s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.iz1h9

📛 Threat Title

Malware family: IZ1H9

Category: IZ1H9 First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.iz1h9`. Printable name: IZ1H9.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:blog.netmanageit.com

    Description In September 2023, our FortiGuard Labs team observed that the IZ1H9 Mirai-based DDoS campaign has aggressively updated its arsenal of exploits. Thirteen payloads were included in this variant, including D-Link devices, Netis wireless router, Sunhillo SureLine, Geutebruck IP camera, Yealink Device Management, Zyxel devices, TP-Link Archer, Korenix Jetwave, and TOTOLINK routers.

  • web:securityaffairs.com

    A Mirai-based DDoS botnet tracked as IZ1H9 has added thirteen new exploits to target routers from different vendors.

  • web:therecord.media

    A Mirai-based malware botnet has expanded its payload arsenal to aggressively target routers and other internet-facing devices, researchers have discovered. The variant, called IZ1H9 , was observed by researchers at Fortinet exploiting vulnerabilities in products from nine different brands, including ...

  • web:unit42.paloaltonetworks.com

    We analyze Mirai variant IZ1H9 , which targets IoT devices. Our overview includes campaigns observed, botnet configuration and vulnerabilities exploited.

  • web:www.broadcom.com

    Mirai variant known as IZ1H9 has updated its portfolio of exploited IoT vulnerabilities. The malware currently targets miscellaneous devices including D-Link and Netis routers, Sunhillo SureLine, Geutebruck IP cameras, Zyxel devices, TP-Link Archer, Korenix Jetwave wireless AP, TOTOLINK routers, and others. Upon infection with IZ1H9 , the vulnerable devices become part of the botnet, allow the ...

  • web:www.cybersecurity-review.com

    In September 2023, our FortiGuard Labs team observed that the IZ1H9 Mirai-based DDoS campaign has aggressively updated its arsenal of exploits. Thirteen payloads were included in this variant, including D-Link devices, Netis wireless router, Sunhillo SureLine, Geutebruck IP camera, Yealink Device Management, Zyxel devices, TP-Link Archer ...

  • web:www.fortinet.com

    Malware Analysis - IZ1H9 IZ1H9 , a Mirai variant, infects Linux-based networked devices, especially IoT devices, turning them into remote-controlled bots for large-scale network attacks. The XOR key to decode configuration is 0xBAADF00D, shown in Figure 10.

  • web:www.infosecurity-magazine.com

    Dubbed IZ1H9 , this variant was first discovered in August 2018 and has since become one of the most active Mirai variants. Unit 42 researchers observed on April 10 that a wave of malicious campaigns, all deployed by the same threat actor, have been using IZ1H9 since November 2021. They published a malware analysis on May 25.

  • web:www.securityweek.com

    Malware & Threats Mirai Variant IZ1H9 Adds 13 Exploits to Arsenal A Mirai botnet variant tracked as IZ1H9 has updated its arsenal with 13 exploits targeting various routers, IP cameras, and other IoT devices.

  • web:www.techradar.com

    A version of Mirai, called IZ1H9 , has become the dominant variant of the dreaded botnet, infecting countless Linux devices and using them for different nefarious purposes.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.