Hajime
153 addresses observed running Hajime botnet nodes — 17 still listed, 136 archived. Observed from 2026-06-13.
Detection packs
Rules for the 17 still-listed addresses on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.
About
A peer-to-peer IoT worm that spreads like Mirai but carries no attack payload — instead it firewalls off telnet and the TR-069 ports that IoT worms use to get in, which has been read as vigilante rather than criminal. It has no central C2 SERVER, though it is not uncontrolled: peers are found over a BitTorrent DHT and its author's signed modules propagate through the mesh. So an address listed here was observed as an infected device rather than as operator infrastructure. Its intent remains unresolved either way — it is an unauthorised install base on hardware nobody consented to hand over.
Ports
Addresses · page 2 of 2
Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.
Listed in error?
These pages are generated from automated scanning and are publicly available. Write to support@publicmosaic.com — see abuse & takedown, or opt-out to exclude a network range from scanning.