1.
abuse.ch
@abuse_ch
Vidar using Mastodon instance used by threat researchers for botnet command&control (ioc .exchange)
Malware samp… twitter.com/i/web/status/1…
Malware samp… twitter.com/i/web/status/1…
28 Mar 23
copy & paste +upvote -downvote Vidar using Mastodon instance used by threat researchers for botnet command&control (ioc .exchange) 🔥
Malware samp… https://t.co/nQpV86O4wL
2.
abuse.ch
@abuse_ch
Gozi targeting Italy
url->zip->smb->exe
Payload URLs:
urlhaus.abuse.ch/browse/tag/771…
Payload:
… twitter.com/i/web/status/1…
url->zip->smb->exe
Payload URLs:
urlhaus.abuse.ch/browse/tag/771…
Payload:
… twitter.com/i/web/status/1…
07 Mar 23
copy & paste +upvote -downvote Gozi targeting Italy 🇮🇹
url->zip->smb->exe
Payload URLs:
🌐 https://t.co/vX802XAAzy
Payload:
📄… https://t.co/fFRmCBdAXE
3.
4.
5.
6.
7.
abuse.ch
@abuse_ch
Here's another reason why you should share malware distribution sites on #URLhaus
We push confirmed malware… twitter.com/i/web/status/1…
We push confirmed malware… twitter.com/i/web/status/1…
11 Feb 23
copy & paste +upvote -downvote Here's another reason why you should share malware distribution sites on #URLhaus ⬇️⬇️⬇️
We push confirmed malware… https://t.co/hUDpuFI64o
abuse.ch
@abuse_ch
Qakbot (aka Qbot) emerging URLhaus now tracks 4 times more active malware distribution sites compared to end of S… twitter.com/i/web/status/1…
21 Oct 22
copy & paste +upvote -downvote Qakbot (aka Qbot) emerging 🔥 URLhaus now tracks 4 times more active malware distribution sites compared to end of S… https://t.co/WH2hN92Yki
abuse.ch
@abuse_ch
Who can label this malware family? 🪲
C2s
http://dixiel22 .top/gate.php
http://dixuip12 .top/gate.php
http://ula… twitter.com/i/web/status/1…
C2s
http://dixiel22 .top/gate.php
http://dixuip12 .top/gate.php
http://ula… twitter.com/i/web/status/1…
21 Sep 22
copy & paste +upvote -downvote Who can label this malware family? 🪲❔
C2s 🔥
http://dixiel22 .top/gate.php
http://dixuip12 .top/gate.php
http://ula… https://t.co/S5bCLYs55U
abuse.ch
@abuse_ch
Dealing with malware is like: "Hey, I have this batch of 50k malware samples. You want them?"
Turns out that 95%… twitter.com/i/web/status/1…
Turns out that 95%… twitter.com/i/web/status/1…
15 Sep 22
copy & paste +upvote -downvote Dealing with malware is like: "Hey, I have this batch of 50k malware samples. You want them?"
👉 Turns out that 95%… https://t.co/gIBGLnek7x
abuse.ch
@abuse_ch
In August 2021, 11'295 (+25% ) malware samples have been shared on MalwareBazaar
Top contributors
2'576… twitter.com/i/web/status/1…
Top contributors
2'576… twitter.com/i/web/status/1…
02 Sep 21
copy & paste +upvote -downvote In August 2021, 11'295 (+25% ⬆️) malware samples have been shared on MalwareBazaar 💪
Top contributors 🏆
2'576… https://t.co/D0pQz6Ur4e
8.
9.
10.
11.
abuse.ch
@abuse_ch
FedEx themed credit card phishing, embedding the phishing URL in a QR code instead of the email body 🪝
sgservicec… twitter.com/i/web/status/1…
sgservicec… twitter.com/i/web/status/1…
14 Aug 21
copy & paste +upvote -downvote FedEx themed credit card phishing, embedding the phishing URL in a QR code instead of the email body 🪝🐟
sgservicec… https://t.co/x38T6babCe
abuse.ch
@abuse_ch
Did you know that there are daily MISP events available for URLhaus, MalwareBazaar and ThreatFox?
URLhaus:
… twitter.com/i/web/status/1…
URLhaus:
… twitter.com/i/web/status/1…
18 Jun 21
copy & paste +upvote -downvote Did you know that there are daily MISP events available for URLhaus, MalwareBazaar and ThreatFox?
URLhaus:
👉… https://t.co/fULll9Dka1
abuse.ch
@abuse_ch
Watch out for malicious VBS and JS files in emails, distributing Dridex (botnet: 40112)
JS:… twitter.com/i/web/status/1…
JS:… twitter.com/i/web/status/1…
03 May 21
copy & paste +upvote -downvote Watch out for malicious VBS and JS files in emails, distributing Dridex (botnet: 40112) 🔥
📑 JS:… https://t.co/xlnsR5oSB7
abuse.ch
@abuse_ch
Malspam with weaponized XLS file distributing #Ostap
Payload on MalwareBazaar:
bazaar.abuse.ch/sample/a2ed32e…
Payloa… twitter.com/i/web/status/1…
Payload on MalwareBazaar:
bazaar.abuse.ch/sample/a2ed32e…
Payloa… twitter.com/i/web/status/1…
15 Oct 20
copy & paste +upvote -downvote Malspam with weaponized XLS file distributing #Ostap 💣
Payload on MalwareBazaar:
👉 https://t.co/mw8V7IiU6Q
Payloa… https://t.co/91qmTetgNq
...but wait! There's more!
1.
fakhright
@fakhright
astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat*
14 Jan 13
copy & paste +upvote -downvote astaghfirullah peng.krim guaaaaaaaa..............a *salto sambil solat* 🙈🙈🙊