This hunt targets Mirai malware infections by identifying IoT devices exhibiting anomalous outbound traffic to known malicious IP:port pairs and C2 URLs, indicative of compromised default credentials or weak configurations. Proactively hunting for these indicators in Azure Sentinel is critical to detect early-stage botnet recruitment before adversaries leverage the infected infrastructure to launch large-scale DDoS attacks against the organization.
Malware Family: Mirai Total IOCs: 34 IOC Types: ip:port, sha256_hash, url
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| ip:port | 103[.]83[.]87[.]122:80 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 103[.]83[.]87[.]122:2222 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 103[.]83[.]87[.]122:4444 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 103[.]83[.]87[.]122:8060 | botnet_cc | 2026-07-19 | 100% |
| ip:port | 103[.]83[.]87[.]122:4444 | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/telnet.sh | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.x86_64 | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.aarch64 | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.m68k | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.mips | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.mipsel | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.powerpc | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.sparc | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.sh4 | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.arc | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.i486 | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.armv4l | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.armv5l | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.armv6l | payload_delivery | 2026-07-19 | 100% |
| url | hxxp://103[.]83[.]87[.]122/iran.armv7l | payload_delivery | 2026-07-19 | 100% |
| sha256_hash | b1a6dba6636b519d76d7219f6264ac9f1456681c0855baef954fb435d3e25ce5 | payload | 2026-07-19 | 100% |
| sha256_hash | bf38b3e5d645c78377599a6c218a347312c5a3daef693c7931f2710806d85317 | payload | 2026-07-19 | 100% |
| sha256_hash | f5cb6dadaee4399a1f014ef5946d0a4c1af578d15ff078e725e0757f28dc8493 | payload | 2026-07-19 | 100% |
| sha256_hash | e987bb8b32facef51c3cc5a94bd51e01d8c3be8a19c106de70147ab5ce84dc66 | payload | 2026-07-19 | 100% |
| sha256_hash | 6e709fb9b09d9f8318724a8620812f55411a3ea49de6319c4832885547773ddd | payload | 2026-07-19 | 100% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Mirai
let malicious_ips = dynamic(["103.83.87.122"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["103.83.87.122"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for access to known malicious URLs
// Source: ThreatFox - Mirai
let malicious_urls = dynamic(["http://103.83.87.122/telnet.sh", "http://103.83.87.122/iran.x86_64", "http://103.83.87.122/iran.aarch64", "http://103.83.87.122/iran.m68k", "http://103.83.87.122/iran.mips", "http://103.83.87.122/iran.mipsel", "http://103.83.87.122/iran.powerpc", "http://103.83.87.122/iran.sparc", "http://103.83.87.122/iran.sh4", "http://103.83.87.122/iran.arc", "http://103.83.87.122/iran.i486", "http://103.83.87.122/iran.armv4l", "http://103.83.87.122/iran.armv5l", "http://103.83.87.122/iran.armv6l", "http://103.83.87.122/iran.armv7l"]);
UrlClickEvents
| where Url has_any (malicious_urls)
| project Timestamp, AccountUpn, Url, ActionType, IsClickedThrough
| order by Timestamp desc
// Hunt for files matching known malicious hashes
// Source: ThreatFox - Mirai
let malicious_hashes = dynamic(["b1a6dba6636b519d76d7219f6264ac9f1456681c0855baef954fb435d3e25ce5", "bf38b3e5d645c78377599a6c218a347312c5a3daef693c7931f2710806d85317", "f5cb6dadaee4399a1f014ef5946d0a4c1af578d15ff078e725e0757f28dc8493", "e987bb8b32facef51c3cc5a94bd51e01d8c3be8a19c106de70147ab5ce84dc66", "6e709fb9b09d9f8318724a8620812f55411a3ea49de6319c4832885547773ddd", "0d64cd75599dea5b8cf393b6e2b709f51b3971e64b96920e0707020e22ee7953", "f38d748d9ea29424c28744c52bcd1d14328d49fcb604ca08fab3547ec500d6f0", "b4acd1ab65624b694946b1181bba0732bb63c88c51b8334914c26c1805b2e1aa", "21c5f4a04173a5176d60b06095bf5d25e0022ffbe304601e368eccf718587dc8", "ec442a132f27486d1dfa3faa92c03e10012afe2b8de39fa9b42b367f7971c989", "9538c8a2edeaa8667134a469d03a7057ddc1e753ce1e5250f92f01c1097fcb1d", "d8cd1d9f8c092aa4a6c1b1b2b97c7de71d55c2af8332532d2956e4f5becac17e", "95f5bd70c4e40f9663b67d40d23a46ca21d97448f9a609be10b12837e6a59805", "b1f2808e05cb42894790c12172ffacf8673a0a7e14c7af5ad43d5bedfa62a5e4"]);
DeviceFileEvents
| where SHA256 in (malicious_hashes) or SHA1 in (malicious_hashes) or MD5 in (malicious_hashes)
| project Timestamp, DeviceName, FileName, FolderPath, SHA256, InitiatingProcessFileName
| order by Timestamp desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceFileEvents | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
UrlClickEvents | Ensure this data connector is enabled |
Here are 4 specific false positive scenarios for the ThreatFox: Mirai IOCs detection rule in an enterprise environment, along with suggested filters or exclusions:
Scheduled Firmware Updates from Vendors
*.synology.com, update.axis.com) and restrict the rule trigger to business hours only, or exclude specific source IP ranges assigned to the “IoT-Management” VLAN where these updates are orchestrated.Cloud Backup and Synchronization Agents
backup-agent-01.corp.local) connecting to known cloud provider IP blocks (AWS, Azure, GCP) on standard ports 443 and 8080.Third-Party Remote Administration Tools