0xDanielLopez / TweetFeed
TweetFeed collects Indicators of Compromise (IOCs) shared by the infosec community at Twitter. Here you will find malicious URLs, domains, IPs, and SHA256/MD5 hashes.
AI Architecture Analysis
This repository is indexed by RepoMind. By analyzing 0xDanielLopez/TweetFeed in our AI interface, you can instantly generate complete architecture diagrams, visualize control flows, and perform automated security audits across the entire codebase.
Our Agentic Context Augmented Generation (Agentic CAG) engine loads full source files into context on-demand, avoiding the fragmentation of traditional RAG systems. Ask questions about the architecture, dependencies, or specific features to see it in action.
Repository Overview (README excerpt)
Crawler viewTweetFeed Feeds of IOCs posted by the community at Twitter TweetFeed.live | Source code | Feedback Want to integrate with OpenCTI? Now you can! --- --- ☰ Content • Data collected • Some statistics • How it works • Hunting IOCs via Microsoft Defender • Author • Disclaimer :heart: Support the project If you like the project, please consider: • Giving it a star :star: • Invite to a coffee :coffee: :page_facing_up: Data collected Feeds 2026-03-16 17:13:47 (UTC) Today Last 7 days Last 30 days Last 365 days :clipboard: Today ( raw ) :clipboard: Week ( raw ) :clipboard: Month ( raw ) :clipboard: Year ( raw ) Output example Date (UTC) SourceUser Type Value Tags Tweet 2021-08-14 02:26:32 phishunt_io url https://netflix.us2.cards/ #phishing #scam https://twitter.com/phishunt_io/status/1426369619422502917 2021-08-17 12:15:00 TheDFIRReport ip 185.56.76.94 #Trickbot https://twitter.com/TheDFIRReport/status/1427604874053578756 :bar_chart: Some statistics Types | Type | Today | Week | Month | Year | | :--- | :---: | :---: | :---: | :---: | | **:link: URLs** | 21 | 448 | 2193 | 71047 | | **:globe_with_meridians: Domains** | 18 | 360 | 1645 | 45895 | | **:triangular_flag_on_post: IPs** | 3 | 103 | 596 | 23598 | | **:1234: SHA256** | 1 | 6 | 57 | 1766 | | **:1234: MD5** | 2 | 24 | 365 | 3790 | --- Tags | Tag | Today | Week | Month | Year | | :--- | :---: | :---: | :---: | :---: | | **#phishing** | 6 | 186 | 662 | 60836 | | **#scam** | 0 | 13 | 127 | 9415 | | **#opendir** | 0 | 5 | 82 | 792 | | **#malware** | 5 | 15 | 91 | 8848 | | **#maldoc** | 0 | 0 | 0 | 0 | | **#ransomware** | 2 | 10 | 51 | 1076 | | **#banker** | 0 | 0 | 0 | 6 | | **#AgentTesla** | 0 | 0 | 4 | 208 | | **#Alienbot** | 0 | 0 | 0 | 0 | | **#AsyncRAT** | 0 | 2 | 28 | 2129 | | **#Batloader** | 0 | 0 | 0 | 0 | | **#BazarLoader** | 0 | 0 | 0 | 0 | | **#CobaltStrike** | 0 | 2 | 7 | 9501 | | **#Dcrat** | 0 | 0 | 0 | 364 | | **#Emotet** | 0 | 0 | 0 | 0 | | **#Formbook** | 0 | 0 | 58 | 578 | | **#GootLoader** | 0 | 0 | 0 | 0 | | **#GuLoader** | 0 | 0 | 0 | 56 | | **#IcedID** | 0 | 0 | 0 | 0 | | **#Lazarus** | 0 | 0 | 10 | 153 | | **#Lokibot** | 0 | 0 | 0 | 155 | | **#log4j** | 0 | 0 | 0 | 4 | | **#Log4shell** | 0 | 0 | 0 | 0 | | **#Njrat** | 0 | 6 | 22 | 986 | | **#Qakbot** | 0 | 0 | 0 | 933 | | **#Raccoon** | 0 | 0 | 0 | 3 | | **#RedLine** | 0 | 0 | 0 | 148 | | **#Remcos** | 0 | 5 | 24 | 2780 | | **#RaspberryRobin** | 0 | 0 | 0 | 0 | | **#Spring4Shell** | 0 | 0 | 0 | 0 | | **#SocGolish** | 0 | 0 | 0 | 7 | | **#Ursnif** | 0 | 0 | 0 | 0 | --- Top Reporters (today) | Number | User | IOCs | | :--- | :---: | :---: | | **#1** | urldna_bot | 16 | | **#2** | skocherhan | 6 | | **#3** | malwrhunterteam | 4 | | **#4** | FABO97662188 | 4 | | **#5** | papa_anniekey | 2 | | **#6** | @Phish_Destroy | 6 | | **#7** | @CarlyGriggs13 | 4 | | **#8** | @urldna_bot | 2 | | **#9** | smica83 | 2 | | **#10** | tial_cl | 2 | :question: How it works? Search tweets that contain certain tags **or** that are posted by certain *infosec* people. Tags being searched *(not case sensitive)* Also search Tweets posted by *(these are trusted folks that sometimes don't use tags)* **TweetFeed list** :mag: Hunting IOCs via Microsoft Defender **1. Search hashes with tweets feed** **2. Search with tweets feed** **3. Search and with tweets feed** :bust_in_silhouette: Author • **Daniel López** :pushpin: Disclaimer Please note that all the data is collected from Twitter and sorted/served here as it is on **best effort**. I have tried to tune as much as possible the searches trying to collect only valuable info. However please consider making your own analysis before taking any action related to these IOCs. Anyway feel free to **reach me out** or to provide any kind of **feedback** regarding any contribution or suggestion. By the community, for the community.