top of page
  • Nello Verde

Traffic Linked To Mirai Botnet



Since the beginning of January, there was consistent targeting of our honeypots from a variety of IP addresses. The traffic - directed towards SSH port 22 - predominantly originated from China, Canada, India, the United States and Germany. Peaks of malicious traffic were observed on 6 and 10 January 2024.


Timestamp Of Suspicious Traffic

Analysis of the activity suggests attempts to login with weak credentials.


Set Of Passwords Submitted To Out Honeypots

Furthermore, a review of the top ten IP addresses suggests a partial correlation with the Mirai botnet whose variant - NoaBot - has been recently targeting SSH servers to install cryptominers.

Top Ten Source IP Addresses

Open sources also indicate some of these IP addresses are reported in connection with mass scanning activities.


If you are interested in specifics or additional insights on the threats above or any other threat, please visit our dedicated service page or reach out to info@clipeusintelligence.com with your inquiry. We would be glad to assist you

bottom of page