Mirai Botnet Activity, (Sat, Jun 13th)

Read the original article: Mirai Botnet Activity, (Sat, Jun 13th)


This past week, I noticed new activity from the Mirai botnet in my honeypot. The sample log with the IP and file associated with the first log appears to have been taken down (96.30.193.26) which appeared multiple times this week including today. However, the last two logs from today are still active which is using a Bash script to download multiple exploits targeting various device types (MIPS, ARM4-7, MPSL, x86, PPC, M68k). Something else of interest is the User-Agent: XTC and the name viktor which appear to be linked to XTC IRC Botnet, aka Hoaxcalls.


Read the original article: Mirai Botnet Activity, (Sat, Jun 13th)