Understanding the Mirai Botnet Manos Antonakakis ✝ , Tim April ◆ , Michael Bailey ★ , Matthew Bernhard ‡ , Elie Bursztein ✱ Jaime Cochran △ , Michalis Kallitsis ● , Damian Menscher ✱ , Zakir Durumeric ‡ Deepak Kumar ★ , Chad Seaman ◆ , J. Alex Halderman ‡ , Luca Invernizzi ✱ , Chaz Lever ✝ Zane Ma ★ , Joshua Mason ★ , Nick Sullivan △ , Kurt Thomas ✱ , Yi Zhou ★ ◆ Akamai Technologies, △ Cloudflare, ✝ Georgia Institute of Technology, ✱ Google, ● Merit Network ★ University of Illinois Urbana-Champaign , ‡ University of Michigan Understanding the Mirai Botnet ▪︎ Zane Ma 1
Internet of Things 2016 2020 6 - 9 Billion ~30 Billion Understanding the Mirai Botnet ▪︎ Zane Ma 2
IoT Botnets 2012 Carna Botnet 2015 BASHLITE / gafgyt 420,000 devices 1,000,000 devices Understanding the Mirai Botnet ▪︎ Zane Ma 3
Mirai Understanding the Mirai Botnet ▪︎ Zane Ma 4
Measurement Attacker Data Source Size �� Send command Network Telescope 4.7M unused IPs Active Scanning 136 IPv4 scans Command Report �� Dispatch Loader & Control Server Infrastructure Telnet Honeypots 434 binaries �� Relay ��� Load � Malware Repository 594 binaries � Report Active/Passive DNS 499M daily RRs Devices �� Scan Victim C2 Milkers 64K issued attacks Bots Krebs DDoS Attack 170K attacker IPs � Attack Dyn DDoS Attack 108K attacker IPS DDoS Target July 2016 - February 2017 Understanding the Mirai Botnet ▪︎ Zane Ma 5
Roadmap 1. Growth & Composition 2. Ownership & Evolution 3. Attacks 4. Lessons Learned Understanding the Mirai Botnet ▪︎ Zane Ma 6
Population 700,000 Total Mirai Scans # network telescope scans 600,000 500,000 400,000 300,000 200,000 100,000 0 08/01/16 09/01/16 10/01/16 11/01/16 12/01/16 01/01/17 02/01/17 Date Understanding the Mirai Botnet ▪︎ Zane Ma 7
Population 140,000 120,000 # network telescope scans 700,000 1:42 AM Single Scanner Total Mirai Scans # network telescope scans 600,000 100,000 500,000 23:59 PM 64,500 scanners 80,000 400,000 60,000 300,000 3:59 AM Botnet Expands 40,000 200,000 Mirai TCP/23 scans Non-Mirai TCP/23 scans 100,000 0 08-01 00:00 08/01 06:00 08/01 12:00 08/01 18:00 08/02 00:00 08/02 06:00 08/02 12:00 08/02 18:00 08/03 00:00 08/03 06:00 08/03 12:00 08/03 18:00 0 08/01/16 09/01/16 10/01/16 11/01/16 12/01/16 01/01/17 02/01/17 Date Date Understanding the Mirai Botnet ▪︎ Zane Ma 8
Population 700,000 Total Mirai Scans # network telescope scans 600,000 TCP/23 TCP/2323 500,000 “IoT Telnet” TCP/2323 400,000 300,000 200,000 100,000 0 08/01/16 09/01/16 10/01/16 11/01/16 12/01/16 01/01/17 02/01/17 Date Understanding the Mirai Botnet ▪︎ Zane Ma 9
Population CWMP TCP/7547 700,000 600K peak Total Mirai Scans # network telescope scans 600,000 TCP/7547 500,000 400,000 300,000 200,000 100,000 0 08/01/16 09/01/16 10/01/16 11/01/16 12/01/16 01/01/17 02/01/17 Date Understanding the Mirai Botnet ▪︎ Zane Ma 10
Population 700,000 Total Mirai Scans TCP/443 # network telescope scans 600,000 TCP/23231 TCP/5555 TCP/22 TCP/6789 500,000 TCP/2222 TCP/8080 TCP/37777 TCP/80 400,000 300,000 200,000 100,000 0 08/01/16 09/01/16 10/01/16 11/01/16 12/01/16 01/01/17 02/01/17 Date 9 Additional Protocols Understanding the Mirai Botnet ▪︎ Zane Ma 11
Population 700,000 Total Mirai Scans TCP/6789 # network telescope scans 600,000 TCP/23231 TCP/8080 TCP/22 TCP/80 500,000 TCP/2222 TCP/23 TCP/37777 TCP/2323 TCP/443 TCP/7547 400,000 TCP/5555 300,000 Steady state 200,000 100,000 0 08/01/16 09/01/16 10/01/16 11/01/16 12/01/16 01/01/17 02/01/17 Date Understanding the Mirai Botnet ▪︎ Zane Ma 12
Geography Mirai TDSS/TDL4 South America + North America + Southeast Asia = Europe = 50% of Infections 94% of Infections Understanding the Mirai Botnet ▪︎ Zane Ma 13
Composition Targeted Default Passwords Understanding the Mirai Botnet ▪︎ Zane Ma 14
Composition Infected Devices Understanding the Mirai Botnet ▪︎ Zane Ma 15
Roadmap 1. Growth & Composition 2. Ownership & Evolution 3. Attacks 4. Lessons Learned Understanding the Mirai Botnet ▪︎ Zane Ma 16
Ownership Cluster 0 Cluster 2 • Extract C2 domains from binaries Cluster 6 proht.us gettwrrnty.us nextorrent.net elyricsworld.com boost-factory.com kedbuffigfjs.online nuvomarine.com emp3world.com avac.io bklan.ru rippr.club alcvid.com kciap.pw xex-pass.com clearsignal.com strongconnection.cc tr069.support mwcluster.com xpknpxmywqsrhe.online xf0.pw dibamovie.site pontobreventos.com.br investor-review.com anabolika.bz ip-51-255-103.eu dmim.ir diamondhax.com ip-137-74-49.eu binpt.pw elektro-engel.de srrys.pw controluz.com.br drogamedic.com.br voxility.net angoshtarkhatam.ir mziep.pw expertscompany.com youporn.wf piratetorrents.net nfoservers.com moreoverus.com voxility.com voxility.org postrader.eu 2ws.com.br dibamovie.biz novotele.online soplya.com tr069.online 2world.com.br robositer.com voxility.mobi voxility.ro postrader.it geroncioribeiro.com as62454.net sistematitanium.com • Find coinciding C2s through siterhunter.com gideonneto.com zugzwang.me postrader.org woodpallet.com.br jgop.org sipa.be aodxhb.ru bitnodes.io mehinso.ru myfootbalgamestoday.xyz dyndn-web.com mufoscam.org escolavitoria.com.br nrzkobn.ru bluematt.me acessando.com.br pontobreventos.com checkforupdates.online zogrm.ru qlrzb.ru sillycatmouth.us hyrokumata.com stt-spb.ru shokwave.ru infoyarsk.ru bitcoinstats.com txocxs.ru domisto.ru polycracks.com zosjoupf.ru active and passive DNS data 5153030.ru kernelorg.download fastgg.net mediaforetak.com absentvodka.com daf-razbor.ru lottobooker.ru dom-italia39.ru alexandramoore.co.uk eduk-central.net analianus.com firstclaz-shop.ru kiditema.ru hightechcrime.club greenkittensdeal.pw ta-bao.com rutrax.ru intervideo.online cheapestdogspecials.win tr069.pw securityupdates.us dardiwaterjet.ru pornopokrovitel.ru intervideo.top childrens-health.ru 33kittensspecials.pw greenbirdsspecials.win wwrf.ru yellowpetsspecials.pw kia-moskva.ru findcatspecial.win timeserver.host ocalhost.host dolgoprud.top bluepuppyspecial.pw infonta.ru 33puppiesspecials.win avtotyn.ru food-syst.ru xn--b1acdqjrfck3b7e.xn--p1ai bluepuppiesdeals.pw upfarm.ru cheapestdogspecial.pw sony-s.ru yellowcatdeal.win xn----7sbhguokj.xn--p1ai udalenievmiatin.ru favy.club admin-vk.ru kopernick.ru avtoatelie-at.ru sert-cgb.ru video-girle.ru greendoggyspecial.pw yellowpuppyspecial.pw xn--80aac5cct.xn--80aswg kvartplata1.ru transfer.club kinosibay.ru findbirdsspecials.pw videostrannik.ru finddogdeal.win lr-top.ru jealousyworld.ru 33catspecials.pw infobusiness-eto-prosto.ru osinniki-tatu.ru 70,000 tomlive.ru gam-mon.ru 33catsdeal.pw taylor-lautner.ru bocciatime.ru cheapkittensspecial.win Cluster ID sims-4.ru alexander-block.ru cheapestdoggyspecial.pw party-bar66.ru aaliya.ru general-city.ru 60,000 agrohim33.ru 1 7 hotelkhiva.ru wapud.ru Daily C2 DNS Lookups Cluster 23 igm-shop.ru poliklinikasp.ru 2 11 receptprigotovlenia.ru 5d-xsite-cinema.ru pavelsigal.ru 50,000 vkladpodprocenti.ru 6 13 svoibuhgalter.ru 4 15 69speak.eu titata.ru ip-149-202-144.eu mp3impulse.ru 40,000 5 24 bebux.net dopegame.ru sl22.ru gramtu.pl madlamhockeyleague.com russianpotatoes.ru semazen.com.tr 3200138.com disabled.racing e3ybt.top q5f2k0evy7go2rax9m4g.ru 30,000 occurelay.net secure-limited-accounts.com hexacooperation.com dopegame.su ipeb.biz icmp.online germanfernandez.cl dumpsterrentalwestpalmbeachfl.... blockquadrat.de netwxrk.org protopal.club servdiscount-customer.com 20,000 middlechildink.com rencontreadopoursitedetours.xyz critical-damage.org ip-151-80-27.eu lateto.work kentalmanis.info layerjet.com zeldalife.com addsow.top serverhost.name doki.co 6969max.com edhelppro.bid chiviti.com nerafashion.com 10,000 brendasaviationplans.xyz kunathemes.com secure-support.services secure-payment.online happy-hack.ru zvezdogram.com cloudtechaz.net my2016mobileapplications.tech Cluster 7 ok6666.net playkenogamesonline.com grotekleinekerkstraat.nl 0 centurystyleantiques.com thqaf.com topdealdiscounted.online 09/01/16 10/01/16 11/01/16 12/01/16 01/01/17 megadealsfinder.online thcrcz.top megadealsdiscounter.online realsaunasuit.com stbenedictschoolbx.org bigdealsfinder.online kcgraphics.co.uk Date superpriceshopping.online Cluster 1 starpricediscounted.online santasbigcandycane.cx bestsavingfinder.online boatnetswootnet.xyz superpriceshopper.online greatdealninja.online bestpricecastle.online skinplat.ru skincoin24.ru smsall.pk steamon.ru amgauto.vn joomlavision.com gowars.ru gameshoper.ru tradewallet.ru irisstudio.vn steamcoin24.ru dacsanthitchua.com keygolds.ru herokids.vn ngot.net keyzet.ru teamcoin.ru ssldomainerrordisp2003.com ousquadrant.com tradewallet24.ru tamthat.com namlimxanh.net.vn spevat.net apkmarket.mobi keycoins.ru skincoin.ru kleverfood.vn muplay.ru keydealer.ru walletzone.ru gamegolds.ru playerstore.ru gamewallet.ru Understanding the Mirai Botnet ▪︎ Zane Ma 17
Recommend
More recommend