This detection rule identifies network traffic matching six specific Indicators of Compromise (IOCs) linked to the Mirai botnet, which is known for executing large-scale DDoS attacks and IoT device compromises. SOC teams should proactively hunt for these signatures in Azure Sentinel to rapidly isolate infected endpoints and prevent potential lateral movement or service disruption before the botnet scales its attack capabilities.
Malware Family: Mirai Total IOCs: 6 IOC Types: ip:port, domain
| Type | Value | Threat Type | First Seen | Confidence |
|---|---|---|---|---|
| domain | mail.coping.ink | botnet_cc | 2026-08-09 | 100% |
| ip:port | 79[.]143[.]191[.]7:8082 | botnet_cc | 2026-08-09 | 100% |
| domain | smtp.coping.ink | botnet_cc | 2026-08-09 | 100% |
| ip:port | 94[.]154[.]43[.]87:8082 | botnet_cc | 2026-08-09 | 100% |
| ip:port | 94[.]154[.]43[.]175:6794 | botnet_cc | 2026-08-09 | 100% |
| ip:port | 91[.]92[.]40[.]5:80 | botnet_cc | 2026-08-08 | 75% |
// Hunt for network connections to known malicious IPs
// Source: ThreatFox - Mirai
let malicious_ips = dynamic(["79.143.191.7", "94.154.43.87", "91.92.40.5", "94.154.43.175"]);
CommonSecurityLog
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, SourceIP, DestinationIP, DestinationPort, DeviceAction, Activity
| order by TimeGenerated desc
// Hunt in Defender for Endpoint network events
let malicious_ips = dynamic(["79.143.191.7", "94.154.43.87", "91.92.40.5", "94.154.43.175"]);
DeviceNetworkEvents
| where RemoteIP in (malicious_ips)
| project Timestamp, DeviceName, RemoteIP, RemotePort, InitiatingProcessFileName, ActionType
| order by Timestamp desc
// Hunt for DNS queries to known malicious domains
// Source: ThreatFox - Mirai
let malicious_domains = dynamic(["mail.coping.ink", "smtp.coping.ink"]);
DnsEvents
| where Name has_any (malicious_domains)
| project TimeGenerated, Computer, Name, IPAddresses, QueryType
| order by TimeGenerated desc
| Sentinel Table | Notes |
|---|---|
CommonSecurityLog | Ensure this data connector is enabled |
DeviceNetworkEvents | Ensure this data connector is enabled |
DnsEvents | Ensure this data connector is enabled |
Here are specific false positive scenarios for the ThreatFox: Mirai IOCs detection rule, along with targeted exclusion strategies suitable for an enterprise environment:
Scenario 1: IoT Device Firmware Updates via Scheduled Tasks
VLAN-IoT) AND the event occurs between 02:00 and 04:00 UTC.Scenario 2: External Vendor API Integration for Asset Management
api.inventory-cloud.com) AND the initiating process is a known enterprise service, such as sn_agent.exe or jira-cli.jar.Scenario 3: Security Tool Telemetry and Threat Intelligence Feeds