{
  "type": "Domain",
  "indicator": "789ab.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/789ab.com",
    "alexa": "http://www.alexa.com/siteinfo/789ab.com",
    "indicator": "789ab.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3909004760,
      "indicator": "789ab.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "69f81318a2109f370618aef6",
          "name": "I feel like im dying, actually.",
          "description": "Havana symtoms. Documenting. In case. \"pet remains\" from dead dogs vet receipt. Wow.",
          "modified": "2026-05-05T12:47:44.795000",
          "created": "2026-05-04T03:31:36.579000",
          "tags": [
            "ransom",
            "urls",
            "domain",
            "as714",
            "smtpimap pool",
            "node",
            "highvolume mail",
            "relay",
            "trust failure",
            "tier1 upstreams",
            "general",
            "virustotal",
            "win32 exe",
            "manager",
            "adobe service",
            "zzmzlowckofr",
            "uxpoezwoazc",
            "cvjlfb",
            "bgxmqneqfnf",
            "afjhivfgx",
            "adobe updater",
            "configurator",
            "service",
            "launcher",
            "launch",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "os2 executable",
            "pe32 compiler",
            "exe32",
            "compiler",
            "pe32 executable",
            "ms visual"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1132,
            "FileHash-SHA1": 32,
            "IPv4": 1161,
            "domain": 11,
            "hostname": 58,
            "URL": 80,
            "CIDR": 1,
            "CVE": 1,
            "FileHash-MD5": 140
          },
          "indicator_count": 2616,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f8131990bf85d55cd999b0",
          "name": "I feel like im dying, actually.",
          "description": "Havana symtoms. Documenting. In case. \"pet remains\" from dead dogs vet receipt. Wow.",
          "modified": "2026-05-05T12:47:42.104000",
          "created": "2026-05-04T03:31:37.660000",
          "tags": [
            "ransom",
            "urls",
            "domain",
            "as714",
            "smtpimap pool",
            "node",
            "highvolume mail",
            "relay",
            "trust failure",
            "tier1 upstreams",
            "general",
            "virustotal",
            "win32 exe",
            "manager",
            "adobe service",
            "zzmzlowckofr",
            "uxpoezwoazc",
            "cvjlfb",
            "bgxmqneqfnf",
            "afjhivfgx",
            "adobe updater",
            "configurator",
            "service",
            "launcher",
            "launch",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "os2 executable",
            "pe32 compiler",
            "exe32",
            "compiler",
            "pe32 executable",
            "ms visual"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 230,
            "FileHash-SHA1": 10,
            "IPv4": 23,
            "domain": 9,
            "hostname": 38,
            "URL": 74,
            "CIDR": 1,
            "CVE": 1,
            "FileHash-MD5": 91
          },
          "indicator_count": 477,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "689aeb712617e30672cbb8ac",
          "name": "Botnet Sinkhole Domains |  Ramnit | Project Endgame",
          "description": "Redirects traffic to controlled servers.[iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com] Botnet Sinkhole\n[ns768.com]\tBotnet Sinkhole\n[fkbpvfnbhfwedagussg.com] Botnet Sinkhole\n[w5q7spejg96n.com] Botnet Sinkhole\n[enyeikruptiukjorq.com] Botnet Sinkhole\n#Project_Endgame #botnet_sinkhole #redirect #trojan #malware #worm #dns #traffic #ramnit #monitored_target",
          "modified": "2025-09-11T07:00:20.186000",
          "created": "2025-08-12T07:21:21.080000",
          "tags": [
            "botnet sinkhole",
            "process32nextw",
            "high",
            "memcommit",
            "medium",
            "stops windows",
            "attempts",
            "t1055",
            "pglv68s",
            "searches",
            "locally unique",
            "url http",
            "url https",
            "iocs",
            "enter source",
            "url or",
            "text drag",
            "drop or",
            "browse to",
            "select file",
            "or drop",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "spawns",
            "ssl certificate",
            "execution att",
            "development att",
            "united",
            "date",
            "flag",
            "name server",
            "markmonitor",
            "namecheap inc",
            "organization",
            "whoisguard",
            "server",
            "domain address"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 35,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 59,
            "FileHash-SHA256": 451,
            "URL": 433,
            "hostname": 154,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "CVE": 1
          },
          "indicator_count": 1100,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "262 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "689ae28d66814f3c2cbf1791",
          "name": "Botnet Sinkhole | Potential WannaCry DNS Lookup",
          "description": "*iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com Botnet Sinkhole | Potential WannaCry DNSLookup. Targeting , Project Content Reputation. Backdoor:Win32/Fynloski \u2022\nWas [Win.Trojan.DarkKomet-1] now- [Worm:Win32/Mofksys.R!MTB] \u2022\nPotential WannaCry DNS lookup\nIllegal Content 20 + teen p0r\u0146 content sites for reputation abuse and or framing.\n| highjacked? URL\nhttps://archive.org/web/petabox.php |\n| cdn1.onlyteenporn.com |\n| http://onlyteenporn.com/go.php.php?link=top |\n| http://onlyteenporn.com/go.php?link= |\n\n#botnet #sinkhole #worm #trojan #injection #socialengineering  #wannacry #dns #teen_porn #content_reputation #dumpsite #petabox #webarchive #photography",
          "modified": "2025-09-11T05:01:39.966000",
          "created": "2025-08-12T06:43:25.992000",
          "tags": [
            "show process",
            "united",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "ck id",
            "show technique",
            "ck matrix",
            "programfiles",
            "sha1",
            "date",
            "comspec",
            "class",
            "august",
            "hybrid",
            "general",
            "path",
            "model",
            "click",
            "strings",
            "meta",
            "body",
            "present jun",
            "present aug",
            "present may",
            "present apr",
            "present feb",
            "creation date",
            "worm",
            "search",
            "present jul",
            "error",
            "msil",
            "passive dns",
            "urls",
            "url add",
            "pulse pulses",
            "http",
            "hostname",
            "files domain",
            "files related",
            "pulses none",
            "related tags",
            "unknown ns",
            "ip address",
            "name servers",
            "status",
            "showing",
            "found title",
            "open ports",
            "backdoor",
            "hacktool",
            "entries",
            "next associated",
            "ipv4",
            "trojan",
            "domain",
            "authority",
            "record value",
            "script script",
            "cname",
            "script urls",
            "learn",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "spawns",
            "ssl certificate",
            "execution att",
            "present mar",
            "mtb sep",
            "ransom",
            "win32",
            "gmt contenttype",
            "ipv4 add",
            "files",
            "location united",
            "development att",
            "extra data",
            "extraction",
            "please",
            "sc data",
            "type",
            "failed",
            "extr data",
            "ox sunnort",
            "include review",
            "exclude data",
            "sugges",
            "process32nextw",
            "observed dns",
            "query",
            "read c",
            "medium",
            "dns lookup",
            "msdos",
            "wannacry dns",
            "lookup",
            "wannacry",
            "delphi",
            "malware",
            "copy",
            "service",
            "explorer",
            "write",
            "darkcomet",
            "ping",
            "tools",
            "capture",
            "next"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1054",
              "name": "Indicator Blocking",
              "display_name": "T1054 - Indicator Blocking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1089",
              "name": "Disabling Security Tools",
              "display_name": "T1089 - Disabling Security Tools"
            },
            {
              "id": "T1158",
              "name": "Hidden Files and Directories",
              "display_name": "T1158 - Hidden Files and Directories"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 145,
            "FileHash-SHA1": 138,
            "FileHash-SHA256": 398,
            "SSLCertFingerprint": 12,
            "URL": 876,
            "domain": 136,
            "hostname": 216,
            "email": 3,
            "CVE": 1
          },
          "indicator_count": 1925,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "262 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66bbf5ef43b695838a17661c",
          "name": "Unsupported Browser - WordPress.com | Injection - Brian Sabey Hall Render",
          "description": "Malicious attack from hacker claiming to be an attorney. Every device, network, and others impacted. Illegal attack. Invasion of privacy vs investigation. Target is using all zombie devices. \u00c0 malevolent army of hackers injecting everything and everyone related to assault victim. Retaliation, malice, obsession all indicitive of danger from  ever present adversaries. \n'' ALF:Backdoor:MSIL/Noancooe\nALF:Trojan:MSIL/AgentTesla.KM\nALF:Win32/GbdInf_CFF3548C.J!ibt\nBackdoor:Win32/Fynloski\nET\nETERNALBLUE? Federal \nExploit:Win32/CVE-2017-0147\nRansom:Win32/WannaCrypt.H\nTrojan:Linux/Dakkatoni\nTrojan:Win32/ClipBanker\nWin32:PWSX-gen\\ [Trj]\nWorm:Win32/Mofksys",
          "modified": "2024-10-12T19:02:41.872000",
          "created": "2024-08-14T00:10:22.703000",
          "tags": [
            "referrer",
            "vt report",
            "project skynet",
            "cyber army",
            "goog mal",
            "android windows",
            "maze",
            "startpage",
            "regsz",
            "english",
            "t1082",
            "adobe air",
            "standard",
            "java",
            "high",
            "discovery",
            "yara detections",
            "updater",
            "install",
            "et trojan",
            "et exploit",
            "request",
            "probe ms17010",
            "yara rule",
            "ransom",
            "kryptos logic",
            "html response",
            "wannacry",
            "logic",
            "related pulses",
            "files matching",
            "search",
            "hitmen",
            "unknown",
            "nxdomain",
            "creation date",
            "mtb sep",
            "backdoor",
            "worm",
            "msil",
            "all scoreblue",
            "file samples",
            "win32",
            "copyright",
            "levelblue",
            "dashboard",
            "browse scan",
            "next",
            "exploit",
            "as16276",
            "canada unknown",
            "passive dns",
            "historical ssl",
            "levelblue labs",
            "otx telemetry",
            "name servers",
            "google safe",
            "browsing",
            "brian sabey",
            "thebrotherssabey",
            "murderer",
            "hackers",
            "united states",
            "lazarus",
            "united",
            "msie",
            "chrome",
            "body",
            "gmt content",
            "scan endpoints",
            "domain",
            "ipv4",
            "files",
            "asn as13335",
            "dns resolutions",
            "browser",
            "purtroppo",
            "visualizza",
            "carica la",
            "javascript",
            "unsupported",
            "view",
            "dead",
            "fakedout threat",
            "analyzer paste",
            "iocs",
            "tofsee",
            "status",
            "as47846",
            "germany unknown",
            "as44273 host",
            "as12876 online",
            "tsara brashears",
            "memcommit",
            "show",
            "read c",
            "entries",
            "icmp traffic",
            "medium",
            "memreserve",
            "packing t1045",
            "write",
            "malware",
            "urls",
            "emails",
            "servers",
            "showing",
            "date",
            "findwindowa",
            "regopenkeyexw",
            "checks",
            "redline stealer",
            "whitelisted",
            "as23393",
            "aaaa",
            "aaaa nxdomain",
            "as40676 psychz",
            "as53667",
            "as3842 inmotion",
            "pulse pulses",
            "domains top",
            "hong kong",
            "moved",
            "trojan",
            "trojan features",
            "date hash",
            "cname",
            "as50069 misaka",
            "as3214 xtom",
            "virgin islands",
            "antigua",
            "org domains",
            "proxy",
            "code",
            "alf features"
          ],
          "references": [
            "*http://hghltd.yandex.net/yandbtm?fmode=inject&url=http://siteinlink.d1.cnbd.net/search/tsara-brashears-assaulted-by-jeffrey-reimer/",
            "botnetsinkhole@gmail.com",
            "Adware ALF:Win32/GbdInf_CFF3548C.J!ibt:  FileHash-SHA256 459a0c8088f9c7455f12b90a809322e307553ee1b335299a705a400538144182",
            "Antivirus Detections ALF:Win32/GbdInf_CFF3548C.J!ibt",
            "IDS Detections: Lavasoft PUA/Adware Client Install",
            "Yara Detections research_pe_signed_outside_timestamp ,  _7_Zip_Installer",
            "Alerts: network_icmp antiav_detectreg antisandbox_idletime recon_programs ransomware_file_moves ransomware_appends_extensions",
            "Alerts: injection_resumethread dumped_buffer network_cnc_http network_http network_http_post allocates_rwx",
            "Alerts: creates_exe dropper exe_appdata has_wmi injection_process_search protection_rx antivm_network_adapters privilege_luid_check",
            "Ransom:Win32/WannaCrypt.H: FileHash-SHA256 f361351a71dfa356f67d501cf3990bfab3b5b66d48afee659bfa7c6e40e7fe79",
            "Antivirus Detections Win.Ransomware.Wanna-9769986-0 ,  Ransom:Win32/WannaCrypt.H",
            "IDS Detections: Possible WannaCry DNS Lookup 1 W32/WannaCry.Ransomware Killswitch Domain HTTP Request 1",
            "IDS Detections: Domain Sinkholed by Kryptos Logic (HTML Response) Known Sinkhole Response Kryptos Logic",
            "IDS Detections: Possible ETERNALBLUE Probe MS17-010 (MSF style) Possible ETERNALBLUE Probe MS17-010 (Generic Flags)",
            "IDS Detections: ETERNALBLUE Probe Vulnerable System Response MS17-010 Possible ETERNALBLUE MS17-010 Heap Spray",
            "IDS Detections: Observed DNS Query to Suspicious Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com)",
            "IDS Detections: Behavioral Unusual Port 445 traffic Potential Scan or Infection",
            "Yara Detections: WannaCry_Ransomware ,  Win32_Ransomware_WannaCry ,  stack_string ,  MS17_010_WanaCry_worm ,  MS_Visual_Cpp_6_0",
            "Alerts: procmem_yara persistence_autorun persistence_autorun_tasks stealth_file spawns_dev_util cape_detected_threat suricata_alert",
            "Alerts: antisandbox_sleep dead_connect dynamic_function_loading http_request https_urls powershell_download powershell_request",
            "Alerts: stealth_window network_multiple_direct_ip_connections network_cnc_http network_http antidebug_setunhandledexceptionfilter antivm_network_adapters",
            "1510 IP\u2019s Contacted!! 53.45.82.160 117.149.89.86 71.8.199.125 196.247.232.166 125.124.203.12 | Wow! Get her. Rage against the assaulted. 0 Testosterone]",
            "1510 IP\u2019s Contacted!! 105.186.124.102 194.249.100.247 6.192.197.229 174.145.199.195 7.249.17.5   Okay.",
            "HTTP Scans - comment 'sinkhole.tech where the bots party hard and the researchers harder.h6'",
            "Researched existing pulse: https://thebrotherssabey.wordpress.com/wp-admin/customize.php?url=https://thebrotherssabey.wordpress.com/",
            "zoopussy.com roar, grrrr, hiss",
            "Antivirus Detections Win32:PWSX-gen\\ [Trj]",
            "IDS Detections: External IP Address Lookup DNS Query (api .ip .sb) Observed External IP Lookup Domain (api.ip .sb in TLS SNI)",
            "IDS Detections: ETPRO TROJAN Redline Stealer TCP CnC - CheckConnect ETPRO TROJAN Redline Stealer TCP CnC - EnvironmentSettings",
            "High Priority Alerts: network_icmp nolookup_communication  antisandbox_idletime antivm_vmware_in_instruction",
            "High Priority Alerts: antivm_generic_bios infostealer_ftp recon_programs antivm_firmware antidbg_windows"
          ],
          "public": 1,
          "adversary": "Lazarus Group",
          "targeted_countries": [
            "Netherlands",
            "United States of America",
            "Hong Kong"
          ],
          "malware_families": [
            {
              "id": "ALF:Win32/GbdInf_CFF3548C.J!ibt",
              "display_name": "ALF:Win32/GbdInf_CFF3548C.J!ibt",
              "target": "/malware/ALF:Win32/GbdInf_CFF3548C.J!ibt"
            },
            {
              "id": "Ransom:Win32/WannaCrypt.H",
              "display_name": "Ransom:Win32/WannaCrypt.H",
              "target": "/malware/Ransom:Win32/WannaCrypt.H"
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "ETERNALBLUE",
              "display_name": "ETERNALBLUE",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Fynloski",
              "display_name": "Backdoor:Win32/Fynloski",
              "target": "/malware/Backdoor:Win32/Fynloski"
            },
            {
              "id": "Worm:Win32/Mofksys",
              "display_name": "Worm:Win32/Mofksys",
              "target": "/malware/Worm:Win32/Mofksys"
            },
            {
              "id": "Exploit:Win32/CVE-2017-0147",
              "display_name": "Exploit:Win32/CVE-2017-0147",
              "target": "/malware/Exploit:Win32/CVE-2017-0147"
            },
            {
              "id": "ALF:Trojan:MSIL/AgentTesla.KM",
              "display_name": "ALF:Trojan:MSIL/AgentTesla.KM",
              "target": null
            },
            {
              "id": "Win32:PWSX-gen\\ [Trj]",
              "display_name": "Win32:PWSX-gen\\ [Trj]",
              "target": null
            },
            {
              "id": "Trojan:Win32/ClipBanker",
              "display_name": "Trojan:Win32/ClipBanker",
              "target": "/malware/Trojan:Win32/ClipBanker"
            },
            {
              "id": "ALF:Backdoor:MSIL/Noancooe",
              "display_name": "ALF:Backdoor:MSIL/Noancooe",
              "target": null
            },
            {
              "id": "Trojan:Linux/Dakkatoni",
              "display_name": "Trojan:Linux/Dakkatoni",
              "target": "/malware/Trojan:Linux/Dakkatoni"
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [
            "Telecommunications",
            "Technology",
            "Civilian Society"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 39,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2748,
            "FileHash-SHA1": 2485,
            "FileHash-SHA256": 6374,
            "hostname": 525,
            "URL": 146,
            "domain": 290,
            "email": 7,
            "CVE": 2
          },
          "indicator_count": 12577,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 232,
          "modified_text": "595 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "botnetsinkhole@gmail.com",
        "zoopussy.com roar, grrrr, hiss",
        "High Priority Alerts: antivm_generic_bios infostealer_ftp recon_programs antivm_firmware antidbg_windows",
        "Antivirus Detections Win32:PWSX-gen\\ [Trj]",
        "High Priority Alerts: network_icmp nolookup_communication  antisandbox_idletime antivm_vmware_in_instruction",
        "IDS Detections: Possible WannaCry DNS Lookup 1 W32/WannaCry.Ransomware Killswitch Domain HTTP Request 1",
        "Antivirus Detections ALF:Win32/GbdInf_CFF3548C.J!ibt",
        "Antivirus Detections Win.Ransomware.Wanna-9769986-0 ,  Ransom:Win32/WannaCrypt.H",
        "IDS Detections: ETERNALBLUE Probe Vulnerable System Response MS17-010 Possible ETERNALBLUE MS17-010 Heap Spray",
        "Adware ALF:Win32/GbdInf_CFF3548C.J!ibt:  FileHash-SHA256 459a0c8088f9c7455f12b90a809322e307553ee1b335299a705a400538144182",
        "1510 IP\u2019s Contacted!! 53.45.82.160 117.149.89.86 71.8.199.125 196.247.232.166 125.124.203.12 | Wow! Get her. Rage against the assaulted. 0 Testosterone]",
        "Yara Detections: WannaCry_Ransomware ,  Win32_Ransomware_WannaCry ,  stack_string ,  MS17_010_WanaCry_worm ,  MS_Visual_Cpp_6_0",
        "Alerts: antisandbox_sleep dead_connect dynamic_function_loading http_request https_urls powershell_download powershell_request",
        "Alerts: injection_resumethread dumped_buffer network_cnc_http network_http network_http_post allocates_rwx",
        "IDS Detections: Possible ETERNALBLUE Probe MS17-010 (MSF style) Possible ETERNALBLUE Probe MS17-010 (Generic Flags)",
        "Ransom:Win32/WannaCrypt.H: FileHash-SHA256 f361351a71dfa356f67d501cf3990bfab3b5b66d48afee659bfa7c6e40e7fe79",
        "IDS Detections: Lavasoft PUA/Adware Client Install",
        "Alerts: procmem_yara persistence_autorun persistence_autorun_tasks stealth_file spawns_dev_util cape_detected_threat suricata_alert",
        "*http://hghltd.yandex.net/yandbtm?fmode=inject&url=http://siteinlink.d1.cnbd.net/search/tsara-brashears-assaulted-by-jeffrey-reimer/",
        "Alerts: stealth_window network_multiple_direct_ip_connections network_cnc_http network_http antidebug_setunhandledexceptionfilter antivm_network_adapters",
        "Alerts: network_icmp antiav_detectreg antisandbox_idletime recon_programs ransomware_file_moves ransomware_appends_extensions",
        "Researched existing pulse: https://thebrotherssabey.wordpress.com/wp-admin/customize.php?url=https://thebrotherssabey.wordpress.com/",
        "IDS Detections: Domain Sinkholed by Kryptos Logic (HTML Response) Known Sinkhole Response Kryptos Logic",
        "Yara Detections research_pe_signed_outside_timestamp ,  _7_Zip_Installer",
        "IDS Detections: ETPRO TROJAN Redline Stealer TCP CnC - CheckConnect ETPRO TROJAN Redline Stealer TCP CnC - EnvironmentSettings",
        "1510 IP\u2019s Contacted!! 105.186.124.102 194.249.100.247 6.192.197.229 174.145.199.195 7.249.17.5   Okay.",
        "HTTP Scans - comment 'sinkhole.tech where the bots party hard and the researchers harder.h6'",
        "IDS Detections: Behavioral Unusual Port 445 traffic Potential Scan or Infection",
        "IDS Detections: External IP Address Lookup DNS Query (api .ip .sb) Observed External IP Lookup Domain (api.ip .sb in TLS SNI)",
        "Alerts: creates_exe dropper exe_appdata has_wmi injection_process_search protection_rx antivm_network_adapters privilege_luid_check",
        "IDS Detections: Observed DNS Query to Suspicious Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com)"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Lazarus Group"
          ],
          "malware_families": [
            "Et",
            "Ransom:win32/wannacrypt.h",
            "Backdoor:win32/fynloski",
            "Worm:win32/mofksys",
            "Exploit:win32/cve-2017-0147",
            "Alf:backdoor:msil/noancooe",
            "Trojan:linux/dakkatoni",
            "Trojan:win32/clipbanker",
            "Win32:pwsx-gen\\ [trj]",
            "Alf:win32/gbdinf_cff3548c.j!ibt",
            "Alf:trojan:msil/agenttesla.km",
            "Eternalblue"
          ],
          "industries": [
            "Technology",
            "Telecommunications",
            "Civilian society"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "69f81318a2109f370618aef6",
      "name": "I feel like im dying, actually.",
      "description": "Havana symtoms. Documenting. In case. \"pet remains\" from dead dogs vet receipt. Wow.",
      "modified": "2026-05-05T12:47:44.795000",
      "created": "2026-05-04T03:31:36.579000",
      "tags": [
        "ransom",
        "urls",
        "domain",
        "as714",
        "smtpimap pool",
        "node",
        "highvolume mail",
        "relay",
        "trust failure",
        "tier1 upstreams",
        "general",
        "virustotal",
        "win32 exe",
        "manager",
        "adobe service",
        "zzmzlowckofr",
        "uxpoezwoazc",
        "cvjlfb",
        "bgxmqneqfnf",
        "afjhivfgx",
        "adobe updater",
        "configurator",
        "service",
        "launcher",
        "launch",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "os2 executable",
        "pe32 compiler",
        "exe32",
        "compiler",
        "pe32 executable",
        "ms visual"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1132,
        "FileHash-SHA1": 32,
        "IPv4": 1161,
        "domain": 11,
        "hostname": 58,
        "URL": 80,
        "CIDR": 1,
        "CVE": 1,
        "FileHash-MD5": 140
      },
      "indicator_count": 2616,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f8131990bf85d55cd999b0",
      "name": "I feel like im dying, actually.",
      "description": "Havana symtoms. Documenting. In case. \"pet remains\" from dead dogs vet receipt. Wow.",
      "modified": "2026-05-05T12:47:42.104000",
      "created": "2026-05-04T03:31:37.660000",
      "tags": [
        "ransom",
        "urls",
        "domain",
        "as714",
        "smtpimap pool",
        "node",
        "highvolume mail",
        "relay",
        "trust failure",
        "tier1 upstreams",
        "general",
        "virustotal",
        "win32 exe",
        "manager",
        "adobe service",
        "zzmzlowckofr",
        "uxpoezwoazc",
        "cvjlfb",
        "bgxmqneqfnf",
        "afjhivfgx",
        "adobe updater",
        "configurator",
        "service",
        "launcher",
        "launch",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "os2 executable",
        "pe32 compiler",
        "exe32",
        "compiler",
        "pe32 executable",
        "ms visual"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 230,
        "FileHash-SHA1": 10,
        "IPv4": 23,
        "domain": 9,
        "hostname": 38,
        "URL": 74,
        "CIDR": 1,
        "CVE": 1,
        "FileHash-MD5": 91
      },
      "indicator_count": 477,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "689aeb712617e30672cbb8ac",
      "name": "Botnet Sinkhole Domains |  Ramnit | Project Endgame",
      "description": "Redirects traffic to controlled servers.[iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com] Botnet Sinkhole\n[ns768.com]\tBotnet Sinkhole\n[fkbpvfnbhfwedagussg.com] Botnet Sinkhole\n[w5q7spejg96n.com] Botnet Sinkhole\n[enyeikruptiukjorq.com] Botnet Sinkhole\n#Project_Endgame #botnet_sinkhole #redirect #trojan #malware #worm #dns #traffic #ramnit #monitored_target",
      "modified": "2025-09-11T07:00:20.186000",
      "created": "2025-08-12T07:21:21.080000",
      "tags": [
        "botnet sinkhole",
        "process32nextw",
        "high",
        "memcommit",
        "medium",
        "stops windows",
        "attempts",
        "t1055",
        "pglv68s",
        "searches",
        "locally unique",
        "url http",
        "url https",
        "iocs",
        "enter source",
        "url or",
        "text drag",
        "drop or",
        "browse to",
        "select file",
        "or drop",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "spawns",
        "ssl certificate",
        "execution att",
        "development att",
        "united",
        "date",
        "flag",
        "name server",
        "markmonitor",
        "namecheap inc",
        "organization",
        "whoisguard",
        "server",
        "domain address"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 35,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 59,
        "FileHash-SHA256": 451,
        "URL": 433,
        "hostname": 154,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "CVE": 1
      },
      "indicator_count": 1100,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "262 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "689ae28d66814f3c2cbf1791",
      "name": "Botnet Sinkhole | Potential WannaCry DNS Lookup",
      "description": "*iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com Botnet Sinkhole | Potential WannaCry DNSLookup. Targeting , Project Content Reputation. Backdoor:Win32/Fynloski \u2022\nWas [Win.Trojan.DarkKomet-1] now- [Worm:Win32/Mofksys.R!MTB] \u2022\nPotential WannaCry DNS lookup\nIllegal Content 20 + teen p0r\u0146 content sites for reputation abuse and or framing.\n| highjacked? URL\nhttps://archive.org/web/petabox.php |\n| cdn1.onlyteenporn.com |\n| http://onlyteenporn.com/go.php.php?link=top |\n| http://onlyteenporn.com/go.php?link= |\n\n#botnet #sinkhole #worm #trojan #injection #socialengineering  #wannacry #dns #teen_porn #content_reputation #dumpsite #petabox #webarchive #photography",
      "modified": "2025-09-11T05:01:39.966000",
      "created": "2025-08-12T06:43:25.992000",
      "tags": [
        "show process",
        "united",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "ck id",
        "show technique",
        "ck matrix",
        "programfiles",
        "sha1",
        "date",
        "comspec",
        "class",
        "august",
        "hybrid",
        "general",
        "path",
        "model",
        "click",
        "strings",
        "meta",
        "body",
        "present jun",
        "present aug",
        "present may",
        "present apr",
        "present feb",
        "creation date",
        "worm",
        "search",
        "present jul",
        "error",
        "msil",
        "passive dns",
        "urls",
        "url add",
        "pulse pulses",
        "http",
        "hostname",
        "files domain",
        "files related",
        "pulses none",
        "related tags",
        "unknown ns",
        "ip address",
        "name servers",
        "status",
        "showing",
        "found title",
        "open ports",
        "backdoor",
        "hacktool",
        "entries",
        "next associated",
        "ipv4",
        "trojan",
        "domain",
        "authority",
        "record value",
        "script script",
        "cname",
        "script urls",
        "learn",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "spawns",
        "ssl certificate",
        "execution att",
        "present mar",
        "mtb sep",
        "ransom",
        "win32",
        "gmt contenttype",
        "ipv4 add",
        "files",
        "location united",
        "development att",
        "extra data",
        "extraction",
        "please",
        "sc data",
        "type",
        "failed",
        "extr data",
        "ox sunnort",
        "include review",
        "exclude data",
        "sugges",
        "process32nextw",
        "observed dns",
        "query",
        "read c",
        "medium",
        "dns lookup",
        "msdos",
        "wannacry dns",
        "lookup",
        "wannacry",
        "delphi",
        "malware",
        "copy",
        "service",
        "explorer",
        "write",
        "darkcomet",
        "ping",
        "tools",
        "capture",
        "next"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1054",
          "name": "Indicator Blocking",
          "display_name": "T1054 - Indicator Blocking"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1089",
          "name": "Disabling Security Tools",
          "display_name": "T1089 - Disabling Security Tools"
        },
        {
          "id": "T1158",
          "name": "Hidden Files and Directories",
          "display_name": "T1158 - Hidden Files and Directories"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 33,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 145,
        "FileHash-SHA1": 138,
        "FileHash-SHA256": 398,
        "SSLCertFingerprint": 12,
        "URL": 876,
        "domain": 136,
        "hostname": 216,
        "email": 3,
        "CVE": 1
      },
      "indicator_count": 1925,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "262 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66bbf5ef43b695838a17661c",
      "name": "Unsupported Browser - WordPress.com | Injection - Brian Sabey Hall Render",
      "description": "Malicious attack from hacker claiming to be an attorney. Every device, network, and others impacted. Illegal attack. Invasion of privacy vs investigation. Target is using all zombie devices. \u00c0 malevolent army of hackers injecting everything and everyone related to assault victim. Retaliation, malice, obsession all indicitive of danger from  ever present adversaries. \n'' ALF:Backdoor:MSIL/Noancooe\nALF:Trojan:MSIL/AgentTesla.KM\nALF:Win32/GbdInf_CFF3548C.J!ibt\nBackdoor:Win32/Fynloski\nET\nETERNALBLUE? Federal \nExploit:Win32/CVE-2017-0147\nRansom:Win32/WannaCrypt.H\nTrojan:Linux/Dakkatoni\nTrojan:Win32/ClipBanker\nWin32:PWSX-gen\\ [Trj]\nWorm:Win32/Mofksys",
      "modified": "2024-10-12T19:02:41.872000",
      "created": "2024-08-14T00:10:22.703000",
      "tags": [
        "referrer",
        "vt report",
        "project skynet",
        "cyber army",
        "goog mal",
        "android windows",
        "maze",
        "startpage",
        "regsz",
        "english",
        "t1082",
        "adobe air",
        "standard",
        "java",
        "high",
        "discovery",
        "yara detections",
        "updater",
        "install",
        "et trojan",
        "et exploit",
        "request",
        "probe ms17010",
        "yara rule",
        "ransom",
        "kryptos logic",
        "html response",
        "wannacry",
        "logic",
        "related pulses",
        "files matching",
        "search",
        "hitmen",
        "unknown",
        "nxdomain",
        "creation date",
        "mtb sep",
        "backdoor",
        "worm",
        "msil",
        "all scoreblue",
        "file samples",
        "win32",
        "copyright",
        "levelblue",
        "dashboard",
        "browse scan",
        "next",
        "exploit",
        "as16276",
        "canada unknown",
        "passive dns",
        "historical ssl",
        "levelblue labs",
        "otx telemetry",
        "name servers",
        "google safe",
        "browsing",
        "brian sabey",
        "thebrotherssabey",
        "murderer",
        "hackers",
        "united states",
        "lazarus",
        "united",
        "msie",
        "chrome",
        "body",
        "gmt content",
        "scan endpoints",
        "domain",
        "ipv4",
        "files",
        "asn as13335",
        "dns resolutions",
        "browser",
        "purtroppo",
        "visualizza",
        "carica la",
        "javascript",
        "unsupported",
        "view",
        "dead",
        "fakedout threat",
        "analyzer paste",
        "iocs",
        "tofsee",
        "status",
        "as47846",
        "germany unknown",
        "as44273 host",
        "as12876 online",
        "tsara brashears",
        "memcommit",
        "show",
        "read c",
        "entries",
        "icmp traffic",
        "medium",
        "memreserve",
        "packing t1045",
        "write",
        "malware",
        "urls",
        "emails",
        "servers",
        "showing",
        "date",
        "findwindowa",
        "regopenkeyexw",
        "checks",
        "redline stealer",
        "whitelisted",
        "as23393",
        "aaaa",
        "aaaa nxdomain",
        "as40676 psychz",
        "as53667",
        "as3842 inmotion",
        "pulse pulses",
        "domains top",
        "hong kong",
        "moved",
        "trojan",
        "trojan features",
        "date hash",
        "cname",
        "as50069 misaka",
        "as3214 xtom",
        "virgin islands",
        "antigua",
        "org domains",
        "proxy",
        "code",
        "alf features"
      ],
      "references": [
        "*http://hghltd.yandex.net/yandbtm?fmode=inject&url=http://siteinlink.d1.cnbd.net/search/tsara-brashears-assaulted-by-jeffrey-reimer/",
        "botnetsinkhole@gmail.com",
        "Adware ALF:Win32/GbdInf_CFF3548C.J!ibt:  FileHash-SHA256 459a0c8088f9c7455f12b90a809322e307553ee1b335299a705a400538144182",
        "Antivirus Detections ALF:Win32/GbdInf_CFF3548C.J!ibt",
        "IDS Detections: Lavasoft PUA/Adware Client Install",
        "Yara Detections research_pe_signed_outside_timestamp ,  _7_Zip_Installer",
        "Alerts: network_icmp antiav_detectreg antisandbox_idletime recon_programs ransomware_file_moves ransomware_appends_extensions",
        "Alerts: injection_resumethread dumped_buffer network_cnc_http network_http network_http_post allocates_rwx",
        "Alerts: creates_exe dropper exe_appdata has_wmi injection_process_search protection_rx antivm_network_adapters privilege_luid_check",
        "Ransom:Win32/WannaCrypt.H: FileHash-SHA256 f361351a71dfa356f67d501cf3990bfab3b5b66d48afee659bfa7c6e40e7fe79",
        "Antivirus Detections Win.Ransomware.Wanna-9769986-0 ,  Ransom:Win32/WannaCrypt.H",
        "IDS Detections: Possible WannaCry DNS Lookup 1 W32/WannaCry.Ransomware Killswitch Domain HTTP Request 1",
        "IDS Detections: Domain Sinkholed by Kryptos Logic (HTML Response) Known Sinkhole Response Kryptos Logic",
        "IDS Detections: Possible ETERNALBLUE Probe MS17-010 (MSF style) Possible ETERNALBLUE Probe MS17-010 (Generic Flags)",
        "IDS Detections: ETERNALBLUE Probe Vulnerable System Response MS17-010 Possible ETERNALBLUE MS17-010 Heap Spray",
        "IDS Detections: Observed DNS Query to Suspicious Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com)",
        "IDS Detections: Behavioral Unusual Port 445 traffic Potential Scan or Infection",
        "Yara Detections: WannaCry_Ransomware ,  Win32_Ransomware_WannaCry ,  stack_string ,  MS17_010_WanaCry_worm ,  MS_Visual_Cpp_6_0",
        "Alerts: procmem_yara persistence_autorun persistence_autorun_tasks stealth_file spawns_dev_util cape_detected_threat suricata_alert",
        "Alerts: antisandbox_sleep dead_connect dynamic_function_loading http_request https_urls powershell_download powershell_request",
        "Alerts: stealth_window network_multiple_direct_ip_connections network_cnc_http network_http antidebug_setunhandledexceptionfilter antivm_network_adapters",
        "1510 IP\u2019s Contacted!! 53.45.82.160 117.149.89.86 71.8.199.125 196.247.232.166 125.124.203.12 | Wow! Get her. Rage against the assaulted. 0 Testosterone]",
        "1510 IP\u2019s Contacted!! 105.186.124.102 194.249.100.247 6.192.197.229 174.145.199.195 7.249.17.5   Okay.",
        "HTTP Scans - comment 'sinkhole.tech where the bots party hard and the researchers harder.h6'",
        "Researched existing pulse: https://thebrotherssabey.wordpress.com/wp-admin/customize.php?url=https://thebrotherssabey.wordpress.com/",
        "zoopussy.com roar, grrrr, hiss",
        "Antivirus Detections Win32:PWSX-gen\\ [Trj]",
        "IDS Detections: External IP Address Lookup DNS Query (api .ip .sb) Observed External IP Lookup Domain (api.ip .sb in TLS SNI)",
        "IDS Detections: ETPRO TROJAN Redline Stealer TCP CnC - CheckConnect ETPRO TROJAN Redline Stealer TCP CnC - EnvironmentSettings",
        "High Priority Alerts: network_icmp nolookup_communication  antisandbox_idletime antivm_vmware_in_instruction",
        "High Priority Alerts: antivm_generic_bios infostealer_ftp recon_programs antivm_firmware antidbg_windows"
      ],
      "public": 1,
      "adversary": "Lazarus Group",
      "targeted_countries": [
        "Netherlands",
        "United States of America",
        "Hong Kong"
      ],
      "malware_families": [
        {
          "id": "ALF:Win32/GbdInf_CFF3548C.J!ibt",
          "display_name": "ALF:Win32/GbdInf_CFF3548C.J!ibt",
          "target": "/malware/ALF:Win32/GbdInf_CFF3548C.J!ibt"
        },
        {
          "id": "Ransom:Win32/WannaCrypt.H",
          "display_name": "Ransom:Win32/WannaCrypt.H",
          "target": "/malware/Ransom:Win32/WannaCrypt.H"
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        },
        {
          "id": "ETERNALBLUE",
          "display_name": "ETERNALBLUE",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Fynloski",
          "display_name": "Backdoor:Win32/Fynloski",
          "target": "/malware/Backdoor:Win32/Fynloski"
        },
        {
          "id": "Worm:Win32/Mofksys",
          "display_name": "Worm:Win32/Mofksys",
          "target": "/malware/Worm:Win32/Mofksys"
        },
        {
          "id": "Exploit:Win32/CVE-2017-0147",
          "display_name": "Exploit:Win32/CVE-2017-0147",
          "target": "/malware/Exploit:Win32/CVE-2017-0147"
        },
        {
          "id": "ALF:Trojan:MSIL/AgentTesla.KM",
          "display_name": "ALF:Trojan:MSIL/AgentTesla.KM",
          "target": null
        },
        {
          "id": "Win32:PWSX-gen\\ [Trj]",
          "display_name": "Win32:PWSX-gen\\ [Trj]",
          "target": null
        },
        {
          "id": "Trojan:Win32/ClipBanker",
          "display_name": "Trojan:Win32/ClipBanker",
          "target": "/malware/Trojan:Win32/ClipBanker"
        },
        {
          "id": "ALF:Backdoor:MSIL/Noancooe",
          "display_name": "ALF:Backdoor:MSIL/Noancooe",
          "target": null
        },
        {
          "id": "Trojan:Linux/Dakkatoni",
          "display_name": "Trojan:Linux/Dakkatoni",
          "target": "/malware/Trojan:Linux/Dakkatoni"
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [
        "Telecommunications",
        "Technology",
        "Civilian Society"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 39,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2748,
        "FileHash-SHA1": 2485,
        "FileHash-SHA256": 6374,
        "hostname": 525,
        "URL": 146,
        "domain": 290,
        "email": 7,
        "CVE": 2
      },
      "indicator_count": 12577,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 232,
      "modified_text": "595 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "789ab.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "789ab.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780236842.1821127
}