{
  "type": "MD5",
  "indicator": "d09c0744273355b6da719fdb62923bed",
  "general": {
    "sections": [
      "general",
      "analysis"
    ],
    "type": "md5",
    "type_title": "FileHash-MD5",
    "indicator": "d09c0744273355b6da719fdb62923bed",
    "validation": [],
    "base_indicator": {
      "id": 4383617986,
      "indicator": "364cc871e66afe65e1845205105c3f53f34afc01",
      "type": "FileHash-SHA1",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "6a19766cc7caf96e27eae35e",
          "name": "Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant",
          "description": "Through April 2026, Kimsuky deployed sophisticated malicious campaigns against South Korean military and corporate entities using tailored social engineering tactics including fake security software installation pages and spoofed Webex meeting pages leveraging legitimate meeting schedules. The threat actor introduced a novel JSONPing technique allowing distribution pages to verify in real time whether victims executed the payload via JSONP queries to localhost servers. Analysis revealed a new HttpSpy variant with a three-stage execution chain replacing the previous single-binary architecture, utilizing RC4 encryption and shared infrastructure indicators. Attribution was confirmed through code pattern overlaps, reused encryption keys, XAMPP certificate fingerprints, and preferred ASN usage consistent with historical Kimsuky operations targeting South Korea.",
          "modified": "2026-05-29T12:34:19.341000",
          "created": "2026-05-29T11:20:12.463000",
          "tags": [
            "spear phishing",
            "httpspy",
            "webex spoofing",
            "loaddll.dll",
            "south korea targeting",
            "memloader",
            "jsonping",
            "calc.exe",
            "social engineering",
            "kimsuky",
            "spyloader.dll",
            "rat",
            "spyinster.dll"
          ],
          "references": [
            "https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant"
          ],
          "public": 1,
          "adversary": "Kimsuky",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "HttpSpy",
              "display_name": "HttpSpy",
              "target": null
            },
            {
              "id": "MemLoader",
              "display_name": "MemLoader",
              "target": null
            },
            {
              "id": "calc.exe",
              "display_name": "calc.exe",
              "target": null
            },
            {
              "id": "spyInster.dll",
              "display_name": "spyInster.dll",
              "target": null
            },
            {
              "id": "spyLoader.dll",
              "display_name": "spyLoader.dll",
              "target": null
            },
            {
              "id": "loadDll.dll",
              "display_name": "loadDll.dll",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Defense",
            "Finance"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 17,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 3,
            "IPv4": 2,
            "URL": 23,
            "hostname": 10
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386445,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "FileHash-SHA256",
          "related_indicator_is_active": 1
        },
        {
          "id": "69aa502a35cf71d8bfec3d58",
          "name": "Twitter Feed - skocherhan - 05-03-2026",
          "description": "",
          "modified": "2026-04-05T03:15:44.299000",
          "created": "2026-03-06T03:55:22.605000",
          "tags": [
            "Lazarus",
            "APT",
            "Remcos",
            "malware"
          ],
          "references": [
            "https://x.com/skocherhan/status/2029467781633110217",
            "https://x.com/skocherhan/status/2029554479452864834",
            "https://x.com/skocherhan/status/2029562704088723584",
            "https://x.com/skocherhan/status/2029562792835956767",
            "https://x.com/skocherhan/status/2029562800532574376",
            "https://x.com/skocherhan/status/2029575415711637506",
            "https://x.com/skocherhan/status/2029575432840872440",
            "https://x.com/skocherhan/status/2029575442378772862",
            "https://x.com/skocherhan/status/2029575966863904771",
            "https://x.com/skocherhan/status/2029619603886719059",
            "https://x.com/skocherhan/status/2029671521275253221",
            "https://x.com/skocherhan/status/2029673317381153065"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 4,
            "URL": 8,
            "FileHash-MD5": 1,
            "FileHash-SHA256": 6,
            "hostname": 2
          },
          "indicator_count": 21,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "55 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "FileHash-SHA256",
          "related_indicator_is_active": 1
        },
        {
          "id": "699fd75d96af929c09da4615",
          "name": "Twitter Feed - skocherhan - 25-02-2026",
          "description": "",
          "modified": "2026-03-28T05:07:47.431000",
          "created": "2026-02-26T05:17:17.815000",
          "tags": [
            "phishing",
            "malware",
            "APT",
            "Kimsuky",
            "Lumma"
          ],
          "references": [
            "https://x.com/skocherhan/status/2026509387485843716",
            "https://x.com/skocherhan/status/2026528655220805982",
            "https://x.com/skocherhan/status/2026533741816857070",
            "https://x.com/skocherhan/status/2026534973700780128",
            "https://x.com/skocherhan/status/2026542638179004651",
            "https://x.com/skocherhan/status/2026542835499987125",
            "https://x.com/skocherhan/status/2026572076442669456",
            "https://x.com/skocherhan/status/2026572092041286095",
            "https://x.com/skocherhan/status/2026607896566411412",
            "https://x.com/skocherhan/status/2026608229719912645",
            "https://x.com/skocherhan/status/2026626540172132553",
            "https://x.com/skocherhan/status/2026626640353075443",
            "https://x.com/skocherhan/status/2026704242615136530",
            "https://x.com/skocherhan/status/2026704262768501232",
            "https://x.com/skocherhan/status/2026715794403450924",
            "https://x.com/skocherhan/status/2026716493665202286",
            "https://x.com/skocherhan/status/2026716830585217175",
            "https://x.com/skocherhan/status/2026740591392928113",
            "https://x.com/skocherhan/status/2026779140750270744",
            "https://x.com/skocherhan/status/2026781529146278187",
            "https://x.com/skocherhan/status/2026789606411190564"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 7,
            "URL": 12,
            "FileHash-SHA256": 4,
            "FileHash-MD5": 5
          },
          "indicator_count": 28,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "63 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "FileHash-SHA256",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://x.com/skocherhan/status/2026534973700780128",
        "https://x.com/skocherhan/status/2026626540172132553",
        "https://x.com/skocherhan/status/2029575442378772862",
        "https://x.com/skocherhan/status/2026704262768501232",
        "https://x.com/skocherhan/status/2026789606411190564",
        "https://x.com/skocherhan/status/2029575432840872440",
        "https://x.com/skocherhan/status/2029554479452864834",
        "https://x.com/skocherhan/status/2026781529146278187",
        "https://x.com/skocherhan/status/2029619603886719059",
        "https://x.com/skocherhan/status/2029575415711637506",
        "https://x.com/skocherhan/status/2026740591392928113",
        "https://x.com/skocherhan/status/2026572092041286095",
        "https://x.com/skocherhan/status/2029562704088723584",
        "https://x.com/skocherhan/status/2026779140750270744",
        "https://x.com/skocherhan/status/2026716493665202286",
        "https://x.com/skocherhan/status/2026572076442669456",
        "https://x.com/skocherhan/status/2026533741816857070",
        "https://x.com/skocherhan/status/2026509387485843716",
        "https://x.com/skocherhan/status/2026542638179004651",
        "https://x.com/skocherhan/status/2026704242615136530",
        "https://x.com/skocherhan/status/2029671521275253221",
        "https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant",
        "https://x.com/skocherhan/status/2029467781633110217",
        "https://x.com/skocherhan/status/2026542835499987125",
        "https://x.com/skocherhan/status/2026626640353075443",
        "https://x.com/skocherhan/status/2026528655220805982",
        "https://x.com/skocherhan/status/2026715794403450924",
        "https://x.com/skocherhan/status/2026607896566411412",
        "https://x.com/skocherhan/status/2029562792835956767",
        "https://x.com/skocherhan/status/2029575966863904771",
        "https://x.com/skocherhan/status/2026608229719912645",
        "https://x.com/skocherhan/status/2026716830585217175",
        "https://x.com/skocherhan/status/2029562800532574376",
        "https://x.com/skocherhan/status/2029673317381153065"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "Kimsuky"
          ],
          "malware_families": [
            "Spyinster.dll",
            "Httpspy",
            "Memloader",
            "Calc.exe",
            "Loaddll.dll",
            "Spyloader.dll"
          ],
          "industries": [
            "Finance",
            "Defense"
          ]
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "6a19766cc7caf96e27eae35e",
      "name": "Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant",
      "description": "Through April 2026, Kimsuky deployed sophisticated malicious campaigns against South Korean military and corporate entities using tailored social engineering tactics including fake security software installation pages and spoofed Webex meeting pages leveraging legitimate meeting schedules. The threat actor introduced a novel JSONPing technique allowing distribution pages to verify in real time whether victims executed the payload via JSONP queries to localhost servers. Analysis revealed a new HttpSpy variant with a three-stage execution chain replacing the previous single-binary architecture, utilizing RC4 encryption and shared infrastructure indicators. Attribution was confirmed through code pattern overlaps, reused encryption keys, XAMPP certificate fingerprints, and preferred ASN usage consistent with historical Kimsuky operations targeting South Korea.",
      "modified": "2026-05-29T12:34:19.341000",
      "created": "2026-05-29T11:20:12.463000",
      "tags": [
        "spear phishing",
        "httpspy",
        "webex spoofing",
        "loaddll.dll",
        "south korea targeting",
        "memloader",
        "jsonping",
        "calc.exe",
        "social engineering",
        "kimsuky",
        "spyloader.dll",
        "rat",
        "spyinster.dll"
      ],
      "references": [
        "https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant"
      ],
      "public": 1,
      "adversary": "Kimsuky",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "HttpSpy",
          "display_name": "HttpSpy",
          "target": null
        },
        {
          "id": "MemLoader",
          "display_name": "MemLoader",
          "target": null
        },
        {
          "id": "calc.exe",
          "display_name": "calc.exe",
          "target": null
        },
        {
          "id": "spyInster.dll",
          "display_name": "spyInster.dll",
          "target": null
        },
        {
          "id": "spyLoader.dll",
          "display_name": "spyLoader.dll",
          "target": null
        },
        {
          "id": "loadDll.dll",
          "display_name": "loadDll.dll",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Defense",
        "Finance"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 17,
        "FileHash-SHA1": 3,
        "FileHash-SHA256": 3,
        "IPv4": 2,
        "URL": 23,
        "hostname": 10
      },
      "indicator_count": 58,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386445,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "FileHash-SHA256",
      "related_indicator_is_active": 1
    },
    {
      "id": "69aa502a35cf71d8bfec3d58",
      "name": "Twitter Feed - skocherhan - 05-03-2026",
      "description": "",
      "modified": "2026-04-05T03:15:44.299000",
      "created": "2026-03-06T03:55:22.605000",
      "tags": [
        "Lazarus",
        "APT",
        "Remcos",
        "malware"
      ],
      "references": [
        "https://x.com/skocherhan/status/2029467781633110217",
        "https://x.com/skocherhan/status/2029554479452864834",
        "https://x.com/skocherhan/status/2029562704088723584",
        "https://x.com/skocherhan/status/2029562792835956767",
        "https://x.com/skocherhan/status/2029562800532574376",
        "https://x.com/skocherhan/status/2029575415711637506",
        "https://x.com/skocherhan/status/2029575432840872440",
        "https://x.com/skocherhan/status/2029575442378772862",
        "https://x.com/skocherhan/status/2029575966863904771",
        "https://x.com/skocherhan/status/2029619603886719059",
        "https://x.com/skocherhan/status/2029671521275253221",
        "https://x.com/skocherhan/status/2029673317381153065"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 4,
        "URL": 8,
        "FileHash-MD5": 1,
        "FileHash-SHA256": 6,
        "hostname": 2
      },
      "indicator_count": 21,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "55 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "FileHash-SHA256",
      "related_indicator_is_active": 1
    },
    {
      "id": "699fd75d96af929c09da4615",
      "name": "Twitter Feed - skocherhan - 25-02-2026",
      "description": "",
      "modified": "2026-03-28T05:07:47.431000",
      "created": "2026-02-26T05:17:17.815000",
      "tags": [
        "phishing",
        "malware",
        "APT",
        "Kimsuky",
        "Lumma"
      ],
      "references": [
        "https://x.com/skocherhan/status/2026509387485843716",
        "https://x.com/skocherhan/status/2026528655220805982",
        "https://x.com/skocherhan/status/2026533741816857070",
        "https://x.com/skocherhan/status/2026534973700780128",
        "https://x.com/skocherhan/status/2026542638179004651",
        "https://x.com/skocherhan/status/2026542835499987125",
        "https://x.com/skocherhan/status/2026572076442669456",
        "https://x.com/skocherhan/status/2026572092041286095",
        "https://x.com/skocherhan/status/2026607896566411412",
        "https://x.com/skocherhan/status/2026608229719912645",
        "https://x.com/skocherhan/status/2026626540172132553",
        "https://x.com/skocherhan/status/2026626640353075443",
        "https://x.com/skocherhan/status/2026704242615136530",
        "https://x.com/skocherhan/status/2026704262768501232",
        "https://x.com/skocherhan/status/2026715794403450924",
        "https://x.com/skocherhan/status/2026716493665202286",
        "https://x.com/skocherhan/status/2026716830585217175",
        "https://x.com/skocherhan/status/2026740591392928113",
        "https://x.com/skocherhan/status/2026779140750270744",
        "https://x.com/skocherhan/status/2026781529146278187",
        "https://x.com/skocherhan/status/2026789606411190564"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 7,
        "URL": 12,
        "FileHash-SHA256": 4,
        "FileHash-MD5": 5
      },
      "indicator_count": 28,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "63 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "FileHash-SHA256",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "d09c0744273355b6da719fdb62923bed",
    "type": "Hash"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "d09c0744273355b6da719fdb62923bed",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780169962.1761448
}