Gootloader malware command and control servers
realugbun opened this issue ยท 6 comments
realugbun commented
Goot loader infects machines and is the first step in a ransomware attack.
A full writeup on goot loader listing the servers can be found here.
https://www.mandiant.com/resources/blog/tracking-evolution-gootloader-operations
## Goot loader command and control
0.0.0.0 jonathanbartz.com
0.0.0.0 jp.imonitorsoft.com
0.0.0.0 junk-bros.com
0.0.0.0 kakiosk.adsparkdev.com
0.0.0.0 kepw.org
0.0.0.0 kristinee.com
0.0.0.0 lakeside-fishandchips.com
krystian3w commented
IP can not by used in HOSTS or domains list: StevenBlack/hosts#1006 StevenBlack/hosts#1004
realugbun commented
I have updated the request to remove pure ip addresses.
realugbun commented
Thank you for adding these and thank you for maintaining the list!
krystian3w commented
github-actions commented
This thread was automatically locked as/because there was no activity after it was closed. Please open a new ticket for related issues.