{
  "type": "Domain",
  "indicator": "carlosja.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/carlosja.com",
    "alexa": "http://www.alexa.com/siteinfo/carlosja.com",
    "indicator": "carlosja.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2226936650,
      "indicator": "carlosja.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 14,
      "pulses": [
        {
          "id": "6a040bf64fe2efef00132467",
          "name": "AWS.DEV | Ransom REevil | MaaS -Mirai , Makop , Sodinokibi | 6.13.25 Appears ti be ongoing  ",
          "description": "",
          "modified": "2026-05-13T05:28:22.199000",
          "created": "2026-05-13T05:28:22.199000",
          "tags": [
            "filehashmd5",
            "filehashsha1",
            "showing",
            "copyright",
            "levelblue",
            "packer entropy",
            "pe features",
            "pe unknown",
            "resource name",
            "allocates rwx",
            "network icmp",
            "antivm network",
            "exe nolookup",
            "proxy wpad",
            "dead host",
            "tools",
            "generic",
            "deletes self",
            "ransom",
            "evader",
            "active",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "installs",
            "adversaries",
            "windows",
            "modules",
            "registry",
            "persistence",
            "execution",
            "service",
            "united",
            "path",
            "flag",
            "date",
            "access type",
            "germany germany",
            "create",
            "http header",
            "tcp traffic",
            "et info",
            "entropy",
            "hybrid",
            "malicious",
            "general",
            "click",
            "strings",
            "inject",
            "remote",
            "encrypt files",
            "python",
            "global",
            "win32 exe",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 compiler",
            "overlay",
            "data",
            "pe32 executable",
            "borland delphi",
            "delphi generic",
            "md5 code",
            "empty hash",
            "file type",
            "success",
            "regopenkeyexw",
            "regopenkeyexa",
            "hkeycurrentuser",
            "virtualallocex",
            "createfilew",
            "genericread",
            "hkeyclassesroot",
            "genericwrite",
            "regsetvalueexw",
            "desktop",
            "webview",
            "mirai",
            "russsian data",
            "reevil",
            "money doc",
            "gmt flag",
            "server",
            "united kingdom",
            "france france",
            "ukraine ukraine",
            "llc name",
            "viet nam",
            "show",
            "cve",
            "bad traffic",
            "false",
            "error",
            "tags",
            "ipv4",
            "url https",
            "url http",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "entries",
            "monitor",
            "target",
            "members",
            "maas",
            "attack",
            "mitre att"
          ],
          "references": [
            "RANSOM_REvil - https://www.nextron-systems.com/notes-on-virustotal-matches/",
            "YARA:  Matches rule MAL_RANSOM_REvil_Oct20_1 from ruleset crime_ransom_revil by Florian Roth (Nextron Systems)",
            "YARA: Matches rule Windows_Ransomware_Sodinokibi_83f05fbe from ruleset Windows_Ransomware_Sodinokibi by Elastic Security",
            "YARA: Matches rule win_revil_auto from ruleset win.revil_auto by Felix Bilstein - yara-signator at cocacoding dot com",
            "https://otx.alienvault.com/malware/Ransom:Win32/Makop/",
            "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
            "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
            "Permissions requested: SE_DEBUG_PRIVILEGE SE_LOAD_DRIVER_PRIVILEGE",
            "Behaviour: Extract file to system directory"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransom:Win32/Makop.PA!MTB",
              "display_name": "Ransom:Win32/Makop.PA!MTB",
              "target": "/malware/Ransom:Win32/Makop.PA!MTB"
            },
            {
              "id": "Trojan/Win32.BlueCrab.R331768",
              "display_name": "Trojan/Win32.BlueCrab.R331768",
              "target": null
            },
            {
              "id": "Trojan.Ransom.Sodinokibi",
              "display_name": "Trojan.Ransom.Sodinokibi",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Virus.Neshta",
              "display_name": "Virus.Neshta",
              "target": null
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "RANSOM_REvil",
              "display_name": "RANSOM_REvil",
              "target": null
            },
            {
              "id": "Labeled as: Ransom.Sodinokibi.Generic",
              "display_name": "Labeled as: Ransom.Sodinokibi.Generic",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1035",
              "name": "Service Execution",
              "display_name": "T1035 - Service Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1215",
              "name": "Kernel Modules and Extensions",
              "display_name": "T1215 - Kernel Modules and Extensions"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1181",
              "name": "Extra Window Memory Injection",
              "display_name": "T1181 - Extra Window Memory Injection"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0010",
              "name": "Exfiltration",
              "display_name": "TA0010 - Exfiltration"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "684cad9bc64e61ae0e6df4c1",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 85,
            "FileHash-SHA256": 110,
            "URL": 83,
            "CVE": 1,
            "domain": 102,
            "hostname": 36
          },
          "indicator_count": 516,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "18 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a03f318b2e654e26402adaa",
          "name": "\" New Sample of REvil Ransomware - REvil Returned?\" by SteamMiningEx",
          "description": "",
          "modified": "2026-05-13T05:26:35.084000",
          "created": "2026-05-13T03:42:16.083000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65708d5530ef54f76f70777b",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 802,
            "FileHash-MD5": 209,
            "FileHash-SHA1": 198,
            "domain": 517,
            "hostname": 8,
            "URL": 2
          },
          "indicator_count": 1736,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "18 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a040afa13cf077fedd59f36",
          "name": "Ransom REevil | AWS.DEV | MaaS -Mirai , Makop , Sodinokibi , FlyStudio + Campaign| Appears to be ongoing ",
          "description": "",
          "modified": "2026-05-13T05:24:10.262000",
          "created": "2026-05-13T05:24:10.262000",
          "tags": [
            "filehashmd5",
            "filehashsha1",
            "showing",
            "copyright",
            "levelblue",
            "packer entropy",
            "pe features",
            "pe unknown",
            "resource name",
            "allocates rwx",
            "network icmp",
            "antivm network",
            "exe nolookup",
            "proxy wpad",
            "dead host",
            "tools",
            "generic",
            "deletes self",
            "ransom",
            "evader",
            "active",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "installs",
            "adversaries",
            "windows",
            "modules",
            "registry",
            "persistence",
            "execution",
            "service",
            "united",
            "path",
            "flag",
            "date",
            "access type",
            "germany germany",
            "create",
            "http header",
            "tcp traffic",
            "et info",
            "entropy",
            "hybrid",
            "malicious",
            "general",
            "click",
            "strings",
            "inject",
            "remote",
            "encrypt files",
            "python",
            "global",
            "win32 exe",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 compiler",
            "overlay",
            "data",
            "pe32 executable",
            "borland delphi",
            "delphi generic",
            "md5 code",
            "empty hash",
            "file type",
            "success",
            "regopenkeyexw",
            "regopenkeyexa",
            "hkeycurrentuser",
            "virtualallocex",
            "createfilew",
            "genericread",
            "hkeyclassesroot",
            "genericwrite",
            "regsetvalueexw",
            "desktop",
            "webview",
            "mirai",
            "russsian data",
            "reevil",
            "money doc",
            "gmt flag",
            "server",
            "united kingdom",
            "france france",
            "ukraine ukraine",
            "llc name",
            "viet nam",
            "show",
            "cve",
            "bad traffic",
            "false",
            "error",
            "tags",
            "ipv4",
            "url https",
            "url http",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "entries",
            "monitor",
            "target",
            "members",
            "maas",
            "attack",
            "mitre att"
          ],
          "references": [
            "RANSOM_REvil - https://www.nextron-systems.com/notes-on-virustotal-matches/",
            "YARA:  Matches rule MAL_RANSOM_REvil_Oct20_1 from ruleset crime_ransom_revil by Florian Roth (Nextron Systems)",
            "YARA: Matches rule Windows_Ransomware_Sodinokibi_83f05fbe from ruleset Windows_Ransomware_Sodinokibi by Elastic Security",
            "YARA: Matches rule win_revil_auto from ruleset win.revil_auto by Felix Bilstein - yara-signator at cocacoding dot com",
            "https://otx.alienvault.com/malware/Ransom:Win32/Makop/",
            "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
            "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
            "Permissions requested: SE_DEBUG_PRIVILEGE SE_LOAD_DRIVER_PRIVILEGE",
            "Behaviour: Extract file to system directory"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransom:Win32/Makop.PA!MTB",
              "display_name": "Ransom:Win32/Makop.PA!MTB",
              "target": "/malware/Ransom:Win32/Makop.PA!MTB"
            },
            {
              "id": "Trojan/Win32.BlueCrab.R331768",
              "display_name": "Trojan/Win32.BlueCrab.R331768",
              "target": null
            },
            {
              "id": "Trojan.Ransom.Sodinokibi",
              "display_name": "Trojan.Ransom.Sodinokibi",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Virus.Neshta",
              "display_name": "Virus.Neshta",
              "target": null
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "RANSOM_REvil",
              "display_name": "RANSOM_REvil",
              "target": null
            },
            {
              "id": "Labeled as: Ransom.Sodinokibi.Generic",
              "display_name": "Labeled as: Ransom.Sodinokibi.Generic",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1035",
              "name": "Service Execution",
              "display_name": "T1035 - Service Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1215",
              "name": "Kernel Modules and Extensions",
              "display_name": "T1215 - Kernel Modules and Extensions"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1181",
              "name": "Extra Window Memory Injection",
              "display_name": "T1181 - Extra Window Memory Injection"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0010",
              "name": "Exfiltration",
              "display_name": "TA0010 - Exfiltration"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "684cad9bc64e61ae0e6df4c1",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 3,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 85,
            "FileHash-SHA256": 110,
            "URL": 83,
            "CVE": 1,
            "domain": 102,
            "hostname": 36
          },
          "indicator_count": 516,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "18 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "617af11f370d993aeff26e71",
          "name": "Kaseya VSA REvil Indicators",
          "description": "",
          "modified": "2025-08-25T16:22:33.668000",
          "created": "2021-10-28T18:51:11.197000",
          "tags": [
            "REvil",
            "Kaseya",
            "VSA Server",
            "ransomware"
          ],
          "references": [
            "https://www.virustotal.com/gui/file/d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e/details",
            "https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers",
            "https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/",
            "https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
            "https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/",
            "https://gist.github.com/fwosar/a63e1249bfccb8395b961d3d780c0354",
            "https://docs.google.com/spreadsheets/d/11AFPdK5A-7g484lfc0HmXdBrZpYI-Jhx4N1VwFXrcrQ/edit#gid=1201846661",
            "https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident?utm_campaign=CY21-Q3-RapidResponse-KaseyaVSA&utm_medium=email&_hsmi=138021297&_hsenc=p2ANqtz--HvqdKyS4A0PNoXQXXy44zns31VXVSOFaz97KXwFQMvl-wiRhktYL4l036tl-r5zmeY3RRVzgz2GqtktDCLPLQ8gB8vg&utm_content=138021297&utm_source=hs_email",
            "https://github.com/Neo23x0/signature-base/blob/master/yara/crime_revil_general.yar"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "REvil",
              "display_name": "REvil",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "60df80a7a665c1dd6baf7753",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "VertekLabs",
            "id": "168455",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_168455/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 16,
            "URL": 1,
            "domain": 1177,
            "hostname": 5,
            "YARA": 4
          },
          "indicator_count": 1233,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 564,
          "modified_text": "278 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "684cad9bc64e61ae0e6df4c1",
          "name": "Ransom  REevil | AWS.DEV | MaaS",
          "description": "Malicious campaigners paid to  target specific groups and individuals. Large ongoing operation.",
          "modified": "2025-07-13T22:02:31.447000",
          "created": "2025-06-13T23:00:43.338000",
          "tags": [
            "filehashmd5",
            "filehashsha1",
            "showing",
            "copyright",
            "levelblue",
            "packer entropy",
            "pe features",
            "pe unknown",
            "resource name",
            "allocates rwx",
            "network icmp",
            "antivm network",
            "exe nolookup",
            "proxy wpad",
            "dead host",
            "tools",
            "generic",
            "deletes self",
            "ransom",
            "evader",
            "active",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "installs",
            "adversaries",
            "windows",
            "modules",
            "registry",
            "persistence",
            "execution",
            "service",
            "united",
            "path",
            "flag",
            "date",
            "access type",
            "germany germany",
            "create",
            "http header",
            "tcp traffic",
            "et info",
            "entropy",
            "hybrid",
            "malicious",
            "general",
            "click",
            "strings",
            "inject",
            "remote",
            "encrypt files",
            "python",
            "global",
            "win32 exe",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 compiler",
            "overlay",
            "data",
            "pe32 executable",
            "borland delphi",
            "delphi generic",
            "md5 code",
            "empty hash",
            "file type",
            "success",
            "regopenkeyexw",
            "regopenkeyexa",
            "hkeycurrentuser",
            "virtualallocex",
            "createfilew",
            "genericread",
            "hkeyclassesroot",
            "genericwrite",
            "regsetvalueexw",
            "desktop",
            "webview",
            "mirai",
            "russsian data",
            "reevil",
            "money doc",
            "gmt flag",
            "server",
            "united kingdom",
            "france france",
            "ukraine ukraine",
            "llc name",
            "viet nam",
            "show",
            "cve",
            "bad traffic",
            "false",
            "error",
            "tags",
            "ipv4",
            "url https",
            "url http",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "entries",
            "monitor",
            "target",
            "members",
            "maas",
            "attack",
            "mitre att"
          ],
          "references": [
            "RANSOM_REvil - https://www.nextron-systems.com/notes-on-virustotal-matches/",
            "YARA:  Matches rule MAL_RANSOM_REvil_Oct20_1 from ruleset crime_ransom_revil by Florian Roth (Nextron Systems)",
            "YARA: Matches rule Windows_Ransomware_Sodinokibi_83f05fbe from ruleset Windows_Ransomware_Sodinokibi by Elastic Security",
            "YARA: Matches rule win_revil_auto from ruleset win.revil_auto by Felix Bilstein - yara-signator at cocacoding dot com",
            "https://otx.alienvault.com/malware/Ransom:Win32/Makop/",
            "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
            "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
            "Permissions requested: SE_DEBUG_PRIVILEGE SE_LOAD_DRIVER_PRIVILEGE",
            "Behaviour: Extract file to system directory"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransom:Win32/Makop.PA!MTB",
              "display_name": "Ransom:Win32/Makop.PA!MTB",
              "target": "/malware/Ransom:Win32/Makop.PA!MTB"
            },
            {
              "id": "Trojan/Win32.BlueCrab.R331768",
              "display_name": "Trojan/Win32.BlueCrab.R331768",
              "target": null
            },
            {
              "id": "Trojan.Ransom.Sodinokibi",
              "display_name": "Trojan.Ransom.Sodinokibi",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Virus.Neshta",
              "display_name": "Virus.Neshta",
              "target": null
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "RANSOM_REvil",
              "display_name": "RANSOM_REvil",
              "target": null
            },
            {
              "id": "Labeled as: Ransom.Sodinokibi.Generic",
              "display_name": "Labeled as: Ransom.Sodinokibi.Generic",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1035",
              "name": "Service Execution",
              "display_name": "T1035 - Service Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1215",
              "name": "Kernel Modules and Extensions",
              "display_name": "T1215 - Kernel Modules and Extensions"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1181",
              "name": "Extra Window Memory Injection",
              "display_name": "T1181 - Extra Window Memory Injection"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0010",
              "name": "Exfiltration",
              "display_name": "TA0010 - Exfiltration"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 85,
            "FileHash-SHA256": 110,
            "URL": 83,
            "CVE": 1,
            "domain": 102,
            "hostname": 36
          },
          "indicator_count": 516,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "321 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6585b183175afafb5e3bfff5",
          "name": "Potential Poodle Attack against a server | Injection | Threat Network",
          "description": "",
          "modified": "2024-01-21T15:01:52.390000",
          "created": "2023-12-22T15:55:47.977000",
          "tags": [
            "whois record",
            "ssl certificate",
            "threat roundup",
            "december",
            "whois whois",
            "historical ssl",
            "referrer",
            "problems",
            "november",
            "tsara brashears",
            "startpage",
            "core",
            "hacktool",
            "vhash",
            "authentihash",
            "imphash",
            "rich pe",
            "ssdeep",
            "file type",
            "win32 dll",
            "magic pe32",
            "intel",
            "ms windows",
            "compiler",
            "no data",
            "tag count",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "iocs",
            "sample summary",
            "as54113",
            "united",
            "xamzexpires300",
            "unknown",
            "a domains",
            "passive dns",
            "entries",
            "github pages",
            "request id",
            "sea x",
            "virtool",
            "accept",
            "cache",
            "hit x",
            "date hash",
            "avast avg",
            "files show",
            "execution",
            "contacted",
            "threat analyzer",
            "threat",
            "paste",
            "hostnames",
            "urls http",
            "noname057",
            "generic malware",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "generic",
            "inject",
            "!#AddsCopyToStartup",
            "SLF:Exploit:Win32/UACPathBypass.A",
            "SSL excessive fatal alerts (possible POODLE attack against serve",
            "injector",
            "185.199.108.133",
            "malware infection",
            "link",
            "name servers",
            "date",
            "title",
            "urls",
            "domain robot",
            "for privacy",
            "redacted for",
            "expiration date",
            "emotet",
            "upx",
            "msil",
            "trojan",
            "malware",
            "apple",
            "data collection",
            "privilege escalation",
            "evasive",
            "show",
            "scan endpoints",
            "all octoseek",
            "filehash",
            "pulse pulses",
            "av detections",
            "ids detections",
            "yara detections",
            "copy",
            "threat network",
            "service modification",
            "target",
            "targeting an individual",
            "cybercrime",
            "fraud services",
            "attack",
            "africa",
            "libel",
            "password cracker",
            "ios"
          ],
          "references": [
            "frostwire-5.3.9.windows.exe",
            "185.199.108.133",
            "cdn-185-199-108-133.github.com",
            "AS : AS16509 Amazon.com, Inc",
            "SRC URL : http://dl.frostwire.com/frostwire/5.3.9/frostwire-5.3.9.windows.exe",
            "IP : 54.192.29.164",
            "https://otx.alienvault.com/indicator/ip/185.199.108.133",
            "Malware Hosting: IPv4 185.199.108.133, 185.199.109.133, 185.199.110.133, 185.199.111.133",
            "YARA Rules",
            "Matches rule Windows_API_Function from ruleset Windows_API_Function by InQuest Labs",
            "Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
            "Matches rule UPX from ruleset UPX by kevoreilly",
            "REFERENCE: https://goo.gl/hXbwiV",
            "RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_JS_Command",
            "More information: https://www.nextron-systems.com/notes-on-virustotal-matches/",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
            "https://www.assurant.com/?utm_source=email&utm_medium=email&utm_campaign=Mobile_Transactional_withad&utm_content=Deductible+Charge+Acknowledgement+PD-MB&utm_term= [Mobile transactional with ads/ malicious]",
            "https://otx.alienvault.com/indicator/url/https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [ Walker | Apple Password Cracker]",
            "http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [Apple exploit]",
            "www.pornhub.com [New Relic | nr-data.net | Apple Private Data Collection]",
            "www.anyxxxtube.net",
            "https://otx.alienvault.com/indicator/url/https://www.bleepingcomputer.com/forums/t/268006/wormmalware-that-kills-run-system-restore-regedit/ [ phishing attack directed towards Tsara Brashears]",
            "phishing-campaign-cloudstation-eu-west-98.githubusercontent.com [phishing]",
            "louisianarooflawyers.com [phishing| songculture.com redirect , compromised by threat actors]",
            "103.246.145.111 [malware]",
            "x.ss2.us",
            "nr-data.net [Apple Private Data Collection]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Magic",
              "display_name": "Magic",
              "target": null
            },
            {
              "id": "Multios.Coinminer.Miner-6781728-2",
              "display_name": "Multios.Coinminer.Miner-6781728-2",
              "target": null
            },
            {
              "id": "Win32/Ispen BADNEWS Fake User-Agent",
              "display_name": "Win32/Ispen BADNEWS Fake User-Agent",
              "target": null
            },
            {
              "id": "Babulya/CollectorStealer User-Agent",
              "display_name": "Babulya/CollectorStealer User-Agent",
              "target": null
            },
            {
              "id": "Win.Malware.Generic-9820446-0",
              "display_name": "Win.Malware.Generic-9820446-0",
              "target": null
            },
            {
              "id": "Worm:Win32/AutoRun!atmn",
              "display_name": "Worm:Win32/AutoRun!atmn",
              "target": "/malware/Worm:Win32/AutoRun!atmn"
            },
            {
              "id": "VirTool:MSIL/Obfuscator.BV",
              "display_name": "VirTool:MSIL/Obfuscator.BV",
              "target": "/malware/VirTool:MSIL/Obfuscator.BV"
            },
            {
              "id": "Win.Trojan.Emotet-9850453-0",
              "display_name": "Win.Trojan.Emotet-9850453-0",
              "target": null
            },
            {
              "id": "ALF:HSTR:HackTool:ExtremeInjector.S01",
              "display_name": "ALF:HSTR:HackTool:ExtremeInjector.S01",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/AgentTesla!rfn",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/AgentTesla!rfn",
              "target": null
            },
            {
              "id": "!#HSTR:Win32/Spectorsoft",
              "display_name": "!#HSTR:Win32/Spectorsoft",
              "target": "/malware/!#HSTR:Win32/Spectorsoft"
            },
            {
              "id": "ALF:Base64EncodeFunctionMonitorW",
              "display_name": "ALF:Base64EncodeFunctionMonitorW",
              "target": null
            },
            {
              "id": "185.199.108.133.Malware_Host",
              "display_name": "185.199.108.133.Malware_Host",
              "target": null
            },
            {
              "id": "adware.opencandy",
              "display_name": "adware.opencandy",
              "target": null
            },
            {
              "id": "Malvertizing",
              "display_name": "Malvertizing",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 32,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1872,
            "FileHash-SHA1": 1140,
            "FileHash-SHA256": 2367,
            "URL": 1969,
            "domain": 327,
            "hostname": 1025,
            "email": 1
          },
          "indicator_count": 8701,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "860 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6585b18d61efd8798827c12a",
          "name": "Potential Poodle Attack against a server | Injection | Threat Network",
          "description": "",
          "modified": "2024-01-21T15:01:52.390000",
          "created": "2023-12-22T15:55:57.639000",
          "tags": [
            "whois record",
            "ssl certificate",
            "threat roundup",
            "december",
            "whois whois",
            "historical ssl",
            "referrer",
            "problems",
            "november",
            "tsara brashears",
            "startpage",
            "core",
            "hacktool",
            "vhash",
            "authentihash",
            "imphash",
            "rich pe",
            "ssdeep",
            "file type",
            "win32 dll",
            "magic pe32",
            "intel",
            "ms windows",
            "compiler",
            "no data",
            "tag count",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "search",
            "iocs",
            "sample summary",
            "as54113",
            "united",
            "xamzexpires300",
            "unknown",
            "a domains",
            "passive dns",
            "entries",
            "github pages",
            "request id",
            "sea x",
            "virtool",
            "accept",
            "cache",
            "hit x",
            "date hash",
            "avast avg",
            "files show",
            "execution",
            "contacted",
            "threat analyzer",
            "threat",
            "paste",
            "hostnames",
            "urls http",
            "noname057",
            "generic malware",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "generic",
            "inject",
            "!#AddsCopyToStartup",
            "SLF:Exploit:Win32/UACPathBypass.A",
            "SSL excessive fatal alerts (possible POODLE attack against serve",
            "injector",
            "185.199.108.133",
            "malware infection",
            "link",
            "name servers",
            "date",
            "title",
            "urls",
            "domain robot",
            "for privacy",
            "redacted for",
            "expiration date",
            "emotet",
            "upx",
            "msil",
            "trojan",
            "malware",
            "apple",
            "data collection",
            "privilege escalation",
            "evasive",
            "show",
            "scan endpoints",
            "all octoseek",
            "filehash",
            "pulse pulses",
            "av detections",
            "ids detections",
            "yara detections",
            "copy",
            "threat network",
            "service modification",
            "target",
            "targeting an individual",
            "cybercrime",
            "fraud services",
            "attack",
            "africa",
            "libel",
            "password cracker",
            "ios"
          ],
          "references": [
            "frostwire-5.3.9.windows.exe",
            "185.199.108.133",
            "cdn-185-199-108-133.github.com",
            "AS : AS16509 Amazon.com, Inc",
            "SRC URL : http://dl.frostwire.com/frostwire/5.3.9/frostwire-5.3.9.windows.exe",
            "IP : 54.192.29.164",
            "https://otx.alienvault.com/indicator/ip/185.199.108.133",
            "Malware Hosting: IPv4 185.199.108.133, 185.199.109.133, 185.199.110.133, 185.199.111.133",
            "YARA Rules",
            "Matches rule Windows_API_Function from ruleset Windows_API_Function by InQuest Labs",
            "Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
            "Matches rule UPX from ruleset UPX by kevoreilly",
            "REFERENCE: https://goo.gl/hXbwiV",
            "RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_JS_Command",
            "More information: https://www.nextron-systems.com/notes-on-virustotal-matches/",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
            "https://www.assurant.com/?utm_source=email&utm_medium=email&utm_campaign=Mobile_Transactional_withad&utm_content=Deductible+Charge+Acknowledgement+PD-MB&utm_term= [Mobile transactional with ads/ malicious]",
            "https://otx.alienvault.com/indicator/url/https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [ Walker | Apple Password Cracker]",
            "http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [Apple exploit]",
            "www.pornhub.com [New Relic | nr-data.net | Apple Private Data Collection]",
            "www.anyxxxtube.net",
            "https://otx.alienvault.com/indicator/url/https://www.bleepingcomputer.com/forums/t/268006/wormmalware-that-kills-run-system-restore-regedit/ [ phishing attack directed towards Tsara Brashears]",
            "phishing-campaign-cloudstation-eu-west-98.githubusercontent.com [phishing]",
            "louisianarooflawyers.com [phishing| songculture.com redirect , compromised by threat actors]",
            "103.246.145.111 [malware]",
            "x.ss2.us",
            "nr-data.net [Apple Private Data Collection]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "VirTool",
              "display_name": "VirTool",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Magic",
              "display_name": "Magic",
              "target": null
            },
            {
              "id": "Multios.Coinminer.Miner-6781728-2",
              "display_name": "Multios.Coinminer.Miner-6781728-2",
              "target": null
            },
            {
              "id": "Win32/Ispen BADNEWS Fake User-Agent",
              "display_name": "Win32/Ispen BADNEWS Fake User-Agent",
              "target": null
            },
            {
              "id": "Babulya/CollectorStealer User-Agent",
              "display_name": "Babulya/CollectorStealer User-Agent",
              "target": null
            },
            {
              "id": "Win.Malware.Generic-9820446-0",
              "display_name": "Win.Malware.Generic-9820446-0",
              "target": null
            },
            {
              "id": "Worm:Win32/AutoRun!atmn",
              "display_name": "Worm:Win32/AutoRun!atmn",
              "target": "/malware/Worm:Win32/AutoRun!atmn"
            },
            {
              "id": "VirTool:MSIL/Obfuscator.BV",
              "display_name": "VirTool:MSIL/Obfuscator.BV",
              "target": "/malware/VirTool:MSIL/Obfuscator.BV"
            },
            {
              "id": "Win.Trojan.Emotet-9850453-0",
              "display_name": "Win.Trojan.Emotet-9850453-0",
              "target": null
            },
            {
              "id": "ALF:HSTR:HackTool:ExtremeInjector.S01",
              "display_name": "ALF:HSTR:HackTool:ExtremeInjector.S01",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/AgentTesla!rfn",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/AgentTesla!rfn",
              "target": null
            },
            {
              "id": "!#HSTR:Win32/Spectorsoft",
              "display_name": "!#HSTR:Win32/Spectorsoft",
              "target": "/malware/!#HSTR:Win32/Spectorsoft"
            },
            {
              "id": "ALF:Base64EncodeFunctionMonitorW",
              "display_name": "ALF:Base64EncodeFunctionMonitorW",
              "target": null
            },
            {
              "id": "185.199.108.133.Malware_Host",
              "display_name": "185.199.108.133.Malware_Host",
              "target": null
            },
            {
              "id": "adware.opencandy",
              "display_name": "adware.opencandy",
              "target": null
            },
            {
              "id": "Malvertizing",
              "display_name": "Malvertizing",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 32,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1872,
            "FileHash-SHA1": 1140,
            "FileHash-SHA256": 2367,
            "URL": 1969,
            "domain": 327,
            "hostname": 1025,
            "email": 1
          },
          "indicator_count": 8701,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "860 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708d5530ef54f76f70777b",
          "name": "New Sample of REvil Ransomware - REvil Returned?",
          "description": "",
          "modified": "2023-12-06T15:03:49.881000",
          "created": "2023-12-06T15:03:49.881000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 800,
            "FileHash-MD5": 198,
            "FileHash-SHA1": 198,
            "domain": 419,
            "hostname": 5
          },
          "indicator_count": 1620,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707c3be05f3a7ea9e654d4",
          "name": "Kaseya VSA REvil Indicators",
          "description": "",
          "modified": "2023-12-06T13:50:51.719000",
          "created": "2023-12-06T13:50:51.719000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 16,
            "URL": 1,
            "domain": 1178,
            "hostname": 5,
            "YARA": 4
          },
          "indicator_count": 1234,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707bedc2fbc934427f325c",
          "name": "Kaseya VSA REvil Indicators",
          "description": "",
          "modified": "2023-12-06T13:49:33.291000",
          "created": "2023-12-06T13:49:33.291000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 16,
            "URL": 1,
            "domain": 1179,
            "hostname": 5,
            "YARA": 4
          },
          "indicator_count": 1235,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6273e73af82e7127ef0c570e",
          "name": "New Sample of REvil Ransomware - REvil Returned?",
          "description": "A New sample of REvil has emerged almost a year after the major Attack on Kaseya.",
          "modified": "2022-06-04T00:03:57.626000",
          "created": "2022-05-05T15:03:22.128000",
          "tags": [
            "REvil",
            "Sodinokibi"
          ],
          "references": [
            "https://www.virustotal.com/graph/0c10cf1b1640c9c845080f460ee69392bfaac981a4407b607e8e30d2ddf903e8",
            "https://blog.malwarebytes.com/ransomware/2022/05/its-business-as-usual-for-revil-ransomware/",
            "https://twitter.com/JakubKroustek/status/1520135975262957568/photo/2"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Ransom:Win32/Revil",
              "display_name": "Ransom:Win32/Revil",
              "target": "/malware/Ransom:Win32/Revil"
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "BITSecurity",
            "id": "103352",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_103352/resized/80/avatar_1540652530.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 198,
            "FileHash-SHA1": 198,
            "FileHash-SHA256": 800,
            "domain": 419,
            "hostname": 5
          },
          "indicator_count": 1620,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 246,
          "modified_text": "1457 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62256a33bdf7c94b437d1be9",
          "name": "Risky domains",
          "description": "A list of 20 domains that are recognized as risky for the users",
          "modified": "2022-03-07T02:13:07.512000",
          "created": "2022-03-07T02:13:07.512000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Juank4986",
            "id": "167839",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 20
          },
          "indicator_count": 20,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 0,
          "modified_text": "1546 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "621fd560d5153c1fc94d8425",
          "name": "reported urls",
          "description": "",
          "modified": "2022-03-02T20:36:48.124000",
          "created": "2022-03-02T20:36:48.124000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CamiloF002",
            "id": "183333",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 30
          },
          "indicator_count": 30,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 6,
          "modified_text": "1550 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "60df80a7a665c1dd6baf7753",
          "name": "Kaseya VSA REvil Indicators",
          "description": "",
          "modified": "2022-02-18T14:52:05.251000",
          "created": "2021-07-02T21:09:59.361000",
          "tags": [
            "REvil",
            "Kaseya",
            "VSA Server",
            "ransomware"
          ],
          "references": [
            "https://www.virustotal.com/gui/file/d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e/details",
            "https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers",
            "https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/",
            "https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
            "https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/",
            "https://gist.github.com/fwosar/a63e1249bfccb8395b961d3d780c0354",
            "https://docs.google.com/spreadsheets/d/11AFPdK5A-7g484lfc0HmXdBrZpYI-Jhx4N1VwFXrcrQ/edit#gid=1201846661",
            "https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident?utm_campaign=CY21-Q3-RapidResponse-KaseyaVSA&utm_medium=email&_hsmi=138021297&_hsenc=p2ANqtz--HvqdKyS4A0PNoXQXXy44zns31VXVSOFaz97KXwFQMvl-wiRhktYL4l036tl-r5zmeY3RRVzgz2GqtktDCLPLQ8gB8vg&utm_content=138021297&utm_source=hs_email",
            "https://github.com/Neo23x0/signature-base/blob/master/yara/crime_revil_general.yar"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "REvil",
              "display_name": "REvil",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 63,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "vthelpdesk",
            "id": "1766",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_1766/resized/80/avatar_0be7a35fab.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 15,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 16,
            "URL": 1,
            "domain": 1179,
            "hostname": 5,
            "YARA": 4
          },
          "indicator_count": 1235,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 624,
          "modified_text": "1562 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://docs.google.com/spreadsheets/d/11AFPdK5A-7g484lfc0HmXdBrZpYI-Jhx4N1VwFXrcrQ/edit#gid=1201846661",
        "louisianarooflawyers.com [phishing| songculture.com redirect , compromised by threat actors]",
        "https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/",
        "Matches rule UPX from ruleset UPX by kevoreilly",
        "www.anyxxxtube.net",
        "Behaviour: Extract file to system directory",
        "https://otx.alienvault.com/indicator/url/https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [ Walker | Apple Password Cracker]",
        "https://gist.github.com/fwosar/a63e1249bfccb8395b961d3d780c0354",
        "https://otx.alienvault.com/indicator/ip/185.199.108.133",
        "YARA: Matches rule win_revil_auto from ruleset win.revil_auto by Felix Bilstein - yara-signator at cocacoding dot com",
        "YARA:  Matches rule MAL_RANSOM_REvil_Oct20_1 from ruleset crime_ransom_revil by Florian Roth (Nextron Systems)",
        "More information: https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "SRC URL : http://dl.frostwire.com/frostwire/5.3.9/frostwire-5.3.9.windows.exe",
        "Matches rule Windows_API_Function from ruleset Windows_API_Function by InQuest Labs",
        "https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident?utm_campaign=CY21-Q3-RapidResponse-KaseyaVSA&utm_medium=email&_hsmi=138021297&_hsenc=p2ANqtz--HvqdKyS4A0PNoXQXXy44zns31VXVSOFaz97KXwFQMvl-wiRhktYL4l036tl-r5zmeY3RRVzgz2GqtktDCLPLQ8gB8vg&utm_content=138021297&utm_source=hs_email",
        "https://blog.malwarebytes.com/ransomware/2022/05/its-business-as-usual-for-revil-ransomware/",
        "103.246.145.111 [malware]",
        "https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
        "RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_JS_Command",
        "https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers",
        "Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
        "https://otx.alienvault.com/malware/Ransom:Win32/Makop/",
        "185.199.108.133",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
        "IP : 54.192.29.164",
        "www.pornhub.com [New Relic | nr-data.net | Apple Private Data Collection]",
        "x.ss2.us",
        "AS : AS16509 Amazon.com, Inc",
        "https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/",
        "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
        "Permissions requested: SE_DEBUG_PRIVILEGE SE_LOAD_DRIVER_PRIVILEGE",
        "https://www.assurant.com/?utm_source=email&utm_medium=email&utm_campaign=Mobile_Transactional_withad&utm_content=Deductible+Charge+Acknowledgement+PD-MB&utm_term= [Mobile transactional with ads/ malicious]",
        "https://www.virustotal.com/graph/0c10cf1b1640c9c845080f460ee69392bfaac981a4407b607e8e30d2ddf903e8",
        "YARA Rules",
        "frostwire-5.3.9.windows.exe",
        "phishing-campaign-cloudstation-eu-west-98.githubusercontent.com [phishing]",
        "Malware Hosting: IPv4 185.199.108.133, 185.199.109.133, 185.199.110.133, 185.199.111.133",
        "REFERENCE: https://goo.gl/hXbwiV",
        "https://otx.alienvault.com/indicator/url/https://www.bleepingcomputer.com/forums/t/268006/wormmalware-that-kills-run-system-restore-regedit/ [ phishing attack directed towards Tsara Brashears]",
        "http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [Apple exploit]",
        "cdn-185-199-108-133.github.com",
        "nr-data.net [Apple Private Data Collection]",
        "https://twitter.com/JakubKroustek/status/1520135975262957568/photo/2",
        "https://github.com/Neo23x0/signature-base/blob/master/yara/crime_revil_general.yar",
        "RANSOM_REvil - https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "YARA: Matches rule Windows_Ransomware_Sodinokibi_83f05fbe from ruleset Windows_Ransomware_Sodinokibi by Elastic Security",
        "https://www.virustotal.com/gui/file/d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e/details"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Trojan/win32.bluecrab.r331768",
            "Babulya/collectorstealer user-agent",
            "185.199.108.133.malware_host",
            "Revil",
            "Win.trojan.emotet-9850453-0",
            "Adware.opencandy",
            "Ransom_revil",
            "Virus.neshta",
            "Win.malware.generic-9820446-0",
            "Alf:base64encodefunctionmonitorw",
            "Labeled as: ransom.sodinokibi.generic",
            "Alf:hstr:hacktool:extremeinjector.s01",
            "Malvertizing",
            "Generic",
            "Mirai",
            "Magic",
            "!#hstr:win32/spectorsoft",
            "Ransom:win32/makop.pa!mtb",
            "Emotet",
            "Alf:heraklezeval:trojan:win32/agenttesla!rfn",
            "Win32/ispen badnews fake user-agent",
            "Virtool",
            "Multios.coinminer.miner-6781728-2",
            "Ransom:win32/revil",
            "Worm:win32/autorun!atmn",
            "Hacktool",
            "Virtool:msil/obfuscator.bv",
            "Trojan.ransom.sodinokibi"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 14,
  "pulses": [
    {
      "id": "6a040bf64fe2efef00132467",
      "name": "AWS.DEV | Ransom REevil | MaaS -Mirai , Makop , Sodinokibi | 6.13.25 Appears ti be ongoing  ",
      "description": "",
      "modified": "2026-05-13T05:28:22.199000",
      "created": "2026-05-13T05:28:22.199000",
      "tags": [
        "filehashmd5",
        "filehashsha1",
        "showing",
        "copyright",
        "levelblue",
        "packer entropy",
        "pe features",
        "pe unknown",
        "resource name",
        "allocates rwx",
        "network icmp",
        "antivm network",
        "exe nolookup",
        "proxy wpad",
        "dead host",
        "tools",
        "generic",
        "deletes self",
        "ransom",
        "evader",
        "active",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "installs",
        "adversaries",
        "windows",
        "modules",
        "registry",
        "persistence",
        "execution",
        "service",
        "united",
        "path",
        "flag",
        "date",
        "access type",
        "germany germany",
        "create",
        "http header",
        "tcp traffic",
        "et info",
        "entropy",
        "hybrid",
        "malicious",
        "general",
        "click",
        "strings",
        "inject",
        "remote",
        "encrypt files",
        "python",
        "global",
        "win32 exe",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 compiler",
        "overlay",
        "data",
        "pe32 executable",
        "borland delphi",
        "delphi generic",
        "md5 code",
        "empty hash",
        "file type",
        "success",
        "regopenkeyexw",
        "regopenkeyexa",
        "hkeycurrentuser",
        "virtualallocex",
        "createfilew",
        "genericread",
        "hkeyclassesroot",
        "genericwrite",
        "regsetvalueexw",
        "desktop",
        "webview",
        "mirai",
        "russsian data",
        "reevil",
        "money doc",
        "gmt flag",
        "server",
        "united kingdom",
        "france france",
        "ukraine ukraine",
        "llc name",
        "viet nam",
        "show",
        "cve",
        "bad traffic",
        "false",
        "error",
        "tags",
        "ipv4",
        "url https",
        "url http",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "entries",
        "monitor",
        "target",
        "members",
        "maas",
        "attack",
        "mitre att"
      ],
      "references": [
        "RANSOM_REvil - https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "YARA:  Matches rule MAL_RANSOM_REvil_Oct20_1 from ruleset crime_ransom_revil by Florian Roth (Nextron Systems)",
        "YARA: Matches rule Windows_Ransomware_Sodinokibi_83f05fbe from ruleset Windows_Ransomware_Sodinokibi by Elastic Security",
        "YARA: Matches rule win_revil_auto from ruleset win.revil_auto by Felix Bilstein - yara-signator at cocacoding dot com",
        "https://otx.alienvault.com/malware/Ransom:Win32/Makop/",
        "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
        "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
        "Permissions requested: SE_DEBUG_PRIVILEGE SE_LOAD_DRIVER_PRIVILEGE",
        "Behaviour: Extract file to system directory"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Ransom:Win32/Makop.PA!MTB",
          "display_name": "Ransom:Win32/Makop.PA!MTB",
          "target": "/malware/Ransom:Win32/Makop.PA!MTB"
        },
        {
          "id": "Trojan/Win32.BlueCrab.R331768",
          "display_name": "Trojan/Win32.BlueCrab.R331768",
          "target": null
        },
        {
          "id": "Trojan.Ransom.Sodinokibi",
          "display_name": "Trojan.Ransom.Sodinokibi",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Virus.Neshta",
          "display_name": "Virus.Neshta",
          "target": null
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "RANSOM_REvil",
          "display_name": "RANSOM_REvil",
          "target": null
        },
        {
          "id": "Labeled as: Ransom.Sodinokibi.Generic",
          "display_name": "Labeled as: Ransom.Sodinokibi.Generic",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1035",
          "name": "Service Execution",
          "display_name": "T1035 - Service Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1215",
          "name": "Kernel Modules and Extensions",
          "display_name": "T1215 - Kernel Modules and Extensions"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1181",
          "name": "Extra Window Memory Injection",
          "display_name": "T1181 - Extra Window Memory Injection"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0010",
          "name": "Exfiltration",
          "display_name": "TA0010 - Exfiltration"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "684cad9bc64e61ae0e6df4c1",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 85,
        "FileHash-SHA256": 110,
        "URL": 83,
        "CVE": 1,
        "domain": 102,
        "hostname": 36
      },
      "indicator_count": 516,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "18 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a03f318b2e654e26402adaa",
      "name": "\" New Sample of REvil Ransomware - REvil Returned?\" by SteamMiningEx",
      "description": "",
      "modified": "2026-05-13T05:26:35.084000",
      "created": "2026-05-13T03:42:16.083000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65708d5530ef54f76f70777b",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 802,
        "FileHash-MD5": 209,
        "FileHash-SHA1": 198,
        "domain": 517,
        "hostname": 8,
        "URL": 2
      },
      "indicator_count": 1736,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "18 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a040afa13cf077fedd59f36",
      "name": "Ransom REevil | AWS.DEV | MaaS -Mirai , Makop , Sodinokibi , FlyStudio + Campaign| Appears to be ongoing ",
      "description": "",
      "modified": "2026-05-13T05:24:10.262000",
      "created": "2026-05-13T05:24:10.262000",
      "tags": [
        "filehashmd5",
        "filehashsha1",
        "showing",
        "copyright",
        "levelblue",
        "packer entropy",
        "pe features",
        "pe unknown",
        "resource name",
        "allocates rwx",
        "network icmp",
        "antivm network",
        "exe nolookup",
        "proxy wpad",
        "dead host",
        "tools",
        "generic",
        "deletes self",
        "ransom",
        "evader",
        "active",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "installs",
        "adversaries",
        "windows",
        "modules",
        "registry",
        "persistence",
        "execution",
        "service",
        "united",
        "path",
        "flag",
        "date",
        "access type",
        "germany germany",
        "create",
        "http header",
        "tcp traffic",
        "et info",
        "entropy",
        "hybrid",
        "malicious",
        "general",
        "click",
        "strings",
        "inject",
        "remote",
        "encrypt files",
        "python",
        "global",
        "win32 exe",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 compiler",
        "overlay",
        "data",
        "pe32 executable",
        "borland delphi",
        "delphi generic",
        "md5 code",
        "empty hash",
        "file type",
        "success",
        "regopenkeyexw",
        "regopenkeyexa",
        "hkeycurrentuser",
        "virtualallocex",
        "createfilew",
        "genericread",
        "hkeyclassesroot",
        "genericwrite",
        "regsetvalueexw",
        "desktop",
        "webview",
        "mirai",
        "russsian data",
        "reevil",
        "money doc",
        "gmt flag",
        "server",
        "united kingdom",
        "france france",
        "ukraine ukraine",
        "llc name",
        "viet nam",
        "show",
        "cve",
        "bad traffic",
        "false",
        "error",
        "tags",
        "ipv4",
        "url https",
        "url http",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "entries",
        "monitor",
        "target",
        "members",
        "maas",
        "attack",
        "mitre att"
      ],
      "references": [
        "RANSOM_REvil - https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "YARA:  Matches rule MAL_RANSOM_REvil_Oct20_1 from ruleset crime_ransom_revil by Florian Roth (Nextron Systems)",
        "YARA: Matches rule Windows_Ransomware_Sodinokibi_83f05fbe from ruleset Windows_Ransomware_Sodinokibi by Elastic Security",
        "YARA: Matches rule win_revil_auto from ruleset win.revil_auto by Felix Bilstein - yara-signator at cocacoding dot com",
        "https://otx.alienvault.com/malware/Ransom:Win32/Makop/",
        "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
        "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
        "Permissions requested: SE_DEBUG_PRIVILEGE SE_LOAD_DRIVER_PRIVILEGE",
        "Behaviour: Extract file to system directory"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Ransom:Win32/Makop.PA!MTB",
          "display_name": "Ransom:Win32/Makop.PA!MTB",
          "target": "/malware/Ransom:Win32/Makop.PA!MTB"
        },
        {
          "id": "Trojan/Win32.BlueCrab.R331768",
          "display_name": "Trojan/Win32.BlueCrab.R331768",
          "target": null
        },
        {
          "id": "Trojan.Ransom.Sodinokibi",
          "display_name": "Trojan.Ransom.Sodinokibi",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Virus.Neshta",
          "display_name": "Virus.Neshta",
          "target": null
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "RANSOM_REvil",
          "display_name": "RANSOM_REvil",
          "target": null
        },
        {
          "id": "Labeled as: Ransom.Sodinokibi.Generic",
          "display_name": "Labeled as: Ransom.Sodinokibi.Generic",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1035",
          "name": "Service Execution",
          "display_name": "T1035 - Service Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1215",
          "name": "Kernel Modules and Extensions",
          "display_name": "T1215 - Kernel Modules and Extensions"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1181",
          "name": "Extra Window Memory Injection",
          "display_name": "T1181 - Extra Window Memory Injection"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0010",
          "name": "Exfiltration",
          "display_name": "TA0010 - Exfiltration"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "684cad9bc64e61ae0e6df4c1",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 3,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 85,
        "FileHash-SHA256": 110,
        "URL": 83,
        "CVE": 1,
        "domain": 102,
        "hostname": 36
      },
      "indicator_count": 516,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "18 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "617af11f370d993aeff26e71",
      "name": "Kaseya VSA REvil Indicators",
      "description": "",
      "modified": "2025-08-25T16:22:33.668000",
      "created": "2021-10-28T18:51:11.197000",
      "tags": [
        "REvil",
        "Kaseya",
        "VSA Server",
        "ransomware"
      ],
      "references": [
        "https://www.virustotal.com/gui/file/d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e/details",
        "https://community.sophos.com/b/security-blog/posts/active-ransomware-attack-on-kaseya-customers",
        "https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/",
        "https://doublepulsar.com/kaseya-supply-chain-attack-delivers-mass-ransomware-event-to-us-companies-76e4ec6ec64b",
        "https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransomware_incident_in_progress/",
        "https://gist.github.com/fwosar/a63e1249bfccb8395b961d3d780c0354",
        "https://docs.google.com/spreadsheets/d/11AFPdK5A-7g484lfc0HmXdBrZpYI-Jhx4N1VwFXrcrQ/edit#gid=1201846661",
        "https://www.huntress.com/blog/rapid-response-kaseya-vsa-mass-msp-ransomware-incident?utm_campaign=CY21-Q3-RapidResponse-KaseyaVSA&utm_medium=email&_hsmi=138021297&_hsenc=p2ANqtz--HvqdKyS4A0PNoXQXXy44zns31VXVSOFaz97KXwFQMvl-wiRhktYL4l036tl-r5zmeY3RRVzgz2GqtktDCLPLQ8gB8vg&utm_content=138021297&utm_source=hs_email",
        "https://github.com/Neo23x0/signature-base/blob/master/yara/crime_revil_general.yar"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "REvil",
          "display_name": "REvil",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "60df80a7a665c1dd6baf7753",
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "VertekLabs",
        "id": "168455",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_168455/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 15,
        "FileHash-SHA1": 15,
        "FileHash-SHA256": 16,
        "URL": 1,
        "domain": 1177,
        "hostname": 5,
        "YARA": 4
      },
      "indicator_count": 1233,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 564,
      "modified_text": "278 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "684cad9bc64e61ae0e6df4c1",
      "name": "Ransom  REevil | AWS.DEV | MaaS",
      "description": "Malicious campaigners paid to  target specific groups and individuals. Large ongoing operation.",
      "modified": "2025-07-13T22:02:31.447000",
      "created": "2025-06-13T23:00:43.338000",
      "tags": [
        "filehashmd5",
        "filehashsha1",
        "showing",
        "copyright",
        "levelblue",
        "packer entropy",
        "pe features",
        "pe unknown",
        "resource name",
        "allocates rwx",
        "network icmp",
        "antivm network",
        "exe nolookup",
        "proxy wpad",
        "dead host",
        "tools",
        "generic",
        "deletes self",
        "ransom",
        "evader",
        "active",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "installs",
        "adversaries",
        "windows",
        "modules",
        "registry",
        "persistence",
        "execution",
        "service",
        "united",
        "path",
        "flag",
        "date",
        "access type",
        "germany germany",
        "create",
        "http header",
        "tcp traffic",
        "et info",
        "entropy",
        "hybrid",
        "malicious",
        "general",
        "click",
        "strings",
        "inject",
        "remote",
        "encrypt files",
        "python",
        "global",
        "win32 exe",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 compiler",
        "overlay",
        "data",
        "pe32 executable",
        "borland delphi",
        "delphi generic",
        "md5 code",
        "empty hash",
        "file type",
        "success",
        "regopenkeyexw",
        "regopenkeyexa",
        "hkeycurrentuser",
        "virtualallocex",
        "createfilew",
        "genericread",
        "hkeyclassesroot",
        "genericwrite",
        "regsetvalueexw",
        "desktop",
        "webview",
        "mirai",
        "russsian data",
        "reevil",
        "money doc",
        "gmt flag",
        "server",
        "united kingdom",
        "france france",
        "ukraine ukraine",
        "llc name",
        "viet nam",
        "show",
        "cve",
        "bad traffic",
        "false",
        "error",
        "tags",
        "ipv4",
        "url https",
        "url http",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "entries",
        "monitor",
        "target",
        "members",
        "maas",
        "attack",
        "mitre att"
      ],
      "references": [
        "RANSOM_REvil - https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "YARA:  Matches rule MAL_RANSOM_REvil_Oct20_1 from ruleset crime_ransom_revil by Florian Roth (Nextron Systems)",
        "YARA: Matches rule Windows_Ransomware_Sodinokibi_83f05fbe from ruleset Windows_Ransomware_Sodinokibi by Elastic Security",
        "YARA: Matches rule win_revil_auto from ruleset win.revil_auto by Felix Bilstein - yara-signator at cocacoding dot com",
        "https://otx.alienvault.com/malware/Ransom:Win32/Makop/",
        "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
        "https://www.hybrid-analysis.com/sample/cb33f3d60a715436ab49ab7968c5a31410d0cd6b9d141b41b2362c02b59e2913/5e68effaec3f2e3f0c5237b8",
        "Permissions requested: SE_DEBUG_PRIVILEGE SE_LOAD_DRIVER_PRIVILEGE",
        "Behaviour: Extract file to system directory"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Ransom:Win32/Makop.PA!MTB",
          "display_name": "Ransom:Win32/Makop.PA!MTB",
          "target": "/malware/Ransom:Win32/Makop.PA!MTB"
        },
        {
          "id": "Trojan/Win32.BlueCrab.R331768",
          "display_name": "Trojan/Win32.BlueCrab.R331768",
          "target": null
        },
        {
          "id": "Trojan.Ransom.Sodinokibi",
          "display_name": "Trojan.Ransom.Sodinokibi",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Virus.Neshta",
          "display_name": "Virus.Neshta",
          "target": null
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "RANSOM_REvil",
          "display_name": "RANSOM_REvil",
          "target": null
        },
        {
          "id": "Labeled as: Ransom.Sodinokibi.Generic",
          "display_name": "Labeled as: Ransom.Sodinokibi.Generic",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1035",
          "name": "Service Execution",
          "display_name": "T1035 - Service Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1215",
          "name": "Kernel Modules and Extensions",
          "display_name": "T1215 - Kernel Modules and Extensions"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1181",
          "name": "Extra Window Memory Injection",
          "display_name": "T1181 - Extra Window Memory Injection"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0010",
          "name": "Exfiltration",
          "display_name": "TA0010 - Exfiltration"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 28,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 85,
        "FileHash-SHA256": 110,
        "URL": 83,
        "CVE": 1,
        "domain": 102,
        "hostname": 36
      },
      "indicator_count": 516,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "321 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6585b183175afafb5e3bfff5",
      "name": "Potential Poodle Attack against a server | Injection | Threat Network",
      "description": "",
      "modified": "2024-01-21T15:01:52.390000",
      "created": "2023-12-22T15:55:47.977000",
      "tags": [
        "whois record",
        "ssl certificate",
        "threat roundup",
        "december",
        "whois whois",
        "historical ssl",
        "referrer",
        "problems",
        "november",
        "tsara brashears",
        "startpage",
        "core",
        "hacktool",
        "vhash",
        "authentihash",
        "imphash",
        "rich pe",
        "ssdeep",
        "file type",
        "win32 dll",
        "magic pe32",
        "intel",
        "ms windows",
        "compiler",
        "no data",
        "tag count",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "search",
        "iocs",
        "sample summary",
        "as54113",
        "united",
        "xamzexpires300",
        "unknown",
        "a domains",
        "passive dns",
        "entries",
        "github pages",
        "request id",
        "sea x",
        "virtool",
        "accept",
        "cache",
        "hit x",
        "date hash",
        "avast avg",
        "files show",
        "execution",
        "contacted",
        "threat analyzer",
        "threat",
        "paste",
        "hostnames",
        "urls http",
        "noname057",
        "generic malware",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "generic",
        "inject",
        "!#AddsCopyToStartup",
        "SLF:Exploit:Win32/UACPathBypass.A",
        "SSL excessive fatal alerts (possible POODLE attack against serve",
        "injector",
        "185.199.108.133",
        "malware infection",
        "link",
        "name servers",
        "date",
        "title",
        "urls",
        "domain robot",
        "for privacy",
        "redacted for",
        "expiration date",
        "emotet",
        "upx",
        "msil",
        "trojan",
        "malware",
        "apple",
        "data collection",
        "privilege escalation",
        "evasive",
        "show",
        "scan endpoints",
        "all octoseek",
        "filehash",
        "pulse pulses",
        "av detections",
        "ids detections",
        "yara detections",
        "copy",
        "threat network",
        "service modification",
        "target",
        "targeting an individual",
        "cybercrime",
        "fraud services",
        "attack",
        "africa",
        "libel",
        "password cracker",
        "ios"
      ],
      "references": [
        "frostwire-5.3.9.windows.exe",
        "185.199.108.133",
        "cdn-185-199-108-133.github.com",
        "AS : AS16509 Amazon.com, Inc",
        "SRC URL : http://dl.frostwire.com/frostwire/5.3.9/frostwire-5.3.9.windows.exe",
        "IP : 54.192.29.164",
        "https://otx.alienvault.com/indicator/ip/185.199.108.133",
        "Malware Hosting: IPv4 185.199.108.133, 185.199.109.133, 185.199.110.133, 185.199.111.133",
        "YARA Rules",
        "Matches rule Windows_API_Function from ruleset Windows_API_Function by InQuest Labs",
        "Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
        "Matches rule UPX from ruleset UPX by kevoreilly",
        "REFERENCE: https://goo.gl/hXbwiV",
        "RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_JS_Command",
        "More information: https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
        "https://www.assurant.com/?utm_source=email&utm_medium=email&utm_campaign=Mobile_Transactional_withad&utm_content=Deductible+Charge+Acknowledgement+PD-MB&utm_term= [Mobile transactional with ads/ malicious]",
        "https://otx.alienvault.com/indicator/url/https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [ Walker | Apple Password Cracker]",
        "http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [Apple exploit]",
        "www.pornhub.com [New Relic | nr-data.net | Apple Private Data Collection]",
        "www.anyxxxtube.net",
        "https://otx.alienvault.com/indicator/url/https://www.bleepingcomputer.com/forums/t/268006/wormmalware-that-kills-run-system-restore-regedit/ [ phishing attack directed towards Tsara Brashears]",
        "phishing-campaign-cloudstation-eu-west-98.githubusercontent.com [phishing]",
        "louisianarooflawyers.com [phishing| songculture.com redirect , compromised by threat actors]",
        "103.246.145.111 [malware]",
        "x.ss2.us",
        "nr-data.net [Apple Private Data Collection]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Magic",
          "display_name": "Magic",
          "target": null
        },
        {
          "id": "Multios.Coinminer.Miner-6781728-2",
          "display_name": "Multios.Coinminer.Miner-6781728-2",
          "target": null
        },
        {
          "id": "Win32/Ispen BADNEWS Fake User-Agent",
          "display_name": "Win32/Ispen BADNEWS Fake User-Agent",
          "target": null
        },
        {
          "id": "Babulya/CollectorStealer User-Agent",
          "display_name": "Babulya/CollectorStealer User-Agent",
          "target": null
        },
        {
          "id": "Win.Malware.Generic-9820446-0",
          "display_name": "Win.Malware.Generic-9820446-0",
          "target": null
        },
        {
          "id": "Worm:Win32/AutoRun!atmn",
          "display_name": "Worm:Win32/AutoRun!atmn",
          "target": "/malware/Worm:Win32/AutoRun!atmn"
        },
        {
          "id": "VirTool:MSIL/Obfuscator.BV",
          "display_name": "VirTool:MSIL/Obfuscator.BV",
          "target": "/malware/VirTool:MSIL/Obfuscator.BV"
        },
        {
          "id": "Win.Trojan.Emotet-9850453-0",
          "display_name": "Win.Trojan.Emotet-9850453-0",
          "target": null
        },
        {
          "id": "ALF:HSTR:HackTool:ExtremeInjector.S01",
          "display_name": "ALF:HSTR:HackTool:ExtremeInjector.S01",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/AgentTesla!rfn",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/AgentTesla!rfn",
          "target": null
        },
        {
          "id": "!#HSTR:Win32/Spectorsoft",
          "display_name": "!#HSTR:Win32/Spectorsoft",
          "target": "/malware/!#HSTR:Win32/Spectorsoft"
        },
        {
          "id": "ALF:Base64EncodeFunctionMonitorW",
          "display_name": "ALF:Base64EncodeFunctionMonitorW",
          "target": null
        },
        {
          "id": "185.199.108.133.Malware_Host",
          "display_name": "185.199.108.133.Malware_Host",
          "target": null
        },
        {
          "id": "adware.opencandy",
          "display_name": "adware.opencandy",
          "target": null
        },
        {
          "id": "Malvertizing",
          "display_name": "Malvertizing",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 32,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1872,
        "FileHash-SHA1": 1140,
        "FileHash-SHA256": 2367,
        "URL": 1969,
        "domain": 327,
        "hostname": 1025,
        "email": 1
      },
      "indicator_count": 8701,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "860 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6585b18d61efd8798827c12a",
      "name": "Potential Poodle Attack against a server | Injection | Threat Network",
      "description": "",
      "modified": "2024-01-21T15:01:52.390000",
      "created": "2023-12-22T15:55:57.639000",
      "tags": [
        "whois record",
        "ssl certificate",
        "threat roundup",
        "december",
        "whois whois",
        "historical ssl",
        "referrer",
        "problems",
        "november",
        "tsara brashears",
        "startpage",
        "core",
        "hacktool",
        "vhash",
        "authentihash",
        "imphash",
        "rich pe",
        "ssdeep",
        "file type",
        "win32 dll",
        "magic pe32",
        "intel",
        "ms windows",
        "compiler",
        "no data",
        "tag count",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "search",
        "iocs",
        "sample summary",
        "as54113",
        "united",
        "xamzexpires300",
        "unknown",
        "a domains",
        "passive dns",
        "entries",
        "github pages",
        "request id",
        "sea x",
        "virtool",
        "accept",
        "cache",
        "hit x",
        "date hash",
        "avast avg",
        "files show",
        "execution",
        "contacted",
        "threat analyzer",
        "threat",
        "paste",
        "hostnames",
        "urls http",
        "noname057",
        "generic malware",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "generic",
        "inject",
        "!#AddsCopyToStartup",
        "SLF:Exploit:Win32/UACPathBypass.A",
        "SSL excessive fatal alerts (possible POODLE attack against serve",
        "injector",
        "185.199.108.133",
        "malware infection",
        "link",
        "name servers",
        "date",
        "title",
        "urls",
        "domain robot",
        "for privacy",
        "redacted for",
        "expiration date",
        "emotet",
        "upx",
        "msil",
        "trojan",
        "malware",
        "apple",
        "data collection",
        "privilege escalation",
        "evasive",
        "show",
        "scan endpoints",
        "all octoseek",
        "filehash",
        "pulse pulses",
        "av detections",
        "ids detections",
        "yara detections",
        "copy",
        "threat network",
        "service modification",
        "target",
        "targeting an individual",
        "cybercrime",
        "fraud services",
        "attack",
        "africa",
        "libel",
        "password cracker",
        "ios"
      ],
      "references": [
        "frostwire-5.3.9.windows.exe",
        "185.199.108.133",
        "cdn-185-199-108-133.github.com",
        "AS : AS16509 Amazon.com, Inc",
        "SRC URL : http://dl.frostwire.com/frostwire/5.3.9/frostwire-5.3.9.windows.exe",
        "IP : 54.192.29.164",
        "https://otx.alienvault.com/indicator/ip/185.199.108.133",
        "Malware Hosting: IPv4 185.199.108.133, 185.199.109.133, 185.199.110.133, 185.199.111.133",
        "YARA Rules",
        "Matches rule Windows_API_Function from ruleset Windows_API_Function by InQuest Labs",
        "Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
        "Matches rule UPX from ruleset UPX by kevoreilly",
        "REFERENCE: https://goo.gl/hXbwiV",
        "RULE_LINK: https://valhalla.nextron-systems.com/info/rule/SUSP_JS_Command",
        "More information: https://www.nextron-systems.com/notes-on-virustotal-matches/",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
        "https://www.assurant.com/?utm_source=email&utm_medium=email&utm_campaign=Mobile_Transactional_withad&utm_content=Deductible+Charge+Acknowledgement+PD-MB&utm_term= [Mobile transactional with ads/ malicious]",
        "https://otx.alienvault.com/indicator/url/https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [ Walker | Apple Password Cracker]",
        "http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [Apple exploit]",
        "www.pornhub.com [New Relic | nr-data.net | Apple Private Data Collection]",
        "www.anyxxxtube.net",
        "https://otx.alienvault.com/indicator/url/https://www.bleepingcomputer.com/forums/t/268006/wormmalware-that-kills-run-system-restore-regedit/ [ phishing attack directed towards Tsara Brashears]",
        "phishing-campaign-cloudstation-eu-west-98.githubusercontent.com [phishing]",
        "louisianarooflawyers.com [phishing| songculture.com redirect , compromised by threat actors]",
        "103.246.145.111 [malware]",
        "x.ss2.us",
        "nr-data.net [Apple Private Data Collection]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "VirTool",
          "display_name": "VirTool",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Magic",
          "display_name": "Magic",
          "target": null
        },
        {
          "id": "Multios.Coinminer.Miner-6781728-2",
          "display_name": "Multios.Coinminer.Miner-6781728-2",
          "target": null
        },
        {
          "id": "Win32/Ispen BADNEWS Fake User-Agent",
          "display_name": "Win32/Ispen BADNEWS Fake User-Agent",
          "target": null
        },
        {
          "id": "Babulya/CollectorStealer User-Agent",
          "display_name": "Babulya/CollectorStealer User-Agent",
          "target": null
        },
        {
          "id": "Win.Malware.Generic-9820446-0",
          "display_name": "Win.Malware.Generic-9820446-0",
          "target": null
        },
        {
          "id": "Worm:Win32/AutoRun!atmn",
          "display_name": "Worm:Win32/AutoRun!atmn",
          "target": "/malware/Worm:Win32/AutoRun!atmn"
        },
        {
          "id": "VirTool:MSIL/Obfuscator.BV",
          "display_name": "VirTool:MSIL/Obfuscator.BV",
          "target": "/malware/VirTool:MSIL/Obfuscator.BV"
        },
        {
          "id": "Win.Trojan.Emotet-9850453-0",
          "display_name": "Win.Trojan.Emotet-9850453-0",
          "target": null
        },
        {
          "id": "ALF:HSTR:HackTool:ExtremeInjector.S01",
          "display_name": "ALF:HSTR:HackTool:ExtremeInjector.S01",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/AgentTesla!rfn",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/AgentTesla!rfn",
          "target": null
        },
        {
          "id": "!#HSTR:Win32/Spectorsoft",
          "display_name": "!#HSTR:Win32/Spectorsoft",
          "target": "/malware/!#HSTR:Win32/Spectorsoft"
        },
        {
          "id": "ALF:Base64EncodeFunctionMonitorW",
          "display_name": "ALF:Base64EncodeFunctionMonitorW",
          "target": null
        },
        {
          "id": "185.199.108.133.Malware_Host",
          "display_name": "185.199.108.133.Malware_Host",
          "target": null
        },
        {
          "id": "adware.opencandy",
          "display_name": "adware.opencandy",
          "target": null
        },
        {
          "id": "Malvertizing",
          "display_name": "Malvertizing",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 32,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1872,
        "FileHash-SHA1": 1140,
        "FileHash-SHA256": 2367,
        "URL": 1969,
        "domain": 327,
        "hostname": 1025,
        "email": 1
      },
      "indicator_count": 8701,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "860 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708d5530ef54f76f70777b",
      "name": "New Sample of REvil Ransomware - REvil Returned?",
      "description": "",
      "modified": "2023-12-06T15:03:49.881000",
      "created": "2023-12-06T15:03:49.881000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 800,
        "FileHash-MD5": 198,
        "FileHash-SHA1": 198,
        "domain": 419,
        "hostname": 5
      },
      "indicator_count": 1620,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707c3be05f3a7ea9e654d4",
      "name": "Kaseya VSA REvil Indicators",
      "description": "",
      "modified": "2023-12-06T13:50:51.719000",
      "created": "2023-12-06T13:50:51.719000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 15,
        "FileHash-SHA1": 15,
        "FileHash-SHA256": 16,
        "URL": 1,
        "domain": 1178,
        "hostname": 5,
        "YARA": 4
      },
      "indicator_count": 1234,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707bedc2fbc934427f325c",
      "name": "Kaseya VSA REvil Indicators",
      "description": "",
      "modified": "2023-12-06T13:49:33.291000",
      "created": "2023-12-06T13:49:33.291000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 15,
        "FileHash-SHA1": 15,
        "FileHash-SHA256": 16,
        "URL": 1,
        "domain": 1179,
        "hostname": 5,
        "YARA": 4
      },
      "indicator_count": 1235,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "carlosja.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "carlosja.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780206419.9492736
}