TF-MAL-elf.noabot
📛 Threat Title
Malware family: NoaBot
Description
ThreatFox malware family `elf.noabot`. Printable name: NoaBot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.noabot
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.noabot
IOC database
- Type
- domain
- Value
elf.noabot- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.noabot
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.noabot
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
However, the attribution is complicated due to the seemingly childish naming conventions within the malware's binaries. NoaBot , a Mirai-based botnet, distinguishes itself with unique features and evolutions compared to the original Mirai botnet.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the NoaBot malware family including references, samples and yara signatures.
-
web:nikhilh-20.github.io
The NoaBot is yet another Mirai-based botnet, except it has notable differences in its capabilities like the SSH spreader. The main goal of this analysis was to demonstrate the usage of the ELFEN sandbox to quickly get insights into a given malware sample.
-
web:thehackernews.com
There are indications that NoaBot could be linked to another botnet campaign involving a Rust-based malware family known as P2PInfect, which recently received an update to target routers and IoT devices.
-
web:thenewstack.io
Really? This blend of high-level technical skill and juvenile execution potentially offers clues for future identification and tracking of related malware activities. NoaBot , while seemingly another Mirai variant and XMRig cryptominer, stands out due to the significant obfuscations and enhancements made to the source code.
-
web:www.akamai.com
The malware is spread over SSH protocol using a custom Mirai botnet that was modified by the threat actors. The capabilities of the new botnet, NoaBot , include a wormable self-spreader and an SSH key backdoor to download and execute additional binaries or spread itself to new victims.
-
web:www.anavem.com
KB890830 delivers the March 2026 update for Windows Malicious Software Removal Tool (MSRT), adding detection and removal capabilities for 47 new malware families including advanced ransomware variants and AI-powered threats targeting Windows 10, Windows 11, and Windows Server systems.
-
web:www.broadcom.com
NoaBot - new Mirai-based botnet The year 2023 marked a significant recovery for crypto markets, rebounding from the 2022 downturn, although it has yet to reach the highs of 2021. As per reports the total crypto market cap surged from below $1 trillion in mid-2022 to surpass $1.5 trillion by December 2023. Threat actors, adapting to new trends in cryptojacking, have shifted their focus to ...
-
web:www.cisa.gov
It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.
-
web:www.ncsc.gov.uk
This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.