abuse.ch :verified:
abuse_ch@ioc.exchange
<p><a href="https://ioc.exchange/tags/cybersecurity" class="mention hashtag" rel="tag">#<span>cybersecurity</span></a> - Fighting <a href="https://ioc.exchange/tags/malware" class="mention hashtag" rel="tag">#<span>malware</span></a> and <a href="https://ioc.exchange/tags/botnets" class="mention hashtag" rel="tag">#<span>botnets</span></a></p>
Posts
-
Post #4501348
Over the past days, active #malspam campaigns targeting LatAm users π¦π·π§π·π²π½ have been delivering the Grandoreiro banking trojan π¦π° π§ Email β π JS file β π Fake PDF download Final payload is hosted on MediaFire π₯ free file hosting C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent π₯οΈβ€΅οΈ User-Agent: Embarcadero URI Client/1.0 π Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com π π‘...
-
Post #4241275
π’ SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. Accounts generating unusually high query volumes may be temporarily limited for up to 72 hours. Repeated or persistent abuse may result in longer-term restrictions on API access.
-
Post #4159260
It's here!! The @abuse_ch@ioc.exchange #CommunityHub is LIVE π₯π₯π₯ Now you can access a LIVE view of: β‘οΈ Total community contributions β‘οΈ Top 10 Leaderboards β‘οΈ Monthly contribution trends ....and a place to track your own impact! Our community is bigger than any one platform. It's a global network of researchers working together to disrupt malware, botnets, and cybercrime. And every contributor deserves recognition π Head to the Community and claim your profile π abuse.ch/community
-
Post #4044450
Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users πΊπ¦π΅οΈ The malware sample: 1οΈβ£ Obtains the DNS A record of ns2.theendlessweb .com 2οΈβ£ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site 3οΈβ£ 207.90.251 .10 returns a PowerShell command as part of the DNS TXT record 4οΈβ£ Malware executes the PS command and obtains second stage from global-research .space/adv13.php global-research .space has been regis...
-
Post #1324733
Weβve identified an interesting malware family π, which weβve named #GrokPy due to its use of a Grok LLM model π€ to solve and subsequently bypass CAPTCHAs π₯ The malware gets dropped by #Amadey and: πͺ collects information about the infected device, such as screen resolution, public IP &amp; location, ram usage and CPU name π» attempts to escalate privileges by running as admin or as a scheduled task
-
Post #1317007
We are happy to announce the integration of @kunai_project Linux Sandbox on MalwareBazaar π₯³ Sample ELF X86 report β€΅οΈ https://bazaar.abuse.ch/sample/0d2211b7e92fcc6a9f7c94d4adf8e47f6f97e31dacd3b2ffb6cce3c485fcef26/