{
  "type": "Domain",
  "indicator": "clmfireproofing.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/clmfireproofing.com",
    "alexa": "http://www.alexa.com/siteinfo/clmfireproofing.com",
    "indicator": "clmfireproofing.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4032084168,
      "indicator": "clmfireproofing.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "67a1f245f3709030a9f0ccb7",
          "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
          "description": "A report by Insikt Group, based on an analysis of compromised WordPress sites, outlines the threat posed by a network of cybercriminal servers known as TAG-124, which is used to distribute malware.",
          "modified": "2025-03-06T10:04:51.026000",
          "created": "2025-02-04T10:56:05.010000",
          "tags": [
            "tag124",
            "cloudflare",
            "wordpress",
            "insikt group",
            "figure",
            "google chrome",
            "future",
            "urls",
            "ta582",
            "fake google",
            "rhysida",
            "powershell",
            "april",
            "insikt",
            "remcos",
            "interlock"
          ],
          "references": [
            "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
          ],
          "public": 1,
          "adversary": "Insikt",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Insikt",
              "display_name": "Insikt",
              "target": null
            },
            {
              "id": "Rhysida",
              "display_name": "Rhysida",
              "target": null
            },
            {
              "id": "REMCOS",
              "display_name": "REMCOS",
              "target": null
            },
            {
              "id": "Interlock",
              "display_name": "Interlock",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 30,
            "FileHash-SHA1": 30,
            "FileHash-SHA256": 30,
            "URL": 2,
            "domain": 254,
            "hostname": 112
          },
          "indicator_count": 458,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "452 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "679ba047fa5e47a0f6e2c071",
          "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
          "description": "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base\n\nInsikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked by Recorded Future as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, 404TDS, KongTuke, and Chaya_002. TAG-124 comprises a network of compromised WordPress sites, actor-controlled payload servers, a central server, a suspected management server, an additional panel, and other components. The threat actors behind TAG-124 demonstrate high levels of activity, including regularly updating URLs embedded in the compromised WordPress sites, adding servers, refining TDS logic to evade detection, and adapting infection tactics, as demonstrated by their recent implementation of the ClickFix technique.",
          "modified": "2025-03-01T15:01:42.461000",
          "created": "2025-01-30T15:52:39.738000",
          "tags": [
            "fake google",
            "chrome update",
            "matomo instance",
            "remcos rat",
            "c2 ip",
            "address",
            "ta582",
            "hashes"
          ],
          "references": [],
          "public": 1,
          "adversary": "TAG-124",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Rhysida",
              "display_name": "Rhysida",
              "target": null
            },
            {
              "id": "Interlock",
              "display_name": "Interlock",
              "target": null
            },
            {
              "id": "SocGholish",
              "display_name": "SocGholish",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "InformationTechnogyISAC",
            "id": "141282",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 30,
            "domain": 234,
            "hostname": 105
          },
          "indicator_count": 383,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 43,
          "modified_text": "457 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Insikt",
            "TAG-124"
          ],
          "malware_families": [
            "Interlock",
            "Rhysida",
            "Remcos",
            "Socgholish",
            "Insikt"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "67a1f245f3709030a9f0ccb7",
      "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
      "description": "A report by Insikt Group, based on an analysis of compromised WordPress sites, outlines the threat posed by a network of cybercriminal servers known as TAG-124, which is used to distribute malware.",
      "modified": "2025-03-06T10:04:51.026000",
      "created": "2025-02-04T10:56:05.010000",
      "tags": [
        "tag124",
        "cloudflare",
        "wordpress",
        "insikt group",
        "figure",
        "google chrome",
        "future",
        "urls",
        "ta582",
        "fake google",
        "rhysida",
        "powershell",
        "april",
        "insikt",
        "remcos",
        "interlock"
      ],
      "references": [
        "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
      ],
      "public": 1,
      "adversary": "Insikt",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Insikt",
          "display_name": "Insikt",
          "target": null
        },
        {
          "id": "Rhysida",
          "display_name": "Rhysida",
          "target": null
        },
        {
          "id": "REMCOS",
          "display_name": "REMCOS",
          "target": null
        },
        {
          "id": "Interlock",
          "display_name": "Interlock",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 30,
        "FileHash-SHA1": 30,
        "FileHash-SHA256": 30,
        "URL": 2,
        "domain": 254,
        "hostname": 112
      },
      "indicator_count": 458,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 863,
      "modified_text": "452 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "679ba047fa5e47a0f6e2c071",
      "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
      "description": "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base\n\nInsikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked by Recorded Future as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, 404TDS, KongTuke, and Chaya_002. TAG-124 comprises a network of compromised WordPress sites, actor-controlled payload servers, a central server, a suspected management server, an additional panel, and other components. The threat actors behind TAG-124 demonstrate high levels of activity, including regularly updating URLs embedded in the compromised WordPress sites, adding servers, refining TDS logic to evade detection, and adapting infection tactics, as demonstrated by their recent implementation of the ClickFix technique.",
      "modified": "2025-03-01T15:01:42.461000",
      "created": "2025-01-30T15:52:39.738000",
      "tags": [
        "fake google",
        "chrome update",
        "matomo instance",
        "remcos rat",
        "c2 ip",
        "address",
        "ta582",
        "hashes"
      ],
      "references": [],
      "public": 1,
      "adversary": "TAG-124",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Rhysida",
          "display_name": "Rhysida",
          "target": null
        },
        {
          "id": "Interlock",
          "display_name": "Interlock",
          "target": null
        },
        {
          "id": "SocGholish",
          "display_name": "SocGholish",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "InformationTechnogyISAC",
        "id": "141282",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 7,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 30,
        "domain": 234,
        "hostname": 105
      },
      "indicator_count": 383,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 43,
      "modified_text": "457 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "clmfireproofing.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "clmfireproofing.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780373858.0525029
}