Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
132
Global rank
93 infographic chevron month
Month rank
75 infographic chevron week
Week rank
0
IOCs

Adwind RAT, sometimes also called Unrecom, Sockrat, Frutas, jRat, and JSocket, is a Malware As A Service Remote Access Trojan that attackers can use to collect information from infected machines. It was one of the most popular RATs in the market in 2015.

Trojan
Type
Likely Mexico
Origin
1 January, 2012
First seen
10 September, 2026
Last seen
Also known as
Unrecom
Sockrat
Frutas
jRat
JSocket

How to analyze Adwind with ANY.RUN

Type
Likely Mexico
Origin
1 January, 2012
First seen
10 September, 2026
Last seen

IOCs

IP addresses
150.171.109.99
150.171.109.100
217.160.0.134
172.211.123.249
2.16.204.157
92.223.97.79
150.171.27.11
2.23.246.9
142.250.154.113
20.165.94.63
23.11.41.157
2.16.241.227
104.86.148.134
150.171.28.11
48.209.138.168
20.190.159.129
2.16.241.199
204.79.197.203
48.209.133.15
150.171.109.104
Hashes
3eb38ae99653a7dbc724132ee240f6e5c4af4bfe7c01d31d23faf373f9f2eaca
299c2360b6155eb28990ec49cd21753f97e43442fe8fab03e04f3e213df43a66
2b2627548e61316150d47ffc3e6cad465ca05b3cccd4785eb7d21aa7baa0f441
aa9efb969444c1484e29adecab55a122458090616e766b2f1230ef05bc3867e0
758b930a526fc670ab7537f8c26321527050a31f5f42149a2dda623c56a0a1a9
6da0747334b0fea7592fd92614b2bbc8b126535e129b1fee483774d914e98eb5
968ac99bbaaf8a49a474c934e73ad58f88c6c7f2a363cb44771e0378444e36ba
583500b76965eb54b03493372989ab4d3426f85462d1db232c5ae6706a4d6c58
32d83ff113fef532a9f97e0d2831f8656628ab1c99e9060f0332b1532839afd9
9b1fbf0c11c520ae714af8aa9af12cfd48503eedecd7398d8992ee94d1b4dc37
9be85b986ea66a6997dde658abe82b3147ed2a1a3dcb784bb5176f41d22815a6
5d9ceb1ce5f35aea5f9e5a0c0edeeec04dfefe0c77890c80c70e98209b58b962
8a9c58fbded5ea3474315e4a9824ca8b1486098a1a03e897e0b19419d5e1876a
59a6d632b8a9f5dba26f2a689c3865e195351df7c3c08aa1669fe0df9f9eb883
ae259630c56c98202c0e52d02a0f13b83b936fe485de8f0aecb647dfbd9dda12
20b88f684fce572a639879558cad00a9057b569a58f6511b1d5913cd1a866cf4
af7b99be1b8770c0e4d18e43b04e81d11bdeb667fa6b07ade7a88f4c5676bf9a
604dd0d41f6c420d342da804b1ceeee15a318ada932e507b4f06f8893af6aebd
a49fd2b21bf2fced1159cb9589c8e5c87ce3dfe40fed23b25a32d85f80c63e6b
1de9ae545519ddd4b410e04005e92ec5293bfb303b348a2535eec4cecbca3e4e
Domains
cxcs.microsoft.net
msedge.b.tlu.dl.delivery.mp.microsoft.com
go.microsoft.com
settings-win.data.microsoft.com
edge.microsoft.com
google.com
activation-v2.sls.microsoft.com
www.bing.com
www.microsoft.com
fe3cr.delivery.mp.microsoft.com
config.edge.skype.com
images.unsplash.com
ocsp.digicert.com
client.wns.windows.com
edge-consumer-static.azureedge.net
copilot.microsoft.com
static.edge.microsoftapp.net
self.events.data.microsoft.com
watchnex.fr
oneocsp.microsoft.com
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:daz_awoq6ck1urxfpe328ffxopevkvnsnvvjzry9xf0&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://watchnex.fr/
https://watchnex.fr/mockup.jpg
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://fonts.googleapis.com/css2?family=inter:wght@300;400;500;600;700;800;900&display=swap
https://images.unsplash.com/photo-1536440136628-849c177e76a1?auto=format&fit=crop&w=1000&q=80
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://fonts.gstatic.com/s/inter/v20/ucc73fwrk3iltehus_nvmrmxcp50sjia1zl7.woff2
https://watchnex.fr/favicon.ico
https://edge.microsoft.com/autofillservice/core/page/-6205843084447141029/6332256805659130340?cidalgoversion=2
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://edge.microsoft.com/extensionwebstorebase/v1/crx?os=win&arch=x64&os_arch=x86_64&nacl_arch=x86-64&prod=edgecrx&prodchannel=&prodversion=133.0.3065.92&lang=en-us&acceptformat=crx3,puff&x=id%3djmjflgjpcpepeafmmgdpfkogkghcpiha%26v%3d1.2.1%26installedby%3dother%26uc%26ping%3dr%253d265%2526e%253d1
https://update.googleapis.com/service/update2/json?cup2key=14:efcldm3a8ymesxoggbrzgc9-lep-jpz8kb_yuditzbi&cup2hreq=50c9932a20d621cbd52a1c4ddb27ef1a2d9bbbec91e51299ad1b3b99f768e902
https://www.bing.com/api/shopping/v1/user/shoppingsettings?enabledservicefeaturesv2=edgeserverux.shopping.cashbackeumarkets,edgeserverux.shopping.msedgeshoppingcashbackdismisstimeout2s
https://watchnex.fr/downloads/watchnex%20setup%201.3.2.0.exe
Last Seen at

Recent blog posts

post image
ANY.RUN Secures Leader Status in G2’s Malware...
watchers 4268
comments 0
post image
15 Minutes Saved Per Alert: How a Lean German...
watchers 8705
comments 0
post image
HVNC Backdoor Targets LATAM Organizations wit...
watchers 10727
comments 0

What is Adwind RAT?

Adwind RAT, sometimes also called Unrecom, Sockrat, Frutas, jRat, and JSocket, is a remote access trojan available as MaaS ( Malware-As-A-Service ). Adwind can collect user and system data, control the webcam of the infected machine, capture screenshots, install and run other malicious programs, log keystrokes, steal web browser passwords, and more.

First identified in January 2012, Adwind can’t be called a new malware, but it managed to become as popular as ransomware despite the age. In fact, in 2015, over 1,800 people purchased Adwind on its “official” website, making the site one of the most popular malware distribution platforms globally. It should be noted that Adwind poses a danger to users of all major operating systems, including Windows, Mac OS X, Linux, and BSD.

General description of Adwind

Initially discovered for the first time in 2012, the malware was known as Frutas and presumably originated in Mexico. For the initial year of Adwind’s existence, the creator released multiple versions, all distributed on Spanish hacker forums for free.

The feature-set of the original version was somewhat limited as compared to the latest iteration of the virus. As such, in 2012, Adwind RAT could capture screenshots, steal passwords from selected online services, open specific web pages and take screenshots, as well as display pop-up messages.

In 2013, the creator of the malware released a new version, changing its name to Adwind. The new version added support for Android OS and started to gain traction outside of the Spanish hacker community, becoming a popular tool worldwide. Following the popularity of the malware, the author has set up a YouTube channel to post tutorials for other cybercriminals. During the same year, the first-ever case of Adwind malware used in a targeted attack was documented in Pacific Asia. In November 2013, the malware was rebranded as UNRECOM and sold to Unrecom Soft. The rebranded version of Adwind retained all functionality of the previous iteration.

In 2014, the source code of Adwind was leaked. As a result, it became available online free of charge, becoming a popular tool among cybercriminals who widely used the cracked versions in attacks during 2014 and 2015, further contributing to the overall popularity of Adwind. In response to the leak, the “official” version of Adwind Trojan was significantly upgraded and re-released as AlienSpy in October 2014. The Adwind RAT v3.0 learned to auto-detect sandboxes, gained cryptographically secured communication with the control server, and became capable of detecting and disabling antiviruses.

Finally, in 2015, the malware was renamed once again, becoming a JSocket RAT. As a malware-as-a-service, Adwind RAT is sold to users for a fixed fee charged monthly as a subscription and could be purchased at JSocket.org until the website became unavailable. The price depends on the package which the user chooses.

Based on the analysis, Adwind requires active actions from the potential victim to start the execution process. As such, being delivered in a malicious .JAR file, the malware won’t be able to execute itself until the victim double-clicks on the attachment.

Adwind RAT malware analysis

ANY.RUN interactive service enables researchers to perform the analysis of the execution process of Adwind Trojan in a secure environment in multiple formats, including video.

adwind execution process graph

Figure 1: Visual process graphs generated by ANY.RUN help to simplify and speed up research work

text report of the Adwind malware analysis Figure 2: ANY.RUN creates customizable text reports allowing researchers to share the results of the simulation easily

Adwind execution process

In the case of our simulation, after a user opened the malicious .jar file, the malware started execution through Java virtual machine. This initial process executed the js script, which ran one more js script and another .jar file.

JS script also used Task Scheduler to run itself later. Jar file started a series of malicious activities such as using attrib.exe to mark files or folders as hidden, running VBS script files, changing the autorun value in the registry, and more. It has been noted that sometimes Jar file runs a series of taskkill commands to shutdown processes by their names based on a list containing names of system processes, names of common Anti-virus programs, and analyzing programs wireshark.exe, procexp.exe, processhacker.exe, and so on. It should be noted that this malware doesn't work without installed Java.

How to avoid infection by Adwind?

Exhibiting caution when handling emails from unknown senders is a reliable way to prevent contamination since Adwind trojan requires a victim to interact with the malicious file to enter an active phase. Therefore, never downloading attachments in suspicious emails is a sure way to stay safe when you are dealing with any malicious objects such as ransomware, RAT, or others. In addition, preventing .JAR files from running in %AppData%[random folder name], and prohibiting the creation of .JAR in the same folder can be considered a good security measure.

Distribution of Adwind

Adwind RAT is distributed in mail spam campaigns the same as AZORult or Remcos and has two general attack vectors. It can be delivered to the victim's machine as an email attachment in the form of a malicious file such as a PDF or a Microsoft Office file.

The other attack vector is a malicious URL that redirects the victim to a website from where Adwind is downloaded.

How to export process graph from the analysis of Adwind malware using ANY.RUN?

Analysts can export the process graph from a task to SVG format if they want it to share. Just click on the "Export" button and choose "Export Process Graph (SVG)" in the drop-down menu.

adwind process graph Figure 3: Adwind's process graph exported in SVG format

Conclusion

Distributed as a malware-as-a-service, the Adwind RAT v3.0 has become one of the most popular RATs and targets users of all major operating systems worldwide.

Not only is the “official” paid version of the malware is known to have created a massive following, but several slightly outdated but still very powerful cracked, free-to-use versions are readily available online on the underground hacking forums together with ransomware. As a result, today, Adwind remains a serious, active, and, perhaps, even growing threat.

HAVE A LOOK AT

Remcos screenshot
Remcos is a commercially distributed remote administration and surveillance tool that has been widely observed in unauthorized deployments, where threat actors use it to perform remote actions on compromised machines. It is actively maintained by its vendor, with new versions and feature updates released on a frequent, near-monthly basis.
Read More
ClickLock screenshot
ClickLock
clicklock
ClickLock is a macOS information stealer and remote backdoor distributed via deceptive, terminal-based social engineering pages. Once executed, it bypasses Gatekeeper checks by stripping download quarantine flags and signing its executable with ad-hoc digital certificates. If users resist its initial demands, the malware initiates high-frequency background loops that repeatedly kill vital operating system applications to force plaintext password entry. It exfiltrates captured browser data, system keychain credentials, and cryptocurrency wallets to a Telegram bot before establishing a permanent backdoor.
Read More
Kali365 screenshot
Kali365 is an emerging Phishing-as-a-Service (PhaaS) platform that targets Microsoft 365 environments by stealing OAuth authentication tokens instead of passwords. First observed in April 2026, the service enables even low-skilled threat actors to bypass multi-factor authentication (MFA), gain persistent access to corporate cloud accounts, and compromise business communications, files, and collaboration platforms. Kali365 represents a shift from traditional credential theft toward session hijacking and token abuse, making it a significant threat to organizations that rely on Microsoft 365.
Read More
Bert Ransomware screenshot
Bert Ransomware is a newly emerged ransomware group that has been active since April 2025. It deploys variants targeting both Windows and Linux systems, focusing on critical sectors like healthcare, technology, and event services across the US, Asia, and Europe.
Read More
DarkVision screenshot
DarkVision
darkvision
DarkVision RAT is a low-cost, modular Remote Access Trojan that gives attackers remote control of infected Windows hosts. Initially observed around 2020 and sold in underground marketplaces, DarkVision has become notable for its full feature set (keylogging, screen capture, file theft, remote command execution and plugin support) and for being distributed via multi-stage loaders in recent campaigns.
Read More
GravityRAT screenshot
GravityRAT
gravity
GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.
Read More