{
  "type": "Domain",
  "indicator": "bitdefender.fr",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/bitdefender.fr",
    "alexa": "http://www.alexa.com/siteinfo/bitdefender.fr",
    "indicator": "bitdefender.fr",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3896485821,
      "indicator": "bitdefender.fr",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "69f47e886aac3dce3a958d27",
          "name": "2011: Malware Analysis Report",
          "description": "",
          "modified": "2026-05-01T10:20:56.666000",
          "created": "2026-05-01T10:20:56.666000",
          "tags": [],
          "references": [
            "2011-03-11 - Trojan.Koredos Comes with an Unwelcomed Surprise.pdf",
            "2011-01-20 - Beschreibung des Virus Backdoor.Win32. Buterat.afj.pdf",
            "2011-03-08 - Worm-Win32-Yimfoca.A.pdf",
            "2011-03-02 - TDL4 and Glupteba- Piggyback PiggyBugs.pdf",
            "2011-04-26 - SpyEye Targets Opera, Google Chrome Users.pdf",
            "2011-03-28 - Microsoft Hunting Rustock Controllers.pdf",
            "2011-01-09 - Jan 6 CVE-2010-3333 DOC with info theft trojan from the American Chamber of Commerce.pdf",
            "2011-04-19 - TDSS part 1- The x64 Dollar Question.pdf",
            "2011-04-16 - Troj-Sasfis-O.pdf",
            "2011-05-19 - Win32-Expiro.pdf",
            "2011-06-22 - Criminals gain control over Mac with BackDoor.Olyx.pdf",
            "2011-04-30 - BKA-Trojaner (Ransomware).pdf",
            "2011-06-29 - Inside a Back Door Attack.pdf",
            "2011-07-26 - SpyEye Trojan defeating online banking defenses.pdf",
            "2011-04-28 - Un observateur d\u2019\u00e9v\u00e9nements aveugle\u2026.pdf",
            "2011-07-08 - Trojan.Mayachok.2- ?????? ??????? ?????????? VBR-???????.pdf",
            "2011-07-14 - Cycbot- Ready to Ride.pdf",
            "2011-07-06 - Cybercriminals switch from MBR to NTFS.pdf",
            "2011-07-28 - Trojan Tricks Victims Into Transferring Funds.pdf",
            "2011-08-27 - Morto.A.pdf",
            "2011-01-30 - GpCode Ransomware 2010 Simple Analysis.pdf",
            "2011-08-03 - HTran and the Advanced Persistent Threat.pdf",
            "2011-08-28 - Windows Remote Desktop Worm -Morto- Spreading.pdf",
            "2011-09-09 - BIOS Threat is Showing up Again!.pdf",
            "2011-09-02 - ZeuS Gets Another Update.pdf",
            "2011-08-24 - Ice IX, the first crimeware based on the leaked ZeuS sources.pdf",
            "2011-09-13 - Mebromi- the first BIOS rootkit in the wild.pdf",
            "2011-08-04 - Analysis of ngrBot.pdf",
            "2011-09-14 - Ice IX- not cool at all.pdf",
            "2011-09-14 - Malware burrows deep into computer BIOS to escape AV.pdf",
            "2011-09-19 - Mebromi BIOS rootkit affecting Award BIOS (aka -BMW- virus).pdf",
            "2011-08-28 - Windows Remote Desktop Worm -Morto- Spreading22.pdf",
            "2011-09-21 - Sept 21 Greedy Shylock - financial malware.pdf",
            "2011-09-09 - Stuxnet Malware Analysis Paper.pdf",
            "2011-09-27 - Debugging Injected Code with IDA Pro.pdf",
            "2011-10-07 - Rustock samples and analysis links. Rustock.C, E, I, J and other variants.pdf",
            "2011-10-14 - A Detailed Analysis of an Advanced Persistent Threat Malware.pdf",
            "2011-10-06 - ZeuS-in-the-Mobile \u2013 Facts and Theories.pdf",
            "2011-10-08 - Possible Governmental Backdoor Found (-Case R2D2-).pdf",
            "2011-10-17 - W32-Yunsip!tr.pws.pdf",
            "2011-10-06 - Sep 28 CVE-2010-3333 Manuscript with Taidoor (Trojan.Matryoshka by CyberESI).pdf",
            "2011-10-13 - A Detailed Analysis of an Advanced Persistent Threat Malware.pdf",
            "2011-10-31 - The Significance of the -Nitro- Attacks.pdf",
            "2011-10-26 - Tsunami Backdoor Can Be Used for Denial of Service Attacks.pdf",
            "2011-12-20 - Analyzing CVE-2011-4369 \u2013 Part One.pdf",
            "2011-12-08 - The Sykipot Attacks.pdf",
            "2011-12-11 - Intro. To Reversing - W32Pinkslipbot.pdf",
            "Duqu Trojan Questions and Answers.pdf",
            "Palebot trojan.pdf",
            "HTran.pdf",
            "Ghost RAT- Many faces.pdf",
            "Operation Shady Rat.pdf",
            "Alleged APT Intrusion Set 1.php Group.pdf",
            "Stuxnet , Duqu - The Evolution of Drivers.pdf",
            "The RSA Hack.pdf",
            "The Nitro Attacks - Stealing secrets from the Chemical Industry.pdf",
            "Global_Energy_Cyberattacks_-_Night_Dragon_.pdf",
            "The LURID Downloader.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "kikinumpav",
            "id": "385742",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1031,
            "domain": 435,
            "CVE": 13,
            "FileHash-MD5": 155,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 234,
            "IPv4": 88,
            "email": 9,
            "hostname": 1031
          },
          "indicator_count": 3004,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 12,
          "modified_text": "29 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66762a4ccb10185d774ddbde",
          "name": "Lazarus Group - Emotet | Sony Music",
          "description": "Is the Lazarus Group still attacking Sony Music, affiliated, former, contacts, aspiring prospects and independent artists?\n\nA Denver Studio owner had former Sony leadership role was fully infected with Pegasus, Mirai and  a Lazarus Group affiliation seen. An independent Denver publishing company and artists were greatly targeted and continue to be. A songwriter known to have recorded at Denver Studio had songs pirated. Tori Kelly and Justin Bieber recorded over chops copy written by artist. Strangely legally affiliated. A rumor suggests Lazarus group & Anonymous are hacker made up of government employees, police officers, attorneys and PI's. The government affiliated IP's are give rumors some weight. Hackers will hack anything, \nMost popular beliefs are artist was targeted and therefore the studio where she target worked from often. Denver Studio report scrubbed by HistoryKillerPro & other Unknown Stealers.",
          "modified": "2024-07-22T01:04:09.406000",
          "created": "2024-06-22T01:35:08.834000",
          "tags": [
            "url https",
            "url http",
            "active related",
            "pulses hostname",
            "ipv4",
            "showing",
            "entries",
            "active",
            "passive dns",
            "as2527 sony",
            "all scoreblue",
            "pulse pulses",
            "urls",
            "files",
            "reverse dns",
            "location chiba",
            "united",
            "unknown",
            "date",
            "moved",
            "search",
            "gmt content",
            "domain",
            "body",
            "encrypt",
            "as58061 scalaxy",
            "asn as58061",
            "dns resolutions",
            "expiration",
            "no expiration",
            "hostname",
            "iocs",
            "filehashsha256",
            "scan endpoints",
            "next",
            "report spam",
            "lazarus created",
            "minutes ago",
            "amber tags",
            "filehashsha1",
            "group",
            "tip oriented",
            "threat research",
            "android10",
            "type indicator",
            "role title",
            "creation date",
            "emails",
            "pulse submit",
            "url analysis",
            "germany unknown",
            "aaaa",
            "cname",
            "as209453 gandi",
            "as209453",
            "france unknown",
            "ireland unknown",
            "susp",
            "backdoor",
            "win32",
            "meta",
            "cookie",
            "pragma",
            "open ports",
            "as20940",
            "status",
            "certificate",
            "rsa sha256",
            "record value",
            "historical ssl",
            "referrer",
            "collection",
            "vt graph",
            "glaxosmithkline",
            "cyber threat",
            "heur",
            "phishing",
            "team",
            "malicious site",
            "control server",
            "coalition",
            "team phishing",
            "engineering",
            "emotet",
            "malware",
            "malicious",
            "download",
            "cobalt strike",
            "binder",
            "dropper",
            "formbook",
            "facebook",
            "artemis",
            "azorult",
            "bank",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "hostnames",
            "detection list",
            "blacklist",
            "a domains",
            "bitdefender",
            "leader",
            "as15133 verizon",
            "melbourne it",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers date",
            "gmt contenttype",
            "connection",
            "ip address",
            "web redirection",
            "sha1",
            "ascii text",
            "sha256",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "pattern match",
            "hybrid",
            "starfield",
            "format",
            "june",
            "local",
            "click",
            "strings",
            "contact",
            "loki"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
            "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
            "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
            "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
            "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
            "Server: Web redirection - http://loki.com/download",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
          ],
          "public": 1,
          "adversary": "Lazarus Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Win.Trojan.DarkKomet-1",
              "display_name": "Win.Trojan.DarkKomet-1",
              "target": null
            },
            {
              "id": "VirTool:Win32/CeeInject",
              "display_name": "VirTool:Win32/CeeInject",
              "target": "/malware/VirTool:Win32/CeeInject"
            },
            {
              "id": "Backdoor:MSIL/Bladabindi",
              "display_name": "Backdoor:MSIL/Bladabindi",
              "target": "/malware/Backdoor:MSIL/Bladabindi"
            },
            {
              "id": "Win32:Evo-gen",
              "display_name": "Win32:Evo-gen",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Susp]",
              "display_name": "Win32:Evo-gen\\ [Susp]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [
            "Entertainment",
            "Technology",
            "Media"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 50,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3528,
            "domain": 1453,
            "hostname": 1542,
            "FileHash-SHA256": 757,
            "FileHash-SHA1": 66,
            "FileHash-MD5": 79,
            "email": 5,
            "CVE": 4,
            "SSLCertFingerprint": 14
          },
          "indicator_count": 7448,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 234,
          "modified_text": "678 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "667648f0bc130bdaa294ea19",
          "name": "Sony Music | Emotet  - Lazarus Affiliated",
          "description": "",
          "modified": "2024-07-22T01:04:09.406000",
          "created": "2024-06-22T03:45:52.401000",
          "tags": [
            "url https",
            "url http",
            "active related",
            "pulses hostname",
            "ipv4",
            "showing",
            "entries",
            "active",
            "passive dns",
            "as2527 sony",
            "all scoreblue",
            "pulse pulses",
            "urls",
            "files",
            "reverse dns",
            "location chiba",
            "united",
            "unknown",
            "date",
            "moved",
            "search",
            "gmt content",
            "domain",
            "body",
            "encrypt",
            "as58061 scalaxy",
            "asn as58061",
            "dns resolutions",
            "expiration",
            "no expiration",
            "hostname",
            "iocs",
            "filehashsha256",
            "scan endpoints",
            "next",
            "report spam",
            "lazarus created",
            "minutes ago",
            "amber tags",
            "filehashsha1",
            "group",
            "tip oriented",
            "threat research",
            "android10",
            "type indicator",
            "role title",
            "creation date",
            "emails",
            "pulse submit",
            "url analysis",
            "germany unknown",
            "aaaa",
            "cname",
            "as209453 gandi",
            "as209453",
            "france unknown",
            "ireland unknown",
            "susp",
            "backdoor",
            "win32",
            "meta",
            "cookie",
            "pragma",
            "open ports",
            "as20940",
            "status",
            "certificate",
            "rsa sha256",
            "record value",
            "historical ssl",
            "referrer",
            "collection",
            "vt graph",
            "glaxosmithkline",
            "cyber threat",
            "heur",
            "phishing",
            "team",
            "malicious site",
            "control server",
            "coalition",
            "team phishing",
            "engineering",
            "emotet",
            "malware",
            "malicious",
            "download",
            "cobalt strike",
            "binder",
            "dropper",
            "formbook",
            "facebook",
            "artemis",
            "azorult",
            "bank",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "hostnames",
            "detection list",
            "blacklist",
            "a domains",
            "bitdefender",
            "leader",
            "as15133 verizon",
            "melbourne it",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers date",
            "gmt contenttype",
            "connection",
            "ip address",
            "web redirection",
            "sha1",
            "ascii text",
            "sha256",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "pattern match",
            "hybrid",
            "starfield",
            "format",
            "june",
            "local",
            "click",
            "strings",
            "contact",
            "loki"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
            "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
            "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
            "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
            "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
            "Server: Web redirection - http://loki.com/download",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
          ],
          "public": 1,
          "adversary": "Lazarus Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Win.Trojan.DarkKomet-1",
              "display_name": "Win.Trojan.DarkKomet-1",
              "target": null
            },
            {
              "id": "VirTool:Win32/CeeInject",
              "display_name": "VirTool:Win32/CeeInject",
              "target": "/malware/VirTool:Win32/CeeInject"
            },
            {
              "id": "Backdoor:MSIL/Bladabindi",
              "display_name": "Backdoor:MSIL/Bladabindi",
              "target": "/malware/Backdoor:MSIL/Bladabindi"
            },
            {
              "id": "Win32:Evo-gen",
              "display_name": "Win32:Evo-gen",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Susp]",
              "display_name": "Win32:Evo-gen\\ [Susp]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [
            "Entertainment",
            "Technology",
            "Media"
          ],
          "TLP": "green",
          "cloned_from": "66762a4ccb10185d774ddbde",
          "export_count": 47,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3528,
            "domain": 1453,
            "hostname": 1542,
            "FileHash-SHA256": 757,
            "FileHash-SHA1": 66,
            "FileHash-MD5": 79,
            "email": 5,
            "CVE": 4,
            "SSLCertFingerprint": 14
          },
          "indicator_count": 7448,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 232,
          "modified_text": "678 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6681f340f8c0223ae0ce199d",
          "name": "Bitdefender Ransomware| | Sony Music |  Lazarus Affiliated",
          "description": "",
          "modified": "2024-07-22T01:04:09.406000",
          "created": "2024-07-01T00:07:28.402000",
          "tags": [
            "url https",
            "url http",
            "active related",
            "pulses hostname",
            "ipv4",
            "showing",
            "entries",
            "active",
            "passive dns",
            "as2527 sony",
            "all scoreblue",
            "pulse pulses",
            "urls",
            "files",
            "reverse dns",
            "location chiba",
            "united",
            "unknown",
            "date",
            "moved",
            "search",
            "gmt content",
            "domain",
            "body",
            "encrypt",
            "as58061 scalaxy",
            "asn as58061",
            "dns resolutions",
            "expiration",
            "no expiration",
            "hostname",
            "iocs",
            "filehashsha256",
            "scan endpoints",
            "next",
            "report spam",
            "lazarus created",
            "minutes ago",
            "amber tags",
            "filehashsha1",
            "group",
            "tip oriented",
            "threat research",
            "android10",
            "type indicator",
            "role title",
            "creation date",
            "emails",
            "pulse submit",
            "url analysis",
            "germany unknown",
            "aaaa",
            "cname",
            "as209453 gandi",
            "as209453",
            "france unknown",
            "ireland unknown",
            "susp",
            "backdoor",
            "win32",
            "meta",
            "cookie",
            "pragma",
            "open ports",
            "as20940",
            "status",
            "certificate",
            "rsa sha256",
            "record value",
            "historical ssl",
            "referrer",
            "collection",
            "vt graph",
            "glaxosmithkline",
            "cyber threat",
            "heur",
            "phishing",
            "team",
            "malicious site",
            "control server",
            "coalition",
            "team phishing",
            "engineering",
            "emotet",
            "malware",
            "malicious",
            "download",
            "cobalt strike",
            "binder",
            "dropper",
            "formbook",
            "facebook",
            "artemis",
            "azorult",
            "bank",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "hostnames",
            "detection list",
            "blacklist",
            "a domains",
            "bitdefender",
            "leader",
            "as15133 verizon",
            "melbourne it",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers date",
            "gmt contenttype",
            "connection",
            "ip address",
            "web redirection",
            "sha1",
            "ascii text",
            "sha256",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "pattern match",
            "hybrid",
            "starfield",
            "format",
            "june",
            "local",
            "click",
            "strings",
            "contact",
            "loki"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
            "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
            "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
            "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
            "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
            "Server: Web redirection - http://loki.com/download",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
          ],
          "public": 1,
          "adversary": "Lazarus Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Win.Trojan.DarkKomet-1",
              "display_name": "Win.Trojan.DarkKomet-1",
              "target": null
            },
            {
              "id": "VirTool:Win32/CeeInject",
              "display_name": "VirTool:Win32/CeeInject",
              "target": "/malware/VirTool:Win32/CeeInject"
            },
            {
              "id": "Backdoor:MSIL/Bladabindi",
              "display_name": "Backdoor:MSIL/Bladabindi",
              "target": "/malware/Backdoor:MSIL/Bladabindi"
            },
            {
              "id": "Win32:Evo-gen",
              "display_name": "Win32:Evo-gen",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Susp]",
              "display_name": "Win32:Evo-gen\\ [Susp]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [
            "Entertainment",
            "Technology",
            "Media"
          ],
          "TLP": "green",
          "cloned_from": "667648f0bc130bdaa294ea19",
          "export_count": 6847,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3528,
            "domain": 1453,
            "hostname": 1542,
            "FileHash-SHA256": 757,
            "FileHash-SHA1": 66,
            "FileHash-MD5": 79,
            "email": 5,
            "CVE": 4,
            "SSLCertFingerprint": 14
          },
          "indicator_count": 7448,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "678 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "2011-03-08 - Worm-Win32-Yimfoca.A.pdf",
        "Global_Energy_Cyberattacks_-_Night_Dragon_.pdf",
        "2011-09-02 - ZeuS Gets Another Update.pdf",
        "2011-10-07 - Rustock samples and analysis links. Rustock.C, E, I, J and other variants.pdf",
        "Alleged APT Intrusion Set 1.php Group.pdf",
        "The RSA Hack.pdf",
        "The LURID Downloader.pdf",
        "2011-05-19 - Win32-Expiro.pdf",
        "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "2011-04-28 - Un observateur d\u2019\u00e9v\u00e9nements aveugle\u2026.pdf",
        "2011-09-14 - Malware burrows deep into computer BIOS to escape AV.pdf",
        "The Nitro Attacks - Stealing secrets from the Chemical Industry.pdf",
        "2011-08-27 - Morto.A.pdf",
        "2011-07-14 - Cycbot- Ready to Ride.pdf",
        "2011-09-13 - Mebromi- the first BIOS rootkit in the wild.pdf",
        "2011-04-19 - TDSS part 1- The x64 Dollar Question.pdf",
        "2011-09-09 - BIOS Threat is Showing up Again!.pdf",
        "Server: Web redirection - http://loki.com/download",
        "2011-07-08 - Trojan.Mayachok.2- ?????? ??????? ?????????? VBR-???????.pdf",
        "2011-08-28 - Windows Remote Desktop Worm -Morto- Spreading22.pdf",
        "2011-03-28 - Microsoft Hunting Rustock Controllers.pdf",
        "2011-04-30 - BKA-Trojaner (Ransomware).pdf",
        "2011-08-24 - Ice IX, the first crimeware based on the leaked ZeuS sources.pdf",
        "2011-09-14 - Ice IX- not cool at all.pdf",
        "2011-12-11 - Intro. To Reversing - W32Pinkslipbot.pdf",
        "2011-06-22 - Criminals gain control over Mac with BackDoor.Olyx.pdf",
        "2011-09-27 - Debugging Injected Code with IDA Pro.pdf",
        "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
        "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
        "2011-08-04 - Analysis of ngrBot.pdf",
        "Palebot trojan.pdf",
        "Ghost RAT- Many faces.pdf",
        "2011-06-29 - Inside a Back Door Attack.pdf",
        "2011-07-26 - SpyEye Trojan defeating online banking defenses.pdf",
        "2011-09-09 - Stuxnet Malware Analysis Paper.pdf",
        "2011-10-06 - Sep 28 CVE-2010-3333 Manuscript with Taidoor (Trojan.Matryoshka by CyberESI).pdf",
        "2011-09-21 - Sept 21 Greedy Shylock - financial malware.pdf",
        "Operation Shady Rat.pdf",
        "2011-04-26 - SpyEye Targets Opera, Google Chrome Users.pdf",
        "Stuxnet , Duqu - The Evolution of Drivers.pdf",
        "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
        "2011-07-28 - Trojan Tricks Victims Into Transferring Funds.pdf",
        "2011-01-20 - Beschreibung des Virus Backdoor.Win32. Buterat.afj.pdf",
        "2011-08-28 - Windows Remote Desktop Worm -Morto- Spreading.pdf",
        "2011-09-19 - Mebromi BIOS rootkit affecting Award BIOS (aka -BMW- virus).pdf",
        "2011-07-06 - Cybercriminals switch from MBR to NTFS.pdf",
        "2011-08-03 - HTran and the Advanced Persistent Threat.pdf",
        "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
        "2011-12-08 - The Sykipot Attacks.pdf",
        "2011-01-30 - GpCode Ransomware 2010 Simple Analysis.pdf",
        "2011-10-17 - W32-Yunsip!tr.pws.pdf",
        "Duqu Trojan Questions and Answers.pdf",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
        "2011-10-14 - A Detailed Analysis of an Advanced Persistent Threat Malware.pdf",
        "2011-10-31 - The Significance of the -Nitro- Attacks.pdf",
        "2011-12-20 - Analyzing CVE-2011-4369 \u2013 Part One.pdf",
        "2011-04-16 - Troj-Sasfis-O.pdf",
        "2011-10-26 - Tsunami Backdoor Can Be Used for Denial of Service Attacks.pdf",
        "2011-01-09 - Jan 6 CVE-2010-3333 DOC with info theft trojan from the American Chamber of Commerce.pdf",
        "2011-10-08 - Possible Governmental Backdoor Found (-Case R2D2-).pdf",
        "2011-10-13 - A Detailed Analysis of an Advanced Persistent Threat Malware.pdf",
        "HTran.pdf",
        "2011-03-11 - Trojan.Koredos Comes with an Unwelcomed Surprise.pdf",
        "2011-03-02 - TDL4 and Glupteba- Piggyback PiggyBugs.pdf",
        "2011-10-06 - ZeuS-in-the-Mobile \u2013 Facts and Theories.pdf"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Lazarus Group"
          ],
          "malware_families": [
            "Backdoor:msil/bladabindi",
            "Win32:evo-gen",
            "Virtool:win32/ceeinject",
            "Win32:evo-gen\\ [susp]",
            "Win.trojan.darkkomet-1",
            "Mirai"
          ],
          "industries": [
            "Media",
            "Entertainment",
            "Technology"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "69f47e886aac3dce3a958d27",
      "name": "2011: Malware Analysis Report",
      "description": "",
      "modified": "2026-05-01T10:20:56.666000",
      "created": "2026-05-01T10:20:56.666000",
      "tags": [],
      "references": [
        "2011-03-11 - Trojan.Koredos Comes with an Unwelcomed Surprise.pdf",
        "2011-01-20 - Beschreibung des Virus Backdoor.Win32. Buterat.afj.pdf",
        "2011-03-08 - Worm-Win32-Yimfoca.A.pdf",
        "2011-03-02 - TDL4 and Glupteba- Piggyback PiggyBugs.pdf",
        "2011-04-26 - SpyEye Targets Opera, Google Chrome Users.pdf",
        "2011-03-28 - Microsoft Hunting Rustock Controllers.pdf",
        "2011-01-09 - Jan 6 CVE-2010-3333 DOC with info theft trojan from the American Chamber of Commerce.pdf",
        "2011-04-19 - TDSS part 1- The x64 Dollar Question.pdf",
        "2011-04-16 - Troj-Sasfis-O.pdf",
        "2011-05-19 - Win32-Expiro.pdf",
        "2011-06-22 - Criminals gain control over Mac with BackDoor.Olyx.pdf",
        "2011-04-30 - BKA-Trojaner (Ransomware).pdf",
        "2011-06-29 - Inside a Back Door Attack.pdf",
        "2011-07-26 - SpyEye Trojan defeating online banking defenses.pdf",
        "2011-04-28 - Un observateur d\u2019\u00e9v\u00e9nements aveugle\u2026.pdf",
        "2011-07-08 - Trojan.Mayachok.2- ?????? ??????? ?????????? VBR-???????.pdf",
        "2011-07-14 - Cycbot- Ready to Ride.pdf",
        "2011-07-06 - Cybercriminals switch from MBR to NTFS.pdf",
        "2011-07-28 - Trojan Tricks Victims Into Transferring Funds.pdf",
        "2011-08-27 - Morto.A.pdf",
        "2011-01-30 - GpCode Ransomware 2010 Simple Analysis.pdf",
        "2011-08-03 - HTran and the Advanced Persistent Threat.pdf",
        "2011-08-28 - Windows Remote Desktop Worm -Morto- Spreading.pdf",
        "2011-09-09 - BIOS Threat is Showing up Again!.pdf",
        "2011-09-02 - ZeuS Gets Another Update.pdf",
        "2011-08-24 - Ice IX, the first crimeware based on the leaked ZeuS sources.pdf",
        "2011-09-13 - Mebromi- the first BIOS rootkit in the wild.pdf",
        "2011-08-04 - Analysis of ngrBot.pdf",
        "2011-09-14 - Ice IX- not cool at all.pdf",
        "2011-09-14 - Malware burrows deep into computer BIOS to escape AV.pdf",
        "2011-09-19 - Mebromi BIOS rootkit affecting Award BIOS (aka -BMW- virus).pdf",
        "2011-08-28 - Windows Remote Desktop Worm -Morto- Spreading22.pdf",
        "2011-09-21 - Sept 21 Greedy Shylock - financial malware.pdf",
        "2011-09-09 - Stuxnet Malware Analysis Paper.pdf",
        "2011-09-27 - Debugging Injected Code with IDA Pro.pdf",
        "2011-10-07 - Rustock samples and analysis links. Rustock.C, E, I, J and other variants.pdf",
        "2011-10-14 - A Detailed Analysis of an Advanced Persistent Threat Malware.pdf",
        "2011-10-06 - ZeuS-in-the-Mobile \u2013 Facts and Theories.pdf",
        "2011-10-08 - Possible Governmental Backdoor Found (-Case R2D2-).pdf",
        "2011-10-17 - W32-Yunsip!tr.pws.pdf",
        "2011-10-06 - Sep 28 CVE-2010-3333 Manuscript with Taidoor (Trojan.Matryoshka by CyberESI).pdf",
        "2011-10-13 - A Detailed Analysis of an Advanced Persistent Threat Malware.pdf",
        "2011-10-31 - The Significance of the -Nitro- Attacks.pdf",
        "2011-10-26 - Tsunami Backdoor Can Be Used for Denial of Service Attacks.pdf",
        "2011-12-20 - Analyzing CVE-2011-4369 \u2013 Part One.pdf",
        "2011-12-08 - The Sykipot Attacks.pdf",
        "2011-12-11 - Intro. To Reversing - W32Pinkslipbot.pdf",
        "Duqu Trojan Questions and Answers.pdf",
        "Palebot trojan.pdf",
        "HTran.pdf",
        "Ghost RAT- Many faces.pdf",
        "Operation Shady Rat.pdf",
        "Alleged APT Intrusion Set 1.php Group.pdf",
        "Stuxnet , Duqu - The Evolution of Drivers.pdf",
        "The RSA Hack.pdf",
        "The Nitro Attacks - Stealing secrets from the Chemical Industry.pdf",
        "Global_Energy_Cyberattacks_-_Night_Dragon_.pdf",
        "The LURID Downloader.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "kikinumpav",
        "id": "385742",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1031,
        "domain": 435,
        "CVE": 13,
        "FileHash-MD5": 155,
        "FileHash-SHA1": 8,
        "FileHash-SHA256": 234,
        "IPv4": 88,
        "email": 9,
        "hostname": 1031
      },
      "indicator_count": 3004,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 12,
      "modified_text": "29 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66762a4ccb10185d774ddbde",
      "name": "Lazarus Group - Emotet | Sony Music",
      "description": "Is the Lazarus Group still attacking Sony Music, affiliated, former, contacts, aspiring prospects and independent artists?\n\nA Denver Studio owner had former Sony leadership role was fully infected with Pegasus, Mirai and  a Lazarus Group affiliation seen. An independent Denver publishing company and artists were greatly targeted and continue to be. A songwriter known to have recorded at Denver Studio had songs pirated. Tori Kelly and Justin Bieber recorded over chops copy written by artist. Strangely legally affiliated. A rumor suggests Lazarus group & Anonymous are hacker made up of government employees, police officers, attorneys and PI's. The government affiliated IP's are give rumors some weight. Hackers will hack anything, \nMost popular beliefs are artist was targeted and therefore the studio where she target worked from often. Denver Studio report scrubbed by HistoryKillerPro & other Unknown Stealers.",
      "modified": "2024-07-22T01:04:09.406000",
      "created": "2024-06-22T01:35:08.834000",
      "tags": [
        "url https",
        "url http",
        "active related",
        "pulses hostname",
        "ipv4",
        "showing",
        "entries",
        "active",
        "passive dns",
        "as2527 sony",
        "all scoreblue",
        "pulse pulses",
        "urls",
        "files",
        "reverse dns",
        "location chiba",
        "united",
        "unknown",
        "date",
        "moved",
        "search",
        "gmt content",
        "domain",
        "body",
        "encrypt",
        "as58061 scalaxy",
        "asn as58061",
        "dns resolutions",
        "expiration",
        "no expiration",
        "hostname",
        "iocs",
        "filehashsha256",
        "scan endpoints",
        "next",
        "report spam",
        "lazarus created",
        "minutes ago",
        "amber tags",
        "filehashsha1",
        "group",
        "tip oriented",
        "threat research",
        "android10",
        "type indicator",
        "role title",
        "creation date",
        "emails",
        "pulse submit",
        "url analysis",
        "germany unknown",
        "aaaa",
        "cname",
        "as209453 gandi",
        "as209453",
        "france unknown",
        "ireland unknown",
        "susp",
        "backdoor",
        "win32",
        "meta",
        "cookie",
        "pragma",
        "open ports",
        "as20940",
        "status",
        "certificate",
        "rsa sha256",
        "record value",
        "historical ssl",
        "referrer",
        "collection",
        "vt graph",
        "glaxosmithkline",
        "cyber threat",
        "heur",
        "phishing",
        "team",
        "malicious site",
        "control server",
        "coalition",
        "team phishing",
        "engineering",
        "emotet",
        "malware",
        "malicious",
        "download",
        "cobalt strike",
        "binder",
        "dropper",
        "formbook",
        "facebook",
        "artemis",
        "azorult",
        "bank",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "hostnames",
        "detection list",
        "blacklist",
        "a domains",
        "bitdefender",
        "leader",
        "as15133 verizon",
        "melbourne it",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "headers date",
        "gmt contenttype",
        "connection",
        "ip address",
        "web redirection",
        "sha1",
        "ascii text",
        "sha256",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "pattern match",
        "hybrid",
        "starfield",
        "format",
        "june",
        "local",
        "click",
        "strings",
        "contact",
        "loki"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
        "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
        "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
        "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
        "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
        "Server: Web redirection - http://loki.com/download",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
      ],
      "public": 1,
      "adversary": "Lazarus Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Win.Trojan.DarkKomet-1",
          "display_name": "Win.Trojan.DarkKomet-1",
          "target": null
        },
        {
          "id": "VirTool:Win32/CeeInject",
          "display_name": "VirTool:Win32/CeeInject",
          "target": "/malware/VirTool:Win32/CeeInject"
        },
        {
          "id": "Backdoor:MSIL/Bladabindi",
          "display_name": "Backdoor:MSIL/Bladabindi",
          "target": "/malware/Backdoor:MSIL/Bladabindi"
        },
        {
          "id": "Win32:Evo-gen",
          "display_name": "Win32:Evo-gen",
          "target": null
        },
        {
          "id": "Win32:Evo-gen\\ [Susp]",
          "display_name": "Win32:Evo-gen\\ [Susp]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [
        "Entertainment",
        "Technology",
        "Media"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 50,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3528,
        "domain": 1453,
        "hostname": 1542,
        "FileHash-SHA256": 757,
        "FileHash-SHA1": 66,
        "FileHash-MD5": 79,
        "email": 5,
        "CVE": 4,
        "SSLCertFingerprint": 14
      },
      "indicator_count": 7448,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 234,
      "modified_text": "678 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "667648f0bc130bdaa294ea19",
      "name": "Sony Music | Emotet  - Lazarus Affiliated",
      "description": "",
      "modified": "2024-07-22T01:04:09.406000",
      "created": "2024-06-22T03:45:52.401000",
      "tags": [
        "url https",
        "url http",
        "active related",
        "pulses hostname",
        "ipv4",
        "showing",
        "entries",
        "active",
        "passive dns",
        "as2527 sony",
        "all scoreblue",
        "pulse pulses",
        "urls",
        "files",
        "reverse dns",
        "location chiba",
        "united",
        "unknown",
        "date",
        "moved",
        "search",
        "gmt content",
        "domain",
        "body",
        "encrypt",
        "as58061 scalaxy",
        "asn as58061",
        "dns resolutions",
        "expiration",
        "no expiration",
        "hostname",
        "iocs",
        "filehashsha256",
        "scan endpoints",
        "next",
        "report spam",
        "lazarus created",
        "minutes ago",
        "amber tags",
        "filehashsha1",
        "group",
        "tip oriented",
        "threat research",
        "android10",
        "type indicator",
        "role title",
        "creation date",
        "emails",
        "pulse submit",
        "url analysis",
        "germany unknown",
        "aaaa",
        "cname",
        "as209453 gandi",
        "as209453",
        "france unknown",
        "ireland unknown",
        "susp",
        "backdoor",
        "win32",
        "meta",
        "cookie",
        "pragma",
        "open ports",
        "as20940",
        "status",
        "certificate",
        "rsa sha256",
        "record value",
        "historical ssl",
        "referrer",
        "collection",
        "vt graph",
        "glaxosmithkline",
        "cyber threat",
        "heur",
        "phishing",
        "team",
        "malicious site",
        "control server",
        "coalition",
        "team phishing",
        "engineering",
        "emotet",
        "malware",
        "malicious",
        "download",
        "cobalt strike",
        "binder",
        "dropper",
        "formbook",
        "facebook",
        "artemis",
        "azorult",
        "bank",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "hostnames",
        "detection list",
        "blacklist",
        "a domains",
        "bitdefender",
        "leader",
        "as15133 verizon",
        "melbourne it",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "headers date",
        "gmt contenttype",
        "connection",
        "ip address",
        "web redirection",
        "sha1",
        "ascii text",
        "sha256",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "pattern match",
        "hybrid",
        "starfield",
        "format",
        "june",
        "local",
        "click",
        "strings",
        "contact",
        "loki"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
        "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
        "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
        "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
        "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
        "Server: Web redirection - http://loki.com/download",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
      ],
      "public": 1,
      "adversary": "Lazarus Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Win.Trojan.DarkKomet-1",
          "display_name": "Win.Trojan.DarkKomet-1",
          "target": null
        },
        {
          "id": "VirTool:Win32/CeeInject",
          "display_name": "VirTool:Win32/CeeInject",
          "target": "/malware/VirTool:Win32/CeeInject"
        },
        {
          "id": "Backdoor:MSIL/Bladabindi",
          "display_name": "Backdoor:MSIL/Bladabindi",
          "target": "/malware/Backdoor:MSIL/Bladabindi"
        },
        {
          "id": "Win32:Evo-gen",
          "display_name": "Win32:Evo-gen",
          "target": null
        },
        {
          "id": "Win32:Evo-gen\\ [Susp]",
          "display_name": "Win32:Evo-gen\\ [Susp]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [
        "Entertainment",
        "Technology",
        "Media"
      ],
      "TLP": "green",
      "cloned_from": "66762a4ccb10185d774ddbde",
      "export_count": 47,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3528,
        "domain": 1453,
        "hostname": 1542,
        "FileHash-SHA256": 757,
        "FileHash-SHA1": 66,
        "FileHash-MD5": 79,
        "email": 5,
        "CVE": 4,
        "SSLCertFingerprint": 14
      },
      "indicator_count": 7448,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 232,
      "modified_text": "678 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6681f340f8c0223ae0ce199d",
      "name": "Bitdefender Ransomware| | Sony Music |  Lazarus Affiliated",
      "description": "",
      "modified": "2024-07-22T01:04:09.406000",
      "created": "2024-07-01T00:07:28.402000",
      "tags": [
        "url https",
        "url http",
        "active related",
        "pulses hostname",
        "ipv4",
        "showing",
        "entries",
        "active",
        "passive dns",
        "as2527 sony",
        "all scoreblue",
        "pulse pulses",
        "urls",
        "files",
        "reverse dns",
        "location chiba",
        "united",
        "unknown",
        "date",
        "moved",
        "search",
        "gmt content",
        "domain",
        "body",
        "encrypt",
        "as58061 scalaxy",
        "asn as58061",
        "dns resolutions",
        "expiration",
        "no expiration",
        "hostname",
        "iocs",
        "filehashsha256",
        "scan endpoints",
        "next",
        "report spam",
        "lazarus created",
        "minutes ago",
        "amber tags",
        "filehashsha1",
        "group",
        "tip oriented",
        "threat research",
        "android10",
        "type indicator",
        "role title",
        "creation date",
        "emails",
        "pulse submit",
        "url analysis",
        "germany unknown",
        "aaaa",
        "cname",
        "as209453 gandi",
        "as209453",
        "france unknown",
        "ireland unknown",
        "susp",
        "backdoor",
        "win32",
        "meta",
        "cookie",
        "pragma",
        "open ports",
        "as20940",
        "status",
        "certificate",
        "rsa sha256",
        "record value",
        "historical ssl",
        "referrer",
        "collection",
        "vt graph",
        "glaxosmithkline",
        "cyber threat",
        "heur",
        "phishing",
        "team",
        "malicious site",
        "control server",
        "coalition",
        "team phishing",
        "engineering",
        "emotet",
        "malware",
        "malicious",
        "download",
        "cobalt strike",
        "binder",
        "dropper",
        "formbook",
        "facebook",
        "artemis",
        "azorult",
        "bank",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "hostnames",
        "detection list",
        "blacklist",
        "a domains",
        "bitdefender",
        "leader",
        "as15133 verizon",
        "melbourne it",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "headers date",
        "gmt contenttype",
        "connection",
        "ip address",
        "web redirection",
        "sha1",
        "ascii text",
        "sha256",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "pattern match",
        "hybrid",
        "starfield",
        "format",
        "june",
        "local",
        "click",
        "strings",
        "contact",
        "loki"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
        "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
        "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
        "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
        "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
        "Server: Web redirection - http://loki.com/download",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
      ],
      "public": 1,
      "adversary": "Lazarus Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Win.Trojan.DarkKomet-1",
          "display_name": "Win.Trojan.DarkKomet-1",
          "target": null
        },
        {
          "id": "VirTool:Win32/CeeInject",
          "display_name": "VirTool:Win32/CeeInject",
          "target": "/malware/VirTool:Win32/CeeInject"
        },
        {
          "id": "Backdoor:MSIL/Bladabindi",
          "display_name": "Backdoor:MSIL/Bladabindi",
          "target": "/malware/Backdoor:MSIL/Bladabindi"
        },
        {
          "id": "Win32:Evo-gen",
          "display_name": "Win32:Evo-gen",
          "target": null
        },
        {
          "id": "Win32:Evo-gen\\ [Susp]",
          "display_name": "Win32:Evo-gen\\ [Susp]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [
        "Entertainment",
        "Technology",
        "Media"
      ],
      "TLP": "green",
      "cloned_from": "667648f0bc130bdaa294ea19",
      "export_count": 6847,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3528,
        "domain": 1453,
        "hostname": 1542,
        "FileHash-SHA256": 757,
        "FileHash-SHA1": 66,
        "FileHash-MD5": 79,
        "email": 5,
        "CVE": 4,
        "SSLCertFingerprint": 14
      },
      "indicator_count": 7448,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "678 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "bitdefender.fr",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "bitdefender.fr",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780210870.4917505
}