PULSE NAME
Inside Water Barghest's Rapid Exploit-to-Market Strategy for IoT Devices
WHITE Water Barghest AlienVault 2024-11-18 Modified: 2024-11-18
97
IOCs
HIGH VOLUME
Water Barghest, a cybercriminal group, has developed a highly automated system for exploiting and monetizing IoT devices. Their botnet, comprising over 20,000 devices as of October 2024, uses automated scripts to identify and compromise vulnerable IoT devices from public internet scan databases. Once compromised, the Ngioweb malware is deployed, running in memory and connecting to command-and-control servers. The entire process, from initial infection to listing the device on a residential proxy marketplace, can take as little as 10 minutes. Water Barghest targets various IoT devices from brands like Cisco, DrayTek, and Zyxel, using both n-day vulnerabilities and at least one zero-day exploit. Their sophisticated operation has allowed them to maintain a low profile while generating steady income through their cybercriminal activities.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Ngioweb
Indicators of Compromise (97)
All FileHash-SHA256 domain FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 c91795b59248562e44d6c07526c7ab89dfe45344293703a94a3ae5ff02eab5a4 2024-11-18
FileHash-SHA256 db1f96b20679f9fb9cbd96b242ab8530102c0105b64c83c3ae544f87594a6fa9 2024-11-18
domain ultradomafy.net 2024-11-18
FileHash-MD5 053b4e35af82776cc84f1e997d13e874 MD5 of 9cb6c49173e4cb5a0b3c2f6d69a5bdc0bc67138329f00afaf38d678f2c0e00a6 2024-11-18
FileHash-MD5 25c1373db67c8c5addf80d57f8f23815 MD5 of 5353228926aa96b546b33de4418f15e347441d16d292f4946beca6a0d314e635 2024-11-18
FileHash-MD5 2a8ef3975395c3358889a723ea03741a MD5 of 9fda16ad1d32f34c221d0e074a4ef13217eded63b5ff507452c4e2bbb57df3a4 2024-11-18
FileHash-MD5 33d2ae1f5cee2a033be5bb8447296816 MD5 of a8f7eaf999eb6cc8461f785fad13da30315da80b534cae047c5811bbea3351e3 2024-11-18
FileHash-MD5 39ebbdbfb0e8543ba04df5cc7d69327f MD5 of 2e940e3bd88226cfbbfb7a2eefbdd675173fd2950847a9131e11c1682353e286 2024-11-18
FileHash-MD5 4b0e1773a743509505cba6846950bde0 MD5 of 129693d8c474a8de8f91e1d16e0129732aba20bea9ac24e7c68b345b7b05ad6f 2024-11-18
FileHash-MD5 5584380ce95f7f96186be99cf408e07b MD5 of 869965781d96a06741c2a28c54bb8e3233bc10fcb92455e6cb9ab0c9fc2c54d4 2024-11-18
FileHash-MD5 64708f9beb8cadcf3caa5f767590d83b MD5 of b9360f1434ce7ff45b3ca49ff7269293188a339747b03bcd395b71b1d179700f 2024-11-18
FileHash-MD5 6b1cafa1fb4d72ea37f0dcde4143a7a1 MD5 of 05cd00f975bd2522d943e836ef5a1cb00806c6d684987274da850be348b2b1f4 2024-11-18
FileHash-MD5 8983d7ef13904aa6f7cdbc08f143a70a MD5 of 9fb33a16762dce934e7a48946e396ad672ab16d42a060021238f2ddf6a9f0514 2024-11-18
FileHash-MD5 8e817c5998b15f5127b2189e486e1c7c MD5 of be285b77211d1a33b7ae1665623a9526f58219e20a685b6548bc2d8e857b6b44 2024-11-18
FileHash-MD5 9c38019e7a78e4d42228bc3aedc87441 MD5 of e3344c598a984dc5dc8dc1d971da8dd9b7058c48288dc5ad063548fff61543a1 2024-11-18
FileHash-MD5 b5cde533fce5867099b2d23d19817acd MD5 of a79ff2cd7f47b11d9176c40f0e82ba9b378c463ff9dd6e3e907df9480c7a1547 2024-11-18
FileHash-MD5 c623440a590fe1cdad46a1e16baf6bc0 MD5 of b8385ce60ca6c69b7ea67fa93c7d5908809658e7d8a4fb9e003890b820979f53 2024-11-18
FileHash-MD5 d38cf622452526188998d4239abd6301 MD5 of 78a1b5bea50034e7a03e6ed5c0f4f80f1fbc770555891a73790e1b59a2fba608 2024-11-18
FileHash-SHA1 01167038527bb1d09f3056cdcfbf3763de69a1af SHA1 of 5353228926aa96b546b33de4418f15e347441d16d292f4946beca6a0d314e635 2024-11-18
FileHash-SHA1 06a4e404bddf2d8cc197941e8ff083bcf745f197 SHA1 of 2e940e3bd88226cfbbfb7a2eefbdd675173fd2950847a9131e11c1682353e286 2024-11-18
FileHash-SHA1 0e498562928ec0b1af49dd5306aaf30587624a36 SHA1 of 129693d8c474a8de8f91e1d16e0129732aba20bea9ac24e7c68b345b7b05ad6f 2024-11-18
FileHash-SHA1 10989546aa40aa9e107e13153d86167076e4cfaa SHA1 of b9360f1434ce7ff45b3ca49ff7269293188a339747b03bcd395b71b1d179700f 2024-11-18
FileHash-SHA1 1b481016b55e8af628346f201f8968a9e8ae3c63 SHA1 of 05cd00f975bd2522d943e836ef5a1cb00806c6d684987274da850be348b2b1f4 2024-11-18
FileHash-SHA1 29bb78c7ca17ef946ed625ca5ba34908e8107357 SHA1 of 869965781d96a06741c2a28c54bb8e3233bc10fcb92455e6cb9ab0c9fc2c54d4 2024-11-18
FileHash-SHA1 7703e08b434cbc914a582e7b53112b23286226a5 SHA1 of be285b77211d1a33b7ae1665623a9526f58219e20a685b6548bc2d8e857b6b44 2024-11-18
FileHash-SHA1 7babb406d534d61565c7d1d9dad9ba4fe64f356a SHA1 of b8385ce60ca6c69b7ea67fa93c7d5908809658e7d8a4fb9e003890b820979f53 2024-11-18
FileHash-SHA1 8a66979a5ac882dd228ef3b036c1e50e3b16c974 SHA1 of a8f7eaf999eb6cc8461f785fad13da30315da80b534cae047c5811bbea3351e3 2024-11-18
FileHash-SHA1 aaa953477814aac037fd2a260040f0c34f151cac SHA1 of 9fb33a16762dce934e7a48946e396ad672ab16d42a060021238f2ddf6a9f0514 2024-11-18
FileHash-SHA1 b0cb5e2a5046ffb48fe09cedaf8c8553e85c82af SHA1 of 9fda16ad1d32f34c221d0e074a4ef13217eded63b5ff507452c4e2bbb57df3a4 2024-11-18
FileHash-SHA1 e3688268c33e644268bfe37b0d01889259dddcae SHA1 of a79ff2cd7f47b11d9176c40f0e82ba9b378c463ff9dd6e3e907df9480c7a1547 2024-11-18
FileHash-SHA1 e58007398bd4cfdaad6934a6c9e601e6469b4889 SHA1 of e3344c598a984dc5dc8dc1d971da8dd9b7058c48288dc5ad063548fff61543a1 2024-11-18
FileHash-SHA1 ef5a03ed597790130e02f766e38165edec410a94 SHA1 of 9cb6c49173e4cb5a0b3c2f6d69a5bdc0bc67138329f00afaf38d678f2c0e00a6 2024-11-18
FileHash-SHA1 f2f21b7eac6508f97662fdc36f95b2712af1669a SHA1 of 78a1b5bea50034e7a03e6ed5c0f4f80f1fbc770555891a73790e1b59a2fba608 2024-11-18
FileHash-SHA256 05cd00f975bd2522d943e836ef5a1cb00806c6d684987274da850be348b2b1f4 2024-11-18
FileHash-SHA256 129693d8c474a8de8f91e1d16e0129732aba20bea9ac24e7c68b345b7b05ad6f 2024-11-18
FileHash-SHA256 1748978997d9630c568f6c06ff0767ed8b0cfbf5c93612daf600adefecfba2e1 2024-11-18
FileHash-SHA256 1fe1cece08fef19448a32a746f5c8f77521db757c2b345103834a5f617101f15 2024-11-18
FileHash-SHA256 2bf2c10332f1d31e1b87e62ca2d7afc70f073c55474d7f03ff6c37caec28df4a 2024-11-18
FileHash-SHA256 2e940e3bd88226cfbbfb7a2eefbdd675173fd2950847a9131e11c1682353e286 2024-11-18
FileHash-SHA256 35f95fbb1b439a89cbd6e825188fb64fde44aef9829d549b4f547850552e095c 2024-11-18
FileHash-SHA256 4af537b29c54f976801ee7688c4db78d4b4e7b9947769226afc108e4645cf20f 2024-11-18
FileHash-SHA256 4e8a36f467f1dab1b4768f67efd3712562699603839e38d93525c90989a4cf26 2024-11-18
FileHash-SHA256 5353228926aa96b546b33de4418f15e347441d16d292f4946beca6a0d314e635 2024-11-18
FileHash-SHA256 56657300f250fa9df77d6bc393bfc01d585d00bfb5302bf34314368fb13cbe26 2024-11-18
FileHash-SHA256 5d89b09dfb7c09a3a42345a136293b469a71ef7a1f599102ad67c09dc4fc53bf 2024-11-18
FileHash-SHA256 600c56a175f3661f434d1fe3418fb4cca96cdf6f880bd74a389e0d16d85ca501 2024-11-18
FileHash-SHA256 6a3288b1d326290778544769ea7c1ed80af763ea47fee5131afef209a0e2d301 2024-11-18
FileHash-SHA256 710e0317de732f1bce32ed96d33468cb2b55e513106393b11bf7800081f1e681 2024-11-18
FileHash-SHA256 743f7c495048d8983bbedc3d52ea00c914fe008b06ef01c1be2a78cd5c1375f3 2024-11-18
FileHash-SHA256 74f4d77bf367063bccece2fb3796e6bd7a1f51528f58ed3f1450b7de6c29b5f4 2024-11-18
FileHash-SHA256 78a1b5bea50034e7a03e6ed5c0f4f80f1fbc770555891a73790e1b59a2fba608 2024-11-18
FileHash-SHA256 7bddb716c233211fa7332586e7d3e859814ec508108fa1024c4fb99aab843cdf 2024-11-18
FileHash-SHA256 83cf89428e07a1a10b22958dca25f50a8a151bccfa01ee9bcce870303a4f9861 2024-11-18
FileHash-SHA256 869965781d96a06741c2a28c54bb8e3233bc10fcb92455e6cb9ab0c9fc2c54d4 2024-11-18
FileHash-SHA256 892eb161254733cf5923313544e923fface375c27b3dcf8f66e79da84c93cf65 2024-11-18
FileHash-SHA256 97cadc2eba1eaa7a4115ea7cc82a6955bc69d8e2913b0b46f493f9cc84ec07de 2024-11-18
FileHash-SHA256 9cb6c49173e4cb5a0b3c2f6d69a5bdc0bc67138329f00afaf38d678f2c0e00a6 2024-11-18
FileHash-SHA256 9f1fcfb2fcc66f4e534d3348b8d01eef0be1b153bc022ae7601ed3a0817aae88 2024-11-18
FileHash-SHA256 9fb33a16762dce934e7a48946e396ad672ab16d42a060021238f2ddf6a9f0514 2024-11-18
FileHash-SHA256 9fda16ad1d32f34c221d0e074a4ef13217eded63b5ff507452c4e2bbb57df3a4 2024-11-18
FileHash-SHA256 9fead901a3012825841cb6091f52e0a914944fbb1460c3ddb9d07213fbb7e30e 2024-11-18
FileHash-SHA256 a3317844f3d6b5b2440be896b84fd6aa4ee77a0f9b656b784b235e077b69715d 2024-11-18
FileHash-SHA256 a79ff2cd7f47b11d9176c40f0e82ba9b378c463ff9dd6e3e907df9480c7a1547 2024-11-18
FileHash-SHA256 a8497257d78ea15088e0b9c68319a2c0ae8c651ed36780e9424effe97f440c0c 2024-11-18
FileHash-SHA256 a8f7eaf999eb6cc8461f785fad13da30315da80b534cae047c5811bbea3351e3 2024-11-18
FileHash-SHA256 b8385ce60ca6c69b7ea67fa93c7d5908809658e7d8a4fb9e003890b820979f53 2024-11-18
FileHash-SHA256 b9360f1434ce7ff45b3ca49ff7269293188a339747b03bcd395b71b1d179700f 2024-11-18
FileHash-SHA256 be285b77211d1a33b7ae1665623a9526f58219e20a685b6548bc2d8e857b6b44 2024-11-18
FileHash-SHA256 bfab45d715e0e090ea18849661ed3ed58bdd7310c54c4a14a607eee4cc742e33 2024-11-18
FileHash-SHA256 c267e0bf3f1a0448e66427d5863d762af7cd6cc7ff812e6addcd4e54d9a46ac9 2024-11-18
FileHash-SHA256 e0cdaaba90f061d31cfe0211fe207cb3971970a141d9d72f95c8a55c8d565cb1 2024-11-18
FileHash-SHA256 e2423e93b84284890a27e3796491049a22f6496b3830e20e808dff1c77560e3d 2024-11-18
FileHash-SHA256 e3344c598a984dc5dc8dc1d971da8dd9b7058c48288dc5ad063548fff61543a1 2024-11-18
FileHash-SHA256 eddd909b49f2fef023a7b6188b2ae70bbf1e25e85f5e4c84c19cc25641f17175 2024-11-18
FileHash-SHA256 f6d70464165e00de26127464a84919f20521aa4efbecfae41e75688f74436489 2024-11-18
FileHash-SHA256 f95342caa61e77174fe7653eea60909b9db0102c27a0641e25cdc053689110ab 2024-11-18
domain antigutation.info 2024-11-18
domain antihicipate.com 2024-11-18
domain disimunous.com 2024-11-18
domain emelenalike.com 2024-11-18
domain enidecikive.net 2024-11-18
domain exagenafy.com 2024-11-18
domain inoluvary.com 2024-11-18
domain interocakate.com 2024-11-18
domain macrofocafify.org 2024-11-18
domain minixetepate.biz 2024-11-18
domain misukumotist.info 2024-11-18
domain monobimefist.com 2024-11-18
domain prekudinish.com 2024-11-18
domain prenurevaty.info 2024-11-18
domain promexucate.com 2024-11-18
domain recepatission.info 2024-11-18
domain remalexation.name 2024-11-18
domain semiridinution-postepudency.com 2024-11-18
domain subonuker.name 2024-11-18
domain ultradomafy.net 2024-11-18
domain underuvukent.com 2024-11-18