IP addresses
- 131.228.12[.]0/22
- 144.86.226[.]0/24
- 20.140.0[.]0/15
- 224.0.0[.]0/3
- 96.31.172[.]0/24
- fc00:: - fe00::
- fec0:: - ffc0::
- ff00:: - ff00::
Domains
SUNBURST uses a domain generation algorithm (DGA) to construct and resolve subdomains of avsvmcloud[.]com in order to receive commands. These subdomains are concatenated with one of the following to generate hostnames:
- .appsync-api.eu-west-1.avsvmcloud[.]com
- .appsync-api.us-west-2.avsvmcloud[.]com
- .appsync-api.us-east-1.avsvmcloud[.]com
- .appsync-api.us-east-2.avsvmcloud[.]com
The following domains are typical of SUNBURST's DGA implementation:
- 6a57jk2ba1d9keg15cbg[.]appsync-api[.]eu-west-1[.]avsvmcloud[.]com
- 7sbvaemscs0mc925tb99[.]appsync-api[.]us-west-2[.]avsvmcloud[.]com
- gq1h856599gqh538acqn[.]appsync-api[.]us-west-2[.]avsvmcloud[.]com
- ihvpgv9psvq02ffo77et[.]appsync-api[.]us-east-2[.]avsvmcloud[.]com
- k5kcubuassl3alrf7gm3[.]appsync-api[.]eu-west-1[.]avsvmcloud[.]com
- mhdosoksaccf9sni9icp[.]appsync-api[.]eu-west-1[.]avsvmcloud[.]com
Resolved domains
- databasegalore[.]com
- deftsecurity[.]com
- digitalcollege[.]org
- ervsystem[.]com
- freescanonline[.]com
- globalnetworkissues[.]com
- highdatabase[.]com
- incomeupdate[.]com
- infinitysoftwares[.]com
- kubecloud[.]com
- lcomputers[.]com
- panhardware[.]com
- seobundlekit[.]com
- solartrackingsystem[.]net
- thedoccloud[.]com
- virtualdataserver[.]com
- virtualwebdata[.]com
- webcodez[.]com
- websitetheme[.]com
- zupertech[.]com