s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

MB-fa024040dffa3cd7afae3ce7f6e9e5b7a33ebffe41b394cd918978d867b1677a high

📛 Threat Title

Mirai: ooikocqj.aarch64

Category: Mirai Published: Source updated: First seen: Last updated: Source: Abuse.ch

Description

File type: elf. Size: 1100113 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-23 23:43:15.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 fa024040dffa3cd7afae3ce7f6e9e5b7a33ebffe41b394cd918978d867b1677a

IOC database

Type
hash_sha256
Value
fa024040dffa3cd7afae3ce7f6e9e5b7a33ebffe41b394cd918978d867b1677a
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha1 42ff92a5b8a46806550f4d85283b37c05a1a0259

IOC database

Type
hash_sha1
Value
42ff92a5b8a46806550f4d85283b37c05a1a0259
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_md5 9f4c2d1aec365af25a881b44c1baea7a

IOC database

Type
hash_md5
Value
9f4c2d1aec365af25a881b44c1baea7a
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • MalwareBazaar sample page Abuse.ch

    File type: elf. Size: 1100113 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-23 23:43:15.

Remediations (10)

  • web:any.run

    Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

  • web:cve.imfht.com

    Static Analysis: The firmware binary was unpacked, and webmgt was loaded into IDA Pro 9.1 using the Hex-Rays AArch64 decompiler. Dynamic Testing: A QEMU AArch64 user-mode environment was configured, and the root filesystem was extracted.

  • web:dailysecurityreview.com

    A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of vulnerable devices are exposed online.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:github.com

    IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.

  • web:github.com

    Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...

  • web:link.springer.com

    The Mirai botnet has emerged as one of the most persistent and evolving threats targeting Internet of Things devices. Originally designed to orchestrate large-scale Distributed Denial of Service attacks, Mirai compromises devices by exploiting weak credentials and...

  • web:lkml.org

    [lkml] [2026] [Sep] [22] [last100] Views: [wrap] [no wrap] [headers] [forward] Messages in this thread First message in thread Mario Limonciello Niklas Cassel Mario Limonciello Date Tue, 22 Sep 2026 05:44:00 -0500 Subject Re: [PATCH v2 0/2] Fix for storage corruption w/ AMD IOMMU on 64-bit addressing From Mario Limonciello <> On 9/22/26 04:49, Niklas Cassel wrote: > On Sun, Sep 20, 2026 at 11: ...

  • web:panorays.com

    Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.

  • web:www.yazoul.net

    Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.