Mirai Botnet Telnet Default Credential Propagation Scan
This rule monitors network traffic over the Telnet protocol (TCP port 23) for patterns indicative of Mirai botnet propagation. It identifies sequences of characters commonly used in Mirai brute-force attempts to guess default credentials (e.g., 'admin' followed by 'password'). The rule utilizes a threshold-based detection filter to trigger only when multiple such attempts are observed from a single source within a 60-second window, helping to filter out individual noise and focus on active scanning behavior.
Suricata

