Verdict
- VT_HIGH_DETECTION_RATIO 30% or more of VirusTotal vendors flag the indicator.
Key indicators
- SHA256
- 06a3c8722c3fbca61d4311a9a8219af64e94f1334d553ff45e4302e7e8206c69
- File name
- jutkdlwf.exe
- File type
- ELF
- Family
- trojan.mirai/mozi
- First submitted
- 2021-02-12
- First seen
- 2021-02-12 (2049 days before · VirusTotal)
- Last seen
- 2026-08-18 (36 days before)
Relationship graph
Expand| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi. | 43/75 | 36 days aging | Strong | |
| Referenced in 2 community pulses, which are unverified. | — | — | Neutral |
Coverage · checked, no record: MalwareBazaar, ThreatFox, CIRCL hashlookup · failed: none
Analyst summary
Consistent with engineMalicious, medium confidence. 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi. It rests on one source family, so confidence is medium. VirusTotal Code Insight (AI-generated) describes it as: The sample is an ARM ELF binary identified as a variant of the Mozi IoT malware/botnet family.
Why the evidence points to malicious
- [VirusTotal] 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi.
Attribution
The evidence does not establish who operates this indicator.
Threat context
Context onlyNot collected for this investigation. Re-run to add it.
All evidence
5 sources queried · click a row for its raw fields · ages computed by the engine| Source | Finding | Confidence | Age | Signal |
|---|---|---|---|---|
| 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi. | 43/75 | 36 days aging | Strong | |
| Referenced in 2 community pulses, which are unverified. | — | — | Neutral | |
| No record. | — | — | No record | |
| No record. | — | — | No record | |
| No record. | — | — | No record |
Engine rules applied
- VT_HIGH_DETECTION_RATIO30% or more of VirusTotal vendors flag the indicator.
- SINGLE_SOURCE_ONLYOnly one source family provides malicious evidence.
Analyst summary
Consistent with engineMalicious, medium confidence. 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi. It rests on one source family, so confidence is medium. VirusTotal Code Insight (AI-generated) describes it as: The sample is an ARM ELF binary identified as a variant of the Mozi IoT malware/botnet family.
Why the evidence points to malicious
- [VirusTotal] 43/75 vendors (57.3%) flag it: strong multi-vendor detection; label trojan.mirai/mozi. ELF file; vendors name it mirai, mozi.
Attribution
The evidence does not establish who operates this indicator.
Key indicators
- SHA256
- 06a3c8722c3fbca61d4311a9a8219af64e94f1334d553ff45e4302e7e8206c69
- File name
- jutkdlwf.exe
- File type
- ELF
- Family
- trojan.mirai/mozi
- First submitted
- 2021-02-12
- First seen
- 2021-02-12 (2049 days before · VirusTotal)
- Last seen
- 2026-08-18 (36 days before)
By source
No infrastructure source returned a record.
Relationship graph
Click a node for details · edges are observed relationships, not ownershipContext
Attribution
The evidence does not establish who operates this indicator.
Relationship ≠ ownership. Shared IPs, ASNs or platforms never imply the same operator.
Threat context
Context onlyNot collected for this investigation. Re-run to add it.
Evidence timeline
- 2026-08-18VirusTotal: 43/75 vendors (57.3%) flag it: strong multi-vendor detection
- 2026-09-23Investigated
Run history
3 collections of this indicator- 2026-09-23MALICIOUS82Stored evidenceShown
- 2026-09-23MALICIOUS82Live lookupsOpen
- 2026-09-23MALICIOUS92Stored evidenceOpen
Sources are checked again on every live run, so a source that has since dropped the indicator from its feed can change the verdict. Each run keeps the evidence exactly as it was collected.
Recommended next steps
- huntLook for 06a3c8722c3f... on Linux servers, routers and IoT devices; EDR rarely runs on IoT, so check firewall logs for scanning or unusual outbound traffic from those devices.
- contextThe behaviour summary describes peer-to-peer command and control, so blocking single C2 addresses will not stop it; detect the peer-to-peer traffic pattern at the network edge.
- blockBlock the hash in your security controls and isolate any device found running it.
Pivot to other tools
Opens the indicator in the source's own site (new tab).

