TF-1932596
high
📛 Threat Title
Mirai: SHA256 hash of a malware sample (payload) 004050e1115593e1588e6cc1691369dcd47939626fdec7f4f0c12eebd0a36a84
Description
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-09-25 02:44:47 UTC. Reporter: whack_sh. Tags: elf, Mirai.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
004050e1115593e1588e6cc1691369dcd47939626fdec7f4f0c12eebd0a36a84
IOC database
- Type
- hash_sha256
- Value
004050e1115593e1588e6cc1691369dcd47939626fdec7f4f0c12eebd0a36a84- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- SHA256 hash of a malware sample (payload) attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware sample (payload). IOC type: SHA256 hash of a malware sample (payload). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-09-25 02:44:47 UTC. Reporter: whack_sh. Tags: elf, Mirai.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial- of -service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:arxiv.org
The researchers give a thorough description of Mirai , as well as the botnets' timeline of events, structure, and propagation, malware phylogeny and its relation to BASHLITE, the types of devices infected, types of attacks and targets, and possible defense strategies IoT companies can take against botnets.
-
web:bazaar.abuse.ch
A malware sample can be associated with only one malware family. The page below gives you an overview on malware samples that MalwareBazaar has identified as Mirai .
-
web:bazaar.abuse.ch
Information on Mirai malware sample ( SHA256 7237ce139be1d569db17ae0937c9391caf941313768f0f68f0053080abd10086) MalwareBazaar uses YARA rules from several public and ...
-
web:github.com
This project contains a full analysis of a Mirai botnet variant, including hash identification, malware behavior, IoCs, detection methods, impact assessment, and recommendations.
-
web:github.com
This repository contains a static malware analysis of the IoT Mirai malware (loader component) obtained from theZoo malware repository. The objective of this project is to understand Mirai's infection mechanism, network behavior, architecture-specific payload delivery, and execution flow using reverse engineering techniques.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Mirai malware family including references, samples and yara signatures.
-
web:rruzi.github.io
The sample sends attack packets to the target victim machine via the send function at the end of the attack_udp_openvpn function. The sent data payload is the fixed memory content pointed to by unk_211040: ... We then captured the traffic generated by the sample in a controlled environment, and the generated data was consistent with our memory ...
-
web:www.akamai.com
Fig. 1: Unique JenX Mirai -related console string from a malware sample with the SHA256 hash of ac43c52b42b123e2530538273dfb12e3b70178aa1dee6d4fd5198c08bfeb4dc1
-
web:www.yazoul.net
Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.