# Copyright (c) 2014-2021 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission

# Aliases: slrat, spymax

# Reference: https://twitter.com/LukasStefanko/status/1239494265618694147

assdsiwi.ddns.net

# Reference: https://www.virustotal.com/gui/file/eb5db64f88a09cf8b5c72d2b3a0a45439c678bb513fb7adb59b335f0354cd095/detection

41.253.52.89:1515
41.253.23.12:1515
41.253.23.12:28028
216.38.7.245:6666
41.252.167.210:1515
41.252.167.210:28028
82.205.176.250:1515
41.252.139.115:1515
41.252.139.115:28028
165.16.67.82:1515
165.16.67.82:28028
41.253.168.216:1515
41.253.168.216:28028
assdsiwi.duckdns.org

# Reference: https://www.virustotal.com/gui/file/988ba9665b44a2791f4ea3d6b95b885287212e0fecac8bb517784a6a69c0c6ff/detection

shakermohammd19999.ddns.net

# Reference: https://www.virustotal.com/gui/file/07ae6fa0f804e16f24ed052ef25349780195bfa95b557e9be52f29f9abbf39db/detection

187.122.224.72:5214

# Reference: https://www.virustotal.com/gui/file/4d5e47d30b62dcb134f3c2964f70e18efd73df1e6c8da5cc1e6582ec62fe366d/detection

177.64.155.133:5214

# Reference: https://twitter.com/malwrhunterteam/status/1248661416791465984

anti-corona.app

# Reference: https://www.virustotal.com/gui/ip-address/144.76.30.213/relations

144.76.30.213:443

# Reference: https://twitter.com/LukasStefanko/status/1250451829877587968
# Reference: https://www.virustotal.com/gui/domain/pataraha.com/relations

pataraha.com/apps/downloads/

# Reference: https://twitter.com/malwrhunterteam/status/1251514856114737154
# Reference: https://www.virustotal.com/gui/file/234fab850c14c91c9e0cd0b2a003c5ce9d17aeba5e88b24abd29c7cab89181ba/detection

frewasss.myq-see.com

# Reference: https://www.virustotal.com/gui/file/74cea86b03f5a3f31a8b5f262f3ff8349eb406f3ea0221d34ea85cde46717f4c/detection
# Reference: https://www.virustotal.com/gui/file/9a436bf2e60a9682d5cd5c4c74fa87c56e094ebaec03b8818d84298af1fd8b05/detection
# Reference: https://www.virustotal.com/gui/file/043c30441bde4a1f839bbbb06aa0651fb80f043510848c7a22cea33ddc966136/detection
# Reference: https://www.virustotal.com/gui/file/3aff643f9121af2881b7995c7cfc7fe456e87bf189765576c96a0a6e4273dead/detection

141.255.147.237:2492
91.192.6.212:2392
91.192.6.212:2492
q1q1q1.ddns.net

# Reference: https://twitter.com/malwrhunterteam/status/1252909522605277184
# Reference: https://www.virustotal.com/gui/file/ccb7c588115211956598f8af7ac66c0feabf6ba7b6b6832a7f66ad2edf2492d3/detection

39.53.94.143:4444
tandertx.ddns.net

# Reference: https://twitter.com/ReBensk/status/1254691066298511360
# Reference: https://www.virustotal.com/gui/file/253262aa1b7eb99796acbcccdedb3cf627e32042ab35a75544c23af9e25a76b3/detection
# Reference: https://www.virustotal.com/gui/file/bdffec168572196309fd356c26e0db5180d083297f76264945f463635fc5ed98/detection

197.206.139.184:71
41.105.255.65:71
steemit.hopto.org

# Reference: https://www.virustotal.com/gui/file/f733ded73d4f498327480d232e415465c0f5654a69b431da081f83998b49ead2/detection

193.161.193.99:45467
gwennie.duckdns.org

# Reference: https://twitter.com/malwrhunterteam/status/1256471836457684992
# Reference: https://www.virustotal.com/gui/file/c140c29382aae632858fdb39f0fd9fe0737b7d758c818b582cea89354524937a/detection

185.166.27.9:5555
whoami769.hopto.org

# Reference: https://twitter.com/malwrhunterteam/status/1258671300777783297
# Reference: https://www.virustotal.com/gui/file/638f7ae0adb26c5f57243c098a5f47781a981318c2461f9a3a2759ba9ef33cae/detection

111.94.75.182:2219
202.162.210.172:2219
mikymouse.ddns.net

# Reference: https://www.virustotal.com/gui/file/15ad81a58df7a8fdf5f1f0d4fe6917989ae51d0fa0b3584b3ab7aebbe19af8f9/detection

105.105.215.75:3210
141.255.159.128:3210

# Reference: https://www.virustotal.com/gui/domain/hammoud777.ddns.net/relations
# Reference: https://www.virustotal.com/gui/file/e701dfabda46e950db66fca6823198765f7226c9cda0f9bdb301d0af4045243b/detection

141.255.147.63:1177
141.255.155.10:1177

# Reference: https://twitter.com/malwrhunterteam/status/1260890636737273858
# Reference: https://www.virustotal.com/gui/file/3f69bc4b7fc50db582b13835206d2480acc66919db9123b37cf97f7f3da3b443/detection

193.161.193.99:37916
johnnj2-37916.portmap.io

# Reference: https://www.virustotal.com/gui/file/97a286e006d2233f0a2b9d2d0b680dcf9a163b3d2646d0b9fd5f12aec5a61cbf/detection

193.161.193.99:48572
wajikhan.duckdns.org

# Reference: https://twitter.com/malwrhunterteam/status/1260892816307367937
# Reference: https://www.virustotal.com/gui/file/885d07d1532dcce08ae8e0751793ec30ed0152eee3c1321e2d051b2f0e3fa3d7/detection

204.48.26.131:29491
prettysavantwholesale.com

# Reference: https://twitter.com/ReBensk/status/1261155044059222016

contactsocialmedia.tk

# Reference: https://twitter.com/Sh1ttyKids/status/1261022463002947584

spynote.us

# Reference: https://twitter.com/ReBensk/status/1261647350579097601

microsoftupdating.online

# Reference: https://www.virustotal.com/gui/file/af50e1ae653109062254c5fadc030cc7d61db21272e56d5754572f21faf903c6/detection

thecreator2020.ddns.net

# Reference: https://twitter.com/malwrhunterteam/status/1262430537714728960

aragerot.com

# Reference: https://twitter.com/malwrhunterteam/status/1262454926074093569

156.220.5.128:1337
spynotesooker17.ddns.net

# Reference: https://www.virustotal.com/gui/file/efb8414f3d653685de5c0cc421d64fb36f757f462d51ac41f8fd6b5a76f1772a/detection

193.161.193.99:39546
farhad5010-39546.portmap.io

# Reference: https://twitter.com/ReBensk/status/1268742575537549316

m8dmkw.dynu.net

# Reference: https://twitter.com/malwrhunterteam/status/1269300424693239809
# Reference: https://www.virustotal.com/gui/file/ab079c5e6189c241000ce4da51f9e18b9f68d408d524bc88ea695f3280c42349/detection

105.155.228.6:3210
imsgms.myvnc.com

# Reference: https://www.virustotal.com/gui/file/36ff6698d50a85504bc876f4878de1b911082effa6d3c445ebf9924184fd17a2/detection

193.161.193.99:62364
antorkhan-62364.portmap.io

# Reference: https://www.virustotal.com/gui/file/9aa01a909ccd2300d0c196fa2b408fe63c9b2aae0abe5acd1e2c2d03ec1ebdc4/detection

217.54.133.82:4444

# Reference: https://www.virustotal.com/gui/file/0cb7e42bd7f9bfbd6e048f59cce4a0e3f1e963981b7f0c5970a86a70583d2b68/detection

62.114.186.254:9999

# Reference: https://www.virustotal.com/gui/file/d710bd370bac3ea7cfd737ad243d107ba870e03886ca7fa945b838e66fe867c4/detection

217.54.88.221:9999

# Reference: https://www.virustotal.com/gui/file/6f129c7805b6997974bf1a1939f0e473708711cfb896460ea02a52ae6818259f/detection

62.114.215.21:4000

# Reference: https://www.virustotal.com/gui/file/cc5b7eb74dd0f51ed76a061350fec6b1b61b8262ddb6288ee981ac080c31a5c4/detection

62.114.207.156:9999

# Reference: https://twitter.com/malwrhunterteam/status/1271855227411587072
# Reference: https://www.virustotal.com/gui/file/ccf588a728abb3f9a1f1b1d0d8f02b1a3a0ff4198589b25575969d0428a8a66b/detection

82.137.218.185:215

# Reference: https://www.virustotal.com/gui/file/aa9133d68ebbb8f777b685ec15a358e0fb2d572bd30ce962d3d1b0c53b785523/detection

185.255.46.114:5551

# Reference: https://www.virustotal.com/gui/file/40836373cb307d6472e20f2c65916ee2ab291fdb27864d456fc5fbe2ec927d21/detection

192.169.69.25:24306

# Reference: https://www.virustotal.com/gui/file/5fc0d6fe1d249ed433dba8f9ad03307748434ca08a6ae729858c2382861c4d04/detection

190.74.113.35:8000
enrike653.ddns.net

# Reference: https://www.virustotal.com/gui/file/45ef21cca5c70be1f607252c89ebf4873795fe53fa214ed627b24f9000d1852f/detection

190.73.153.239:8000

# Reference: https://www.virustotal.com/gui/file/592bdfea96900f38525b6afe0b353cca422923052360c771b3fd1d3729824494/detection

141.255.146.170:3210
mlh123.ddns.net

# Reference: https://www.virustotal.com/gui/file/6f046db5bbd119d9d383a46ead8c1369ac597c37ea567144c341ea5e9ebed3e9/detection

141.255.145.115:3210

# Reference: https://www.virustotal.com/gui/file/c6954678b39e121c60fd691275238267f97f5ce4264255458c06e155a232423c/detection

141.255.153.22:5214

# Reference: https://www.virustotal.com/gui/file/ce4db4c837defde7461daa1a8a77a0232629b881a21a5741cdb072cf4d897552/detection

141.255.157.158:5214

# Reference: https://www.virustotal.com/gui/file/90d5a6b010901ed67c861d0c3bfdd21f894c13c094a06b78cccc16625c6147de/detection

37.8.24.221:5214

# Reference: https://twitter.com/SecuriTears/status/1276907531231727616
# Reference: https://www.virustotal.com/gui/file/41b2e5473836a59bbba209b9a0d346b22f7e9bb9d1b4c90ca9b5f1626112ee31/detection

http://49.233.182.150
49.233.182.150:3210

# Reference: https://twitter.com/bl4ckh0l3z/status/1281591279122550784

193.161.193.99:53976
reddesk-53976.portmap.io

# Reference: https://www.virustotal.com/gui/file/d716ba34cad70fb14dfe490252a655630e14ffb6aeb221e4d839e9cc63589df9/detection

193.161.193.99:59671
Eathenjacobe-59671.portmap.host

# Reference: https://www.virustotal.com/gui/file/23f3b76890b7a41efca6288e00689425ffabe8113b8f0ec71b6ab113dd434029/detection

njfdu84hc83nb8-46899.portmap.io

# Reference: https://twitter.com/ReBensk/status/1283666334295838721

monprofil.online

# Reference: https://twitter.com/ReBensk/status/1290158109395050497
# Reference: https://www.virustotal.com/gui/file/f6ec2dbd9d6bff73d626321a6e889e64db3a7c2a3dbdc6f7eae6bcf3be09167f/detection

arduinofreaks.ml

# Reference: https://www.virustotal.com/gui/file/e5c415b3d79694a5e89d5d813a88200b3516648a6808911dbb365c61a4efd578/detection

41.108.251.174:3210

# Reference: https://www.virustotal.com/gui/file/d9d82adc58d5950c7c91a9c484ba1d1142132acd23b6a42a56b3d807a05e0918/detection

86.4.221.98:4040
apexspoofer.duckdns.org

# Reference: https://www.virustotal.com/gui/file/0e7e14a743c7d5d589d7c617bc2ac1094b9bcf5f0c8d99657f1c392568ce477f/detection

154.236.146.219:4444
154.236.90.116:4444
41.199.197.93:4444
217.55.49.9:4444
body.bounceme.net

# Reference: https://www.virustotal.com/gui/file/32cdfdb08716efc720deb34fed85cff65523d66e26022571ba96c65c6fddaf4d/detection

bnbn.ddns.net

# Reference: https://www.virustotal.com/gui/file/7b0984af6b49c12cb0e8322aad0611fd497f3ee9d801515b5eaf9591b327726f/detection

deepnest.duckdns.org

# Reference: https://www.virustotal.com/gui/file/47d0fd4eca95d85e9d00fb3e14b295f5023f7ad6bf34fde63393f373baf545bb/detection

187.40.132.99:3473

# Reference: https://www.virustotal.com/gui/file/79c51704b4565ee42ad05e482db9f471d847858fdebb5793df49f8a9867eb591/detection

197.59.102.90:1177
mr32123.ddns.net

# Reference: https://www.virustotal.com/gui/file/c5153499bfabb6ddcefba591b6fba081ff8851ca1910793e66cf9e810857eb9b/detection

194.176.99.68:4444
idkjustgo.ddns.net

# Reference: https://www.virustotal.com/gui/file/3446f499aa768e5afc5cc19b02d430ceaffefd17872d1bccf2467b2b54f848c0/detection

193.161.193.99:62207
hm1234-62207.portmap.host

# Reference: https://www.virustotal.com/gui/file/37f8afdc1117de292a29f9449824ad40d76b67d96ff0b5feef773bb1c7ae1b29/detection

193.161.193.99:42421
kr1pt0n-46860.portmap.host

# Reference: https://www.virustotal.com/gui/file/9e5aa550fa4bcf3d2d48269d19efca3e708ed6a9572e61d4613ee2f754e7b7c4/detection

193.161.193.99:38300
yozoraxph-38300.portmap.host

# Reference: https://www.virustotal.com/gui/file/11714a034d9bc0b9c617b898963342727ac140e8106fc1d3cd92a30fd3edfccb/detection

193.161.193.99:23892
mascarpone-35171.portmap.host

# Reference: https://www.virustotal.com/gui/file/a18c9ce516b4494c65475b85c283e32b4f5777ea3fb055a4a0f702b640a8a7b4/detection

193.161.193.99:58574
dhruwr9-58574.portmap.host

# Reference: https://www.virustotal.com/gui/file/13a7415335abc943cb5dfe17d994b1f81f4b21703e9a7695a9522bbfb355c720/detection

193.161.193.99:36201
hackimti-36201.portmap.host

# Reference: https://www.virustotal.com/gui/file/7784822e37f4d3f5ca7b1d65bf1104e9ab28495a629a4105af90ddeb47258bbf/detection

193.161.193.99:28869
assa-28869.portmap.host

# Reference: https://www.virustotal.com/gui/file/88123fd9567f112872ab373685ff30267f291a18d6f892c22d5d59d26af29d49/detection

193.161.193.99:44144
kichae-42764.portmap.host

# Reference: https://www.virustotal.com/gui/file/1163c5e75d8a149dd342220f04aeb5b4924c59dd6b3a854bc5d0ebfe58fc8cfb/detection

193.161.193.99:35767
wolfx-35767.portmap.host

# Reference: https://www.virustotal.com/gui/file/640d7352ade1e47a264a868363c528f926fd41e30b151b42623b748bd1085a4c/detection

193.161.193.99:29042
toth-27008.portmap.host

# Reference: https://www.virustotal.com/gui/file/c9ad77b616fb56b34da6da9a15232b1f421003c728c127b95e87a8e527adb8f3/detection

193.161.193.99:22354
anon6863-48284.portmap.host

# Reference: https://www.virustotal.com/gui/file/d935ccd35e3979204f2c8f48173121f88bc82ef4fa96abc64348bc8992cc9092/detection

193.161.193.99:4242
193.161.193.99:64775
vishal99099-64775.portmap.host

# Reference: https://www.virustotal.com/gui/file/01ea9c2c06882c5555cbba14ee84153167cd46db0ea4ecb9c19dacb5123f24e9/detection

193.161.193.99:38353
hunterhmd-38353.portmap.host

# Reference: https://www.virustotal.com/gui/file/7d544e33d95b33935ab3f288ceb1ad15bc44be72936ae8bea66a2a65391577fe/detection

193.161.193.99:38508
black9654-38508.portmap.host

# Reference: https://www.virustotal.com/gui/file/a8cefcfcce3d79812f11e614102acce8bdf4253df405604ac01ca7c2e746c300/detection

193.161.193.99:31722
siraxeb658-62133.portmap.host

# Reference: https://www.virustotal.com/gui/file/4edeaa23afece052dccd3d2ca9cdeb32b4962058abf6e297c5e6f020256fe37f/detection

193.161.193.99:27460
ddindia-33351.portmap.host

# Reference: https://www.virustotal.com/gui/file/b04d6535e696e8378d36f93e575fd37dc9cffd2cb1ce36b5276df80e4eb7729e/detection

178.32.12.103:2222
94.47.17.91:2222

# Reference: https://www.virustotal.com/gui/file/e907b35f7afd7b96c8e08cd1043622926a205411606a807210a9eb2ab260b562/detection

193.161.193.99:25263
apaya-25263.portmap.io

# Reference: https://www.virustotal.com/gui/file/de779ec44f5c458621b104c44d88f7e268d8798b67597b7861ca94f9595bd43a/detection

199.66.93.68:5552

# Reference: https://www.virustotal.com/gui/file/2f0fc0f90e3abbf3017dfbe562a5341610206788e0f1671d110acecb149cc6d4/detection

41.105.44.177:3210

# Reference: https://www.virustotal.com/gui/file/9b50d732354e7aa8bcef6603b575584871797c6e2171364f6a144d3804483293/detection
# Reference: https://www.virustotal.com/gui/file/9b50d732354e7aa8bcef6603b575584871797c6e2171364f6a144d3804483293/detection

102.69.5.159:2222
192.169.69.25:2222

# Reference: https://www.virustotal.com/gui/file/3aca04e3a574bccad8086323516abaf90f05cbb36a37053b88fe562131612cbf/detection

45.74.46.195:8181

# Reference: https://www.virustotal.com/gui/file/0d69ea9679b293299234b44004670fa3eb667734709af83edf0914fcb6508a90/detection

45.74.46.199:5214

# Reference: https://www.virustotal.com/gui/file/6140caeb42927993ee127c1976dc8bafc6f6456c60f120d94c7ef919d3dea14d/detection

196.75.140.215:2020
snowypix.hopto.org

# Reference: https://www.virustotal.com/gui/file/f5cd7798179e2d713e31812b15ca0189dfe97f7e25ac796e6f36d181a96efcd0/detection

41.142.85.225:3333
simoxsimox.ddns.net

# Reference: https://www.virustotal.com/gui/file/403e620134abfde92d5611b7949cde966b0fedaea58213d635a9105b48fe0c85/detection

105.156.80.242:3333
191.101.124.175:3333
mrxtnt.ddns.net

# Reference: https://www.virustotal.com/gui/file/ffaa313fb3aba56b439c8e6c40bd03d6627158a2a4c6a23a74ec8cad318af452/detection

41.142.230.203:3333

# Reference: https://www.virustotal.com/gui/file/df88a0c05a3a53d2ea33703d4ecd3705d30940bc79c09e9b8e86ced707514b28/detection

41.140.184.191:3333
41.142.224.183:3333

# Reference: https://www.virustotal.com/gui/file/a024ef4ecc1a497e97f34a0ab6c117205621754f4bee5cb7855c6af775ba369e/detection

105.156.90.254:3333

# Reference: https://www.virustotal.com/gui/file/8abd566ed52e4ed9c76d49afd85a20d6988be321118dbea5151435cda98cefbf/detection

182.180.49.15:7777
needforrat.hopto.org

# Reference: https://www.virustotal.com/gui/file/361a6c8d74b59a5669ca425bed423bf45b23adab8f07625bcdb37a98e8696807/detection

67.227.226.240:1337
ahmadremawi.system-ns.net

# Reference: https://www.virustotal.com/gui/file/3a4510584d53ff1233fca61fafb0f86ec1b62f0a04e82970d7d917e5f09293fd/detection

197.59.115.31:5214

# Reference: https://www.virustotal.com/gui/file/5f499b804d3d37060ee3f0ee0f329bccdf59e3ee4f9f7ff610c253389a275bb5/detection

89.39.107.197:2222
1234noba.ddns.net

# Reference: https://www.virustotal.com/gui/file/e35bad73e6bdf7afff5e967399daa0e16cbf4cb4413148460596d0ea79b47e1d/detection

62.201.255.38:5214
79.134.225.124:5214
adam9.ddns.net

# Reference: https://www.virustotal.com/gui/file/bda8637d0bbeec23ba68f328fbd3a84db20b9d734b7a0c20d04bd7dbbd2a2c2a/detection

79.134.225.124:3210

# Reference: https://www.virustotal.com/gui/file/c657c331a6e73443bb89f0d98925771e92489e699e0c185667902c20e293e63c/detection

62.201.254.218:4000

# Reference: https://www.virustotal.com/gui/file/22b035d4c497bd9bb520e49e3a1355bfb248369a49391824af7d54157619ce5a/detection

79.134.225.124:8181

# Reference: https://www.virustotal.com/gui/file/4bbfef5f36feb663e564721352ff3cdea466a6372306c9c7aa66524e97f01bb6/detection

62.201.255.6:5214

# Reference: https://www.virustotal.com/gui/file/bc0c55efffe32ba0d2bdc23d5aa9d60200b50c5a373bce9822af6316cdd4f2fb/detection

79.134.225.124:4000

# Reference: https://www.virustotal.com/gui/file/f64e25a5aac68cc011e6578f4f3832767f81c26a9652b43afd8d9d156d774912/detection

62.201.242.88:4000

# Reference: https://www.virustotal.com/gui/file/698b68cfaceb3b7b63646cbcca394838057ba84944b248beaf1ae145a180e719/detection

62.201.240.193:5214

# Reference: https://www.virustotal.com/gui/file/ac3fa09ffee643790e1e208a758c20b6cecf8f1737dd9f47cef1407471256a79/detection

888rat.hopto.org

# Reference: https://twitter.com/malwrhunterteam/status/1315743478593343489
# Reference: https://www.virustotal.com/gui/file/43eb81706caed170357244a8d4ff16316368b239c2a132f18f3a1b8e634cd7f2/detection

toutapc.myftp.biz

# Reference: https://www.virustotal.com/gui/file/c70d4b3c056d8dfa69eda66180b817d028acd979b16de519fcf30525bdd1487c/detection

41.230.96.3:3210

# Reference: https://www.virustotal.com/gui/file/a2451b0dcaec6eea3566abd8b19bb36ea2c41d321301e1c9a0f077c21fa90c6a/detection

46.43.82.146:2255

# Reference: https://twitter.com/malwrhunterteam/status/1317469278132703235

hediyekarti.22web.org

# Reference: https://www.virustotal.com/gui/file/0ee6f6a2626f92d0fc2a738825de8e087bfc1b5c9455517ee73dfb68aa68ea71/detection

41.239.87.219:5552
mesho13568.ddns.net

# Reference: https://www.virustotal.com/gui/file/eef6a9f76e671d56eb7f55284d8686ecc014f29decb713c6d6716c30bb3e2393/detection

141.255.147.20:5010
rofixman.myq-see.com

# Reference: https://www.virustotal.com/gui/file/cec9b39be8831de276e364cfe75f9967f94602fac924917babcd903781f47181/detection

6ix10en.ddns.net

# Reference: https://www.virustotal.com/gui/file/086caa69a22c90ec4884410cea99eec579bc872c9354a66a8822ceb59aab4d71/detection

89.189.84.169:8080
8ddjdgugs99.ddns.net

# Reference: https://www.virustotal.com/gui/file/c77a066c9774e12d6a49589196463c1c96244225dde6b3a6f5af1b7dac34f46c/detection

41.104.49.27:1988

# Reference: https://www.virustotal.com/gui/file/4f5e43c27f8e38d37983771e3b9dc61a9bb253cea8412238bc4feef17f7568ef/detection

197.207.184.71:1988

# Reference: https://www.virustotal.com/gui/file/6a05848f403d2f60ab798488f5176a79be7ca51e56dd551aa0fac8bbc8a5a46e/detection

197.207.173.110:1916
41.104.53.81:1916
41.105.45.5:1916

# Reference: https://www.virustotal.com/gui/file/c7243be00dc84c2ff83bd9fd4581e6b8ecab9ad8056076ae84c88556de0a761b/detection

181.51.127.244:3210
201.232.179.81:3210

# Reference: https://www.virustotal.com/gui/file/d4b6c1ecad98bc4c694afe943e1f3e7d559105ebeaf337311bf2ebaff26ae332/detection
# Reference: https://www.virustotal.com/gui/file/201d4a3b2d550d5cc8e0fc213abc5565f3b771919ad3a7087886440fe9e96d0e/detection

197.38.31.75:1337
197.38.50.73:1337
197.39.98.118:1337
41.43.23.72:1337
41.43.239.241:1337
abcabc2002692.ddns.net

# Reference: https://www.virustotal.com/gui/file/7bd4c48af2085cc085d53f503b727945a93db709307085120ab887e6dd588637/detection

189.6.120.28:1000
dlrodvox.ddns.net

# Reference: https://www.virustotal.com/gui/file/44aa8ee46dda6d043704c34046d404e020fd57c2e546a0ef476914ad9ab16e71/detection

118.24.85.85:3210

# Reference: https://www.virustotal.com/gui/file/7574f21911d0dc9c7240da975e2c00ab26cdbc632b1e226c534a5c8a13bd2cc8/detection

3.129.187.220:18202

# Reference: https://www.virustotal.com/gui/file/120146134587fe32a320303e440ac2c3c5cb5ae2b650021a3b2653b3c6c2a396/detection

141.255.153.144:1177
191.184.244.32:1177
eaegurizada.duckdns.org

# Reference: https://twitter.com/ReBensk/status/1337233675377930242
# Reference: https://www.virustotal.com/gui/file/ec661366a3767e20f839ebfe8c9baef3e65aaef90407d6cb61468d440716f76e/detection

34.92.173.92:7771
covid19.servehttp.com
tello122j.onthewifi.com

# Reference: https://www.virustotal.com/gui/file/5f4df9d6bda84ef496301a0388da6c34e7467ba628b78078a76a059a0da08e17/detection
# Reference: https://www.virustotal.com/gui/file/fde3ef90993481e9a413164fae13c6e2140639749a0ab4964a5241cc63563a49/detection

134.35.81.176:1177
5.255.27.5:1177
fackyouman123456789.ddns.net

# Reference: https://twitter.com/malwrhunterteam/status/1308439809594191872
# Reference: https://twitter.com/bl4ckh0l3z/status/1308450629027860481
# Reference: https://www.virustotal.com/gui/file/caaed52688bac628268ff3482d0e5f60e47d8f317bef3fecacf93b434c7692d7/detection

13.59.15.185:11721
3.128.107.74:11721
3.130.209.29:11721
3.131.123.134:11721
3.131.147.49:11721
3.131.207.170:11721
3.138.45.170:11721
3.17.202.129:11721
3.18.75.105:11721
3.19.6.32:11721
3.20.96.224:11721
3.21.60.148:11721
3.22.15.135:11721
3.22.53.161:11721
3.23.201.37:11721
52.14.18.129:11721

# Reference: https://twitter.com/malwrhunterteam/status/1283484998432182273
# Reference: https://twitter.com/bl4ckh0l3z/status/1283513238336999425
# Reference: https://www.virustotal.com/gui/file/6dae1d095fe28cf717ab250580b77daeae27c59a93a8a6ee899829083203eab0/detection

41.254.43.46:4444
karama216.ddns.net

# Reference: https://www.virustotal.com/gui/file/7d381ae3d4554e799807b42fffa4e1207c28377d0a66fb77f14965619488f991/detection

85.86.181.192:1337
anunankis.dynu.net

# APK

/FUCK__U_.apk
/HediyeKart%C4%B1n%C4%B1Kullan.apk
/HediyeKartınıKullan.apk
/karma.apk
/KUPRJQ.apk
/Synhron.apk
/up4net-pubg-mobile.apk
/Youtube22.apk
