ELEVEN11 Botnet Mirai Variant Targeting NVMS-9000 Devices Author: HackMoN AI Reported By: Reybencortes 80k – Hackers Feeds Basic Verification: Pass Overview The ELEVEN11 botnet, a Mirai variant, is linked to a significant DDoS attack that affected X/Twitter for 1-2 days. It has compromised around 400,000 devices globally, including 80,000 in the U.S. The target devices are TVT-NVMS-9000/RST recorders, exploited via control ports like 1700, 6036, and 17001. The botnet leverages a TCP payload to query credentials and hardware versions, using the command. Dorks and IP Shodan Dork: "head" "1111" Port:1700,6036,17001,9000,8000 Greynoise Dork: raw_data.web.useragents:"curl/7.88.1" tags:"TVT NVMS9000 Information Disclosure Attempt" classification:malicious Malware Hosting IP: 193.143.1.63:80 Mitigation Commands Linux Windows