MB-fa024040dffa3cd7afae3ce7f6e9e5b7a33ebffe41b394cd918978d867b1677a
high
📛 Threat Title
Mirai: ooikocqj.aarch64
Description
File type: elf. Size: 1100113 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-23 23:43:15.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
fa024040dffa3cd7afae3ce7f6e9e5b7a33ebffe41b394cd918978d867b1677a
IOC database
- Type
- hash_sha256
- Value
fa024040dffa3cd7afae3ce7f6e9e5b7a33ebffe41b394cd918978d867b1677a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
42ff92a5b8a46806550f4d85283b37c05a1a0259
IOC database
- Type
- hash_sha1
- Value
42ff92a5b8a46806550f4d85283b37c05a1a0259- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
9f4c2d1aec365af25a881b44c1baea7a
IOC database
- Type
- hash_md5
- Value
9f4c2d1aec365af25a881b44c1baea7a- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: elf. Size: 1100113 bytes. Tags: elf, Mirai. Reporter: abuse_ch. First seen: 2026-09-23 23:43:15.
Remediations (10)
-
web:any.run
Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.
-
web:cve.imfht.com
Static Analysis: The firmware binary was unpacked, and webmgt was loaded into IDA Pro 9.1 using the Hex-Rays AArch64 decompiler. Dynamic Testing: A QEMU AArch64 user-mode environment was configured, and the root filesystem was extracted.
-
web:dailysecurityreview.com
A Mirai malware botnet is leveraging a zero-day vulnerability (CVE-2024-11120) in outdated GeoVision devices to deploy malware, potentially for DDoS attacks or cryptomining. Thousands of vulnerable devices are exposed online.
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:github.com
IoT Secure Gateway: Mirai Mitigation Lab A network security project that simulates Mirai -style IoT attack behavior and validates a firewall-based defense using Docker, Linux networking, nftables, Bash, and PowerShell automation.
-
web:github.com
Mirai is a malware botnet that infects Internet of Things (IoT) devices using default or weak login credentials. Once infected, these devices are controlled by a command-and-control (CnC) server and can be used to launch DDoS attacks. This repo is a fork of the original leaked source code and includes components such as: The bot (runs on IoT devices) The CnC server The loader (infects devices ...
-
web:link.springer.com
The Mirai botnet has emerged as one of the most persistent and evolving threats targeting Internet of Things devices. Originally designed to orchestrate large-scale Distributed Denial of Service attacks, Mirai compromises devices by exploiting weak credentials and...
-
web:lkml.org
[lkml] [2026] [Sep] [22] [last100] Views: [wrap] [no wrap] [headers] [forward] Messages in this thread First message in thread Mario Limonciello Niklas Cassel Mario Limonciello Date Tue, 22 Sep 2026 05:44:00 -0500 Subject Re: [PATCH v2 0/2] Fix for storage corruption w/ AMD IOMMU on 64-bit addressing From Mario Limonciello <> On 9/22/26 04:49, Niklas Cassel wrote: > On Sun, Sep 20, 2026 at 11: ...
-
web:panorays.com
Discover the difference between remediation and mitigation in risk management and how each strategy impacts security and resilience.
-
web:www.yazoul.net
Mirai threat intelligence: 2400 samples tracked, 24 daily reports, IOCs, detection rates, and C2 infrastructure. Updated daily from MalwareBazaar.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.