{
  "type": "Domain",
  "indicator": "cable-modem.org",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/cable-modem.org",
    "alexa": "http://www.alexa.com/siteinfo/cable-modem.org",
    "indicator": "cable-modem.org",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 102073652,
      "indicator": "cable-modem.org",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 12,
      "pulses": [
        {
          "id": "6998f7aa0bbea2bda9d216b5",
          "name": "no-ip",
          "description": "",
          "modified": "2026-05-18T20:26:39.259000",
          "created": "2026-02-21T00:09:14.394000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 93
          },
          "indicator_count": 93,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "14 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69de16ad2eff99041dc0798f",
          "name": "CAPE Sandbox",
          "description": "The full text of the full report on the events of 9 January 2016:-17 February 2017.. and the details will appear on Facebook, Twitter, Instagram and iPlayer, as well as BBC News.Publicly sourced data.",
          "modified": "2026-05-14T13:12:04.466000",
          "created": "2026-04-14T10:27:57.413000",
          "tags": [
            "default",
            "win1",
            "acrongl integ",
            "adc4240758",
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "angsana new",
            "accept",
            "shutdown",
            "bits",
            "users",
            "files c",
            "registry keys",
            "parent pid",
            "full path",
            "command line",
            "mutexes nothing",
            "settings c",
            "users c",
            "file type",
            "ascii text",
            "html document",
            "ascii",
            "smtp",
            "united",
            "pe file",
            "ms windows",
            "found",
            "pe32",
            "exploit",
            "window",
            "mydoom",
            "malicious",
            "next",
            "windows sandbox",
            "calls process"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776161759&Signature=r%2BKlsLyBnYpOeeNHzRs9%2B7pdGx2v0X0pOyuXLCoa%2BnUPUCVB26zsfTA6MkxYVG1EJEHvnIlhFuROVrTGOBD3iJ8Pi88PQMXIZ3v2jPn9uE50%2B7sfn3PB%2FD2SBG1luKM%2BcX4xmmAa9lBeO4YV7eHLZRuujfrNAD1p7ibfanLrhtk7C%2BooBJ%2BBrhzZgQiVRPozazGmTh0p9ZDu5uwqfnNncRfsUH3MC2DU7%2F2lLeIXl2i4",
            "https://vtbehaviour.commondatastorage.googleapis.com/19a366688d6cbe45c99c2eb49ae11f06ac85a63b83753bdae693ba36032dbc3f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162253&Signature=DsUEk3x0D0tLMeH64e%2BL%2BU0fmDQgZPub6sr2i81od6MJcTmkUHTvUwY4TX7A4UF7CHp6x9os7H6ACU0L6ZaarkQrPNm5dsT7lulfOTfMO4b8%2B9vETdbWgCFKDoxSh1JDRedcaByU9eHDx1EubCyeCzVwlhIQD6DY731Nqnbs%2FbM6xAvxXIrjJXGTEIhmWk2rwD9E7fIYWKxJ3PIwdd9LxuRcfsiqFrEfxSfL%2FhCUtkAzP9VJk%2B",
            "https://vtbehaviour.commondatastorage.googleapis.com/19a366688d6cbe45c99c2eb49ae11f06ac85a63b83753bdae693ba36032dbc3f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162273&Signature=sHM7md8FG3NGW4EaoHgxxJxesr%2BwB7HqWHK1D3tULtGS5B9x6lSEfz%2F7oBPbC%2FW1AjBMAQvDCNRY5nUYvLs9v1lyCmWTdlaXzqGLXKKucME3uJxTnsyz%2BD1NufC0hBTMCOi72Sr8g6t%2Fs0AUKgWVoI%2FzNNPjkBnA8yhuPJDg%2FagW1ZWHbCCmuvDq89e7cuw7zAwSyLYepQaw6NwWxkbXxbLmCPt8NgH1FxvePXTh2u6kEBUkC3rfaYMz",
            "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162432&Signature=TWbtmQs4bcHbMfmTekVuORg%2BkrtroxYd8P8uC5usycoJ%2BB%2FHow0wKjA9ZjhOZxjEmMD0SR0LJtJtz9WjU4Bo%2BUGImGkUS%2BpVWmWEUlAnFAifUeH4f5YQ%2F6cNsYropo5WcFbSSs5CBkVFTFkx0oi7v6eoTVbSOB6ZuXf3th4SLotta8FcMAzmgs6224SExEQaOgbe8HNnU%2F7BqF5906uMA793JnqbInA83%2BrUvFoO1vo3f%",
            "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162454&Signature=s%2FL8LyYQ5ohWNf8k%2F4%2BjtOHEZw%2FPBQ50rPOAG6qtrJE1i6GAlRl5exjz0kySLyFUjqw1a%2BRmbp%2BGOUpGT1lFr%2FJQ6MrmypYvlc6FB451hDVD6FGhK1ux%2FDBdqi3jA5ZcM0TBp9nG%2FzUmdBcnXGtpTT6vgdZpgZT6%2FcaTnDSXLieEgVqCAgVX%2FZFQg3ZVxCBndzTcuRqQmR2axdb1QaRQ%2BIFIaYonKsJt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 294,
            "FileHash-SHA1": 122,
            "FileHash-SHA256": 1747,
            "URL": 5866,
            "hostname": 1673,
            "domain": 432,
            "CVE": 1,
            "email": 2
          },
          "indicator_count": 10137,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "19 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68d332d77a7eedf3ad71c406",
          "name": "Denizbankk.net \u2022  LevelBlue - Open Threat Exchange",
          "description": "Denizbankk.net \u2022 Debian.org \u2022 hallrender.com \u2022 alienvault.com \u2022 hopto.org \u2022 striven.com| ? | This is concerning. It\u2019s not like intended to find what I have found but I am disappointed. The few people on the platform who do their own research eventually leave with a large amount of reposters. Related to haallrendee, brian sabey and each link listed. Stange happenings this weak. [otx auto populated- Google Safe Browsing, Denizbankk.net, has been used by the Russian government to create a secure web address that can be accessed only if the user has the correct address.{",
          "modified": "2025-10-23T23:03:23.167000",
          "created": "2025-09-23T23:52:55.453000",
          "tags": [
            "log id",
            "gmtn",
            "tls web",
            "zerossl",
            "zerossl rsa",
            "domain secure",
            "site ca",
            "fa c7",
            "ocsp",
            "a167",
            "code",
            "keepalive",
            "false",
            "record type",
            "ttl a",
            "value",
            "o jarm",
            "fingerprint",
            "file format",
            "relevance",
            "united",
            "tempe",
            "arizona create",
            "domain",
            "expiry date",
            "name",
            "query time",
            "technical city",
            "tempe technical",
            "technical state",
            "rdap database",
            "handle",
            "iana registrar",
            "links",
            "algorithm",
            "key identifier",
            "data",
            "v3 serial",
            "number",
            "cat ozerossl",
            "cnzerossl rsa",
            "validity",
            "server",
            "domain name",
            "status",
            "abuse contact",
            "email",
            "registrar abuse",
            "contact phone",
            "registrar iana",
            "registrar url",
            "registrar whois",
            "date",
            "available from",
            "country",
            "proxy",
            "postal code",
            "city",
            "admin city",
            "tempe admin",
            "filehashmd5",
            "url https",
            "filehashsha1",
            "url http",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "filehashsha256",
            "showing",
            "germany unknown",
            "passive dns",
            "entries",
            "a domains",
            "body doctype",
            "content type",
            "gmt server",
            "ipv4 add",
            "pulse submit",
            "url analysis",
            "main",
            "apache",
            "accept",
            "title",
            "present dec",
            "present jun",
            "present nov",
            "aaaa",
            "present feb",
            "present sep",
            "search",
            "canada",
            "encrypt",
            "devam",
            "ad soyad",
            "mteri numaras",
            "gvenlik iin",
            "gizli soru",
            "gvenlik sorusu",
            "cevab",
            "ltfen bir",
            "present may",
            "moved",
            "present oct",
            "ip address",
            "gandi sas",
            "body",
            "backdoor",
            "next associated",
            "trojandropper",
            "fastly error",
            "please",
            "sea p",
            "twitter",
            "win32",
            "creation date",
            "name servers",
            "hostname add",
            "pulse pulses",
            "urls",
            "record value",
            "japan",
            "germany",
            "ipv4",
            "countries",
            "america",
            "netherlands",
            "italy",
            "brian sabey",
            "report spam",
            "tsara brashears",
            "created",
            "days ago",
            "green well",
            "sabey stash",
            "service",
            "hours ago",
            "malicious",
            "forbidden",
            "actionlistccc",
            "malware family",
            "mufanom att",
            "capture",
            "ck ids",
            "checkin",
            "t1036",
            "t1055",
            "injection",
            "t1056"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1410",
              "name": "Network Traffic Capture or Redirection",
              "display_name": "T1410 - Network Traffic Capture or Redirection"
            },
            {
              "id": "T1448",
              "name": "Carrier Billing Fraud",
              "display_name": "T1448 - Carrier Billing Fraud"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 617,
            "URL": 2495,
            "hostname": 1698,
            "FileHash-MD5": 275,
            "FileHash-SHA1": 265,
            "FileHash-SHA256": 1241,
            "SSLCertFingerprint": 2,
            "email": 4
          },
          "indicator_count": 6597,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 144,
          "modified_text": "221 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68d3368ae75cccf736a55441",
          "name": "ET TROJAN Hiloti/Mufanom Downloader Checkin | Denizbankk.net",
          "description": "",
          "modified": "2025-10-23T23:03:23.167000",
          "created": "2025-09-24T00:08:42.048000",
          "tags": [
            "log id",
            "gmtn",
            "tls web",
            "zerossl",
            "zerossl rsa",
            "domain secure",
            "site ca",
            "fa c7",
            "ocsp",
            "a167",
            "code",
            "keepalive",
            "false",
            "record type",
            "ttl a",
            "value",
            "o jarm",
            "fingerprint",
            "file format",
            "relevance",
            "united",
            "tempe",
            "arizona create",
            "domain",
            "expiry date",
            "name",
            "query time",
            "technical city",
            "tempe technical",
            "technical state",
            "rdap database",
            "handle",
            "iana registrar",
            "links",
            "algorithm",
            "key identifier",
            "data",
            "v3 serial",
            "number",
            "cat ozerossl",
            "cnzerossl rsa",
            "validity",
            "server",
            "domain name",
            "status",
            "abuse contact",
            "email",
            "registrar abuse",
            "contact phone",
            "registrar iana",
            "registrar url",
            "registrar whois",
            "date",
            "available from",
            "country",
            "proxy",
            "postal code",
            "city",
            "admin city",
            "tempe admin",
            "filehashmd5",
            "url https",
            "filehashsha1",
            "url http",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "filehashsha256",
            "showing",
            "germany unknown",
            "passive dns",
            "entries",
            "a domains",
            "body doctype",
            "content type",
            "gmt server",
            "ipv4 add",
            "pulse submit",
            "url analysis",
            "main",
            "apache",
            "accept",
            "title",
            "present dec",
            "present jun",
            "present nov",
            "aaaa",
            "present feb",
            "present sep",
            "search",
            "canada",
            "encrypt",
            "devam",
            "ad soyad",
            "mteri numaras",
            "gvenlik iin",
            "gizli soru",
            "gvenlik sorusu",
            "cevab",
            "ltfen bir",
            "present may",
            "moved",
            "present oct",
            "ip address",
            "gandi sas",
            "body",
            "backdoor",
            "next associated",
            "trojandropper",
            "fastly error",
            "please",
            "sea p",
            "twitter",
            "win32",
            "creation date",
            "name servers",
            "hostname add",
            "pulse pulses",
            "urls",
            "record value",
            "japan",
            "germany",
            "ipv4",
            "countries",
            "america",
            "netherlands",
            "italy",
            "brian sabey",
            "report spam",
            "tsara brashears",
            "created",
            "days ago",
            "green well",
            "sabey stash",
            "service",
            "hours ago",
            "malicious",
            "forbidden",
            "actionlistccc",
            "malware family",
            "mufanom att",
            "capture",
            "ck ids",
            "checkin",
            "t1036",
            "t1055",
            "injection",
            "t1056"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1410",
              "name": "Network Traffic Capture or Redirection",
              "display_name": "T1410 - Network Traffic Capture or Redirection"
            },
            {
              "id": "T1448",
              "name": "Carrier Billing Fraud",
              "display_name": "T1448 - Carrier Billing Fraud"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "68d332d77a7eedf3ad71c406",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 617,
            "URL": 2495,
            "hostname": 1698,
            "FileHash-MD5": 275,
            "FileHash-SHA1": 265,
            "FileHash-SHA256": 1241,
            "SSLCertFingerprint": 2,
            "email": 4
          },
          "indicator_count": 6597,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 141,
          "modified_text": "221 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6775b17c488523ee9d290afd",
          "name": "agressive extra",
          "description": "",
          "modified": "2025-03-17T22:57:49.933000",
          "created": "2025-01-01T21:19:56.847000",
          "tags": [],
          "references": [
            "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 35208,
            "URL": 79504,
            "domain": 19527,
            "hostname": 28058,
            "CVE": 9
          },
          "indicator_count": 162306,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 207,
          "modified_text": "441 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c76a410bca940a8cb84f91",
          "name": "Remote Access - Dynamic DNS  | Injection",
          "description": "Blamed for Botnet exchange, Ddos, ssh, email spamming, brute forcing emails, sending viruses/trojans to countless emails, injection, app installation, gov , bank employee targeting, etc. Listed ALL victim information in downed WikiLeaks website.The list is long, Swipper is still a mystery. The name has been linked to an IT graduate. This doesn't mean much as hackers frame everyone. The [person or links to does link back to subject of hacks against a targeted person. When target researched Swipper EVERYTHING related was cleaned from the Internet.\n\nThe best clue deleted was for IP's in the 152.199.0.0/24 Block. \nThe other was used by Brian Sabey who used service to distribute So much porn (and worse) all with targets name! It was a 'hopto' N\u2205 IP address. It disappeared so fast along with any  trace.",
          "modified": "2024-09-21T14:04:09.409000",
          "created": "2024-08-22T16:41:37.285000",
          "tags": [
            "referrer",
            "nanocore rat",
            "hunting guide",
            "your apt",
            "malware",
            "bitter apt",
            "using zxxz",
            "backdoor",
            "pakistan public",
            "committee",
            "ukraine",
            "maxage7200",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "dynamic dns",
            "access",
            "html info",
            "title remote",
            "ddns account",
            "meta tags",
            "ip address",
            "trackers amazon",
            "tag manager",
            "cookies noipbid",
            "netrange",
            "nethandle",
            "net152",
            "net1520000",
            "as1321",
            "inc orgid",
            "loudoun county",
            "parkway city",
            "postalcode",
            "content",
            "utc google",
            "gtmvfgb",
            "utc ggg8ybn7flc",
            "gg8ybn7flc",
            "samples",
            "no data",
            "tag count",
            "analyzer threat",
            "ip summary",
            "summary",
            "detection list",
            "heur",
            "malicious site",
            "malicious host",
            "services",
            "exchange botnet",
            "command",
            "control server",
            "host",
            "azorult",
            "pony",
            "asyncrat",
            "cobalt strike",
            "phishing",
            "team",
            "dropper",
            "crypt",
            "outbreak",
            "mimikatz",
            "riskware",
            "trojanx",
            "cisco umbrella",
            "site",
            "safe site",
            "redline stealer",
            "generic pua",
            "malware site",
            "utorrent",
            "generic",
            "yakes",
            "agent",
            "adposhel",
            "zbot",
            "cl0p",
            "managed dns",
            "strong",
            "noip",
            "please",
            "buy plus",
            "managed",
            "free",
            "service",
            "already",
            "read c",
            "dll read",
            "function read",
            "medium",
            "systemroot",
            "search",
            "high",
            "smtp host",
            "virustotal",
            "trojan",
            "write",
            "drweb",
            "vipre",
            "panda",
            "phishing",
            "ransomware",
            "rat",
            "swipper",
            "swipp9",
            "vj92",
            "uagdaaeqcqaaaag",
            "ukgbagaqcqaaaae",
            "slfrd1",
            "hostnames",
            "ukgbagaqcq",
            "jid1886833764",
            "jid882556742",
            "unknown",
            "as36947",
            "algeria unknown",
            "germany unknown",
            "as37340",
            "nigeria unknown",
            "united kingdom",
            "as200350",
            "france unknown",
            "date",
            "z557338487",
            "z129433407",
            "z2111579734",
            "name servers",
            "passive dns",
            "as14627",
            "scan endpoints",
            "all scoreblue",
            "next",
            "aaaa",
            "asnone united",
            "moved",
            "certificate",
            "rsa ca",
            "ipv4",
            "pulse pulses",
            "win32",
            "process32nextw",
            "onlogon ru",
            "discovery",
            "t1057",
            "discovery t1057",
            "windows",
            "post http",
            "actionhello",
            "delphi",
            "dock",
            "memcommit",
            "writeconsolea",
            "nat monitor",
            "f tn",
            "delete c",
            "write c",
            "create c",
            "autoit",
            "look",
            "suspicious",
            "as9009 m247",
            "sri lanka",
            "domain",
            "creation date",
            "hungary unknown",
            "as36352",
            "files",
            "hosting",
            "reverse dns",
            "all search",
            "otx scoreblue",
            "hostname",
            "pulse submit",
            "url analysis",
            "status",
            "mtb sep",
            "record value",
            "servers",
            "gmt server",
            "pecancer",
            "as15169 google",
            "mtb apr",
            "open ports",
            "trojandropper",
            "gmt cache",
            "cashreminder",
            "philadelphia",
            "status hostname",
            "query type",
            "address first",
            "seen last",
            "seen asn",
            "country unknown",
            "nxdomain",
            "a nxdomain",
            "encrypt",
            "body",
            "present mar",
            "emails",
            "domain name",
            "expiration date",
            "error",
            "code",
            "location united",
            "united states",
            "malicious.75188e",
            "united",
            "icmp traffic",
            "pe section",
            "low software",
            "packing t1045",
            "t1045",
            "pe resource",
            "filehash",
            "ireland unknown",
            "as396982 google",
            "belgium unknown",
            "as24940 hetzner",
            "trojan process",
            "file samples",
            "files matching",
            "show",
            "date hash",
            "worm features",
            "related pulses",
            "malware process",
            "trojan features",
            "brute force",
            "brute forcing emails",
            "hacking",
            "logan utah",
            "ddos attack",
            "web app attacks",
            "bad web bot",
            "cwaf",
            "verizon enterprise"
          ],
          "references": [
            "Title: The page title. Remote Access - Dynamic DNS - Create a Free DDNS Account Now - No-IP",
            "http://hopto.org/colocrossing/192.3.13.56/telco",
            "N\u2205 IP: https://otx.alienvault.com/otxapi/indicators/url/screenshot/http://hopto.org/colocrossing/192.3.13.56/telco",
            "SLF:Trojan:Win32/Grandoreiro.A - FILEHASH - SHA256 5253cfaec7456b9fe440ab25207b8e1ff948b04fc2f2f34befc2354bf4431d07",
            "FILEHASH - SHA256 253cfaec7456b9fe440ab25207b8e1ff948b04fc2f2f34befc2354bf4431d07  |  IP\u2019s Contacted: 34.117.59.81",
            "Malicious Antivirus Detections SLF:Trojan:Win32/Grandoreiro.A  Yara Detections md5_constants ,  Delphi ,",
            "IDS Defections: Possible Cerber Ransomware IP Check Possible ET INFO RealThinClient Session Init",
            "IDS Defections: Possible External IP Lookup ipinfo.io DNS Query to DynDNS Domain *.ddns .me",
            "Alerts: network_icmp antianalysis_detectfile antidbg_windows antivm_generic_scsi",
            "Alerts: sysinternals_tools_usage antivm_vmware_in_instruction persistence_autorun",
            "Yara Detections: XOR_embeded_exefile_xored_with_round_256_bytes_key",
            "Malware.Nymeria-6993588-0: FileHash-SHA256 9dddb78cec49c05f2bec6f2583e4d8a663435f5a265a09a5966d5d4bfa866761",
            "NanoCore RAT CnC 7 : FileHash-SHA256 0031cb925e76f801a0ca2ebbc32029be927687f0d6183777be917878ffd7cd4b",
            "CVE-2023-23397 | scanning_host IPv4 158.247.7.206 scanning_host IP's: 192.3.13.56  158.247.7.206",
            "Whois-RWS ; Name, SWIPPER ; Handle, SWIPP9-ARIN ; Company, Verizon ; Street, 22001 Loudoun County Pkwy.",
            "Whois-RWS ; Name, SWIPPER ; Handle, SWIPP9-ARIN ; Company, Verizon ; Street, 22001",
            "Is Swipper: pool-70-21-23-161.washdc.fios.verizon.net",
            "SWIPPER - IP: 152.199.161.19  ISP Edgecast Inc. Content Delivery Network Domain Name edgecast.com Los Angeles, California",
            "SWIPPER - IP: 152.199.161.19 - Florence, Co related",
            "SWIPPER - ISP: WS/Acs Inc/Acs  Usage Type:University/College/School Domain Name: acs-inc.com Pittsburgh, Pennsylvania",
            "SWIPPER Behavior: Brute-Force Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc.",
            "SWIPPER Behavior: Category is seperate from DDoS attacks. Bad Web Bot Web App Attack",
            "Confirmed Malware:  Cl0p QVM41.1.083F.Malware SLF:Trojan:Win32/Grandoreiro VirTool:Win32/Injector",
            "Confirmed Malware: Trojan:Win/Zombie Trojan:Win32/AutoitInject Trojan:Win32/Glupteba Trojan:Win32/QQpass",
            "Confirmed Malware: Trojan:Win32/Zbot TrojanDropper:Win32/Muldrop Worm:Win32/Mofksys",
            "Command and Control: 208.95.112.1  |  34.154.67.14",
            "https://www.colocrossing.com/",
            "American Registry for Internet Numbers (ARIN) http://www.arin.net \u203a cgi-bin \u203a Who is RWS",
            "https://whois.arin.net/rest/net/NET-71-96-0-0-1/pft?s=71.106.106.47"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Cl0p",
              "display_name": "Cl0p",
              "target": null
            },
            {
              "id": "SLF:Trojan:Win32/Grandoreiro",
              "display_name": "SLF:Trojan:Win32/Grandoreiro",
              "target": null
            },
            {
              "id": "QVM41.1.083F.Malware",
              "display_name": "QVM41.1.083F.Malware",
              "target": null
            },
            {
              "id": "Trojan:Win32/Glupteba",
              "display_name": "Trojan:Win32/Glupteba",
              "target": "/malware/Trojan:Win32/Glupteba"
            },
            {
              "id": "Worm:Win32/Mofksys",
              "display_name": "Worm:Win32/Mofksys",
              "target": "/malware/Worm:Win32/Mofksys"
            },
            {
              "id": "TrojanDropper:Win32/Muldrop",
              "display_name": "TrojanDropper:Win32/Muldrop",
              "target": "/malware/TrojanDropper:Win32/Muldrop"
            },
            {
              "id": "Trojan:Win32/Zbot",
              "display_name": "Trojan:Win32/Zbot",
              "target": "/malware/Trojan:Win32/Zbot"
            },
            {
              "id": "Trojan:Win32/QQpass",
              "display_name": "Trojan:Win32/QQpass",
              "target": "/malware/Trojan:Win32/QQpass"
            },
            {
              "id": "Trojan:Win/Zombie",
              "display_name": "Trojan:Win/Zombie",
              "target": "/malware/Trojan:Win/Zombie"
            },
            {
              "id": "Trojan:Win32/AutoitInject",
              "display_name": "Trojan:Win32/AutoitInject",
              "target": "/malware/Trojan:Win32/AutoitInject"
            },
            {
              "id": "VirTool:Win32/Injector",
              "display_name": "VirTool:Win32/Injector",
              "target": "/malware/VirTool:Win32/Injector"
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1110.004",
              "name": "Credential Stuffing",
              "display_name": "T1110.004 - Credential Stuffing"
            },
            {
              "id": "T1584.005",
              "name": "Botnet",
              "display_name": "T1584.005 - Botnet"
            },
            {
              "id": "T1037",
              "name": "Boot or Logon Initialization Scripts",
              "display_name": "T1037 - Boot or Logon Initialization Scripts"
            },
            {
              "id": "T1102.002",
              "name": "Bidirectional Communication",
              "display_name": "T1102.002 - Bidirectional Communication"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "T1444",
              "name": "Masquerade as Legitimate Application",
              "display_name": "T1444 - Masquerade as Legitimate Application"
            },
            {
              "id": "T1037.003",
              "name": "Network Logon Script",
              "display_name": "T1037.003 - Network Logon Script"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0010",
              "name": "Exfiltration",
              "display_name": "TA0010 - Exfiltration"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1147",
              "name": "Hidden Users",
              "display_name": "T1147 - Hidden Users"
            },
            {
              "id": "T1098.002",
              "name": "Exchange Email Delegate Permissions",
              "display_name": "T1098.002 - Exchange Email Delegate Permissions"
            },
            {
              "id": "T1460",
              "name": "Biometric Spoofing",
              "display_name": "T1460 - Biometric Spoofing"
            },
            {
              "id": "T1205.001",
              "name": "Port Knocking",
              "display_name": "T1205.001 - Port Knocking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [
            "Technology",
            "Telecommunications",
            "Civilian Society",
            "Any"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 53,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 546,
            "FileHash-MD5": 1677,
            "FileHash-SHA1": 1288,
            "FileHash-SHA256": 1385,
            "CVE": 1,
            "domain": 404,
            "hostname": 591,
            "CIDR": 3,
            "email": 12
          },
          "indicator_count": 5907,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "619 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6303290568240f6ed1285370",
          "name": "New Grandoreiro Banking Malware Campaign Targeting Spanish Manufacturers",
          "description": "Organizations in the Spanish-speaking nations of Mexico and Spain are in the crosshairs of a new campaign designed to deliver the Grandoreiro banking trojan.\n\n\"In this campaign, the threat actors impersonate government officials from the Attorney General's Office of Mexico City and from the Public Ministry in the form of spear-phishing emails in order to lure victims to download and execute 'Grandoreiro,' a prolific banking trojan that has been active since at least 2016, and that specifically targets users in Latin America,\" Zscaler said in a report.",
          "modified": "2022-09-21T00:02:24.222000",
          "created": "2022-08-22T06:58:13.526000",
          "tags": [
            "grandoreiro",
            "latentbot",
            "grandoreiro banking",
            "spear phishing",
            "banking",
            "malware",
            "government",
            "mexico",
            "spain",
            "trojan",
            "banking trojan",
            "threatintel",
            "threats",
            "payload",
            "resolution",
            "english",
            "zip file",
            "pmsubject",
            "delphi",
            "actionhello",
            "june",
            "path",
            "loader",
            "general",
            "class",
            "tools",
            "next",
            "crypto",
            "sandbox"
          ],
          "references": [
            "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals",
            "https://thehackernews.com/2022/08/new-grandoreiro-banking-malware.html"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Spain",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "LatentBot",
              "display_name": "LatentBot",
              "target": null
            },
            {
              "id": "Grandoreiro",
              "display_name": "Grandoreiro",
              "target": null
            },
            {
              "id": "Grandoreiro Banking",
              "display_name": "Grandoreiro Banking",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Logistics",
            "Construction",
            "Industrial",
            "Automotive",
            "Manufacturing"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 351,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dekaRituraj",
            "id": "99856",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_99856/resized/80/avatar_0e93d502b7.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 5,
            "URL": 8,
            "domain": 12,
            "hostname": 5
          },
          "indicator_count": 31,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 436,
          "modified_text": "1350 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "630333d999f50875b5504dfa",
          "name": "Grandoreiro Malware with New TTPs",
          "description": "Zscaler is the world\u2019s largest security platform built for the cloud and provides a platform that delivers zero trust and delivers the best experience possible for users, businesses, and government alike.",
          "modified": "2022-09-21T00:02:24.222000",
          "created": "2022-08-22T07:44:25.632000",
          "tags": [
            "grandoreiro",
            "latentbot",
            "grandoreiro banking",
            "spear phishing",
            "banking",
            "malware",
            "government",
            "mexico",
            "spain",
            "trojan",
            "banking trojan",
            "threatintel",
            "threats",
            "payload",
            "resolution",
            "english",
            "zip file",
            "pmsubject",
            "delphi",
            "actionhello",
            "june",
            "path",
            "loader",
            "general",
            "class",
            "tools",
            "next",
            "crypto",
            "sandbox"
          ],
          "references": [
            "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Spain",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "LatentBot",
              "display_name": "LatentBot",
              "target": null
            },
            {
              "id": "Grandoreiro",
              "display_name": "Grandoreiro",
              "target": null
            },
            {
              "id": "Grandoreiro Banking",
              "display_name": "Grandoreiro Banking",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Logistics",
            "Construction",
            "Industrial",
            "Automotive",
            "Manufacturing"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 6,
            "URL": 19,
            "CVE": 1,
            "FileHash-MD5": 5,
            "domain": 12
          },
          "indicator_count": 43,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "1350 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63037dcc6c6d01768ea3563b",
          "name": "Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals",
          "description": "Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals",
          "modified": "2022-09-21T00:02:24.222000",
          "created": "2022-08-22T12:59:56.515000",
          "tags": [
            "grandoreiro",
            "latentbot",
            "grandoreiro banking",
            "spear phishing",
            "banking",
            "malware",
            "government",
            "mexico",
            "spain",
            "trojan",
            "banking trojan",
            "threatintel",
            "threats",
            "payload",
            "resolution",
            "english",
            "zip file",
            "pmsubject",
            "delphi",
            "actionhello",
            "june",
            "path",
            "loader",
            "general",
            "class",
            "tools",
            "next",
            "crypto",
            "sandbox",
            "threat analysis",
            "cyber security news",
            "cyber news",
            "cyber security news today",
            "cyber security updates",
            "cyber updates",
            "hacker news",
            "hacking news",
            "software vulnerability",
            "cyber attacks",
            "data breach",
            "ransomware malware",
            "how to hack",
            "network security",
            "information security",
            "the hacker news",
            "computer security",
            "bumblebee",
            "trickbot",
            "cybereason",
            "bazarloader",
            "icedid",
            "alon laufer",
            "march",
            "google",
            "group",
            "conti",
            "cobalt strike",
            "anydesk",
            "facebook",
            "twitter"
          ],
          "references": [
            "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals"
          ],
          "public": 1,
          "adversary": "Threat Analysis",
          "targeted_countries": [
            "Spain",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "LatentBot",
              "display_name": "LatentBot",
              "target": null
            },
            {
              "id": "Grandoreiro",
              "display_name": "Grandoreiro",
              "target": null
            },
            {
              "id": "Grandoreiro Banking",
              "display_name": "Grandoreiro Banking",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Logistics",
            "Construction",
            "Industrial",
            "Automotive",
            "Manufacturing"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "KernelSanders",
            "id": "73862",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 5,
            "URL": 8,
            "domain": 12,
            "hostname": 5
          },
          "indicator_count": 31,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 42,
          "modified_text": "1350 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6303ca72fe01b5fe1719f042",
          "name": "Grandoreiro Banking Trojan with New TTPs | Zscaler Blog",
          "description": "In this campaign, the threat actors impersonate government officials from the Attorney General\u2019s Office of Mexico City and from the Public Ministry in the form of spear-phishing emails in order to lure victims to download and execute \u201cGrandoreiro\u201d a prolific banking trojan that has been active since at least 2016, and that specifically targets users in Latin America",
          "modified": "2022-09-21T00:02:24.222000",
          "created": "2022-08-22T18:26:58.520000",
          "tags": [
            "Trojan",
            "Phishing",
            "LatentBot",
            "CnC",
            "KeyLogger",
            "BankingTrojan"
          ],
          "references": [
            "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Spain",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "LatentBot",
              "display_name": "LatentBot",
              "target": null
            },
            {
              "id": "Grandoreiro",
              "display_name": "Grandoreiro",
              "target": null
            },
            {
              "id": "Grandoreiro Banking",
              "display_name": "Grandoreiro Banking",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Logistics",
            "Construction",
            "Industrial",
            "Automotive",
            "Manufacturing"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "jgomez1677",
            "id": "99942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 5,
            "URL": 2,
            "domain": 11,
            "hostname": 5
          },
          "indicator_count": 24,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 35,
          "modified_text": "1350 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62ff3289f51ef80978e45787",
          "name": "Grandoreiro Malware with New TTPs",
          "description": "Zscaler is the world\u2019s largest security platform built for the cloud and provides a platform that delivers zero trust and delivers the best experience possible for users, businesses, and government alike.",
          "modified": "2022-09-18T00:03:55.814000",
          "created": "2022-08-19T06:49:45.441000",
          "tags": [
            "grandoreiro",
            "latentbot",
            "grandoreiro banking",
            "spear phishing",
            "banking",
            "malware",
            "government",
            "mexico",
            "spain",
            "trojan",
            "banking trojan",
            "threatintel",
            "threats",
            "payload",
            "resolution",
            "english",
            "zip file",
            "pmsubject",
            "delphi",
            "actionhello",
            "june",
            "path",
            "loader",
            "general",
            "class",
            "tools",
            "next",
            "crypto",
            "sandbox"
          ],
          "references": [
            "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Spain",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "LatentBot",
              "display_name": "LatentBot",
              "target": null
            },
            {
              "id": "Grandoreiro",
              "display_name": "Grandoreiro",
              "target": null
            },
            {
              "id": "Grandoreiro Banking",
              "display_name": "Grandoreiro Banking",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Logistics",
            "Construction",
            "Industrial",
            "Automotive",
            "Manufacturing"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 6,
            "URL": 19,
            "CVE": 1,
            "FileHash-MD5": 5,
            "domain": 12
          },
          "indicator_count": 43,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 864,
          "modified_text": "1353 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62ff6e4f25ad372c70adf4c6",
          "name": "Grandoreiro IOCs",
          "description": "Grandoreiro CnC: Facebook, Twitter, Instagram, Snapchat, Google, Facebook and Twitter all share the same web address address for users who visit the site on their mobile phones or tablets.",
          "modified": "2022-09-18T00:03:55.814000",
          "created": "2022-08-19T11:04:47.140000",
          "tags": [
            "urls",
            "same",
            "checkin request",
            "checkin url",
            "time",
            "grandoreiro cnc",
            "md5 hashes"
          ],
          "references": [
            "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "brazen.fox.thirteen",
            "id": "155136",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 10,
            "URL": 8,
            "domain": 12,
            "hostname": 5
          },
          "indicator_count": 35,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "1353 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162454&Signature=s%2FL8LyYQ5ohWNf8k%2F4%2BjtOHEZw%2FPBQ50rPOAG6qtrJE1i6GAlRl5exjz0kySLyFUjqw1a%2BRmbp%2BGOUpGT1lFr%2FJQ6MrmypYvlc6FB451hDVD6FGhK1ux%2FDBdqi3jA5ZcM0TBp9nG%2FzUmdBcnXGtpTT6vgdZpgZT6%2FcaTnDSXLieEgVqCAgVX%2FZFQg3ZVxCBndzTcuRqQmR2axdb1QaRQ%2BIFIaYonKsJt",
        "Is Swipper: pool-70-21-23-161.washdc.fios.verizon.net",
        "https://vtbehaviour.commondatastorage.googleapis.com/19a366688d6cbe45c99c2eb49ae11f06ac85a63b83753bdae693ba36032dbc3f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162253&Signature=DsUEk3x0D0tLMeH64e%2BL%2BU0fmDQgZPub6sr2i81od6MJcTmkUHTvUwY4TX7A4UF7CHp6x9os7H6ACU0L6ZaarkQrPNm5dsT7lulfOTfMO4b8%2B9vETdbWgCFKDoxSh1JDRedcaByU9eHDx1EubCyeCzVwlhIQD6DY731Nqnbs%2FbM6xAvxXIrjJXGTEIhmWk2rwD9E7fIYWKxJ3PIwdd9LxuRcfsiqFrEfxSfL%2FhCUtkAzP9VJk%2B",
        "Confirmed Malware:  Cl0p QVM41.1.083F.Malware SLF:Trojan:Win32/Grandoreiro VirTool:Win32/Injector",
        "https://thehackernews.com/2022/08/new-grandoreiro-banking-malware.html",
        "Malicious Antivirus Detections SLF:Trojan:Win32/Grandoreiro.A  Yara Detections md5_constants ,  Delphi ,",
        "SLF:Trojan:Win32/Grandoreiro.A - FILEHASH - SHA256 5253cfaec7456b9fe440ab25207b8e1ff948b04fc2f2f34befc2354bf4431d07",
        "http://hopto.org/colocrossing/192.3.13.56/telco",
        "SWIPPER Behavior: Category is seperate from DDoS attacks. Bad Web Bot Web App Attack",
        "https://www.colocrossing.com/",
        "IDS Defections: Possible External IP Lookup ipinfo.io DNS Query to DynDNS Domain *.ddns .me",
        "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals",
        "Whois-RWS ; Name, SWIPPER ; Handle, SWIPP9-ARIN ; Company, Verizon ; Street, 22001 Loudoun County Pkwy.",
        "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules",
        "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776161759&Signature=r%2BKlsLyBnYpOeeNHzRs9%2B7pdGx2v0X0pOyuXLCoa%2BnUPUCVB26zsfTA6MkxYVG1EJEHvnIlhFuROVrTGOBD3iJ8Pi88PQMXIZ3v2jPn9uE50%2B7sfn3PB%2FD2SBG1luKM%2BcX4xmmAa9lBeO4YV7eHLZRuujfrNAD1p7ibfanLrhtk7C%2BooBJ%2BBrhzZgQiVRPozazGmTh0p9ZDu5uwqfnNncRfsUH3MC2DU7%2F2lLeIXl2i4",
        "NanoCore RAT CnC 7 : FileHash-SHA256 0031cb925e76f801a0ca2ebbc32029be927687f0d6183777be917878ffd7cd4b",
        "Alerts: network_icmp antianalysis_detectfile antidbg_windows antivm_generic_scsi",
        "Alerts: sysinternals_tools_usage antivm_vmware_in_instruction persistence_autorun",
        "Confirmed Malware: Trojan:Win32/Zbot TrojanDropper:Win32/Muldrop Worm:Win32/Mofksys",
        "https://whois.arin.net/rest/net/NET-71-96-0-0-1/pft?s=71.106.106.47",
        "CVE-2023-23397 | scanning_host IPv4 158.247.7.206 scanning_host IP's: 192.3.13.56  158.247.7.206",
        "Title: The page title. Remote Access - Dynamic DNS - Create a Free DDNS Account Now - No-IP",
        "Command and Control: 208.95.112.1  |  34.154.67.14",
        "IDS Defections: Possible Cerber Ransomware IP Check Possible ET INFO RealThinClient Session Init",
        "FILEHASH - SHA256 253cfaec7456b9fe440ab25207b8e1ff948b04fc2f2f34befc2354bf4431d07  |  IP\u2019s Contacted: 34.117.59.81",
        "SWIPPER Behavior: Brute-Force Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc.",
        "Malware.Nymeria-6993588-0: FileHash-SHA256 9dddb78cec49c05f2bec6f2583e4d8a663435f5a265a09a5966d5d4bfa866761",
        "American Registry for Internet Numbers (ARIN) http://www.arin.net \u203a cgi-bin \u203a Who is RWS",
        "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162432&Signature=TWbtmQs4bcHbMfmTekVuORg%2BkrtroxYd8P8uC5usycoJ%2BB%2FHow0wKjA9ZjhOZxjEmMD0SR0LJtJtz9WjU4Bo%2BUGImGkUS%2BpVWmWEUlAnFAifUeH4f5YQ%2F6cNsYropo5WcFbSSs5CBkVFTFkx0oi7v6eoTVbSOB6ZuXf3th4SLotta8FcMAzmgs6224SExEQaOgbe8HNnU%2F7BqF5906uMA793JnqbInA83%2BrUvFoO1vo3f%",
        "N\u2205 IP: https://otx.alienvault.com/otxapi/indicators/url/screenshot/http://hopto.org/colocrossing/192.3.13.56/telco",
        "SWIPPER - IP: 152.199.161.19  ISP Edgecast Inc. Content Delivery Network Domain Name edgecast.com Los Angeles, California",
        "Yara Detections: XOR_embeded_exefile_xored_with_round_256_bytes_key",
        "Whois-RWS ; Name, SWIPPER ; Handle, SWIPP9-ARIN ; Company, Verizon ; Street, 22001",
        "SWIPPER - IP: 152.199.161.19 - Florence, Co related",
        "https://vtbehaviour.commondatastorage.googleapis.com/19a366688d6cbe45c99c2eb49ae11f06ac85a63b83753bdae693ba36032dbc3f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162273&Signature=sHM7md8FG3NGW4EaoHgxxJxesr%2BwB7HqWHK1D3tULtGS5B9x6lSEfz%2F7oBPbC%2FW1AjBMAQvDCNRY5nUYvLs9v1lyCmWTdlaXzqGLXKKucME3uJxTnsyz%2BD1NufC0hBTMCOi72Sr8g6t%2Fs0AUKgWVoI%2FzNNPjkBnA8yhuPJDg%2FagW1ZWHbCCmuvDq89e7cuw7zAwSyLYepQaw6NwWxkbXxbLmCPt8NgH1FxvePXTh2u6kEBUkC3rfaYMz",
        "Confirmed Malware: Trojan:Win/Zombie Trojan:Win32/AutoitInject Trojan:Win32/Glupteba Trojan:Win32/QQpass",
        "SWIPPER - ISP: WS/Acs Inc/Acs  Usage Type:University/College/School Domain Name: acs-inc.com Pittsburgh, Pennsylvania"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Threat Analysis"
          ],
          "malware_families": [
            "Trojan:win/zombie",
            "Virtool:win32/injector",
            "Cl0p",
            "Worm:win32/mofksys",
            "Grandoreiro banking",
            "Latentbot",
            "Grandoreiro",
            "Slf:trojan:win32/grandoreiro",
            "Trojan:win32/glupteba",
            "Trojan:win32/zbot",
            "Trojan:win32/autoitinject",
            "Trojandropper:win32/muldrop",
            "Trojan:win32/qqpass",
            "Qvm41.1.083f.malware"
          ],
          "industries": [
            "Logistics",
            "Industrial",
            "Any",
            "Civilian society",
            "Automotive",
            "Manufacturing",
            "Telecommunications",
            "Construction",
            "Technology"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 12,
  "pulses": [
    {
      "id": "6998f7aa0bbea2bda9d216b5",
      "name": "no-ip",
      "description": "",
      "modified": "2026-05-18T20:26:39.259000",
      "created": "2026-02-21T00:09:14.394000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 93
      },
      "indicator_count": 93,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 186,
      "modified_text": "14 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69de16ad2eff99041dc0798f",
      "name": "CAPE Sandbox",
      "description": "The full text of the full report on the events of 9 January 2016:-17 February 2017.. and the details will appear on Facebook, Twitter, Instagram and iPlayer, as well as BBC News.Publicly sourced data.",
      "modified": "2026-05-14T13:12:04.466000",
      "created": "2026-04-14T10:27:57.413000",
      "tags": [
        "default",
        "win1",
        "acrongl integ",
        "adc4240758",
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "angsana new",
        "accept",
        "shutdown",
        "bits",
        "users",
        "files c",
        "registry keys",
        "parent pid",
        "full path",
        "command line",
        "mutexes nothing",
        "settings c",
        "users c",
        "file type",
        "ascii text",
        "html document",
        "ascii",
        "smtp",
        "united",
        "pe file",
        "ms windows",
        "found",
        "pe32",
        "exploit",
        "window",
        "mydoom",
        "malicious",
        "next",
        "windows sandbox",
        "calls process"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776161759&Signature=r%2BKlsLyBnYpOeeNHzRs9%2B7pdGx2v0X0pOyuXLCoa%2BnUPUCVB26zsfTA6MkxYVG1EJEHvnIlhFuROVrTGOBD3iJ8Pi88PQMXIZ3v2jPn9uE50%2B7sfn3PB%2FD2SBG1luKM%2BcX4xmmAa9lBeO4YV7eHLZRuujfrNAD1p7ibfanLrhtk7C%2BooBJ%2BBrhzZgQiVRPozazGmTh0p9ZDu5uwqfnNncRfsUH3MC2DU7%2F2lLeIXl2i4",
        "https://vtbehaviour.commondatastorage.googleapis.com/19a366688d6cbe45c99c2eb49ae11f06ac85a63b83753bdae693ba36032dbc3f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162253&Signature=DsUEk3x0D0tLMeH64e%2BL%2BU0fmDQgZPub6sr2i81od6MJcTmkUHTvUwY4TX7A4UF7CHp6x9os7H6ACU0L6ZaarkQrPNm5dsT7lulfOTfMO4b8%2B9vETdbWgCFKDoxSh1JDRedcaByU9eHDx1EubCyeCzVwlhIQD6DY731Nqnbs%2FbM6xAvxXIrjJXGTEIhmWk2rwD9E7fIYWKxJ3PIwdd9LxuRcfsiqFrEfxSfL%2FhCUtkAzP9VJk%2B",
        "https://vtbehaviour.commondatastorage.googleapis.com/19a366688d6cbe45c99c2eb49ae11f06ac85a63b83753bdae693ba36032dbc3f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162273&Signature=sHM7md8FG3NGW4EaoHgxxJxesr%2BwB7HqWHK1D3tULtGS5B9x6lSEfz%2F7oBPbC%2FW1AjBMAQvDCNRY5nUYvLs9v1lyCmWTdlaXzqGLXKKucME3uJxTnsyz%2BD1NufC0hBTMCOi72Sr8g6t%2Fs0AUKgWVoI%2FzNNPjkBnA8yhuPJDg%2FagW1ZWHbCCmuvDq89e7cuw7zAwSyLYepQaw6NwWxkbXxbLmCPt8NgH1FxvePXTh2u6kEBUkC3rfaYMz",
        "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162432&Signature=TWbtmQs4bcHbMfmTekVuORg%2BkrtroxYd8P8uC5usycoJ%2BB%2FHow0wKjA9ZjhOZxjEmMD0SR0LJtJtz9WjU4Bo%2BUGImGkUS%2BpVWmWEUlAnFAifUeH4f5YQ%2F6cNsYropo5WcFbSSs5CBkVFTFkx0oi7v6eoTVbSOB6ZuXf3th4SLotta8FcMAzmgs6224SExEQaOgbe8HNnU%2F7BqF5906uMA793JnqbInA83%2BrUvFoO1vo3f%",
        "https://vtbehaviour.commondatastorage.googleapis.com/00013c14102d59e189e1ad191b4367fda0146a1a1d354ae36bd8b315186042ad_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1776162454&Signature=s%2FL8LyYQ5ohWNf8k%2F4%2BjtOHEZw%2FPBQ50rPOAG6qtrJE1i6GAlRl5exjz0kySLyFUjqw1a%2BRmbp%2BGOUpGT1lFr%2FJQ6MrmypYvlc6FB451hDVD6FGhK1ux%2FDBdqi3jA5ZcM0TBp9nG%2FzUmdBcnXGtpTT6vgdZpgZT6%2FcaTnDSXLieEgVqCAgVX%2FZFQg3ZVxCBndzTcuRqQmR2axdb1QaRQ%2BIFIaYonKsJt"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1203",
          "name": "Exploitation for Client Execution",
          "display_name": "T1203 - Exploitation for Client Execution"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 294,
        "FileHash-SHA1": 122,
        "FileHash-SHA256": 1747,
        "URL": 5866,
        "hostname": 1673,
        "domain": 432,
        "CVE": 1,
        "email": 2
      },
      "indicator_count": 10137,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "19 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68d332d77a7eedf3ad71c406",
      "name": "Denizbankk.net \u2022  LevelBlue - Open Threat Exchange",
      "description": "Denizbankk.net \u2022 Debian.org \u2022 hallrender.com \u2022 alienvault.com \u2022 hopto.org \u2022 striven.com| ? | This is concerning. It\u2019s not like intended to find what I have found but I am disappointed. The few people on the platform who do their own research eventually leave with a large amount of reposters. Related to haallrendee, brian sabey and each link listed. Stange happenings this weak. [otx auto populated- Google Safe Browsing, Denizbankk.net, has been used by the Russian government to create a secure web address that can be accessed only if the user has the correct address.{",
      "modified": "2025-10-23T23:03:23.167000",
      "created": "2025-09-23T23:52:55.453000",
      "tags": [
        "log id",
        "gmtn",
        "tls web",
        "zerossl",
        "zerossl rsa",
        "domain secure",
        "site ca",
        "fa c7",
        "ocsp",
        "a167",
        "code",
        "keepalive",
        "false",
        "record type",
        "ttl a",
        "value",
        "o jarm",
        "fingerprint",
        "file format",
        "relevance",
        "united",
        "tempe",
        "arizona create",
        "domain",
        "expiry date",
        "name",
        "query time",
        "technical city",
        "tempe technical",
        "technical state",
        "rdap database",
        "handle",
        "iana registrar",
        "links",
        "algorithm",
        "key identifier",
        "data",
        "v3 serial",
        "number",
        "cat ozerossl",
        "cnzerossl rsa",
        "validity",
        "server",
        "domain name",
        "status",
        "abuse contact",
        "email",
        "registrar abuse",
        "contact phone",
        "registrar iana",
        "registrar url",
        "registrar whois",
        "date",
        "available from",
        "country",
        "proxy",
        "postal code",
        "city",
        "admin city",
        "tempe admin",
        "filehashmd5",
        "url https",
        "filehashsha1",
        "url http",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "filehashsha256",
        "showing",
        "germany unknown",
        "passive dns",
        "entries",
        "a domains",
        "body doctype",
        "content type",
        "gmt server",
        "ipv4 add",
        "pulse submit",
        "url analysis",
        "main",
        "apache",
        "accept",
        "title",
        "present dec",
        "present jun",
        "present nov",
        "aaaa",
        "present feb",
        "present sep",
        "search",
        "canada",
        "encrypt",
        "devam",
        "ad soyad",
        "mteri numaras",
        "gvenlik iin",
        "gizli soru",
        "gvenlik sorusu",
        "cevab",
        "ltfen bir",
        "present may",
        "moved",
        "present oct",
        "ip address",
        "gandi sas",
        "body",
        "backdoor",
        "next associated",
        "trojandropper",
        "fastly error",
        "please",
        "sea p",
        "twitter",
        "win32",
        "creation date",
        "name servers",
        "hostname add",
        "pulse pulses",
        "urls",
        "record value",
        "japan",
        "germany",
        "ipv4",
        "countries",
        "america",
        "netherlands",
        "italy",
        "brian sabey",
        "report spam",
        "tsara brashears",
        "created",
        "days ago",
        "green well",
        "sabey stash",
        "service",
        "hours ago",
        "malicious",
        "forbidden",
        "actionlistccc",
        "malware family",
        "mufanom att",
        "capture",
        "ck ids",
        "checkin",
        "t1036",
        "t1055",
        "injection",
        "t1056"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1199",
          "name": "Trusted Relationship",
          "display_name": "T1199 - Trusted Relationship"
        },
        {
          "id": "T1410",
          "name": "Network Traffic Capture or Redirection",
          "display_name": "T1410 - Network Traffic Capture or Redirection"
        },
        {
          "id": "T1448",
          "name": "Carrier Billing Fraud",
          "display_name": "T1448 - Carrier Billing Fraud"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 617,
        "URL": 2495,
        "hostname": 1698,
        "FileHash-MD5": 275,
        "FileHash-SHA1": 265,
        "FileHash-SHA256": 1241,
        "SSLCertFingerprint": 2,
        "email": 4
      },
      "indicator_count": 6597,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 144,
      "modified_text": "221 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68d3368ae75cccf736a55441",
      "name": "ET TROJAN Hiloti/Mufanom Downloader Checkin | Denizbankk.net",
      "description": "",
      "modified": "2025-10-23T23:03:23.167000",
      "created": "2025-09-24T00:08:42.048000",
      "tags": [
        "log id",
        "gmtn",
        "tls web",
        "zerossl",
        "zerossl rsa",
        "domain secure",
        "site ca",
        "fa c7",
        "ocsp",
        "a167",
        "code",
        "keepalive",
        "false",
        "record type",
        "ttl a",
        "value",
        "o jarm",
        "fingerprint",
        "file format",
        "relevance",
        "united",
        "tempe",
        "arizona create",
        "domain",
        "expiry date",
        "name",
        "query time",
        "technical city",
        "tempe technical",
        "technical state",
        "rdap database",
        "handle",
        "iana registrar",
        "links",
        "algorithm",
        "key identifier",
        "data",
        "v3 serial",
        "number",
        "cat ozerossl",
        "cnzerossl rsa",
        "validity",
        "server",
        "domain name",
        "status",
        "abuse contact",
        "email",
        "registrar abuse",
        "contact phone",
        "registrar iana",
        "registrar url",
        "registrar whois",
        "date",
        "available from",
        "country",
        "proxy",
        "postal code",
        "city",
        "admin city",
        "tempe admin",
        "filehashmd5",
        "url https",
        "filehashsha1",
        "url http",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "filehashsha256",
        "showing",
        "germany unknown",
        "passive dns",
        "entries",
        "a domains",
        "body doctype",
        "content type",
        "gmt server",
        "ipv4 add",
        "pulse submit",
        "url analysis",
        "main",
        "apache",
        "accept",
        "title",
        "present dec",
        "present jun",
        "present nov",
        "aaaa",
        "present feb",
        "present sep",
        "search",
        "canada",
        "encrypt",
        "devam",
        "ad soyad",
        "mteri numaras",
        "gvenlik iin",
        "gizli soru",
        "gvenlik sorusu",
        "cevab",
        "ltfen bir",
        "present may",
        "moved",
        "present oct",
        "ip address",
        "gandi sas",
        "body",
        "backdoor",
        "next associated",
        "trojandropper",
        "fastly error",
        "please",
        "sea p",
        "twitter",
        "win32",
        "creation date",
        "name servers",
        "hostname add",
        "pulse pulses",
        "urls",
        "record value",
        "japan",
        "germany",
        "ipv4",
        "countries",
        "america",
        "netherlands",
        "italy",
        "brian sabey",
        "report spam",
        "tsara brashears",
        "created",
        "days ago",
        "green well",
        "sabey stash",
        "service",
        "hours ago",
        "malicious",
        "forbidden",
        "actionlistccc",
        "malware family",
        "mufanom att",
        "capture",
        "ck ids",
        "checkin",
        "t1036",
        "t1055",
        "injection",
        "t1056"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1199",
          "name": "Trusted Relationship",
          "display_name": "T1199 - Trusted Relationship"
        },
        {
          "id": "T1410",
          "name": "Network Traffic Capture or Redirection",
          "display_name": "T1410 - Network Traffic Capture or Redirection"
        },
        {
          "id": "T1448",
          "name": "Carrier Billing Fraud",
          "display_name": "T1448 - Carrier Billing Fraud"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "68d332d77a7eedf3ad71c406",
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 617,
        "URL": 2495,
        "hostname": 1698,
        "FileHash-MD5": 275,
        "FileHash-SHA1": 265,
        "FileHash-SHA256": 1241,
        "SSLCertFingerprint": 2,
        "email": 4
      },
      "indicator_count": 6597,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 141,
      "modified_text": "221 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6775b17c488523ee9d290afd",
      "name": "agressive extra",
      "description": "",
      "modified": "2025-03-17T22:57:49.933000",
      "created": "2025-01-01T21:19:56.847000",
      "tags": [],
      "references": [
        "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 35208,
        "URL": 79504,
        "domain": 19527,
        "hostname": 28058,
        "CVE": 9
      },
      "indicator_count": 162306,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 207,
      "modified_text": "441 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66c76a410bca940a8cb84f91",
      "name": "Remote Access - Dynamic DNS  | Injection",
      "description": "Blamed for Botnet exchange, Ddos, ssh, email spamming, brute forcing emails, sending viruses/trojans to countless emails, injection, app installation, gov , bank employee targeting, etc. Listed ALL victim information in downed WikiLeaks website.The list is long, Swipper is still a mystery. The name has been linked to an IT graduate. This doesn't mean much as hackers frame everyone. The [person or links to does link back to subject of hacks against a targeted person. When target researched Swipper EVERYTHING related was cleaned from the Internet.\n\nThe best clue deleted was for IP's in the 152.199.0.0/24 Block. \nThe other was used by Brian Sabey who used service to distribute So much porn (and worse) all with targets name! It was a 'hopto' N\u2205 IP address. It disappeared so fast along with any  trace.",
      "modified": "2024-09-21T14:04:09.409000",
      "created": "2024-08-22T16:41:37.285000",
      "tags": [
        "referrer",
        "nanocore rat",
        "hunting guide",
        "your apt",
        "malware",
        "bitter apt",
        "using zxxz",
        "backdoor",
        "pakistan public",
        "committee",
        "ukraine",
        "maxage7200",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "dynamic dns",
        "access",
        "html info",
        "title remote",
        "ddns account",
        "meta tags",
        "ip address",
        "trackers amazon",
        "tag manager",
        "cookies noipbid",
        "netrange",
        "nethandle",
        "net152",
        "net1520000",
        "as1321",
        "inc orgid",
        "loudoun county",
        "parkway city",
        "postalcode",
        "content",
        "utc google",
        "gtmvfgb",
        "utc ggg8ybn7flc",
        "gg8ybn7flc",
        "samples",
        "no data",
        "tag count",
        "analyzer threat",
        "ip summary",
        "summary",
        "detection list",
        "heur",
        "malicious site",
        "malicious host",
        "services",
        "exchange botnet",
        "command",
        "control server",
        "host",
        "azorult",
        "pony",
        "asyncrat",
        "cobalt strike",
        "phishing",
        "team",
        "dropper",
        "crypt",
        "outbreak",
        "mimikatz",
        "riskware",
        "trojanx",
        "cisco umbrella",
        "site",
        "safe site",
        "redline stealer",
        "generic pua",
        "malware site",
        "utorrent",
        "generic",
        "yakes",
        "agent",
        "adposhel",
        "zbot",
        "cl0p",
        "managed dns",
        "strong",
        "noip",
        "please",
        "buy plus",
        "managed",
        "free",
        "service",
        "already",
        "read c",
        "dll read",
        "function read",
        "medium",
        "systemroot",
        "search",
        "high",
        "smtp host",
        "virustotal",
        "trojan",
        "write",
        "drweb",
        "vipre",
        "panda",
        "phishing",
        "ransomware",
        "rat",
        "swipper",
        "swipp9",
        "vj92",
        "uagdaaeqcqaaaag",
        "ukgbagaqcqaaaae",
        "slfrd1",
        "hostnames",
        "ukgbagaqcq",
        "jid1886833764",
        "jid882556742",
        "unknown",
        "as36947",
        "algeria unknown",
        "germany unknown",
        "as37340",
        "nigeria unknown",
        "united kingdom",
        "as200350",
        "france unknown",
        "date",
        "z557338487",
        "z129433407",
        "z2111579734",
        "name servers",
        "passive dns",
        "as14627",
        "scan endpoints",
        "all scoreblue",
        "next",
        "aaaa",
        "asnone united",
        "moved",
        "certificate",
        "rsa ca",
        "ipv4",
        "pulse pulses",
        "win32",
        "process32nextw",
        "onlogon ru",
        "discovery",
        "t1057",
        "discovery t1057",
        "windows",
        "post http",
        "actionhello",
        "delphi",
        "dock",
        "memcommit",
        "writeconsolea",
        "nat monitor",
        "f tn",
        "delete c",
        "write c",
        "create c",
        "autoit",
        "look",
        "suspicious",
        "as9009 m247",
        "sri lanka",
        "domain",
        "creation date",
        "hungary unknown",
        "as36352",
        "files",
        "hosting",
        "reverse dns",
        "all search",
        "otx scoreblue",
        "hostname",
        "pulse submit",
        "url analysis",
        "status",
        "mtb sep",
        "record value",
        "servers",
        "gmt server",
        "pecancer",
        "as15169 google",
        "mtb apr",
        "open ports",
        "trojandropper",
        "gmt cache",
        "cashreminder",
        "philadelphia",
        "status hostname",
        "query type",
        "address first",
        "seen last",
        "seen asn",
        "country unknown",
        "nxdomain",
        "a nxdomain",
        "encrypt",
        "body",
        "present mar",
        "emails",
        "domain name",
        "expiration date",
        "error",
        "code",
        "location united",
        "united states",
        "malicious.75188e",
        "united",
        "icmp traffic",
        "pe section",
        "low software",
        "packing t1045",
        "t1045",
        "pe resource",
        "filehash",
        "ireland unknown",
        "as396982 google",
        "belgium unknown",
        "as24940 hetzner",
        "trojan process",
        "file samples",
        "files matching",
        "show",
        "date hash",
        "worm features",
        "related pulses",
        "malware process",
        "trojan features",
        "brute force",
        "brute forcing emails",
        "hacking",
        "logan utah",
        "ddos attack",
        "web app attacks",
        "bad web bot",
        "cwaf",
        "verizon enterprise"
      ],
      "references": [
        "Title: The page title. Remote Access - Dynamic DNS - Create a Free DDNS Account Now - No-IP",
        "http://hopto.org/colocrossing/192.3.13.56/telco",
        "N\u2205 IP: https://otx.alienvault.com/otxapi/indicators/url/screenshot/http://hopto.org/colocrossing/192.3.13.56/telco",
        "SLF:Trojan:Win32/Grandoreiro.A - FILEHASH - SHA256 5253cfaec7456b9fe440ab25207b8e1ff948b04fc2f2f34befc2354bf4431d07",
        "FILEHASH - SHA256 253cfaec7456b9fe440ab25207b8e1ff948b04fc2f2f34befc2354bf4431d07  |  IP\u2019s Contacted: 34.117.59.81",
        "Malicious Antivirus Detections SLF:Trojan:Win32/Grandoreiro.A  Yara Detections md5_constants ,  Delphi ,",
        "IDS Defections: Possible Cerber Ransomware IP Check Possible ET INFO RealThinClient Session Init",
        "IDS Defections: Possible External IP Lookup ipinfo.io DNS Query to DynDNS Domain *.ddns .me",
        "Alerts: network_icmp antianalysis_detectfile antidbg_windows antivm_generic_scsi",
        "Alerts: sysinternals_tools_usage antivm_vmware_in_instruction persistence_autorun",
        "Yara Detections: XOR_embeded_exefile_xored_with_round_256_bytes_key",
        "Malware.Nymeria-6993588-0: FileHash-SHA256 9dddb78cec49c05f2bec6f2583e4d8a663435f5a265a09a5966d5d4bfa866761",
        "NanoCore RAT CnC 7 : FileHash-SHA256 0031cb925e76f801a0ca2ebbc32029be927687f0d6183777be917878ffd7cd4b",
        "CVE-2023-23397 | scanning_host IPv4 158.247.7.206 scanning_host IP's: 192.3.13.56  158.247.7.206",
        "Whois-RWS ; Name, SWIPPER ; Handle, SWIPP9-ARIN ; Company, Verizon ; Street, 22001 Loudoun County Pkwy.",
        "Whois-RWS ; Name, SWIPPER ; Handle, SWIPP9-ARIN ; Company, Verizon ; Street, 22001",
        "Is Swipper: pool-70-21-23-161.washdc.fios.verizon.net",
        "SWIPPER - IP: 152.199.161.19  ISP Edgecast Inc. Content Delivery Network Domain Name edgecast.com Los Angeles, California",
        "SWIPPER - IP: 152.199.161.19 - Florence, Co related",
        "SWIPPER - ISP: WS/Acs Inc/Acs  Usage Type:University/College/School Domain Name: acs-inc.com Pittsburgh, Pennsylvania",
        "SWIPPER Behavior: Brute-Force Credential brute-force attacks on webpage logins and services like SSH, FTP, SIP, SMTP, RDP, etc.",
        "SWIPPER Behavior: Category is seperate from DDoS attacks. Bad Web Bot Web App Attack",
        "Confirmed Malware:  Cl0p QVM41.1.083F.Malware SLF:Trojan:Win32/Grandoreiro VirTool:Win32/Injector",
        "Confirmed Malware: Trojan:Win/Zombie Trojan:Win32/AutoitInject Trojan:Win32/Glupteba Trojan:Win32/QQpass",
        "Confirmed Malware: Trojan:Win32/Zbot TrojanDropper:Win32/Muldrop Worm:Win32/Mofksys",
        "Command and Control: 208.95.112.1  |  34.154.67.14",
        "https://www.colocrossing.com/",
        "American Registry for Internet Numbers (ARIN) http://www.arin.net \u203a cgi-bin \u203a Who is RWS",
        "https://whois.arin.net/rest/net/NET-71-96-0-0-1/pft?s=71.106.106.47"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Cl0p",
          "display_name": "Cl0p",
          "target": null
        },
        {
          "id": "SLF:Trojan:Win32/Grandoreiro",
          "display_name": "SLF:Trojan:Win32/Grandoreiro",
          "target": null
        },
        {
          "id": "QVM41.1.083F.Malware",
          "display_name": "QVM41.1.083F.Malware",
          "target": null
        },
        {
          "id": "Trojan:Win32/Glupteba",
          "display_name": "Trojan:Win32/Glupteba",
          "target": "/malware/Trojan:Win32/Glupteba"
        },
        {
          "id": "Worm:Win32/Mofksys",
          "display_name": "Worm:Win32/Mofksys",
          "target": "/malware/Worm:Win32/Mofksys"
        },
        {
          "id": "TrojanDropper:Win32/Muldrop",
          "display_name": "TrojanDropper:Win32/Muldrop",
          "target": "/malware/TrojanDropper:Win32/Muldrop"
        },
        {
          "id": "Trojan:Win32/Zbot",
          "display_name": "Trojan:Win32/Zbot",
          "target": "/malware/Trojan:Win32/Zbot"
        },
        {
          "id": "Trojan:Win32/QQpass",
          "display_name": "Trojan:Win32/QQpass",
          "target": "/malware/Trojan:Win32/QQpass"
        },
        {
          "id": "Trojan:Win/Zombie",
          "display_name": "Trojan:Win/Zombie",
          "target": "/malware/Trojan:Win/Zombie"
        },
        {
          "id": "Trojan:Win32/AutoitInject",
          "display_name": "Trojan:Win32/AutoitInject",
          "target": "/malware/Trojan:Win32/AutoitInject"
        },
        {
          "id": "VirTool:Win32/Injector",
          "display_name": "VirTool:Win32/Injector",
          "target": "/malware/VirTool:Win32/Injector"
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1110.004",
          "name": "Credential Stuffing",
          "display_name": "T1110.004 - Credential Stuffing"
        },
        {
          "id": "T1584.005",
          "name": "Botnet",
          "display_name": "T1584.005 - Botnet"
        },
        {
          "id": "T1037",
          "name": "Boot or Logon Initialization Scripts",
          "display_name": "T1037 - Boot or Logon Initialization Scripts"
        },
        {
          "id": "T1102.002",
          "name": "Bidirectional Communication",
          "display_name": "T1102.002 - Bidirectional Communication"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "T1444",
          "name": "Masquerade as Legitimate Application",
          "display_name": "T1444 - Masquerade as Legitimate Application"
        },
        {
          "id": "T1037.003",
          "name": "Network Logon Script",
          "display_name": "T1037.003 - Network Logon Script"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0010",
          "name": "Exfiltration",
          "display_name": "TA0010 - Exfiltration"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1147",
          "name": "Hidden Users",
          "display_name": "T1147 - Hidden Users"
        },
        {
          "id": "T1098.002",
          "name": "Exchange Email Delegate Permissions",
          "display_name": "T1098.002 - Exchange Email Delegate Permissions"
        },
        {
          "id": "T1460",
          "name": "Biometric Spoofing",
          "display_name": "T1460 - Biometric Spoofing"
        },
        {
          "id": "T1205.001",
          "name": "Port Knocking",
          "display_name": "T1205.001 - Port Knocking"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [
        "Technology",
        "Telecommunications",
        "Civilian Society",
        "Any"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 53,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 546,
        "FileHash-MD5": 1677,
        "FileHash-SHA1": 1288,
        "FileHash-SHA256": 1385,
        "CVE": 1,
        "domain": 404,
        "hostname": 591,
        "CIDR": 3,
        "email": 12
      },
      "indicator_count": 5907,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "619 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6303290568240f6ed1285370",
      "name": "New Grandoreiro Banking Malware Campaign Targeting Spanish Manufacturers",
      "description": "Organizations in the Spanish-speaking nations of Mexico and Spain are in the crosshairs of a new campaign designed to deliver the Grandoreiro banking trojan.\n\n\"In this campaign, the threat actors impersonate government officials from the Attorney General's Office of Mexico City and from the Public Ministry in the form of spear-phishing emails in order to lure victims to download and execute 'Grandoreiro,' a prolific banking trojan that has been active since at least 2016, and that specifically targets users in Latin America,\" Zscaler said in a report.",
      "modified": "2022-09-21T00:02:24.222000",
      "created": "2022-08-22T06:58:13.526000",
      "tags": [
        "grandoreiro",
        "latentbot",
        "grandoreiro banking",
        "spear phishing",
        "banking",
        "malware",
        "government",
        "mexico",
        "spain",
        "trojan",
        "banking trojan",
        "threatintel",
        "threats",
        "payload",
        "resolution",
        "english",
        "zip file",
        "pmsubject",
        "delphi",
        "actionhello",
        "june",
        "path",
        "loader",
        "general",
        "class",
        "tools",
        "next",
        "crypto",
        "sandbox"
      ],
      "references": [
        "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals",
        "https://thehackernews.com/2022/08/new-grandoreiro-banking-malware.html"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Spain",
        "Mexico"
      ],
      "malware_families": [
        {
          "id": "LatentBot",
          "display_name": "LatentBot",
          "target": null
        },
        {
          "id": "Grandoreiro",
          "display_name": "Grandoreiro",
          "target": null
        },
        {
          "id": "Grandoreiro Banking",
          "display_name": "Grandoreiro Banking",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        }
      ],
      "industries": [
        "Logistics",
        "Construction",
        "Industrial",
        "Automotive",
        "Manufacturing"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 351,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dekaRituraj",
        "id": "99856",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_99856/resized/80/avatar_0e93d502b7.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-MD5": 5,
        "URL": 8,
        "domain": 12,
        "hostname": 5
      },
      "indicator_count": 31,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 436,
      "modified_text": "1350 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "630333d999f50875b5504dfa",
      "name": "Grandoreiro Malware with New TTPs",
      "description": "Zscaler is the world\u2019s largest security platform built for the cloud and provides a platform that delivers zero trust and delivers the best experience possible for users, businesses, and government alike.",
      "modified": "2022-09-21T00:02:24.222000",
      "created": "2022-08-22T07:44:25.632000",
      "tags": [
        "grandoreiro",
        "latentbot",
        "grandoreiro banking",
        "spear phishing",
        "banking",
        "malware",
        "government",
        "mexico",
        "spain",
        "trojan",
        "banking trojan",
        "threatintel",
        "threats",
        "payload",
        "resolution",
        "english",
        "zip file",
        "pmsubject",
        "delphi",
        "actionhello",
        "june",
        "path",
        "loader",
        "general",
        "class",
        "tools",
        "next",
        "crypto",
        "sandbox"
      ],
      "references": [
        "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Spain",
        "Mexico"
      ],
      "malware_families": [
        {
          "id": "LatentBot",
          "display_name": "LatentBot",
          "target": null
        },
        {
          "id": "Grandoreiro",
          "display_name": "Grandoreiro",
          "target": null
        },
        {
          "id": "Grandoreiro Banking",
          "display_name": "Grandoreiro Banking",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        }
      ],
      "industries": [
        "Logistics",
        "Construction",
        "Industrial",
        "Automotive",
        "Manufacturing"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 6,
        "URL": 19,
        "CVE": 1,
        "FileHash-MD5": 5,
        "domain": 12
      },
      "indicator_count": 43,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 863,
      "modified_text": "1350 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63037dcc6c6d01768ea3563b",
      "name": "Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals",
      "description": "Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals",
      "modified": "2022-09-21T00:02:24.222000",
      "created": "2022-08-22T12:59:56.515000",
      "tags": [
        "grandoreiro",
        "latentbot",
        "grandoreiro banking",
        "spear phishing",
        "banking",
        "malware",
        "government",
        "mexico",
        "spain",
        "trojan",
        "banking trojan",
        "threatintel",
        "threats",
        "payload",
        "resolution",
        "english",
        "zip file",
        "pmsubject",
        "delphi",
        "actionhello",
        "june",
        "path",
        "loader",
        "general",
        "class",
        "tools",
        "next",
        "crypto",
        "sandbox",
        "threat analysis",
        "cyber security news",
        "cyber news",
        "cyber security news today",
        "cyber security updates",
        "cyber updates",
        "hacker news",
        "hacking news",
        "software vulnerability",
        "cyber attacks",
        "data breach",
        "ransomware malware",
        "how to hack",
        "network security",
        "information security",
        "the hacker news",
        "computer security",
        "bumblebee",
        "trickbot",
        "cybereason",
        "bazarloader",
        "icedid",
        "alon laufer",
        "march",
        "google",
        "group",
        "conti",
        "cobalt strike",
        "anydesk",
        "facebook",
        "twitter"
      ],
      "references": [
        "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals"
      ],
      "public": 1,
      "adversary": "Threat Analysis",
      "targeted_countries": [
        "Spain",
        "Mexico"
      ],
      "malware_families": [
        {
          "id": "LatentBot",
          "display_name": "LatentBot",
          "target": null
        },
        {
          "id": "Grandoreiro",
          "display_name": "Grandoreiro",
          "target": null
        },
        {
          "id": "Grandoreiro Banking",
          "display_name": "Grandoreiro Banking",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [
        "Logistics",
        "Construction",
        "Industrial",
        "Automotive",
        "Manufacturing"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "KernelSanders",
        "id": "73862",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-MD5": 5,
        "URL": 8,
        "domain": 12,
        "hostname": 5
      },
      "indicator_count": 31,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 42,
      "modified_text": "1350 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6303ca72fe01b5fe1719f042",
      "name": "Grandoreiro Banking Trojan with New TTPs | Zscaler Blog",
      "description": "In this campaign, the threat actors impersonate government officials from the Attorney General\u2019s Office of Mexico City and from the Public Ministry in the form of spear-phishing emails in order to lure victims to download and execute \u201cGrandoreiro\u201d a prolific banking trojan that has been active since at least 2016, and that specifically targets users in Latin America",
      "modified": "2022-09-21T00:02:24.222000",
      "created": "2022-08-22T18:26:58.520000",
      "tags": [
        "Trojan",
        "Phishing",
        "LatentBot",
        "CnC",
        "KeyLogger",
        "BankingTrojan"
      ],
      "references": [
        "https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Spain",
        "Mexico"
      ],
      "malware_families": [
        {
          "id": "LatentBot",
          "display_name": "LatentBot",
          "target": null
        },
        {
          "id": "Grandoreiro",
          "display_name": "Grandoreiro",
          "target": null
        },
        {
          "id": "Grandoreiro Banking",
          "display_name": "Grandoreiro Banking",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        }
      ],
      "industries": [
        "Logistics",
        "Construction",
        "Industrial",
        "Automotive",
        "Manufacturing"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "jgomez1677",
        "id": "99942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-MD5": 5,
        "URL": 2,
        "domain": 11,
        "hostname": 5
      },
      "indicator_count": 24,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 35,
      "modified_text": "1350 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "cable-modem.org",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "cable-modem.org",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780416414.1282272
}