{
  "type": "Domain",
  "indicator": "claude-pro.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/claude-pro.com",
    "alexa": "http://www.alexa.com/siteinfo/claude-pro.com",
    "indicator": "claude-pro.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4347299846,
      "indicator": "claude-pro.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 7,
      "pulses": [
        {
          "id": "69fcc63f1dce161fc2f8380c",
          "name": "Donuts and Beagles: Fake Claude site spreads backdoor",
          "description": "A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.",
          "modified": "2026-05-08T09:01:36.876000",
          "created": "2026-05-07T17:05:03.022000",
          "tags": [
            "beagle",
            "adaptixc2",
            "beagle backdoor",
            "donutloader"
          ],
          "references": [
            "https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Beagle",
              "display_name": "Beagle",
              "target": null
            },
            {
              "id": "DonutLoader",
              "display_name": "DonutLoader",
              "target": null
            },
            {
              "id": "AdaptixC2",
              "display_name": "AdaptixC2",
              "target": null
            },
            {
              "id": "PlugX - S0013",
              "display_name": "PlugX - S0013",
              "target": null
            },
            {
              "id": "Thoper",
              "display_name": "Thoper",
              "target": null
            },
            {
              "id": "TVT",
              "display_name": "TVT",
              "target": null
            },
            {
              "id": "DestroyRAT",
              "display_name": "DestroyRAT",
              "target": null
            },
            {
              "id": "Sogu",
              "display_name": "Sogu",
              "target": null
            },
            {
              "id": "Kaba",
              "display_name": "Kaba",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1573.001",
              "name": "Symmetric Cryptography",
              "display_name": "T1573.001 - Symmetric Cryptography"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1070.004",
              "name": "File Deletion",
              "display_name": "T1070.004 - File Deletion"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1,
            "hostname": 1
          },
          "indicator_count": 2,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386525,
          "modified_text": "23 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5fa1852d337eca8e99c2ec32",
          "name": "Malware - Malware Domain Feed V2 - November 03 2020",
          "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
          "modified": "2026-05-30T03:19:46.084000",
          "created": "2020-11-03T16:28:29.011000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 552808,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 3,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "otxrobottwo",
            "id": "78495",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 49967,
            "domain": 75353
          },
          "indicator_count": 125320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1727,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a047bb5f2b9d59bf3636161",
          "name": "EbeeMay2026 Pt2",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-05-13T13:25:09.112000",
          "created": "2026-05-13T13:25:09.112000",
          "tags": [
            "filehashsha256",
            "filehashmd5",
            "filehashsha1",
            "cve20250921 cve",
            "cve20260300 cve",
            "cve20261281 cve",
            "cve20261340 cve",
            "cve20261731 cve",
            "cve20261357 cve",
            "cve20259501 cve",
            "yara"
          ],
          "references": [
            "IOCs.csv"
          ],
          "public": 1,
          "adversary": "JDownloader, DarkCloud, Chaos Ransomware, APT29, Shadow-Earth-053",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 66,
            "URL": 45,
            "CVE": 23,
            "FileHash-MD5": 232,
            "FileHash-SHA1": 239,
            "FileHash-SHA256": 264,
            "domain": 130,
            "email": 3,
            "hostname": 41
          },
          "indicator_count": 1043,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 40,
          "modified_text": "17 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a03bf4773b48c0ba5708a9c",
          "name": "hjkhhkjhjhkhkj",
          "description": "The following is the full text of the text-based code that has been used to identify and identify people using the word \"deepseek\" as a means of identifying and identifying them from the public.",
          "modified": "2026-05-13T00:01:11.186000",
          "created": "2026-05-13T00:01:11.186000",
          "tags": [
            "indicator name",
            "ydznvjljcz6f7",
            "kpuspriyonews"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "MohammedRizwan2001",
            "id": "361933",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 153,
            "FileHash-MD5": 186,
            "FileHash-SHA1": 85,
            "FileHash-SHA256": 81,
            "IPv4": 657,
            "domain": 211,
            "hostname": 561
          },
          "indicator_count": 1934,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 20,
          "modified_text": "18 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a029848e7b6f6dab757e762",
          "name": "IOC -  Donuts and Beagles: Fake Claude site spreads backdoor",
          "description": "",
          "modified": "2026-05-12T03:08:05.477000",
          "created": "2026-05-12T03:02:32.680000",
          "tags": [
            "beagle",
            "adaptixc2",
            "beagle backdoor",
            "donutloader"
          ],
          "references": [
            "https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Beagle",
              "display_name": "Beagle",
              "target": null
            },
            {
              "id": "DonutLoader",
              "display_name": "DonutLoader",
              "target": null
            },
            {
              "id": "AdaptixC2",
              "display_name": "AdaptixC2",
              "target": null
            },
            {
              "id": "PlugX - S0013",
              "display_name": "PlugX - S0013",
              "target": null
            },
            {
              "id": "Thoper",
              "display_name": "Thoper",
              "target": null
            },
            {
              "id": "TVT",
              "display_name": "TVT",
              "target": null
            },
            {
              "id": "DestroyRAT",
              "display_name": "DestroyRAT",
              "target": null
            },
            {
              "id": "Sogu",
              "display_name": "Sogu",
              "target": null
            },
            {
              "id": "Kaba",
              "display_name": "Kaba",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1573.001",
              "name": "Symmetric Cryptography",
              "display_name": "T1573.001 - Symmetric Cryptography"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1070.004",
              "name": "File Deletion",
              "display_name": "T1070.004 - File Deletion"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "69fcc63f1dce161fc2f8380c",
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "celestre",
            "id": "295357",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1,
            "hostname": 1
          },
          "indicator_count": 2,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 139,
          "modified_text": "19 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a026d1302c9455055c93776",
          "name": "hdsaljlkdldjlksjalkjlksdajlkdas",
          "description": "",
          "modified": "2026-05-11T23:58:11.141000",
          "created": "2026-05-11T23:58:11.141000",
          "tags": [
            "kpuspriyonews"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "MohammedRizwan2001",
            "id": "361933",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 953,
            "FileHash-MD5": 151,
            "FileHash-SHA1": 50,
            "FileHash-SHA256": 54,
            "IPv4": 858,
            "domain": 214,
            "hostname": 559
          },
          "indicator_count": 2839,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 20,
          "modified_text": "19 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a01601a5577d48cf5f71e57",
          "name": "Donuts and Beagles: Fake Claude site spreads backdoor",
          "description": "",
          "modified": "2026-05-11T04:50:34.480000",
          "created": "2026-05-11T04:50:34.480000",
          "tags": [
            "beagle",
            "adaptixc2",
            "beagle backdoor",
            "donutloader"
          ],
          "references": [
            "https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Beagle",
              "display_name": "Beagle",
              "target": null
            },
            {
              "id": "DonutLoader",
              "display_name": "DonutLoader",
              "target": null
            },
            {
              "id": "AdaptixC2",
              "display_name": "AdaptixC2",
              "target": null
            },
            {
              "id": "PlugX - S0013",
              "display_name": "PlugX - S0013",
              "target": null
            },
            {
              "id": "Thoper",
              "display_name": "Thoper",
              "target": null
            },
            {
              "id": "TVT",
              "display_name": "TVT",
              "target": null
            },
            {
              "id": "DestroyRAT",
              "display_name": "DestroyRAT",
              "target": null
            },
            {
              "id": "Sogu",
              "display_name": "Sogu",
              "target": null
            },
            {
              "id": "Kaba",
              "display_name": "Kaba",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1573.001",
              "name": "Symmetric Cryptography",
              "display_name": "T1573.001 - Symmetric Cryptography"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1070.004",
              "name": "File Deletion",
              "display_name": "T1070.004 - File Deletion"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "69fcc63f1dce161fc2f8380c",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1,
            "hostname": 1
          },
          "indicator_count": 2,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "20 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor",
        "IOCs.csv"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [
            "Beagle",
            "Destroyrat",
            "Sogu",
            "Thoper",
            "Korplug",
            "Plugx - s0013",
            "Adaptixc2",
            "Donutloader",
            "Tvt",
            "Kaba"
          ],
          "industries": []
        },
        "other": {
          "adversary": [
            "JDownloader, DarkCloud, Chaos Ransomware, APT29, Shadow-Earth-053"
          ],
          "malware_families": [
            "Beagle",
            "Destroyrat",
            "Sogu",
            "Thoper",
            "Korplug",
            "Plugx - s0013",
            "Adaptixc2",
            "Donutloader",
            "Tvt",
            "Kaba"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 7,
  "pulses": [
    {
      "id": "69fcc63f1dce161fc2f8380c",
      "name": "Donuts and Beagles: Fake Claude site spreads backdoor",
      "description": "A fraudulent website impersonating Anthropic's Claude AI platform has been distributing a previously undocumented backdoor called Beagle through malvertising campaigns. The attack begins when victims download a fictitious tool named Claude-Pro Relay from claude-pro[.]com, delivered as a 505 MB ZIP archive. The infection chain utilizes DLL sideloading, exploiting a signed G DATA antivirus updater to load malicious code. The technique mirrors PlugX delivery methods but deploys different payloads. Beagle supports eight commands including shell execution, file transfer, and directory listing, communicating with C2 servers using AES encryption. Related samples dating to February 2026 have been identified, with some variants delivering AdaptixC2 framework. Additional domains impersonated security vendors like Trellix, CrowdStrike, and SentinelOne. The infrastructure spans Cloudflare for distribution and Alibaba Cloud for command and control.",
      "modified": "2026-05-08T09:01:36.876000",
      "created": "2026-05-07T17:05:03.022000",
      "tags": [
        "beagle",
        "adaptixc2",
        "beagle backdoor",
        "donutloader"
      ],
      "references": [
        "https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Beagle",
          "display_name": "Beagle",
          "target": null
        },
        {
          "id": "DonutLoader",
          "display_name": "DonutLoader",
          "target": null
        },
        {
          "id": "AdaptixC2",
          "display_name": "AdaptixC2",
          "target": null
        },
        {
          "id": "PlugX - S0013",
          "display_name": "PlugX - S0013",
          "target": null
        },
        {
          "id": "Thoper",
          "display_name": "Thoper",
          "target": null
        },
        {
          "id": "TVT",
          "display_name": "TVT",
          "target": null
        },
        {
          "id": "DestroyRAT",
          "display_name": "DestroyRAT",
          "target": null
        },
        {
          "id": "Sogu",
          "display_name": "Sogu",
          "target": null
        },
        {
          "id": "Kaba",
          "display_name": "Kaba",
          "target": null
        },
        {
          "id": "Korplug",
          "display_name": "Korplug",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1573.001",
          "name": "Symmetric Cryptography",
          "display_name": "T1573.001 - Symmetric Cryptography"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1070.004",
          "name": "File Deletion",
          "display_name": "T1070.004 - File Deletion"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1,
        "hostname": 1
      },
      "indicator_count": 2,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386525,
      "modified_text": "23 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5fa1852d337eca8e99c2ec32",
      "name": "Malware - Malware Domain Feed V2 - November 03 2020",
      "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
      "modified": "2026-05-30T03:19:46.084000",
      "created": "2020-11-03T16:28:29.011000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 552808,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 3,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "otxrobottwo",
        "id": "78495",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 49967,
        "domain": 75353
      },
      "indicator_count": 125320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1727,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a047bb5f2b9d59bf3636161",
      "name": "EbeeMay2026 Pt2",
      "description": "Multiple APT/threat actors, Malware and Campaigns",
      "modified": "2026-05-13T13:25:09.112000",
      "created": "2026-05-13T13:25:09.112000",
      "tags": [
        "filehashsha256",
        "filehashmd5",
        "filehashsha1",
        "cve20250921 cve",
        "cve20260300 cve",
        "cve20261281 cve",
        "cve20261340 cve",
        "cve20261731 cve",
        "cve20261357 cve",
        "cve20259501 cve",
        "yara"
      ],
      "references": [
        "IOCs.csv"
      ],
      "public": 1,
      "adversary": "JDownloader, DarkCloud, Chaos Ransomware, APT29, Shadow-Earth-053",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 66,
        "URL": 45,
        "CVE": 23,
        "FileHash-MD5": 232,
        "FileHash-SHA1": 239,
        "FileHash-SHA256": 264,
        "domain": 130,
        "email": 3,
        "hostname": 41
      },
      "indicator_count": 1043,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 40,
      "modified_text": "17 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a03bf4773b48c0ba5708a9c",
      "name": "hjkhhkjhjhkhkj",
      "description": "The following is the full text of the text-based code that has been used to identify and identify people using the word \"deepseek\" as a means of identifying and identifying them from the public.",
      "modified": "2026-05-13T00:01:11.186000",
      "created": "2026-05-13T00:01:11.186000",
      "tags": [
        "indicator name",
        "ydznvjljcz6f7",
        "kpuspriyonews"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "MohammedRizwan2001",
        "id": "361933",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 153,
        "FileHash-MD5": 186,
        "FileHash-SHA1": 85,
        "FileHash-SHA256": 81,
        "IPv4": 657,
        "domain": 211,
        "hostname": 561
      },
      "indicator_count": 1934,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 20,
      "modified_text": "18 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a029848e7b6f6dab757e762",
      "name": "IOC -  Donuts and Beagles: Fake Claude site spreads backdoor",
      "description": "",
      "modified": "2026-05-12T03:08:05.477000",
      "created": "2026-05-12T03:02:32.680000",
      "tags": [
        "beagle",
        "adaptixc2",
        "beagle backdoor",
        "donutloader"
      ],
      "references": [
        "https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Beagle",
          "display_name": "Beagle",
          "target": null
        },
        {
          "id": "DonutLoader",
          "display_name": "DonutLoader",
          "target": null
        },
        {
          "id": "AdaptixC2",
          "display_name": "AdaptixC2",
          "target": null
        },
        {
          "id": "PlugX - S0013",
          "display_name": "PlugX - S0013",
          "target": null
        },
        {
          "id": "Thoper",
          "display_name": "Thoper",
          "target": null
        },
        {
          "id": "TVT",
          "display_name": "TVT",
          "target": null
        },
        {
          "id": "DestroyRAT",
          "display_name": "DestroyRAT",
          "target": null
        },
        {
          "id": "Sogu",
          "display_name": "Sogu",
          "target": null
        },
        {
          "id": "Kaba",
          "display_name": "Kaba",
          "target": null
        },
        {
          "id": "Korplug",
          "display_name": "Korplug",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1573.001",
          "name": "Symmetric Cryptography",
          "display_name": "T1573.001 - Symmetric Cryptography"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1070.004",
          "name": "File Deletion",
          "display_name": "T1070.004 - File Deletion"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "69fcc63f1dce161fc2f8380c",
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "celestre",
        "id": "295357",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1,
        "hostname": 1
      },
      "indicator_count": 2,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 139,
      "modified_text": "19 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a026d1302c9455055c93776",
      "name": "hdsaljlkdldjlksjalkjlksdajlkdas",
      "description": "",
      "modified": "2026-05-11T23:58:11.141000",
      "created": "2026-05-11T23:58:11.141000",
      "tags": [
        "kpuspriyonews"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "MohammedRizwan2001",
        "id": "361933",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 953,
        "FileHash-MD5": 151,
        "FileHash-SHA1": 50,
        "FileHash-SHA256": 54,
        "IPv4": 858,
        "domain": 214,
        "hostname": 559
      },
      "indicator_count": 2839,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 20,
      "modified_text": "19 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a01601a5577d48cf5f71e57",
      "name": "Donuts and Beagles: Fake Claude site spreads backdoor",
      "description": "",
      "modified": "2026-05-11T04:50:34.480000",
      "created": "2026-05-11T04:50:34.480000",
      "tags": [
        "beagle",
        "adaptixc2",
        "beagle backdoor",
        "donutloader"
      ],
      "references": [
        "https://www.sophos.com/en-us/blog/donuts-and-beagles-fake-claude-site-spreads-backdoor"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Beagle",
          "display_name": "Beagle",
          "target": null
        },
        {
          "id": "DonutLoader",
          "display_name": "DonutLoader",
          "target": null
        },
        {
          "id": "AdaptixC2",
          "display_name": "AdaptixC2",
          "target": null
        },
        {
          "id": "PlugX - S0013",
          "display_name": "PlugX - S0013",
          "target": null
        },
        {
          "id": "Thoper",
          "display_name": "Thoper",
          "target": null
        },
        {
          "id": "TVT",
          "display_name": "TVT",
          "target": null
        },
        {
          "id": "DestroyRAT",
          "display_name": "DestroyRAT",
          "target": null
        },
        {
          "id": "Sogu",
          "display_name": "Sogu",
          "target": null
        },
        {
          "id": "Kaba",
          "display_name": "Kaba",
          "target": null
        },
        {
          "id": "Korplug",
          "display_name": "Korplug",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1573.001",
          "name": "Symmetric Cryptography",
          "display_name": "T1573.001 - Symmetric Cryptography"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1070.004",
          "name": "File Deletion",
          "display_name": "T1070.004 - File Deletion"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "69fcc63f1dce161fc2f8380c",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1,
        "hostname": 1
      },
      "indicator_count": 2,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 277,
      "modified_text": "20 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "claude-pro.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "claude-pro.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780231798.7472944
}