Fighting malware and botnets

Zurich
Pinned Tweet
๐Ÿ“ข To our incredible community of contributors: thank you for everything you do to keep the internet safe! ๐Ÿ›ก๏ธ To help protect our platforms and maintain the high-quality data you rely on, here is a quick refresher on our submission guidelines across MalwareBazaar, URLhaus, and ThreatFox: ๐Ÿ‘‡ โ“ Why do these guidelines matter so much? โ“ 1๏ธโƒฃ Impact at scale: Our datasets power security tools worldwide ๐ŸŒ. Inaccurate submissions cause false positives on a massive scale - with great power comes great responsibility! ๐Ÿ•ธ๏ธ๐Ÿ’ช 2๏ธโƒฃ Actionable intelligence: We want the data to stay razor-sharp and immediately useful, not a graveyard of noise ๐Ÿชฆ If an contributor's account is ever restricted, our goal is always to send an explanation right away โœ‰๏ธ. On rare occasions, immediate action is required to prevent harm before we can send a heads-up. If this happens, please reach out to us so we can review it together: ๐Ÿ”— contact.abuse.ch/ Since 2009, abuse.ch has been built by the community, for the community. None of this works without you. ๐Ÿ™Œ If a policy ever feels unclear or counterproductive, talk to us! We would much rather refine our wording (or the policy itself) than lose good data or a great contributor. ๐Ÿ’› Quick links to the submission policies for each platform: ๐Ÿฆ  MalwareBazaar: bazaar.abuse.ch/faq/#policy ๐ŸŒ URLhaus: urlhaus.abuse.ch/api/#policy ๐ŸฆŠ ThreatFox: threatfox.abuse.ch/faq/ Thank you for standing with us to make the web safer for everyone! ๐Ÿš€๐Ÿ‘
4
4
11
3,169
Did you know that if you run Cowrie high interaction SSH and Telnet honeypot ๐Ÿฏ๐Ÿ, you can automatically submit malicious URLs caught by it to URLhaus ๐Ÿ’ก? If you aren't running a Cowrie honeypot yet, you may want to check it out: Project website: ๐Ÿ–ฅ๏ธ cowrie.org/ GitHub repository: ๐Ÿ–ฑ๏ธ github.com/cowrie/cowrie Malicious URLs caught by Cowrie honeypots: ๐ŸŒ urlhaus.abuse.ch/browse/tag/โ€ฆ
7
7
1,615
A couple of months in and the Community Hub is thriving ๐Ÿคฉ ... 36,441 contributions across all abuse.ch platforms in the last 30 days (up +30.8%) ๐Ÿ”ฅ๐Ÿ”ฅ๐Ÿ”ฅ @geenensp ๐Ÿฅ‡ on URLhaus (78-month streak!!) TheRavenFile ๐Ÿฅ‡ on ThreatFox whack_sh ๐Ÿฅ‡ on MalwareBazaar Go see the full Top10 leaderboards ๐Ÿ‘‰ community.abuse.ch #SharingisCaring #Leaderboards #Community ๐Ÿ’›
3
6
19
2,027
We recently sinkholed a DDoS #botnet of 200,000 compromised Android TV boxes infected with #CECbot malware ๐Ÿ•ต๏ธโ€โ™€๏ธ. Shortly after, the threat actor responded by registering a rather specific botnet C2 domain ๐Ÿ‘‡ ๐Ÿ“ก spamhaushackers .at Nice try, but their new C2 domain is already flagged๐Ÿ›‘. Its authoritative DNS runs on DNSPod (*.dnspod.com), which has carried a poor reputation for years! ๐Ÿ’ก โคต๏ธโคต๏ธโคต๏ธโคต๏ธ hunting.abuse.ch/hunt/6aa7e8โ€ฆ
4
18
68
9,036
๐Ÿšจ ANNOUNCEMENT FOR TOP CONTRIBUTORS! ๐Ÿšจ Weโ€™ve been working on something huge and the cat ๐Ÿˆ is finally out of the bag ๐Ÿ‘€ ...ย abuse.ch and Spamhaus have officially partnered with Modat (@modat_magnify) to give FREE Magnify licenses to our top contributors! ๐ŸŽ‰๐Ÿ”ฅ You give your time, brainpower, and expertise to this community ๐Ÿ‘. You hunt down the bad guys every single day - we want to make sure you have the best tools ๐Ÿ› ๏ธ to do what you do for the good of the internet every single day! Consider this our way of saying THANK YOUย  ๐Ÿ™ย ๐Ÿ™ Top contributors - keep an eye out, we'll be reaching out in the coming weeks to get your access sorted. More details in comments ๐Ÿ‘‡
1
9
22
3,093
#BoratRAT spreading using similar tactics as #ClickFix ๐Ÿ‘‡ 1๏ธโƒฃ Fake Microsoft Security Verification ๐Ÿ”‘ leading to malicious PowerShell execution ๐Ÿ–ฑ๏ธ 2๏ธโƒฃ Command triggers a DNS TXT request to recapture-robot .today ๐ŸŒ to obtain a PowerShell script ๐Ÿ“œ 3๏ธโƒฃ Script drops payload, infecting host with BoratRAT ๐Ÿ’ป Payload delivery: ๐ŸŒ recapture-robot .today (PDR ๐Ÿ‡ฎ๐Ÿ‡ณ) ๐ŸŒ 91.193.7.186:49094 (M247 ๐Ÿ‡ฏ๐Ÿ‡ต) Botnet C2: ๐Ÿ“ก out-agent.duckdns .org ๐Ÿ“ก 91.193.7.186:48988 (M247 ๐Ÿ‡ฏ๐Ÿ‡ต) ๐Ÿ“„ Sample: bazaar.abuse.ch/sample/5a8abโ€ฆ
2
27
80
7,296
Overlord RAT ๐Ÿ”Œ dropped by Amadey loader ๐Ÿ”ฅ Botnet C2 server: mypamella .xyz โžก๏ธ NameSilo ๐Ÿ‡บ๐Ÿ‡ธ 136.175.82.88:443 โžก๏ธ 2ETELECOM๐Ÿ‡ง๐Ÿ‡ฌ Payload is bulletproof hosted ๐Ÿ›ก๏ธat Omegatech LTD ๐Ÿ‡ณ๐Ÿ‡ฑ ๐ŸŒ urlhaus.abuse.ch/url/3906755โ€ฆ ๐Ÿ“„ Malware sample: bazaar.abuse.ch/sample/ac1f8โ€ฆ ๐ŸฆŠ Further IOCs on ThreatFox: threatfox.abuse.ch/browse/maโ€ฆ Admin panel โคต๏ธ
2
16
63
6,177
NeedleStealer ๐Ÿชก๐Ÿช written in Go โคต๏ธ ๐Ÿ”Ž HTTP user agents observed: User-Agent: Loader-cli/v1 user-agent: Go-http-client/2.0 ๐Ÿ“ก Botnet C2s, all behind Cloudflare CDN: http://woolvilli .com/api/v2 http://allremdeskriki .com/api/v2 http://dubl1allremriki .com/api/v2 http://dubl2allremriki .com/api/v2 ๐Ÿ’ก Related C2 infrastructure at Vultr ๐Ÿ‡ณ๐Ÿ‡ฑ: http://136.244.100 .54:8899/api/v1/agent/register http://136.244.100 .54:8899/api/v1/agent/ws โšฑ๏ธ Artifacts: \Sessions\1\BaseNamedObjects\Local\NeedleRemoteAgentSingle C:\Users\user\AppData\Local\Temp\needle-2fa ๐Ÿ“„ Malware samples: bazaar.abuse.ch/browse/signaโ€ฆ ๐ŸฆŠ Relevant IOCs are on ThreatFox: threatfox.abuse.ch/browse/taโ€ฆ Stealer admin panelโคต๏ธ
3
27
68
8,742
abuse.ch retweeted
We identified a new malware called #HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam ๐Ÿ“ง, first observed on August 1, 2026 ๐Ÿ”ญ๐Ÿ‘€ Key Capabilities โคต๏ธ ๐Ÿ•ต๏ธ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto miners ๐Ÿ’ธ ๐Ÿ”Ž Targeted Harvesting: Steals web browser & email credentials, crypto wallets, and gaming accounts (Steam, Roblox) ๐ŸŽฎ ๐Ÿค– AI & Platform Cookie Stealing: Targets a list of hardcoded domains like Grok, Anthropic, Coinbase, ByBit, Instagram, and Rockstar Games for which it steals session cookies ๐Ÿช ๐Ÿ’ฐ Electron App Webinjects: Intercepts activity on desktop apps like Exodus Wallet ๐Ÿ‘› Artifacts observed โคต๏ธ 1๏ธโƒฃ Stores stealers logs under C:\Users\USERNAME\AppData\Local\Temp\hype-YYYY-MM-DD.log 2๏ธโƒฃ Uses HTTP host header "X-Hype-Agent-Token" during botnet C2 communication HypeAgent communicates via WebSocket using JSON. Here are some Botnet C2 servers we have been observed โคต๏ธ ๐Ÿ“ก 31.40.204.178:7080 WhiteLabel ๐Ÿ‡น๐Ÿ‡ท ๐Ÿ“ก 94.26.3.211:7443 Stellar Group SAS ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ“ก 192.109.139.91:7443 Stellar Group SAS ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ“ก 195.177.94.60:7443 Stellar Group SAS ๐Ÿ‡ซ๐Ÿ‡ท ๐Ÿ“ก 107.175.148.122:7443 HostPapa ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ“ก 209.54.103.173:7443 HostPapa ๐Ÿ‡บ๐Ÿ‡ธ ๐Ÿ“ก 132.243.225.173:7080 QWINS-Hosting ๐Ÿ‡ฉ๐Ÿ‡ช ๐Ÿ“ก 78.40.209.113:7081 QWINS-Hosting ๐Ÿ‡ซ๐Ÿ‡ฎ ๐Ÿ“ก 31.77.138.55:5654 QWINS-Hosting ๐Ÿ‡ซ๐Ÿ‡ฎ ๐ŸฆŠ Releated IOCs on ThreatFox: threatfox.abuse.ch/browse/taโ€ฆ ๐Ÿ“„ Releated malware samples on MalwareBazaar: bazaar.abuse.ch/browse/signaโ€ฆ
1
22
64
6,761
๐Ÿ“ข HUNTERS WANTED: Thereโ€™s still time to join our small group of experts helping shape a new CTI hunting platform from Spamhaus and @abuse_ch. We're looking for people who: โžก๏ธ Run structured CTI/detection-engineering workflows โžก๏ธ Write and maintain YARA rules โžก๏ธ Consume data programmatically โžก๏ธ Understand TLP governance and public/private boundaries We want to build it with people who know these challenges first-hand: running detections at scale, dealing with noisy results, building and maintaining complex infrastructure, and struggling to get to actionable intelligence. Commitment is light-touch this year - an hour or two a month - with early access when the beta opens. Does this sound like you or someone you know? Read on, or share the link below to find out more ๐Ÿ‘‰ hubs.ly/Q04sKM3D0 #ThreatIntel #YARA #ThreatHunting
3
5
800
StealC C2 domains dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains ๐Ÿ‘๏ธ ๐ŸŒ cloud-flare-authenticator .link ๐ŸŒ cloud-flare-authenticator .click ๐ŸŒ update-microsoft-data .services ๐Ÿ“ก 89.34.90.45:443 OverlordRAT #botnet C2 server โคต๏ธ ๐ŸŒ download-windows-update .live ๐Ÿ“ก 151.243.113.94:5173 Both hosted at AS207043 DEDIK-IO in Germany๐Ÿ‡ฉ๐Ÿ‡ช ๐Ÿ“„ Malware sample: bazaar.abuse.ch/sample/5c61cโ€ฆ ๐ŸฆŠ IOCs on ThreatFox: threatfox.abuse.ch/browse/maโ€ฆ threatfox.abuse.ch/browse/taโ€ฆ
Possible interesting opendir: http://cloud-flare-authenticator[.]link/ ๐Ÿคทโ€โ™‚๏ธ
1
17
67
6,813
Over the past days, active #malspam campaigns targeting LatAm users ๐Ÿ‡ฆ๐Ÿ‡ท๐Ÿ‡ง๐Ÿ‡ท๐Ÿ‡ฒ๐Ÿ‡ฝ have been delivering the Grandoreiro banking trojan ๐Ÿฆ๐Ÿ’ฐ ๐Ÿ“ง Email โž” ๐Ÿ“œ JS file โž” ๐Ÿ“‘ Fake PDF download Final payload is hosted on MediaFire ๐Ÿ”ฅ free file hosting C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent ๐Ÿ–ฅ๏ธโคต๏ธ User-Agent: Embarcadero URI Client/1.0 ๐Ÿ”Ž Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com ๐Ÿ‘€ ๐Ÿ“ก Grandoreiro botnet C2s hosted at AWS: 54.80.154.193 54.91.129.132 54.91.223.28 ๐ŸŒ Payloads URLs: urlhaus.abuse.ch/browse/tag/โ€ฆ ๐Ÿ“„ Malware samples: bazaar.abuse.ch/browse/signaโ€ฆ ๐ŸฆŠ Relevant IOCs are available on ThreatFox: threatfox.abuse.ch/browse/maโ€ฆ
3
13
44
4,561
Rogue #ScreenConnect RMM cluster using a fake @COLDCARDwallet domain to lure crypto wallet owners ๐Ÿ’ฐ into downloading a fake DocuSign MSI which drops ScreenConnect ๐Ÿ–ฑ๏ธ๐Ÿ–ฅ๏ธ โ›“๏ธ Attack Chain: Threat actor domain โžก๏ธ GitHub repo โžก๏ธ ScreenConnect ๐Ÿ” Fake #COLDCARD domain with opendir: hardware-data .com โžก๏ธ Tucows Domains ๐Ÿ‡บ๐Ÿ‡ธ โš™๏ธ Rogue GitHub user with 19 code repositories: github.com/kaswareteam/ ๐Ÿ”Œ ScreenConnect RMM botnet C2s (Port 8041 TCP): ๐Ÿ‡บ๐Ÿ‡ธ DeltaHost : hitpanels .com โžก๏ธ 185.174.101.132 hitspanels .com โžก๏ธ 185.174.101.132 ๐Ÿ‡บ๐Ÿ‡ธ 1337 Services GmbH: vicspanel .com โžก๏ธ 155.2.192.94 hitstp .com โžก๏ธ 155.2.192.235 vps133panel .com โžก๏ธ 203.159.90.31 ๐ŸฆŠ IOCs on ThreatFox: threatfox.abuse.ch/browse/taโ€ฆ ๐Ÿ  Payload delivery URLs on URLhaus: urlhaus.abuse.ch/browse/tag/โ€ฆ
2
6
17
3,542
๐Ÿ“ข SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. Accounts generating unusually high query volumes may be temporarily limited for up to 72 hours. Repeated or persistent abuse may result in longer-term restrictions on API access.
1
3
2,452