Executive Summary
An information security researcher reported on November 20 that the Daixin Team ransomware group had claimed that a recent attack against an airline had resulted in a breach exposing the personal data of all airline employees and five million passengers.
Following this report, the SecurityScorecard Threat Research, Intelligence, Knowledge, and Engagement (STRIKE) Team consulted internal and external data sources to identify possible methods by which Daixin Team compromised the victim organization.
- STRIKE identified evidence suggesting two possible (and not mutually exclusive) paths by which the threat actors may have accessed airline systems:
Traffic data and files containing the victim domain suggest that attackers employed information-stealing malware in the early stages of the attack.
Other traffic and Attack Surface Intelligence (ASI) data revealed communication between a vulnerable airline IP address and IP addresses linked to malicious activity targeting vulnerable services.
These findings may indicate activity similar to that identified in previous ransomware investigations, suggesting a possible overlap in the tactics, techniques, and procedures (TTPs) of Daixin Team and the threat actors responsible for earlier incidents.
Background
An information security researcher reported on November 20 that the Daixin Team ransomware group had claimed that a recent attack against an airline had resulted in a breach exposing the personal data of all airline employees and five million passengers. This follows CISA’s October 21 publication of a #StopRansomware alert regarding the Daixin Team ransomware group.
The alert names spear phishing with malicious attachments as a Daixin Team reconnaissance technique, noting that the group has stolen credentials for later use by distributing malicious attachments in spear phishing emails to employees of target organizations. While researchers have not observed malicious documents that mention the airline, the HTML files discussed below may reflect a slight variation on this technique. The attacker might have sent spearphishing emails with links rather than attachments; these links could have similarly led to malicious downloads that facilitated credential theft; compromised credentials have also figured prominently in the group’s initial access techniques, with the group having previously leveraged exposed credentials to access target organizations’ servers.
Daixin has also exploited public-facing applications in the past by leveraging unpatched vulnerabilities in VPN servers for initial access and is known to move laterally across victim networks using both SSH and RDP hijacking. While STRIKE has not identified vulnerable VPN servers, SecurityScorecard’s ASI tool has identified a vulnerable, public-facing SSH server (discussed at greater length below) that the group may have targeted.
To identify the TTPs that Daixin Group may have employed in this attack, STRIKE leveraged traffic data provided by a strategic partner, which reflected roughly two months of communication involving IP addresses SecurityScorecard attributes to the victim organization and then enriched this data by consulting SecurityScorecard’s ratings platform, ASI tool, and internal threat intelligence platform and then enriching the data contained in those internal sources by cross-referencing it with data available in public cybersecurity information-sharing platform VirusTotal.
Findings: IP Addresses Communicating with This and Previous Ransomware Victims
STRIKE compared the traffic data involving the victim airline to data collected during previous ransomware investigations and found that 272 IP addresses observed in this most recent collection had also communicated with other ransomware victims. While this may, on its own, suggest that those 272 IP addresses may have been involved in the attack against the airline, of these IP addresses, other vendors have already linked eighty-three to malicious activity, indicating that they are especially likely to have been part of the compromise. Both groups of IP addresses are available in the appendices below.
Findings: Possible SSH Brute Force Attack
By pairing the traffic data they collected with VirusTotal and SecurityScorecard’s Attack Surface Intelligence (ASI) tool, STRIKE also observed evidence suggesting that the attackers may have targeted a vulnerable SSH service during the early stages of the attack. The traffic data contains 1,485 flows over port 22 (the default port for SSH) involving 332 unique, non-airline IP addresses. STRIKE then consulted both VirusTotal and ASI to further investigate those IP addresses and found that either VirusTotal community members or ASI linked the majority (289 of 332) of the non-airline IP addresses to SSH brute force attacks.
Images 1-5: ASI has linked many of the IP addresses communicating with airline assets to previous attacks against SSH services
Most of those flows (1,117 of 1,485) involved an airline IP address where ASI found port 22 open and running vulnerable SSH software. Given that repeated traffic in a relatively small amount of time is a common indication of a brute force attack, it may additionally bear noting that port 22 of this IP address experienced particularly heavy concentrations of traffic on (in descending order of flow count) November 3, September 24, November 6, September 25, and September 23.
Image 6: ASI has found port 22 to be open and running vulnerable software at an airline IP address that received a large portion of the traffic to port 22
The recent advisory regarding Daixin Team does not name brute force attacks on SSH services as one of the group’s established TTPs, but does note that the group has compromised SSH services in the past. While it is thus possible that the traffic suggesting a brute force attack is unrelated to Daixin’s compromise of the airline, it may also reflect a more minor deviation from the group’s patterns when targeting those services. Moreover, STRIKE has observed evidence that groups responsible for recent ransomware attacks may have targeted similarly vulnerable SSH services. Other researchers observed earlier ransomware groups employing similar techniques in 2016 and 2019.
Findings: Additional Risky SSH Traffic
While investigating traffic over port 22, STRIKE researchers identified a series of large data transfers from port 22 of an external IP address, 209.97.172[.]51, to an airline-attributed IP address where SecurityScorecard’s ratings platform observed outdated browsers and OS.
ASI shows that the media platform Plex is one of the services used at 209.97.172[.]51. While this may not relate directly to the ransomware incident, it could reflect deficiencies in the airline’s overall cybersecurity hygiene; the large transfers of data to an airline IP address from one where Plex is running could indicate that an airline employee was downloading entertainment media while connected to the company network.
While non-business application use does not in and of itself indicate compromise, it suggests broader cyber-hygiene issues: organizations’ acceptable use policies normally prohibit it, so this traffic may indicate insufficient adherence to, or enforcement of, that policy. Moreover, downloads of unofficial versions of media products can contain malware, so this traffic could represent a risk, depending upon the specific contents of the transfers it reflects. The observation of out-of-date software in use at the same airline-attributed IP address may compound these risks; malware sometimes distributed in unofficial media downloads often exploits the vulnerabilities software updates remedy, and if nothing else, it suggests further issues in the company’s cyber hygiene, as it may reflect insufficient adherence to, or enforcement of, a patching policy.
Findings: Redline Infostealer Traffic
69,996 of the 332,291 observed flows involved 1,042 IP addresses (available in an appendix below) that a strategic partner has linked to the Redline information-stealing malware, which suggests that attackers used Redline or other malware similar to it during the compromise. Analysts have observed initial access brokers using Redline to compromise credentials ransomware operators can later use it to access target systems and encrypt them. They have also observed Redline delivering ransomware as a second-stage payload. Communication between the victim network and Redline-linked IP addresses may therefore indicate that threat actors used Redline or another Trojan like it to steal airline credentials or deliver ransomware after initially infecting airline devices with a Trojan. Given that Daixin Team has reused compromised credentials to access victim systems in previous attacks, some of this traffic may reflect credential thefts that enabled subsequent stages of the attack.
Files recently submitted to VirusTotal may reflect similar activity: vendors have linked many files that contain the airline’s name or domain to various Trojans; this traffic, in combination with these files, may suggest that attackers employed an information-stealing Trojan like Redline in the early stages of the attack.
Findings: Recent VirusTotal Submissions Containing Airline Domain
In a two-month period around the time of the attack (September 21 to November 21), sixty-six files containing the victim organization’s domain, which vendors have linked to malicious activity, appeared on VirusTotal. Of these, vendors have linked fifty-four to various Trojans, and twelve are PDFs containing airline itineraries. The SHA-256 hashes of the files in each of these two groups are available in the appendices below.
Of the fifty-four files that appear malicious, slightly more than half (twenty-eight) are HTML files containing embedded JavaScript, which vendors detect as either generic Trojans or as the Wacatac, Cryxos, CoinMiner, or JS.Iframe Trojans. These files do not appear to have targeted the airline directly; most seem to be HTML for blogs or other websites with information for tourists, which link to the airline’s website when discussing the carriers serving the regions upon which they focus. However, two files’ contents suggest that they may have been more likely than others to attract the attention of airline personnel and may offer further evidence of credential theft leading up to the encryption of the target organization’s systems.
The files identified by the SHA-256 hashes A4870d0353d7f4beaaf25dc14a6c0577baf7ec3b68d02a76eacae4efca1514e3 and 539a23d4e9abb0bf486b1a080696c937b091a4c9c65669ec796087e2899dba2b appear to come from a website dedicated to share career and recruitment information about the airline industry and share a common detection, Trojan:Script/Wacatac.B!ml. Threat actors often use Wacatac to steal information (including credentials) from infected devices and distribute it by concealing it in downloads of unofficial versions of media products (possibly reflected in some of the traffic discussed above) or by using JavaScript injected into a vulnerable website to display messages leading to downloads of it. It is possible, then, that a malicious advertisement or alert showed when an airline employee visited a site about other careers in the industry, which led the employee to a download of an information-stealing Trojan like Wacatac, enabling the theft of employee credentials later used to access airline systems.
While less likely to have attracted the attention of airline employees, the nine files detected as Cryxos may also merit some attention, given similar files’ appearance in other SecurityScorecard investigations. Cryxos refers to a family of malicious JavaScript files that display fraudulent alerts to users when they visit web pages hosting those files. These files typically enable tech support scams, warning users that their computer has been infected by a virus and instructing them to call a threat actor-controlled telephone number. While attackers typically use the call as an opportunity to extract payment information from the victim, in some cases, they direct the victim to install software that gives the attackers remote access to their computer, which could, in turn, facilitate data theft or the deployment of ransomware. While these files appear to have originated from websites aimed at tourists rather than airline employees, they link to the airline’s website. An airline employee could still have come across them and ended up falling victim to a message directing them to call the telephone number displayed as the result of malicious JavaScript embedded into a website discussing their employer. The following SHA-256 hashes identify the files that vendors have linked to Cryxos:
536643341b59fdcda8a0dcc4b53aa9fae2007eb8a43f28d70a0002883e85c75a
1dcf99e980765e4f410d59a1ff0612485630109229107be9d0445ebf685f3aba
d1ccc79acf1708e59e8c90103a314e0c39c7ff6399b1206ecc6af626e5f9c28c
88eee66cec5f917033c328651ab9374dd952ea822d753658fedd6807ed26e85b
B19050beb5b2c3712f746761fa0da3a722cf136f3429b13b35b3e2ee84b81ebc
D6b1db14c863b7252b3f6be01b43966e3f59cbfed7ff96df5b84b46e112a6791
25319eeed6a5fb70decebb9699570205261d494df144c958965dd39e35a2de35
294be49c71aa1b93d94bdeec778a9c4e399b3cbbed2d1b4158834003c6de52ab
Dbebd9e2fb4ce17eeca4449116cefcef4ce23e136d149d2de591317f3963f2e5
Unlike the above files, the PDF itineraries do not appear to behave maliciously, but they do contain passengers’ identifying information and may therefore represent a risk; their availability on a public platform could constitute an unintentional exposure of information by the affected airline in the wake of the attack. Incident response professionals often upload files to VirusTotal for additional analysis, so given these files’ submission dates, which are close to those of reports of the attacks, airline IT personnel or other parties supporting their response may have uploaded them after identifying them while investigating the attack, either to assess whether their contents were malicious (and therefore involved in the attack) or because attackers may have attempted to exfiltrate them as part of a larger effort to steal data.
These now-public files may present the airline with additional risks. While they do not contain credentials or payment information, they do contain airline passengers’ names, which other threat actors could easily abuse. The details in these documents could, for example, lead to the creation of more believable lures for subsequent spear phishing attacks by threat actors either contacting the named passengers and impersonating the airline or impersonating the passengers when contacting the airline or by informing later extortion attempts–a threat actor could, for example, download them and then use them to claim responsibility for an additional airline breach only to circulate (or threaten to circulate) the files after accessing them at the public site in question. Although SecurityScorecard cannot yet assess the full impact of these particular findings, they may nonetheless represent dimensions of risk that the airline may not have previously considered.
Conclusion
This information was gathered and analyzed to briefly preview some of STRIKE’s capabilities. Therefore, it bears noting that this is not an exhaustive list of issues related to the airline’s overall cyber risk exposure. However, the data researchers have collected and analyzed thus far may offer new insights into the attack and Daixin Team’s operations.
Traffic data and files available in VirusTotal suggest airline devices suffered from infections with information-stealing malware in the months leading up to the breach claimed by the Daixin Team ransomware group. Given that the group is known to reuse compromised credentials when accessing victim systems, such infections may have led to credential theft that enabled subsequent stages of the attack. Analysts have additionally previously observed the group targeting public-facing services and compromising SSH servers in the past; traffic data, when paired with ASI findings indicating vulnerable and publicly-exposed SSH services running at an IP address attributed to the victim airline, may suggest that the attackers also exploited this vulnerable asset when compromising the target organization. While they may reflect a slight variation in the publicly available TTPs linked to Daixin Team, these findings may also indicate activity similar to that identified in previous ransomware investigations, suggesting a possible overlap between the TTPs of Daixin Team and those of the threat actors responsible for previous incidents.
Appendix: Vendor-Detected IP Addresses
142[.]93[.]116[.]249
164[.]90[.]194[.]36
159[.]203[.]102[.]122
178[.]62[.]81[.]147
142[.]93[.]8[.]99
157[.]230[.]218[.]88
143[.]198[.]4[.]69
67[.]205[.]138[.]198
68[.]183[.]188[.]159
157[.]245[.]81[.]154
45[.]232[.]73[.]84
38[.]43[.]193[.]19
185[.]133[.]240[.]155
159[.]65[.]154[.]92
45[.]232[.]73[.]54
142[.]93[.]112[.]39
161[.]35[.]138[.]131
162[.]243[.]28[.]146
192[.]241[.]192[.]164
134[.]122[.]112[.]12
139[.]59[.]239[.]64
165[.]227[.]164[.]139
206[.]81[.]1[.]80
159[.]223[.]47[.]173
134[.]209[.]183[.]166
45[.]232[.]73[.]53
89[.]203[.]192[.]113
161[.]35[.]127[.]34
206[.]189[.]198[.]55
38[.]43[.]193[.]10
159[.]89[.]94[.]23
159[.]203[.]94[.]62
104[.]248[.]12[.]1
178[.]128[.]41[.]141
159[.]203[.]174[.]165
167[.]71[.]228[.]234
178[.]128[.]93[.]138
178[.]128[.]107[.]206
41[.]63[.]0[.]245
170[.]210[.]44[.]162
150[.]129[.]48[.]228
207[.]154[.]241[.]99
198[.]12[.]158[.]38
161[.]35[.]188[.]242
41[.]94[.]22[.]4
137[.]184[.]204[.]85
118[.]179[.]224[.]50
103[.]4[.]119[.]20
68[.]183[.]91[.]89
159[.]223[.]177[.]83
102[.]134[.]149[.]124
193[.]142[.]146[.]227
45[.]55[.]44[.]194
146[.]20[.]132[.]131
64[.]15[.]129[.]102
174[.]138[.]21[.]251
116[.]90[.]224[.]135
38[.]43[.]193[.]193
128[.]199[.]255[.]87
168[.]167[.]84[.]166
103[.]127[.]184[.]167
180[.]233[.]120[.]210
209[.]197[.]3[.]8
131[.]221[.]37[.]179
157[.]245[.]25[.]14
45[.]58[.]183[.]18
89[.]203[.]150[.]42
206[.]189[.]40[.]239
142[.]93[.]112[.]105
142[.]93[.]6[.]2
146[.]20[.]132[.]109
64[.]225[.]70[.]121
147[.]182[.]190[.]253
45[.]178[.]139[.]153
64[.]227[.]1[.]83
68[.]235[.]33[.]136
165[.]227[.]181[.]220
146[.]20[.]128[.]62
177[.]131[.]18[.]98
68[.]235[.]32[.]253
68[.]235[.]32[.]244
91[.]207[.]120[.]56
116[.]90[.]228[.]197
Appendix: IP Addresses Communicating with Airline
177[.]131[.]18[.]98
167[.]71[.]245[.]126
68[.]235[.]32[.]253
68[.]235[.]32[.]244
38[.]43[.]193[.]19
91[.]207[.]120[.]56
103[.]71[.]42[.]172
168[.]167[.]26[.]226
168[.]167[.]26[.]254
102[.]165[.]41[.]32
118[.]103[.]137[.]77
168[.]167[.]36[.]69
168[.]167[.]84[.]166
192[.]241[.]192[.]224
167[.]71[.]241[.]128
162[.]243[.]5[.]116
143[.]198[.]2[.]47
157[.]245[.]220[.]48
157[.]230[.]229[.]121
116[.]90[.]228[.]197
206[.]189[.]180[.]143
157[.]245[.]4[.]84
118[.]179[.]224[.]50
64[.]227[.]1[.]83
216[.]6[.]37[.]10
156[.]26[.]17[.]11
202[.]168[.]72[.]5
68[.]235[.]33[.]136
167[.]71[.]243[.]107
142[.]93[.]195[.]24
137[.]184[.]128[.]227
206[.]189[.]235[.]120
59[.]153[.]82[.]64
142[.]93[.]205[.]250
137[.]184[.]213[.]96
167[.]172[.]229[.]95
128[.]199[.]255[.]87
193[.]142[.]146[.]227
193[.]1[.]98[.]136
103[.]162[.]186[.]254
177[.]154[.]81[.]98
206[.]189[.]40[.]239
135[.]84[.]57[.]36
165[.]227[.]193[.]203
104[.]248[.]68[.]63
170[.]210[.]44[.]162
150[.]129[.]48[.]228
64[.]15[.]129[.]102
193[.]146[.]86[.]29
177[.]66[.]196[.]254
192[.]241[.]245[.]94
157[.]245[.]216[.]33
174[.]138[.]21[.]251
116[.]90[.]224[.]135
142[.]93[.]195[.]21
157[.]230[.]218[.]88
131[.]221[.]229[.]20
146[.]20[.]128[.]65
192[.]33[.]214[.]47
157[.]230[.]89[.]209
178[.]62[.]202[.]251
161[.]47[.]17[.]28
143[.]244[.]220[.]80
23[.]253[.]31[.]170
142[.]93[.]195[.]186
45[.]232[.]73[.]54
38[.]43[.]193[.]10
109[.]205[.]46[.]206
206[.]81[.]1[.]80
159[.]89[.]94[.]23
38[.]43[.]193[.]193
41[.]94[.]22[.]4
159[.]203[.]94[.]62
198[.]61[.]165[.]71
159[.]89[.]47[.]185
165[.]22[.]33[.]43
146[.]20[.]132[.]109
146[.]20[.]132[.]57
142[.]93[.]1[.]23
157[.]230[.]93[.]47
142[.]93[.]177[.]253
138[.]197[.]61[.]175
167[.]99[.]116[.]243
165[.]227[.]118[.]62
167[.]99[.]153[.]13
147[.]182[.]219[.]240
64[.]225[.]70[.]121
138[.]197[.]104[.]58
23[.]253[.]188[.]26
146[.]20[.]132[.]198
157[.]230[.]89[.]169
146[.]20[.]132[.]186
104[.]248[.]125[.]207
146[.]20[.]132[.]196
146[.]20[.]176[.]192
146[.]20[.]132[.]122
137[.]184[.]65[.]255
146[.]20[.]128[.]63
146[.]20[.]128[.]80
157[.]230[.]89[.]254
142[.]93[.]6[.]2
157[.]230[.]85[.]253
142[.]93[.]185[.]29
138[.]197[.]55[.]50
146[.]20[.]132[.]121
89[.]203[.]193[.]220
69[.]20[.]95[.]4
165[.]227[.]164[.]139
146[.]20[.]132[.]149
134[.]213[.]70[.]247
104[.]248[.]117[.]198
146[.]20[.]132[.]124
198[.]211[.]110[.]128
167[.]99[.]116[.]130
165[.]22[.]46[.]48
159[.]223[.]177[.]83
146[.]20[.]132[.]86
146[.]20[.]132[.]85
167[.]99[.]120[.]235
165[.]227[.]222[.]159
146[.]20[.]128[.]178
146[.]20[.]128[.]179
134[.]213[.]193[.]62
147[.]182[.]190[.]253
82[.]192[.]85[.]130
159[.]89[.]246[.]130
146[.]20[.]128[.]41
108[.]171[.]167[.]254
159[.]65[.]196[.]12
167[.]99[.]53[.]99
146[.]20[.]128[.]168
146[.]20[.]132[.]81
209[.]160[.]67[.]5
159[.]203[.]145[.]121
146[.]20[.]128[.]176
143[.]198[.]184[.]117
146[.]20[.]128[.]107
143[.]198[.]4[.]69
137[.]184[.]106[.]94
159[.]65[.]197[.]210
146[.]20[.]132[.]173
108[.]166[.]3[.]50
159[.]203[.]174[.]165
192[.]241[.]192[.]164
69[.]20[.]43[.]192
142[.]93[.]177[.]175
146[.]20[.]128[.]81
35[.]212[.]200[.]165
146[.]20[.]128[.]114
35[.]212[.]132[.]154
174[.]138[.]50[.]235
146[.]20[.]132[.]140
146[.]20[.]128[.]165
45[.]55[.]44[.]194
167[.]71[.]160[.]189
134[.]122[.]112[.]12
148[.]62[.]50[.]92
68[.]183[.]91[.]89
146[.]20[.]132[.]131
142[.]93[.]6[.]18
146[.]20[.]128[.]146
207[.]154[.]241[.]99
198[.]12[.]158[.]38
178[.]62[.]248[.]152
161[.]35[.]188[.]242
146[.]20[.]132[.]135
137[.]184[.]21[.]87
146[.]20[.]132[.]100
146[.]20[.]132[.]84
146[.]20[.]132[.]76
143[.]244[.]175[.]88
143[.]198[.]171[.]225
45[.]79[.]53[.]162
165[.]22[.]39[.]175
146[.]20[.]128[.]147
64[.]185[.]181[.]238
45[.]55[.]51[.]207
142[.]93[.]112[.]105
165[.]227[.]188[.]82
137[.]184[.]130[.]80
165[.]22[.]230[.]217
165[.]227[.]181[.]220
159[.]89[.]181[.]37
159[.]223[.]101[.]112
142[.]93[.]249[.]147
104[.]248[.]6[.]158
143[.]244[.]163[.]25
157[.]245[.]120[.]56
172[.]99[.]67[.]55
143[.]110[.]212[.]118
165[.]227[.]103[.]144
143[.]110[.]220[.]36
165[.]227[.]220[.]240
146[.]20[.]128[.]140
146[.]20[.]132[.]159
146[.]20[.]128[.]139
104[.]130[.]70[.]25
146[.]20[.]132[.]71
146[.]20[.]132[.]61
146[.]20[.]132[.]201
146[.]20[.]132[.]60
146[.]20[.]132[.]111
72[.]32[.]90[.]251
146[.]20[.]132[.]151
41[.]63[.]0[.]245
146[.]20[.]128[.]109
162[.]242[.]174[.]138
146[.]20[.]128[.]181
161[.]35[.]138[.]131
146[.]20[.]32[.]58
146[.]20[.]132[.]89
159[.]203[.]102[.]122
146[.]20[.]132[.]180
45[.]232[.]73[.]84
146[.]20[.]132[.]156
146[.]20[.]128[.]56
146[.]20[.]128[.]164
146[.]20[.]128[.]136
146[.]20[.]128[.]62
146[.]20[.]132[.]166
23[.]253[.]207[.]75
146[.]20[.]128[.]143
108[.]166[.]2[.]67
146[.]20[.]128[.]177
146[.]20[.]128[.]175
209[.]197[.]3[.]8
146[.]20[.]128[.]112
146[.]20[.]132[.]168
146[.]88[.]111[.]230
177[.]66[.]152[.]139
206[.]189[.]198[.]55
139[.]59[.]239[.]64
131[.]221[.]37[.]179
45[.]237[.]188[.]138
107[.]152[.]42[.]162
167[.]71[.]228[.]234
157[.]245[.]25[.]14
180[.]233[.]121[.]132
45[.]58[.]183[.]18
89[.]203[.]150[.]42
159[.]223[.]47[.]173
142[.]93[.]8[.]99
134[.]209[.]183[.]166
142[.]93[.]116[.]249
45[.]232[.]73[.]53
137[.]184[.]204[.]85
142[.]93[.]112[.]39
45[.]178[.]139[.]153
102[.]134[.]149[.]124
198[.]211[.]103[.]209
104[.]248[.]12[.]1
45[.]237[.]188[.]130
178[.]62[.]81[.]147
103[.]28[.]156[.]106
67[.]205[.]138[.]198
178[.]128[.]93[.]138
68[.]183[.]188[.]159
178[.]128[.]107[.]206
157[.]245[.]81[.]154
100[.]109[.]252[.]11
27[.]0[.]182[.]218
103[.]127[.]184[.]167
177[.]66[.]154[.]204
185[.]133[.]240[.]155
180[.]233[.]120[.]210
89[.]203[.]192[.]113
164[.]90[.]194[.]36
103[.]4[.]119[.]20
178[.]128[.]41[.]141
161[.]35[.]127[.]34
159[.]65[.]154[.]92
162[.]243[.]28[.]146
Appendix: IP Addresses Linked to Redline
103[.]233[.]89[.]60
103[.]44[.]33[.]168
180[.]233[.]120[.]210
103[.]44[.]33[.]132
150[.]129[.]50[.]130
217[.]147[.]224[.]94
103[.]14[.]110[.]238
192[.]140[.]224[.]132
209[.]160[.]67[.]6
59[.]153[.]80[.]226
200[.]196[.]136[.]34
103[.]44[.]33[.]76
192[.]140[.]225[.]187
43[.]252[.]145[.]120
103[.]90[.]239[.]132
120[.]89[.]95[.]132
103[.]233[.]89[.]253
177[.]154[.]82[.]4
85[.]13[.]90[.]185
186[.]237[.]182[.]227
43[.]252[.]144[.]37
59[.]153[.]83[.]170
103[.]109[.]218[.]221
103[.]44[.]35[.]157
103[.]200[.]93[.]250
192[.]140[.]224[.]254
103[.]245[.]34[.]186
105[.]235[.]212[.]13
120[.]89[.]95[.]219
59[.]153[.]82[.]213
43[.]252[.]144[.]68
120[.]89[.]94[.]34
103[.]44[.]33[.]159
111[.]67[.]73[.]178
103[.]47[.]33[.]232
197[.]155[.]6[.]250
103[.]44[.]33[.]154
103[.]233[.]89[.]190
103[.]233[.]88[.]22
103[.]157[.]233[.]3
150[.]129[.]49[.]25
131[.]221[.]229[.]20
103[.]233[.]89[.]142
103[.]233[.]88[.]93
103[.]233[.]88[.]92
103[.]143[.]208[.]49
54[.]36[.]108[.]162
146[.]88[.]73[.]188
103[.]131[.]95[.]22
103[.]145[.]227[.]144
45[.]189[.]203[.]233
89[.]203[.]150[.]42
59[.]153[.]80[.]34
59[.]153[.]81[.]102
59[.]153[.]82[.]64
103[.]233[.]88[.]58
43[.]252[.]145[.]218
27[.]0[.]182[.]218
180[.]233[.]121[.]21
103[.]233[.]89[.]234
185[.]193[.]52[.]180
192[.]140[.]225[.]130
103[.]109[.]216[.]125
213[.]235[.]133[.]38
197[.]155[.]5[.]50
46[.]255[.]225[.]176
46[.]255[.]227[.]176
189[.]84[.]21[.]44
45[.]226[.]228[.]2
85[.]13[.]96[.]14
185[.]207[.]141[.]172
120[.]89[.]94[.]151
192[.]140[.]224[.]229
192[.]140[.]224[.]202
59[.]153[.]82[.]51
59[.]153[.]80[.]66
43[.]252[.]144[.]75
103[.]28[.]156[.]170
185[.]248[.]101[.]215
195[.]146[.]123[.]2
43[.]252[.]145[.]26
103[.]44[.]33[.]144
59[.]153[.]82[.]70
103[.]233[.]89[.]117
217[.]147[.]228[.]15
185[.]103[.]189[.]33
103[.]44[.]35[.]149
43[.]252[.]145[.]146
192[.]140[.]224[.]200
116[.]90[.]226[.]2
103[.]44[.]33[.]235
103[.]233[.]88[.]227
103[.]210[.]46[.]155
82[.]117[.]137[.]38
82[.]117[.]137[.]37
196[.]61[.]62[.]8
46[.]105[.]54[.]220
192[.]140[.]225[.]106
103[.]233[.]89[.]186
59[.]153[.]80[.]240
192[.]140[.]224[.]138
91[.]203[.]5[.]146
120[.]89[.]95[.]116
195[.]80[.]151[.]30
82[.]117[.]137[.]36
138[.]59[.]18[.]110
150[.]129[.]49[.]169
213[.]235[.]133[.]39
103[.]44[.]33[.]69
131[.]108[.]156[.]1
170[.]81[.]249[.]196
45[.]125[.]65[.]112
84[.]239[.]46[.]144
103[.]44[.]35[.]159
213[.]235[.]133[.]103
103[.]157[.]232[.]210
45[.]160[.]0[.]110
82[.]117[.]137[.]39
77[.]92[.]103[.]42
212[.]11[.]96[.]21
178[.]62[.]220[.]93
103[.]44[.]33[.]251
180[.]233[.]121[.]185
103[.]160[.]62[.]102
59[.]153[.]80[.]206
103[.]44[.]35[.]155
192[.]140[.]225[.]156
103[.]44[.]33[.]167
103[.]90[.]238[.]171
103[.]90[.]237[.]133
95[.]214[.]55[.]43
27[.]0[.]180[.]244
91[.]203[.]5[.]118
89[.]203[.]192[.]113
43[.]252[.]144[.]38
177[.]70[.]65[.]29
103[.]233[.]88[.]194
195[.]176[.]3[.]24
103[.]44[.]35[.]151
77[.]48[.]28[.]236
192[.]140[.]224[.]62
82[.]202[.]90[.]97
141[.]255[.]161[.]166
177[.]39[.]198[.]182
27[.]0[.]178[.]175
120[.]89[.]94[.]78
103[.]145[.]226[.]105
177[.]154[.]82[.]56
164[.]92[.]218[.]139
103[.]44[.]33[.]169
177[.]154[.]86[.]13
45[.]168[.]85[.]50
102[.]222[.]216[.]71
185[.]72[.]244[.]37
103[.]14[.]111[.]46
103[.]44[.]35[.]61
111[.]67[.]76[.]230
102[.]221[.]248[.]75
45[.]229[.]9[.]23
150[.]129[.]102[.]160
94[.]75[.]225[.]70
172[.]107[.]241[.]110
103[.]44[.]33[.]125
179[.]43[.]128[.]16
170[.]81[.]249[.]233
45[.]163[.]166[.]102
103[.]47[.]34[.]183
192[.]140[.]225[.]54
111[.]67[.]76[.]162
120[.]89[.]94[.]122
59[.]153[.]82[.]206
103[.]200[.]95[.]100
111[.]67[.]73[.]162
202[.]129[.]251[.]241
59[.]153[.]81[.]254
103[.]200[.]94[.]174
78[.]156[.]44[.]203
35[.]244[.]245[.]148
170[.]81[.]249[.]248
168[.]0[.]24[.]104
43[.]251[.]159[.]144
93[.]115[.]86[.]4
146[.]185[.]253[.]104
43[.]252[.]144[.]46
94[.]177[.]149[.]140
43[.]252[.]144[.]166
201[.]33[.]174[.]146
139[.]28[.]36[.]142
103[.]14[.]111[.]10
103[.]28[.]156[.]106
103[.]47[.]34[.]52
103[.]233[.]89[.]235
103[.]162[.]187[.]152
103[.]109[.]217[.]46
103[.]210[.]47[.]161
27[.]0[.]177[.]103
103[.]170[.]83[.]198
103[.]210[.]45[.]200
103[.]148[.]144[.]134
102[.]23[.]164[.]5
185[.]133[.]240[.]155
196[.]3[.]96[.]69
190[.]124[.]61[.]139
59[.]153[.]82[.]58
59[.]153[.]81[.]57
103[.]44[.]33[.]130
43[.]252[.]145[.]6
143[.]198[.]163[.]66
103[.]47[.]35[.]106
103[.]210[.]45[.]217
59[.]153[.]82[.]94
120[.]89[.]95[.]198
176[.]126[.]253[.]190
180[.]233[.]121[.]50
103[.]44[.]33[.]182
216[.]10[.]247[.]146
103[.]44[.]34[.]77
103[.]28[.]157[.]54
103[.]28[.]156[.]95
45[.]229[.]8[.]207
103[.]28[.]157[.]18
213[.]226[.]209[.]109
103[.]44[.]33[.]91
43[.]252[.]144[.]10
45[.]222[.]73[.]230
41[.]163[.]7[.]77
41[.]163[.]7[.]79
103[.]90[.]236[.]95
82[.]202[.]118[.]252
213[.]235[.]189[.]243
118[.]103[.]136[.]49
185[.]91[.]229[.]67
87[.]120[.]237[.]130
103[.]160[.]62[.]2
190[.]124[.]56[.]236
45[.]229[.]10[.]25
103[.]44[.]33[.]215
102[.]221[.]248[.]90
103[.]28[.]156[.]83
120[.]89[.]94[.]170
103[.]28[.]157[.]185
62[.]113[.]216[.]173
217[.]147[.]227[.]67
109[.]205[.]46[.]204
103[.]44[.]35[.]154
170[.]210[.]44[.]162
51[.]75[.]129[.]204
185[.]86[.]151[.]168
43[.]252[.]144[.]67
43[.]241[.]139[.]213
103[.]44[.]33[.]176
85[.]13[.]73[.]240
103[.]44[.]33[.]161
192[.]140[.]224[.]189
103[.]44[.]35[.]153
109[.]205[.]46[.]206
192[.]140[.]224[.]68
109[.]205[.]46[.]207
109[.]205[.]46[.]205
103[.]161[.]249[.]171
192[.]140[.]224[.]167
103[.]44[.]33[.]160
89[.]203[.]191[.]112
169[.]159[.]232[.]66
85[.]13[.]78[.]7
103[.]233[.]88[.]66
45[.]237[.]189[.]86
45[.]87[.]209[.]91
103[.]90[.]239[.]98
190[.]124[.]63[.]11
103[.]233[.]89[.]94
59[.]153[.]80[.]128
103[.]145[.]226[.]234
103[.]44[.]33[.]66
192[.]140[.]224[.]246
192[.]140[.]225[.]14
195[.]146[.]123[.]82
103[.]109[.]216[.]70
103[.]14[.]111[.]26
27[.]0[.]176[.]76
103[.]44[.]33[.]97
94[.]143[.]236[.]125
186[.]237[.]182[.]228
187[.]109[.]52[.]217
194[.]127[.]196[.]162
103[.]14[.]110[.]40
190[.]124[.]63[.]4
181[.]224[.]211[.]252
59[.]153[.]81[.]146
118[.]103[.]138[.]105
196[.]3[.]102[.]50
103[.]233[.]88[.]225
177[.]154[.]81[.]98
102[.]132[.]12[.]61
59[.]153[.]81[.]126
82[.]221[.]131[.]5
185[.]227[.]82[.]43
82[.]118[.]242[.]103
185[.]67[.]45[.]76
103[.]233[.]89[.]191
103[.]44[.]33[.]107
103[.]90[.]236[.]59
46[.]173[.]206[.]141
103[.]14[.]111[.]20
82[.]117[.]130[.]20
91[.]92[.]109[.]43
103[.]44[.]35[.]146
46[.]229[.]122[.]122
213[.]226[.]67[.]250
82[.]221[.]128[.]191
89[.]203[.]159[.]75
103[.]166[.]43[.]64
103[.]14[.]110[.]138
27[.]0[.]181[.]18
103[.]131[.]95[.]99
192[.]140[.]225[.]170
82[.]117[.]137[.]40
103[.]170[.]82[.]73
89[.]203[.]249[.]27
170[.]81[.]249[.]85
59[.]153[.]81[.]54
103[.]233[.]88[.]212
43[.]252[.]145[.]231
103[.]44[.]33[.]103
192[.]140[.]225[.]103
120[.]89[.]94[.]166
103[.]233[.]88[.]166
103[.]233[.]88[.]144
185[.]249[.]25[.]86
185[.]249[.]24[.]115
185[.]249[.]24[.]48
217[.]147[.]237[.]202
37[.]205[.]37[.]242
185[.]159[.]200[.]90
103[.]145[.]227[.]134
27[.]0[.]180[.]210
213[.]235[.]133[.]41
103[.]44[.]33[.]228
43[.]252[.]144[.]14
103[.]44[.]33[.]177
94[.]177[.]149[.]122
192[.]140[.]225[.]93
103[.]14[.]111[.]17
212[.]11[.]105[.]241
103[.]44[.]35[.]148
45[.]64[.]158[.]219
59[.]153[.]80[.]135
103[.]157[.]232[.]90
196[.]3[.]98[.]6
103[.]44[.]35[.]147
154[.]68[.]225[.]253
103[.]233[.]89[.]242
197[.]155[.]20[.]194
103[.]44[.]33[.]249
59[.]153[.]80[.]186
103[.]14[.]111[.]35
103[.]145[.]226[.]75
103[.]47[.]34[.]67
177[.]154[.]84[.]241
170[.]81[.]249[.]13
185[.]91[.]231[.]112
103[.]109[.]218[.]145
190[.]124[.]63[.]12
192[.]140[.]224[.]186
103[.]233[.]89[.]55
27[.]0[.]178[.]17
78[.]156[.]49[.]72
45[.]138[.]222[.]236
59[.]153[.]80[.]68
43[.]252[.]145[.]153
103[.]245[.]34[.]39
177[.]154[.]82[.]126
103[.]14[.]110[.]38
190[.]124[.]60[.]10
180[.]233[.]122[.]164
89[.]104[.]241[.]1
177[.]39[.]196[.]150
185[.]6[.]7[.]27
103[.]170[.]82[.]154
103[.]44[.]35[.]150
103[.]157[.]232[.]186
103[.]233[.]88[.]152
177[.]39[.]196[.]195
149[.]255[.]175[.]99
89[.]104[.]233[.]68
105[.]235[.]213[.]42
59[.]153[.]80[.]205
103[.]213[.]126[.]212
103[.]14[.]111[.]110
27[.]0[.]170[.]254
27[.]0[.]178[.]3
103[.]44[.]34[.]109
59[.]153[.]81[.]134
103[.]90[.]237[.]164
45[.]222[.]73[.]95
66[.]36[.]241[.]158
197[.]155[.]23[.]157
43[.]241[.]138[.]133
43[.]252[.]144[.]72
192[.]140[.]224[.]159
103[.]233[.]89[.]189
103[.]143[.]143[.]208
103[.]143[.]143[.]47
103[.]162[.]186[.]243
36[.]255[.]229[.]106
45[.]163[.]164[.]130
170[.]231[.]97[.]197
177[.]154[.]86[.]145
103[.]143[.]143[.]139
177[.]154[.]82[.]7
43[.]252[.]144[.]66
103[.]143[.]143[.]45
103[.]143[.]143[.]168
103[.]27[.]63[.]85
103[.]27[.]62[.]79
43[.]252[.]145[.]183
118[.]103[.]139[.]114
103[.]233[.]88[.]224
103[.]47[.]32[.]178
103[.]27[.]62[.]153
59[.]153[.]83[.]94
27[.]0[.]176[.]1
37[.]205[.]37[.]66
27[.]0[.]182[.]242
59[.]153[.]83[.]198
82[.]117[.]137[.]100
103[.]44[.]33[.]173
59[.]153[.]81[.]70
103[.]143[.]143[.]136
177[.]154[.]86[.]187
89[.]203[.]185[.]8
103[.]145[.]227[.]97
185[.]91[.]229[.]240
103[.]14[.]110[.]154
103[.]145[.]227[.]65
89[.]203[.]142[.]87
103[.]145[.]226[.]28
59[.]153[.]80[.]208
103[.]233[.]89[.]123
45[.]221[.]132[.]181
143[.]208[.]251[.]150
190[.]124[.]63[.]14
194[.]149[.]131[.]243
103[.]47[.]34[.]44
192[.]140[.]224[.]161
103[.]206[.]211[.]162
103[.]44[.]33[.]110
103[.]83[.]157[.]14
120[.]89[.]95[.]124
120[.]89[.]94[.]210
78[.]156[.]48[.]118
103[.]233[.]88[.]96
103[.]127[.]254[.]202
43[.]252[.]144[.]100
103[.]44[.]33[.]114
41[.]94[.]14[.]2
103[.]170[.]83[.]116
103[.]152[.]0[.]217
43[.]252[.]144[.]123
59[.]153[.]81[.]227
213[.]235[.]140[.]25
27[.]0[.]177[.]10
35[.]244[.]245[.]21
89[.]203[.]137[.]19
213[.]235[.]133[.]102
43[.]252[.]145[.]115
78[.]156[.]49[.]78
78[.]156[.]48[.]29
181[.]174[.]251[.]117
43[.]252[.]145[.]228
103[.]44[.]33[.]205
103[.]90[.]236[.]71
103[.]160[.]62[.]214
103[.]44[.]33[.]207
41[.]94[.]22[.]2
103[.]143[.]208[.]208
59[.]153[.]80[.]54
120[.]89[.]95[.]130
170[.]81[.]249[.]21
27[.]0[.]171[.]82
59[.]153[.]81[.]26
103[.]200[.]94[.]169
43[.]252[.]144[.]167
146[.]190[.]72[.]130
27[.]0[.]176[.]17
103[.]83[.]156[.]190
103[.]145[.]227[.]139
103[.]143[.]143[.]240
213[.]169[.]148[.]151
128[.]223[.]223[.]46
177[.]154[.]86[.]54
168[.]181[.]72[.]185
169[.]159[.]233[.]50
103[.]208[.]164[.]86
120[.]89[.]95[.]237
200[.]49[.]241[.]153
190[.]8[.]161[.]31
103[.]102[.]161[.]30
103[.]90[.]236[.]22
103[.]134[.]79[.]231
103[.]44[.]34[.]80
43[.]252[.]144[.]92
190[.]124[.]61[.]69
89[.]203[.]249[.]38
103[.]255[.]107[.]92
212[.]11[.]115[.]91
103[.]208[.]164[.]84
103[.]44[.]33[.]115
103[.]44[.]33[.]198
94[.]156[.]175[.]86
103[.]83[.]156[.]102
89[.]203[.]170[.]16
103[.]44[.]34[.]115
103[.]83[.]156[.]240
103[.]145[.]226[.]120
36[.]255[.]230[.]188
102[.]215[.]34[.]58
103[.]143[.]143[.]181
103[.]44[.]33[.]140
103[.]44[.]33[.]74
217[.]147[.]224[.]178
103[.]208[.]164[.]81
177[.]154[.]86[.]179
102[.]23[.]167[.]43
190[.]124[.]63[.]3
37[.]205[.]39[.]189
192[.]140[.]225[.]153
103[.]44[.]34[.]143
197[.]155[.]8[.]66
177[.]125[.]55[.]205
186[.]237[.]182[.]229
213[.]235[.]133[.]104
89[.]203[.]250[.]36
192[.]140[.]225[.]78
103[.]44[.]33[.]243
45[.]227[.]113[.]115
103[.]47[.]35[.]72
37[.]205[.]38[.]225
27[.]0[.]176[.]142
103[.]44[.]33[.]179
103[.]170[.]83[.]197
103[.]24[.]32[.]102
103[.]157[.]233[.]135
150[.]129[.]50[.]202
177[.]154[.]86[.]235
45[.]230[.]234[.]57
128[.]223[.]157[.]25
200[.]196[.]136[.]37
36[.]255[.]230[.]217
118[.]103[.]137[.]75
43[.]252[.]144[.]232
103[.]44[.]33[.]68
43[.]225[.]51[.]69
103[.]145[.]227[.]174
103[.]109[.]218[.]190
190[.]106[.]96[.]110
103[.]27[.]62[.]229
102[.]215[.]34[.]10
27[.]0[.]183[.]166
103[.]255[.]104[.]194
103[.]47[.]33[.]201
180[.]233[.]122[.]156
103[.]233[.]88[.]142
177[.]154[.]82[.]1
103[.]44[.]33[.]124
207[.]228[.]225[.]135
89[.]203[.]248[.]212
103[.]90[.]238[.]177
103[.]83[.]156[.]248
213[.]235[.]133[.]111
89[.]203[.]251[.]188
103[.]44[.]34[.]110
213[.]235[.]133[.]40
103[.]208[.]164[.]83
200[.]49[.]241[.]108
103[.]47[.]32[.]120
103[.]83[.]156[.]28
103[.]44[.]34[.]95
154[.]66[.]88[.]189
103[.]14[.]111[.]146
36[.]255[.]230[.]223
103[.]170[.]83[.]252
194[.]149[.]148[.]242
41[.]76[.]135[.]18
180[.]233[.]121[.]206
43[.]252[.]145[.]152
103[.]206[.]211[.]241
170[.]231[.]99[.]204
103[.]170[.]82[.]122
43[.]225[.]48[.]3
43[.]241[.]138[.]8
165[.]232[.]165[.]246
59[.]153[.]83[.]90
103[.]162[.]187[.]212
45[.]230[.]234[.]62
177[.]124[.]133[.]100
103[.]44[.]33[.]156
102[.]215[.]34[.]6
85[.]13[.]90[.]132
180[.]233[.]122[.]182
31[.]47[.]72[.]140
31[.]47[.]72[.]150
102[.]221[.]248[.]70
103[.]255[.]104[.]177
43[.]225[.]48[.]84
102[.]215[.]34[.]22
41[.]79[.]10[.]78
43[.]252[.]144[.]198
103[.]233[.]88[.]95
103[.]44[.]34[.]250
181[.]174[.]251[.]121
103[.]208[.]164[.]87
103[.]233[.]88[.]226
185[.]180[.]32[.]68
102[.]215[.]34[.]2
154[.]68[.]230[.]13
182[.]54[.]156[.]10
103[.]44[.]33[.]162
103[.]90[.]236[.]182
192[.]140[.]224[.]170
177[.]154[.]84[.]20
103[.]127[.]254[.]242
103[.]160[.]62[.]78
103[.]170[.]83[.]55
103[.]44[.]33[.]96
103[.]127[.]254[.]228
89[.]104[.]243[.]86
103[.]208[.]164[.]85
213[.]235[.]133[.]110
185[.]190[.]196[.]74
185[.]250[.]12[.]240
103[.]233[.]89[.]182
81[.]19[.]35[.]178
103[.]44[.]33[.]98
192[.]140[.]224[.]86
103[.]162[.]187[.]217
180[.]233[.]121[.]108
103[.]109[.]219[.]34
59[.]153[.]82[.]69
154[.]66[.]92[.]249
207[.]228[.]234[.]190
190[.]124[.]61[.]144
89[.]203[.]249[.]49
103[.]14[.]111[.]74
103[.]47[.]32[.]206
27[.]0[.]178[.]80
103[.]162[.]187[.]254
103[.]14[.]111[.]118
59[.]153[.]82[.]118
103[.]47[.]32[.]213
27[.]0[.]181[.]222
103[.]157[.]232[.]71
118[.]103[.]143[.]56
118[.]103[.]137[.]201
41[.]163[.]7[.]74
45[.]170[.]203[.]55
103[.]71[.]42[.]225
45[.]222[.]75[.]144
78[.]156[.]40[.]23
154[.]68[.]226[.]30
103[.]231[.]63[.]222
103[.]71[.]41[.]243
185[.]190[.]198[.]188
102[.]215[.]34[.]26
43[.]241[.]137[.]205
45[.]237[.]189[.]80
103[.]161[.]248[.]203
103[.]14[.]111[.]134
120[.]89[.]95[.]104
27[.]0[.]178[.]127
103[.]143[.]143[.]135
103[.]208[.]164[.]82
150[.]129[.]50[.]92
103[.]44[.]33[.]174
103[.]90[.]236[.]82
213[.]226[.]215[.]47
103[.]245[.]32[.]34
185[.]190[.]197[.]109
103[.]233[.]88[.]25
105[.]235[.]213[.]196
103[.]44[.]33[.]146
103[.]44[.]33[.]234
191[.]37[.]28[.]117
45[.]175[.]101[.]66
37[.]205[.]33[.]154
118[.]179[.]254[.]78
89[.]203[.]172[.]159
36[.]255[.]229[.]213
202[.]168[.]72[.]107
27[.]0[.]177[.]117
37[.]111[.]197[.]222
103[.]47[.]35[.]159
202[.]22[.]237[.]193
202[.]22[.]234[.]109
174[.]128[.]250[.]166
103[.]47[.]35[.]73
36[.]255[.]230[.]204
181[.]174[.]251[.]248
118[.]179[.]245[.]157
154[.]68[.]228[.]22
213[.]235[.]161[.]147
103[.]109[.]218[.]197
185[.]57[.]196[.]246
103[.]17[.]44[.]18
103[.]109[.]217[.]119
103[.]160[.]62[.]94
103[.]109[.]216[.]197
89[.]203[.]250[.]111
190[.]103[.]89[.]75
168[.]0[.]24[.]143
27[.]0[.]177[.]36
180[.]233[.]121[.]132
168[.]167[.]72[.]96
103[.]47[.]34[.]26
89[.]203[.]193[.]220
45[.]58[.]183[.]18
36[.]255[.]229[.]160
103[.]44[.]34[.]66
103[.]17[.]45[.]175
168[.]167[.]23[.]31
202[.]22[.]237[.]104
118[.]179[.]252[.]107
27[.]0[.]177[.]99
103[.]109[.]216[.]19
103[.]17[.]45[.]66
102[.]220[.]72[.]57
43[.]225[.]48[.]129
43[.]225[.]48[.]56
43[.]225[.]51[.]60
43[.]225[.]48[.]221
102[.]222[.]67[.]208
102[.]222[.]67[.]113
102[.]222[.]66[.]238
102[.]222[.]217[.]20
43[.]225[.]51[.]119
43[.]225[.]50[.]50
102[.]222[.]66[.]250
102[.]222[.]66[.]189
102[.]222[.]216[.]59
102[.]222[.]66[.]243
102[.]222[.]67[.]182
102[.]222[.]67[.]59
43[.]225[.]50[.]137
43[.]225[.]48[.]199
43[.]225[.]51[.]15
43[.]225[.]48[.]85
196[.]220[.]156[.]168
43[.]225[.]51[.]13
43[.]225[.]51[.]248
43[.]225[.]48[.]239
43[.]225[.]48[.]50
43[.]225[.]51[.]240
43[.]225[.]50[.]151
43[.]225[.]50[.]36
43[.]225[.]48[.]179
103[.]47[.]34[.]53
118[.]179[.]224[.]50
118[.]179[.]233[.]179
185[.]153[.]49[.]138
103[.]200[.]95[.]240
45[.]58[.]156[.]76
192[.]144[.]73[.]169
118[.]179[.]232[.]91
103[.]145[.]227[.]94
45[.]167[.]102[.]151
45[.]167[.]103[.]91
45[.]167[.]103[.]162
45[.]167[.]101[.]21
45[.]167[.]102[.]70
45[.]167[.]103[.]76
45[.]167[.]101[.]208
45[.]167[.]101[.]130
45[.]167[.]101[.]210
45[.]167[.]102[.]125
45[.]167[.]101[.]30
203[.]80[.]50[.]100
195[.]146[.]116[.]127
103[.]44[.]34[.]87
103[.]47[.]34[.]34
103[.]160[.]62[.]76
176[.]58[.]83[.]222
128[.]223[.]93[.]125
192[.]140[.]224[.]50
45[.]222[.]76[.]184
118[.]179[.]247[.]129
208[.]98[.]0[.]49
36[.]255[.]229[.]175
103[.]28[.]156[.]203
202[.]22[.]225[.]140
168[.]167[.]84[.]166
168[.]167[.]36[.]69
168[.]167[.]53[.]22
168[.]167[.]26[.]197
168[.]167[.]26[.]208
168[.]167[.]23[.]126
168[.]167[.]26[.]136
103[.]47[.]34[.]33
118[.]179[.]238[.]100
168[.]167[.]26[.]254
168[.]167[.]26[.]251
168[.]167[.]26[.]203
168[.]167[.]23[.]101
168[.]167[.]84[.]78
168[.]167[.]26[.]154
143[.]255[.]135[.]47
103[.]24[.]35[.]69
118[.]179[.]233[.]252
202[.]22[.]229[.]27
170[.]210[.]105[.]238
176[.]58[.]80[.]195
64[.]7[.]189[.]165
103[.]28[.]157[.]152
212[.]11[.]126[.]136
168[.]167[.]23[.]110
168[.]167[.]26[.]193
168[.]167[.]23[.]121
168[.]167[.]23[.]32
103[.]28[.]158[.]30
103[.]28[.]157[.]136
185[.]5[.]127[.]6
103[.]28[.]158[.]32
102[.]220[.]72[.]227
103[.]28[.]158[.]7
45[.]58[.]128[.]36
185[.]100[.]85[.]101
168[.]167[.]23[.]107
168[.]167[.]26[.]219
168[.]167[.]23[.]111
168[.]167[.]23[.]54
168[.]167[.]26[.]143
168[.]167[.]26[.]227
168[.]167[.]26[.]153
168[.]167[.]23[.]221
103[.]161[.]248[.]234
168[.]167[.]85[.]133
103[.]161[.]248[.]245
168[.]167[.]26[.]212
168[.]167[.]26[.]152
103[.]255[.]107[.]123
118[.]103[.]138[.]97
36[.]255[.]229[.]204
103[.]17[.]46[.]197
27[.]0[.]177[.]22
118[.]179[.]254[.]45
103[.]134[.]79[.]134
168[.]167[.]95[.]5
168[.]167[.]23[.]99
168[.]167[.]26[.]232
168[.]167[.]26[.]209
36[.]255[.]228[.]8
168[.]167[.]23[.]4
36[.]255[.]229[.]235
103[.]210[.]47[.]39
36[.]255[.]229[.]101
103[.]47[.]35[.]82
103[.]44[.]34[.]72
36[.]255[.]229[.]28
118[.]103[.]138[.]110
27[.]0[.]178[.]114
36[.]255[.]230[.]243
118[.]103[.]138[.]126
103[.]210[.]47[.]27
103[.]255[.]104[.]247
118[.]103[.]138[.]96
103[.]255[.]107[.]142
68[.]235[.]38[.]170
103[.]47[.]35[.]35
202[.]22[.]228[.]143
36[.]255[.]229[.]140
103[.]47[.]32[.]193
201[.]49[.]191[.]166
41[.]94[.]113[.]30
185[.]5[.]202[.]148
185[.]249[.]27[.]145
89[.]104[.]240[.]241
185[.]249[.]25[.]194
185[.]249[.]26[.]110
185[.]249[.]24[.]0
185[.]249[.]25[.]126
27[.]0[.]176[.]63
103[.]109[.]217[.]191
185[.]212[.]252[.]113
185[.]246[.]20[.]183
103[.]109[.]216[.]129
185[.]153[.]48[.]130
103[.]109[.]216[.]79
45[.]229[.]8[.]8
185[.]159[.]203[.]143
64[.]7[.]187[.]42
207[.]246[.]181[.]101
207[.]246[.]181[.]105
194[.]149[.]140[.]38
212[.]11[.]96[.]107
64[.]7[.]163[.]126
89[.]104[.]244[.]54
128[.]223[.]76[.]88
146[.]20[.]128[.]154
41[.]94[.]84[.]187
89[.]203[.]181[.]126
45[.]58[.]131[.]98
45[.]68[.]21[.]11
103[.]109[.]217[.]219
103[.]47[.]34[.]7
68[.]235[.]38[.]36
118[.]179[.]246[.]92
36[.]255[.]230[.]167
103[.]109[.]217[.]95
202[.]22[.]236[.]25
68[.]235[.]52[.]36
104[.]160[.]160[.]162
198[.]54[.]129[.]45
118[.]179[.]247[.]70
36[.]255[.]229[.]158
45[.]191[.]157[.]41
168[.]167[.]23[.]71
118[.]179[.]254[.]108
36[.]255[.]230[.]251
118[.]103[.]138[.]103
169[.]159[.]231[.]227
41[.]94[.]245[.]125
199[.]188[.]120[.]81
103[.]17[.]46[.]17
195[.]146[.]108[.]238
103[.]145[.]226[.]76
41[.]94[.]93[.]218
168[.]167[.]72[.]179
103[.]47[.]32[.]61
45[.]229[.]251[.]95
36[.]255[.]230[.]168
103[.]44[.]34[.]99
82[.]117[.]137[.]222
45[.]229[.]251[.]94
27[.]0[.]176[.]30
118[.]103[.]138[.]118
188[.]166[.]31[.]252
27[.]0[.]176[.]93
27[.]0[.]178[.]203
45[.]229[.]44[.]9
103[.]109[.]217[.]144
103[.]47[.]32[.]144
103[.]210[.]47[.]225
176[.]58[.]86[.]65
118[.]103[.]138[.]104
27[.]0[.]176[.]168
27[.]0[.]176[.]35
36[.]255[.]230[.]228
103[.]47[.]32[.]186
118[.]179[.]224[.]126
103[.]47[.]34[.]101
168[.]167[.]23[.]115
103[.]24[.]33[.]250
64[.]30[.]184[.]131
118[.]179[.]231[.]183
103[.]47[.]32[.]98
163[.]47[.]248[.]60
198[.]54[.]128[.]108
118[.]103[.]138[.]106
68[.]235[.]38[.]140
163[.]47[.]251[.]117
200[.]3[.]123[.]76
180[.]233[.]120[.]67
103[.]109[.]217[.]77
165[.]16[.]3[.]8
168[.]167[.]26[.]242
68[.]235[.]44[.]37
102[.]64[.]22[.]139
168[.]167[.]26[.]177
198[.]148[.]92[.]176
41[.]94[.]163[.]94
209[.]103[.]249[.]235
31[.]47[.]76[.]194
85[.]13[.]64[.]100
102[.]215[.]34[.]42
168[.]167[.]23[.]40
168[.]167[.]23[.]69
103[.]127[.]254[.]198
168[.]167[.]23[.]87
168[.]167[.]23[.]103
168[.]167[.]23[.]89
168[.]167[.]53[.]98
118[.]179[.]235[.]254
27[.]0[.]178[.]109
103[.]47[.]33[.]56
168[.]167[.]23[.]100
168[.]167[.]23[.]8
45[.]87[.]209[.]5
193[.]38[.]249[.]240
213[.]235[.]162[.]79
213[.]235[.]173[.]213
82[.]117[.]141[.]73
143[.]208[.]139[.]40
103[.]200[.]95[.]242
27[.]0[.]177[.]73
181[.]174[.]249[.]200
82[.]117[.]129[.]158
41[.]94[.]86[.]138
118[.]179[.]228[.]42
170[.]245[.]119[.]150
45[.]170[.]201[.]113
168[.]167[.]53[.]6
168[.]167[.]23[.]61
168[.]167[.]26[.]165
45[.]170[.]201[.]203
45[.]170[.]200[.]111
103[.]166[.]42[.]36
45[.]170[.]202[.]161
45[.]170[.]201[.]39
45[.]170[.]200[.]120
45[.]170[.]201[.]168
45[.]170[.]200[.]31
45[.]170[.]201[.]147
45[.]170[.]200[.]8
45[.]170[.]200[.]106
168[.]167[.]95[.]134
168[.]167[.]23[.]117
103[.]255[.]104[.]208
168[.]167[.]23[.]2
168[.]167[.]23[.]35
168[.]167[.]254[.]65
168[.]167[.]128[.]142
118[.]103[.]139[.]113
102[.]214[.]234[.]131
68[.]235[.]43[.]126
154[.]73[.]154[.]116
168[.]167[.]213[.]81
103[.]47[.]34[.]167
168[.]167[.]86[.]230
168[.]167[.]53[.]223
168[.]167[.]55[.]62
168[.]167[.]69[.]94
168[.]167[.]26[.]102
168[.]167[.]26[.]100
103[.]47[.]32[.]157
45[.]58[.]128[.]4
45[.]58[.]128[.]2
103[.]162[.]187[.]36
27[.]0[.]178[.]116
36[.]255[.]230[.]146
118[.]179[.]228[.]238
45[.]175[.]101[.]222
168[.]167[.]23[.]5
103[.]109[.]216[.]114
Appendix: Vendor-Detected Files Containing Airline Domain
adbba3097d481578543b69c5a87d7124b3cb9f0320cb596657f750e5a528cec4
536643341b59fdcda8a0dcc4b53aa9fae2007eb8a43f28d70a0002883e85c75a
1dcf99e980765e4f410d59a1ff0612485630109229107be9d0445ebf685f3aba
A4870d0353d7f4beaaf25dc14a6c0577baf7ec3b68d02a76eacae4efca1514e3
363ec5f48f4228a27fe9830ba0e409bb52b72e7811488b1844f3d4ae7a36eb30
Ad878241408ebd3a04e8380ab24397d556fab14ea5a17e6b3d15b83714aed00d
2afd539a74934c6525540d48dfcf668c4b20b9a376084a6acf4ab624ee667a8f
d1ccc79acf1708e59e8c90103a314e0c39c7ff6399b1206ecc6af626e5f9c28c
Bf690a399e1cbc42cedef4893133300622f88fc6e1bd711fab2970eecb9c1559
Ecf21446e637bb70564d2826f9778911f883429f3235ac67de145e76752dcea1
F3f86772eafec3f06f266a31361cfe8c76129fdc6d7ccf1943984218fad9661c
9594f7c5b1834d2ab32b510bce24c63d08d5799645cecbe952c1aad50bcf8ab7
88eee66cec5f917033c328651ab9374dd952ea822d753658fedd6807ed26e85b
B240cac40e1e35306e3127735e5efe36b49ff16236e5ff31e6f8f66d0270bea4
4ba1c4407bf08ccecb276a155f8197c95ec523af3dbc86cd77df06bc326b4e57
2d1ea09628fdbdbf635f985c60a2794ec6cd52ba8657cd0ba278bcd61fecb36c
B19050beb5b2c3712f746761fa0da3a722cf136f3429b13b35b3e2ee84b81ebc
539a23d4e9abb0bf486b1a080696c937b091a4c9c65669ec796087e2899dba2b
241a7c1152d90b27803b90d414d98ebc65a5bc1e5202840fa7706f1acd8ba8f6
D10afa9478d5a52468bdd1d678cc59deab5d6c3dce5147100cb1fe772c20a8f9
D6b1db14c863b7252b3f6be01b43966e3f59cbfed7ff96df5b84b46e112a6791
Dc72fd0fd4c09b35c9da89ea4452c9dce2bff851583ef61903f6a2cf81ba4dad
604914b977e2c5f309c07a09fd494c1fa322bdc85fc9f367fc6c5f9bf83a200e
25319eeed6a5fb70decebb9699570205261d494df144c958965dd39e35a2de35
21dcfbf4f37590c052e953c41ca87a5293c99c50e2457c35f44d778b1ce87856
D89828cefbca12b5d7bff533a9b4c110ff6f623f8ef02716d16aae7f5c6b2554
1ce07589cbb88757ae753726ed096c74cd21da5414a58e2db92cfeb850f2934d
7f403a23274f7d64d19d457ceab85cfb16337412198f4b96dca0941ab3baba29
1aab38523224293c41f9ccb2b62ef9595a36e3ddf0d06bf0faabb3bf407ddfbe
7c67fdfb2b29dd96324230640fdca59fdb86ced92ae23f67e8312efc51a1c73e
E2138f5da9f50d7031b51732a11c8d27aa47564a80618cb1e4c87d05afc8be7f
294be49c71aa1b93d94bdeec778a9c4e399b3cbbed2d1b4158834003c6de52ab
1fdb166ad6fa6343221b0912d888d800e72339ea48f31e62c9014322c61c3fc8
Bb3c62e586a9d3cc96d09e4be7f7871138b3e63b7e85f2a7f8ddc8f1dd575049
9c11f6f52b295a29157df3c87e103427f0f2c991a8010704af29e90b6f738e8b
91694a125900e2893cb02a983ad7c5f4a094709c09ddc8f6bb077ae293d0928e
Dbebd9e2fb4ce17eeca4449116cefcef4ce23e136d149d2de591317f3963f2e5
F549e6ae7de422040c4c8d8016a3f385bb33fe92b688578f3e27b404cd1fb29d
3104e0c1c075356053f6cf560d3d5da6ebf54710c0bf0128301a4c7fa3a28a1b
1687d33e163f11256439ec46a08ebadf4cdd805b8ba4308dbf6d9cba8e2dc62c
009d841bc61b21e9770b6242799af0f47509fdac2a0d5e390cff245daf22defd
Bd068ba67e12a2d5a558ff0741ab9807efa64ed973b86315199bab4ef173a797
7364908dcd95717fba9d8091ea52c38121a12c43d72c898da111367219ff50ce
4e8943bd98ea8b8576f86faaab4b4459ded96f0f9b9441d65934c87a09fc23cf
Ce38c57e209181f24ef60e14f3414c2c78a170f9c5acf5156cd410891ca622f7
1d5052afa786bbd60dfc93ebcbbe764a7d1ab504c56529b35340618bc949cc0f
A06512ba744c52bfe7dc6d94cb00b5ab7cbebe625953ed7699a3edcd74ae3304
2fa02bfb75350292163c68fc12bcb05e1fd485a8c1ef68a238935014384bdad7
84b14c8b9b61ea915fb2eee001e965fcc37d6cd2e677881e2e0db7fc958f1b44
756273e9525c93229234579baf1a6f707b09a9dd47a205de880333c1d2af6a2b
11ed0f8f42c14e86bf09c05497f527505a192b12c9378b1dbc810bc062292dee
14534fd49c25b8287a6cd4ea8c0947bc4b74986710100484d7ae872442b056fc
Ca2c2f59ef4cde66eb596457b679797847b0fbf67f9874d330d85bc19dee1de3
4d58ec16911455c2f95fc1f7bedca1e0d32bef642c8711143f0ee48fc8591118
Appendix: SHA-256 Hashes
2da803ed4960495f987aa6ce51552d0fc0ee9d7d6fb01d932cb978d2220e7e0f
789ddc8cf2bb7075190df7c081504fcf6aa3964f9a10914371635820b32c2083
8fab6267676e929b3140eda2109687802eb95bce7f2daa13cc64f4131f00ac86
Faf1037e8e01c9823f0adee3d2d4ba17433bff18a6e849749d0277c9414771a0
657c4c5da82eb7a827da71521b1d570f7e6c65a4c6569c7120bfdd9f0d0ab0a2
a387ae07a9cbfe11b3bff333f378214e0b3e2546fdf485becf12723b9a14b815
440a4da69abc77e38c11d9b992a882df75e2bb944951ed22f5e578ad1a0dfc0e
f2459b016f6d7159eb6cf5dd5e8d3b4317a501436516012111d2b7d93d82cb36
386130be32e341f48343b0efbca960d1068484460fd5197553c2ac79f0140f99
7504587a6b1a75660993d77cdd4d0e58ade78de11f83bd06aab63e3536e18105
8ee256e414b4ecd56363b6dff34cc0b42798d9e65854881b7c6ace91e93060a1
8d8e747f48d87d876ba17938e951b783d49301ad1eb22f75596a72f5927ca5a8