logo

Recent vulnerability in Eir D1000 Router used to spread updated version of Mirai DDoS bot

ID: e5adfe4e-e740-56a6-b9c0-9a5d17d447f2

STIX ID: report--e5adfe4e-e740-56a6-b9c0-9a5d17d447f2

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2016-11-28

Date Updated: 2026-04-27

...
...

Fox-IT observed a Mirai botnet variant that propagates by abusing a TR-069 SOAP Remote Code Execution (SetNTPServers) vulnerability on consumer modems: attackers supply BusyBox commands in the NTP server field to wget a payload, chmod it, and execute it. The report includes the HTTP POST request example, payload hashes (MIPS/ARM), malicious hostnames and IPs seen in honeypots, Snort IDS rules to detect exploitation attempts, mitigation recommendations for ISPs and users, and context on prior Mirai attacks and botnet scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.