A sandbox for websites - Find malicious websites and phishing - status.urlscan.io - urlscan.io/blog/ - #threatintel #cybercrime #infosec #web #phishing

Joined October 2016
541 Photos and videos
Pinned Tweet
30 Jul 2025
Today we're launching urlscan Brand AI within our urlscan Pro portal. Brand AI will visually examine websites to determine the name of the brand the website claims to represent, a more robust approach than text-based queries. Read the details in our blog: urlscan.io/blog/2025/07/30/bโ€ฆ
25
90
11,021
New TI report ๐Ÿ“ท Duoyu stands out for its backend-driven flows, tracking identifiers, and distinctive handling patterns. Misconfigurations also provide useful detection opportunities. Dive in ๐Ÿ“ท urlscan.io/pricing/urlscanprโ€ฆ
5
13
1,185
Oriental Gudgeon ("CoGUI") is a structured phishing kit built on reusable components, storage artifacts, and API-driven workflows. Designed for scale and persistence across campaigns. Detection details inside ๐Ÿ‘‡ Public reporting: urlscan.io/blog/2026/06/01/Cโ€ฆ - More on urlscan Pro
8
9
1,280
New TI report ๐Ÿ“ท Chenlun (โ€œOutsiderโ€) is a feature-rich phishing kit using modern web frameworks, verification flows, and anti-bot techniques. A step up in sophistication across Chinese Phishing-as-a-Service ecosystems. Full analysis detections ๐Ÿ“ท urlscan.io/pricing/urlscanprโ€ฆ
9
24
3,830
urlscan.io retweeted
May 21
๐Ÿ‡ธ๐Ÿ‡ฆ ๐Ÿ‡ฎ๐Ÿ‡ท ๐—ก๐—ฒ๐˜„ ๐— ๐—ถ๐—ฑ๐—ฑ๐—น๐—ฒ ๐—˜๐—ฎ๐˜€๐˜ ๐—บ๐—ฎ๐—น๐—ถ๐—ฐ๐—ถ๐—ผ๐˜‚๐˜€ ๐—ถ๐—ป๐—ณ๐—ฟ๐—ฎ๐˜€๐˜๐—ฟ๐˜‚๐—ฐ๐˜๐˜‚๐—ฟ๐—ฒ ๐—ฟ๐—ฒ๐—ฝ๐—ผ๐—ฟ๐˜: ๐Ÿญ,๐Ÿฏ๐Ÿฑ๐Ÿฌ ๐—–๐Ÿฎ ๐—ฆ๐—ฒ๐—ฟ๐˜ƒ๐—ฒ๐—ฟ๐˜€ ๐— ๐—ฎ๐—ฝ๐—ฝ๐—ฒ๐—ฑ ๐—”๐—ฐ๐—ฟ๐—ผ๐˜€๐˜€ ๐Ÿต๐Ÿด ๐—ฃ๐—ฟ๐—ผ๐˜ƒ๐—ถ๐—ฑ๐—ฒ๐—ฟ๐˜€ Over a three-month window, we mapped more than 1,350 active C2 servers operating across 98 infrastructure providers in 14 Middle Eastern countries, covering telecoms, shared hosting, and VPS environments. ๐Ÿ‘‰ Read the full report: hunt.io/blog/middle-east-malโ€ฆ Here's what the data shows: โ†’ A single telecom carrier accounts for nearly 72% of all detected regional C2 activity, most of it tied to compromised customer endpoints rather than provider-level abuse โ†’ C2 infrastructure makes up over 96% of all observed malicious artifacts in the region โ†’ Tactical RMM leads the malware family breakdown with 92 unique C2 IPs, followed by Keitaro TDS (71) and Acunetix (38) โ†’ The malware mix covers a wide range of attack types - IoT botnets (Mozi, Hajime, Mirai), remote access tools (AsyncRAT, Sliver, Cobalt Strike), active scanning (Acunetix), and phishing infrastructure (Gophish, Keitaro TDS) โ†’ Campaigns in the dataset include Eagle Werewolf espionage operations, the DYNOWIPER destructive campaign targeting Poland's energy sector, and RondoDox botnet exploitation infrastructure on Iranian hosting The main takeaway is that malicious infrastructure in the region is not evenly spread. A small set of providers keeps showing up across unrelated campaigns and malware families, which is where the tracking value is. Provider-level visibility is what lets defenders get ahead of that pattern, rather than reacting to individual indicators that rotate daily. Full breakdown, including infrastructure observables, HuntSQL queries, and campaign examples, is in the report ๐Ÿ‘‡ hunt.io/blog/middle-east-malโ€ฆ
14
31
3,028
urlscan.io retweeted
This is a much smaller Chinese phishing framework๐Ÿ‡จ๐Ÿ‡ณ ๐Ÿช™I bet you won't have heard of it before! ๐ŸŒWhat makes this notable is the targeting of Chinese companies by the framework๐Ÿ”Ž ๐ŸŽฏThis is a Pro only report โœ‰๏ธReach out to sales@ if you are not on the pro platform!
New TI report on urlscan Pro ๐Ÿ“ท Flyfish is a lightweight phishing kit built around simple but effective API endpoints. Despite its simplicity, itโ€™s actively used for large-scale victim interaction and data capture. Detection patterns included ๐Ÿ“ท urlscan.io/pricing/urlscanprโ€ฆ
2
4
1,006
New TI report on urlscan Pro ๐Ÿ“ท Flyfish is a lightweight phishing kit built around simple but effective API endpoints. Despite its simplicity, itโ€™s actively used for large-scale victim interaction and data capture. Detection patterns included ๐Ÿ“ท urlscan.io/pricing/urlscanprโ€ฆ
9
28
3,545
urlscan.io retweeted
3
6
19
2,131
urlscan.io retweeted
May 14
๐Ÿšจ NEW RESEARCH: TeamPCP's C2 fallback needs no attacker infrastructure. @wiz_io covered the delivery and flagged some payload behavior (great job!). However, nobody went deeper into the full toolkit itself, the GovCloud targeting, or the infrastructure. We did. Full analysis, IOCs, HuntSQL queries, and MITRE mapping: hunt.io/blog/teampcp-python-โ€ฆ
1
18
41
3,203
Last week we hosted a hands-on workshop at @pivot_con in Mรกlaga. Participants learned how to hunt and cluster web-based phishing activity using our urlscan Pro platform. If you did not manage to get in, just send us a message and we'll give you a private tour of the platform!
1
11
403
New report: Darcula (โ€œMagic Catโ€) is one of the most active phishing frameworks weโ€™re tracking. From API-driven infra to socket-based comms and fake shop deployments, this kit continues to evolve rapidly. Breakdown, detections: urlscan.io/blog/2026/05/11/Cโ€ฆ Full report on urlscan Pro
21
42
3,778
New urlscan report ๐Ÿšจ Weโ€™re kicking off our Chinese phishing series with a deep dive into the Sailor framework. A modular kit leveraging client-side storage for session tracking and victim management at scale. Detection included ๐Ÿ‘‡ urlscan.io/blog/2026/05/04/Cโ€ฆ
9
17
1,934
urlscan.io retweeted
Apr 29
๐Ÿšจ NEW RESEARCH: xlabs_v1 DDoS-for-Hire IoT Botnet Exposed - One Open Directory. An Entire Operation Revealed. hunt.io/blog/xlabs-v1-ddos-fโ€ฆ The operator built a full commercial DDoS-for-hire operation. Tiered pricing, 21 flood variants, competitor-killing routines baked in. Then left the whole toolkit on a public server with no login. Hunt.io AttackCapture tool had it indexed before they noticed. Key findings: - Botnet branded xlabs_v1, operator handle Tadashi, targeting game servers and Minecraft hosts - 21 flood variants including RakNet and OpenVPN-shaped UDP to dodge common filters - TCP/5555 observed open on 4M hosts in the past 180 days, any running ADB is a potential target - ChaCha20 encryption broken via known-plaintext, full nonce reuse across all 16 calls - C2, staging, distribution, and Monero cryptojacking all inside one bulletproof /24 in the Netherlands ๐Ÿ‘‰ Full IOCs, MITRE mapping, and HuntSQL queries: hunt.io/blog/xlabs-v1-ddos-fโ€ฆ
1
12
47
10,352
urlscan.io retweeted
This is going to be huge ๐Ÿงจ ๐Ÿ”ŽMyself and the team worked so hard on these. It is going to uncover and expose the true scale of multiple frameworks Watch this space...
New research drop ๐Ÿšจ We're diving deep into Chinese-language phishing-as-a-service ecosystems powering large-scale global campaigns. From infrastructure to operations, this series uncovers how these platforms scale and evade detection. Starting May 4th: urlscan.io/blog/2026/04/27/Cโ€ฆ
1
8
1,243
This urlscan Pro Threat Intel Report covering Calendly-themed lures is now available on our public blog as well: urlscan.io/blog/2026/04/28/Cโ€ฆ
New urlscan Pro Threat Intel Report: We uncovered 7 distinct phishing kit clusters hiding behind Calendly-themed lures. Same brand, very different tooling & infrastructure. The report includes hunting queries & technical fingerprints for defenders.
3
16
1,508
New research drop ๐Ÿšจ We're diving deep into Chinese-language phishing-as-a-service ecosystems powering large-scale global campaigns. From infrastructure to operations, this series uncovers how these platforms scale and evade detection. Starting May 4th: urlscan.io/blog/2026/04/27/Cโ€ฆ
1
21
61
6,578
urlscan.io retweeted
Apr 11
Apparent WordPress compromise of popular restaurant chain #TGIFridays observed with #clickfix infection chain delivering malicious MSI disguised as "Microsoft Endpoint DLP Module" TGIF? ๐Ÿ‘พ #malware #clickfix @executemalware
5
6
16
1,307
The completion dropdown for our search page is now also available on the community platform on urlscan.io. Enjoy!
6
22
1,478
urlscan.io retweeted
Apr 15
๐Ÿšจ ๐Ÿ‡ท๐Ÿ‡บ We tracked 1,252 active C2 servers across 165 Russian hosting providers over 90 days. Here's what's running inside those networks. C2 traffic accounts for 88.6% of all observed malicious artifacts. The rest splits between malicious open directories (5.3%), phishing infrastructure (4.9%), and public IOCs (1.2%). The hosting concentration is notable: - TimeWeb leads with 311 C2 detections - WebHost1 follows with 140, REG[.]RU with 138 - PROSPERO OOO hosts 80 C2s alongside 30 malicious open directories and 50 phishing sites - Yandex[.]Cloud carries the widest malware diversity: 11 distinct families across 39 C2 endpoints On the malware side: - Keitaro dominates with 587 unique C2 IPs - Hajime (191), Mozi (48), and Mirai (13) show IoT botnet infrastructure is still active - Cobalt Strike, Sliver, and Ligolo-ng are all present across the ecosystem Specific campaigns tied to this infrastructure include Latrodectus via ClickFix on TimeWeb, Lumma Stealer on REG[.]RU, Remcos RAT via SmartApeSG on Hosting Technology LTD, and intrusion activity attributed to Head Mare inside LLC Smart Ape. Full research with Host Radar breakdowns and HuntSQL queries ๐Ÿ‘‡ hunt.io/blog/russian-malicioโ€ฆ #ThreatHunting #ThreatIntelligence #C2 #Malware #CyberSecurity
14
43
4,716
urlscan.io retweeted
โš ๏ธPublic blog post is now live: urlscan.io/blog/2026/04/15/Pโ€ฆ
JavaScript Proxy frameworks are interesting๐Ÿ–ฅ๏ธ ๐Ÿ”Have you detected these being used in any campaigns? Investigating these is tricky but the fingerprints caused are simple to track!๐ŸŽฏ
2
5
1,222
We have just launched the public version of this urlscan Pro Intel Brief, check it out: urlscan.io/blog/2026/04/15/Pโ€ฆ
TAs are weaponising client-side proxy frameworks like Ultraviolet & Scramjet to deliver stealthy phishing campaigns that evade traditional detection. Our latest urlscan Pro report covers techniques, artifacts, and detection strategies for this new threat: urlscan.io/pricing/urlscanprโ€ฆ
5
18
2,532