Hunting Mirai Control Servers Using Known Shell Scripts
ID: c6bbe215-3a2c-5d5c-8d83-68f9bc09e13b
STIX ID: report--c6bbe215-3a2c-5d5c-8d83-68f9bc09e13b
Feed Name: Censys Blog
Threat Score
The report reviews the Mirai botnet’s 2016 large-scale IoT infections and DDoS impact, then demonstrates how Censys Internet-wide search can locate Mirai-like control/distribution servers (e.g., open directories with "Index Of" listings and a "bins.sh" script). It shows examples of discovered Mirai binaries, recommends using those findings as indicators to hunt outbound traffic and hashes in network logs, and links to further research on Mirai’s growth and impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
