Coder Social home page Coder Social logo

hostsmod's Introduction

HostsMod

If you don't trust it, either compile it yourself or manually append each entry to your hosts file.

Description

In the Minecraft cheating community, it's not uncommon for clients or client cracks/leaks to be malware. The most famous example of this would be the Autumn client "crack", released by Kant. This application attempts to blacklist known hosts of Kant's malware, in order to prevent someone from accidentally getting themselves ratted.

HostsMod also blocks grabify links as well as a few token loggers.

Domains

For a list of blocked domains, check out https://raw.githubusercontent.com/GardeningTool/HostsMod/main/domains.txt.

Important

One of the websites, "mvncentral.net" is made to look like maven central (https://repo1.maven.org/maven2/). Maven central is safe, but mvncentral.net is not.

Many of the domains may appear to be suspended. This is due to the fact that Kant, the purchaser of the domains and person who spread the malware this program attempts to block, purchased these domains fraudulently. Though they are suspended, I have decided to include them anyways.

All releases are Windows specific. If you'd like one for Linux, I'd suggest https://github.com/HackingMC/HostsMod (though there's no known rats from Kant for Linux)

Usage

Run as administrator

Clarification

If you run netstat after running HostsMod, you will likely see connections to mvncentral.net. This is caused by HostsMod pointing everything to localhost (127.0.0.1). To prove this, open a command prompt window and type "ping mvncentral.net". The reply should be "Reply from 127.0.0.1". This shows that mvncentral.net now points to localhost.

Known ratted cracks & proofs

  • Autumn "leak" | Proof
  • Remix 1.6.3 crack
  • Remix 1.7.1 crack
  • Astolfo crack
  • ZeroDay b20.4 crack
  • Tenacity crack

hostsmod's People

Contributors

aauth avatar e4zily avatar gabrielvicenteyt avatar gardeningtool avatar git-eternal avatar intexception avatar josephworks avatar numzskull avatar realdirt avatar ryuzaki-3301 avatar solastis avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar

hostsmod's Issues

Add new website

discordsteams.com is apparently a new IP grabbing one, I didn't see that it was on the list when I checked.
Screenshot_20211005-072045

Hosts file for archlinux users

Disclaimer:This maybe dont work on the following arch linux based distros: Garudalinux,Arcolinux,Manjaro
Please respect my work i made this url list with a gnu nano editor (very hard)
How to apply this?

  1. Copy the code i placed down to /etc/hosts folder/file
  2. Save it (You NEED sudo to do this)
  3. Restart your pc or broswer or log out and log back
  4. Done

Static table lookup for hostnames.

See hosts(5) for details.

127.0.0.1 mvncentral.net
127.0.0.1 vladvilcu2006.tech
127.0.0.1 verble.software
127.0.0.1 jonathanhardwick.me
127.0.0.1 etc.catering
127.0.0.1 tlrepo.cc
127.0.0.1 khonsarifamily.tech
127.0.0.1 batonrogue.tech
127.0.0.1 verbleisover.party
127.0.0.1 grabify.link
127.0.0.1 bmwforum.co
127.0.0.1 leancoding.co
127.0.0.1 spottyfly.com
127.0.0.1 stopify.co
127.0.0.1 yoütu.be
127.0.0.1 discörd.com
127.0.0.1 minecräft.com
127.0.0.1 freegiftcards.co
127.0.0.1 disçordapp.com
127.0.0.1 särahah.eu
127.0.0.1 särahah.pl
127.0.0.1 xda-developers.us
127.0.0.1 quickmessage.us
127.0.0.1 fortnight.space
127.0.0.1 fortnitechat.site
127.0.0.1 youshouldclick.us
127.0.0.1 joinmy.site
127.0.0.1 crabrave.pw
127.0.0.1 lovebird.guru
127.0.0.1 trulove.guru
127.0.0.1 dateing.club
127.0.0.1 otherhalf.life
127.0.0.1 shrekis.life
127.0.0.1 datasig.io
127.0.0.1 datauth.io
127.0.0.1 headshot.monster
127.0.0.1 gaming-at-my.best
127.0.0.1 progaming.monster
127.0.0.1 yourmy.monster
127.0.1.1 screenshare.host
127.0.1.1 imageshare.best
127.0.0.1 screenshot.best
127.0.0.1 gamingfun.me
127.0.0.1 catsnthing.com
127.0.0.1 mypic.icu
127.0.0.1 catsnthings.fun
127.0.0.1 curiouscat.club
127.0.0.1 gyazo.nl
127.0.0.1 gaymers.ax
127.0.0.1 ps3cfw.com
127.0.0.1 iplogger.org
127.0.0.1 steancomunnity.ru
127.0.0.1 streamcommunnlty.ru
127.0.0.1 streancommunuty.ru
127.0.0.1 streamconmunitlu.me
127.0.0.1 xn--yutube-iqc.com
127.0.0.1 yȯutube.com
127.0.0.1 streamconmunitlu.me
127.0.0.1 stearncomminuty.ru
127.0.0.1 steamcommunytu.ru
127.0.0.1 steamcommnuitry.com
127.0.0.1 stearncomunitu.ru
127.0.0.1 stearncormunsity.com
127.0.0.1 steamcommunytiu.ru
127.0.0.1 streammcomunnity.ru
127.0.0.1 steamcommunytiy.ru
127.0.0.1 stearncommunytiy.ru
127.0.0.1 strearncomuniity.ru.com
127.0.0.1 steamcomminytiu.ru
127.0.0.1 steamcconuunity.co
127.0.0.1 tournament-predator.xyz
127.0.1.1 steamcomminytiu.com
127.0.1.1 store-stempowered.com
127.0.1.1 stemcomnunity.ru.com
127.0.1.1 steamcommynitu.ru
127.0.1.1 discord-nitro.site
127.0.1.1 steamcommurnuity.com
127.0.1.1 dlscord.space
127.0.1.1 steamcomminutiu.ru
127.0.1.1 steamcommunrlity.com
127.0.1.1 steamcommytiny.com
127.0.1.1 steamcommunityu.ru
127.0.1.1 lemonchase.club
127.0.1.1 discod.art
127.0.1.1 steamgivenitro.com
127.0.1.1 xpro.gift
127.0.1.1 disscord-nitro.com
127.0.1.1 dirscod.com
127.0.1.1 dlscord.in
127.0.1.1 discorcl.link
127.0.1.1 steamcommunity.link
127.0.1.1 discorb.co
127.0.1.1 discord-nitro.su

``

need update

update highly needed
context
i got ratted by kant (lucas william breeden sr. roe)

and itpromised to block the rats
??? hello
fuck you

hosts

doesnt work, i ran it as an adminsitrator, doesnt work, my hosts file exists, idk what to do

must be removed

cant order delicious centi curry lentil salads with this.

Failed to block grabify

Recently I got ip logged and yes, I checked that I had run hostmod before, unfortunately it didn't really blocked grabify and my ip was vulnerable because of that. I remember it blocked grabify months ago, but what happened? Is it a bug? Did I accidentally turned on something? Thanks

Reverse Changes

In the next update can you make something that un-blacklists the blacklisted domains? Just in case someone wants to revert the changes.

How to remove kant + Make less "fear" when checking if infected

Hi, i'm body, recently i got infected by kant/eviate rat a new version that is somehow good?

So, how to remove it ?

You will need a usb key and if you want to save your data, you will need an external usb drive

-> Reset your router
-> Get another pc that isn't infected
-> Use windows media creation tool to create a bootable usb
-> Reset your pc with that usb key

If you have saved your data
-> Delete all exe files, they may have been infected, we don't know.

Once you are back on windows, run HostsMod for never getting ratted again.
I hope for you that everything went well

If you want to know if you are infected ?
Run netstat, if you see mvncentral.net a bunch of times you are infected. Myself being infected and mvncentral.net blocked, i thought i was protected but nah. This doesn't actually stops if you are already infected but prevents to be infected.

To see if you are infected you can also download process hacker and go in network tab, search for anything where remote address is mvncentral.net.

If you see like svchost in local address the well know domain mvncentral.net It's because, in your hosts file the domain mvncentral.net is the first one, it redirect that domain to localhost. This means that process hacker will replace 127.0.0.1 to mvncentral.net in the network tab.

So my suggestion, add as blocked domain BEFORE mvncentral.net : 127.0.0.1, localhost get redirected to localhost which is the same so nothing will happen except that it process hacker it will show that.

Cheers, body, hope u got some reading xd

Quick question

Is it safe to use autumn crack by kant now? (I have downloaded and ran HostsMod with admin)

im about to uninstall this

as ive said i cant order salads with this
i will uninstall this
say bye bye to your trustpilot reviews

Still not working?

Everything seems normal with the hosts file after modification, however after running netstat i still have multiple connections from mvncentral.net on my computer.

Btw, a factory reset did nothing.

Please help because i dont want to be doxxed. I already ran a scan with malwarebytes, windows defender and adwcleaner.

I'm sorry for spamming the issues, but this really is an issue.

im legit starving

i cannot order my salads due to this
i'm on the verge of death by starvation
please help

Helpfull domains to blacklist.

Hey, I recently watched some videos about using custom DNS to block adware and phishing scams take a look at this blacklisted addresses and I would appreciate if u add it to host-mode as it can improve by a tone. Sorry for writing this as an issue but I don't know if there is any contact with developers other then github if there is discord server or something make sure to drop me a reply.

Blacklisted domains : https://obutterbach.medium.com/unlock-the-full-potential-of-pihole-e795342e0e36 (scroll down)

Do we need to clear .m2 maven folder?

I was looking through the code and noticed it blocks a fake maven repo. And I was thinking, I use maven for my projects and I was ratted. So would that mean that I have to clear maven's .m2 folder? And if it required you should make the program auto wipe it

having an issue

When I run the exe it says "unable to access hosts file" and I have firewall and everything off, I also run it as administrator.

Black list bigrat.monster

Got ratted by a new version of Kant rat… it injects code into .exe and it’s not even dynamic ! It inject static code. Here’s netstat
AED5A0A1-1011-4111-AA5C-D5694CF32E97

Suggestion

You should really add these two domains, yȯutube.com and xn--yutube-iqc.com
These are owned by https://webresolver.nl/tools/iplogger and the youtube one can appear hidden on applications like Teamspeak so can be quite harmful.

Issue with blocking websites.

After running hostsmod, I visit a malicious link, and it doesn't get blocked.
Does this only take effect after a reboot?

Also, do you know where the location of the RAT is from mvncentral.net? I downloaded the Remix "crack" and I need to remove it rq.

PLEASE TAKE DOWN

THIS REPO STOPS MY SON FROM GAINING MONEY PLEASE CEASE AND DESIST IMMEDATE

not working

i tried to open this but it didnt work.
Unable to access hosts file! Try running as Administrator.
i tried to open it without admin and with admin and it didnt work

add steancommunity.ru

people have been getting token logged on discord due to spam bots dming this link telling you it gives you "csgo skins" and what not. The token logged people then dm others and it's insane how many people are falling for this.

guys

why gaymers.ax domain isnt blocked here

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.