s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1868478 high

📛 Threat Title

Mirai: Domain that is used for botnet Command&control (C&C) poop.garden

Category: Mirai Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-08-04 19:16:25 UTC. Reporter: botnetkiller. Tags: c2, Mirai.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain poop.garden

IOC database

Type
domain
Value
poop.garden
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to Mirai

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-08-04 19:16:25 UTC. Reporter: botnetkiller. Tags: c2, Mirai.

Remediations (10)

  • web:blog.pulsedive.com

    Dive into a technical primer on the modern botnet landscape - including the evolution of Mirai -based botnets , capabilities, and recent enforcement actions.

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.

  • web:grokipedia.com

    The massive scale of Mirai's botnet , which peaked at infecting hundreds of thousands of IoT devices and enabling DDoS attacks exceeding 600 Gbps, has sparked debate over primary causality, with analysts attributing the rapid proliferation primarily to systemic vulnerabilities in IoT hardware rather than the malware's novelty.

  • web:www.checkpoint.com

    How Does Mirai Work? Mirai is an example of botnet malware. Botnet malware infects a computer and opens a command and control (C2) channel to an attacker's C2 infrastructure. This allows the attacker to send commands to the botnet malware, which executes them using the resources of the infected machine. With many infected devices, botnets are able to perform large-scale automated attacks ...

  • web:www.corero.com

    Mitigation and defense strategies against Mirai botnet attacks In addition to addressing security weaknesses in your IoT devices and how you deploy and use them, a combination of best practices and technology aimed at defending the network itself against Mirai botnet attacks is also critical.

  • web:www.fortinet.com

    If the malware has not yet established a connection with its command-and-control (C2) server, it initiates communication by randomly selecting from a list of predefined C2 domains . To resolve these domains , the malware uses public DNS servers—such as 1.1.1.1, 8.8.8.8, or 8.8.4.4—instead of relying on the system's configured resolver.

  • web:www.indusface.com

    The Mirai botnet is a network of compromised IoT devices used to launch massive DDoS attacks, exploiting weak credentials & vulnerabilities to disrupt services.

  • web:www.pwndefend.com

    Observed in-the-wild chain: CVE-2026-34908 (access-control/traversal bypass to the localhost updater) → CVE-2026-34910 (command injection via pkg_name) → Mirai loader (zok) drop. So they use part of a CVE and part of another CVE to achieve the outcome, but I'd suggest that they could have just used either CVE if they had full knowledge.

  • web:www.radware.com

    Infected devices join a distributed botnet controlled by command-and-control (C2) infrastructure and can be instructed to launch volumetric and application-layer attacks on chosen targets. The danger of Mirai stems from the combination of always-on devices, widespread insecure defaults, and the low cost for attackers to operate large botnets .

  • web:www.sciencedirect.com

    The Mirai botnet is a well-known example of a network used for malicious activities, detected for the first time by the white-hat research group in August 2016. Since then, Mirai initiated massive DDoS attacks by scanning for and exploiting vulnerabilities in network devices.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.