Verdict
- MALWAREBAZAAR_MATCH MalwareBazaar has the sample.
- VT_HIGH_DETECTION_RATIO 30% or more of VirusTotal vendors flag the indicator.
- MULTIPLE_CORROBORATING_SOURCES Two or more independent source families agree.
Key indicators
- SHA256
- 06a3c8722c3fbca61d4311a9a8219af64e94f1334d553ff45e4302e7e8206c69
- File name
- jutkdlwf.exe
- File type
- elf
- Family
- Mirai
- First submitted
- 2021-02-12
- First seen
- 2021-02-12 (2045 days before · VirusTotal)
- Last seen
- 2026-09-18 (1 day before)
Relationship graph
Expand| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| Sample catalogued as Mirai, submitted 1 day ago. | — | 1 day recent | Strong | |
| 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi. | 43/75 | 32 days aging | Strong |
Coverage · checked, no record: ThreatFox, CIRCL hashlookup · failed: AlienVault OTX
Analyst summary
Consistent with engineMalicious, high confidence. Sample catalogued as Mirai, submitted 1 day ago. Independent sources corroborate it. VirusTotal Code Insight (AI-generated) describes it as: The sample is an ARM ELF binary identified as a variant of the Mozi IoT malware/botnet family.
Why the evidence points to malicious
- [MalwareBazaar] Sample catalogued as Mirai, submitted 1 day ago.
- [VirusTotal] 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi.
Attribution
Links the indicator to Mirai activity; this does not identify a specific threat actor or implicate the hosting provider.
Threat context
All evidence
5 sources queried · click a row for its raw fields · ages computed by the engine| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| Sample catalogued as Mirai, submitted 1 day ago. | — | 1 day recent | Strong | |
| 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi. | 43/75 | 32 days aging | Strong | |
| Lookup failed: no information either way. | — | — | Failed | |
| No record. | — | — | No record | |
| No record. | — | — | No record |
Engine rules applied
- LOOKUPS_FAILEDOne or more lookups failed; their absence carries no information.
- MALWAREBAZAAR_MATCHMalwareBazaar has the sample.
- VT_HIGH_DETECTION_RATIO30% or more of VirusTotal vendors flag the indicator.
- MULTIPLE_CORROBORATING_SOURCESTwo or more independent source families agree.
Analyst summary
Consistent with engineMalicious, high confidence. Sample catalogued as Mirai, submitted 1 day ago. Independent sources corroborate it. VirusTotal Code Insight (AI-generated) describes it as: The sample is an ARM ELF binary identified as a variant of the Mozi IoT malware/botnet family.
Why the evidence points to malicious
- [MalwareBazaar] Sample catalogued as Mirai, submitted 1 day ago.
- [VirusTotal] 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi.
Attribution
Links the indicator to Mirai activity; this does not identify a specific threat actor or implicate the hosting provider.
Key indicators
- SHA256
- 06a3c8722c3fbca61d4311a9a8219af64e94f1334d553ff45e4302e7e8206c69
- File name
- jutkdlwf.exe
- File type
- elf
- Family
- Mirai
- First submitted
- 2021-02-12
- First seen
- 2021-02-12 (2045 days before · VirusTotal)
- Last seen
- 2026-09-18 (1 day before)
By source
No infrastructure source returned a record.
Relationship graph
Click a node for details · edges are observed relationships, not ownershipContext
Attribution
Links the indicator to Mirai activity; this does not identify a specific threat actor or implicate the hosting provider.
Relationship ≠ ownership. Shared IPs, ASNs or platforms never imply the same operator.
Threat context
Context onlyNot collected for this investigation. Re-run to add it.
Evidence timeline
- 2026-08-18VirusTotal: 43/75 vendors (57.3%) flag it: strong multi-vendor detection
- 2026-09-18MalwareBazaar: Sample catalogued as Mirai, submitted 1 day ago
- 2026-09-19Investigated
Run history
3 collections of this indicator- 2026-09-23MALICIOUS82Stored evidenceOpen · newest
- 2026-09-23MALICIOUS82Live lookupsOpen
- 2026-09-23MALICIOUS92Stored evidenceShown
Sources are checked again on every live run, so a source that has since dropped the indicator from its feed can change the verdict. Each run keeps the evidence exactly as it was collected.
Recommended next steps
- huntLook for 06a3c8722c3f... on Linux servers, routers and IoT devices; EDR rarely runs on IoT, so check firewall logs for scanning or unusual outbound traffic from those devices.
- contextThe behaviour summary describes peer-to-peer command and control, so blocking single C2 addresses will not stop it; detect the peer-to-peer traffic pattern at the network edge.
- blockBlock the hash in your security controls and isolate any device found running it.
Pivot to other tools
Opens the indicator in the source's own site (new tab).

