# Bulletproof Host Gerber EDV Tied to Adwind Botnets

Published: 2018-04-09 · Severity: medium
Canonical: https://vorant.io/reports/7b722745-d413-5702-8d87-59e26deeb373/bulletproof-host-gerber-edv-tied-to-adwind-botnets

> Researcher traces thousands of Adwind/Qrypter RAT C2 servers to a fake Swiss company, Gerber EDV-Dienstleistungen, sharing infrastructure with the AnMaXX bulletproof hosting network.

Abuse.ch researchers tracked nearly 10,000 Adwind (jRAT/JSocket) samples calling back to over 2,800 distinct C&C servers over a six-month period, with most tied to the Qrypter Malware-as-a-Service platform hosted on Tor. Investigation into the hosting infrastructure led to two networks, Gerber EDV-Dienstleistungen (gerber-edv.net) and AnMaXX (anmaxx.net), which share the same IP address and mail server, along with a third domain, rivavpn.com. Both networks advertise themselves as "non-logging VPN" services in RIPE records but have no functioning website.

A physical visit to Gerber's registered Bern office address found no such company present, and no matching entity exists in Switzerland's official business registry, confirming the registration details are fabricated. The analyst concludes Gerber EDV and AnMaXX are operated by the same actors and exist solely to provide bulletproof hosting for Adwind/Qrypter as well as other RAT families including NanoCore and RemcosRAT. RIPE was notified of the fraudulent registration data, though the organization does not verify submitted WHOIS information, allowing such abuse to persist.

The report includes an extensive list of IP netranges tied to Gerber EDV, AnMaXX, and rivavpn.com, plus additional netranges from other providers (including Swiftway, Host1Plus, GigeNET, and others) observed hosting large volumes of Adwind C2 infrastructure, recommending network defenders block these ranges at the perimeter.

## Mentioned in this report

- Threat actors: Gerber EDV-Dienstleistungen
- Malware: AdWind, NanoCore, Qrypter, RemcosRAT

Source reporting: https://abuse.ch/blog/anmaxx-gerber-edv-and-the-qrypter-connection

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7b722745-d413-5702-8d87-59e26deeb373/bulletproof-host-gerber-edv-tied-to-adwind-botnets.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
