Elektrine lite

← Feed

abuse.ch :verified:

abuse_ch@ioc.exchange

<p><a href="https://ioc.exchange/tags/cybersecurity" class="mention hashtag" rel="tag">#<span>cybersecurity</span></a> - Fighting <a href="https://ioc.exchange/tags/malware" class="mention hashtag" rel="tag">#<span>malware</span></a> and <a href="https://ioc.exchange/tags/botnets" class="mention hashtag" rel="tag">#<span>botnets</span></a></p>

Posts

  • Post #4501348

    Over the past days, active #malspam campaigns targeting LatAm users πŸ‡¦πŸ‡·πŸ‡§πŸ‡·πŸ‡²πŸ‡½ have been delivering the Grandoreiro banking trojan πŸ¦πŸ’° πŸ“§ Email βž” πŸ“œ JS file βž” πŸ“‘ Fake PDF download Final payload is hosted on MediaFire πŸ”₯ free file hosting C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools&#39; HTTP user agent πŸ–₯️‡️ User-Agent: Embarcadero URI Client/1.0 πŸ”Ž Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com πŸ‘€ πŸ“‘...

  • Post #4241275

    πŸ“’ SERVICE UPDATE | As you may have noticed, we&#39;ve experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. Accounts generating unusually high query volumes may be temporarily limited for up to 72 hours. Repeated or persistent abuse may result in longer-term restrictions on API access.

  • Post #4159260

    It&#39;s here!! The @abuse_ch@ioc.exchange #CommunityHub is LIVE πŸ”₯πŸ”₯πŸ”₯ Now you can access a LIVE view of: ➑️ Total community contributions ➑️ Top 10 Leaderboards ➑️ Monthly contribution trends ....and a place to track your own impact! Our community is bigger than any one platform. It&#39;s a global network of researchers working together to disrupt malware, botnets, and cybercrime. And every contributor deserves recognition πŸ’› Head to the Community and claim your profile πŸ‘‰ abuse.ch/community

  • Post #4044450

    Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users πŸ‡ΊπŸ‡¦πŸ•΅οΈ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site 3️⃣ 207.90.251 .10 returns a PowerShell command as part of the DNS TXT record 4️⃣ Malware executes the PS command and obtains second stage from global-research .space/adv13.php global-research .space has been regis...

  • Post #1324733

    We’ve identified an interesting malware family πŸ”, which we’ve named #GrokPy due to its use of a Grok LLM model πŸ€– to solve and subsequently bypass CAPTCHAs πŸ”₯ The malware gets dropped by #Amadey and: πŸͺ collects information about the infected device, such as screen resolution, public IP &amp;amp; location, ram usage and CPU name πŸ’» attempts to escalate privileges by running as admin or as a scheduled task

  • Post #1317007

    We are happy to announce the integration of @kunai_project Linux Sandbox on MalwareBazaar πŸ₯³ Sample ELF X86 report ‡️ https://bazaar.abuse.ch/sample/0d2211b7e92fcc6a9f7c94d4adf8e47f6f97e31dacd3b2ffb6cce3c485fcef26/