home.social

#mirai — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #mirai, aggregated by home.social.

  1. Jutro samochód na wodór przyjeżdża do serwisu, tam go odbieram, oglądam, zostawiam na europeizację i zabieram się za formalności. Na początku zwolnienie z akcyzy, bo cło i VAT mam już zapłacone. Oba były doliczone do opłat portowych, bez tego auto nie opuściłoby portu. Akcyza zajmie kilka dni, jak się skończy to zrobię podejście do tablic tymczasowych, żeby z serwisu już móc na nich wyjechać. Wtedy okaże się czego mi brakuje, co trzeba przetłumaczyć itd. Oczywiście będę dawał znać

    #wodór #paliwaalternatywne #toyota #mirai

  2. Jutro samochód na wodór przyjeżdża do serwisu, tam go odbieram, oglądam, zostawiam na europeizację i zabieram się za formalności. Na początku zwolnienie z akcyzy, bo cło i VAT mam już zapłacone. Oba były doliczone do opłat portowych, bez tego auto nie opuściłoby portu. Akcyza zajmie kilka dni, jak się skończy to zrobię podejście do tablic tymczasowych, żeby z serwisu już móc na nich wyjechać. Wtedy okaże się czego mi brakuje, co trzeba przetłumaczyć itd. Oczywiście będę dawał znać

    #wodór #paliwaalternatywne #toyota #mirai

  3. 📰 Mirai Variant 'xlabs_v1' Builds DDoS Botnet by Hijacking IoT Devices with Exposed ADB Ports

    🚨 New Mirai-based botnet 'xlabs_v1' hijacks IoT devices & Android TVs via exposed ADB ports (TCP/5555). The botnet is used for DDoS-for-hire services, targeting Minecraft servers. #Mirai #Botnet #DDoS #IoTSecurity

    🔗 cyber.netsecops.io

  4. Mirai-Based xlabs_v1 Botnet Exploits ADB for IoT Hijacking

    Meet xlabs_v1, a powerful botnet derived from Mirai that's hijacking IoT devices by exploiting exposed Android Debug Bridge (ADB) services on TCP port 5555. This sneaky malware infects devices like Android TV boxes and smart TVs, and can even measure a device's bandwidth to sell it on the black market.

    osintsights.com/mirai-based-xl

    #IotBotnet #Mirai #AdbExploitation #EmergingThreats #IotHijacking

  5. Found an odd Telnet like connection in a Mirai malware execution. Follow these steps to see for yourself:
    telnet 45.149.186.18 8080
    Enter: newsrv

    🔥 nivela.duckdns[.]org:8080
    🔥 45.149.186.18:8080
    🔥 b8d37e1ba85e8cebd9802b31747a1689

    #Mirai #OWARI

  6. Found an odd Telnet like connection in a Mirai malware execution. Follow these steps to see for yourself:
    telnet 45.149.186.18 8080
    Enter: newsrv

    🔥 nivela.duckdns[.]org:8080
    🔥 45.149.186.18:8080
    🔥 b8d37e1ba85e8cebd9802b31747a1689

    #Mirai #OWARI

  7. Potassium update: the Mirai fork @synthient reported in March (x.com/deobfuscately/status/203) is still active and the operator appears to have taken up Dutch poetry. The new C2 domain is ikhebkankerinmijnrechterteelbal[.]st (would not recommend pasting that into Google Translate during standup.)

    Same key material and HTTP C2 protocol as the original potassium.vitacoco...[.]st variant. 11-port random C2 rotation, spreading via ADB to Android TV boxes.

    IoCs:

    a87aa7995ee9996952edb323d703875812f71d08237756ab44367f10e6197c7e
    6833cb4681ac69281474be2c626df06cd90bb05bec72ae697cf219a6603826c9
    3f13e18e190a7fc4c795d7caa83534d2879376ce43fd1a9120f23e48639cfe85

    C2: ikhebkankerinmijnrechterteelbal[.]st → byte-swapped → 45.153.34[.]245
    Dropper: 92.38.186[.]44 (HTTP + netcat :25565)

    #mirai #DDoS #threatintel

    edit: added byte-swapped C2 value

  8. Potassium update: the Mirai fork @synthient reported in March (x.com/deobfuscately/status/203) is still active and the operator appears to have taken up Dutch poetry. The new C2 domain is ikhebkankerinmijnrechterteelbal[.]st (would not recommend pasting that into Google Translate during standup.)

    Same key material and HTTP C2 protocol as the original potassium.vitacoco...[.]st variant. 11-port random C2 rotation, spreading via ADB to Android TV boxes.

    IoCs:

    a87aa7995ee9996952edb323d703875812f71d08237756ab44367f10e6197c7e
    6833cb4681ac69281474be2c626df06cd90bb05bec72ae697cf219a6603826c9
    3f13e18e190a7fc4c795d7caa83534d2879376ce43fd1a9120f23e48639cfe85

    C2: ikhebkankerinmijnrechterteelbal[.]st → byte-swapped → 45.153.34[.]245
    Dropper: 92.38.186[.]44 (HTTP + netcat :25565)

    #mirai #DDoS #threatintel

    edit: added byte-swapped C2 value

  9. Twój stary router TP-Link na celowniku Mirai – czas na zmiany?

    Masz w domu router „za stówkę”, który działa „od zawsze”? Sprawdź, czy to nie ten moment, kiedy „od zawsze” właśnie się kończy.

    Czytaj dalej:
    pressmind.org/twoj-stary-route

    #PressMindLabs #botnet #cve202333538 #iot #mirai #routery

  10. 📰 Mirai Botnet Exploits Critical Flaw in Discontinued D-Link Routers for DDoS Attacks

    🚨 A new Mirai botnet campaign is exploiting a critical RCE flaw (CVE-2025-29635) in discontinued D-Link routers. The devices are EoL and will not be patched. Disconnect them now to prevent them from joining a DDoS botnet! #Mirai #Botnet #IoT #DLink

    🔗 cyber.netsecops.io/articles/mi

  11. Masz stary router TP-Link? Botnet Mirai aktywnie wykorzystuje lukę CVE-2023-33538 do przejęcia kontroli nad urządzeniami

    Badacze bezpieczeństwa z Unit42 alarmują o trwającej kampanii wymierzonej w posiadaczy starszych routerów TP-Link. Na celowniku są modele, które nie są już objęte wsparciem producenta (status End-of-Line): Cyberprzestępcy wykorzystują lukę oznaczoną jako CVE-2023-33538, która pozwala na wstrzykiwanie złośliwych poleceń (RCE, Remote Command Execution). Analizując próbki można dojść do wniosku, że...

    #Aktualności #Botnet #Malware #Mirai #Router

    sekurak.pl/masz-stary-router-t

  12. Masz stary router TP-Link? Botnet Mirai aktywnie wykorzystuje lukę CVE-2023-33538 do przejęcia kontroli nad urządzeniami

    Badacze bezpieczeństwa z Unit42 alarmują o trwającej kampanii wymierzonej w posiadaczy starszych routerów TP-Link. Na celowniku są modele, które nie są już objęte wsparciem producenta (status End-of-Line): Cyberprzestępcy wykorzystują lukę oznaczoną jako CVE-2023-33538, która pozwala na wstrzykiwanie złośliwych poleceń (RCE, Remote Command Execution). Analizując próbki można dojść do wniosku, że...

    #Aktualności #Botnet #Malware #Mirai #Router

    sekurak.pl/masz-stary-router-t

  13. Playing with {mirai} `launch_remote`.
    Had to fight a little with the `sshd` configuration of the servers . Seems like the default `sshd` conf only allows for 10 unauthenticated logins at the same time, so launching 12 daemons gave me some trouble until I figured it out.
    I also discovered, that any library you load in remote processes (with `mirai::everywhere` for example) needs to be already installed in the remote server. Now it seems obvious, but I was assuming that libraries were behaving as any other object passed through.
    Related to the previous, I've also discovered that if for some reason any connection fails, and you go below the `.min` argument value of `mirai::everywhere`, then the code stays waiting forever until more daemons are added. This is a problem with not interactive scripts. I think a timeout option in `mirai::everywhere` could come in handy.
    But after all, there they are, my little daemons, running freely in 4 different servers. Now I can relax :blobfoxcofe_w_: :blobfoxcofe_w_: :blobfoxcofe_w_:

    #mirai #RStats

  14. Playing with {mirai} `launch_remote`.
    Had to fight a little with the `sshd` configuration of the servers . Seems like the default `sshd` conf only allows for 10 unauthenticated logins at the same time, so launching 12 daemons gave me some trouble until I figured it out.
    I also discovered, that any library you load in remote processes (with `mirai::everywhere` for example) needs to be already installed in the remote server. Now it seems obvious, but I was assuming that libraries were behaving as any other object passed through.
    Related to the previous, I've also discovered that if for some reason any connection fails, and you go below the `.min` argument value of `mirai::everywhere`, then the code stays waiting forever until more daemons are added. This is a problem with not interactive scripts. I think a timeout option in `mirai::everywhere` could come in handy.
    But after all, there they are, my little daemons, running freely in 4 different servers. Now I can relax :blobfoxcofe_w_: :blobfoxcofe_w_: :blobfoxcofe_w_:

    #mirai #RStats