s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1846931 high

📛 Threat Title

Mirai: Domain that is used for botnet Command&control (C&C) lynxsecurity.ru

Category: Mirai Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-07-09 08:15:10 UTC. Reporter: botnetkiller. Tags: c2, Mirai.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain lynxsecurity.ru UrlVoid 5 / 35

IOC database

Type
domain
Value
lynxsecurity.ru
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-07-09 08:15:10 UTC. Reporter: botnetkiller. Tags: c2, Mirai.

Remediations (10)

  • web:arxiv.org

    botnet is a collection of bots connected to and controlled by a Command and Control (C&C) channel [23]. Bots are used all over the Internet and on various systems, such as video games and social media platforms.

  • web:blog.pulsedive.com

    Dive into a technical primer on the modern botnet landscape - including the evolution of Mirai -based botnets , capabilities, and recent enforcement actions.

  • web:blog.qualys.com

    The above-mentioned figure shows the complete details of identified command-and-control servers, with respective payload content to the final URL, which drops the Mirai malware. Murdoc Botnet Mirai malware, here dubbed as Murdoc Botnet , is a prominent malware family for *nix systems. It mainly targets vulnerable AVTECH and Huawei devices.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:www.checkpoint.com

    How Does Mirai Work? Mirai is an example of botnet malware. Botnet malware infects a computer and opens a command and control (C2) channel to an attacker's C2 infrastructure. This allows the attacker to send commands to the botnet malware, which executes them using the resources of the infected machine. With many infected devices, botnets are able to perform large-scale automated attacks ...

  • web:www.cloudflare.com

    What is Mirai ? Mirai is malware that infects smart devices that run on ARC processors, turning them into a network of remotely controlled bots or "zombies". This network of bots, called a botnet , is often used to launch DDoS attacks. Botnet - networked malicious bots Malware, short for malicious software, is an umbrella term that includes computer worms, viruses, Trojan horses, rootkits and ...

  • web:www.corero.com

    Mitigation and defense strategies against Mirai botnet attacks In addition to addressing security weaknesses in your IoT devices and how you deploy and use them, a combination of best practices and technology aimed at defending the network itself against Mirai botnet attacks is also critical.

  • web:www.fortinet.com

    If the malware has not yet established a connection with its command-and-control (C2) server, it initiates communication by randomly selecting from a list of predefined C2 domains . To resolve these domains , the malware uses public DNS servers—such as 1.1.1.1, 8.8.8.8, or 8.8.4.4—instead of relying on the system's configured resolver.

  • web:www.netscout.com

    Attack traffic generated by TurboMirai DDoS botnets such as Aisuru is not spoofed because the botnet code does not run in a privileged context on compromised devices; additionally, most botnet nodes are sited on broadband access networks that have source-address validation (SAV) mechanisms enabled by default at the access layer.

  • web:www.radware.com

    Infected devices join a distributed botnet controlled by command-and-control (C2) infrastructure and can be instructed to launch volumetric and application-layer attacks on chosen targets. The danger of Mirai stems from the combination of always-on devices, widespread insecure defaults, and the low cost for attackers to operate large botnets .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.