s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.masuta

📛 Threat Title

Malware family: Masuta

Category: Masuta First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.masuta`. Printable name: Masuta. Aliases: PureMasuta.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.masuta VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.masuta

IOC database

Type
domain
Value
elf.masuta
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.masuta

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.masuta

References (1)

Remediations (10)

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:en.wikipedia.org

    Mirai (from the Japanese word for "future", 未来) is malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks. It primarily targets online consumer devices such as IP cameras and home routers. [1] The Mirai botnet was first found in August 2016 [2] by MalwareMustDie, [3] a white hat malware research ...

  • web:fastnetmon.com

    Second, the Mirai source code was leaked online, providing cybercriminals with a codebase on which to build and refine their own malware . Mirai code and techniques are believed to have inspired more recent botnet variants including the Okiru, the Satori, the Masuta and the PureMasuta. In many ways, Mirai has shown the future of DDoS attacks.

  • web:geekflare.com

    How Mirai Was Created The Mirai malware was written by Paras Jha and Josiah White, who at the time were students in their early 20s and also the founders of ProTraf Solutions, a company that offered DDOS mitigation services. Mirai Malware was written using C and Go programming languages.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.cisecurity.org

    IoT devices built for convenience over security complicate mitigation efforts for the Mirai malware family . Mirai Technical Details Mirai starts as a self-propagating worm (T0866 [5]) replicating itself once it infects and locates another vulnerable IoT device [3].

  • web:www.cybersecurity-review.com

    Researchers at NewSky Security say the hacker behind a Mirai malware variant called Satori, also known as Mirai Okiru, is the same hacker behind two new Mirai variants called Masuta and PureMasuta. Based on source code for Masuta malware recently found on the dark web, researchers at NewSky Security said they were able to connect the ...

  • web:www.quorumcyber.com

    Mirai is a botnet malware variant that compromises smart devices that operate on ARC processors, the aim of which is to formulate a network of bot machines to carry out distributed denial-of-service (DDoS) attacks1.

  • web:www.sciencedirect.com

    PureMasuta, an advanced variation of Masuta , reuses common Mirai-style code, and includes a list of weak credentials to exploit. The main distinctive feature of PureMasuta is its use of the EDB 38722 D-Link vulnerability [53]. The OMG variant of Mirai converts an IoT device in a proxy server for cybercriminals that mine cryptocurrencies.

  • web:www.securityweek.com

    Vulnerabilities Mirai-Based Masuta Botnet Weaponizes Old Router Vulnerability A new Internet of Things-targeting piece of malware based on Mirai's publicly released source code has been observed at large, ensnaring devices into a botnet.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.