{
  "type": "Domain",
  "indicator": "blockstream.info",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/blockstream.info",
    "alexa": "http://www.alexa.com/siteinfo/blockstream.info",
    "indicator": "blockstream.info",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3351100288,
      "indicator": "blockstream.info",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "67dd90a215aee67faa59f106",
          "name": "Rilide: An Information Stealing Browser Extension",
          "description": "Rilide is an information stealer masquerading as a browser extension that is designed to steal personal information, log passwords and steal credentials for cryptocurrency wallets, according to research published by CyberChef.",
          "modified": "2025-04-20T16:04:48.699000",
          "created": "2025-03-21T16:15:30.763000",
          "tags": [
            "threat intelligence",
            "malware",
            "rilide",
            "powershell",
            "figure",
            "google drive",
            "vmray",
            "bitcoin address",
            "iocs",
            "cyberchef",
            "strong",
            "learn",
            "twitter",
            "april",
            "august",
            "dropper",
            "virustotal",
            "facebook",
            "restrict"
          ],
          "references": [
            "https://blog.pulsedive.com/rilide-an-information-stealing-browser-extension/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Rilide",
              "display_name": "Rilide",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "arringtont",
            "id": "6086",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_6086/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "URL": 14,
            "domain": 17,
            "hostname": 3
          },
          "indicator_count": 38,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 104,
          "modified_text": "405 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63a1e56b3622762b160953cf",
          "name": "Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain",
          "description": "Nozomi Networks provides a comprehensive guide to the best ways to close IoT security gaps in your operations. \u00c2\u00a31.5m of research, development and development in the UK, Ireland, Scotland and Wales.",
          "modified": "2022-12-20T16:40:11.795000",
          "created": "2022-12-20T16:40:11.795000",
          "tags": [
            "glupteba",
            "bitcoin address",
            "bitcoin",
            "google",
            "campaign",
            "xyzc2 domain",
            "november",
            "figure",
            "addressfirst",
            "nozomi networks",
            "june",
            "evolution",
            "virustotal",
            "february",
            "april",
            "malware"
          ],
          "references": [
            "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/"
          ],
          "public": 1,
          "adversary": "Glupteba",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Glupteba",
              "display_name": "Glupteba",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Cyber74Team",
            "id": "202637",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_202637/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 25,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "domain": 54
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 164,
          "modified_text": "1257 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63a06a51dd330cf876dbc282",
          "name": "Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain",
          "description": "Nozomi reports that the Glupteba malware botnet has sprung back into action, infecting devices worldwide after its operation was disrupted by Google almost a year ago.  Nozomi analysis reveals a new, large-scale Glupteba campaign that started in June 2022 and is still ongoing based on data from blockchain transactions, TLS certificate registrations and reverse engineering Glupteba samples.",
          "modified": "2022-12-19T13:42:41.740000",
          "created": "2022-12-19T13:42:41.740000",
          "tags": [
            "malware/glupteba"
          ],
          "references": [
            "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Glupteba",
              "display_name": "Glupteba",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 26,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "eric.ford",
            "id": "42510",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_42510/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 25,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "domain": 54
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 130,
          "modified_text": "1259 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63a01c1cbcffc92811696826",
          "name": "Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain",
          "description": "Find out more about Nozomi Networks, the UK-based company that provides solutions for OT and IoT security and management services for the pharmaceutical industry and other sectors, including oil and gas operations.",
          "modified": "2022-12-19T08:09:00.694000",
          "created": "2022-12-19T08:09:00.694000",
          "tags": [
            "glupteba",
            "bitcoin address",
            "bitcoin",
            "google",
            "campaign",
            "xyzc2 domain",
            "november",
            "figure",
            "addressfirst",
            "nozomi networks",
            "june",
            "evolution",
            "virustotal",
            "february",
            "april",
            "malware"
          ],
          "references": [
            "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/"
          ],
          "public": 1,
          "adversary": "Glupteba",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Glupteba",
              "display_name": "Glupteba",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 25,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "domain": 54
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1259 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "639ffce6a10024195feea5e5",
          "name": "Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain",
          "description": "Find out more about Nozomi Networks, the UK-based company that provides solutions for OT and IoT security and management services for the pharmaceutical industry and other sectors, including oil and gas operations.",
          "modified": "2022-12-19T05:55:50.112000",
          "created": "2022-12-19T05:55:50.112000",
          "tags": [
            "glupteba",
            "bitcoin address",
            "bitcoin",
            "google",
            "campaign",
            "xyzc2 domain",
            "november",
            "figure",
            "addressfirst",
            "nozomi networks",
            "june",
            "evolution",
            "virustotal",
            "february",
            "april",
            "malware"
          ],
          "references": [
            "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/"
          ],
          "public": 1,
          "adversary": "Glupteba",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Glupteba",
              "display_name": "Glupteba",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "nageswaran",
            "id": "61577",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 25,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "domain": 54
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 48,
          "modified_text": "1259 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/",
        "https://blog.pulsedive.com/rilide-an-information-stealing-browser-extension/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Glupteba"
          ],
          "malware_families": [
            "Glupteba",
            "Rilide"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "67dd90a215aee67faa59f106",
      "name": "Rilide: An Information Stealing Browser Extension",
      "description": "Rilide is an information stealer masquerading as a browser extension that is designed to steal personal information, log passwords and steal credentials for cryptocurrency wallets, according to research published by CyberChef.",
      "modified": "2025-04-20T16:04:48.699000",
      "created": "2025-03-21T16:15:30.763000",
      "tags": [
        "threat intelligence",
        "malware",
        "rilide",
        "powershell",
        "figure",
        "google drive",
        "vmray",
        "bitcoin address",
        "iocs",
        "cyberchef",
        "strong",
        "learn",
        "twitter",
        "april",
        "august",
        "dropper",
        "virustotal",
        "facebook",
        "restrict"
      ],
      "references": [
        "https://blog.pulsedive.com/rilide-an-information-stealing-browser-extension/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Rilide",
          "display_name": "Rilide",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1104",
          "name": "Multi-Stage Channels",
          "display_name": "T1104 - Multi-Stage Channels"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "arringtont",
        "id": "6086",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_6086/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 1,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "URL": 14,
        "domain": 17,
        "hostname": 3
      },
      "indicator_count": 38,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 104,
      "modified_text": "405 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63a1e56b3622762b160953cf",
      "name": "Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain",
      "description": "Nozomi Networks provides a comprehensive guide to the best ways to close IoT security gaps in your operations. \u00c2\u00a31.5m of research, development and development in the UK, Ireland, Scotland and Wales.",
      "modified": "2022-12-20T16:40:11.795000",
      "created": "2022-12-20T16:40:11.795000",
      "tags": [
        "glupteba",
        "bitcoin address",
        "bitcoin",
        "google",
        "campaign",
        "xyzc2 domain",
        "november",
        "figure",
        "addressfirst",
        "nozomi networks",
        "june",
        "evolution",
        "virustotal",
        "february",
        "april",
        "malware"
      ],
      "references": [
        "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/"
      ],
      "public": 1,
      "adversary": "Glupteba",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Glupteba",
          "display_name": "Glupteba",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Cyber74Team",
        "id": "202637",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_202637/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 25,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "domain": 54
      },
      "indicator_count": 82,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 164,
      "modified_text": "1257 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63a06a51dd330cf876dbc282",
      "name": "Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain",
      "description": "Nozomi reports that the Glupteba malware botnet has sprung back into action, infecting devices worldwide after its operation was disrupted by Google almost a year ago.  Nozomi analysis reveals a new, large-scale Glupteba campaign that started in June 2022 and is still ongoing based on data from blockchain transactions, TLS certificate registrations and reverse engineering Glupteba samples.",
      "modified": "2022-12-19T13:42:41.740000",
      "created": "2022-12-19T13:42:41.740000",
      "tags": [
        "malware/glupteba"
      ],
      "references": [
        "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Glupteba",
          "display_name": "Glupteba",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 26,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "eric.ford",
        "id": "42510",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_42510/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 25,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "domain": 54
      },
      "indicator_count": 82,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 130,
      "modified_text": "1259 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63a01c1cbcffc92811696826",
      "name": "Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain",
      "description": "Find out more about Nozomi Networks, the UK-based company that provides solutions for OT and IoT security and management services for the pharmaceutical industry and other sectors, including oil and gas operations.",
      "modified": "2022-12-19T08:09:00.694000",
      "created": "2022-12-19T08:09:00.694000",
      "tags": [
        "glupteba",
        "bitcoin address",
        "bitcoin",
        "google",
        "campaign",
        "xyzc2 domain",
        "november",
        "figure",
        "addressfirst",
        "nozomi networks",
        "june",
        "evolution",
        "virustotal",
        "february",
        "april",
        "malware"
      ],
      "references": [
        "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/"
      ],
      "public": 1,
      "adversary": "Glupteba",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Glupteba",
          "display_name": "Glupteba",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 25,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "domain": 54
      },
      "indicator_count": 82,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "1259 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "639ffce6a10024195feea5e5",
      "name": "Nozomi Networks Researchers Track Malicious Glupteba Activity Through the Blockchain",
      "description": "Find out more about Nozomi Networks, the UK-based company that provides solutions for OT and IoT security and management services for the pharmaceutical industry and other sectors, including oil and gas operations.",
      "modified": "2022-12-19T05:55:50.112000",
      "created": "2022-12-19T05:55:50.112000",
      "tags": [
        "glupteba",
        "bitcoin address",
        "bitcoin",
        "google",
        "campaign",
        "xyzc2 domain",
        "november",
        "figure",
        "addressfirst",
        "nozomi networks",
        "june",
        "evolution",
        "virustotal",
        "february",
        "april",
        "malware"
      ],
      "references": [
        "https://www.nozominetworks.com/blog/tracking-malicious-glupteba-activity-through-the-blockchain/"
      ],
      "public": 1,
      "adversary": "Glupteba",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Glupteba",
          "display_name": "Glupteba",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "nageswaran",
        "id": "61577",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 25,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "domain": 54
      },
      "indicator_count": 82,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 48,
      "modified_text": "1259 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "blockstream.info",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "blockstream.info",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780237644.6743555
}