-
Notifications
You must be signed in to change notification settings - Fork 5
/
Copy pathblocklists-sekoia.txt
1298 lines (1260 loc) · 38.1 KB
/
blocklists-sekoia.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
## hosts-blocklists
## domains-ips-hashes
## blocklists-sekoia
## https://blog.sekoia.io/
# https://blog.sekoia.io/muddywater-replaces-atera-by-custom-muddyrot-implant-in-a-recent-campaign/
91.235.234.202
146.19.143.14
73c677dd3b264e7eb80e26e78ac9df1dba30915b5ce3b1bc1c83db52b9c6b30e
960d4c9e79e751be6cad470e4f8e1d3a2b11f76f47597df8619ae41c96ba5809
94278fa01900fdbfb58d2e373895c045c69c01915edc5349cd6f3e5b7130c472
b8703744744555ad841f922995cef5dbca11da22565195d05529f5f9095fbfca
# https://blog.sekoia.io/exposing-fakebat-loader-distribution-methods-and-adversary-infrastructure/
0212top.online
0212top.site
0212top.top
0212top.xyz
0909kses.top
62.204.41.98
343-ads-info.top
364klhjsfsl.top
465jsdlkd.top
756-ads-info.site
756-ads-info.top
756-ads-info.xyz
875jhrfks.top
999-ads-info.top
1212stars.online
1212stars.site
1212stars.top
1212stars.xyz
2311foreign.xyz
2311forget.online
2311forget.site
2311forget.xyz
2610asdkj.online
2610asdkj.site
2610asdkj.top
2610asdkj.xyz
2610kjhsda.online
2610kjhsda.site
2610kjhsda.top
2610kjhsda.xyz
3010cars.online
3010cars.site
3010cars.top
3010cars.xyz
3010offers.online
3010offers.site
3010offers.top
3010offers.xyz
11234jkhfkujhs.online
11234jkhfkujhs.site
11234jkhfkujhs.top
11234jkhfkujhs.xyz
98762341tdgi.online
98762341tdgi.site
98762341tdgi.top
98762341tdgi.xyz
ads-analyze.online
ads-analyze.site
ads-analyze.top
ads-analyze.xyz
ads-change.online
ads-change.site
ads-change.top
ads-change.xyz
ads-creep.top
ads-creep.xyz
ads-eagle.top
ads-eagle.xyz
ads-forget.top
ads-hoop.top
ads-hoop.xyz
ads-info.ru
ads-info.site
ads-moon.top
ads-moon.xyz
ads-pill.top
ads-pill.xyz
ads-star.online
ads-star.site
ads-star.top
ads-star.xyz
ads-strong.online
ads-strong.site
ads-strong.top
ads-strong.xyz
ads-tooth.top
ads-tooth.xyz
ads-work.site
ads-work.top
ads-work.xyz
aipanelnew.ru
aipanelnew.site
app.getmess.io
brow-ser-update.top
cdn-ads.ru
cdn-ads.site
cdn-dwnld.ru
cdn-dwnld.site
cdn-inform.com
cdn-new-dwnl.ru
clk-brom.ru
clk-brom.site
clk-brood.online
clk-brood.top
clk-info.ru
clk-info.site
cornbascet.ru
cornbascet.site
dns-inform.top
findreaders.com
fresh-prok.ru
fresh-prok.site
ganalytics-api.com
getmess.download
gotrustfear.ru
gotrustfear.site
infocdn-111.online
infocdn-111.site
infocdn-111.xyz
new-prok.ru
new-prok.site
newtorpan.ru
newtorpan.site
noltlion.com
notilion.co
notilon.co
notion-loads.com
notion.findreaders.com
notion.help
notion.ilusofficial.com
notion.kyngsacademy.com
notion.li
notion.officespacesearchdc.com
notiorn.org
notiron.org
notliion.com
notlilon.co
notlon.top
photoshop-adobe.shop
prkl-ads.ru
prkl-ads.site
rabby.pro
test-pn.ru
test-pn.site
topttr.com
trust-flare.ru
trust-flare.site
trustdwnl.ru
udr-offdips.com
urd-apdaps.com
usm-pontic.com
utd-corts.com
utd-corts.com/buy
utd-forts.com
utd-gochisu.com
utd-horipsy.com
utm-adrooz.com
utm-adschuk.com
utm-adsgoogle.com
utm-adsname.com
utm-advrez.com
utm-drmka.com
utm-fukap.com
utm-msh.com
utr-gavlup.com
utr-jopass.com
utr-krubz.com
utr-provit.com
0cc7ced10b6521b60787531120cb4876
0ce7a763c4358dbb21f1b124d173bc87
06b51647790672b16e7e65a0cee21319
070ab75296470ff7bd0af76eb72a3500
1ae54e6e68472ae989ebf0f9e8534b4c
1eecbf4870d504be91cdffc6362a28ff
1ffc3756ba44768c57a06ff786b428cd
3a0d04c60706424f09200755835e880a
4d8bbe057d3807dd43b8636904be7c54
4f2e138b6891395a408368a9a5998304
4f35e56de635c20c22a275a0234fee53
5cb1ecc52f72d287cc12fb185e260f07
6c967965545c5b1e26b27e88b7b56759
6dfb183ee517aa0956776d135052ae30
6f8c0572b502254437a42c7924a80cac
9bfee4fde1e6cde3683b78ffe00fdfcc
9c8a65abac35977b794160a120c5f044
9db48848925a7a36c90b740957a22cc0
30f5b5ab7ed02ef43dd03ed763ec9446
55d614058f3b2f237ad7b9a63e72de0f
55de04d9156a8503c271d076fd4ff122
56a53e670d013ec4b46f5267cf0e1cb7
59a3f38020da965d6f3e6c8f927276c1
69dc6c7ee83aed292be2bd3358825448
117a24ddc194538eeb4e05ac8a719929
486e9147d9370c0baf27fe148284ed61
569d206636b75c33240ba4c1739c04d6
881ec5bf0da0d49a7f564eda71209097
952b2eb13a51b622c24dd78ff6dbc690
3246a476a442381d9875265ecf23d525
61986dc188c0aec278b905e44ea0b329
84125e29913a25d2a090a04469a9d8df
609541eb99a68eb13321f8fefb3cde47
5607822ee71e3fdc1842c8806f6a0bc9
6753037f029a8d95cfb456fdcdf96067
a0eaf00612641acfc762301ead31688c
a1724ddc85e98eddb2d93fc8a024a8f0
a98599c1ef1782898dc29b1c798ba3ae
b1f93418b1d0d6fcd74dfc97606cace5
b8fec162d921ec73fafd7a66f38babed
b9c050894aceac32800344be2034b25f
b52e5866aa620bcd5a8bfb07a6c76e6f
b222ccfee202aad652c2fa18f51e1c76
b9140df9f59858f27f85f8ba6b4cf31b
be587294af0072be016e59681477a5bd
c9c4d601c6e3bb9f3560b6bc4df2b13a
d3c8e13000edb3eda1410c6bd1c46293
d7e02c376cb608d85375da95f2be4ef4
d7f10b971dba61a2059d1a6b7d5fb41d
d9d9085f645e2c31ceffb24b88b10246
d45ef460434751141646c473e7adf304
db2aab51bd2fc45c28218fc76e7db97d
de6721eed077276030fc1253a35bdafd
e4f143f3a16088f3cfc9bfe86cda4e84
e56b3ff3de6ff210309a5fa99845b036
f8bbc7cdf14753268082e3b57d18e764
fd615b958da316ad06a0053dfa8cbeb8
02ba723a61a8b557b5e2bf16aa0363fb959317bf
043702a3943d997795232bea2fb5528ce92c077e
1fa8f012fe2c9a2febf93cf71f14d7739a96c9b1
2e812403935b77e79d8d6b664f0375784f6fc66d
3c0d1d30ad289a57a315988c747c172f5aabe26e
3c65e96790b4ce411826f1cb8b86014246c1429d
4b53b18ea8d498a4b94877d022b52f281c0d8d6d
5a3262a09dc1ba321156f990da715c302455691f
5efb3af1460b6a2a5da2ae9b515f830fe1d54287
6ac9fb76abe3b652c50776bf5f346306c948e1a8
6bbf77d3f3c21c7e9718bfe999763fa709801d28
6ce3fa3f635dcf5e8a80e2f3aa90d5ef395026ca
7a1c3257094739b8bec0e78a4c00b36738f5ee4d
7b3b6dfd5af3504b0d3f85748fe1b4b2e7f61ca0
8a8fb9537ebcac06f1d87ff0953ab8817b4bcaa8
8ae6d465252e118c717c3a7051bbd51a881f99b2
8c6b2b0c794ec4d97773b11e379cde4ceccaf08a
8d29b5733461e3edf2ac7606aff9c671a6137dac
8e584a7f79d659b5cd988caad311d7c05af43c36
9d7ac0b92617a9a7a6f341e457e36947e0e7f11d
9e80b1e21bf3a53086fd2c2badfb788cfa6c3ee1
21e1752218ea09be3f7355a43b5f6ca2dda4a484
60e95fae4775bedcf64ec6b048e1a3e9c590567e
63d94e9b134081332729e56d4ac368100843f854
80d399c928e586ec26110025cd866004fcf9c7e2
86b11e7036143d0475363ab3b91f34c0e37dad2b
92abdd7fa9778b0d352d95d09fdae4ff424d09fd
486fe3628ac5139ab8570a8094285ed2a83b35af
507c60c6e099a3a6ed2b1b6494fd72cff7b22cd9
519c269d1ab802088f7a92f4f961d1bae810ce72
565cc7265031f4e888f756bd1a48db404d9227f3
615e1362ed452e76592cb11784b8240e4b3464bc
6062f7859eb407e737844bc30ca45256a7609ab2
7950a9edb339d1d5c14040215673f7d7c7057c3e
8150d225d5b77bafb58775f87e2410b7a9ab5799
64833c6148b3fdc6febb14a308ecc2631c5173a4
865167e36f199de48e003abecfd3b6895285a95f
529840151d8f81f2fd357a1429bd89dec4af5a4e
a3cfa6a856096e8441ab36755f74fbcbc6bd8b48
a115926e97b5b4e658a33157abc14472b36daf3b
af3ceefe8a8d39485fc8e7dc8095be88c3257d41
c2b271573cabf60004ab6c8e99eb8bfa590c210b
c4c09e2996bfe6f49b0a5c7af6ecbafcf4fbb83f
c8d8b660e8ef8d37a64413f1d16df297e1b0a6c4
c6621ae29a7b6dbbfd313e1b32e3d470402d5bbf
d5ce9bae15ce340a2b1821c539b43eebe5778263
d68ce17e09024a414b81750d3b7cc8c619e989d5
d538b4e73b1a581aa02205e27fec6f569a725a6e
de7e2944ec4e1135e950c7147e69a210b799fbf8
de85668782590e9590fe600d7d4fcd9b857d74ec
e3ce3b83dd56d5a6993c3c3f8a15343970045477
e50b4378c32b2d876eb220cfa0307afae97359b7
f074f1d3f578d4b1d6ca2e41506e5ebd96dfd40f
f07523d6f22a397db94f26ac8aac329ccbdd81a1
f468dfbcf346aaec76e5370b8296e9c7b47392aa
f228627f676ad96d95b6ad954242a242826c9443
fd1694a1e3f941303bb05bc0571a638385c38390
0c4cef985c90ed764f041c2ccab6820fdbe38edaaddebe01a5b8d31d93204b88
00e7e8a0e8495189bb7feca21864fbd6c61a5aa680462186504de02536e0c2f9
00ea5d43f2779a705856a824a3f8133cb100101e043cb670e49b163534b0c525
020cd2e4ec27185550bf736b490d8ace0d244fe09315f9f7e18362de659bc7ad
07a0986ab43f717e181a32d6742b11f788403ce582ad5fcbb9d20d0bd40d410b
088ed84658a7c3bef4401601ef67a6953492fb0200a3b580bfabb21cd3ac8236
1bb51d62457f606e947a4e7ce86198e9956ae1fe4e51e4e945370cc25fe6bfff
1c5cadde01f10a730cd8f55633c967c3a7259f4906f961477b7e095e7db326b7
1d5d671bf680d739ded1e25e78970b38d00e8182816171a7c6a186504a79eeee
2b033fc28ad12cb57c7c691bd40911ca47dd2a8e495a2d253557d2c6bcd40c5e
2e8a82f07de254848615f81272f08e0cf9af474d1c20f67d9ddbdf439f1d8fde
3bd95eadb44349c7d88ea989501590fb3652ae27eded15ab5d12b17e2708969f
3d3a9cd140972b7b8a01dde2e4cd9707913f2eba09a3742c72016fd073004951
4e39fa74e49be2bf26fbfbbcea12d1374fa2f1607ff7fa2a0c8c323e697959ad
5e5c134cea48e57da9604981c0a7fd6ef1704c4151b540f29de685e0017fa730
5ee273180702a54f32520be02c170ad154588893b63eefe2062cdb34ad83712c
6e0179344ca0bbc42dce77027f5a6a049844daf34595fd184d9f094e8c74325c
6fb502d83b7b5181abcb53784270239cc3e4143344e1f64101537aa3848c8c95
7c7dc62ed7af2f90aeafdd5c3af5284c5539aeded7d642d39f5fd5f187d33c87
7d0aaf734f73c1cf93e53703e648125bba43e023203be9a938f270dfe3492718
8f88a86d57b93cd7f63dfdf3cb8cc398cdce358e683fb04e19b0d0ed73dd50ee
9a2268162982113c12d163b1377dc4e72c93f91e26bd511d16c1b705262ca03c
9aa39f017b50dcc2214ce472d3967721c676a7826030c2e34cb95c495dba4960
9e800a05e65efe923a35815157129652980f03cbcf95cf0d64676f6da73471de
12ea41f2dfa89ad86f082fdf80ca57f14cd8a8f27280aca4f18111758de96d15
49a7668d60e8df9d0a57ba9e0e736c1eb48700da19711cc0ec0f3c94a56ce507
72a1f6e7979daae38d8e0e14893db4c182b8362acc5d721141ed328ed02c7e28
96bd6abb1c8ec2ede22b915a11b97c0cd44c1f5ed1cda8bee0acfee290f8f580
175fcb7495c0814a5c18afa6244d467f0daeb0f02ad93c0ab4d3af8cbbacb537
409a2a2a4e442017e6d647524fdec11507515a9f58a314e74307e67059bd8149
763bdd0b5413bb2e0e3c4a68a7542586bbd638665b7ca250dbd9c7558216e427
767dd301dc5297828a35eaba81f84bd0f50d61fe1a9208b8d89b5eaba064d65e
806d08e6169569eb1649b2d1f770ad30a01ff55beedfe93aebccac2bc24533c0
904ce1b1ffa601f9aeb0a6d68bc83532c5e76b958029bd1c889937fa7cf1867f
4029e194864e2557786e169c7f2c101b9972164de7b4f1ffadf89382317cf96c
7265ffdbe31dd96d6e6c8ead5a56817c905ff012418546e2233b7dce22372630
7316ed0cb0fdbede33a0b6d05d0be1fe3c616ef7c1098dfcc9a2339c793e7020
90641a72a4ea6f1fca57ec5e5daec4319ec95bec53dd2bf0fa58d1f9ade42ad4
67663233f9e3763171afd3a44b769dc67a8a61d4a159f205003c5fdb150e2ca1
400277618bd2591efb2eb22ac0041c1c5561d96c479a60924ef799de3e2d290c
aa998fde06a6a6ab37593c054333e192ce4706a14d210d8fc6c0de3fd2d74ce2
ae641dda420f2cf63ac29804f7009ba1c248c702679fbccef35e4d9319d77d2d
b5ed2f42359e809bf171183a444457c378355d07b414f5828e1e4f7b35bb505f
b7aa4697e16bbafe0df02ab3b8d0be8ec6e4abf6e6ca7d787d3d3684ca8f4b63
c336d98d8d4810666ee4693e8c3a2a34191bad864d6b46e468a7eed36e7085f4
cea1c4f2229e7aa0167c07e22a3809f42ec931332da7cc28f7d14b9e702af66b
d069437eda843bd7a675a1cca7fd4922803833f39265d951fa01e7ad8e662c60
d1da457b0891b68df16ce86e2a48a799b9528c1631bccc379623551f873c0eed
e3f18df1d8f5e27a41221246cc63236487c56354ba0c926a3fdaea70db901adb
e5b94c001fc3c1c1aa35c71a3d1e9909124339e0ade09f897b918fe0729c12e1
f0e0aea32962a8a4aecd0c4b0329dc7e901fa5b103f0b03563cf9705d751bbe1
f0f77c85c7da4391e34d106c4b5f671eb606ba695dc11401a6ee8ae53e337cbe
f1d72a27147c42a4f4baf3e10a6f03988c70546bb174a1025553a8319717ba95
f3ebb23bdcc7ac016d958c1a057152636bc2372b3a059bf49675882f64105068
f8ab48848ab915d1b23e3ee51dd20a2699bd4f277bde218a727d7a55a572d174
f312e59be5ddbf857d92de506d55ae267800b0cbc2b82665ce63c889a7ae9414
f138728ce2cc87201a51c9250fa87cbab20354012a8f566e1b2cd776cc1a66af
# https://blog.sekoia.io/pikabot-a-guide-to-its-deep-secrets-and-operations/#h-iocs
4.175.178.149
5.45.69.171
5.61.43.38
5.180.151.180
5.180.151.194
8.20.255.249
15.235.44.231
15.235.45.155
15.235.47.80
15.235.47.206
15.235.143.190
15.235.202.109
23.226.138.143
23.227.194.96
34.135.79.247
37.1.208.52
37.1.215.220
37.60.242.86
38.242.240.28
43.229.78.74
45.32.21.184
45.32.188.56
45.32.204.175
45.32.232.31
45.32.235.46
45.32.248.100
45.33.15.215
45.33.76.163
45.63.26.148
45.76.96.172
45.76.98.136
45.76.119.22
45.77.55.133
45.77.63.237
45.79.147.119
45.131.108.250
45.154.24.57
45.182.189.105
45.182.189.106
46.250.241.188
46.250.241.191
46.250.241.197
46.250.253.58
50.116.54.138
51.68.144.135
51.68.146.19
51.83.253.102
51.195.232.97
54.37.79.82
54.84.110.180
57.128.83.129
57.128.103.99
57.128.109.221
57.128.164.11
57.128.165.176
62.197.48.230
64.23.199.206
64.176.66.137
64.176.190.166
64.176.218.254
64.176.225.21
65.20.69.208
65.20.73.169
65.20.77.19
65.20.78.68
65.20.78.70
65.20.84.3
65.20.84.254
65.20.85.39
65.20.115.154
66.42.80.169
66.135.31.146
70.34.207.219
70.34.209.101
70.34.223.131
70.34.223.164
78.47.233.121
78.141.200.111
85.106.94.167
85.215.162.167
85.239.243.155
86.38.225.105
86.38.225.108
88.214.27.74
89.116.131.40
89.117.23.185
89.117.55.178
89.117.55.179
91.215.85.154
94.72.104.77
94.72.104.80
94.199.173.6
94.228.169.221
95.179.141.41
95.179.182.147
95.179.214.49
95.179.247.197
97.107.131.224
102.129.139.65
103.151.20.137
104.129.55.103
104.129.55.104
104.129.55.105
104.129.55.106
104.200.28.75
104.207.143.168
107.191.47.85
107.191.56.230
108.61.224.209
109.107.182.10
109.107.182.11
109.107.182.13
109.107.182.15
109.107.182.16
109.107.182.17
109.107.182.18
109.107.182.19
109.123.227.54
109.123.227.147
109.123.227.158
109.123.227.170
109.123.227.174
109.199.99.131
131.153.231.178
135.125.124.72
136.244.98.80
139.99.216.90
139.144.31.103
139.144.97.180
139.177.198.199
140.82.56.164
141.95.106.106
141.95.108.72
141.95.108.252
145.239.135.24
148.113.141.220
148.153.34.82
149.28.17.176
149.28.49.170
149.248.53.65
154.12.248.41
154.12.252.84
154.12.255.254
154.38.164.50
154.38.175.241
154.38.184.3
154.38.184.5
154.38.185.138
154.53.55.165
154.80.229.76
154.92.19.139
154.221.30.136
155.138.140.156
155.138.147.62
155.138.156.94
156.251.137.134
158.220.80.157
158.220.80.167
158.220.90.198
158.220.90.199
158.220.95.215
158.247.196.155
158.247.197.73
158.247.202.180
158.247.210.203
158.247.215.68
158.247.240.58
158.247.246.182
161.97.98.95
167.179.93.21
167.179.100.211
172.232.7.224
172.232.24.58
172.232.54.192
172.232.161.248
172.232.162.97
172.232.163.111
172.232.163.208
172.232.164.159
172.232.172.117
172.232.172.171
172.232.173.219
172.232.174.6
172.232.186.100
172.232.186.251
172.232.188.124
172.232.189.84
172.232.189.134
172.232.189.141
172.232.189.166
172.233.154.98
172.233.155.253
172.233.156.100
172.233.185.220
172.233.186.50
172.233.221.61
172.234.16.175
172.234.29.13
172.234.224.202
176.58.102.36
178.154.205.14
185.87.148.132
185.87.150.108
185.87.151.234
185.106.94.152
185.106.94.167
185.106.94.177
185.187.235.158
188.26.127.4
194.233.91.144
196.218.123.202
198.13.58.126
198.38.94.213
198.244.141.4
199.247.8.136
199.247.15.68
207.148.93.23
207.148.103.233
208.76.221.253
210.243.8.247
213.142.147.218
216.128.136.231
216.128.151.26
216.238.79.12
217.69.8.229
#https://blog.sekoia.io/master-of-puppets-uncovering-the-doppelganger-pro-russian-influence-campaign/#h-i-doppelganger-campaign-victims-objectives-and-relays
40pg96.risebedutt07.club
590lotto.com
711ggr.com
adoazra.com
adventistya.com
aimbrilliant.com
akramir.com
akz.bg
alfonrust.com
altgoat.com
ambeey.com
americanatectana.com
argondigital.pro
argonlabs.pro
arizztar.com
arturbichoev.com
aviatotventure.com
avtechdaddy.com
b34ibw.fbcaseappeal34512742794167.live
bafq5v.theironforest.com
beecontrolparadisevalleyaz.com
bitsdepartment.online
blazetrucks.com
bluetoffee-books.com
bookingyatri.com
buymeagradient.com
c8re5h.cheatinject.space
carolynjettproperty.com
cdsofiowa.com
cerrajerosviladecans.online
cgocn5.penisbreakfast.com
charayaassociates.com
companyrush.com
contrictor.com
cxskm6.ugandanchemist.com
d4mt2p.kredyt-kr33.buzz
daileaf.com
dev_est.dafen.ru
docnanb.com
doublerproperty.com
dreamgeorgia.com
dumonmap.com
ecboteltekstil.com
edurustoday.ru
emdrnearme.com
emverticales.com
est_dev.dafen.ru
etherdatalabs.com
f859cj.brisks.shop
faridmehdipour.com
fastnep.com
financiallyfitemployee.com
fionaparr.com
flexkopanalo.top
flexwe.com
freeebooktemplates.com
freemit.com
freexp3series.com
frontiersemiconductor.com
gestarcare.com
gevirts.com
ggspace.space
globalindustires.com
glowforgeusergroup.com
govreadyq.com
greatroomservice.info
grumpymomma.com
guzzlerspubpos.com
healthsuggetions.com
heavycreambags.com
hjwbdb.renderny.com
ikkyle.com
incredipoll.com
interactiveleap.com
intsightful.com
invierteseguroenmiami.com
jetcarsrentacar.com
jiajamfit.com
jlaworld.com
kamnarajput.com
kenevirinfaydalari.com
kgdr3b.froggy.lol
kiddosdeals.com
lastminutenews.ru
letsfind123.com
lildoxi.com
littlecrumblybits.com
lu531k.vibor-cred96.buzz
m7rwtu.whencontact.com
maddiecrum.com
manojrawniar.com
matiasbenavides.com
meetfinancialsidekick.com
milloa.com
minsetguru.com
misterwindowanddoor.com
mmawire.com
momixapkdownload.com
mspbazar.com
mt-secure-bnk.com
mundowao.com
myfreshnews.ru
newsbd.ru
newsroad.online
nnewws.ru
pawbiiotix.com
paypalcheck.com
pkjobs23.com
plusdates.com
prebid.deepintent.com
pro-gymuk.com
profesionalvirtual.com
protodsp.ru
realpeoplesreviews.com
realulim.com
reedleycornerstonecommunitychurch.com
referendud.com
restuapp.com
rg.urldirect.ru
rockdogtech.com
roomworkout.com
roysel.com
ruf-des-reiches.com
ruffai.com
rulesascode.com
rustomega.com
safevpn-app.com
saivitecreation.com
sdgqaef.site
seckinyayincilik.com
sociallords.com
stemduniya.com
test-auth.argonlabs.ru
thetoiletpaperman.com
thetoycrew.com
thevegasstakes.com
thinkwritepost.com
todaybrings.ru
ul3kin.freevideodownloader.pro
ulz9re.eboy.info
umlouj.gasskuy149.click
utf5w1.nice-credits-list228.buzz
uv2hzh.opensea9.tech
uw79hp.reyt-cre-ann44.buzz
uzxtbm.cepatlahini93.click
v029ec.ger4098764793ggwhit3.online
v2mn9i.rating-cred26.buzz
v3ix3z.rou.bar
v5utyg.great-cred50.buzz
v5yoaq.chilling.lol
va63pm.rating-cred164.buzz
vcahd4.fitspressousa.com
vddxlv.worldcryptomining.live
vi8bgj.garaj.site
vls6oj.mountainslife.xyz
vmtu1y.yellowbarrels.co.uk
voshod-agency.ru
vp53bj.shine-squadcleaning.store
vv5md4.parmarthyogashram.com
vxy9ts.rentranking.online
w3yr6b.khidmatkhalq.com
w4ux1u.zaksi-kred-mx23.buzz
w4x964.cepatlahini93.click
w7fs5u.testingarsip.xyz
w9rpgr.getmobile.online
w39vyh.zm-kariz-best114.buzz
wflfks.start-cred-history90.buzz
wgwkkc.slimminggummiesofficial.store
wh3kmz.digipanservices.in
who9g3.balala.tech
wi7brv.tanpapenyesalan.click
wmpp73.speaiker.com
wrbb8d.karritech.co.uk
x0fxvm.antipandemicsupplies.com
x7r8nz.santsuono.club
x76yrj.start-cred-history118.buzz
xbqaz5.coinmaster.world
xfx6hd.c-majac-ann15.buzz
xmyaqs.homeopathypjnhmc.edu.in
xr2x9u.kbbet1.life
xu71vo.grocerysphere.com
xvjxj7.indianmandirs.com
xywsho.hurkushackteam.org
y1dod2.futurity.partners
y1z85z.bestlimitedoffer.store
y5j23h.incawonders.com
yea52d.informationforeveryone.org
yfaoli.cemerytasui.info
yfljmd.whencontact.com
ygdpd1.karritech.co.uk
yio4t3.real-credits-snap116.buzz
ykr195.theoceanartcompany.com
ykts2v.luismillares.store
ykycoi.appleid-iosdevice.info
ymcz5z.emaarindia62.com
younais.com
ypj9em.biogolden.site
ypxlhq.mayavati.online
yrd1iz.nutribargains.life
yrh431.protradeindia.com
yrxibe.elembajadordelapampa.com
ytbw95.kredit-money-fun284.buzz
yzl45b.depolumi5.click
yzrhhk.kredit-money-fun202.buzz
z53bcd.eliteestates.services
zacedf.cypressnewsgh.online
ze2vt3.yamadeko187.click
zgb1pt.hungryhenrietta.com
zhe455.accesspromarket.live
zhsqmc.welovequran.com
zj8cp5.fasty.org.uk
zjksjp.norfolkcustomconcrete.com
zm6hh2.khach-hang-ca-nhan-v-n.com
zmivco.northernenviortech.com
zmkmayak.ru
znh94x.grupoametista.online
zpepsz.se5pro.co.uk
zplsdj.16c10.com
zrzzje.academicwriters.info
64.190.113.45
195.85.115.36
206.71.148.217
206.188.197.116
206.188.197.119
# https://blog.sekoia.io/mallox-ransomware-affiliate-leverages-purecrypter-in-microsoft-sql-exploitation-campaigns/
80.66.75.44
80.66.76.251
87.251.75.92
91.215.85.142
5d511bb13f728fa5973e1504970dfe0e
31d9f253b4bedfeabc8837eda397a738
310b3eb441e5c8cf72409c3d99bd8c6e
e98b3a8d2179e0bd0bebba42735d11b7
ef6c1850fbd323ba490d639af2373493
fa31d90f5cd6746c3db8ad9a443dc07c
6a8c72125a5257dd7cf393f80fd3e2bf52a2471b
9c3b5d6a529804d7c0c4bc2f587d5245fd84ef96
47c4a1544299260826efd9b3118ac4f727895632
8164b6964db12bd3064b436b71551d7c4941dc0e
2578289d2d457d986d6924f457ae5874b9abd6c5
d9d07700de5d5755f769c2256a2a61a756536298
04ba9dd2d3127511af52e1be3015e0424491cfb2133f90f8b5b5cac2e33166d4
0772ab3066dbc9863f415f505e3a136266d46d9c8889646b3c3720c44d4ced79
19005bf424024b22edaae18bf1da55ea05092f906a19aee7b86e9624cc9fa34e
29256d84f25518007da05dba434aee3b20260817809f8407a7ac6d97b3ed81de
dd41f029f28c03067bb392ec99f085d84ce02f84102f948782fda9e69a835b51
e92f5d73a8cb1aa132602d3f35f2c2005deba64df99dcfff4e2219819ab3fffd
# https://blog.sekoia.io/unplugging-plugx-sinkholing-the-plugx-usb-worm-botnet/
43.254.217.165
45.142.166.112
45.251.240.55
103.56.53.46
3a53bd36b24bc40bdce289d26f1b6965c0a5e71f26b05d19c7aa73d9e3cfa6ff
6bb959c33fdfc0086ac48586a73273a0a1331f1c4f0053ef021eebe7f377a292
8b8adc6c14ed3bbeacd9f39c4d1380835eaf090090f6f826341a018d6b2ad450
432a07eb49473fa8c71d50ccaf2bc980b692d458ec4aaedd52d739cb377f3428
2304891f176a92c62f43d9fd30cae943f1521394dce792c6de0e097d10103d45
b9f3cf9d63d2e3ce1821f2e3eb5acd6e374ea801f9c212eebfa734bd649bec7a
e8f55d0f327fd1d5f26428b890ef7fe878e135d494acda24ef01c695a2e9136d
# https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/
0q5e0.nemen9.com
4m2swl.7e2r.com
5me78.methw.ru
6j312.rchan0.com
8uecv.gnornamb.com
9c43r.theq0.com
9oc0y2isa27.demur3.com
25rw2.canweal.com
35fu2.ouchar.ru
43rw98nop8.m1p8z.com
77p3e.rimesh3.com
98q5e.ructin.com
4343w.jgu0.com
8000n.uqin.ru
beacon.diremsto.com
bloggcenter.com
buneji.fiernmar.com
codecrafters.su
codecrafterspro.com
devcraftingsolutions.com
e85t8.nechsha.com
ex1uo.rhknt.ru
explore.atlester.ru
fiq75d.rexj.ru
fisaca.trodeckh.com
galume.aricente.com
gz238.uatimin.com
horizon.sologerg.com
jp1y36.it2ua.com
k348d.venti71.com
kjlvo.ningeona.com
kjsdflwe.nitertym.ru
l846d.ferver8.com
libudi.oreversa.com
n9zph.lw8opi.com
n29k4.ilert.ru
o6t94g.3tdx2r.com
oo99v.coqqwx.ru
p1v12.17nor.com
pmd8ot6xhw.3qjpc.com
q908q.refec7.com
r298y.sem01.com
rlpq.tk9u.com
roriku.orankfix.com
tlger-surveillance.com
tnyr.moporins.com
tycoongroup.ws
wasogo.shantowd.com
x12y.restrice.ru
xrs.chenebystie.com
xva.tjlpkcia.com
zaqaxu.dthiterp.ru
zekal6.tnjxb.com
zemj4f.ymarir.ru
#https://blog.sekoia.io/unveiling-the-depths-of-residential-proxies-providers/
103.chtsite.com
api.honeygain.com
api.iproyal.com
api.pawns.app
api.peer2profit.global
client.c6gj-static.net
client.earnapp.com
client.h-vpn.org
client.haffnetworkam.com
client.haffnetworkmm.com
client.hola-vpn.com
client.hola.org
client.holabrowser.com
client.holafreevpn.com
client.holavpn.net
client.holavpnandroid.com
client.holavpnextension.com
client.holavpninstaller.com
client.holavpnrussia.com
client.holavpnworld.com
client.holax.io
client.shoopit.com
client.su89-cdn.net
client.yd6n63ptky.com
client.zspeed-cdn.com
clientsdk.brdtnet.com
clientsdk.bright-sdk.com
clientsdk.lum-sdk.io
clientsdk.luminati-china.io
clientsdk.luminati.io
clientsdk.luminatinet.com
ipv6-api.iproyal.com
ipv6-api.pawns.app
resi6-api.pawns.app
resi-api.pawns.app
updates.peer2profit.app
3.228.36.186
3.228.177.90
34.237.199.147
54.225.227.202
54.243.128.120
93.189.62.83
178.32.99.172
185.223.94.16
# https://blog.sekoia.io/noname05716-ddosia-project-2024-updates-and-behavioural-shifts/
5.44.42.29
5.252.23.100
38.180.95.29
38.180.101.98
45.84.0.235
45.89.55.4
45.136.199.235
77.75.230.221
77.83.246.159
83.217.9.33
83.217.9.48
89.105.201.91
94.131.97.202
94.140.114.239
94.140.115.89
94.140.115.92
161.35.199.2
185.39.204.86
185.234.66.126
185.234.66.239
185.239.48.70
185.255.123.84
188.116.20.254
193.17.183.18
193.187.175.252
193.233.193.65
193.233.193.90
193.233.193.240
195.35.19.138
195.133.88.73
212.73.134.208
0bd18838ea6d5f84f656261d1468306cc7d4b6efc1c3a79883b12a37c43dd010
0db86c3abdeadb44817e087e027ecf7572b3f6db492852a1c3bb78b81b1ba08a
0de4307b8c4519b59e4bac8fc398a12bd5d370e20ae580f4340ca519686e90ba
0e260d76a54edb4527fd9d1630ff6e5956d29f11ea1c5e36e5131a4a6e74a1b6
0e543ed1f5938fb106214f2c64f59cb74f2a294dcd7ce80868bc1a068f474137
0ed621330bad1dd2e58c91c5bcb01c532c7b2822b11c1e744727d1e9d3ebdf7a
0f4b73adfd946de88d3f13de2f1b3f861ece6d6bda8c2499efb8d3a1f592d9e9
01ba7a50286d87a1dbc16203f313f6a49160f059d93f1d04479a6c1e3f258f41
01f642934e6192f4e907caba8a7c935ccf8ae5dd84f350e679b9c51e2508cd77
021e802872dd7875561caa5ae5522170e2e59803cdf483e12e3ef1c04fb5a7a1