
abuse.ch
@abuse_ch
Followers
35K
Following
4K
Media
1K
Statuses
3K
Active #CobaltStrike botnet C2 with watermark 100000000 🔥. ⛔️ https://api.micosoftr .icu/djiowejdf.⛔️ https://www.googleapi .top/jquery-3.3.1.min.js. Pointing to:.📡43.163.107 .212:443 Tencent 🇨🇳. Sample:.📄 IOCs on ThreatFox🦊.
1
4
25
We are happy to announce the integration of @kunai_project Linux Sandbox on MalwareBazaar 🥳 . Sample ELF X86 report ⤵️.
0
16
79
There's a #MassLogger malware campaign using an allegedly compromised email account🪝of an employee at the Ministry of Agriculture, Water Management and Forestry of Bosnia and Herzegovina 🇧🇦, used to exfiltrate data from compromised devices through SMTP 🔥. Corresponding malware
0
5
11
After the #Lumma Stealer takedown a few weeks ago, threat actors moved away from Cloudflare to AS47105 Vault Dweller OU 🇪🇪 with Finnish upstream Creanova 🇫🇮. ⛔ 195.82.146.193:443.⛔ 195.82.146.221:443.⛔ 195.82.146.223:443. Not only Lumma botnet C2s are hosted there as.
2
11
74
📢 Heads-up! In just 3 WEEKS authentication will be required to access data via API across ALL our platforms. This change will help us manage heavy usage and keep things running smoothly for everyone ➡️ #SteadyPlatform #SteadySignal. Rely on our APIs? . #AuthenticateNow, to avoid
1
3
7
#ItsNewFeatureTuesday! (That’s a thing, right?) 😎.You can now share searches with 3rd parties without them needing to authenticate to view the results! It’s a neat feature that will save time and hassle. Here's how it works ⤵️.1) User (authenticated!) searches on
1
6
9
📢 Reminder: Rate limits have been introduced for excessive API queries from unauthenticated users to keep the platforms running smoothly for everyone. If you experience issues #Authenticate – it’s quick, easy to do, and helps ensure the platforms are stable for all.
0
1
4