There are several techniques Umbrella uses to detect and block malicious activity associated with
OceanLotus. First, Umbrella’s DNS tunneling capability instantly detects and blocks DNS abuse
attempts in real-time. Additionally, Umbrella’s Fast Flux classifier is able to proactively discover
Fast Flux infrastructure and block any attempts for command and control callbacks.
Umbrella also blocks domains that are tied to malicious files and IP addresses associated with
OceanLotus IOCs. Umbrella uses AV engines and Cisco Advanced Malware Protection (AMP) to block malicious
files before they are downloaded; AMP detects OceanLotus APT malware as Trojan.Win32.OCEANLOTUS.THABOEAH
and Umbrella proactively blocks the threat.
robstustral.club, adineohler.com, aisicoin.com, alicervois.com, anessallie.com, antenham.com,
arinaurna.com, arkoimmerma.com, aulolloy.com, avidilleneu.com, avidsontre.com, aximilian.com,
biasatts.com, braydenhateaub.com carosseda.com, chascloud.com, dreyoddu.com, dwarduong.com, eckenbaue.com,
eighrimeau.com, errellawle.com, erstin.com, frahreiner.com, hieryells.com, hristophe.com, ichardt.com,
icmannaws.com, iecopeland.com, irkaimboeuf.com, jamedalue.com, jamyer.com, jeanessbinder.com,
jeffreyue.com, keoucha.com, laudiaouc.com, lbertussbau.com, loridanase.com, marrmann.com, meroque.com,
moureuxacv.com, myolton.com, nasahlaes.com, ntjeilliams.com, omasicase.com, onnaha.com, onteagle.com,
orinneamoure.com, orresto.com, orrislark.com, rackerasr.com, rcuselynac.com, sanauer.com, stopherau.com,
tefanie.com, tefanortin.com, tephens.com, traveroyce.com, tsworthoa.com, ucaargo.com, ucairtz.com,
urnage.com, venionne.com, virginiaar.com
Fast Flux Botnet IPs
185.247.21.208, 185.247.8.229, 185.247.79.64, 185.247.31.177, 185.247.118.188, 185.247.89.24,
185.247.65.205, 185.247.8.161, 185.247.67.4, 185.247.82.144, 185.247.62.119, 185.247.3.101,
185.247.118.194, 185.247.26.77, 185.247.20.136