PULSE NAME
One Sock Fits All: The use and abuse of the NSOCKS botnet
WHITE CyberHunter_NL 2024-11-20 Modified: 2024-12-20
22
IOCs
MEDIUM VOLUME
The malware known as Ngioweb has been used to fuel a notorious residential proxy service called NSOCKS, as well as by other services such as VN5Socks and Shopsocks5, new findings from Lumen Technologies reveal. # Loader C2 Tier 2, which aims to identify and track users' IP addresses, has been launched by the Ministry of Defence (MoD) and the Russian Foreign Minister Sergei Lavrov.
Indicators of Compromise (22)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain antigutation.info 2024-11-20
domain antihicipate.com 2024-11-20
domain disimunous.com 2024-11-20
domain dnslookips.com 2024-11-20
domain emelenalike.com 2024-11-20
domain exagenafy.com 2024-11-20
domain inofokable.net 2024-11-20
domain inoluvary.com 2024-11-20
domain interocakate.com 2024-11-20
domain ipscoredns.com 2024-11-20
domain minixetepate.biz 2024-11-20
domain misukumotist.info 2024-11-20
domain nslookups.com 2024-11-20
domain overedaxive-nonameraness.net 2024-11-20
domain overuvezor.com 2024-11-20
domain prekudinish.com 2024-11-20
domain promexucate.com 2024-11-20
domain recepatission.info 2024-11-20
domain remalexation.name 2024-11-20
domain subonuker.name 2024-11-20
domain ultradomafy.net 2024-11-20
domain underuvukent.com 2024-11-20