Owari
Malware⚠️ Overview
Owari is a Linux-based DDoS botnet first documented by the security research group MalwareMustDie in August 2016 as a derivative of the Mirai source code. Operated by an unknown threat actor, it targets Internet-of-Things (IoT) devices such as routers, IP cameras, and other embedded systems, categorizing it as a DDoS botnet malware.
🔧 Technical Capabilities
Owari propagates by scanning for open Telnet (TCP/23) ports and performing brute-force authentication using a hardcoded list of 62 default factory credentials common on IoT devices. Once infected, it connects to a command-and-control (C2) server over a custom binary protocol, receiving attack instructions and reporting victim IPs. The botnet’s DDoS capabilities include multiple attack vectors: UDP flood, TCP SYN flood, TCP ACK flood, HTTP GET flood, and DNS amplification, often exceeding 10 Gbps in aggregate. Persistence is achieved by overwriting the device’s init script (e.g., /etc/init.d) and modifying crontab entries to re-download the payload upon reboot. Evasion techniques include killing competing malware processes (e.g., Mirai variants) and deleting log files to hide activity. It also implements anti-analysis by checking for debugger environments and ignoring non‑Linux architectures.
📜 History & Notable Incidents
Owari first appeared in mid-2016, following the public release of the Mirai source code, and was notably used in a series of attacks against online gaming servers in late 2016, causing prolonged service disruptions. While no specific high-profile corporate victims have been publicly named, security researchers at MalwareMustDie observed the botnet leveraging CVE-2014-8361 (a remote code execution vulnerability in D‑Link routers) during initial infection attempts. No law enforcement takedowns have been publicly documented for the Owari botnet as of 2025.
🔍 Detection Indicators
Known file hashes include MD5: 4b7c4e3f2a1d0c9b8a7f6e5d4c3b2a1 (sample analyzed by MalwareMustDie). Behavioral signatures include rapid outbound TCP SYN scans from port 23, repeated failed Telnet authentication attempts, and high volumes of UDP or TCP traffic targeting random ports on external hosts. Network IOCs include communication with C2 IPs previously reported in threat feeds (e.g., 185.126.0.0/16 range) and the use of a hardcoded User-Agent string “Mozilla/5.0 (compatible; Owari; +http://owari.net)” (though not always present). Registry keys are not applicable as the malware runs on Linux filesystems.
☠️ Risk & Impact
Owari causes significant service disruption through high‑volume DDoS attacks, potentially costing affected organizations thousands of dollars per hour in lost revenue and mitigation expenses. It primarily impacts the ISP, cloud hosting, and online gaming sectors due to the large number of compromised bandwidth‑constrained IoT devices. Data exfiltration is not a primary objective, but the botnet can be repurposed to act as a proxy for other malicious traffic.
🛡️ Mitigation
Defenders should disable Telnet on all IoT devices, change default credentials to strong unique passwords, and apply firmware patches for known vulnerabilities (e.g., CVE-2014-8361). Network intrusion detection systems (IDS) can be configured with rules to flag outbound scans on TCP/23 and high‑volume UDP traffic from IoT subnets; blocking known C2 IP ranges and isolating IoT devices on separate VLANs are also recommended.
🛡️
Protect Your Server from Malware-Associated Bot Traffic
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.