# Copyright (c) 2014-2019 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission

# Reference: https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html

boeing.servehttp.com
alsalam.ddns.net
ngaaksa.ddns.net
ngaaksa.sytes.net
vinnellarabia.myftp.org
managehelpdesk.com
microsoftupdated.com
osupd.com
mywinnetwork.ddns.net
chromup.com
securityupdated.com
googlmail.net
microsoftupdated.net
syn.broadcaster.rocks
googlmail.net

# Reference: https://twitter.com/ClearskySec/status/1059532789572386817
# Reference: https://twitter.com/ClearskySec/status/1059532946045050883

aramcojobs.ddns.net
dyn-corp.ddns.net
dyncorp.ddns.net
mynetwork.ddns.net
mynetwork2.ddns.net
ngaaksa.ga
sabic-co.ddns.net
saharapcc.ddns.net
sipchem.ddns.net
/aramco/

# Reference: https://twitter.com/ClearskySec/status/1142749950998171648
# Reference: https://app.any.run/tasks/c761d00f-4897-4c9e-8468-9172fcce21d7/

backupaccount.net
becomestateman.com
inboxsync.org
whiteelection.com

# Reference: https://go.recordedfuture.com/hubfs/reports/cta-2019-0626.pdf
# Reference: https://otx.alienvault.com/pulse/5d13cf4759eec0125b9d8ffa

microsoftupdated.com
mynetwork.cf
securityupdated.com
service-avant.com
svcexplores.com
update-sec.com
backupnet.ddns.net
bistbotsproxies.ddns.net
fucksaudi.ddns.net
googlechromehost.ddns.net
hellocookies.ddns.net
hyperservice.ddns.net
mynetwork.ddns.net
mypsh.ddns.net
mywinnetwork.ddns.net
n3tc4t.hopto.com
newhost.hopto.org
njrat12.ddns.net
remote-server.ddns.net
remserver.ddns.net
servhost.hopto.org
srvhost.servehttp.com
teamnj.ddns.net
trojan1117.hopto.org
windowsx.sytes.net
wwwgooglecom.sytes.net
xtreme.hopto.org
younesadams.ddns.net
za158155.ddns.net
