Collecting and operationalizing threat data from the Mozi botnet
ID: 1d7fab17-e681-5512-8fab-13d50f3f5df2
STIX ID: report--1d7fab17-e681-5512-8fab-13d50f3f5df2
Feed Name: Elastic Security Labs
This report analyzes the Mozi peer-to-peer IoT botnet: how samples were collected from ThreatFox and Malware Bazaar, how corrupted UPX-packed ARM ELF samples were repaired and unpacked, and which indicators and TTPs were extracted (network IOCs, ip:port, iptables changes, HTTP fingerprint). It demonstrates ingestion and enrichment into the Elastic Stack for visualization and hunting, provides a YARA rule to detect the UPX header zeroing obfuscation, describes propagation fingerprints useful for discovery (HTTP response headers), and gives mitigation advice (change default credentials, patch firmware, segment and limit Internet exposure).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
