Log inSign up
abuse.ch
3,386 posts
Image
user avatar
abuse.ch
@abuse_ch
Fighting malware and botnets
Zurich
abuse.ch
Joined May 2009
299
Following
37.4K
Followers
  • user avatar
    abuse.ch
    @abuse_ch
    Mar 17, 2020
    I've been busy in the past weeks coding on new project. Finally, here it is: Introducing Malwarebazaar! abuse.ch/blog/introduci… 👉 bazaar.abuse.ch #sharingiscaring
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Jun 13, 2022
    We are excited to announce the launch of our most recent platform: YARAify 🥳 Blog post: 👉 abuse.ch/blog/introduci… YARAify platform: 👉 yaraify.abuse.ch Top features: - Live hunt over a large file set - Deploy & share your YARA rules in a structured way - Extensive API
    Hunt for files with custom hunting rules for YARA, telfhash, ClamAV and much more
    Deploy your own YARA rules and hunt for live matches over ten of thousands of files per day
    Share your YARA rules with others in a structured way
  • user avatar
    abuse.ch
    @abuse_ch
    Oct 8, 2021
    URLhaus adds more pressure on threat actors that are abusing the domain name space for distributing malware 👮 Today, we started to notify domain registrars and registries about domains that have been setup by threat actors for the sole purpose of distributing malware 📩🛑
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Feb 23, 2021
    💥 BOOOM 💥 You can now do live malware hunting 🔥 on MalwareBazaar and get notified by email ✉️ or mobile 📱on new hits! You can hunt for: - Tags - Signatures - YARA rules - ClamAV - Vendor detection Oh, before I forget: It's completely free! 🤯 👉 bazaar.abuse.ch/hunting/
    Image
    Image
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Apr 27, 2023
    SERVICE UPDATE | Today, Twitter has revoked our access to their authentication API. The impact is submissions to the abuse.ch platforms cannot be made. We are urgently working to find a different authentication method. Please bear with us - we'll update again
    201K
  • user avatar
    abuse.ch
    @abuse_ch
    Jul 23, 2019
    URLhaus + Virustotal = ❤️ Virustotal is now checking URLhaus for known malware sites. Thanks @virustotal ! virustotal.com/gui/url/7460e3…
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Jan 29, 2020
    Introducing my newest project: I got phished The goal is to notify IT-security representatives about phishing victims within their constituency 📨 👉 igotphished.abuse.ch A big thanks to @jaythl who initiated the project! 👏 For bug reports and feature requests -> DM me
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Mar 8, 2021
    Tired of hunting for IOCs on social media and fighting with different logins across different platforms? I'm happy to announce the newest project of abuse.ch: ThreatFox! 🥳🎉 ThreatFox IOC sharing platform: threatfox.abuse.ch Blog: abuse.ch/blog/introduci…
    Image
    abuse.ch
    abuse.ch - Figthing malware and botnets
    abuse.ch is providing community driven threat intelligence on cyber threats
  • user avatar
    abuse.ch
    @abuse_ch
    Oct 26, 2020
    abuse.ch: Time to move forward. Your help is needed ⛑️ 👉 abuse.ch/blog/moving-fo…
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Nov 16, 2021
    #Emotet has almost doubled its botnet C2 infrastructure in the past 24 hours from 8 active C2s yesterday to 14 active C2s today 🔥🪲 We have also observed an increase of Emotet malspam today 📩 It seems to be very clear that Emotet is firing up its activity! 💥 Be prepared! 🛡️
    Image
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Oct 4, 2021
    The major outage of Facebook, Instagram and WhatsApp apparently causes problems at DNS providers too as the corresponding apps are hammering their resolvers hard 🔥 Facebook is down and the whole internet is having troubles 🤡 Current service status @AdGuard DNS:
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Aug 29, 2023
    Quak 🦆! Goodbye #Qakbot, I hope we won't see you ever again 👋. And this is how it looks like from Feodo Tracker' perspective ⬇️. All #botnet C2s are offline 🛑 feodotracker.abuse.ch/browse/qakbot/ Tango down! 💪
    Feodo Tracker Qakbot botnet C2 tracking
    user avatar
    Spamhaus
    @spamhaus
    Aug 29, 2023
    Qakbot 🦆🤖 takedown!!! Qakbot has been disrupted and dismantled by the FBI following a multinational effort. We will be assisting with the remediation - more info to follow... #malware #takedown #qakbot fbi.gov/news/stories/f…
    54K
  • user avatar
    abuse.ch
    @abuse_ch
    Dec 11, 2021
    Some IOCs related to #Log4j (CVE-2021-44228) and the relevant #Kinsing and #Mirai botnets exploiting it are available here 👇👇👇 Payload URLs (nuking in progress 💣): 🌎 urlhaus.abuse.ch/browse/tag/log… Payloads: 📄 bazaar.abuse.ch/browse/tag/log… Botnet C2s: 🔥 threatfox.abuse.ch/browse/tag/log…
    Image
  • user avatar
    abuse.ch
    @abuse_ch
    Mar 18, 2025
    Have you checked out the new hunting tool yet? We may have mentioned it once or twice already! 😂 And, here it is again!  🔎 Just enter an IPv4, domain, URL, or file hash, and instantly see if it’s been identified on URLhaus, MalwareBazaar, ThreatFox, or YARAify - with just one
    Image
    22K

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
Advertisement
Advertisement