urlquery's profile picture. http://urlquery.net - a service for detecting and analyzing malicious websites.

urlquery

@urlquery

http://urlquery.net - a service for detecting and analyzing malicious websites.

#phishing For the last weeks there as been quite a few domains detected related to #tycoon at least a few hundred daily. Mostly towards Microsoft

urlquery's tweet image. #phishing
For the last weeks there as been quite a few domains detected related to #tycoon at least a few hundred daily. Mostly towards Microsoft

This was a triumph. I'm making a note here: HUGE SUCCESS.


urlquery reposted

and another ~10k are being send today. Keep a eye out on this urlquery.net/search?q=submi… to find urls with a sample giving 1+ Positive as a minimum The hits are giving a strong indication of malware/source does being shared for either educational purposes or malicious intend!

banthisguy9349's tweet image. and another ~10k are being send today. Keep a eye out on this urlquery.net/search?q=submi… to find urls with a sample giving 1+ Positive as a minimum

The hits are giving a strong indication of malware/source does being shared for either educational purposes or malicious intend!

5k more github urls being send! awesome work @urlquery



urlquery reposted

5k more github urls being send! awesome work @urlquery

In collab with @urlquery 9.6k github urls are being send that are potentially used for malicious purposes! Detection rules are hunted over the urls/samples that are discovered! You can find the datastream under the following query/tag: urlquery.net/search?q=submi…

banthisguy9349's tweet image. In collab with @urlquery 9.6k github urls are being send that are potentially used for malicious purposes! Detection rules are hunted over the urls/samples that are discovered!

You can find the datastream under the following query/tag: urlquery.net/search?q=submi…


urlquery reposted

In collab with @urlquery 9.6k github urls are being send that are potentially used for malicious purposes! Detection rules are hunted over the urls/samples that are discovered! You can find the datastream under the following query/tag: urlquery.net/search?q=submi…

banthisguy9349's tweet image. In collab with @urlquery 9.6k github urls are being send that are potentially used for malicious purposes! Detection rules are hunted over the urls/samples that are discovered!

You can find the datastream under the following query/tag: urlquery.net/search?q=submi…

urlquery reposted

Did you know that you can Utileze @urlquery to search for body results? urlquery.net/search?q=%22po… cc: @RacWatchin8872

banthisguy9349's tweet image. Did you know that you can Utileze @urlquery to search for body results? 

urlquery.net/search?q=%22po…

cc: @RacWatchin8872

More Domains showing similar behavior!! hxxps[://]lab[.]adversarygroup[.]com/loader2[.]ps1 hxxps[://]travelwithandrew[.]xyz/assets/in[.]txt hxxps[://]restoindia[.]me/recaptcha/in[.]txt hxxps[://]marimarbahamas[.]me/downloads/in[.]txt urlscan.io/search/#page.t…

salmanvsf's tweet image. More Domains showing similar behavior!! 

hxxps[://]lab[.]adversarygroup[.]com/loader2[.]ps1
hxxps[://]travelwithandrew[.]xyz/assets/in[.]txt
hxxps[://]restoindia[.]me/recaptcha/in[.]txt
hxxps[://]marimarbahamas[.]me/downloads/in[.]txt

urlscan.io/search/#page.t…


Make your browser look like a sandbox and you'll get free anti-phishing

urlquery's tweet image. Make your browser look like a sandbox and you'll get free anti-phishing

urlquery reposted

Check out the new blog I wrote on #Gabagool AiTM Phishing we discovered at @TRACLabs_ 🐟 targeting corporate and government employees. medium.com/@traclabs_/ait…


urlquery reposted

#lummastealer is still heavily using b-cdn[.]net domains IOC's hxxps://privatebin.net/?d92c797cbe6e4c07#GZwqvzUKVzRRQrr1CuVLLKwXFQVdAQwAy1BV2HJk1dB2

banthisguy9349's tweet image. #lummastealer is still heavily using b-cdn[.]net domains

IOC's
hxxps://privatebin.net/?d92c797cbe6e4c07#GZwqvzUKVzRRQrr1CuVLLKwXFQVdAQwAy1BV2HJk1dB2

urlquery reposted

I have had a big pleasure exploring @urlquery dataflow and existing IDS/YARA rules. I have used scraping methods in order to send IOC's/malware towards @abuse_ch and I am willing to share my hunting rules in the following bin. privatebin.net/?150eba485218d…


urlquery reposted

Secret sauce how i ended up @ this ransomware IOC. urlquery.net/search?q=senso… within @urlquery you have the ability to scan URLS but also IDS/YARA rules get triggered on the file download. This is very essential to hunt malicious files.

banthisguy9349's tweet image. Secret sauce  how i ended up @ this ransomware IOC.
urlquery.net/search?q=senso…
within @urlquery you have the ability to scan URLS but also IDS/YARA rules get triggered on the file download. This is very essential to hunt malicious files.

#ransomware IOC 107.175.75.38 was observed today (now taken down it seems) Malware urls / hash can be found here urlquery.net/report/19eb09f…

banthisguy9349's tweet image. #ransomware IOC 107.175.75.38 was observed today (now taken down it seems) 

Malware urls / hash can be found here
urlquery.net/report/19eb09f…


Looking for sites using coin-hive? urlquery.net/search?q=%22ne… or sites which uses a specific key: urlquery.net/search?q=Yq2af…

urlquery's tweet image. Looking for sites using coin-hive?
urlquery.net/search?q=%22ne…
or sites which uses a specific key:
urlquery.net/search?q=Yq2af…

Updates! More info added to the response data (alerts, hash). Search is back online.. (and lots of backend stuff) urlquery.net/search?q=89060…

urlquery's tweet image. Updates! More info added to the response data (alerts, hash). Search is back online.. (and lots of backend stuff) urlquery.net/search?q=89060…

Thanks to all asking to support or help!


Sorry for the downtime! Site is now up and running again.


urlquery.net/report.php?id=… Eval #1, still targeting github. Transaction "GET /h.js?dc953aef17756888ea29a1bc39528010" is the ghost server.


Loading...

Something went wrong.


Something went wrong.