TF-1846931
high
📛 Threat Title
Mirai: Domain that is used for botnet Command&control (C&C) lynxsecurity.ru
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-07-09 08:15:10 UTC. Reporter: botnetkiller. Tags: c2, Mirai.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
lynxsecurity.ru
UrlVoid 5 / 35
IOC database
- Type
- domain
- Value
lynxsecurity.ru- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-07-09 08:15:10 UTC. Reporter: botnetkiller. Tags: c2, Mirai.
Remediations (10)
-
web:arxiv.org
botnet is a collection of bots connected to and controlled by a Command and Control (C&C) channel [23]. Bots are used all over the Internet and on various systems, such as video games and social media platforms.
-
web:blog.pulsedive.com
Dive into a technical primer on the modern botnet landscape - including the evolution of Mirai -based botnets , capabilities, and recent enforcement actions.
-
web:blog.qualys.com
The above-mentioned figure shows the complete details of identified command-and-control servers, with respective payload content to the final URL, which drops the Mirai malware. Murdoc Botnet Mirai malware, here dubbed as Murdoc Botnet , is a prominent malware family for *nix systems. It mainly targets vulnerable AVTECH and Huawei devices.
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:www.checkpoint.com
How Does Mirai Work? Mirai is an example of botnet malware. Botnet malware infects a computer and opens a command and control (C2) channel to an attacker's C2 infrastructure. This allows the attacker to send commands to the botnet malware, which executes them using the resources of the infected machine. With many infected devices, botnets are able to perform large-scale automated attacks ...
-
web:www.cloudflare.com
What is Mirai ? Mirai is malware that infects smart devices that run on ARC processors, turning them into a network of remotely controlled bots or "zombies". This network of bots, called a botnet , is often used to launch DDoS attacks. Botnet - networked malicious bots Malware, short for malicious software, is an umbrella term that includes computer worms, viruses, Trojan horses, rootkits and ...
-
web:www.corero.com
Mitigation and defense strategies against Mirai botnet attacks In addition to addressing security weaknesses in your IoT devices and how you deploy and use them, a combination of best practices and technology aimed at defending the network itself against Mirai botnet attacks is also critical.
-
web:www.fortinet.com
If the malware has not yet established a connection with its command-and-control (C2) server, it initiates communication by randomly selecting from a list of predefined C2 domains . To resolve these domains , the malware uses public DNS servers—such as 1.1.1.1, 8.8.8.8, or 8.8.4.4—instead of relying on the system's configured resolver.
-
web:www.netscout.com
Attack traffic generated by TurboMirai DDoS botnets such as Aisuru is not spoofed because the botnet code does not run in a privileged context on compromised devices; additionally, most botnet nodes are sited on broadband access networks that have source-address validation (SAV) mechanisms enabled by default at the access layer.
-
web:www.radware.com
Infected devices join a distributed botnet controlled by command-and-control (C2) infrastructure and can be instructed to launch volumetric and application-layer attacks on chosen targets. The danger of Mirai stems from the combination of always-on devices, widespread insecure defaults, and the low cost for attackers to operate large botnets .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.