TF-MAL-elf.moobot
📛 Threat Title
Malware family: MooBot
Description
ThreatFox malware family `elf.moobot`. Printable name: MooBot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.moobot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.moobot
IOC database
- Type
- domain
- Value
elf.moobot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.moobot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.moobot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:arxiv.org
Moobot is another recent variant of Mirai that utilizes five vulnerabilities, two of which Satori also used in its exploits in 2017 (see Table III). Moobot was first seen in 2019 by the Network Security Research Lab at 360 (360Netlab) [62], and its main targets are Docker APIs, Small Office Home Office (SOHO) devices, fiber routers, and IoT ...
-
web:echoxec.com
Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...
-
web:media.defense.gov
National Security Agency (NSA), US Cyber Command, and international partners are releasing this joint Cybersecurity Advisory (CSA) to warn of Russian state-sponsored cyber actors' use of compromised Ubiquiti EdgeRouters (EdgeRouters) to facilitate malicious cyber operations worldwide.
-
web:nsarchive.gwu.edu
This botnet was distinct from prior GRU and Russian Federal Security Service (FSB) malware networks disrupted by the Department in that the GRU did not create it from scratch. Instead, the GRU relied on the " Moobot " malware , which is associated with a known criminal group. Non-GRU cybercriminals installed the Moobot malware on Ubiquiti Edge OS routers that still used publicly known default ...
-
web:securityaffairs.com
The operation reversibly modified the routers' firewall rules to block remote management access to the devices. "The Department's court-authorized operation leveraged the Moobot malware to copy and delete stolen and malicious data and files from compromised routers." continues the press release.
-
web:www.bleepingcomputer.com
The Mirai malware botnet variant known as 'MooBot' has re-emerged in a new attack wave that started early last month, targeting vulnerable D-Link routers with a mix of old and new exploits. Bill ...
-
web:www.fortinet.com
FortiGuard Labs examined several attacks targeting Cacti and Realtek vulnerabilities. Understand the payloads of these attacks and their resulting behavior of spreading ShellBot and Moobot malware .
-
web:www.quorumcyber.com
Mirai is a botnet malware variant that compromises smart devices that operate on ARC processors, the aim of which is to formulate a network of bot machines to carry out distributed denial-of-service (DDoS) attacks1.
-
web:www.sciencedirect.com
Ceron et al. developed adaptive network layer techniques to improve the investigation and mitigation of IoT botnets, including the use of Mirai signatures to improve detection and response mechanisms. The network behavior of both Mirai and Bashlite samples was analyzed and scanned for botnet signature over a 24-hour period [88].
-
web:www.semanticscholar.org
This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.