Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Mirai

21
Global rank
19 infographic chevron month
Month rank
9 infographic chevron week
Week rank

Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

Botnet
Type
USA
Origin
1 September, 2016
First seen
8 October, 2026
Last seen

How to analyze Mirai with ANY.RUN

Type
USA
Origin
1 September, 2016
First seen
8 October, 2026
Last seen

IOCs

IP addresses
94.154.43.59
217.144.138.234
151.101.1.91
144.76.139.8
151.101.65.91
151.101.193.91
151.101.129.91
131.188.3.220
185.125.190.57
91.189.91.61
185.125.190.56
5.199.135.198
188.174.253.188
217.60.103.135
91.189.91.62
104.168.4.206
85.215.122.93
46.38.241.235
144.31.150.183
91.189.91.57
Hashes
f0cd29fff42a7dad4b00c7b1c684a7e759a159baef96f57a285e1ff7f61bbab5
9fac6abd1c35da9e68fb4f00f33de82306adf96093ea806f3c42d4a153e39c9e
5279f80f139fcf962ac44abc4b79b67d14807c8f5a6d9ec8e9e3f7023532961d
4377e894b3e7956b74d467118164b7023e9b0f0f4c151e464d00991e30f924ac
f9120c06aad5aa4add1b646456199fd34b4fa72c6eb8ba4d37d85a59d7cac478
7050da3bd5b59468f4ab8457cf5f11b1cd5f556e54e2e0b1d5b1556088b949d8
311d843746a0c17469003556ee0fcce655f97ff20a304a3d6cf2c800dae44e50
b4192fc3931e8f3673788f922c00eb9336412481f365c71835a39eb52c770d5e
041afc79b725ec4e3bd74a687eb96ff65487255a9556cc6b5973cc4f676524c8
bd9a621416a3f8af6f2f0ccf8d32f4df4bcb7479f2b0feeeb99bd6b3f5861a1a
b05c27574c61a7b79ee20aa6e5fa00ddb30027d7063bd587fd468f41845b386b
d8120ef961aa32d03f2623c07a801d07ef7764a2a0da1d9c79678d91fe0b1f7a
e7a84a1e9632acbb1b2a474ad7934af2b52e8d4f2590d484c740dde0d2ef256f
787329bad92ca7e3b9f559a18e4b51b70cb02c8f5a3718897584e1619fbf8d62
482bc954bc92a7c5015f0ec4f60d8739909a8665d9ce7b2514c1885e7be234d4
887c8ada6058f01125a5131f1c495ba5f0171b2c40466ea824494403b87c1a22
a1f66f3cbdecc247ba5c7fefae2642e872535ad9e7f36de71cef8210c8eef56b
34b76c62e23fcbf2f96ede3df420ac0b4b83438441f8af6a0adaf4f5a58527a3
b54bc89673ab79915e3170e804009bb5a725e34510ce62f836614a339ee04f12
2405ffb3aa765459666a30b0e1656cc79e1772d4848515a1c837be0852775e59
Domains
google.com
8.100.168.192.in-addr.arpa
2.debian.pool.ntp.org
12.100.168.192.in-addr.arpa
connectivity-check.ubuntu.com
3.100.168.192.in-addr.arpa
5.100.168.192.in-addr.arpa
4.100.168.192.in-addr.arpa
13.100.168.192.in-addr.arpa
10.100.168.192.in-addr.arpa
14.100.168.192.in-addr.arpa
11.100.168.192.in-addr.arpa
9.100.168.192.in-addr.arpa
cdn.fwupd.org
ntp.ubuntu.com
7.100.168.192.in-addr.arpa
6.100.168.192.in-addr.arpa
c.bing.com
ht.overpassheader.surf
assets.msn.com
URLs
http://connectivity-check.ubuntu.com/
http://217.60.103.135/x86_64
http://104.168.4.206/bins.sh
http://104.168.4.206/dissmips
http://104.168.4.206/dlr.mips
http://104.168.4.206/dissmpsl
http://104.168.4.206/dlr.mpsl
http://104.168.4.206/disssh4
http://104.168.4.206/dlr.sh4
http://104.168.4.206/dissx86
http://104.168.4.206/dlr.x86
http://104.168.4.206:80/kkk.x86
http://104.168.4.206/dissarm4
http://104.168.4.206/dlr.arm
http://104.168.4.206/adissarm5
http://104.168.4.206/dlr.arm5
http://104.168.4.206/dissarm6
http://104.168.4.206/dlr.arm6
http://104.168.4.206/dissarm7
http://104.168.4.206/dlr.arm7
Last Seen at

Recent blog posts

post image
5 Critical Pain Points of Modern US SOCs and...
watchers 2367
comments 0
post image
IronChain Ransomware Threatens Businesses wit...
watchers 3913
comments 0
post image
Threat Coverage Digest: New Malware Reports a...
watchers 11489
comments 0

What is Mirai malware?

Mirai is a botnet that has been targeting Internet of Things (IoT) devices since September 2016. It initially gained notoriety with denial-of-service attacks on several high-profile targets, including Krebs on Security, a blog run by the notable cybersecurity expert and journalist Brian Krebs. The botnet exploited the lack of security in IoT devices in the form of weak passwords, using them to generate massive traffic to overwhelm the target services.

The original developers, three college students from the United States, made the Mirai malware source code public in 2017 in an attempt to demonstrate their willingness to abandon criminal activity. However, this led to the creation of numerous variants of the malware, such as Hajime and Sylveon, as well as an influx of new threat actors employing these in their attacks.

Since then, the botnet has been experiencing a continuous evolution, gaining additional capabilities and exploiting new vulnerabilities found in different devices. It has been employed in numerous campaigns, by 2022 becoming one the largest botnets. According to some estimates, the Mirai malware has been used to infect over half a million IoT products.

Mirai's rise and scale can be attributed to a combination of factors. These include efficient spreading based on Internet-wide scanning and the widespread use of insecure default passwords in IoT products.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Mirai malware technical details

On the basic level, Mirai uses brute forcing to infect new devices. Here are the four stages that define its typical operation:

  • It begins by scanning the internet for vulnerable IoT devices by sending TCP probes to IPv4 addresses.
  • Once it identifies a potential victim, it attempts to log in using a list of popular credentials.
  • Upon successful login, the malware uses its loader module to download and execute a malicious program on the device. Once a device is infected, it becomes part of the botnet and begins scanning the internet for other vulnerable devices to infect.
  • Mirai then engages the infected devices to launch DDoS attacks.

The malware usually communicates with the command-and-control (C2) over the TCP protocol. Yet, there are also TLS-capable variants.

After establishing its presence on a device, Mirai kills any processes associated with the activity of other botnets, such as Gafgyt, that might have infected it prior.

Over the past years, Mirai variants have been able to infect thousands of devices by abusing various vulnerabilities. For instance, in 2020, one Mirai variant took advantage of a security flaw (CVE-2020-9054) in Zyxel NAS devices, which allowed the malware to employ special characters to inject malicious commands and take control of devices.

Another vulnerability used by Mirai, which was identified in Comtrend VR-3033 routers in 2020, was CVE-2020-10173. It enabled attackers to compromise the network managed by the router by injecting malicious commands into its authentication process.

In 2022, Mirai was observed to explore the Spring4Shell vulnerability (CVE-2022-22965) by uploading its executable to target devices’ '/tmp' folder and leveraging the 'chmod' command to launch it.

Many variants of Mirai implement modified UPX packing to complicate the analysis process of their executables and make them more lightweight.

One of the latest variants of Mirai, NoaBot, which was first spotted in 2024, leverages SSH login brute forcing capabilities. Instead of launching DDoS attacks, it turns infected devices into crypto-mining machines.

Mirai execution process

Let’s take a look at how a typical Mirai malware attack unfolds by submitting a sample of this malware to the ANY.RUN sandbox.

Mirai infects the Ubuntu system typically through exposed and vulnerable Telnet or SSH ports. Once access is gained, Mirai downloads its binary from a C2server or through a peer-to-peer network onto the infected system.

To ensure persistence, Mirai may attempt to disable security software, delete competing malware, and create copies of itself in various system directories. It may also modify system startup scripts or use cron jobs to ensure it is executed on system reboot.

The infected system starts scanning the internet for other vulnerable devices by randomly generating IP addresses and attempting to log in using the same list of default credentials, infecting more devices.

The infected device establishes a connection with a C2 server to receive instructions from the botnet operator. These instructions can include launching DDoS attacks, downloading additional payloads, or updating.

It's important to note that the exact execution chain can vary depending on the variant of Mirai and the specific configuration of the infected system.

Mirai Suricata rule in ANY.RUN Suricata rule used for detecting Mirai in ANY.RUN

Mirai malware distribution methods

Unlike most malware families, such as Remcos and NjRAT, Mirai is not distributed via phishing emails or other common attack vectors. Instead, since it is a botnet, Mirai relies on self-propagation. This allows the botnet to grow rapidly and become more powerful, enabling it to launch larger and more devastating attacks.

Conclusion

To protect against Mirai and its variants, it is important to ensure that all IoT devices are secured with strong, unique passwords and that any known vulnerabilities are patched as soon as possible. To conduct Mirai malware analysis to see how the latest variants operate, use the ANY.RUN sandbox.

By executing Mirai in a controlled environment, you can observe its behavior and network activity without risking infection of your own infrastructure. This will enable you to identify the vulnerabilities employed by the malware, as well as expose its C2 servers.

Sign up for ANY.RUN now – it’s free!

HAVE A LOOK AT

Miolab Stealer screenshot
Miolab Stealer is a macOS malware threat designed to steal user credentials and sensitive files without raising immediate suspicion. It relies on fake system prompts and legitimate built-in tools to make malicious actions look routine. Instead of causing obvious disruption, it quietly collects valuable data and prepares it for exfiltration from the device. By blending deception with trusted macOS behavior, it increases the chance that the attack will go unnoticed in its early stages. This makes early behavioral detection critical before the theft of credentials and files is complete.
Read More
Qilin Ransomware screenshot
Qilin ransomware (predecessor known as “Agenda”) is a rapidly evolving ransomware-as-a-service (RaaS) operation targeting organizations worldwide. Known for double extortion tactics (encrypting files while also threatening to leak stolen data) Qilin has quickly gained notoriety for its customization, flexibility, and impact on critical infrastructure.
Read More
Kamasers screenshot
Kamasers
kamasers
Kamasers is a multi-functional DDoS botnet malware that transforms infected machines into remotely controlled attack nodes. It combines network-layer flooding capabilities, resilient command-and-control (C2), and payload delivery, making it not just a disruption tool but a gateway to broader compromise.
Read More
PureCrypter screenshot
PureCrypter
purecrypter
First identified in March 2021, PureCrypter is a .NET-based loader that employs obfuscation techniques, such as SmartAssembly, to evade detection. It has been used to distribute malware families including AgentTesla, RedLine Stealer, and SnakeKeylogger. The malware is typically delivered through phishing campaigns and malicious downloads, often masquerading as legitimate files with extensions like .mp4 or .pdf. PureCrypter utilizes encryption and compression to conceal its payloads and can inject malicious code into legitimate processes to maintain persistence on the infected system.
Read More
Trojan screenshot
Trojan
trojan trojan horse
Trojans are a group of malicious programs distinguished by their ability to masquerade as benign software. Depending on their type, trojans possess a variety of capabilities, ranging from maintaining full remote control over the victim’s machine to stealing data and files, as well as dropping other malware. At the same time, the main functionality of each trojan family can differ significantly depending on its type. The most common trojan infection chain starts with a phishing email.
Read More
Stealer screenshot
Stealer
stealer
Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.
Read More