# Copyright (c) 2014-2018 Miroslav Stampar (@stamparm)
# See the file 'LICENSE' for copying permission

# Reference: https://www.fireeye.com/blog/threat-research/2017/05/cyber-espionage-apt32.html

24.datatimes.org
blog.docksugs.org
blog.panggin.org
contay.deaftone.com
check.paidprefund.org
datatimes.org
docksugs.org
economy.bloghop.org
emp.gapte.name
facebook-cdn.net
gap-facebook.com
gl-appspot.org
help.checkonl.org
high.expbas.net
high.vphelp.net
icon.torrentart.com
images.chinabytes.info
imaps.qki6.com
img.fanspeed.net
job.supperpow.com
lighpress.info
menmin.strezf.com
mobile.pagmobiles.info
news.lighpress.info
notificeva.com
nsquery.net
pagmobiles.info
paidprefund.org
push.relasign.org
relasign.org
share.codehao.net
seri.volveri.net
ssl.zin0.com
static.jg7.org
syn.timeizu.net
teriava.com
timeizu.net
tonholding.com
tulationeva.com
untitled.po9z.com
update-flashs.com
vieweva.com
volveri.net
vphelp.net
yii.yiihao126.net
zone.apize.net

# Reference: https://github.com/eset/malware-ioc/tree/master/oceanlotus

adineohler.com
aisicoin.com
alicervois.com
anessallie.com
antenham.com
arinaurna.com
arkoimmerma.com
aulolloy.com
avidilleneu.com
avidsontre.com
aximilian.com
biasatts.com
braydenhateaub.com
carosseda.com
chascloud.com
dreyoddu.com
dwarduong.com
eckenbaue.com
eighrimeau.com
errellawle.com
erstin.com
frahreiner.com
hieryells.com
hristophe.com
ichardt.com
icmannaws.com
iecopeland.com
irkaimboeuf.com
jamedalue.com
jamyer.com
jeanessbinder.com
jeffreyue.com
keoucha.com
laudiaouc.com
lbertussbau.com
loridanase.com
marrmann.com
meroque.com
moureuxacv.com
myolton.com
nasahlaes.com
ntjeilliams.com
omasicase.com
onnaha.com
onteagle.com
orinneamoure.com
orresto.com
orrislark.com
rackerasr.com
rcuselynac.com
sanauer.com
stopherau.com
tefanie.com
tefanortin.com
tephens.com
traveroyce.com
tsworthoa.com
ucaargo.com
ucairtz.com
urnage.com
venionne.com
virginiaar.com

# Reference: https://www.cybereason.com/blog/operation-cobalt-kitty-apt

food.letsmiles.org

# Reference: https://ti.360.net/blog/articles/oceanlotus-targets-chinese-university/

cctv.avidsonec.com
cert.opennetworklab.com
cloud.reneark.com
cloud.sicaogler.com
cnn.befmann.com
dieordaunt.com
dyndns.angusie.com
fox.ailloux.com
hotel.bookingshop.info
ipv6.uyllain.com
isp.cambodiadaily.org
login.ticketwitheasy.com
myaccount.philtimes.org
news.coleope.com
news.denekasd.com
news.exandre.com
ns1.cambodiadaily.org
ourkekwiciver.com
school.obertamy.com
straliaenollma.xyz
time.ouisers.com

# Reference: https://www.fireeye.com/blog/threat-research/2017/06/phished-at-the-request-of-counsel.html (Network Based Indicators (NBI))

http://104.236.77.169
http://138.68.45.9
http://162.243.143.145
autodiscover.2bunny.com
lyncdiscover.2bunny.com
tk-in-f156.2bunny.com
sfo02s01-in-f2.cloudsend.net

# Reference: https://blog.trendmicro.com/trendlabs-security-intelligence/new-macos-backdoor-linked-to-oceanlotus-found/
# Reference: https://www.virustotal.com/#/file/673ee7a57ba3c5a2384aeb17a66058e59f0a4d0cddc4f01fe32f369f6a845c8f/relations

ssl.arkouthrie.com
s3.hiahornber.com
widget.shoreoa.com

