  • web:blogs.jpcert.or.jp

    The most well-known malware using Anti-UPX Unpacking technique is Mirai and its variants, which target IoT devices. Figure 1 shows the headers of UPX-packed binary and Mirai .

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:github.com

    ADR-064: Stub Remediation & Full Implementation — v3.5.22 Date: 2026-03-17 Status: Implemented (22 stubs fully implemented in v3.5.43, PR #1438) Context: Deep capability audit (ADR-063) identified stub implementations and broken features. This ADR documents the remediation plan and tracks which items were already functional vs genuinely needing fixes.

  • web:learn.microsoft.com

    Automated investigation and remediation (AIR) capabilities in Microsoft Defender for Business are preconfigured and aren't configurable. In Microsoft Defender for Endpoint, you can configure AIR to one of several levels of automation. Your automation level affects whether remediation actions following AIR investigations are taken automatically or only upon approval.

  • web:learn.microsoft.com

    Learn about quick machine recovery and how to configure it with the RemoteRemediation configuration service provider (CSP).

  • web:tria.ge

    Check this mirai report mipsel[.]elf, with a score of 10 out of 10.

  • web:www.ema-eda.com

    Fix high-speed link failures. Familiarize yourself with via stub resonance and signal integrity strategies for cleaner signal paths.

  • web:www.jisem-journal.com

    Table 1 from Imperva's DDoS attacks report, shows the top countries of origin of Mirai DDoS attacks. At this time Mirai malware is having a low antivirus detection ratio, even in the architecture of x86. With the free software avsubmit.py create by Michael Ligh is possible to analyses a file using the VirusTotal engine from the command line.

  • web:www.yazoul.net

    Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.

  • web:xdaforums.com

    Components runbook.sh (method), scripts/helpers.sh (shared), scripts/gpt_verify.py (payload-vs-device GPT verification), scripts/fetch_mifirm.js (stock-ROM fetch helper, optional) config.sh (generic, parametrized; no device-specific identifiers) payloads/README.md (per-SoC payload files + the GPT-rename trick), docs/sources.md (documented method) tools/ (fastboot/adb) is gitignored — fetch ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.