logo

Hunting Mirai Control Servers Using Known Shell Scripts

ID: c6bbe215-3a2c-5d5c-8d83-68f9bc09e13b

STIX ID: report--c6bbe215-3a2c-5d5c-8d83-68f9bc09e13b

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2019-02-20

Date Updated: 2026-04-27

...
...

The report reviews the Mirai botnet’s 2016 large-scale IoT infections and DDoS impact, then demonstrates how Censys Internet-wide search can locate Mirai-like control/distribution servers (e.g., open directories with "Index Of" listings and a "bins.sh" script). It shows examples of discovered Mirai binaries, recommends using those findings as indicators to hunt outbound traffic and hashes in network logs, and links to further research on Mirai’s growth and impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.