MalwareBazaar will now parse shell scripts automatically and will try to identify any payload URLs present in it ππποΈ This will make your life easier when hunting for Linux/Unix malware such as #Mirai and #Gafgyt πͺ
Here's an example:
π https://bazaar.abuse.ch/sample/ec46f105b049d6674acbf45639883623f2f1cb3eed50eedb4b0e25a27a7b67e2/
=> More informations about this toot | More toots from abuse_ch@ioc.exchange
@abuse_ch Now that's a great feature. Love it!
=> More informations about this toot | More toots from thomrstrom@triangletoot.party This content has been proxied by September (3851b).Proxy Information
text/gemini