Mikhail Kasimov (@500mk500) 's Twitter Profile
Mikhail Kasimov

@500mk500

Malicious traffic detection system: @maltrail;

Maltrail Demo Page: maltraildemo.github.io;
Maltrail FAQ: bit.ly/3IM9z07

ID: 4820426207

linkhttp://maltrail.github.io calendar_today17-01-2016 07:45:52

7,7K Tweet

4,4K Followers

591 Following

Mikhail Kasimov (@500mk500) 's Twitter Profile Photo

New #osx #amos stealer distribution domain, based on old "Brew" topic. brrewsh\.org raw.brrewsh\.org B: bazaar.abuse.ch/sample/20fac81… V: virustotal.com/gui/file/20fac…

New #osx #amos stealer distribution domain, based on old "Brew" topic.

brrewsh\.org
raw.brrewsh\.org

B: bazaar.abuse.ch/sample/20fac81…
V: virustotal.com/gui/file/20fac…
Mikhail Kasimov (@500mk500) 's Twitter Profile Photo

Initial IOCs from Patchstack article: patchstack.com/articles/criti… gravityapi\.io gravityapi\.org Potentially related domains with very close creation date found by Validin Lookalike mechanism: gravityapi\.ai gravityapi\.co gravityapi\.dev gravityapi\.net

Initial IOCs from <a href="/patchstackapp/">Patchstack</a> article: patchstack.com/articles/criti…

gravityapi\.io
gravityapi\.org

Potentially related domains with very close creation date found by <a href="/ValidinLLC/">Validin</a> Lookalike mechanism:

gravityapi\.ai
gravityapi\.co
gravityapi\.dev
gravityapi\.net
urlscan.io (@urlscanio) 's Twitter Profile Photo

We're launching experimental ML Verdicts on urlscan Pro. Our new machine learning engine automatically classifies scan results as malicious or benign with a likelihood score. Perfect for threat hunting and for noise reduction. Available now on urlscan Pro: urlscan.io/blog/2025/07/1…

We're launching experimental ML Verdicts on urlscan Pro. Our new machine learning engine automatically classifies scan results as malicious or benign with a likelihood score. Perfect for threat hunting and for noise reduction. Available now on urlscan Pro: urlscan.io/blog/2025/07/1…
Mikhail Kasimov (@500mk500) 's Twitter Profile Photo

🧐🤔"BlockNova" topic, described in Silent Push article: shorturl.at/jRUCz has returned me some fresh data to detect: 103.35.189\.107:3000 103.35.189\.107:4000 74.119.194\.205:3000 74.119.194\.205:4000 (hiring.)crostox\.com (apply.|contract.|hiring|support.)waventic\.com

🧐🤔"BlockNova" topic, described in <a href="/silentpush/">Silent Push</a> article: shorturl.at/jRUCz has returned me some fresh data to detect:

103.35.189\.107:3000
103.35.189\.107:4000
74.119.194\.205:3000
74.119.194\.205:4000
(hiring.)crostox\.com
(apply.|contract.|hiring|support.)waventic\.com
Mikhail Kasimov (@500mk500) 's Twitter Profile Photo

298 domains with suchlike content related to #ACR #Stealer panels. E.g. therenuomystores[.]shop --> urlscan.io/result/019832a… Detection: github.com/stamparm/maltr…

298 domains with suchlike content related to #ACR #Stealer panels.

E.g. therenuomystores[.]shop --&gt; urlscan.io/result/019832a…

Detection: github.com/stamparm/maltr…