{
  "type": "Domain",
  "indicator": "cdnupdate.net",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/cdnupdate.net",
    "alexa": "http://www.alexa.com/siteinfo/cdnupdate.net",
    "indicator": "cdnupdate.net",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3743688846,
      "indicator": "cdnupdate.net",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 22,
      "pulses": [
        {
          "id": "64e62628ed1119d03d3db75a",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "ESET researchers have identified the operators of Spacecolon, a toolset used to deploy variants of the Scarab ransomware, and its operators, in a blogpost published on 22 August 2023.",
          "modified": "2023-09-22T15:00:10.205000",
          "created": "2023-08-23T15:30:48.013000",
          "tags": [
            "spacecolon",
            "cosmicbeetle",
            "bruteforce",
            "rdp",
            "schacktool",
            "scinstaller",
            "scservice",
            "ransomware",
            "rat",
            "scarab",
            "scransom"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Thailand",
            "Israel",
            "Poland",
            "Brazil",
            "T\u00fcrkiye",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "Scarab",
              "display_name": "Scarab",
              "target": null
            },
            {
              "id": "SpaceColon",
              "display_name": "SpaceColon",
              "target": null
            },
            {
              "id": "CosmicBeetle",
              "display_name": "CosmicBeetle",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1136",
              "name": "Create Account",
              "display_name": "T1136 - Create Account"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1529",
              "name": "System Shutdown/Reboot",
              "display_name": "T1529 - System Shutdown/Reboot"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1595",
              "name": "Active Scanning",
              "display_name": "T1595 - Active Scanning"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            }
          ],
          "industries": [
            "Entertainment",
            "Hospitality",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 402,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 31,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386538,
          "modified_text": "981 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ff12aea0b9ba91d923da14",
          "name": "Threat Actor Profile: El Machete",
          "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
          "modified": "2025-04-16T02:15:10.602000",
          "created": "2025-04-16T02:15:10.602000",
          "tags": [
            "threat_actor",
            "unknown",
            "T1497",
            "T1114",
            "T1566.001",
            "T1059.003",
            "T1081",
            "T1059.006",
            "T1059",
            "T1566.002",
            "T1082",
            "T1027",
            "T1071.001",
            "T1566",
            "T1041",
            "T1105",
            "T1204.001",
            "T1049",
            "T1055",
            "T1036",
            "T1503",
            "T1114.001",
            "T1053",
            "T1140",
            "T1012",
            "T1071",
            "T1112",
            "T1036.005",
            "T1547",
            "T1057",
            "T1008",
            "T1518",
            "T1021",
            "T1011",
            "T1060",
            "T1539",
            "T1587",
            "T1087",
            "T1095",
            "T1102",
            "T1070",
            "T1130",
            "T1552",
            "T1106",
            "T1190",
            "T1007",
            "T1133",
            "T1090",
            "T1016",
            "T1137",
            "T1119",
            "T1124",
            "T1005",
            "T1059.001",
            "T1115",
            "T1562.001",
            "T1543",
            "T1078",
            "T1083",
            "T1530",
            "T1085",
            "T1003",
            "T1120",
            "T1218",
            "T1048",
            "T1553",
            "T1490",
            "T1497.003",
            "T1571",
            "T1204.002",
            "T1595.002",
            "T1102.002",
            "T1583.003",
            "T1027.009",
            "T1027.013",
            "T1132",
            "T1562",
            "T1110",
            "T1059.005",
            "T1218.007",
            "T1204",
            "T1550",
            "T1136",
            "T1555",
            "T1176",
            "T1204_-_User_Execution",
            "T1566_-_Phishing",
            "T1561",
            "T1583",
            "T1485",
            "T1127",
            "T1595",
            "T1573",
            "T1189",
            "T1486",
            "T1531",
            "T1529",
            "T1053.005",
            "T1047.",
            "target:Dominican Republic",
            "target:Venezuela",
            "target:Italy",
            "target:Colombia",
            "target:Ecuador",
            "target:Guatemala",
            "target:Belgium",
            "target:Malaysia",
            "target:Brazil",
            "target:France",
            "target:Indonesia",
            "target:United Kingdom",
            "target:China",
            "target:Germany",
            "target:Mexico",
            "target:Argentina",
            "target:Netherlands",
            "target:Japan",
            "target:Bolivia",
            "target:Yibuti",
            "target:Vietnam",
            "target:Fiyi",
            "target:Cuba",
            "target:Camboya",
            "target:Taiw\u00e1n",
            "target:United States",
            "target:Sweden",
            "target:Ukraine",
            "target:South Korea",
            "target:Nicaragua",
            "target:Canada",
            "target:Russia",
            "target:otros"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 9,
            "hostname": 18,
            "domain": 59
          },
          "indicator_count": 86,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 56,
          "modified_text": "410 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ff1245d4dc2a56e5561a57",
          "name": "Threat Actor Profile: El Machete",
          "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
          "modified": "2025-04-16T02:13:25.801000",
          "created": "2025-04-16T02:13:25.801000",
          "tags": [
            "threat_actor",
            "unknown",
            "T1497",
            "T1114",
            "T1566.001",
            "T1059.003",
            "T1081",
            "T1059.006",
            "T1059",
            "T1566.002",
            "T1082",
            "T1027",
            "T1071.001",
            "T1566",
            "T1041",
            "T1105",
            "T1204.001",
            "T1049",
            "T1055",
            "T1036",
            "T1503",
            "T1114.001",
            "T1053",
            "T1140",
            "T1012",
            "T1071",
            "T1112",
            "T1036.005",
            "T1547",
            "T1057",
            "T1008",
            "T1518",
            "T1021",
            "T1011",
            "T1060",
            "T1539",
            "T1587",
            "T1087",
            "T1095",
            "T1102",
            "T1070",
            "T1130",
            "T1552",
            "T1106",
            "T1190",
            "T1007",
            "T1133",
            "T1090",
            "T1016",
            "T1137",
            "T1119",
            "T1124",
            "T1005",
            "T1059.001",
            "T1115",
            "T1562.001",
            "T1543",
            "T1078",
            "T1083",
            "T1530",
            "T1085",
            "T1003",
            "T1120",
            "T1218",
            "T1048",
            "T1553",
            "T1490",
            "T1497.003",
            "T1571",
            "T1204.002",
            "T1595.002",
            "T1102.002",
            "T1583.003",
            "T1027.009",
            "T1027.013",
            "T1132",
            "T1562",
            "T1110",
            "T1059.005",
            "T1218.007",
            "T1204",
            "T1550",
            "T1136",
            "T1555",
            "T1176",
            "T1204_-_User_Execution",
            "T1566_-_Phishing",
            "T1561",
            "T1583",
            "T1485",
            "T1127",
            "T1595",
            "T1573",
            "T1189",
            "T1486",
            "T1531",
            "T1529",
            "T1053.005",
            "T1047.",
            "target:Dominican Republic",
            "target:Venezuela",
            "target:Italy",
            "target:Colombia",
            "target:Ecuador",
            "target:Guatemala",
            "target:Belgium",
            "target:Malaysia",
            "target:Brazil",
            "target:France",
            "target:Indonesia",
            "target:United Kingdom",
            "target:China",
            "target:Germany",
            "target:Mexico",
            "target:Argentina",
            "target:Netherlands",
            "target:Japan",
            "target:Bolivia",
            "target:Yibuti",
            "target:Vietnam",
            "target:Fiyi",
            "target:Cuba",
            "target:Camboya",
            "target:Taiw\u00e1n",
            "target:United States",
            "target:Sweden",
            "target:Ukraine",
            "target:South Korea",
            "target:Nicaragua",
            "target:Canada",
            "target:Russia",
            "target:otros"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 9,
            "hostname": 18,
            "domain": 59
          },
          "indicator_count": 86,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 56,
          "modified_text": "410 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67733b72d522398f5ea0a12d",
          "name": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar",
          "description": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar con Intereses en la Administraci\u00f3n P\u00fablica de la Rep\u00fablica Dominicana, Diciembre 2024",
          "modified": "2025-01-30T00:00:18.927000",
          "created": "2024-12-31T00:31:46.858000",
          "tags": [
            "cve201711882",
            "cve20201472"
          ],
          "references": [],
          "public": 1,
          "adversary": "El Machete, TAG-100, Mirage, Unamed_Grooup",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2631,
            "FileHash-SHA1": 2168,
            "FileHash-SHA256": 3401,
            "CVE": 25,
            "domain": 977,
            "hostname": 1226
          },
          "indicator_count": 10428,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6773390f17d71879c414676a",
          "name": "El Machete",
          "description": "El Machete es un grupo de ciberespionaje activo desde al menos 2014, enfocado en atacar principalmente a naciones de habla hispana. Este grupo es conocido por su sofisticada malware y t\u00e1cticas de exfiltraci\u00f3n de datos, con un enfoque en objetivos de alto perfil, como agencias gubernamentales y organizaciones estrat\u00e9gicas.",
          "modified": "2025-01-30T00:00:18.927000",
          "created": "2024-12-31T00:21:35.813000",
          "tags": [
            "cve201711882",
            "cve20201472",
            "El Machete"
          ],
          "references": [],
          "public": 1,
          "adversary": "El Machete",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 473,
            "FileHash-SHA1": 471,
            "FileHash-SHA256": 500,
            "CVE": 9,
            "domain": 60,
            "hostname": 18
          },
          "indicator_count": 1531,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 60,
          "modified_text": "486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a7c103e1145390bf0541",
          "name": "New Rust-Based Malware Campaign Targets Azerbaijan",
          "description": "",
          "modified": "2023-12-06T16:56:33.921000",
          "created": "2023-12-06T16:56:33.921000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 8,
            "FileHash-MD5": 69,
            "FileHash-SHA1": 70,
            "FileHash-SHA256": 79,
            "BitcoinAddress": 1,
            "domain": 4,
            "hostname": 11,
            "URL": 56,
            "YARA": 5
          },
          "indicator_count": 303,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a0c43d87b76cacd54247",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "",
          "modified": "2023-12-06T16:26:44.660000",
          "created": "2023-12-06T16:26:44.660000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 31,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a08cb966ec5b823d2ae6",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "",
          "modified": "2023-12-06T16:25:48.316000",
          "created": "2023-12-06T16:25:48.316000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 13,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 12,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a08b9a555f128e4c9a96",
          "name": "Scarab Ransomware Deployed Worldwide Via Spacecolon Toolset",
          "description": "",
          "modified": "2023-12-06T16:25:47.091000",
          "created": "2023-12-06T16:25:47.091000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 12,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 12,
            "domain": 2,
            "hostname": 9
          },
          "indicator_count": 49,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a08889b61daf664a9437",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "",
          "modified": "2023-12-06T16:25:44.381000",
          "created": "2023-12-06T16:25:44.381000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 31,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a0820cae34d19682d201",
          "name": "Deployment of Scarab Ransomware Using Spacecolon",
          "description": "",
          "modified": "2023-12-06T16:25:38.477000",
          "created": "2023-12-06T16:25:38.477000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 12,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 12,
            "domain": 2,
            "hostname": 7
          },
          "indicator_count": 47,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a07ccb6768bb6cd47775",
          "name": "Scarabs Colon-izing Vulnerable Servers",
          "description": "",
          "modified": "2023-12-06T16:25:32.438000",
          "created": "2023-12-06T16:25:32.438000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "BitcoinAddress": 1,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a0791631dd9b12650519",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "",
          "modified": "2023-12-06T16:25:29.114000",
          "created": "2023-12-06T16:25:29.114000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 31,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a07760e3f989a5556288",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "",
          "modified": "2023-12-06T16:25:27.062000",
          "created": "2023-12-06T16:25:27.062000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "BitcoinAddress": 1,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "651e5bb828569175edcb8be8",
          "name": "New Rust-Based Malware Campaign Targets Azerbaijan",
          "description": "",
          "modified": "2023-11-04T06:05:18.843000",
          "created": "2023-10-05T06:46:16.368000",
          "tags": [
            "eset",
            "spacecolon",
            "scinstaller",
            "scservice",
            "scransom",
            "schacktool",
            "cosmicbeetle",
            "remote desktop",
            "protocol",
            "delphi",
            "c server",
            "figure",
            "spacecolon c",
            "ini file",
            "clipbanker",
            "hacktool",
            "scarab",
            "nirsoft",
            "installer",
            "service",
            "mimikatz",
            "tools",
            "agent",
            "virustotal",
            "superscan",
            "winrar",
            "download",
            "powershell",
            "downexec",
            "first",
            "comment",
            "metasploit",
            "tips",
            "shadow",
            "polish",
            "mexico",
            "buran",
            "vegalocker",
            "eraser",
            "netscan",
            "nprw",
            "cain",
            "exploit",
            "dump",
            "python",
            "february",
            "pass",
            "music",
            "execution",
            "intelliadmin",
            "nlbrute",
            "lazarus",
            "oilrig",
            "t1115",
            "tcp",
            "cyber arms",
            "zoliwe",
            "w tym",
            "aplikacja",
            "check",
            "anonymous",
            "kiedy",
            "edr nie",
            "case",
            "info",
            "install",
            "jest",
            "lady",
            "windows update",
            "downloading",
            "agent apis",
            "article",
            "updates",
            "current version",
            "software update",
            "services",
            "windows script",
            "scarabey",
            "russian",
            "activexobject",
            "c bcdedit",
            "english",
            "scarabey note",
            "sevnz",
            "apis",
            "june",
            "necurs",
            "next",
            "terminal",
            "hiddentear",
            "passy",
            "group",
            "please",
            "team",
            "red dev",
            "pla unit",
            "twitter",
            "malwrhunterteam",
            "golden chickens",
            "propose change",
            "jackal",
            "hancitor",
            "evolution",
            "mask",
            "machete",
            "bluenoroff",
            "panda",
            "back",
            "jason",
            "ransomware",
            "push",
            "stealth mango",
            "ixeshe",
            "aluminum",
            "msupdater",
            "nettraveler",
            "keyboy",
            "sednit",
            "sofacy",
            "oceanlotus",
            "holmium",
            "scarcruft",
            "venus",
            "sykipot",
            "leviathan",
            "amoeba",
            "hoodoo",
            "dragon",
            "star",
            "matanbuchus",
            "comnie",
            "termite",
            "emdivi",
            "greenbug",
            "careto",
            "cobalt",
            "cyber",
            "icefog",
            "trident",
            "dnspionage",
            "darkhotel",
            "luder",
            "nemim",
            "tapaoux",
            "pioneer",
            "havex",
            "evilnum",
            "carbanak",
            "gcman",
            "ghostnet",
            "bitter",
            "infy",
            "karakurt",
            "kinsing",
            "mercury",
            "naikon",
            "nitro",
            "strongpity",
            "powerpool",
            "indra",
            "sauron",
            "sidewinder",
            "redalpha",
            "mantis",
            "rocke",
            "mimic",
            "silence",
            "guardian",
            "teamspy",
            "teamtnt",
            "teamxrat",
            "turla",
            "snake",
            "wraith",
            "pfinet",
            "krypton",
            "zoopark",
            "strong",
            "zeppelin",
            "cisa",
            "stopransomware",
            "iocs",
            "technique title",
            "id use",
            "disable",
            "august",
            "local",
            "enterprise",
            "bitcoin",
            "prior",
            "rig exploit",
            "gandcrab",
            "yara rule",
            "cis segment",
            "belarus",
            "windows xp",
            "ukraine",
            "jumper",
            "revil",
            "phobos",
            "armenia",
            "malware",
            "component",
            "ipworks",
            "web distributed",
            "authoring",
            "webdav",
            "html",
            "world wide",
            "icmp",
            "imap",
            "windows",
            "windir",
            "type windows",
            "home pro",
            "display name",
            "service service",
            "behavior",
            "default startup",
            "type",
            "vega",
            "rust",
            "rust implant",
            "deep instinct",
            "threat lab",
            "instinct threat",
            "dropbox",
            "msi uploader",
            "msi file",
            "office",
            "cve201711882",
            "stdout",
            "sensrsvc",
            "senior",
            "raas",
            "netcode",
            "lnk",
            "storm-0978"
          ],
          "references": [
            "September 20th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3275 - New Rust-Based Malware Campaign Targets Azerbaijan"
          ],
          "public": 1,
          "adversary": "Scarab",
          "targeted_countries": [
            "Thailand",
            "Israel",
            "Poland",
            "Brazil",
            "T\u00fcrkiye",
            "Mexico",
            "Armenia",
            "Belarus",
            "Kazakhstan",
            "Kyrgyzstan",
            "Moldova, Republic of",
            "Russian Federation",
            "Tajikistan",
            "Turkmenistan",
            "Ukraine",
            "Uzbekistan"
          ],
          "malware_families": [
            {
              "id": "ScHackTool",
              "display_name": "ScHackTool",
              "target": null
            },
            {
              "id": "T1115",
              "display_name": "T1115",
              "target": null
            },
            {
              "id": "TCP",
              "display_name": "TCP",
              "target": null
            },
            {
              "id": "Scarab",
              "display_name": "Scarab",
              "target": null
            },
            {
              "id": "Passy",
              "display_name": "Passy",
              "target": null
            },
            {
              "id": "Necurs",
              "display_name": "Necurs",
              "target": null
            },
            {
              "id": "SCARABEY",
              "display_name": "SCARABEY",
              "target": null
            },
            {
              "id": "Scarabey",
              "display_name": "Scarabey",
              "target": null
            },
            {
              "id": "Vega",
              "display_name": "Vega",
              "target": null
            },
            {
              "id": "Zeppelin",
              "display_name": "Zeppelin",
              "target": null
            },
            {
              "id": "SensrSvc",
              "display_name": "SensrSvc",
              "target": null
            },
            {
              "id": "RaaS",
              "display_name": "RaaS",
              "target": null
            },
            {
              "id": "Ukraine",
              "display_name": "Ukraine",
              "target": null
            },
            {
              "id": "Buran",
              "display_name": "Buran",
              "target": null
            },
            {
              "id": "NetCode",
              "display_name": "NetCode",
              "target": null
            },
            {
              "id": "Storm-0978",
              "display_name": "Storm-0978",
              "target": null
            },
            {
              "id": "Rust",
              "display_name": "Rust",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1136",
              "name": "Create Account",
              "display_name": "T1136 - Create Account"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1529",
              "name": "System Shutdown/Reboot",
              "display_name": "T1529 - System Shutdown/Reboot"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1595",
              "name": "Active Scanning",
              "display_name": "T1595 - Active Scanning"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1531",
              "name": "Account Access Removal",
              "display_name": "T1531 - Account Access Removal"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1550",
              "name": "Use Alternate Authentication Material",
              "display_name": "T1550 - Use Alternate Authentication Material"
            }
          ],
          "industries": [
            "Entertainment",
            "Critical Infrastructure",
            "Defense",
            "Technology",
            "Healthcare",
            "Medical"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 75,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "CVE": 8,
            "FileHash-MD5": 69,
            "FileHash-SHA1": 70,
            "FileHash-SHA256": 79,
            "URL": 56,
            "domain": 4,
            "hostname": 11,
            "YARA": 5
          },
          "indicator_count": 303,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 503,
          "modified_text": "939 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e71ff897b055a08d1bf0c4",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "ESET researchers have identified the operators of Spacecolon, a toolset used to deploy variants of the Scarab ransomware, and its operators, in a blogpost published on 22 August 2023.",
          "modified": "2023-09-23T09:03:35.107000",
          "created": "2023-08-24T09:16:40.133000",
          "tags": [
            "spacecolon",
            "scservice",
            "c server",
            "cosmicbeetle",
            "schacktool",
            "figure",
            "scinstaller",
            "spacecolon c",
            "scransom",
            "ini file",
            "clipbanker",
            "hacktool",
            "scarab",
            "nirsoft",
            "installer",
            "service",
            "tools",
            "mimikatz",
            "virustotal",
            "download",
            "powershell",
            "agent",
            "downexec",
            "first",
            "comment",
            "metasploit",
            "zimbra",
            "tips",
            "delphi",
            "shadow",
            "polish",
            "mexico",
            "buran",
            "vegalocker",
            "exploit",
            "dump",
            "python",
            "february",
            "pass",
            "music",
            "execution",
            "intelliadmin",
            "nlbrute",
            "superscan",
            "winrar",
            "podcast",
            "t1115",
            "tcp"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Thailand",
            "Israel",
            "Poland",
            "Brazil",
            "T\u00fcrkiye",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "ScHackTool",
              "display_name": "ScHackTool",
              "target": null
            },
            {
              "id": "T1115",
              "display_name": "T1115",
              "target": null
            },
            {
              "id": "TCP",
              "display_name": "TCP",
              "target": null
            },
            {
              "id": "Scarab",
              "display_name": "Scarab",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1136",
              "name": "Create Account",
              "display_name": "T1136 - Create Account"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1529",
              "name": "System Shutdown/Reboot",
              "display_name": "T1529 - System Shutdown/Reboot"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1595",
              "name": "Active Scanning",
              "display_name": "T1595 - Active Scanning"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            }
          ],
          "industries": [
            "Entertainment"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "parvesh4399",
            "id": "224939",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 13,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 12,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 55,
          "modified_text": "981 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e709d3f075bbf097623f94",
          "name": "Scarab Ransomware Deployed Worldwide Via Spacecolon Toolset",
          "description": "",
          "modified": "2023-09-23T07:04:07.191000",
          "created": "2023-08-24T07:42:11.589000",
          "tags": [
            "spacecolon c",
            "c server",
            "xhost internet",
            "solutions",
            "hacktool",
            "installer",
            "service",
            "scransom",
            "msi installer",
            "utility",
            "first",
            "scarab"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Scarab",
              "display_name": "Scarab",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "akhanafeer",
            "id": "195327",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 12,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 12,
            "domain": 2,
            "hostname": 9
          },
          "indicator_count": 49,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 71,
          "modified_text": "981 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e6ac7d48784801319b6041",
          "name": "Deployment of Scarab Ransomware Using Spacecolon",
          "description": "",
          "modified": "2023-09-23T01:05:28.173000",
          "created": "2023-08-24T01:03:57.598000",
          "tags": [],
          "references": [
            "August 24th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3111 - Deployment of Scarab Ransomware Using Spacecolon.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 12,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 12,
            "domain": 2,
            "hostname": 7
          },
          "indicator_count": 47,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 499,
          "modified_text": "981 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e84109eecbe0b678365ffa",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "",
          "modified": "2023-09-23T00:03:13.532000",
          "created": "2023-08-25T05:50:01.417000",
          "tags": [
            "spacecolon",
            "cosmicbeetle",
            "bruteforce",
            "rdp",
            "schacktool",
            "scinstaller",
            "scservice",
            "ransomware",
            "rat",
            "scarab",
            "scransom"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Thailand",
            "Israel",
            "Poland",
            "Brazil",
            "T\u00fcrkiye",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "Scarab",
              "display_name": "Scarab",
              "target": null
            },
            {
              "id": "SpaceColon",
              "display_name": "SpaceColon",
              "target": null
            },
            {
              "id": "CosmicBeetle",
              "display_name": "CosmicBeetle",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1136",
              "name": "Create Account",
              "display_name": "T1136 - Create Account"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1529",
              "name": "System Shutdown/Reboot",
              "display_name": "T1529 - System Shutdown/Reboot"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1595",
              "name": "Active Scanning",
              "display_name": "T1595 - Active Scanning"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            }
          ],
          "industries": [
            "Entertainment",
            "Hospitality",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "64e70565e3b0f345c568beb0",
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 31,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 276,
          "modified_text": "981 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e70565e3b0f345c568beb0",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "",
          "modified": "2023-09-23T00:03:13.532000",
          "created": "2023-08-24T07:23:17.180000",
          "tags": [
            "spacecolon",
            "cosmicbeetle",
            "bruteforce",
            "rdp",
            "schacktool",
            "scinstaller",
            "scservice",
            "ransomware",
            "rat",
            "scarab",
            "scransom"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Thailand",
            "Israel",
            "Poland",
            "Brazil",
            "T\u00fcrkiye",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "Scarab",
              "display_name": "Scarab",
              "target": null
            },
            {
              "id": "SpaceColon",
              "display_name": "SpaceColon",
              "target": null
            },
            {
              "id": "CosmicBeetle",
              "display_name": "CosmicBeetle",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1136",
              "name": "Create Account",
              "display_name": "T1136 - Create Account"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1529",
              "name": "System Shutdown/Reboot",
              "display_name": "T1529 - System Shutdown/Reboot"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1595",
              "name": "Active Scanning",
              "display_name": "T1595 - Active Scanning"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            }
          ],
          "industries": [
            "Entertainment",
            "Hospitality",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": "64e62628ed1119d03d3db75a",
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 31,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "981 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e5e500b65a77f1e00c6591",
          "name": "Scarabs colon-izing vulnerable servers",
          "description": "ESET researchers have identified the operators of Spacecolon, a toolset used to deploy variants of the Scarab ransomware, and its operators, in a blogpost published on 22 August 2023.",
          "modified": "2023-09-22T10:00:41.562000",
          "created": "2023-08-23T10:52:48.338000",
          "tags": [
            "spacecolon",
            "scservice",
            "c server",
            "cosmicbeetle",
            "schacktool",
            "figure",
            "scinstaller",
            "spacecolon c",
            "scransom",
            "ini file",
            "clipbanker",
            "hacktool",
            "scarab",
            "nirsoft",
            "installer",
            "service",
            "tools",
            "mimikatz",
            "virustotal",
            "download",
            "powershell",
            "agent",
            "downexec",
            "first",
            "comment",
            "metasploit",
            "zimbra",
            "tips",
            "delphi",
            "shadow",
            "polish",
            "mexico",
            "buran",
            "vegalocker",
            "exploit",
            "dump",
            "python",
            "february",
            "pass",
            "music",
            "execution",
            "intelliadmin",
            "nlbrute",
            "superscan",
            "winrar",
            "podcast",
            "t1115",
            "tcp"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Thailand",
            "Israel",
            "Poland",
            "Brazil",
            "T\u00fcrkiye",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "ScHackTool",
              "display_name": "ScHackTool",
              "target": null
            },
            {
              "id": "T1115",
              "display_name": "T1115",
              "target": null
            },
            {
              "id": "TCP",
              "display_name": "TCP",
              "target": null
            },
            {
              "id": "Scarab",
              "display_name": "Scarab",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1136",
              "name": "Create Account",
              "display_name": "T1136 - Create Account"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1529",
              "name": "System Shutdown/Reboot",
              "display_name": "T1529 - System Shutdown/Reboot"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1595",
              "name": "Active Scanning",
              "display_name": "T1595 - Active Scanning"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            }
          ],
          "industries": [
            "Entertainment"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "CVE": 2,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "982 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e6687104eb558be3ab918c",
          "name": "Scarabs Colon-izing Vulnerable Servers",
          "description": "",
          "modified": "2023-09-22T10:00:41.562000",
          "created": "2023-08-23T20:13:37.506000",
          "tags": [
            "spacecolon",
            "scservice",
            "c server",
            "cosmicbeetle",
            "schacktool",
            "figure",
            "scinstaller",
            "spacecolon c",
            "scransom",
            "ini file",
            "clipbanker",
            "hacktool",
            "scarab",
            "nirsoft",
            "installer",
            "service",
            "tools",
            "mimikatz",
            "virustotal",
            "download",
            "powershell",
            "agent",
            "downexec",
            "first",
            "comment",
            "metasploit",
            "zimbra",
            "tips",
            "delphi",
            "shadow",
            "polish",
            "mexico",
            "buran",
            "vegalocker",
            "exploit",
            "dump",
            "python",
            "february",
            "pass",
            "music",
            "execution",
            "intelliadmin",
            "nlbrute",
            "superscan",
            "winrar",
            "podcast",
            "t1115",
            "tcp"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Thailand",
            "Israel",
            "Poland",
            "Brazil",
            "T\u00fcrkiye",
            "Mexico"
          ],
          "malware_families": [
            {
              "id": "ScHackTool",
              "display_name": "ScHackTool",
              "target": null
            },
            {
              "id": "T1115",
              "display_name": "T1115",
              "target": null
            },
            {
              "id": "TCP",
              "display_name": "TCP",
              "target": null
            },
            {
              "id": "Scarab",
              "display_name": "Scarab",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1136",
              "name": "Create Account",
              "display_name": "T1136 - Create Account"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1529",
              "name": "System Shutdown/Reboot",
              "display_name": "T1529 - System Shutdown/Reboot"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1595",
              "name": "Active Scanning",
              "display_name": "T1595 - Active Scanning"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            }
          ],
          "industries": [
            "Entertainment"
          ],
          "TLP": "white",
          "cloned_from": "64e5e500b65a77f1e00c6591",
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "feisty-swim1410",
            "id": "217462",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 1,
            "CVE": 2,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 8
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 65,
          "modified_text": "982 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "September 20th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3275 - New Rust-Based Malware Campaign Targets Azerbaijan",
        "https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/",
        "August 24th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3111 - Deployment of Scarab Ransomware Using Spacecolon.pdf"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [
            "Cosmicbeetle",
            "Scarab",
            "Spacecolon"
          ],
          "industries": [
            "Hospitality",
            "Government",
            "Entertainment"
          ]
        },
        "other": {
          "adversary": [
            "El Machete",
            "Scarab",
            "El Machete, TAG-100, Mirage, Unamed_Grooup"
          ],
          "malware_families": [
            "T1115",
            "Sensrsvc",
            "Passy",
            "Zeppelin",
            "Scarabey",
            "Spacecolon",
            "Tcp",
            "Necurs",
            "Vega",
            "Schacktool",
            "Buran",
            "Cosmicbeetle",
            "Raas",
            "Storm-0978",
            "Scarab",
            "Rust",
            "Ukraine",
            "Netcode"
          ],
          "industries": [
            "Healthcare",
            "Technology",
            "Government",
            "Entertainment",
            "Hospitality",
            "Critical infrastructure",
            "Medical",
            "Defense"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 22,
  "pulses": [
    {
      "id": "64e62628ed1119d03d3db75a",
      "name": "Scarabs colon-izing vulnerable servers",
      "description": "ESET researchers have identified the operators of Spacecolon, a toolset used to deploy variants of the Scarab ransomware, and its operators, in a blogpost published on 22 August 2023.",
      "modified": "2023-09-22T15:00:10.205000",
      "created": "2023-08-23T15:30:48.013000",
      "tags": [
        "spacecolon",
        "cosmicbeetle",
        "bruteforce",
        "rdp",
        "schacktool",
        "scinstaller",
        "scservice",
        "ransomware",
        "rat",
        "scarab",
        "scransom"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Thailand",
        "Israel",
        "Poland",
        "Brazil",
        "T\u00fcrkiye",
        "Mexico"
      ],
      "malware_families": [
        {
          "id": "Scarab",
          "display_name": "Scarab",
          "target": null
        },
        {
          "id": "SpaceColon",
          "display_name": "SpaceColon",
          "target": null
        },
        {
          "id": "CosmicBeetle",
          "display_name": "CosmicBeetle",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1110",
          "name": "Brute Force",
          "display_name": "T1110 - Brute Force"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1124",
          "name": "System Time Discovery",
          "display_name": "T1124 - System Time Discovery"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1133",
          "name": "External Remote Services",
          "display_name": "T1133 - External Remote Services"
        },
        {
          "id": "T1136",
          "name": "Create Account",
          "display_name": "T1136 - Create Account"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1529",
          "name": "System Shutdown/Reboot",
          "display_name": "T1529 - System Shutdown/Reboot"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1561",
          "name": "Disk Wipe",
          "display_name": "T1561 - Disk Wipe"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1587",
          "name": "Develop Capabilities",
          "display_name": "T1587 - Develop Capabilities"
        },
        {
          "id": "T1595",
          "name": "Active Scanning",
          "display_name": "T1595 - Active Scanning"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1127",
          "name": "Trusted Developer Utilities Proxy Execution",
          "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "display_name": "T1490 - Inhibit System Recovery"
        }
      ],
      "industries": [
        "Entertainment",
        "Hospitality",
        "Government"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 402,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 1,
        "FileHash-MD5": 3,
        "FileHash-SHA1": 14,
        "FileHash-SHA256": 3,
        "domain": 2,
        "hostname": 8
      },
      "indicator_count": 31,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386538,
      "modified_text": "981 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67ff12aea0b9ba91d923da14",
      "name": "Threat Actor Profile: El Machete",
      "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
      "modified": "2025-04-16T02:15:10.602000",
      "created": "2025-04-16T02:15:10.602000",
      "tags": [
        "threat_actor",
        "unknown",
        "T1497",
        "T1114",
        "T1566.001",
        "T1059.003",
        "T1081",
        "T1059.006",
        "T1059",
        "T1566.002",
        "T1082",
        "T1027",
        "T1071.001",
        "T1566",
        "T1041",
        "T1105",
        "T1204.001",
        "T1049",
        "T1055",
        "T1036",
        "T1503",
        "T1114.001",
        "T1053",
        "T1140",
        "T1012",
        "T1071",
        "T1112",
        "T1036.005",
        "T1547",
        "T1057",
        "T1008",
        "T1518",
        "T1021",
        "T1011",
        "T1060",
        "T1539",
        "T1587",
        "T1087",
        "T1095",
        "T1102",
        "T1070",
        "T1130",
        "T1552",
        "T1106",
        "T1190",
        "T1007",
        "T1133",
        "T1090",
        "T1016",
        "T1137",
        "T1119",
        "T1124",
        "T1005",
        "T1059.001",
        "T1115",
        "T1562.001",
        "T1543",
        "T1078",
        "T1083",
        "T1530",
        "T1085",
        "T1003",
        "T1120",
        "T1218",
        "T1048",
        "T1553",
        "T1490",
        "T1497.003",
        "T1571",
        "T1204.002",
        "T1595.002",
        "T1102.002",
        "T1583.003",
        "T1027.009",
        "T1027.013",
        "T1132",
        "T1562",
        "T1110",
        "T1059.005",
        "T1218.007",
        "T1204",
        "T1550",
        "T1136",
        "T1555",
        "T1176",
        "T1204_-_User_Execution",
        "T1566_-_Phishing",
        "T1561",
        "T1583",
        "T1485",
        "T1127",
        "T1595",
        "T1573",
        "T1189",
        "T1486",
        "T1531",
        "T1529",
        "T1053.005",
        "T1047.",
        "target:Dominican Republic",
        "target:Venezuela",
        "target:Italy",
        "target:Colombia",
        "target:Ecuador",
        "target:Guatemala",
        "target:Belgium",
        "target:Malaysia",
        "target:Brazil",
        "target:France",
        "target:Indonesia",
        "target:United Kingdom",
        "target:China",
        "target:Germany",
        "target:Mexico",
        "target:Argentina",
        "target:Netherlands",
        "target:Japan",
        "target:Bolivia",
        "target:Yibuti",
        "target:Vietnam",
        "target:Fiyi",
        "target:Cuba",
        "target:Camboya",
        "target:Taiw\u00e1n",
        "target:United States",
        "target:Sweden",
        "target:Ukraine",
        "target:South Korea",
        "target:Nicaragua",
        "target:Canada",
        "target:Russia",
        "target:otros"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 9,
        "hostname": 18,
        "domain": 59
      },
      "indicator_count": 86,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 56,
      "modified_text": "410 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67ff1245d4dc2a56e5561a57",
      "name": "Threat Actor Profile: El Machete",
      "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
      "modified": "2025-04-16T02:13:25.801000",
      "created": "2025-04-16T02:13:25.801000",
      "tags": [
        "threat_actor",
        "unknown",
        "T1497",
        "T1114",
        "T1566.001",
        "T1059.003",
        "T1081",
        "T1059.006",
        "T1059",
        "T1566.002",
        "T1082",
        "T1027",
        "T1071.001",
        "T1566",
        "T1041",
        "T1105",
        "T1204.001",
        "T1049",
        "T1055",
        "T1036",
        "T1503",
        "T1114.001",
        "T1053",
        "T1140",
        "T1012",
        "T1071",
        "T1112",
        "T1036.005",
        "T1547",
        "T1057",
        "T1008",
        "T1518",
        "T1021",
        "T1011",
        "T1060",
        "T1539",
        "T1587",
        "T1087",
        "T1095",
        "T1102",
        "T1070",
        "T1130",
        "T1552",
        "T1106",
        "T1190",
        "T1007",
        "T1133",
        "T1090",
        "T1016",
        "T1137",
        "T1119",
        "T1124",
        "T1005",
        "T1059.001",
        "T1115",
        "T1562.001",
        "T1543",
        "T1078",
        "T1083",
        "T1530",
        "T1085",
        "T1003",
        "T1120",
        "T1218",
        "T1048",
        "T1553",
        "T1490",
        "T1497.003",
        "T1571",
        "T1204.002",
        "T1595.002",
        "T1102.002",
        "T1583.003",
        "T1027.009",
        "T1027.013",
        "T1132",
        "T1562",
        "T1110",
        "T1059.005",
        "T1218.007",
        "T1204",
        "T1550",
        "T1136",
        "T1555",
        "T1176",
        "T1204_-_User_Execution",
        "T1566_-_Phishing",
        "T1561",
        "T1583",
        "T1485",
        "T1127",
        "T1595",
        "T1573",
        "T1189",
        "T1486",
        "T1531",
        "T1529",
        "T1053.005",
        "T1047.",
        "target:Dominican Republic",
        "target:Venezuela",
        "target:Italy",
        "target:Colombia",
        "target:Ecuador",
        "target:Guatemala",
        "target:Belgium",
        "target:Malaysia",
        "target:Brazil",
        "target:France",
        "target:Indonesia",
        "target:United Kingdom",
        "target:China",
        "target:Germany",
        "target:Mexico",
        "target:Argentina",
        "target:Netherlands",
        "target:Japan",
        "target:Bolivia",
        "target:Yibuti",
        "target:Vietnam",
        "target:Fiyi",
        "target:Cuba",
        "target:Camboya",
        "target:Taiw\u00e1n",
        "target:United States",
        "target:Sweden",
        "target:Ukraine",
        "target:South Korea",
        "target:Nicaragua",
        "target:Canada",
        "target:Russia",
        "target:otros"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 9,
        "hostname": 18,
        "domain": 59
      },
      "indicator_count": 86,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 56,
      "modified_text": "410 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67733b72d522398f5ea0a12d",
      "name": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar",
      "description": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar con Intereses en la Administraci\u00f3n P\u00fablica de la Rep\u00fablica Dominicana, Diciembre 2024",
      "modified": "2025-01-30T00:00:18.927000",
      "created": "2024-12-31T00:31:46.858000",
      "tags": [
        "cve201711882",
        "cve20201472"
      ],
      "references": [],
      "public": 1,
      "adversary": "El Machete, TAG-100, Mirage, Unamed_Grooup",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2631,
        "FileHash-SHA1": 2168,
        "FileHash-SHA256": 3401,
        "CVE": 25,
        "domain": 977,
        "hostname": 1226
      },
      "indicator_count": 10428,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "486 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6773390f17d71879c414676a",
      "name": "El Machete",
      "description": "El Machete es un grupo de ciberespionaje activo desde al menos 2014, enfocado en atacar principalmente a naciones de habla hispana. Este grupo es conocido por su sofisticada malware y t\u00e1cticas de exfiltraci\u00f3n de datos, con un enfoque en objetivos de alto perfil, como agencias gubernamentales y organizaciones estrat\u00e9gicas.",
      "modified": "2025-01-30T00:00:18.927000",
      "created": "2024-12-31T00:21:35.813000",
      "tags": [
        "cve201711882",
        "cve20201472",
        "El Machete"
      ],
      "references": [],
      "public": 1,
      "adversary": "El Machete",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 473,
        "FileHash-SHA1": 471,
        "FileHash-SHA256": 500,
        "CVE": 9,
        "domain": 60,
        "hostname": 18
      },
      "indicator_count": 1531,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 60,
      "modified_text": "486 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a7c103e1145390bf0541",
      "name": "New Rust-Based Malware Campaign Targets Azerbaijan",
      "description": "",
      "modified": "2023-12-06T16:56:33.921000",
      "created": "2023-12-06T16:56:33.921000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 8,
        "FileHash-MD5": 69,
        "FileHash-SHA1": 70,
        "FileHash-SHA256": 79,
        "BitcoinAddress": 1,
        "domain": 4,
        "hostname": 11,
        "URL": 56,
        "YARA": 5
      },
      "indicator_count": 303,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a0c43d87b76cacd54247",
      "name": "Scarabs colon-izing vulnerable servers",
      "description": "",
      "modified": "2023-12-06T16:26:44.660000",
      "created": "2023-12-06T16:26:44.660000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 1,
        "FileHash-MD5": 3,
        "FileHash-SHA1": 14,
        "FileHash-SHA256": 3,
        "domain": 2,
        "hostname": 8
      },
      "indicator_count": 31,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a08cb966ec5b823d2ae6",
      "name": "Scarabs colon-izing vulnerable servers",
      "description": "",
      "modified": "2023-12-06T16:25:48.316000",
      "created": "2023-12-06T16:25:48.316000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 1,
        "FileHash-MD5": 13,
        "FileHash-SHA1": 14,
        "FileHash-SHA256": 12,
        "domain": 2,
        "hostname": 8
      },
      "indicator_count": 50,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a08b9a555f128e4c9a96",
      "name": "Scarab Ransomware Deployed Worldwide Via Spacecolon Toolset",
      "description": "",
      "modified": "2023-12-06T16:25:47.091000",
      "created": "2023-12-06T16:25:47.091000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 12,
        "FileHash-SHA1": 14,
        "FileHash-SHA256": 12,
        "domain": 2,
        "hostname": 9
      },
      "indicator_count": 49,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a08889b61daf664a9437",
      "name": "Scarabs colon-izing vulnerable servers",
      "description": "",
      "modified": "2023-12-06T16:25:44.381000",
      "created": "2023-12-06T16:25:44.381000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "BitcoinAddress": 1,
        "FileHash-MD5": 3,
        "FileHash-SHA1": 14,
        "FileHash-SHA256": 3,
        "domain": 2,
        "hostname": 8
      },
      "indicator_count": 31,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "cdnupdate.net",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "cdnupdate.net",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780237900.39186
}