# Copyright (c) 2014-2019 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission

# Aliases: netwiredrc, netwire, wirenet

# Reference: https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~NetWire-EK/detailed-analysis.aspx

mommyreal.ddns.net

# Reference: https://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Troj~NetWire-CC/detailed-analysis.aspx

wwfvpsv9.serveftp.com

# Reference: https://www.cyren.com/blog/articles/bad-things-come-in-pairs-3004

dinesaad.hopto.org

# Reference: https://twitter.com/James_inthe_box/status/1044616045560967168

cboss33.hopto.org

# Reference: https://twitter.com/James_inthe_box/status/1044365272675573760

natigr.ddns.net
projectadmin.camdvr.org

# Reference: https://twitter.com/James_inthe_box/status/1044231367347732480

ddns.catamosky.biz

# Reference: https://twitter.com/Racco42/status/1042056130577489928

lagos042.ddns.net
manuel3.publicvm.com

# Reference: https://twitter.com/VK_Intel/status/983940199603474432

snoopdmoney2018.sytes.net
snoopdmoneybkup.sytes.net

# Reference: https://www.virustotal.com/#/file/a095a7acda9c73fc89bfbc170bbec75a4572c75114e1687a7c212e9228915945/detection
# Reference: http://www.kernelmode.info/forum/viewtopic.php?f=16&t=3966&sid=a2bb410851e96a6bb24b90b65966112f&start=300#p32187

ola100.hopto.org

# Reference: https://twitter.com/malwrhunterteam/status/1106264932230852608

62.210.10.245:4000

# Reference: https://twitter.com/malwrhunterteam/status/1105163365209554951

amazonsprime.duckdns.org

# Reference: https://twitter.com/JAMESWT_MHT/status/1107630659957329921

leew.linkpc.net

# Reference: https://twitter.com/James_inthe_box/status/1022228835616473088

onetimeade.linkpc.net

# Reference: https://twitter.com/malwrhunterteam/status/1096760442133856256

jackas.gotdns.ch

# Reference: https://maskop9.tech/index.php/2019/01/30/analysis-of-netwiredrc-trojan/
# Reference: https://app.any.run/tasks/e1d7034b-c866-4cef-8d55-04405cd2a81d

109.230.199.103:3360

# Reference: https://twitter.com/James_inthe_box/status/1118217392851566593

havemercy.mooo.com

# Reference: https://twitter.com/malwrhunterteam/status/1122081049809432576

netzirecolq.gleeze.com

# Reference: https://twitter.com/MalwareConfig/status/748754926319181824

socratecafu.zapto.org

# Reference: https://twitter.com/MalwareConfig/status/748754880869707776

monarch01.no-ip.org

# Reference: https://twitter.com/MalwareConfig/status/748625532993019904
# Reference: https://malwareconfig.com/config/d5ce94e9264321d398767c1e3d1a5835/

46.244.10.196:3480

# Reference: https://twitter.com/MalwareConfig/status/748625240486477825

jack.redirectme.net

# Reference: https://twitter.com/Jouliok/status/1123141238197248001
# Reference: https://app.any.run/tasks/9de6804d-2e31-4f55-a225-d99191196803

duc1234.duckdns.org
91.192.100.57:32144

# Reference: https://twitter.com/ps66uk/status/1104050986031767552
# Reference: https://app.any.run/tasks/4b6c4b34-7bc3-41ca-8a35-78399db8e591

akconsult.linkpc.net
185.84.181.94:2018

# Reference: https://twitter.com/luc4m/status/1092365190497255424

checker00.gotdns.ch

# Reference: https://twitter.com/luc4m/status/1072888268528779264

pd1n.ddns.net

# Reference: https://twitter.com/Racco42/status/1062633238802378752

wealthyadmin.ddns.net

# Reference: https://twitter.com/James_inthe_box/status/1059464666672332800

favor.duckdns.org

# Reference: https://twitter.com/Racco42/status/1057317617260736513

godalmighty.ddns.net

# Reference: https://twitter.com/ps66uk/status/1050043711135068161

185.101.93.198:8681

# Reference: https://twitter.com/James_inthe_box/status/1115624726695514113

masterhugo231.servecounterstrike.com

# Reference: https://twitter.com/James_inthe_box/status/1065330244746268672

185.84.181.80:3360

# Reference: https://twitter.com/avman1995/status/1060818874789179392

ddns.unknajiamu.xyz

# Reference: https://twitter.com/pollo290987/status/907273472786812928

199.16.199.2:36133

# Reference: https://twitter.com/JAMESWT_MHT/status/906146267763486720

egonbute.duckdns.org

# Reference: https://twitter.com/Antelox/status/894901722497208321

192.223.25.72:1777

# Reference: https://twitter.com/JayTHL/status/751123206468046848

businessdb3.duckdns.org

# Reference: https://twitter.com/malware_traffic/status/714819056218406914

marchborn.no-ip.biz

# Reference: https://twitter.com/James_inthe_box/status/1123236500311724032

bazwire.sytes.net

# Reference: https://twitter.com/fe7ch/status/1126132771800395777

usb.mine.nu
message-whatsapp.com
zr.webhop.org
enz.webhop.org

# Reference: https://twitter.com/Racco42/status/1132935875430670337
# Reference: https://twitter.com/Racco42/status/1136593634650927105

96.47.239.229:3999

# Reference: https://twitter.com/James_inthe_box/status/1133344506814668800

160.116.15.155:3360

# Reference: https://twitter.com/raby_mr/status/1136889525060325376
# Reference: https://app.any.run/tasks/03268b84-b31c-4a32-a87b-95e7aa4cf8a9/

102.165.38.139:33
heritage.nflfan.org

# Reference: https://www.fireeye.com/blog/threat-research/2014/04/crimeware-or-apt-malwares-fifty-shades-of-grey.html

c0der.zapto.org
rglink77.no-ip.biz

# Reference: https://twitter.com/James_inthe_box/status/1138454939045453825

enginekeys.ddns.net

# Reference: https://twitter.com/James_inthe_box/status/1140571341344538625

duc1234.duckdns.org

# Reference: https://twitter.com/daphiel/status/1141625032801693696 (# CVE-2019-11707)
# Reference: https://twitter.com/cybsecbot/status/1141610397931323393
# Reference: https://www.virustotal.com/gui/file/07a4e04ee8b4c8dc0f7507f56dc24db00537d4637afee43dbb9357d4d54f6ff4/detection (# OSX Netwire/Wirenet)

185.49.69.210:80 
89.34.111.113:443
a678157.oicp.net

# Reference: https://twitter.com/JAMESWT_MHT/status/1142038342583894017

packgeddhl.myddns.me

# Reference: https://twitter.com/HerbieZimmerman/status/1142085603368079361
# Reference: https://app.any.run/tasks/f61c3c81-52aa-4e11-b746-c7c27bc3b7f4/

gojust.publicvm.com

# Reference: https://twitter.com/killamjr/status/1145110513371820033
# Reference: https://twitter.com/killamjr/status/1145114752890413057

185.247.228.73:9510

# Reference: https://pastebin.com/S4ggik78

maxmini.duckdns.org

# Reference: https://twitter.com/killamjr/status/1146521318503964678
# Reference: https://app.any.run/tasks/1c48f325-f211-4442-8cd4-03ed4cd9e538/

88.208.246.122:4110
longman001.chickenkiller.com

# Reference: https://twitter.com/James_inthe_box/status/1146468739493199873

chance2019.ddns.net
