Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
139
Global rank
128 infographic chevron month
Month rank
97 infographic chevron week
Week rank
0
IOCs

Adwind RAT, sometimes also called Unrecom, Sockrat, Frutas, jRat, and JSocket, is a Malware As A Service Remote Access Trojan that attackers can use to collect information from infected machines. It was one of the most popular RATs in the market in 2015.

Trojan
Type
Likely Mexico
Origin
1 January, 2012
First seen
21 August, 2026
Last seen
Also known as
Unrecom
Sockrat
Frutas
jRat
JSocket

How to analyze Adwind with ANY.RUN

Type
Likely Mexico
Origin
1 January, 2012
First seen
21 August, 2026
Last seen

IOCs

IP addresses
150.171.28.11
48.209.138.189
131.253.33.203
151.101.194.208
2.23.246.9
23.11.40.157
150.171.22.17
48.192.1.65
142.250.154.113
104.18.23.222
150.171.109.193
172.211.123.249
217.160.0.134
142.251.13.95
150.171.27.11
48.209.133.15
23.59.18.102
2.16.241.210
2.16.204.161
142.251.20.94
Hashes
8c3d7648abcd95a272ce12db870082937f4d7f6878d730d83cb7fbb31eb8b2c9
b62d2733ab99556b108a1951d894c5a8d76b1ac7a00c02c388f9eb9be046c56f
b44540473b97364e0f7a8a0002dd21d7a0717028fa1533f139bc98f40c91c0f0
8d8a318e6d90dfd7e26612d2b6385aa704f686ca6134c551f8928418d92b851a
780c565d5af3ee6f68b887b75c041cdf46a0592f67012f12eeb691283e92630a
5a4bd51b969bf187ff86d94f4a71fdfbfa602762975fa3c73d264b4575f7c78f
b393f05e8ff919ef071181050e1873c9a776e1a0ae8329aefff7007d0cadf592
b72e9013a6204e9f01076dc38dabbf30870d44dfc66962adbf73619d4331601e
5154e165bd6c2cc0cfbcd8916498c7abab0497923bafcd5cb07673fe8480087d
36dc51c4bf787f640a4b45cbb84ab6954f6e595cbd3617c2f5a4e1e607b38bff
996a259e53ca18b89ec36d038c40148957c978c0fd600a268497d4c92f882a93
11e6aca8e682c046c83b721eeb5c72c5ef03cb5936c60df6f4993511ddc61238
b9fa2d52a4ffabb438b56184131b893b04655b01f336066415d4fe839efe64e7
1224c11b69032c80e1493416641c82a37e558913a41f959f83ab2f96f097d6c0
c82725d91643d0c5d3887053d5a3a6c19a564d1ba4906acd2b250f8f121234d5
edf069011f6957a9630b9197e1f2ac58b5900f979ccfe13748cf062f450f8599
be27b369ac515056f6514b33ea0a2d6eeefe206474c148afd36861a762fab866
e430ace7e122ec2a112a1f9110ad1feb9f12da1eb2406f750f829db2be392aae
6e7644d2b0dbf6b6429a379eb3e282e9f03b3a3fc85ddd3995063cf0d813593e
30e66cedcd682a7d158615cb64471d1c0a944458eea6e2eb5084c8fe4ff24d33
Domains
oneocsp.microsoft.com
settings-win.data.microsoft.com
www.microsoft.com
edge.microsoft.com
www.bing.com
ocsp.digicert.com
copilot.microsoft.com
go.microsoft.com
client.wns.windows.com
edge-consumer-static.azureedge.net
update.googleapis.com
crl.microsoft.com
clients2.googleusercontent.com
api.edgeoffer.microsoft.com
images.unsplash.com
xpaywalletcdn.azureedge.net
login.live.com
fonts.googleapis.com
fonts.gstatic.com
watchnex.fr
URLs
http://edge.microsoft.com/browsernetworktime/time/1/current?cup2key=2:yuqrkou1y2ghfrte2yvad3le_ozjuiea2f9igwp72kw&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edge%2cedgeconfig%2cedgeservices%2cedgefirstrun%2cedgefirstrunconfig&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://edge.microsoft.com/serviceexperimentation/v3/?osname=win&channel=stable&osver=10.0.19045&devicefamily=desktop&installdate=1661339457&clientversion=133.0.3065.92&experimentationmode=2&scpguard=0&scpfull=0&scpver=0
https://copilot.microsoft.com/c/api/user/eligibility
https://watchnex.fr/
https://fonts.googleapis.com/css2?family=inter:wght@300;400;500;600;700;800;900&display=swap
https://watchnex.fr/mockup.jpg
https://watchnex.fr/favicon.ico
https://fonts.gstatic.com/s/inter/v20/ucc73fwrk3iltehus_nvmrmxcp50sjia1zl7.woff2
https://api.edgeoffer.microsoft.com/edgeoffer/pb/experiments?appid=edge-extensions&country=us
https://www.bing.com/bloomfilterfiles/expandeddomainsfilterglobal.json
https://images.unsplash.com/photo-1536440136628-849c177e76a1?auto=format&fit=crop&w=1000&q=80
https://edge.microsoft.com/autofillservice/core/page/-6205843084447141029/6332256805659130340?cidalgoversion=2
https://xpaywalletcdn.azureedge.net/mswallet/expresscheckout/v1/getglobalconfig?edgechannel=stable&edgeversion=133.0.3065.92&configversion=0
https://config.edge.skype.com/config/v1/edge/133.0.3065.92?clientid=4489578223053569932&agents=edgeruntime%2cedgeruntimeconfig%2cedgedomainactions&osname=win&client=edge&channel=stable&scpfre=0&osarch=x86_64&osver=10.0.19045&wu=1&devicefamily=desktop&uma=0&sessionid=72&mngd=0&installdate=1661339457&edu=0&soobedate=1504771245&bphint=2&fg=1&lbfgdate=1766137499&lafgdate=0
https://watchnex.fr/downloads/watchnex%20setup%201.3.2.0.exe
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
http://oneocsp.microsoft.com/ocsp/mfqwujbqme4wtdajbgurdgmcgguabbq3l3%2f%2fa6adk8nray2gxzvayrhg4aqub6t%2b2v%2bxq3lso2d33ojhnyhhqoucezmaaaagb6jmmcovb6saaaaaaay%3d
Last Seen at

Recent blog posts

post image
North Korean IT Workers Scheme: Detection IOC...
watchers 6414
comments 0
post image
Hunt Malware & Phishing Threats with ANY....
watchers 6228
comments 0
post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 19542
comments 0

What is Adwind RAT?

Adwind RAT, sometimes also called Unrecom, Sockrat, Frutas, jRat, and JSocket, is a remote access trojan available as MaaS ( Malware-As-A-Service ). Adwind can collect user and system data, control the webcam of the infected machine, capture screenshots, install and run other malicious programs, log keystrokes, steal web browser passwords, and more.

First identified in January 2012, Adwind can’t be called a new malware, but it managed to become as popular as ransomware despite the age. In fact, in 2015, over 1,800 people purchased Adwind on its “official” website, making the site one of the most popular malware distribution platforms globally. It should be noted that Adwind poses a danger to users of all major operating systems, including Windows, Mac OS X, Linux, and BSD.

General description of Adwind

Initially discovered for the first time in 2012, the malware was known as Frutas and presumably originated in Mexico. For the initial year of Adwind’s existence, the creator released multiple versions, all distributed on Spanish hacker forums for free.

The feature-set of the original version was somewhat limited as compared to the latest iteration of the virus. As such, in 2012, Adwind RAT could capture screenshots, steal passwords from selected online services, open specific web pages and take screenshots, as well as display pop-up messages.

In 2013, the creator of the malware released a new version, changing its name to Adwind. The new version added support for Android OS and started to gain traction outside of the Spanish hacker community, becoming a popular tool worldwide. Following the popularity of the malware, the author has set up a YouTube channel to post tutorials for other cybercriminals. During the same year, the first-ever case of Adwind malware used in a targeted attack was documented in Pacific Asia. In November 2013, the malware was rebranded as UNRECOM and sold to Unrecom Soft. The rebranded version of Adwind retained all functionality of the previous iteration.

In 2014, the source code of Adwind was leaked. As a result, it became available online free of charge, becoming a popular tool among cybercriminals who widely used the cracked versions in attacks during 2014 and 2015, further contributing to the overall popularity of Adwind. In response to the leak, the “official” version of Adwind Trojan was significantly upgraded and re-released as AlienSpy in October 2014. The Adwind RAT v3.0 learned to auto-detect sandboxes, gained cryptographically secured communication with the control server, and became capable of detecting and disabling antiviruses.

Finally, in 2015, the malware was renamed once again, becoming a JSocket RAT. As a malware-as-a-service, Adwind RAT is sold to users for a fixed fee charged monthly as a subscription and could be purchased at JSocket.org until the website became unavailable. The price depends on the package which the user chooses.

Based on the analysis, Adwind requires active actions from the potential victim to start the execution process. As such, being delivered in a malicious .JAR file, the malware won’t be able to execute itself until the victim double-clicks on the attachment.

Adwind RAT malware analysis

ANY.RUN interactive service enables researchers to perform the analysis of the execution process of Adwind Trojan in a secure environment in multiple formats, including video.

adwind execution process graph

Figure 1: Visual process graphs generated by ANY.RUN help to simplify and speed up research work

text report of the Adwind malware analysis Figure 2: ANY.RUN creates customizable text reports allowing researchers to share the results of the simulation easily

Adwind execution process

In the case of our simulation, after a user opened the malicious .jar file, the malware started execution through Java virtual machine. This initial process executed the js script, which ran one more js script and another .jar file.

JS script also used Task Scheduler to run itself later. Jar file started a series of malicious activities such as using attrib.exe to mark files or folders as hidden, running VBS script files, changing the autorun value in the registry, and more. It has been noted that sometimes Jar file runs a series of taskkill commands to shutdown processes by their names based on a list containing names of system processes, names of common Anti-virus programs, and analyzing programs wireshark.exe, procexp.exe, processhacker.exe, and so on. It should be noted that this malware doesn't work without installed Java.

How to avoid infection by Adwind?

Exhibiting caution when handling emails from unknown senders is a reliable way to prevent contamination since Adwind trojan requires a victim to interact with the malicious file to enter an active phase. Therefore, never downloading attachments in suspicious emails is a sure way to stay safe when you are dealing with any malicious objects such as ransomware, RAT, or others. In addition, preventing .JAR files from running in %AppData%[random folder name], and prohibiting the creation of .JAR in the same folder can be considered a good security measure.

Distribution of Adwind

Adwind RAT is distributed in mail spam campaigns the same as AZORult or Remcos and has two general attack vectors. It can be delivered to the victim's machine as an email attachment in the form of a malicious file such as a PDF or a Microsoft Office file.

The other attack vector is a malicious URL that redirects the victim to a website from where Adwind is downloaded.

How to export process graph from the analysis of Adwind malware using ANY.RUN?

Analysts can export the process graph from a task to SVG format if they want it to share. Just click on the "Export" button and choose "Export Process Graph (SVG)" in the drop-down menu.

adwind process graph Figure 3: Adwind's process graph exported in SVG format

Conclusion

Distributed as a malware-as-a-service, the Adwind RAT v3.0 has become one of the most popular RATs and targets users of all major operating systems worldwide.

Not only is the “official” paid version of the malware is known to have created a massive following, but several slightly outdated but still very powerful cracked, free-to-use versions are readily available online on the underground hacking forums together with ransomware. As a result, today, Adwind remains a serious, active, and, perhaps, even growing threat.

HAVE A LOOK AT

Bluesky Ransomware screenshot
BlueSky ransomware, first identified in June 2022, shares code similarities with other well-known ransomware families like Conti and Babuk. It primarily spreads via phishing emails and malicious links and can propagate through networks using SMB protocols. BlueSky uses advanced evasion techniques, such as hiding its processes from debuggers via the NtSetInformationThread API, making it difficult for analysts to detect and mitigate its attacks.
Read More
Bumblebee Loader screenshot
Bumblebee Loader
bumblebee
Bumblebee is a highly adaptable malware loader, often used by threat actors linked to the Conti and TrickBot cybercrime groups. Since its discovery in 2021, Bumblebee has been leveraged in phishing campaigns and email thread hijacking, primarily to distribute payloads like Cobalt Strike and ransomware. The malware employs obfuscation techniques, such as DLL injection and virtual environment detection, to avoid detection and sandbox analysis. Its command-and-control infrastructure and anti-analysis features allow it to persist on infected devices, where it enables further payload downloads and system compromise.
Read More
Crocodilus screenshot
Crocodilus
crocodilus
Crocodilus is a highly sophisticated Android banking Trojan that emerged in March 2025, designed for full device takeover. Disguised as legitimate apps, it steals banking credentials, cryptocurrency wallet data, and enables remote control, rapidly evolving into a global threat targeting financial users across Europe, South America, and Asia.
Read More
XRed screenshot
XRed
xred
XRed operates as a stealthy backdoor, enabling cybercriminals to gain unauthorized remote access to infected systems. XRed has gained particular notoriety for its distribution through trojanized legitimate software and hardware drivers, making it exceptionally dangerous due to its ability to masquerade as trusted applications.
Read More
Mallox screenshot
Mallox
mallox
Mallox is a ransomware strain that emerged in 2021, known for its ability to encrypt files and target database servers using vulnerabilities like RDP. Often distributed through phishing campaigns and exploiting exposed SQL servers, it locks victims' data and demands a ransom. Mallox operates as a Ransomware-as-a-Service (RaaS), making it accessible to affiliates who use it to conduct attacks.
Read More
Diamotrix screenshot
Diamotrix
diamotrix
Diamotrix is a stealthy cryptocurrency clipper malware that silently monitors the Windows clipboard, waiting for the moment a user copies a digital wallet address. Diamotrix replaces it with an attacker-controlled wallet, invisibly redirecting any resulting transaction. Because blockchain transfers are irreversible, victims rarely discover the theft until the funds are long gone.
Read More