# Copyright (c) 2014-2020 Maltrail developers (https://github.com/stamparm/maltrail/)
# See the file 'LICENSE' for copying permission

# Aliases: apt27, apt-c-27, goblin panda, emissary panda, cycldek

# Reference: https://medium.com/@Sebdraven/gobelin-panda-against-the-bears-1f462d00e3a4

36106g.com
cv3sa.gicp.net
kmbk8.hicp.net
sd123.eicp.net

# Reference: https://medium.com/@Sebdraven/malicious-document-targets-vietnamese-officials-acb3b9d8b80a

dn.dulichbiendao.org
gateway.vietbaotinmoi.com
web.thoitietvietnam.org
hn.dulichbiendao.org
halong.dulichculao.com
cat.toonganuh.com
new.sggpnews.com
dulichculao.com
wouderfulu.impresstravel.ga
toonganuh.com
coco.sodexoa.com

# Reference: https://medium.com/@Sebdraven/goblin-panda-changes-the-dropper-and-reused-the-old-infrastructure-a35915f3e37a

skylineqaz.crabdance.com
tele.zyns.com
tajikstantravel.dynamic-dns.net
uzwatersource.dynamic-dns.net

# Reference: https://medium.com/@Sebdraven/goblin-panda-continues-to-target-vietnam-bc2f0f56dcd6
# Reference: https://otx.alienvault.com/pulse/5ccabe9589bea41847a35a0f

web.hcmuafgh.com

# Reference: https://blogs.quickheal.com/apt-27-like-newcore-rat-virut-exploiting-mysql-targeted-attacks-enterprise/

115.214.104.26:81
http://192.167.4.10
http://43.242.75.228
aibeichen.cn

# Reference: https://unit42.paloaltonetworks.com/emissary-panda-attacks-middle-east-government-sharepoint-servers/

185.12.45.134:443

# Reference: https://twitter.com/MeltX0R/status/1175309376493629440
# Reference: https://meltx0r.github.io/tech/2019/09/19/emissary-panda-apt.html

awvsf7esh.dellrescue.com
language.wikaba.com
solution.instanthq.com
yofeopxuuehixwmj.redhatupdater.com

# Reference: https://otx.alienvault.com/pulse/5da9dc215c51c8a86a2d19f1

chatsecure.uk.to
chatsecurelite.uk.to
chatsecurelite.us.to
encryptit.qc.to
privatehd.us.to
sex17.us.to

# Reference: https://marcoramilli.com/2020/03/19/is-apt27-abusing-covid-19-to-attack-people/
# Reference: https://otx.alienvault.com/pulse/5e734d45158714422bc4e774

motivation.neighboring.site

# Reference: https://twitter.com/_marklech_/status/1268138088167018498
# Reference: https://securelist.com/cycldek-bridging-the-air-gap/97157/

http://103.253.25.73
24h.tinthethaoi.com
cdn.laokpl.com
cophieu.dcsvnqvmn.com
hanghoa.trenduang.com
hcm.vietbaonam.com
images.webprogobest.com
info.coreders.com
khinhte.chinhsech.com
kinhte.chototem.com
lat.conglyan.com
login.dangquanwatch.com
login.diendanlichsu.com
login.giaoxuchuson.com
login.thanhnienthegioi.com
login.vietnamfar.com
luan.conglyan.com
mychau.dongnain.com
news.cooodkord.com
news.trungtamwtoa.com
nghiencuu.onetotechnologys.com
nhantai.xmeyeugh.com
quocphong.ministop14.com
thanhnien.vietnannnet.com
thegioi.kinhtevanhoa.com
thoitiet.yrindovn.com
tinmoi.thoitietdulich.com
tinmoi.vieclamthemde.com
tintuc.daikynguyen21.com
toiyeuvn.dongaruou.com
web.hcmuafgh.com
web.laomoodwin.com
web.laovoanew.com
tinthethaoi.com
laokpl.com
dcsvnqvmn.com
trenduang.com
vietbaonam.com
webprogobest.com
coreders.com
chinhsech.com
chototem.com
laovoanew.com
conglyan.com
dangquanwatch.com
diendanlichsu.com
giaoxuchuson.com
thanhnienthegioi.com
vietnamfar.com
conglyan.com
dongnain.com
cooodkord.com
trungtamwtoa.com
onetotechnologys.com
xmeyeugh.com
ministop14.com
vietnannnet.com
kinhtevanhoa.com
yrindovn.com
thoitietdulich.com
vieclamthemde.com
daikynguyen21.com
dongaruou.com
hcmuafgh.com
laomoodwin.com
laovoanew.com
