abuse.ch

3.4K posts

abuse.ch banner
abuse.ch

abuse.ch

@abuse_ch

Fighting malware and botnets

Zurich Katılım Mayıs 2009
299 Takip Edilen37.3K Takipçiler
abuse.ch
abuse.ch@abuse_ch·
@JAMESWT_WT @hatching_io @cocaman Thanks for the headsup James! We are aware of it. Sadly, the issue seems to be not on our side. Hence I can't do anything to solve it 😔
English
0
0
4
210
abuse.ch
abuse.ch@abuse_ch·
@BlinkzSec Hmm are you sure its not cached on your side?
English
1
0
0
925
abuse.ch
abuse.ch@abuse_ch·
Malspam 📧 targeting Spanish users 🇪🇸 Email ➡️ geo filter ➡️ mediafire ➡️ iso ➡️ vbs 1st stage - geo filter 🛑 vmi3228488.contaboserver .net Contabo 🇩🇪 2nd stage - payload 📄 urlhaus.abuse.ch/url/3824487/ Dropped iso: bazaar.abuse.ch/sample/faaa4d0… Botnet C2: 📡 54.197.208.68 Amazon 🇺🇸
abuse.ch tweet mediaabuse.ch tweet media
English
1
6
17
3.6K
abuse.ch
abuse.ch@abuse_ch·
@banthisguy9349 #ClickFix ? Related (all AS202412 Omegatech 🇳🇱): 158.94.210.248 185.224.215.252 91.92.241.160 188.137.247.152 ... More stuff on 91.92.241.160 ⤵️ #sandnet" target="_blank" rel="nofollow noopener">hunting.abuse.ch/hunt/69e251c6c…
abuse.ch tweet mediaabuse.ch tweet media
English
2
3
18
1.8K
abuse.ch
abuse.ch@abuse_ch·
@JAMESWT_WT @guelfoweb @ShadowOpCode @marsomx_ @Certego_Intel @D3LabIT @James_inthe_box @c_APT_ure @Max_Mal_ @struppigel @VirITeXplorer PureHVNC / PureRAT Payload URLs: 🌐 urlhaus.abuse.ch/host/everycare… PureHVNC C2: 📡 5.101.84.202:8996 (AS63023 GTHost 🇺🇸) ➡️ Active since at least 2026-03-17 ⤵️ threatfox.abuse.ch/ioc/1769356/ Network owner got notified multiple times, but apparently doesn't care 😕 #sandnet" target="_blank" rel="nofollow noopener">hunting.abuse.ch/hunt/69e24dd2a…
abuse.ch tweet media
English
0
5
16
839
abuse.ch
abuse.ch@abuse_ch·
@Botconf 2026 is wrapping up, and it’s been a top event 🎉 We’ve been before, but this is the first time we’ve sponsored with our partner @SpamhausTech and supported an event that really matters to our community 🙌 Getting to be in the same room, chatting with people who share data with us and use our platforms, doesn’t happen that often, so it’s been great to make the most of it. Huge thanks 🙏 to the Botconf team for having us - we’re glad the choc bars went down well 😋
abuse.ch tweet media
English
0
1
6
913
sicehice
sicehice@sicehice·
#opendir hosting #AsyncRAT 81.163.111.127:8000 🇷🇺 C2s: 91.242.179.84 🇷🇺 91.242.179.62 🇷🇺 81.163.111.127 🇷🇺
sicehice tweet media
English
2
4
13
1.9K
abuse.ch
abuse.ch@abuse_ch·
Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, including: ➡️SoftConnect ➡️HardConnect ➡️AxisControl It also seems that the threat actor was previously playing around with the legitimate RMM #ScreenConnect (aka ConnectWise) before switching to their own fake RMM 🛠️ What also stands out: the majority of the botnet C2s were hosted at Contabo GmbH 🇩🇪 We track the threat on our platforms as #FakeRMM ⤵️ IOCs on ThreatFox: 🦊 threatfox.abuse.ch/browse/tag/Fak… Malware samples: 📄 bazaar.abuse.ch/browse/tag/Fak…
abuse.ch tweet media
Threat Insight@threatinsight

Proofpoint threat researchers identified a new malware-as-a-service named #TrustConnect. Notably, it masquerades as a legitimate remote monitoring and management tool, marking an evolution in how attackers weaponize trust around enterprise tooling. brnw.ch/21x05Vh

English
0
13
39
6.5K
Emmy Byrne
Emmy Byrne@byrne_emmy12099·
Настроечных работ.pdf.lnk f59754843a12e298eaaf2b889817fdffee55f92109aa181c00ac0b3ed2fe1148 #APT #Suspicious
Emmy Byrne tweet media
2
4
17
2.1K