forked from stamparm/maltrail
-
Notifications
You must be signed in to change notification settings - Fork 0
/
adwind.txt
2471 lines (1992 loc) · 60.3 KB
/
adwind.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
# Copyright (c) 2014-2024 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission
# Aliases: AlienSpy, Frutas, jFrutas, Unrecom, Sockrat, JSocket, jRat, sambaspy, sambaspyrat
# Reference: https://www.secureworks.com/blog/spam-campaign-distributes-adwind-rat
euforiafryz.pl
pepepepe.myvnc.com
millzjsocsingwi80gm.duckdns.org
milzwiregma.no-ip.biz
edebiyazarlar.com
kulturatesesi.com
# Reference: https://malwr.com/analysis/MjAwMGIwMmU0Y2Q4NDkzOGExOTRhNDQ5YWY1ODkxZGI/
uploadp2p.publicvm.com
# Reference: https://otx.alienvault.com/indicator/file/72ccbfa43b24d291ff34941ef3a61c61016650189125221ef769a910b02878e3
repair.sytes.net
cvpimddvt.sytes.net
# Reference: https://abuse.ch/downloads/blog/adwind_domains_20170828.txt
1323.dvrcam.info
1329.mypsx.net
1330.ddnsking.com
1331.ddnsking.com
1332.bounceme.net
1333.hopto.org
1990.nflfan.org
1suser.ddns.net
2016today.duckdns.org
2112.bounceme.net
achyne.publicvm.com
alienware.ddns.net
alienware-pc.loginto.me
amarachi.hopto.org
amazongifts.ddns.net
artwell8.hopto.org
asderman.no-ip.org
asiatravelagency.ddns.net
asorock.mooo.com
benx234.ddns.net
blackhills.ddns.net
blast.ddns.net
bombing212.ddns.net
bomira.ddns.net
carlos88.ddns.net
carlosluize88.zapto.org
cartolarepresentacoes.com.br
charlesdukem.chickenkiller.com
chikazz.ddns.net
chriswork999.ddns.net
chuksthedon.duckdns.org
cjpufffy.hopto.org
code203.ddns.net
coneptor.qarallax.com
controlx.ddns.net
controlxx.ddns.net
dam5i6.linkpc.net
davvid3948.ddns.net
dehaizegroup35.hopto.org
dev.null.vg
dnso.ddns.net
doingtracks.duckdns.org
donaldroberts2014.duckdns.org
dongabby.hopto.org
donmark22.myddns.rocks
donsea.hopto.org
dubaiexchange.dynu.net
ekehken.myddns.rocks
ellatrujillo.com
eni-procurement.info
essztednsbk.ddns.net
exporttaipei.publicvm.com
express4.dynns.com
faridaminmohamm.hopto.org
fetch.duckdns.org
ghostmoney1.hopto.org
ghostmoney2.ddns.net
ghostmoney3.dnsdojo.com
goodjob88.ignorelist.com
googlemapsup.ddns.net
guvencingiller.com
gw1001099.chickenkiller.com
gw1001099.duckdns.org
gypsypy.duckdns.org
hajimusa.ddns.net
importloggm.duckdns.org
indominestuff33.hopto.org
infocolornido.publicvm.com
infotradelinks.ddns.net
isaijra52elizgewigm.duckdns.org
itumobig.ddns.net
jackboy7204.zapto.org
jaybrizzy.gotdns.ch
jbpreshandes5gm1906.duckdns.org
jeffe231.ddns.net
jeremizo888.ddns.net
jhomeland.ddns.net
johnevan227.ddns.net
jra52prealiyoundogm.duckdns.org
jry1234.ddns.net
jsoktin.sytes.net
justyjohnxplodes.ddns.net
kaycee7.ddns.net
kenxx.ddns.net
kingdon.dynu.net
kurtangle083.publicvm.com
lagos042.ddns.net
lashy.ddns.net
lastbornk1.ddns.net
lawpush.ddns.net
lcannex.ddns.net
macdanielo.hopto.org
manzorro.duckdns.org
mariopuzo.ddns.net
markowen.duckdns.org
markscot.ddns.net
mbolo2017.hopto.org
mickyjakey.blogsyte.com
moneyghost.ddns.net
moorexx.hopto.org
morggy11.ddns.net
mrcapable01.publicvm.com
mropera12.no-ip.biz
ms15hinet.publicvm.com
ninja-445.ddns.net
nono198011.ddns.net
nonomee2017.ddns.net
obi234.ddns.net
obi333.ddns.net
obilosgini.ddns.net
officebrighty.ddns.net
online1.mywire.org
onlything4now.ddns.net
ourjra52fullexchgm.duckdns.org
owen6000.hopto.org
palletbush.hopto.org
panini101.chickenkiller.com
pharhmonk1.hopto.org
phererol12.ddns.net
phone2347.ddns.net
pjizzy.hopto.org
pool0852.hopto.org
presjra52opdoxgm.duckdns.org
prince.hackermind.info
r00tshit.ddns.net
r00tziby.ddns.net
reversebaglanti.com
robbieadanfo.ddns.net
robinjmcca.ddns.net
ronytazz2121.ddns.net
scar231.zapto.org
securitypoint.ddns.net
selfmademan2.ddns.net
selfmademan.ddns.net
shadoweye1.ddns.net
shittu09.hopto.org
sidney212.ddns.net
sill.no-ip.biz
sinslave.damnitjim.xyz
softcode2017.hopto.org
songs.linkpc.net
steve654321.ddns.net
svchost.publicvm.com
talentino.ddns.net
teamoluwa.ddns.net
tonychucks96.hopto.org
tonystark001.publicvm.com
trustkemi.duckdns.org
unblocker.bounceme.net
unknowjbireestagm.duckdns.org
unknunon878.chickenkiller.com
vyperps.no-ip.biz
wallstsxer.hopto.org
wongchin11.ddns.net
workstation-spartan.ddns.net
www.creativeforwardings.cf
www.jrocketmassive.cf
www.malaika-jp.com
www.roofmantf.cf
xsubin3310.sytes.net
yadangz.ddns.net
# Reference: https://www.hybrid-analysis.com/sample/4f65cd98a90fc9ec7d8a5bb1087758f6c89251d365479c0c2429d023b6a732c2?environmentId=100
masterentity.cf
# Reference: https://www.threatminer.org/report.php?q=KL_AdwindPublicReport_2016.pdf&y=2016
11111111.noip.me
24rinces.no-ip.biz
abdav21.ddns.net
abudon1990.no-ip.org
abudon22.no-ip.info
abusite11.ddns.net
abyugos.no-ip.info
abyugos0.no-ip.info
achuprn.ddns.net
admin50.no-ip.org
admin8090.no-ip.org
admin90.no-ip.info
adolfo196938.ddns.net
agary917.ddns.net
aisulu.ddns.net
aisulu.ddns.net
ajeolokun.ddns.net
akwotie.ddns.net
albertfrankie.no-ip.org
alicejav777.ddns.net
alicejav777.duckdns.org
alien10socket.ddns.net
alien12socket.ddns.net
alien15socket.ddns.net
alien17socket.ddns.net
alien19socket.ddns.net
alien1socket.ddnsking.com
alien4socket.gotdns.ch
alien6socket.ddns.net
alien9socket.ddns.net
alwadwte.ddns.net
anglekeys.ddns.net
anthonywilkinson10.ddns.net
aptsite.ddns.net
audreysaradin.no-ip.org
avprojets.no-ip.biz
ayomide1.ddns.net
ayomide123.ddns.net
backconnect123.ddns.net
badmanthing.ddns.net
banban66.ddns.net
baronbreeze.ddns.net
barratty.ddns.net
basketmain1.duckdns.org
basketxrtz.ddns.net
ben770.ddns.net
benabangwu.linkpc.net
biafra147.ddns.net
biggestchurch.ddns.net
biggiechurch.ddns.net
biggymoney01.no-ip.biz
biggymoney03.no-ip.biz
biggymoney03.no-ip.biz
biggymoney2.no-ip.biz
blessingonblessings.dnsfor.me
blessingonblessings.ufcfan.org
bms123.twilightparadox.com
bongotedllc.no-ip.org
brownvictor.ddns.net
bsmarket.ddns.net
budapest.ddns.net
budapest89.hopto.me
bugattiboss.servehttp.com
bullgard.ddns.net
calito888.ddns.net
carlos1388.ddns.net
ceo.gotdns.ch
ceoceocompany.gotdns.ch
chadin.serveftp.com
chewc47.ddns.net
chiefonodugo.ddns.net
chima147.linkpc.net
chklagos.no-ip.biz
chris101.ddns.net
chriswoolmer00.no-ip.info
chriswork99.ddns.net
cjfitness.ddns.net
clemens.dynns.com
coralgroups.no-ip.biz
correctip.noip.me
crest01.serveftp.com
crest02.serveftp.com
crested01.serveftp.com
crested01.serveftp.com
damuk1.ddns.net
dave1033.ddns.net
dellboy11.ditchyourip.com
dellboy13.dnsiskinky.com
dellboy15.couchpotatofries.org
dellboy16.eating-organic.net
dellboy17.quicksytes.com
dellboy17.quicksytes.com
dellboy18.securitytactics.com
deprueba1.no-ip.org
deprueba1.no-ip.org
destinynnam.ddns.net
dish-darkcomet2.linkpc.net
divinee.no-ip.biz
divinemove.ddns.net
doingtracks.ddns.net
donhamza.no-ip.org
donorder.ddns.net
dsfgc.ddns.net
dydx69.ddns.net
egbowanted2js.ddns.net
egbowantedjs.ddns.net
egbowantedjs.fishdns.com
egede.no-ip.biz
egombute.duckdns.org
egombute.no-ip.biz
emekau2002.ddns.net
emenike.no-ip.info
escobar.serveftp.com
evanovik.ddns.net
ewillsin.ddns.net
father60.bounceme.net
felbankgmailjs.no-ip.info
felixres015js.zapto.org
felixresult.no-ip.org
filezilla.no-ip.biz
fingers.noip.me
flexyou.chickenkiller.com
floffman.linkpc.net
floffman11.no-ip.org
focusloa.ddns.net
francemaes15.duckdns.org
franklin49.ddns.net
frankwoodsales.ddns.net
froidthefucker.ddns.net
fulga01.ddns.net
gabito234.serveftp.com
galaxymoni.ddns.net
geogelewis90.ddns.net
georgea.serveftp.com
gist.no-ip.info
gmoneydns.duckdns.org
godwin231.zapto.org
godwin4real.ddns.net
goodloves.ddns.net
goods11.ddns.net
goooodymegma.no-ip.org
gta2.ddns.net
harry150.ddns.net
harryaleandro.ddns.net
hdllsy11.no-ip.org
hedie1979.no-ip.org
henrry747.serveminecraft.net
henrygalaxy.publicvm.com
herura.ddns.net
hisandu.ddns.net
holymoney.crabdance.com
hustler.no-ip.org
hydrabad-ur.ddns.net
ifeanyi147.ddns.net
igbankwuruns.no-ip.info
ike-jsocket.publicvm.com
importantloggmal.no-ip.biz
importloggm.duckdns.org
indologisticsltd.no-ip.biz
integralhcs.no-ip.biz
intergralhcs.no-ip.biz
iykeben00.no-ip.info
jacobjsockresyah.no-ip.info
jacobremittance.duckdns.org
jadoltd.ddns.net
jagas21.ddns.net
jamescage112.no-ip.biz
javgretest015.chickenkiller.com
jayson2j.no-ip.org
jcures.serveftp.com
jegs.ddns.net
jesus11.ddns.net
jgabi.serveftp.com
jidespa0024yahjs.no-ip.org
jiokekachi.ddns.net
jjsmits7.serveftp.com
joeban.chickenkiller.com
jonnybary.no-ip.biz
jry123.ddns.net
jsocserveronline.read-books.org
jsucket.hackermind.info
judalien.ddns.net
jupita10.ddns.net
just2015.ddns.net
justice.linkpc.net
justicebro.linkpc.net
justics.no-ip.org
justicsbro.no-ip.org
justmealone.ddns.net
justnd2001.no-ip.biz
justyjohnxplodes.ddns.net
jvaoluwade.ddns.net
kane2244.ddns.net
keithoffman25.ddns.net
kifego.servehalflife.com
kingsman.no-ip.org
kipapos.gotdns.ch
kissfromarose.ddns.net
klasik101.ddns.net
klydest.ddns.net
kokoman.no-ip.biz
kuom.ddns.net
lagostj.servebeer.com
lashsecurities.ddns.net
lawrex.publicvm.com
layziebone009.ddns.net
leonardomateus131.ddns.net
leosplint86.ddns.net
link2bros.ddns.net
link2bross.ddns.net
linsom05.noip.me
lisalove.myftp.biz
livesyn03.midexim.com
loandept227.ddns.net
loandept2281.ddns.net
logisticsltd.no-ip.biz
madman1.ddns.net
magabox126.ddns.net
mainlandbridge.ddns.net
manbks123.ddns.net
mariopuzo.ddns.net
mascott.ddns.net
masterchris211.ddns.net
masterchris221.ddns.net
mavado.serveblog.net
max1239.ddns.net
mcvin.corotext.com
mega123b.ddns.net
michael22244.ddns.net
mikey0147.ddns.net
mikkyserial.redirectme.net
millzjsoctrinwi80gm.duckdns.org
money12.from-ny.net
money12.from-ok.com
moneyboss.ddns.net
moneycee.ddns.net
moneymind.ddns.net
moore11.no-ip.info
morval.ddns.net
mrmoney.no-ip.biz
mropera12.no-ip.biz
mukor.ddns.net
munachim.linkpc.net
muratozkan.ddns.net
myifyboy.serveftp.com
mypres001.serveftp.com
myyveon.ddns.net
nbw09o.gotdns.ch
newbj.no-ip.biz
nickre015jsock.duckdns.org
nikresut015js.no-ip.org
nikresut015js.zapto.org
nklove66.no-ip.info
nonnykey.ddns.net
nono147.ddns.net
oba147.ddns.net
obaniko1111.ddns.net
obicharls.redirectme.net
officetartousi.no-ip.biz
ogawilli.collegefan.org
okoro.ddns.net
okpole123.ddns.net
okwychrist2004.gotdns.ch
olavroy4.ddns.net
olavroy44.ddns.net
omaricha.no-ip.org
ome.no-ip.info
onlything4now.ddns.net
onyechina.ddns.net
opendoors.myftp.org
otimmo.ddns.net
ottimo.ddns.net
otunba.ddns.net
panel2.collegefan.org
passmore1.publicvm.com
perfomiracles247.duckdns.org
peter123456.ddns.net
phcity2090.bounceme.net
philsa.ddns.net
plainview.duckdns.org
plainview.myvnc.com
pompin02.serveftp.com
ppppppp12.ddns.net
prince24.ddns.net
prince240.no-ip.biz
professor.myvnc.com
psarda.ddns.net
quaver.publicvm.com
rayman.ddns.net
reversebaglanti.com
rmg-20.ddns.net
roadmaster2013.ddns.net
rx450.ddns.net
salesexport.sytes.net
saleshore201.serveblog.net
sambahs.ddns.net
septt.dvrcam.info
serialcheck55.serveblog.net
settlement.ddns.net
shadowmek.ddns.net
shadowmekz.ddns.net
silverback.noip.me
smart12456.ddns.net
songs.linkpc.net
spa1dingdiljayah.no-ip.biz
star01.ddns.net
starboy.noip.me
starboy.ufcfan.org
stevemartins02.no-ip.biz
stitatn.no-ip.org
swift.ddns.net
tanwilliam.ddns.net
taraba111.gotdns.ch
tcheckk.ddns.net
tchecks.ddns.net
tetetes2222.chickenkiller.com
theman111.ddns.net
thisreason.ddns.net
tiwamade.ddns.net
toba123.ddns.net
tojaxx.ddns.net
tonychucks.chickenkiller.com
toolsoffice.ddns.net
tpalmer1955.ddns.net
trusplus111.gotdns.ch
ucnas2008.ddns.net
uniteknolog.ddns.net
uniteknolog.duckdns.org
upperway60.no-ip.org
upright2.no-ip.org
upright22.no-ip.org
uyu.webhop.me
valchijioke.publicvm.com
vasocserver.read-books.org
vaspakou.ddns.net
versionfive.ddns.net
vivipas.ddnsking.com
vmoney.ddns.net
web2016web.webhop.me
wellspring4life.ddns.net
whichway.ddns.net
willyd01.ddns.net
wlkd.myftp.org
workshopjs.ddns.net
workshopjs.fishdns.com
writtings.ddns.net
xsubin3310.sytes.net
ypfbackup.mylenovoemc.com
zivva007.ddns.net
zoee.noip.me
zubi009.serveftp.com
# Reference: https://twitter.com/Racco42/status/1053747018835869696
wellcomehome.duckdns.org
# Reference: https://twitter.com/Racco42/status/1097498140452810752
flexio.ddns.net
# Reference: https://twitter.com/Racco42/status/1106671338775814149
goldenshoe.ddns.net
# Reference: https://twitter.com/neonprimetime/status/958078465252712448
vvrhhhnaijyj6s2m.onion.top
# Reference: https://twitter.com/neonprimetime/status/993594473375588352
oluwadey231.zapto.org
# Reference: https://twitter.com/ps66uk/status/1097845468816687105
joewhizz.duckdns.org
# Reference: https://twitter.com/pancak3lullz/status/1068534966898839552
godslove.ddns.net
# Reference: https://twitter.com/ViriBack/status/1089338471091712001
q9999.ddns.net
# Reference: https://twitter.com/malware_traffic/status/917487556455010304
103.68.223.153:6890
# Reference: https://twitter.com/VK_Intel/status/1079681130771689472
frontier222.duckdns.org
# Reference: https://twitter.com/_SecJesus/status/1016678994366877697
slimy.duckdns.org
# Reference: https://twitter.com/Ring0x0/status/900075907548839936
89.35.228.242:4781
# Reference: https://twitter.com/malware_traffic/status/790346116835385344
boscpakloka.myvnc.com
# Reference: https://twitter.com/MalwareConfig/status/693588665788932096
tobytori18.myftp.org
# Reference: https://twitter.com/MalwareConfig/status/644624264239415296
jvupdate.dynamic-dns.net
# Reference: https://twitter.com/Racco42/status/1116788270007037952
# Reference: https://app.any.run/tasks/c19017e3-75ec-4b45-ba4f-4f56bbf58ca8
185.244.29.102:2556
# Reference: https://twitter.com/MalwareConfig/status/931684471992135680
hard.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748754895767908352
vantira.no-ip.biz
# Reference: https://twitter.com/MalwareConfig/status/748754830357700608
yosefmahmud95478.no-ip.biz
# Reference: https://twitter.com/MalwareConfig/status/748754786917289984
erasmuspor.duckdns.org
# Reference: https://twitter.com/JayTHL/status/1141347511694741505
waytoomuchparties1.com
fedex.itemdb.com
uspslabel.itemdb.com
# Reference: https://twitter.com/Bank_Security/status/1145935816650350593
# Reference: https://app.any.run/tasks/79248157-36f0-410f-8102-91614cc06dd2/
185.140.53.14:5050
# Reference: https://pastebin.com/S4ggik78
goodfellas2019.ddns.net
graceofgood.hopto.org
metalin.ddns.net
ogaemma.duckdns.org
richardavis.duckdns.org
# Reference: https://twitter.com/coderippers/status/1154036702152761345
saka1.ddns.net
# Reference: https://twitter.com/James_inthe_box/status/1160942568487567360
# Reference: https://app.any.run/tasks/127d99d5-3ee4-41cb-a26e-b9ae031a4112/
pluginsrv.duckdns.org
37.48.92.195:1350
67.207.93.17:7744
# Reference: https://twitter.com/de_aviation/status/1097547526763433985
checkogauzor.duckdns.org
dxyasser0.linkpc.net
flexio.ddns.net
goodattack.ddns.net
goodfellas2019.ddns.net
graceofgood.hopto.org
metalin.ddns.net
morelogs2019.duckdns.org
ogaemma.duckdns.org
richardavis.duckdns.org
slimmy1.duckdns.org
snopsd.duckdns.org
sukepatel101.ddns.net
unknownsoft.hopto.org
# Reference: https://twitter.com/reecdeep/status/1170984733511045121
# Reference: https://app.any.run/tasks/774e7417-ce26-4471-835a-6524b986dfcf/
79.134.225.83:7075
165.22.129.173:7756
galakhov.duckdns.org
pluginsrv1.duckdns.org
# Reference: https://twitter.com/wwp96/status/1171090871535755264
# Reference: https://app.any.run/tasks/2152b87a-0c8d-4f1e-a195-69d7544ef572/
185.203.116.78:1010
# Reference: https://unit42.paloaltonetworks.com/the-legend-of-adwind-a-commodity-rat-saga-in-eight-parts/
# Reference: https://www.kaspersky.com/blog/adwind-rat/11252
adwind.com.mx
unrecom.net # UnReCoM RAT
alienspy.net # AlienSpy
jsocket.org # JSocket
unknowsoft.com
jconnectpro.info # jConnectPro
unknowncrypter.co # UnknownCrypter
jbifrost.com # JBifrost
# Reference: https://twitter.com/Racco42/status/983634634151026688
newisajrat.duckdns.org
# Reference: https://any.run/report/a4bb70fb8fbb09d86e3529329b651de1677d1f8bec9b9fe324d22b797c1e2493/fb061418-d173-4a35-97eb-1f55e39e4f74
103.125.191.152:7777
103.125.191.152:4040
# Reference: https://app.any.run/tasks/600106b9-844f-4321-8c2b-3726853ff132/
hustle4eva1.sytes.net
hustle4eva2.3utilities.com
194.5.98.19:8881
# Reference: https://app.any.run/tasks/57d385a6-d464-4ae2-b764-9dcabe301d47/
# Reference: https://app.any.run/tasks/7b6da450-57c0-43f5-85fc-28942ddaf4a0/
rootsec.publicvm.com
172.111.141.34:33
# Reference: https://app.any.run/tasks/2adfe124-4d95-4be5-8d73-0e52c1c73b6f/
# Reference: https://app.any.run/tasks/41ed1be7-3a73-4e97-a46d-d491e2d4b3be/
103.125.191.152:7777
# Reference: https://app.any.run/tasks/0764b917-12f4-484d-8ff5-cde26bc42355/
joeiyke22.duckdns.org
79.134.225.121:7442
# Reference: https://app.any.run/tasks/3e41a622-1010-4f42-8fe1-2838cd95c292/
respainc.duckdns.org
79.134.225.99:4379
# Reference: https://app.any.run/tasks/c6fc3d14-00a0-461e-89c4-9212d5f2cb87/
chance2019.ddns.net
194.5.98.37:20131
# Reference: https://twitter.com/wwp96/status/1186369055642607616
tradcan.duckdns.org
185.165.153.150:4145
# Reference: https://pastebin.com/29uSdMAk
# Reference: https://app.any.run/tasks/6272b39e-7fea-4134-819e-6d3b6b5a0d2b
# Reference: https://www.virustotal.com/gui/file/7a01202131c133a5f78134f264383e827a68164a05e5927da485527da00f8b32/detection
0000rrrvvv.duckdns.org
addahost.ddns.net
lexd.duckdns.org
respainc.duckdns.org
# Reference: https://twitter.com/wwp96/status/1192098993158918145
# Reference: https://app.any.run/tasks/4c70e0e0-ce08-4bd8-ae00-77791545807f/
95.213.195.71:3999
mamased.duckdns.org
# Reference: https://twitter.com/JayTHL/status/1194068036396945409
# Reference: https://www.virustotal.com/gui/ip-address/185.140.53.90/relations
185.140.53.90:8585
dbanks.duckdns.org
# Reference: https://app.any.run/tasks/ee9dd5cd-a707-42a1-b300-6c9cc10cfcda/
powerpower19.duckdns.org
# Reference: https://twitter.com/wwp96/status/1199055385073737728
# Reference: https://app.any.run/tasks/14341c9a-57ab-4cca-ae4f-25bc5576c918/
198.50.217.185:1988
# Reference: https://twitter.com/wwp96/status/1199412810545090560
# Reference: https://app.any.run/tasks/bd69d3e3-4981-4843-91ed-3c4032c3e348/
79.134.225.101:1994
gudluck19.duckdns.org
# Reference: https://twitter.com/JayTHL/status/1199367622896357380
216.38.2.206:5252
mirabk.duckdns.org
# Reference: https://any.run/malware-trends/adwind
1gstemos.duckdns.org
avt.duckdns.org
bytelop4902.ddns.net
cash001.duckdns.org
ceodon1.ddns.net
fishecthinker.ddns.net
info1.duckdns.org
ipvhosted.duckdns.org
labelinfo.dubya.us
mansa19ke.ddns.net
money1234.duckdns.org
moran101.duckdns.org
mrmarkangel.duckdns.org
onelove03.duckdns.org
slimyuyo.duckdns.org
tecklink.publicvm.com
thompson62.ddns.net
wasjar.dynu.net
# Reference: https://any.run/malware-trends/adwind
# Reference: https://www.virustotal.com/gui/file/298adda417fab32b1cb54c2ea841659c5f9ff24881a03383c49276516e587cc8/detection
verified.duckdns.org
# Reference: https://any.run/malware-trends/adwind
# Reference: https://www.virustotal.com/gui/file/4556c57ecdf0e6cca993a84702e9fd25b5775a38d920bb4a93a21367c3eed825/detection
79.134.225.92:4040
# Reference: https://www.virustotal.com/gui/file/8931addad269815939959d2edfd3fb94df5af596bc84ba8280b14ad79291a6fe/detection
79.134.225.92:7890
# Reference: https://any.run/malware-trends/adwind
# Reference: https://www.virustotal.com/gui/file/feea58a8648cc911ae870ba1b3cde32682f165eb867a9c8aee8571fe010d679a/detection
204.152.219.76:1177
79.134.225.92:1177
starboy.duckdns.org
# Reference: https://www.virustotal.com/gui/file/7beac47a408dec7b7ce999180ca781a7b531b77e530be76188b857a0947a555a/detection
79.134.225.92:4050
menaxe212.warzonedns.com
# Reference: https://www.symantec.com/security_response/writeup.jsp?docid=2015-041523-0201-99&tabid=2
moneybank92.no-ip.biz
# Reference: https://citizenlab.ca/2015/12/packrat-report/
daynews.sytes.net
deyrep24.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/1034193815505199107
money12.from-ok.com
# Reference: https://twitter.com/MalwareConfig/status/976617168728150016
osbka.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/804767558343725056
imporlogbomyah.zapto.org
# Reference: https://twitter.com/MalwareConfig/status/781777898424373248
kuslarinhayati.com
# Reference: https://twitter.com/MalwareConfig/status/778991643710066688
sara2011.no-ip.biz
# Reference: https://twitter.com/MalwareConfig/status/753247025546878976
linsom05.noip.me
# Reference: https://twitter.com/MalwareConfig/status/753246708075786240
opendoors.myftp.org
# Reference: https://twitter.com/MalwareConfig/status/753245062289584129
jry123.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/753243777674907648
dave1033.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748764868694593536
anglekeys.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748762322001244165
valien1.no-ip.biz
# Reference: https://twitter.com/MalwareConfig/status/748757699723079680
stitatn.no-ip.org
# Reference: https://twitter.com/MalwareConfig/status/748756558545166336
jacobjsockresyah.no-ip.info
# Reference: https://twitter.com/MalwareConfig/status/748756520741908480
felixres015js.zapto.org
# Reference: https://twitter.com/MalwareConfig/status/748756450181197824
alicejav777.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748756425472503808
raydonovan2015.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748756369205964800
mukor.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748756331763339264
oba147.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748756282450915328
alien6socket.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748756247667544064
salesexport.sytes.net
# Reference: https://twitter.com/MalwareConfig/status/748756177744343041
trusplus111.gotdns.ch
# Reference: https://twitter.com/MalwareConfig/status/748754751060209664
opjis123.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748754718189449216
getegoowo.no-ip.biz
# Reference: https://twitter.com/MalwareConfig/status/748754687596195840
uaelab.mypsx.net
# Reference: https://twitter.com/MalwareConfig/status/748625656041340929
okpole123.ddns.net
# Reference: https://twitter.com/MalwareConfig/status/748625186820333568
blessuslord2014.no-ip.biz
# Reference: http://securitywarrior.ca/index.php/2015/11/03/ratcheting-down-on-jsocket-a-pc-and-android-threat/
d370.cc
saleshore201.serveblog.net
floffman11.no-ip.org
akwotie.ddns.net
hydrabad-ur.ddns.net
bright207.ddns.net
stevemartins02.no-ip.biz
ipcorrect.ddns.net
linsom05.noip.me
chriswoolmer00.no-ip.info
justicsbro.linkpc.net
felbankgmailjs.no-ip.info
justicebro.linkpc.net
frookze.ddns.net
moukenji.ddns.net
felixres015js.zapto.org
budapest89.hopto.me
toolsoffice.ddns.net
alien12socket.ddns.net
evanovik.ddns.net
princelarry.ddns.net
nemere.no-ip.org
alicejav777.ddns.net
lawkimsun.ddns.net
arseisa.no-ip.org
blessingonblessings.hopto.me
nikresut015js.zapto.org
dotpago.ddns.net
williasom.ddns.net
jshkoi.ddns.net
egbowantedjs.ddns.net
mrmoney.no-ip.biz
olavroy4.ddns.net
whichway.ddns.net
chriswork.ddns.net
dave1033.ddns.net
filezilla.no-ip.biz
johnsonsammy.ddns.net
abdav21.ddns.net
tpalmer1955.ddns.net
adolfo196938.ddns.net
ome.no-ip.info
lazarus.ufcfan.org
tomluke12.publicvm.com
vyperps.no-ip.biz
logisticsltd.no-ip.biz
ben770.ddns.net
leonardomateus131.ddns.net
opendoors.myftp.org
jjsmits7.serveftp.com
mega123b.ddns.net
tools4chima.ddns.net
paulcoe.no-ip.org