# Copyright (c) 2014-2026 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission

# Reference: https://x.com/cleafylabs/status/1994332276109271538
# Reference: https://x.com/solostalking/status/1994441692640903466
# Reference: https://www.cleafy.com/cleafy-labs/albiriox-rat-mobile-malware-targeting-global-finance-and-crypto-wallets
# CLASS_0_HASH-HOST=2a672292d30cd24f34127db8be406dce
# FAVICON_HASH-HOST=930331d0dfa633ad63997743a29b7d6b

194.32.79.94:5555
212.11.64.50:5555
69.5.189.206:5555
91.227.41.88:5555
crypto-money24.cash
google-aplication.download
google-app-download.download
google-app-get.com
google-app-install.com
google-get-app.com
google-get-app.download
google-get-download.download
google-get.download
google-get.loan
google-get.org
penny-at.com
penny-at.net
penny-at.org
penny-at.uk
penny-at.win
penny-gift.org
pennywheel-at.com
pennywheel.org
play.google-get.store

# Reference: https://x.com/Fact_Finder03/status/2012403215346651141

http://185.208.156.92
82.146.60.30:443
albion-bwb.pages.dev
albiriox.com
albiriox.dev
albiriox.pages.dev
albiriox.su
allbirioxes.pages.dev
privacei.com
vanish.exchange
purchase.albiriox.com

# Reference: https://x.com/apkdetect/status/2016892108590776496
# Reference: https://www.virustotal.com/gui/file/6a440dfa5c59960575f07ab81e779e2066bb0f3541e58ce5c0ab319d34e19b56/detection
# Reference: https://www.virustotal.com/gui/file/bde35bb8bf728613734c338428f88ce9104f663093980bfdf7ee2fd39585cb2a/detection
# Reference: https://www.virustotal.com/gui/file/ff91ebd937db5e8e6f3de8e24d9ff509d973e1bc37d0fd92ca444b5cdcbf6a1c/detection
# CLASS_0_HASH-HOST=77f74f86524a1e50e29938c46524f62d

appfedex.com
fedexcall.com
guidefedex.com
infofedex.com
livenettvtv.com
updateproximus.com
mail.appfedex.com
mail.fedexcall.com
mail.guidefedex.com
mail.infofedex.com
