s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-MAL-elf.moobot

📛 Threat Title

Malware family: MooBot

Category: MooBot First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.moobot`. Printable name: MooBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.moobot VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.moobot

IOC database

Type
domain
Value
elf.moobot
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.moobot

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.moobot

References (1)

Remediations (10)

  • web:arxiv.org

    Moobot is another recent variant of Mirai that utilizes five vulnerabilities, two of which Satori also used in its exploits in 2017 (see Table III). Moobot was first seen in 2019 by the Network Security Research Lab at 360 (360Netlab) [62], and its main targets are Docker APIs, Small Office Home Office (SOHO) devices, fiber routers, and IoT ...

  • web:echoxec.com

    Mirai Malware in 2025: Variant Behavior, Exploit Chains, and Mitigation Insights This post explores the latest Mirai botnet variants actively exploiting critical vulnerabilities in Samsung MagicINFO, DVR devices, and Wazuh servers. It highlights key behaviors observed through sandbox analysis, exploitation techniques, and provides actionable recommendations to defend against these evolving ...

  • web:media.defense.gov

    National Security Agency (NSA), US Cyber Command, and international partners are releasing this joint Cybersecurity Advisory (CSA) to warn of Russian state-sponsored cyber actors' use of compromised Ubiquiti EdgeRouters (EdgeRouters) to facilitate malicious cyber operations worldwide.

  • web:nsarchive.gwu.edu

    This botnet was distinct from prior GRU and Russian Federal Security Service (FSB) malware networks disrupted by the Department in that the GRU did not create it from scratch. Instead, the GRU relied on the " Moobot " malware , which is associated with a known criminal group. Non-GRU cybercriminals installed the Moobot malware on Ubiquiti Edge OS routers that still used publicly known default ...

  • web:securityaffairs.com

    The operation reversibly modified the routers' firewall rules to block remote management access to the devices. "The Department's court-authorized operation leveraged the Moobot malware to copy and delete stolen and malicious data and files from compromised routers." continues the press release.

  • web:www.bleepingcomputer.com

    The Mirai malware botnet variant known as 'MooBot' has re-emerged in a new attack wave that started early last month, targeting vulnerable D-Link routers with a mix of old and new exploits. Bill ...

  • web:www.fortinet.com

    FortiGuard Labs examined several attacks targeting Cacti and Realtek vulnerabilities. Understand the payloads of these attacks and their resulting behavior of spreading ShellBot and Moobot malware .

  • web:www.quorumcyber.com

    Mirai is a botnet malware variant that compromises smart devices that operate on ARC processors, the aim of which is to formulate a network of bot machines to carry out distributed denial-of-service (DDoS) attacks1.

  • web:www.sciencedirect.com

    Ceron et al. developed adaptive network layer techniques to improve the investigation and mitigation of IoT botnets, including the use of Mirai signatures to improve detection and response mechanisms. The network behavior of both Mirai and Bashlite samples was analyzed and scanned for botnet signature over a 24-hour period [88].

  • web:www.semanticscholar.org

    This article summarizes the common vulnerabilities targeted by these variants and analyzes the infection mechanism through vulnerability analysis and provides an overview of possible defense solutions. Mirai is undoubtedly one of the most significant Internet of Things (IoT) botnet attacks in history. In terms of its detrimental effects, seamless spread, and low detection rate, it surpassed ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.