{
  "type": "Domain",
  "indicator": "denwp.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/denwp.com",
    "alexa": "http://www.alexa.com/siteinfo/denwp.com",
    "indicator": "denwp.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3980906967,
      "indicator": "denwp.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "682ad73578171f9c2843b13f",
          "name": "Detailed Examination of the More_Eggs Venom Spider Phishing Campaign",
          "description": "The More_Eggs malware has been confirmed as one of the world\u2019s most prolific cyber-thieves, infecting more than 100,000 organisations in the UK and Ireland. This in-depth report from DenWP provides a thorough analysis of the More_Eggs Venom Spider Phishing Campaign. The study uncovers the sophisticated tactics, techniques, and procedures (TTPs) employed by cybercriminals to execute this phishing campaign.",
          "modified": "2025-11-18T09:50:22.476000",
          "created": "2025-05-19T07:01:09.980000",
          "tags": [
            "moreeggs",
            "lnk file",
            "javascript",
            "microsoft word",
            "filepath",
            "stop",
            "arctic wolf",
            "venom spider",
            "js file",
            "windows",
            "xcopy",
            "next",
            "base64",
            "fig",
            "more_eggs",
            "saturday",
            "jitu url",
            "http",
            "domain",
            "file hash"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Fig",
              "display_name": "Fig",
              "target": null
            },
            {
              "id": "More_Eggs",
              "display_name": "More_Eggs",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 29,
            "domain": 30,
            "FileHash-MD5": 18,
            "FileHash-SHA1": 18,
            "FileHash-SHA256": 62,
            "hostname": 23
          },
          "indicator_count": 180,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 543,
          "modified_text": "195 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68cda7d2fa81b016a486aad8",
          "name": "logo Virustotal/Virustotal.com( usuni\u0119te pliki Virustotal i ich wsp\u00f3lne cechy)",
          "description": "",
          "modified": "2025-10-19T18:02:53.885000",
          "created": "2025-09-19T18:58:26.750000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 213,
            "FileHash-MD5": 100,
            "FileHash-SHA1": 100,
            "FileHash-SHA256": 150,
            "domain": 11,
            "hostname": 5
          },
          "indicator_count": 579,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 124,
          "modified_text": "225 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67aac6e4b628acffaed3f068",
          "name": "New Batch - Malcerts - 02.10.25 - unenriched",
          "description": "Here is the full text of the text that was found on the website of Mozilla, following an investigation by the security firm Virustotal and the UK's Office of National Statistics (ONS).. [autofilled].\n\nMore Malcerts from Sample Device deployed at several sites in YEG - Canada. Related to pulse - Thor Scan Lite Linux\nNot enriched on import, but did include links to VT entries as IOCs (those will be false positives - but easy access). \nFolder name: Mozilla Located @ /usr/share/ca-certificates",
          "modified": "2025-03-16T17:01:06.968000",
          "created": "2025-02-11T03:41:24.585000",
          "tags": [
            "UAlberta",
            "Malcerts",
            "Certificates",
            "Eduroam",
            "Alberta"
          ],
          "references": [
            "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/iocs",
            "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/summary",
            "https://hybrid-analysis.com/file-collection/67aa8951a3fc5708a905306a",
            "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/community",
            "https://tria.ge/250210-3c3c3askfz",
            "https://tria.ge/250210-3nh4kasmes",
            "https://tria.ge/250210-3y8f7sspdy",
            "https://tria.ge/250211-dhpxgswlax",
            "https://tria.ge/250211-dt1hcswme1",
            "https://tria.ge/250211-dx9v7swnbw",
            "Zipped IOC: c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
            "https://www.virustotal.com/graph/embed/g4d7797bcffdd450281d4012ac3a0a5ee3fafe8b4f5964c18b4e0332306cb367b?theme=dark",
            "https://tip.neiki.dev/file/c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
            "c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
            "Cert[.]pl MLDB: 1da23fc67a5f101321e39d04e76dcaa7"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education",
            "Government",
            "Healthcare",
            "Telecommunications",
            "Finance",
            "Agriculture",
            "Hospitality",
            "Media",
            "Retail"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 831,
            "FileHash-SHA1": 801,
            "FileHash-SHA256": 3227,
            "URL": 395,
            "domain": 189,
            "hostname": 798
          },
          "indicator_count": 6241,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 131,
          "modified_text": "442 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "670e2c73c5cd8a793b2b02bf",
          "name": "HijackLoader evolution: abusing genuine signing certificates",
          "description": "A report by HarfangLab EDR and MITRE ATT&CK on the threat posed by the Lumma Stealer malware, published on 11 October, 2024, outlines the tactics used to deploy the malware.",
          "modified": "2024-10-15T08:48:51.289000",
          "created": "2024-10-15T08:48:51.289000",
          "tags": [
            "hijackloader",
            "october",
            "samples",
            "harfanglab edr",
            "sha256",
            "lumma stealer",
            "dll sideloading",
            "infection chain",
            "fake captcha",
            "zip archive",
            "installer",
            "path",
            "hider",
            "loader",
            "gate",
            "powershell",
            "lumma",
            "samecoin"
          ],
          "references": [
            "https://harfanglab.io/insidethelab/hijackloader-abusing-genuine-certificates/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lumma",
              "display_name": "Lumma",
              "target": null
            },
            {
              "id": "SameCoin",
              "display_name": "SameCoin",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 38,
            "FileHash-SHA1": 43,
            "FileHash-SHA256": 70,
            "URL": 1,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 155,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 865,
          "modified_text": "594 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66f10860b1826d7cbdba1818",
          "name": "Dissecting Lumma Malware: Analyzing the Fake CAPTCHA and Obfuscation Techniques - Part 2 | InfoStealers",
          "description": "In our second series on Lumma Stealer, we examine the technical details of the malware\u2019s loader, and how we identify and analyze the malicious activities carried out by the cyber-attackers.",
          "modified": "2024-09-23T06:19:12.399000",
          "created": "2024-09-23T06:19:12.399000",
          "tags": [
            "javascript",
            "lumma stealer",
            "cyberchef",
            "javascript code",
            "bitlockertogo",
            "captcha page",
            "hollows hunter",
            "part",
            "powershell code",
            "detect",
            "easy",
            "powershell",
            "aeon",
            "hunter",
            "virustotal",
            "lumma"
          ],
          "references": [
            "https://infostealers.com/article/dissecting-lumma-malware-analyzing-the-fake-captcha-and-obfuscation-techniques-part-2/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lumma",
              "display_name": "Lumma",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "jacksparrow",
            "id": "142887",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 10,
            "FileHash-SHA256": 2,
            "URL": 1
          },
          "indicator_count": 13,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 37,
          "modified_text": "617 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://tria.ge/250210-3y8f7sspdy",
        "https://tip.neiki.dev/file/c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
        "c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
        "Zipped IOC: c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
        "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/community",
        "https://tria.ge/250210-3nh4kasmes",
        "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/iocs",
        "https://infostealers.com/article/dissecting-lumma-malware-analyzing-the-fake-captcha-and-obfuscation-techniques-part-2/",
        "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/summary",
        "https://harfanglab.io/insidethelab/hijackloader-abusing-genuine-certificates/",
        "Cert[.]pl MLDB: 1da23fc67a5f101321e39d04e76dcaa7",
        "https://tria.ge/250211-dt1hcswme1",
        "https://tria.ge/250210-3c3c3askfz",
        "https://tria.ge/250211-dx9v7swnbw",
        "https://tria.ge/250211-dhpxgswlax",
        "https://hybrid-analysis.com/file-collection/67aa8951a3fc5708a905306a",
        "https://www.virustotal.com/graph/embed/g4d7797bcffdd450281d4012ac3a0a5ee3fafe8b4f5964c18b4e0332306cb367b?theme=dark"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Fig",
            "Samecoin",
            "More_eggs",
            "Lumma"
          ],
          "industries": [
            "Agriculture",
            "Healthcare",
            "Media",
            "Government",
            "Retail",
            "Finance",
            "Telecommunications",
            "Education",
            "Hospitality"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "682ad73578171f9c2843b13f",
      "name": "Detailed Examination of the More_Eggs Venom Spider Phishing Campaign",
      "description": "The More_Eggs malware has been confirmed as one of the world\u2019s most prolific cyber-thieves, infecting more than 100,000 organisations in the UK and Ireland. This in-depth report from DenWP provides a thorough analysis of the More_Eggs Venom Spider Phishing Campaign. The study uncovers the sophisticated tactics, techniques, and procedures (TTPs) employed by cybercriminals to execute this phishing campaign.",
      "modified": "2025-11-18T09:50:22.476000",
      "created": "2025-05-19T07:01:09.980000",
      "tags": [
        "moreeggs",
        "lnk file",
        "javascript",
        "microsoft word",
        "filepath",
        "stop",
        "arctic wolf",
        "venom spider",
        "js file",
        "windows",
        "xcopy",
        "next",
        "base64",
        "fig",
        "more_eggs",
        "saturday",
        "jitu url",
        "http",
        "domain",
        "file hash"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Fig",
          "display_name": "Fig",
          "target": null
        },
        {
          "id": "More_Eggs",
          "display_name": "More_Eggs",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 29,
        "domain": 30,
        "FileHash-MD5": 18,
        "FileHash-SHA1": 18,
        "FileHash-SHA256": 62,
        "hostname": 23
      },
      "indicator_count": 180,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 543,
      "modified_text": "195 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68cda7d2fa81b016a486aad8",
      "name": "logo Virustotal/Virustotal.com( usuni\u0119te pliki Virustotal i ich wsp\u00f3lne cechy)",
      "description": "",
      "modified": "2025-10-19T18:02:53.885000",
      "created": "2025-09-19T18:58:26.750000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 213,
        "FileHash-MD5": 100,
        "FileHash-SHA1": 100,
        "FileHash-SHA256": 150,
        "domain": 11,
        "hostname": 5
      },
      "indicator_count": 579,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 124,
      "modified_text": "225 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67aac6e4b628acffaed3f068",
      "name": "New Batch - Malcerts - 02.10.25 - unenriched",
      "description": "Here is the full text of the text that was found on the website of Mozilla, following an investigation by the security firm Virustotal and the UK's Office of National Statistics (ONS).. [autofilled].\n\nMore Malcerts from Sample Device deployed at several sites in YEG - Canada. Related to pulse - Thor Scan Lite Linux\nNot enriched on import, but did include links to VT entries as IOCs (those will be false positives - but easy access). \nFolder name: Mozilla Located @ /usr/share/ca-certificates",
      "modified": "2025-03-16T17:01:06.968000",
      "created": "2025-02-11T03:41:24.585000",
      "tags": [
        "UAlberta",
        "Malcerts",
        "Certificates",
        "Eduroam",
        "Alberta"
      ],
      "references": [
        "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/iocs",
        "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/summary",
        "https://hybrid-analysis.com/file-collection/67aa8951a3fc5708a905306a",
        "https://www.virustotal.com/gui/collection/207ce29e0defa958ed9ce12667ce39b491e3e8d1f0a345b3c6b50992c9879b5c/community",
        "https://tria.ge/250210-3c3c3askfz",
        "https://tria.ge/250210-3nh4kasmes",
        "https://tria.ge/250210-3y8f7sspdy",
        "https://tria.ge/250211-dhpxgswlax",
        "https://tria.ge/250211-dt1hcswme1",
        "https://tria.ge/250211-dx9v7swnbw",
        "Zipped IOC: c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
        "https://www.virustotal.com/graph/embed/g4d7797bcffdd450281d4012ac3a0a5ee3fafe8b4f5964c18b4e0332306cb367b?theme=dark",
        "https://tip.neiki.dev/file/c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
        "c85a87adee4c099081c0be6a69d7468280f4d289bde882c66af86d023d32288a",
        "Cert[.]pl MLDB: 1da23fc67a5f101321e39d04e76dcaa7"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education",
        "Government",
        "Healthcare",
        "Telecommunications",
        "Finance",
        "Agriculture",
        "Hospitality",
        "Media",
        "Retail"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 831,
        "FileHash-SHA1": 801,
        "FileHash-SHA256": 3227,
        "URL": 395,
        "domain": 189,
        "hostname": 798
      },
      "indicator_count": 6241,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 131,
      "modified_text": "442 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "670e2c73c5cd8a793b2b02bf",
      "name": "HijackLoader evolution: abusing genuine signing certificates",
      "description": "A report by HarfangLab EDR and MITRE ATT&CK on the threat posed by the Lumma Stealer malware, published on 11 October, 2024, outlines the tactics used to deploy the malware.",
      "modified": "2024-10-15T08:48:51.289000",
      "created": "2024-10-15T08:48:51.289000",
      "tags": [
        "hijackloader",
        "october",
        "samples",
        "harfanglab edr",
        "sha256",
        "lumma stealer",
        "dll sideloading",
        "infection chain",
        "fake captcha",
        "zip archive",
        "installer",
        "path",
        "hider",
        "loader",
        "gate",
        "powershell",
        "lumma",
        "samecoin"
      ],
      "references": [
        "https://harfanglab.io/insidethelab/hijackloader-abusing-genuine-certificates/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lumma",
          "display_name": "Lumma",
          "target": null
        },
        {
          "id": "SameCoin",
          "display_name": "SameCoin",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 27,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 38,
        "FileHash-SHA1": 43,
        "FileHash-SHA256": 70,
        "URL": 1,
        "domain": 2,
        "hostname": 1
      },
      "indicator_count": 155,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 865,
      "modified_text": "594 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66f10860b1826d7cbdba1818",
      "name": "Dissecting Lumma Malware: Analyzing the Fake CAPTCHA and Obfuscation Techniques - Part 2 | InfoStealers",
      "description": "In our second series on Lumma Stealer, we examine the technical details of the malware\u2019s loader, and how we identify and analyze the malicious activities carried out by the cyber-attackers.",
      "modified": "2024-09-23T06:19:12.399000",
      "created": "2024-09-23T06:19:12.399000",
      "tags": [
        "javascript",
        "lumma stealer",
        "cyberchef",
        "javascript code",
        "bitlockertogo",
        "captcha page",
        "hollows hunter",
        "part",
        "powershell code",
        "detect",
        "easy",
        "powershell",
        "aeon",
        "hunter",
        "virustotal",
        "lumma"
      ],
      "references": [
        "https://infostealers.com/article/dissecting-lumma-malware-analyzing-the-fake-captcha-and-obfuscation-techniques-part-2/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lumma",
          "display_name": "Lumma",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "jacksparrow",
        "id": "142887",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 10,
        "FileHash-SHA256": 2,
        "URL": 1
      },
      "indicator_count": 13,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 37,
      "modified_text": "617 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "denwp.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "denwp.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780389074.0187597
}