TF-1868478
high
📛 Threat Title
Mirai: Domain that is used for botnet Command&control (C&C) poop.garden
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-08-04 19:16:25 UTC. Reporter: botnetkiller. Tags: c2, Mirai.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
poop.garden
IOC database
- Type
- domain
- Value
poop.garden- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Mirai
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Mirai (aliases: Katana). Confidence: 100. First seen: 2026-08-04 19:16:25 UTC. Reporter: botnetkiller. Tags: c2, Mirai.
Remediations (10)
-
web:blog.pulsedive.com
Dive into a technical primer on the modern botnet landscape - including the evolution of Mirai -based botnets , capabilities, and recent enforcement actions.
-
web:en.wikipedia.org
Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks.
-
web:grokipedia.com
The massive scale of Mirai's botnet , which peaked at infecting hundreds of thousands of IoT devices and enabling DDoS attacks exceeding 600 Gbps, has sparked debate over primary causality, with analysts attributing the rapid proliferation primarily to systemic vulnerabilities in IoT hardware rather than the malware's novelty.
-
web:www.checkpoint.com
How Does Mirai Work? Mirai is an example of botnet malware. Botnet malware infects a computer and opens a command and control (C2) channel to an attacker's C2 infrastructure. This allows the attacker to send commands to the botnet malware, which executes them using the resources of the infected machine. With many infected devices, botnets are able to perform large-scale automated attacks ...
-
web:www.corero.com
Mitigation and defense strategies against Mirai botnet attacks In addition to addressing security weaknesses in your IoT devices and how you deploy and use them, a combination of best practices and technology aimed at defending the network itself against Mirai botnet attacks is also critical.
-
web:www.fortinet.com
If the malware has not yet established a connection with its command-and-control (C2) server, it initiates communication by randomly selecting from a list of predefined C2 domains . To resolve these domains , the malware uses public DNS servers—such as 1.1.1.1, 8.8.8.8, or 8.8.4.4—instead of relying on the system's configured resolver.
-
web:www.indusface.com
The Mirai botnet is a network of compromised IoT devices used to launch massive DDoS attacks, exploiting weak credentials & vulnerabilities to disrupt services.
-
web:www.pwndefend.com
Observed in-the-wild chain: CVE-2026-34908 (access-control/traversal bypass to the localhost updater) → CVE-2026-34910 (command injection via pkg_name) → Mirai loader (zok) drop. So they use part of a CVE and part of another CVE to achieve the outcome, but I'd suggest that they could have just used either CVE if they had full knowledge.
-
web:www.radware.com
Infected devices join a distributed botnet controlled by command-and-control (C2) infrastructure and can be instructed to launch volumetric and application-layer attacks on chosen targets. The danger of Mirai stems from the combination of always-on devices, widespread insecure defaults, and the low cost for attackers to operate large botnets .
-
web:www.sciencedirect.com
The Mirai botnet is a well-known example of a network used for malicious activities, detected for the first time by the white-hat research group in August 2016. Since then, Mirai initiated massive DDoS attacks by scanning for and exploiting vulnerabilities in network devices.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.