Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

Mirai

23
Global rank
9 infographic chevron month
Month rank
4 infographic chevron week
Week rank
0
IOCs

Mirai is a self-propagating malware that scans the internet for vulnerable IoT devices and infects them to create a botnet. Mirai variants utilize lists of common default credentials to gain access to devices. Mirai's primary use is for launching distributed denial-of-service (DDoS) attacks, but it has also been used for cryptocurrency mining.

Botnet
Type
USA
Origin
1 September, 2016
First seen
28 August, 2026
Last seen

How to analyze Mirai with ANY.RUN

Type
USA
Origin
1 September, 2016
First seen
28 August, 2026
Last seen

IOCs

IP addresses
142.251.14.102
142.251.127.84
192.178.183.100
192.178.183.101
185.125.190.101
172.217.115.4
40.114.177.156
147.182.224.216
91.189.91.58
142.251.110.102
192.178.183.102
185.125.190.57
91.189.91.157
142.251.156.119
151.101.65.91
185.125.190.58
192.178.183.113
172.217.116.4
185.125.190.56
142.250.154.113
Hashes
42b55d126d1e640b1ed7a6bdcb9a46c81df461fa7e131f4f8c7108c2c61c14de
14f92b911f9fe774720461eec5bb4761ae6bfc9445c67e30bf624a8694b4b1da
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
0f1bad70c7bd1e0a69562853ec529355462fcd0423263a3d39d6d0d70b780443
e09f42c398d688dce168570291f1f92d079987deda3099a34adb9e8c0522b30c
d6a5fe39cd672781b256e0e3102f7022635f1d4bb7cfcc90a80fffe4d0f3877e
c6fa451ecd1a8a9533801028bc70cf82ef48eba11bb835e53e6c530b43018938
23fb4d1613fb426612119928a7222ca84a9cba4ba081a8b1be7f2565c013c590
e566796c18517e7084e3a892b3291cc189b85e7830800503c256998ab697a507
2771d13c637c267132afff9db67537bef95708534b79ae8d954254c4e64e4e0f
bff3a19327fd09a24c1aa4e7f34c508d7e668a8eb32f2cc7c33bcaa7e9ee2319
0c2dd377ed0cc66161e9db8f89f7d8bcb3ad8c06c4a054bdcba214ab05f58c9a
c1d053e070a02c4a970a1e09601b847826ce158bc9cad4ebbf04706655d6a03e
3227838954949b03fb522482b0bd1cba7e59fea739c5f489ea75ada4cc86f582
f07cd66b4ccc01483c55587b59b45593d4def81c2b99aa2473c31b2da84a4a15
e8006048ffc9aacb8d04179877ba4d7c64e7db7ad5aa27f322f49241ec79adc1
e5cfd25297afeed35f2932ede23ab2b49ef40ba498a51bc52a124b5ebe721539
ac93c3fc3c5030ded4b12b84381639622a473d9e24880f5b27f83f231c83c325
c4791216e0e00a6671efff290fb575532e0eb0d7b4d41f32118505ce257050d0
Domains
connectivity-check.ubuntu.com
ntp.ubuntu.com
optimizationguide-pa.googleapis.com
redirector.gvt1.com
update.googleapis.com
www.google.com
safebrowsingohttpgateway.googleapis.com
google.com
nmcheck.gnome.org
duckduckgo.com
clients2.google.com
android.clients.google.com
accounts.google.com
clientservices.googleapis.com
client.wns.windows.com
licensing.mp.microsoft.com
edge.microsoft.com
slscr.update.microsoft.com
settings-win.data.microsoft.com
login.live.com
URLs
http://connectivity-check.ubuntu.com/
http://nmcheck.gnome.org/
http://clients2.google.com/time/1/current?cup2key=10:tlbzjgotcd6_xsuiv8jqgutgsw7iny0wvufdyk7rfmm&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
http://147.182.224.216/
http://147.182.224.216/favicon.ico
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasybqjzh-7pa44blaaakh6490hufowx0kcym
https://clientservices.googleapis.com/chrome-variations/seed?osname=linux&channel=stable&milestone=150
https://redirector.gvt1.com/edgedl/chrome/dict/en-us-10-1.bdic
https://update.googleapis.com/service/update2/json?cup2key=16:sgq6sjkg3k9adfbzytzbxsfuz242muofmibsilhdxba&cup2hreq=d849d0291518d154e98b2fba1bc5fac00edd4f35f667e6d85da5d0e8502006a7
https://www.google.com/async/folae?async=_fmt:pb&udm=50&client_locale=en-us&client_country=us
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard&laf=b64bin
https://android.clients.google.com/checkin
http://147.182.224.216/zed
http://clients2.google.com/time/1/current?cup2key=10:h4tjbgwm-wnapqdiv0b_6ytkc-dg65-8g6xdcfampkc&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://duckduckgo.com/
https://duckduckgo.com/favicon.ico
https://update.googleapis.com/service/update2/json?cup2key=16:flsdqjacysb2q2iulu7iy9l19dhg7lk_qt4f1bq_vme&cup2hreq=cb460238b56bc384963510e9e43ac8b8fb5e44fd12884168306d71cfba763c5e
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=&oit=0&gs_rn=42&sugkey=aizasybqjzh-7pa44blaaakh6490hufowx0kcym
https://www.google.com/complete/search?client=chrome-omni&gs_ri=chrome-ext-ansg&xssi=t&q=curl+-ss+147.182.224.216%2fzed%7cperl&oit=4&cp=33&pgcl=3&gs_rn=42&psi=yvan_zghiw7sfhi2&sugkey=aizasybqjzh-7pa44blaaakh6490hufowx0kcym
https://optimizationguide-pa.googleapis.com/v1:getmodels?key=aizasybqjzh-7pa44blaaakh6490hufowx0kcym
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2800
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7890
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10855
comments 0

What is Mirai malware?

Mirai is a botnet that has been targeting Internet of Things (IoT) devices since September 2016. It initially gained notoriety with denial-of-service attacks on several high-profile targets, including Krebs on Security, a blog run by the notable cybersecurity expert and journalist Brian Krebs. The botnet exploited the lack of security in IoT devices in the form of weak passwords, using them to generate massive traffic to overwhelm the target services.

The original developers, three college students from the United States, made the Mirai malware source code public in 2017 in an attempt to demonstrate their willingness to abandon criminal activity. However, this led to the creation of numerous variants of the malware, such as Hajime and Sylveon, as well as an influx of new threat actors employing these in their attacks.

Since then, the botnet has been experiencing a continuous evolution, gaining additional capabilities and exploiting new vulnerabilities found in different devices. It has been employed in numerous campaigns, by 2022 becoming one the largest botnets. According to some estimates, the Mirai malware has been used to infect over half a million IoT products.

Mirai's rise and scale can be attributed to a combination of factors. These include efficient spreading based on Internet-wide scanning and the widespread use of insecure default passwords in IoT products.

Get started today for free

Analyze malware and phishing in a fully-interactive sandbox

Create free account

Mirai malware technical details

On the basic level, Mirai uses brute forcing to infect new devices. Here are the four stages that define its typical operation:

  • It begins by scanning the internet for vulnerable IoT devices by sending TCP probes to IPv4 addresses.
  • Once it identifies a potential victim, it attempts to log in using a list of popular credentials.
  • Upon successful login, the malware uses its loader module to download and execute a malicious program on the device. Once a device is infected, it becomes part of the botnet and begins scanning the internet for other vulnerable devices to infect.
  • Mirai then engages the infected devices to launch DDoS attacks.

The malware usually communicates with the command-and-control (C2) over the TCP protocol. Yet, there are also TLS-capable variants.

After establishing its presence on a device, Mirai kills any processes associated with the activity of other botnets, such as Gafgyt, that might have infected it prior.

Over the past years, Mirai variants have been able to infect thousands of devices by abusing various vulnerabilities. For instance, in 2020, one Mirai variant took advantage of a security flaw (CVE-2020-9054) in Zyxel NAS devices, which allowed the malware to employ special characters to inject malicious commands and take control of devices.

Another vulnerability used by Mirai, which was identified in Comtrend VR-3033 routers in 2020, was CVE-2020-10173. It enabled attackers to compromise the network managed by the router by injecting malicious commands into its authentication process.

In 2022, Mirai was observed to explore the Spring4Shell vulnerability (CVE-2022-22965) by uploading its executable to target devices’ '/tmp' folder and leveraging the 'chmod' command to launch it.

Many variants of Mirai implement modified UPX packing to complicate the analysis process of their executables and make them more lightweight.

One of the latest variants of Mirai, NoaBot, which was first spotted in 2024, leverages SSH login brute forcing capabilities. Instead of launching DDoS attacks, it turns infected devices into crypto-mining machines.

Mirai execution process

Let’s take a look at how a typical Mirai malware attack unfolds by submitting a sample of this malware to the ANY.RUN sandbox.

Mirai infects the Ubuntu system typically through exposed and vulnerable Telnet or SSH ports. Once access is gained, Mirai downloads its binary from a C2server or through a peer-to-peer network onto the infected system.

To ensure persistence, Mirai may attempt to disable security software, delete competing malware, and create copies of itself in various system directories. It may also modify system startup scripts or use cron jobs to ensure it is executed on system reboot.

The infected system starts scanning the internet for other vulnerable devices by randomly generating IP addresses and attempting to log in using the same list of default credentials, infecting more devices.

The infected device establishes a connection with a C2 server to receive instructions from the botnet operator. These instructions can include launching DDoS attacks, downloading additional payloads, or updating.

It's important to note that the exact execution chain can vary depending on the variant of Mirai and the specific configuration of the infected system.

Mirai Suricata rule in ANY.RUN Suricata rule used for detecting Mirai in ANY.RUN

Mirai malware distribution methods

Unlike most malware families, such as Remcos and NjRAT, Mirai is not distributed via phishing emails or other common attack vectors. Instead, since it is a botnet, Mirai relies on self-propagation. This allows the botnet to grow rapidly and become more powerful, enabling it to launch larger and more devastating attacks.

Conclusion

To protect against Mirai and its variants, it is important to ensure that all IoT devices are secured with strong, unique passwords and that any known vulnerabilities are patched as soon as possible. To conduct Mirai malware analysis to see how the latest variants operate, use the ANY.RUN sandbox.

By executing Mirai in a controlled environment, you can observe its behavior and network activity without risking infection of your own infrastructure. This will enable you to identify the vulnerabilities employed by the malware, as well as expose its C2 servers.

Sign up for ANY.RUN now – it’s free!

HAVE A LOOK AT

Roning Loader screenshot
Roning Loader
roning
RoningLoader is a multi-stage Windows loader designed to operate quietly while preparing systems for deeper compromise. It abuses trusted system tools and interferes with security controls to reduce the chances of early detection. Instead of acting as a final payload, it creates conditions for follow-on malware to execute more effectively. Its use of staged execution and code injection allows attackers to blend into legitimate activity and escalate impact. This makes early behavioral detection critical before the attack chain progresses further.
Read More
INC Ransomware screenshot
INC Ransomware is a ransomware-as-a-service (RaaS) spotted in mid-2023. It targets industries like retail, real estate, finance, healthcare, and education, primarily in the U.S. and UK. It encrypts and exfiltrates data demanding a ransom. It employs advanced evasion techniques, destroys backup, and abuses legitimate system tools at all the stages of the kill chain.
Read More
XRed screenshot
XRed
xred
XRed operates as a stealthy backdoor, enabling cybercriminals to gain unauthorized remote access to infected systems. XRed has gained particular notoriety for its distribution through trojanized legitimate software and hardware drivers, making it exceptionally dangerous due to its ability to masquerade as trusted applications.
Read More
Quasar RAT screenshot
Quasar RAT
quasar trojan rat
Quasar is a very popular RAT in the world thanks to its code being available in open-source. This malware can be used to control the victim’s computer remotely.
Read More
MassLogger screenshot
MassLogger
masslogger
MassLogger is a credential stealer and keylogger first identified in April 2020. It has been actively used in cyber campaigns to exfiltrate sensitive information from compromised systems. It is designed for easy use by less tech-savvy actors and is prominent for the capability of spreading via USB drives. It targets both individuals and organizations in various industries, mostly in Europe and the USA.
Read More
Cactus Ransomware screenshot
Cactus ransomware-as-a-service (RaaS) was first caught in March 2023 targeting corporate networks. It became known for its self-encrypting payload and double extortion tactics. Cactus primarily targets large enterprises across industries in finance, manufacturing, IT, and healthcare. It is known for using custom encryption techniques, remote access tools, and penetration testing frameworks to maximize damage.
Read More