TF-MAL-elf.ngioweb
📛 Threat Title
Malware family: Ngioweb
Description
ThreatFox malware family `elf.ngioweb`. Printable name: Ngioweb.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.ngioweb
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ngioweb
IOC database
- Type
- domain
- Value
elf.ngioweb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.ngioweb
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ngioweb
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:advisory.eventussecurity.com
Originally identified in 2017, Ngioweb functions as a proxy network used for malicious purposes, including anonymizing illicit activities. Recent findings indicate that its operators, leveraging an extensive arsenal of exploits, scan, and compromise vulnerable devices, selling them as residential proxies through platforms like Nsocks.
-
web:deepweb.net
A Historical Perspective: Ngioweb's Tenacity The earliest detailed examination of Ngioweb was published in a Check Point report in 2018. It highlighted the botnet's link to the Ramnit banking malware family .
-
web:github.com
Resources from Trend Micro Research teams. Contribute to trendmicro/research development by creating an account on GitHub.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Ngioweb malware family including references, samples and yara signatures.
-
web:malware.news
Ngioweb Background In August 2018, Check Point published a report and deep analysis on a new multifunctional proxy server botnet named Ngioweb . The proxy service was being loaded by the banking malware family Ramnit. In their report, Check Point reported that the first sample was observed in the second half of 2017.
-
web:thehackernews.com
The malware known as Ngioweb has been used to fuel a notorious residential proxy service called NSOCKS, as well as by other services such as VN5Socks and Shopsocks5, new findings from Lumen Technologies reveal. "At least 80% of NSOCKS bots in our telemetry originate from the Ngioweb botnet, mainly utilizing small office/home office (SOHO) routers and IoT devices," the Black Lotus Labs team at ...
-
web:www.bleepingcomputer.com
The Ngioweb botnet, which supplies most of the 35,000 bots in the cybercriminal NSOCKS proxy service, is being disrupted as security companies block traffic to and from the two networks.
-
web:www.levelblue.com
Ngioweb Background In August 2018, Check Point published a report and deep analysis on a new multifunctional proxy server botnet named Ngioweb . The proxy service was being loaded by the banking malware family Ramnit. In their report, Check Point reported that the first sample was observed in the second half of 2017.
-
web:www.linkedin.com
The recent revelations about the Ngioweb botnet and its association with malicious activities, particularly through the NSOCKS residential proxy service, underscore a growing threat to ...
-
web:www.securityweek.com
The same workers are also used to upload Ngioweb malware to freshly compromised IoT devices," Trend Micro notes. Initially observed in 2018, when it was targeting Windows systems, Ngioweb started targeting Linux computers in 2019, and switched focus to IoT devices in 2020. A new variant of Ngioweb was seen this year.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.