public mosaic llc support@publicmosaic.com
malware family

Mirai

4 addresses observed running Mirai botnet nodes — 1 still listed, 3 archived. Observed from 2026-06-13.

TLP:CLEAR
addresses 4 1 still listed
observations 5 address and port pairs
networks 4 distinct ASNs
first seen 2026-06-13 oldest observation

Detection packs

Rules for the 1 still-listed address on this page, regenerated as the archive updates; archived episodes are omitted, and a rule can lag a withdrawal by up to five minutes. Suricata rules are rev:2 — alert tcp on address and port, alert tls where a full certificate fingerprint is published — and carry the archive's own episode ids as sids, so packs load beside each other and beside any per-host file. YARA packs are hash matches only: this site holds no file bytes.

About

An IoT botnet whose source was published in 2016 and has been forked continuously since, so "Mirai" names a lineage rather than one program. The original spread by trying a short list of default credentials against exposed telnet on ports 23 and 2323; later variants added exploits for known router and camera flaws. The vast majority of what is convicted under this label is somebody's derivative rather than the original.

Ports

:801:80801:447671:560941:590641

Addresses

Ordered by when this archive first recorded them, newest first — a stable ordering, so a page holds the same addresses tomorrow. Archived addresses are included and marked; they are the majority of this corpus over time.