#moobot search results

🚨🍯 CVE-2023-1389: Unauthenticated Command Injection on TP-Link Archer AX21 leads to #MooBot (Mirai DDoS variant). Attacker: 172.104.228.72 🇩🇪 Path: POST /cgi-bin/luci/;stok=/locale?form=country Payload: hxxp://91.92.249.96/condi/bot.x86_64 C2: 91.92.249.96 [+]…

1ZRR4H's tweet image. 🚨🍯 CVE-2023-1389: Unauthenticated Command Injection on TP-Link Archer AX21 leads to #MooBot (Mirai DDoS variant).

Attacker: 172.104.228.72 🇩🇪
Path: POST /cgi-bin/luci/;stok=/locale?form=country
Payload: hxxp://91.92.249.96/condi/bot.x86_64
C2: 91.92.249.96

[+]…

The #FSB of Russia was attacked by #moobot #Botnet with #DDoS method #tcp_ack_flood Attack time: 2023-09-18 20:50:29(UTC+8) Target IP: 213[.24.76.23 Related domain names: - www[.fsb.ru - fsb[.gov.ru moobot C2: dd[.gaybooba.cc:55552

RedDrip7's tweet image. The #FSB of Russia was attacked by #moobot #Botnet with #DDoS method #tcp_ack_flood
Attack time: 2023-09-18 20:50:29(UTC+8)
Target IP: 213[.24.76.23
Related domain names:
- www[.fsb.ru
- fsb[.gov.ru

moobot C2: dd[.gaybooba.cc:55552

#moobot c2's found through @fofabot i am keeping the query for now ''secret''. Fofa has found over time 79 #moobot c2's. Through another query 42 unique ips observed that indicate moobot also.

banthisguy9349's tweet image. #moobot c2's found through @fofabot i am keeping the query for now ''secret''.

Fofa has found over time 79 #moobot c2's.

Through another query 42 unique ips observed that indicate moobot also.
banthisguy9349's tweet image. #moobot c2's found through @fofabot i am keeping the query for now ''secret''.

Fofa has found over time 79 #moobot c2's.

Through another query 42 unique ips observed that indicate moobot also.

Nice #MooBot botnet caught by @banthisguy9349 😂 Botnet C2 domain: 🔥 putin.zelenskyj .ru Pointing to: 45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪) DNS resolution provided by Cloudflare 🔎 Payload URLs: 🌐 urlhaus.abuse.ch/host/45.88.90.… Payload: 📄 bazaar.abuse.ch/sample/21f1caa…

abuse_ch's tweet image. Nice #MooBot botnet caught by @banthisguy9349 😂

Botnet C2 domain:
🔥 putin.zelenskyj .ru

Pointing to:
45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪)

DNS resolution provided by Cloudflare 🔎

Payload URLs:
🌐 urlhaus.abuse.ch/host/45.88.90.…

Payload:
📄 bazaar.abuse.ch/sample/21f1caa…

the following ips still have not been taken down by PFCLOUD AS 51396 87.121.58.103:6666 #moobot c2 87.121.58.103:32105 #mirai c2 84.54.51.103:6666 #moobot c2 84.54.51.103:32105 #mirai c2 IOC: nekololis[.ovh 87.121.58.103 84.54.51.103 #nekobotnet

banthisguy9349's tweet image. the following ips still have not been taken down by PFCLOUD AS 51396

87.121.58.103:6666 #moobot c2
87.121.58.103:32105 #mirai c2
84.54.51.103:6666 #moobot c2
84.54.51.103:32105 #mirai c2

IOC: 
nekololis[.ovh
87.121.58.103
84.54.51.103

#nekobotnet
banthisguy9349's tweet image. the following ips still have not been taken down by PFCLOUD AS 51396

87.121.58.103:6666 #moobot c2
87.121.58.103:32105 #mirai c2
84.54.51.103:6666 #moobot c2
84.54.51.103:32105 #mirai c2

IOC: 
nekololis[.ovh
87.121.58.103
84.54.51.103

#nekobotnet

#moobot domain heleh[.]vn advertises their #botnet stresser.heleh[.]vn urlhaus.abuse.ch/host/proxy.hel… malware was observed for a very long time urlhaus.abuse.ch/host/103.174.7… t[.me/bolongyn github[.com/BoloNgyn G-mail: [email protected]

banthisguy9349's tweet image. #moobot domain heleh[.]vn advertises their #botnet 
stresser.heleh[.]vn

urlhaus.abuse.ch/host/proxy.hel… malware was observed for a very long time 
urlhaus.abuse.ch/host/103.174.7…

t[.me/bolongyn
github[.com/BoloNgyn
G-mail: support@heleh.vn
banthisguy9349's tweet image. #moobot domain heleh[.]vn advertises their #botnet 
stresser.heleh[.]vn

urlhaus.abuse.ch/host/proxy.hel… malware was observed for a very long time 
urlhaus.abuse.ch/host/103.174.7…

t[.me/bolongyn
github[.com/BoloNgyn
G-mail: support@heleh.vn

\ますます旅行が楽しくなる😊/ #moobot から電動アシスト機能付き #スーツケース が登場🎊 自動アシスト機能で坂道も楽々♪ 360度回転の静音キャスターで移動も静かでスムーズ😍 ポリカーボネート素材で耐衝撃性も抜群👍 ぜひ店頭でお試しください💁 ➡️yodobashi.com/product/100000…


Two more active threats in March-April 2023 are #Batloader, a #malware dropper that downloads and executes other malware, and the #Moobot #botnet which can be used for distributed denial-of-service (DDoS) attacks. #cybersecurity #threatintelligence #ciso #IoT

rst_cloud's tweet image. Two more active threats in March-April 2023 are #Batloader, a #malware dropper that downloads and executes other malware, and the #Moobot #botnet which can be used for distributed denial-of-service (DDoS) attacks.
#cybersecurity #threatintelligence #ciso #IoT
rst_cloud's tweet image. Two more active threats in March-April 2023 are #Batloader, a #malware dropper that downloads and executes other malware, and the #Moobot #botnet which can be used for distributed denial-of-service (DDoS) attacks.
#cybersecurity #threatintelligence #ciso #IoT

The ip 103.172.79.74:43957 keeps being used as #moobot #c2 Although me with some other Security Researcher are able to retrack the new malware samples. Vietnamese language have been observed in one of the script files urlhaus.abuse.ch/host/103.172.7…

banthisguy9349's tweet image. The ip 103.172.79.74:43957  keeps being used as #moobot #c2 
Although me with some other Security Researcher are able to retrack the new malware samples.

Vietnamese language have been observed in one of the script files

urlhaus.abuse.ch/host/103.172.7…
banthisguy9349's tweet image. The ip 103.172.79.74:43957  keeps being used as #moobot #c2 
Although me with some other Security Researcher are able to retrack the new malware samples.

Vietnamese language have been observed in one of the script files

urlhaus.abuse.ch/host/103.172.7…
banthisguy9349's tweet image. The ip 103.172.79.74:43957  keeps being used as #moobot #c2 
Although me with some other Security Researcher are able to retrack the new malware samples.

Vietnamese language have been observed in one of the script files

urlhaus.abuse.ch/host/103.172.7…

found through: 159.223.196.192 bot.layer4[.]bf botnet.layer4[.]bf hiyl7.hilariocolche[.]com found through: 103.172.79.74 bonet.networkbn[.]com Found through: 91.92.240.138 botnet.networkbotbet[.]top networkbotbet[.]top botnet.serveblog[.]net

banthisguy9349's tweet image. found through: 159.223.196.192
bot.layer4[.]bf
botnet.layer4[.]bf
hiyl7.hilariocolche[.]com

found through: 103.172.79.74
bonet.networkbn[.]com

Found through: 91.92.240.138
botnet.networkbotbet[.]top
networkbotbet[.]top
botnet.serveblog[.]net


#new #moobot #domain found domain registrated with @Namecheap virustotal.com/gui/file/21b4a… IP Traffic TCP 103.14.226.21:43957 (c2) urlhaus.abuse.ch/host/103.14.22… sro3ga[.]net

banthisguy9349's tweet image. #new #moobot #domain found domain registrated with @Namecheap 

virustotal.com/gui/file/21b4a…

IP Traffic
TCP 103.14.226.21:43957 (c2) urlhaus.abuse.ch/host/103.14.22…
sro3ga[.]net

#US Gov dismantled the #Moobot #botnet controlled by #Russia-linked #APT28 vapt.me/MooB0t

omvapt's tweet image. #US Gov dismantled the #Moobot #botnet controlled by #Russia-linked #APT28 
vapt.me/MooB0t

Routers Under Attack: Protect Your Business from State-Sponsored Espionage! The Situation: 🔴Pawn Storm, the APT group, hacked hundreds of #SOHO routers using the "Moobot" malware. 1/5 #Moobot #Router #APT28 #PawnStorm #GRU #Malware #APT


#MOOBOT C2's IOC's: 5.59.248.206:56744 c2 urlhaus.abuse.ch/host/5.59.248.… 45.156.21.122:8967 c2 still active, malware urls down urlhaus.abuse.ch/host/45.156.21… 209.141.37.216:3074 c2 185.196.9.5:51237 c2 IOC's


This is what a real botnet looks like #miraibotnet #fbot #moobot #botnet #iot #malware #ddos

armv7l's tweet image. This is what a real botnet looks like #miraibotnet #fbot #moobot #botnet #iot #malware #ddos

電動アシストスーツケース届いた。アシスト機能のスピード調整ないなで、押されて転んだり引きずられそうなスピードなんやが、路上で荷物入れたらちょうど良くなるのかな…クラファンなので届いただけで100点。 #moobot

terurium_chu's tweet image. 電動アシストスーツケース届いた。アシスト機能のスピード調整ないなで、押されて転んだり引きずられそうなスピードなんやが、路上で荷物入れたらちょうど良くなるのかな…クラファンなので届いただけで100点。
#moobot

Why don't cows have phones? Because they can't find the right "moobile" plan! 😂 Keep smiling, friends! Remember, laughter is the "moo-sic" of the soul! 🐄💫 #CowJokes #LaughMore #MooBot


Why did the cow become a detective? Because it heard moo-rmurs of a missing glass of milk! 🐮🥛 Remember, laughter is the cream of life! #CowJokes #MooBot


Why did the cow start a Twitter account? To moo-tivate others with udderly amazing puns! 🐄🤣 Got milk? More like, got laughs! #MooBot #MilkyJokes #CowMedy


Just got my cow-culator and did the math: laughter is the best medicine, and every day is a moo-tivation to share smiles! 🐮😂 #MooBot #MooMents #UdderlyHappy


#MooBot/Mirai variant trying to exploit CVE-2017-17215, you can tell from the TCP connections bazaar.abuse.ch/browse/tag/CVE… urlhaus.abuse.ch/browse/tag/CVE…

NDA0E's tweet image. #MooBot/Mirai variant trying to exploit CVE-2017-17215, you can tell from the TCP connections

bazaar.abuse.ch/browse/tag/CVE…
urlhaus.abuse.ch/browse/tag/CVE…

#MOOBOT C2's IOC's: 5.59.248.206:56744 c2 urlhaus.abuse.ch/host/5.59.248.… 45.156.21.122:8967 c2 still active, malware urls down urlhaus.abuse.ch/host/45.156.21… 209.141.37.216:3074 c2 185.196.9.5:51237 c2 IOC's


new #moobot #botnet #c2 spotted on 157.230.250.250:42597 with @digitalocean


#moobot c2's that are currently discovered through @censysio 45.128.232.90:43957 146.59.3.38:43957 103.116.52.207:42597 209.141.37.216:3074 82.197.68.240:43957 cc: @500mk500


Investigation suggest IPs are on loan to Chang Tiantang, Shui Hao, Shu Weijun, Peng Zhaoli, and Tang Weiming 🇨🇳 Recent reports by @abuse_ch @thehappydinoa and @malpulse show a pattern of increased #C2 hosting on 137.175.0[.]0/17 🤔 #XorDDoS #MooBot #CobaltStrike cc @raksmart


#new #moobot #domain found domain registrated with @Namecheap virustotal.com/gui/file/21b4a… IP Traffic TCP 103.14.226.21:43957 (c2) urlhaus.abuse.ch/host/103.14.22… sro3ga[.]net

banthisguy9349's tweet image. #new #moobot #domain found domain registrated with @Namecheap 

virustotal.com/gui/file/21b4a…

IP Traffic
TCP 103.14.226.21:43957 (c2) urlhaus.abuse.ch/host/103.14.22…
sro3ga[.]net

#moobot domain heleh[.]vn advertises their #botnet stresser.heleh[.]vn urlhaus.abuse.ch/host/proxy.hel… malware was observed for a very long time urlhaus.abuse.ch/host/103.174.7… t[.me/bolongyn github[.com/BoloNgyn G-mail: [email protected]

banthisguy9349's tweet image. #moobot domain heleh[.]vn advertises their #botnet 
stresser.heleh[.]vn

urlhaus.abuse.ch/host/proxy.hel… malware was observed for a very long time 
urlhaus.abuse.ch/host/103.174.7…

t[.me/bolongyn
github[.com/BoloNgyn
G-mail: support@heleh.vn
banthisguy9349's tweet image. #moobot domain heleh[.]vn advertises their #botnet 
stresser.heleh[.]vn

urlhaus.abuse.ch/host/proxy.hel… malware was observed for a very long time 
urlhaus.abuse.ch/host/103.174.7…

t[.me/bolongyn
github[.com/BoloNgyn
G-mail: support@heleh.vn

#moobot c2's found through @fofabot i am keeping the query for now ''secret''. Fofa has found over time 79 #moobot c2's. Through another query 42 unique ips observed that indicate moobot also.

banthisguy9349's tweet image. #moobot c2's found through @fofabot i am keeping the query for now ''secret''.

Fofa has found over time 79 #moobot c2's.

Through another query 42 unique ips observed that indicate moobot also.
banthisguy9349's tweet image. #moobot c2's found through @fofabot i am keeping the query for now ''secret''.

Fofa has found over time 79 #moobot c2's.

Through another query 42 unique ips observed that indicate moobot also.

@abuse_ch community has caught a 🐮#MooBot botnet! Payload delivery URLs, malware sample, and botnet C&C server details below 👇

Nice #MooBot botnet caught by @banthisguy9349 😂 Botnet C2 domain: 🔥 putin.zelenskyj .ru Pointing to: 45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪) DNS resolution provided by Cloudflare 🔎 Payload URLs: 🌐 urlhaus.abuse.ch/host/45.88.90.… Payload: 📄 bazaar.abuse.ch/sample/21f1caa…

abuse_ch's tweet image. Nice #MooBot botnet caught by @banthisguy9349 😂

Botnet C2 domain:
🔥 putin.zelenskyj .ru

Pointing to:
45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪)

DNS resolution provided by Cloudflare 🔎

Payload URLs:
🌐 urlhaus.abuse.ch/host/45.88.90.…

Payload:
📄 bazaar.abuse.ch/sample/21f1caa…


@abuse_ch community has caught a 🐮#MooBot botnet - nice work @banthisguy9349! Payload delivery URLs, malware sample, and botnet C&C server details below 👇

Nice #MooBot botnet caught by @banthisguy9349 😂 Botnet C2 domain: 🔥 putin.zelenskyj .ru Pointing to: 45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪) DNS resolution provided by Cloudflare 🔎 Payload URLs: 🌐 urlhaus.abuse.ch/host/45.88.90.… Payload: 📄 bazaar.abuse.ch/sample/21f1caa…

abuse_ch's tweet image. Nice #MooBot botnet caught by @banthisguy9349 😂

Botnet C2 domain:
🔥 putin.zelenskyj .ru

Pointing to:
45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪)

DNS resolution provided by Cloudflare 🔎

Payload URLs:
🌐 urlhaus.abuse.ch/host/45.88.90.…

Payload:
📄 bazaar.abuse.ch/sample/21f1caa…


abuse.ch community has caught a variant of #Mirai botnet known as #MooBot 🐮 infecting IoT devices around the world - find out more here ⬇️

Nice #MooBot botnet caught by @banthisguy9349 😂 Botnet C2 domain: 🔥 putin.zelenskyj .ru Pointing to: 45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪) DNS resolution provided by Cloudflare 🔎 Payload URLs: 🌐 urlhaus.abuse.ch/host/45.88.90.… Payload: 📄 bazaar.abuse.ch/sample/21f1caa…

abuse_ch's tweet image. Nice #MooBot botnet caught by @banthisguy9349 😂

Botnet C2 domain:
🔥 putin.zelenskyj .ru

Pointing to:
45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪)

DNS resolution provided by Cloudflare 🔎

Payload URLs:
🌐 urlhaus.abuse.ch/host/45.88.90.…

Payload:
📄 bazaar.abuse.ch/sample/21f1caa…


Nice #MooBot botnet caught by @banthisguy9349 😂 Botnet C2 domain: 🔥 putin.zelenskyj .ru Pointing to: 45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪) DNS resolution provided by Cloudflare 🔎 Payload URLs: 🌐 urlhaus.abuse.ch/host/45.88.90.… Payload: 📄 bazaar.abuse.ch/sample/21f1caa…

abuse_ch's tweet image. Nice #MooBot botnet caught by @banthisguy9349 😂

Botnet C2 domain:
🔥 putin.zelenskyj .ru

Pointing to:
45.88.90.30:43957 (AS203168 Constant MOULIN 🇧🇪)

DNS resolution provided by Cloudflare 🔎

Payload URLs:
🌐 urlhaus.abuse.ch/host/45.88.90.…

Payload:
📄 bazaar.abuse.ch/sample/21f1caa…

Preparo #nightbot e #moobot per la live di stasera <3

MadCrossinEyes's tweet image. Preparo #nightbot e #moobot per la live di stasera &amp;lt;3

When it's only you and #moobot in the #twitch chat 😭😭😭😭

JackLogistical's tweet image. When it&apos;s only you and #moobot in the #twitch chat 😭😭😭😭

#moobot on 103.180.149.83 that redirects to

banthisguy9349's tweet image. #moobot on 103.180.149.83

that redirects to
banthisguy9349's tweet image. #moobot on 103.180.149.83

that redirects to

#moobot c2 84.54.51.103:6666 87.121.58.103:6666 #mirai 84.54.51.103:32105 87.121.58.103:32105 IOC: nekololis[.]ovh Hosted on PFcloud[.]io Abuse reports are not being handled by pfcloud. hxxps://t.me/nekobotnet

banthisguy9349's tweet image. #moobot c2 
84.54.51.103:6666
87.121.58.103:6666

#mirai 
84.54.51.103:32105
87.121.58.103:32105

IOC: nekololis[.]ovh
Hosted on PFcloud[.]io

Abuse reports are not being handled by pfcloud.

hxxps://t.me/nekobotnet
banthisguy9349's tweet image. #moobot c2 
84.54.51.103:6666
87.121.58.103:6666

#mirai 
84.54.51.103:32105
87.121.58.103:32105

IOC: nekololis[.]ovh
Hosted on PFcloud[.]io

Abuse reports are not being handled by pfcloud.

hxxps://t.me/nekobotnet
banthisguy9349's tweet image. #moobot c2 
84.54.51.103:6666
87.121.58.103:6666

#mirai 
84.54.51.103:32105
87.121.58.103:32105

IOC: nekololis[.]ovh
Hosted on PFcloud[.]io

Abuse reports are not being handled by pfcloud.

hxxps://t.me/nekobotnet

pulled this because #moobot loves me in @FIFAPETE stream

IanGraffunder's tweet image. pulled this because #moobot loves me in @FIFAPETE stream

Reworking commands in #moobot and improving my #SLOBS overlays got me like


Drew #moobot for #psystreams because????? Inspired by the few tacky farm lesbians I know

EvilBornie's tweet image. Drew #moobot for #psystreams because????? Inspired by the few tacky farm lesbians I know

#moobot #c2 on 42.96.2.220 Observed to use #mirai #malware hxxps://tria.ge/240211-gtq6gafe56 hxxps://www.virustotal.com/graph/http%3A%2F%2Fbotnet.networkbotbet.top%2F Redirect = fbi[.]gov hxxps://urlscan.io/result/f7c04df0-4fb1-419b-947d-cac124b69a0f/ found by @tolisec

banthisguy9349's tweet image. #moobot #c2 on 42.96.2.220 Observed to use #mirai #malware

hxxps://tria.ge/240211-gtq6gafe56
hxxps://www.virustotal.com/graph/http%3A%2F%2Fbotnet.networkbotbet.top%2F

Redirect = fbi[.]gov
hxxps://urlscan.io/result/f7c04df0-4fb1-419b-947d-cac124b69a0f/

found by @tolisec
banthisguy9349's tweet image. #moobot #c2 on 42.96.2.220 Observed to use #mirai #malware

hxxps://tria.ge/240211-gtq6gafe56
hxxps://www.virustotal.com/graph/http%3A%2F%2Fbotnet.networkbotbet.top%2F

Redirect = fbi[.]gov
hxxps://urlscan.io/result/f7c04df0-4fb1-419b-947d-cac124b69a0f/

found by @tolisec

Hair game: next level. 💙 #Twin1 #Moobot

Spendogg5's tweet image. Hair game: next level. 💙 #Twin1 #Moobot

#QOTD Do you use any bots when streaming? #Moobot #Nightbot

GLYFENation's tweet image. #QOTD Do you use any bots when streaming? #Moobot #Nightbot

Why @MoobotApp "Files" doesn't work? I'm trying open Files and I never get it. I can't configure it!Anyone help me? #moobot #moobotassistant

Elf4rw3N's tweet image. Why @MoobotApp &quot;Files&quot; doesn&apos;t work? I&apos;m trying open Files and I never get it. I can&apos;t configure it!Anyone help me? #moobot #moobotassistant

getting there with #moobot, just need to figure out how to giveaway this MISC Reliant tonight #StarCitizen #Twitch

SuperMacBrother's tweet image. getting there with #moobot, just need to figure out how to giveaway this MISC Reliant tonight #StarCitizen #Twitch

🚨🍯 CVE-2023-1389: Unauthenticated Command Injection on TP-Link Archer AX21 leads to #MooBot (Mirai DDoS variant). Attacker: 172.104.228.72 🇩🇪 Path: POST /cgi-bin/luci/;stok=/locale?form=country Payload: hxxp://91.92.249.96/condi/bot.x86_64 C2: 91.92.249.96 [+]…

1ZRR4H's tweet image. 🚨🍯 CVE-2023-1389: Unauthenticated Command Injection on TP-Link Archer AX21 leads to #MooBot (Mirai DDoS variant).

Attacker: 172.104.228.72 🇩🇪
Path: POST /cgi-bin/luci/;stok=/locale?form=country
Payload: hxxp://91.92.249.96/condi/bot.x86_64
C2: 91.92.249.96

[+]…

Just something random... #Moobot Moobot: "No LINKS allowed." Also Moobot: "hErE iS tHe LINK To..."

Creepimus's tweet image. Just something random... #Moobot

Moobot: &quot;No LINKS allowed.&quot;
Also Moobot: &quot;hErE iS tHe LINK To...&quot;

Loading...

Something went wrong.


Something went wrong.


United States Trends