forked from stamparm/maltrail
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathapt_deathstalker.txt
206 lines (196 loc) · 3.74 KB
/
apt_deathstalker.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
# Copyright (c) 2014-2025 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission
# Reference: https://securelist.com/deathstalker-mercenary-triumvirate/98177/
# Reference: https://otx.alienvault.com/pulse/5f43eff7af4508bf663e17ea
# Reference: https://archive.f-secure.com/weblog/archives/00002803.html
http://105.104.10.115
http://54.38.192.174
http://87.121.52.62
http://87.121.52.69
http://91.229.76.153
http://91.229.76.17
http://91.229.77.120
http://91.229.77.240
http://91.229.79.120
http://94.156.77.182
http://95.211.168.10
# Reference: https://securelist.com/what-did-deathstalker-hide-between-two-ferns/99616/ (# PowerPepper)
# Reference: https://otx.alienvault.com/pulse/5fc9193078e666899f4cc5a7
allmedicalpro.com
gofinancesolutions.com
mediqhealthcare.com
footersig.pythonanywhere.com
globalsignature.pythonanywhere.com
mailservice.pythonanywhere.com
mailservices.pythonanywhere.com
mailsignature.pythonanywhere.com
mailsigning.pythonanywhere.com
gsn-nettoyage.com/wp-snapshots/
# Reference: https://twitter.com/z0ul_/status/1389328825855746051 (# PyVil RAT)
audio-azure.com
azure-affiliate.com
check-avg.co
scan-eset.com
service-azure.com
# Reference: https://securelist.com/vilerat-deathstalkers-continuous-strike/107075/
admex.org
adsoftpic.com
affijay.com
agagian.com
aidobe-update.com
allrivercenter.com
amazonappservice.com
amazoncld.com
amazoncontent.org
ammaze.org
amzbooks.org
amznapis.com
anyfoodappz.com
anypicsave.com
apidevops.org
apiygate.com
appcellor.com
apple-sdk.com
atomarket.org
azurecfd.com
azurecontents.com
azureservicesapi.com
bookfinder-ltd.com
borisjns.com
cargoargs.com
cashcores.org
check-avg.com
cloud-appint.com
cloudappcer.com
cloudazureservices.com
cloudpdom.com
cloudreg-email.com
coreadvc.com
corstand.com
cosmoscld.com
covidaff.org
covidgov.org
covsafezone.com
dbcallog.com
dellscanhw.com
diamondncenter.biz
dnserviceapp.com
dnstotal.org
dogeofcoin.com
dustforms.com
earthviehuge.com
econfuss.com
edwardpof.com
eroclasp.com
esetupdater.com
ezteching.com
fastnetbrowsing.com
findmypcs.com
firedomez.com
flightpassist.com
flyingpackagetrack.com
forceground.co
futureggs.com
getappcloud.com
govdefi.com
govtoffice.org
gratedomofrome.com
hostboxapp.com
hostedl.com
hpcloudlive.com
ihotel-deals.com
invgov.org
jarviservice.org
luccares.com
mailcloudservices.org
mailservicenow.com
mainsingular.com
mcafee-secd.com
mevcsft.com
missft.com
msfastbrowse.com
msfsvctassist.com
msft-dev.com
msftapp.com
msftcd.com
msftcrs.com
msftinfo.com
msftmnvm.com
msftprint.com
msintsvc.com
mslogger.org
mullticon.com
multitrolli.com
multizoom.org
murfyslaws.com
musthavethisapp.com
n90app.com
namereslv.org
navyedu.org
netmsvc.com
networkcanner.com
newedgeso.com
ntlmsvc.com
nvidiaupdater.com
oglmart.com
onesportinc.com
orklaus.com
outlooksyn.com
pdfscan-now.com
philipfin.com
picodehub.com
pinktwinlers.com
pivotnet.org
plancetron.com
poccodom.com
praxpay.org
print-hpcloud.com
printauthors.com
prodeload.com
questofma.com
realmacblog.com
realshbe.com
refsurface.com
robmkg.com
roboecloud.com
rombaic.com
rowfus.com
sellcoread.com
servicebu.org
servicejap.com
shopadvs.com
shopamzn.org
soundstuner.com
superimarkets.com
svclouds.com
svcscom.com
symantecq.com
sysconfwmi.com
textmaticz.com
thesailormaid.com
thismads.com
timetwork.com
tomandos.com
tophubbyriver.com
topotato.org
totaledgency.com
unitedubai.org
unitepixel.org
wdigitalecloud.com
weareukrainepeople.com
weatherlocate.com
windowslive-detect.com
wingsnsun.com
wizdomofdo.com
wwcsport.org
yourprintllc.com
zerobitfan.com
zummaride.com
# Reference: https://securelist.com/deathstalker-targets-legal-entities-with-new-janicab-variant/108131/
http://176.223.165.196
http://87.120.254.100
http://87.120.37.68
176.223.165.196:8080
185.62.189.210:8081
87.120.254.100:8080
87.120.37.68:8080