PULSE NAME
One Sock Fits All: The use and abuse of the NSOCKS botnet
WHITE AlienVault 2024-11-19 Modified: 2024-12-19
14
IOCs
MEDIUM VOLUME
The ngioweb botnet serves as the foundation for the NSOCKS criminal proxy service, maintaining over 35,000 bots daily across 180 countries. The botnet primarily targets SOHO routers and IoT devices, with two-thirds of proxies based in the U.S. NSOCKS utilizes over 180 'backconnect' C2 nodes to obscure users' identities. The infrastructure enables various threat actors to create their own services and launch DDoS attacks. The botnet employs multiple exploits, targeting vulnerable devices and evading common security solutions. NSOCKS is notorious among criminal forums and has been used by groups like Muddled Libra. The service allows users to purchase proxies with cryptocurrency, offering features such as domain filtering for targeted use. The open nature of NSOCKS has led to its abuse by other actors, including DDoS attackers and other proxy services like Shopsocks5 and VN5Socks.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
ngioweb
Indicators of Compromise (14)
All domain FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
domain antigutation.info 2024-11-19
domain antihicipate.com 2024-11-19
domain dnslookips.com 2024-11-19
domain emelenalike.com 2024-11-19
domain inofokable.net 2024-11-19
domain interocakate.com 2024-11-19
domain minixetepate.biz 2024-11-19
domain overedaxive-nonameraness.net 2024-11-19
domain overuvezor.com 2024-11-19
domain promexucate.com 2024-11-19
domain subonuker.name 2024-11-19
domain ultradomafy.net 2024-11-19
domain underuvukent.com 2024-11-19
FileHash-MD5 9998be16901e7f80aad8d931305e057e 2024-11-19