{
  "type": "Domain",
  "indicator": "docs.dissect.tools",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/docs.dissect.tools",
    "alexa": "http://www.alexa.com/siteinfo/docs.dissect.tools",
    "indicator": "docs.dissect.tools",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {},
    "pulse_info": {
      "count": 0,
      "pulses": [],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 1,
  "pulses": [
    {
      "id": "6a1447f25db6bc082d5093cb",
      "name": "RemotePE: The Lazarus RAT that lives in memory",
      "description": "A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.",
      "author_name": "AlienVault",
      "modified": "2026-05-25T15:15:11.630000",
      "created": "2026-05-25T13:00:34.674000",
      "revision": 2,
      "tlp": "white",
      "public": 1,
      "adversary": "Lazarus",
      "indicators": [
        {
          "id": 14297815,
          "indicator": "file.name",
          "type": "domain",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 2916025873,
          "indicator": "akamaicloud.com",
          "type": "domain",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 3525046790,
          "indicator": "event.name",
          "type": "domain",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126117224,
          "indicator": "23c2569a65870a9e412d98d5b3bdc554",
          "type": "FileHash-MD5",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126117225,
          "indicator": "75a46b23825ce7aa4ca297d93450f4e2",
          "type": "FileHash-MD5",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126117230,
          "indicator": "3b994549ab4fd9024b2f0155094d7aa43b70bb8f",
          "type": "FileHash-SHA1",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126117231,
          "indicator": "91def0a4dd9b35510d7f8897bc114f975a5d7e2b",
          "type": "FileHash-SHA1",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126117232,
          "indicator": "159471e1abc9adf6733af9d24781fbf27a776b81d182901c2e04e28f3fe2e6f3",
          "type": "FileHash-SHA256",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126117235,
          "indicator": "aa4a2d1215f864481994234f13ab485b95150161b4566c180419d93dda7ac039",
          "type": "FileHash-SHA256",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126123226,
          "indicator": "37f5afb9ed3761e73feb95daceb7a1fdbb13c8b5fc1a2ba22e0ef7994c7920ef",
          "type": "FileHash-SHA256",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126123229,
          "indicator": "4f6ae0110cf652264293df571d66955f7109e3424a070423b5e50edc3eb43874",
          "type": "FileHash-SHA256",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126123233,
          "indicator": "7a05188ab0129b0b4f38e2e7599c5c52149ce0131140db33feb251d926428d68",
          "type": "FileHash-SHA256",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126123245,
          "indicator": "442f4abac74d844256e3ff60f929b358ded71881",
          "type": "FileHash-SHA1",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126123246,
          "indicator": "56f9b97fee195ed8dea39552eac288aa58cfaf48",
          "type": "FileHash-SHA1",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126123248,
          "indicator": "bef8714787a76d33d74dc23e7c750e74b57f6f04",
          "type": "FileHash-SHA1",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126123251,
          "indicator": "aes-secure.net",
          "type": "domain",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4126123252,
          "indicator": "azureglobalaccelerator.com",
          "type": "domain",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4373453820,
          "indicator": "6b33d20196267b0d64bca815ca863558d26b17cee77caf62a6cce8eae555ac8d",
          "type": "FileHash-SHA256",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4373453822,
          "indicator": "62e040a32aac2d2faa8d2bffa2cf7ab662228cebf9bb78eaa0a633c0b729d119",
          "type": "FileHash-SHA256",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4373453823,
          "indicator": "710f15302859c7af1c1e25219d704841b3fdbc48f16a5a574d5ab6cf4f4842e8",
          "type": "FileHash-SHA256",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4377140173,
          "indicator": "https://docs.dissect.tools/en/stable",
          "type": "URL",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4377140174,
          "indicator": "https://docs.dissect.tools/en/stable/",
          "type": "URL",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4377140175,
          "indicator": "6c2b40c172a9c8706abc149ac72f5c509e4c5f56",
          "type": "FileHash-SHA1",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4377140176,
          "indicator": "84bb3752307a088a6cdba4215aa9a993d34f353c",
          "type": "FileHash-SHA1",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4377140177,
          "indicator": "devicelinkintel.com",
          "type": "domain",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4377140178,
          "indicator": "intelcloudinsights.com",
          "type": "domain",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4377140179,
          "indicator": "msdeliverycontent.com",
          "type": "domain",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4377140180,
          "indicator": "docs.dissect.tools",
          "type": "hostname",
          "created": "2026-05-25T13:00:35",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        }
      ],
      "tags": [
        "poolrat",
        "pondrat",
        "dpapiloader",
        "themeforestrat",
        "hellsgate",
        "remotepeloader",
        "remotepe"
      ],
      "targeted_countries": [],
      "malware_families": [
        "DPAPILoader",
        "RemotePELoader",
        "RemotePE",
        "ThemeForestRAT",
        "PondRAT",
        "POOLRAT"
      ],
      "attack_ids": [
        "T1543.003",
        "T1082",
        "T1106",
        "T1005",
        "T1140",
        "T1055",
        "T1560",
        "T1562.006",
        "T1083",
        "T1036.004",
        "T1497",
        "T1057",
        "T1562.001",
        "T1027",
        "T1573",
        "T1132",
        "T1027.002",
        "T1071.001",
        "T1574.002",
        "T1480.001"
      ],
      "references": [
        "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/"
      ],
      "industries": [
        "Finance"
      ],
      "extract_source": [],
      "more_indicators": false,
      "indicator_count": 28
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "docs.dissect.tools",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "docs.dissect.tools",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780173562.5309722
}