{
  "type": "Domain",
  "indicator": "dsdsei.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/dsdsei.com",
    "alexa": "http://www.alexa.com/siteinfo/dsdsei.com",
    "indicator": "dsdsei.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3700942581,
      "indicator": "dsdsei.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "67400d74e667ab8c476122e8",
          "name": "Unveiling WolfsBane: Linux counterpart to Gelsevirine",
          "description": "ESET researchers have discovered previously unknown Linux backdoors attributed to the China-aligned Gelsemium APT group. The main backdoor, named WolfsBane, is the Linux equivalent of Gelsemium's Gelsevirine backdoor for Windows. Another backdoor, FireWood, is connected to the group's Project Wood malware. These tools are designed for cyberespionage, targeting system information, credentials, and specific files. The malware uses sophisticated techniques for persistence, stealth, and command execution. This discovery marks Gelsemium's first known use of Linux malware, indicating a shift in APT tactics towards exploiting vulnerabilities in internet-facing Linux systems.",
          "modified": "2024-12-22T04:02:40.049000",
          "created": "2024-11-22T04:49:56.508000",
          "tags": [
            "linux",
            "wolfsbane",
            "rootkit",
            "apt",
            "backdoor",
            "persistence",
            "gelsevirine",
            "cyberespionage",
            "project wood",
            "firewood"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
          ],
          "public": 1,
          "adversary": "Gelsemium",
          "targeted_countries": [
            "Philippines",
            "Singapore",
            "Taiwan"
          ],
          "malware_families": [
            {
              "id": "WolfsBane",
              "display_name": "WolfsBane",
              "target": null
            },
            {
              "id": "FireWood",
              "display_name": "FireWood",
              "target": null
            },
            {
              "id": "Gelsemium - S0666",
              "display_name": "Gelsemium - S0666",
              "target": null
            },
            {
              "id": "Gelsevirine",
              "display_name": "Gelsevirine",
              "target": null
            },
            {
              "id": "Gelsenicine",
              "display_name": "Gelsenicine",
              "target": null
            },
            {
              "id": "Gelsemine",
              "display_name": "Gelsemine",
              "target": null
            },
            {
              "id": "Project Wood",
              "display_name": "Project Wood",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Government",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 74,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 27,
            "FileHash-SHA1": 70,
            "FileHash-SHA256": 27,
            "domain": 3,
            "hostname": 10
          },
          "indicator_count": 137,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386457,
          "modified_text": "524 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5fa1ee5c64dc0e2060647954",
          "name": "Malware - Malware Domain Feed V2 - November 03 2020",
          "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
          "modified": "2026-05-28T12:10:48.255000",
          "created": "2020-11-03T23:57:16.317000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 130371,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "otxrobottwo_testing",
            "id": "83138",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45551,
            "domain": 66442
          },
          "indicator_count": 111993,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 970,
          "modified_text": "2 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67c0cdc35112c5919563a334",
          "name": "Intel is bad awy",
          "description": "",
          "modified": "2025-03-29T20:01:20.482000",
          "created": "2025-02-27T20:40:35.539000",
          "tags": [
            "sign",
            "github",
            "find",
            "view",
            "search",
            "strong",
            "code issues",
            "pull",
            "breadcrumbs",
            "damn",
            "star",
            "footer",
            "sha1",
            "helldown linux",
            "iocs helldown",
            "windows payload",
            "icon",
            "darkrace",
            "donex",
            "ransom",
            "defanged file",
            "hashes",
            "ipv4",
            "sha256",
            "c2 ip",
            "address",
            "plugin",
            "brazanbamboo c2",
            "panel",
            "archive file",
            "bha006",
            "telegram bot",
            "token",
            "chat id",
            "sha256 hashes",
            "iocs",
            "intermediary",
            "landing",
            "aitm server",
            "compromise note",
            "hashes payload",
            "loader",
            "dropper",
            "ips https",
            "urls https",
            "duoyi",
            "ioc url",
            "ipv4 address",
            "c2 server",
            "sample sha256",
            "remcos",
            "decrypted",
            "urls http",
            "payload",
            "amos stealer",
            "stealc c2",
            "rhadamanthys c2",
            "phishing urls",
            "google meet",
            "amos steaker",
            "html payload",
            "stealc payload",
            "md5 hashes",
            "sha1 hashes",
            "iocs zip",
            "lnk file",
            "msi file",
            "payload url",
            "eldorado",
            "linux",
            "service dll",
            "cheat engine",
            "c2 domain",
            "compromise",
            "urls",
            "iocs files",
            "network ip",
            "domain",
            "malware hash",
            "noopldr type1",
            "noopldr type2",
            "download url",
            "email addresses",
            "block",
            "ioc http",
            "iocs hash",
            "url https",
            "ghostgambit",
            "hidden rootkit",
            "gh0strat",
            "mekotio banking",
            "financial",
            "latin america",
            "detected",
            "zipmsi",
            "downloader",
            "ip address",
            "cobalt strike",
            "first seen",
            "seen",
            "pantegana",
            "tls certificate",
            "fingerprint",
            "samples",
            "trojanspy",
            "msi",
            "subdomains",
            "reddit",
            "wetransfer",
            "ioc hash",
            "file hashes",
            "ip addresses",
            "fake captcha",
            "html",
            "hta script",
            "lumma payload",
            "filehashsha256",
            "indicator type",
            "sha256 lnk",
            "ports",
            "first stage",
            "md5 file",
            "domains",
            "reddelta c2",
            "servers",
            "octoberdecember",
            "shortcut",
            "files",
            "solo airfield",
            "quoc",
            "bctt",
            "kongtuke",
            "mintsloader c2",
            "js download",
            "c2 http",
            "boinc c2",
            "c2 address",
            "analyzed",
            "file name",
            "na stark",
            "na majestic",
            "description",
            "trojanized",
            "beavertail",
            "anydesk module",
            "domain hosting",
            "first",
            "details",
            "monitor",
            "sites",
            "fake chrome",
            "payload host",
            "c2 https",
            "examples",
            "atomic stealer",
            "c2 servers",
            "cthulhu stealer",
            "server http",
            "l files",
            "original",
            "iocs malicious",
            "mirrowsimps",
            "defanged",
            "strike loaders",
            "plugx",
            "plugx c2",
            "sspiuacbypass",
            "malware",
            "malware c2",
            "filehashmd5",
            "site",
            "orgvgodpayment",
            "quite solsjoas",
            "ioc sha256",
            "similar sha256",
            "http",
            "url hundreds",
            "url samples",
            "filehash",
            "guidloader",
            "finaldraft elf",
            "type name",
            "reference",
            "finaldraft",
            "sha256 pfman",
            "pathloader",
            "atomic https",
            "systembc",
            "ghostsocks",
            "invisibleferret",
            "vant",
            "rspackcore",
            "monero",
            "sha256 hash",
            "code snippets",
            "psexec",
            "ituneshelper",
            "pscp",
            "sftp",
            "googleupdate",
            "meshagent",
            "ultravnc",
            "file",
            "bootkitty iocs",
            "phpsert",
            "phpsert variant",
            "createdump tool",
            "visual studio",
            "code",
            "server",
            "sql injection",
            "studio code",
            "ssh access",
            "hta file",
            "vbshower c2",
            "powershower c2",
            "cloud",
            "hta md5",
            "domain name",
            "links",
            "c http",
            "horns",
            "version",
            "version b",
            "version c",
            "version d",
            "version e",
            "burnsrat c",
            "a http",
            "github users",
            "shell commands",
            "vssadmin delete",
            "userprofile",
            "public",
            "registry keys",
            "phobos",
            "lettointago",
            "carljohnson1948",
            "samuelwhite1821",
            "file hash",
            "lockbit",
            "indicatortype",
            "data",
            "mlpea",
            "w32neshtad",
            "gmer",
            "neshta",
            "opswat oesis",
            "v4 removal"
          ],
          "references": [
            "Bootkitty",
            "Glove-Stealer",
            "Fake Discount Sites Exploit Black Friday",
            "Helldown Ransomware",
            "HawkEye Malware",
            "PXA Stealer",
            "Iranian Hackers Use GitHub and Phishing to Evade Detection in SnailResin Attack",
            "BrazenBamboo",
            "SpyGlace",
            "RustyStealer and New Ymir Ransomware",
            "PyPI-AIOCPA",
            "Python NodeStealer",
            "romcom-exploits-firefox-and-windows",
            "Rockstar-Phishing",
            "Silent Skimmer Gets Loud (Again)",
            "SteelFox Trojan",
            "WezRat Malware",
            "Avast-Anti-Root-KIt",
            "Winos4.0 RAT",
            "APT36",
            "WolfsBane Backdoor",
            "APT-K-47",
            "Remcos RAT",
            "babbleloader",
            "Bitter APT",
            "UAC-0194\u2019s Exploitation of CVE-2024-43451 in Ukraine for Phishing",
            "CloudScout_ Evasive Panda scouting cloud services",
            "clickfix-tactic",
            "Akira Ransomware",
            "Bumblebee Malware",
            "ELDORADO RANSOMWARE",
            "Evasive Panda Uses MACMA and MgBot Malware to Target US and Taiwan",
            "Demodex rootkit",
            "BugSleep Malware",
            "HotPage.exe (malware)",
            "Qilin Ransomware",
            "NOOPDOOR Malware",
            "Shadowroot Ransomware",
            "play ransomware",
            "MALLOX RANSOMWARE",
            "New Malware Campaign Abusing RDPWrapper and Tailscale to Target Cryptocurrency Users",
            "ACR Stealer",
            "Suspicious Domains Exploiting the Recent CrowdStrike Outage!",
            "Gh0stGambit",
            "MEKOTIO BANKING TROJAN",
            "TAG-100",
            "Fake game sites lead to information stealers",
            "Chrome Extensions Hijacked, 2.6 Million Users Impacted",
            "macOS Users Targeted by the New Variant of Banshee Infostealer",
            "Hundreds of fake Reddit sites push Lumma Stealer malware",
            "GamaCopy APT Group Mimicking GamaRedon",
            "InvisibleFerret Malware Leveraging Python for Targeted Attacks",
            "Fake CAPTCHA Campaign That Spreads LUMMA Info Stealer",
            "REF5961 Group Deploys EAGERBEE Backdoor Against Critical Sectors",
            "Phishing Campaigns Fuel Compiled AutoIt Malware Distribution",
            "The great Google Ads heist_ criminals ransack advertiser accounts via fake Google ads",
            "New Star Blizzard spear-phishing campaign targets WhatsApp accounts",
            "RansomHub Affiliate leverages Python-based backdoor",
            "Sliver Implant Targets German Entities with DLL Sideloading and Proxying Techniques",
            "Advanced Evasion Techniques Used by NonEuclid RAT",
            "The Return of PlugX Malware with Fresh Tricks",
            "The Growing Risk of Sneaky 2FA for Microsoft and Gmail Accounts",
            "Weaponized Software Targeting Chinese Organizations",
            "Threat Surge as Lumma Stealer Expands Its Reach",
            "Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain",
            "MintsLoader_Stealc",
            "North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks",
            "North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware",
            "Rat Race_ ValleyRAT Malware Targets Organizations with New Delivery Techniques",
            "Salt Typhoon  Target U.S. Telecom Networks",
            "SecTopRAT",
            "Stealers on the Rise",
            "Snake Keylogger",
            "AsyncRAT Reloaded",
            "The BadPilot campaign_ Seashell Blizzard subgroup conducts multiyear global access operation",
            "FatalRAT",
            "SystemBC RAT Poses New Risks to Linux System",
            "Unveiling Silent Lynx APT Targeting Entities Across Kyrgyzstan & Neighbouring Nations",
            "FERRET Malware Targets macOS in Sophisticated North Korean Attacks",
            "Espionage Campaign Targeting South Asian Entities",
            "Astral Stealer Strikes Again Stealing More Than Just Your Cookies",
            "The New Ransomware Menace Vgod Gains Momentum",
            "Microsoft Advertisers Phished via Malicious Google Ads",
            "LegionLoader Malware Expands Global Reach",
            "NEW.txt",
            "From Stealers to Ransomware PureCrypter Delivers It All",
            "New Phishing Campaign Abuses Webflow, SEO, and Fake CAPTCHAs",
            "FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux",
            "LockBit Ransomware Attack Leveraging Cobalt Strike",
            "Rspack_Compromised_Packages",
            "SmokeLoader",
            "Sock5Systemz-PROXY-AM",
            "solana-backdoor",
            "U.S. Organization in China Targeted by Attackers",
            "UAC-0185 attacks warned by CERT-UA",
            "BellaCpp",
            "bootkitty(logofail)",
            "Visual Studio Code Remote tunnels",
            "Cloud Atlas seen using a new tool in its attacks",
            "Christmas-Themed LNK Files Used for Malware Delivery",
            "DarkGate",
            "MirrorFace Campain",
            "horns-hooves",
            "Developers Targeted by New \u2018OtterCookie\u2019 Malware with Fake Job Offers",
            "NetSupport RAT and BurnsRAT",
            "Cybercriminals Leverage Fake CAPTCHAs for Malware Delivery",
            "MUT-1244-GitHub",
            "Phobos ransomware",
            "Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data",
            "PUMAKIT",
            "OtterCookie used by Contagious Interview",
            "Ransomware-Lockbit3-IOCs.csv"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mekotio Banking",
              "display_name": "Mekotio Banking",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "MSI",
              "display_name": "MSI",
              "target": null
            },
            {
              "id": "InvisibleFerret",
              "display_name": "InvisibleFerret",
              "target": null
            },
            {
              "id": "Vant",
              "display_name": "Vant",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 84,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Badderawy",
            "id": "310597",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 950,
            "FileHash-SHA1": 847,
            "FileHash-SHA256": 1060,
            "hostname": 1158,
            "domain": 867,
            "URL": 813,
            "email": 77,
            "CIDR": 2,
            "CVE": 9
          },
          "indicator_count": 5783,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 27,
          "modified_text": "427 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6757e0235277e8122c8d1bb6",
          "name": "Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
          "description": "",
          "modified": "2024-12-22T04:02:40.049000",
          "created": "2024-12-10T06:30:59.144000",
          "tags": [
            "linux",
            "wolfsbane",
            "rootkit",
            "apt",
            "backdoor",
            "persistence",
            "gelsevirine",
            "cyberespionage",
            "project wood",
            "firewood"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
          ],
          "public": 1,
          "adversary": "Gelsemium",
          "targeted_countries": [
            "Philippines",
            "Singapore",
            "Taiwan"
          ],
          "malware_families": [
            {
              "id": "WolfsBane",
              "display_name": "WolfsBane",
              "target": null
            },
            {
              "id": "FireWood",
              "display_name": "FireWood",
              "target": null
            },
            {
              "id": "Gelsemium - S0666",
              "display_name": "Gelsemium - S0666",
              "target": null
            },
            {
              "id": "Gelsevirine",
              "display_name": "Gelsevirine",
              "target": null
            },
            {
              "id": "Gelsenicine",
              "display_name": "Gelsenicine",
              "target": null
            },
            {
              "id": "Gelsemine",
              "display_name": "Gelsemine",
              "target": null
            },
            {
              "id": "Project Wood",
              "display_name": "Project Wood",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Government",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "67400d74e667ab8c476122e8",
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 27,
            "FileHash-SHA1": 70,
            "FileHash-SHA256": 27,
            "domain": 3,
            "hostname": 10
          },
          "indicator_count": 137,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "524 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6757e046f5ca1c9c37d701ed",
          "name": "Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
          "description": "",
          "modified": "2024-12-22T04:02:40.049000",
          "created": "2024-12-10T06:31:34.364000",
          "tags": [
            "linux",
            "wolfsbane",
            "rootkit",
            "apt",
            "backdoor",
            "persistence",
            "gelsevirine",
            "cyberespionage",
            "project wood",
            "firewood"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
          ],
          "public": 1,
          "adversary": "Gelsemium",
          "targeted_countries": [
            "Philippines",
            "Singapore",
            "Taiwan"
          ],
          "malware_families": [
            {
              "id": "WolfsBane",
              "display_name": "WolfsBane",
              "target": null
            },
            {
              "id": "FireWood",
              "display_name": "FireWood",
              "target": null
            },
            {
              "id": "Gelsemium - S0666",
              "display_name": "Gelsemium - S0666",
              "target": null
            },
            {
              "id": "Gelsevirine",
              "display_name": "Gelsevirine",
              "target": null
            },
            {
              "id": "Gelsenicine",
              "display_name": "Gelsenicine",
              "target": null
            },
            {
              "id": "Gelsemine",
              "display_name": "Gelsemine",
              "target": null
            },
            {
              "id": "Project Wood",
              "display_name": "Project Wood",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Government",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "6757e0235277e8122c8d1bb6",
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 27,
            "FileHash-SHA1": 70,
            "FileHash-SHA256": 27,
            "domain": 3,
            "hostname": 10
          },
          "indicator_count": 137,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "524 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6761584faa26234f0381eb4d",
          "name": " Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
          "description": "",
          "modified": "2024-12-22T04:02:40.049000",
          "created": "2024-12-17T10:54:07.508000",
          "tags": [
            "linux",
            "wolfsbane",
            "rootkit",
            "apt",
            "backdoor",
            "persistence",
            "gelsevirine",
            "cyberespionage",
            "project wood",
            "firewood"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
          ],
          "public": 1,
          "adversary": "Gelsemium",
          "targeted_countries": [
            "Philippines",
            "Singapore",
            "Taiwan"
          ],
          "malware_families": [
            {
              "id": "WolfsBane",
              "display_name": "WolfsBane",
              "target": null
            },
            {
              "id": "FireWood",
              "display_name": "FireWood",
              "target": null
            },
            {
              "id": "Gelsemium - S0666",
              "display_name": "Gelsemium - S0666",
              "target": null
            },
            {
              "id": "Gelsevirine",
              "display_name": "Gelsevirine",
              "target": null
            },
            {
              "id": "Gelsenicine",
              "display_name": "Gelsenicine",
              "target": null
            },
            {
              "id": "Gelsemine",
              "display_name": "Gelsemine",
              "target": null
            },
            {
              "id": "Project Wood",
              "display_name": "Project Wood",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Government",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "6757e046f5ca1c9c37d701ed",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 27,
            "FileHash-SHA1": 70,
            "FileHash-SHA256": 27,
            "domain": 3,
            "hostname": 10
          },
          "indicator_count": 137,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "524 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "675076d8ddd32f8b486ee6bf",
          "name": "Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
          "description": "ESET Research has identified two new backdoors linked to China-aligned advanced persistent threat (APT) group Gelsemium, and found other tools potentially related to the group, which has a history of targeting sensitive data.",
          "modified": "2024-12-04T15:35:52.370000",
          "created": "2024-12-04T15:35:52.370000",
          "tags": [
            "strong",
            "wolfsbane",
            "gelsemium",
            "firewood",
            "figure",
            "linux",
            "c server",
            "project wood",
            "eset research",
            "gelsevirine",
            "virustotal",
            "execution",
            "persistence",
            "tips",
            "win32",
            "service",
            "install",
            "comment",
            "download",
            "path",
            "first",
            "podcast",
            "java",
            "windows"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
          ],
          "public": 1,
          "adversary": "Project Wood",
          "targeted_countries": [
            "Taiwan",
            "Philippines",
            "Singapore"
          ],
          "malware_families": [
            {
              "id": "Gelsevirine",
              "display_name": "Gelsevirine",
              "target": null
            },
            {
              "id": "Project Wood",
              "display_name": "Project Wood",
              "target": null
            },
            {
              "id": "Java",
              "display_name": "Java",
              "target": null
            },
            {
              "id": "Windows",
              "display_name": "Windows",
              "target": null
            },
            {
              "id": "Gelsemium",
              "display_name": "Gelsemium",
              "target": null
            },
            {
              "id": "Linux",
              "display_name": "Linux",
              "target": null
            },
            {
              "id": "FireWood",
              "display_name": "FireWood",
              "target": null
            },
            {
              "id": "WolfsBane",
              "display_name": "WolfsBane",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1037",
              "name": "Boot or Logon Initialization Scripts",
              "display_name": "T1037 - Boot or Logon Initialization Scripts"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 6,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "542 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6740553d6835cae0252e955c",
          "name": "Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
          "description": "ESET Research has identified two new backdoors linked to China-aligned advanced persistent threat (APT) group Gelsemium, and found other tools potentially related to the group, which has a history of targeting sensitive data.",
          "modified": "2024-11-22T09:56:13.290000",
          "created": "2024-11-22T09:56:13.290000",
          "tags": [
            "strong",
            "wolfsbane",
            "gelsemium",
            "firewood",
            "figure",
            "linux",
            "c server",
            "project wood",
            "eset research",
            "gelsevirine",
            "virustotal",
            "execution",
            "persistence",
            "tips",
            "win32",
            "service",
            "install",
            "comment",
            "download",
            "path",
            "first",
            "life",
            "nspx30",
            "java",
            "windows"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/#Technical%20analysis"
          ],
          "public": 1,
          "adversary": "Project Wood",
          "targeted_countries": [
            "Taiwan",
            "Philippines",
            "Singapore"
          ],
          "malware_families": [
            {
              "id": "Gelsevirine",
              "display_name": "Gelsevirine",
              "target": null
            },
            {
              "id": "Project Wood",
              "display_name": "Project Wood",
              "target": null
            },
            {
              "id": "Java",
              "display_name": "Java",
              "target": null
            },
            {
              "id": "Windows",
              "display_name": "Windows",
              "target": null
            },
            {
              "id": "Gelsemium",
              "display_name": "Gelsemium",
              "target": null
            },
            {
              "id": "Linux",
              "display_name": "Linux",
              "target": null
            },
            {
              "id": "FireWood",
              "display_name": "FireWood",
              "target": null
            },
            {
              "id": "WolfsBane",
              "display_name": "WolfsBane",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1037",
              "name": "Boot or Logon Initialization Scripts",
              "display_name": "T1037 - Boot or Logon Initialization Scripts"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "domain": 6,
            "hostname": 1
          },
          "indicator_count": 10,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "554 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b5461ad2cb2f9e8d342d",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:06.188000",
          "created": "2024-02-06T22:40:06.188000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "843 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b543bc2adfd3eca5ff2b",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:03.501000",
          "created": "2024-02-06T22:40:03.501000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "843 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b5405e6e9e23324e6d8e",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:00.906000",
          "created": "2024-02-06T22:40:00.906000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "843 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "ELDORADO RANSOMWARE",
        "From Stealers to Ransomware PureCrypter Delivers It All",
        "The Growing Risk of Sneaky 2FA for Microsoft and Gmail Accounts",
        "New Star Blizzard spear-phishing campaign targets WhatsApp accounts",
        "Demodex rootkit",
        "MALLOX RANSOMWARE",
        "The great Google Ads heist_ criminals ransack advertiser accounts via fake Google ads",
        "SpyGlace",
        "babbleloader",
        "Stealers on the Rise",
        "CloudScout_ Evasive Panda scouting cloud services",
        "LegionLoader Malware Expands Global Reach",
        "MintsLoader_Stealc",
        "Akira Ransomware",
        "UAC-0194\u2019s Exploitation of CVE-2024-43451 in Ukraine for Phishing",
        "Evasive Panda Uses MACMA and MgBot Malware to Target US and Taiwan",
        "solana-backdoor",
        "PUMAKIT",
        "MEKOTIO BANKING TROJAN",
        "Remcos RAT",
        "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/#Technical%20analysis",
        "Sliver Implant Targets German Entities with DLL Sideloading and Proxying Techniques",
        "Microsoft Advertisers Phished via Malicious Google Ads",
        "Python NodeStealer",
        "Glove-Stealer",
        "Fake CAPTCHA Campaign That Spreads LUMMA Info Stealer",
        "Gh0stGambit",
        "GamaCopy APT Group Mimicking GamaRedon",
        "AsyncRAT Reloaded",
        "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/",
        "HawkEye Malware",
        "WezRat Malware",
        "clickfix-tactic",
        "Weaponized Software Targeting Chinese Organizations",
        "Ransomware-Lockbit3-IOCs.csv",
        "SmokeLoader",
        "Phishing Campaigns Fuel Compiled AutoIt Malware Distribution",
        "Developers Targeted by New \u2018OtterCookie\u2019 Malware with Fake Job Offers",
        "Suspicious Domains Exploiting the Recent CrowdStrike Outage!",
        "play ransomware",
        "Bitter APT",
        "Salt Typhoon  Target U.S. Telecom Networks",
        "Rspack_Compromised_Packages",
        "Unveiling Silent Lynx APT Targeting Entities Across Kyrgyzstan & Neighbouring Nations",
        "HotPage.exe (malware)",
        "Threat Surge as Lumma Stealer Expands Its Reach",
        "Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain",
        "North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks",
        "Fake Discount Sites Exploit Black Friday",
        "Winos4.0 RAT",
        "FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux",
        "Bootkitty",
        "OtterCookie used by Contagious Interview",
        "Shadowroot Ransomware",
        "DarkGate",
        "NetSupport RAT and BurnsRAT",
        "New Malware Campaign Abusing RDPWrapper and Tailscale to Target Cryptocurrency Users",
        "InvisibleFerret Malware Leveraging Python for Targeted Attacks",
        "Hundreds of fake Reddit sites push Lumma Stealer malware",
        "romcom-exploits-firefox-and-windows",
        "REF5961 Group Deploys EAGERBEE Backdoor Against Critical Sectors",
        "U.S. Organization in China Targeted by Attackers",
        "FERRET Malware Targets macOS in Sophisticated North Korean Attacks",
        "WolfsBane Backdoor",
        "BugSleep Malware",
        "RansomHub Affiliate leverages Python-based backdoor",
        "Sock5Systemz-PROXY-AM",
        "Visual Studio Code Remote tunnels",
        "BellaCpp",
        "Rockstar-Phishing",
        "NEW.txt",
        "Snake Keylogger",
        "MirrorFace Campain",
        "Rat Race_ ValleyRAT Malware Targets Organizations with New Delivery Techniques",
        "Avast-Anti-Root-KIt",
        "Helldown Ransomware",
        "RustyStealer and New Ymir Ransomware",
        "Bumblebee Malware",
        "Fake game sites lead to information stealers",
        "SystemBC RAT Poses New Risks to Linux System",
        "The Return of PlugX Malware with Fresh Tricks",
        "BrazenBamboo",
        "UAC-0185 attacks warned by CERT-UA",
        "Espionage Campaign Targeting South Asian Entities",
        "SecTopRAT",
        "ACR Stealer",
        "Chrome Extensions Hijacked, 2.6 Million Users Impacted",
        "Qilin Ransomware",
        "NOOPDOOR Malware",
        "The New Ransomware Menace Vgod Gains Momentum",
        "The BadPilot campaign_ Seashell Blizzard subgroup conducts multiyear global access operation",
        "New Phishing Campaign Abuses Webflow, SEO, and Fake CAPTCHAs",
        "APT-K-47",
        "macOS Users Targeted by the New Variant of Banshee Infostealer",
        "TAG-100",
        "Astral Stealer Strikes Again Stealing More Than Just Your Cookies",
        "FatalRAT",
        "PyPI-AIOCPA",
        "Cybercriminals Leverage Fake CAPTCHAs for Malware Delivery",
        "Advanced Evasion Techniques Used by NonEuclid RAT",
        "APT36",
        "bootkitty(logofail)",
        "Phobos ransomware",
        "Christmas-Themed LNK Files Used for Malware Delivery",
        "Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data",
        "horns-hooves",
        "SteelFox Trojan",
        "Cloud Atlas seen using a new tool in its attacks",
        "Silent Skimmer Gets Loud (Again)",
        "Iranian Hackers Use GitHub and Phishing to Evade Detection in SnailResin Attack",
        "PXA Stealer",
        "MUT-1244-GitHub",
        "North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware",
        "LockBit Ransomware Attack Leveraging Cobalt Strike"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "Gelsemium"
          ],
          "malware_families": [
            "Gelsevirine",
            "Wolfsbane",
            "Project wood",
            "Firewood",
            "Gelsemium - s0666",
            "Gelsemine",
            "Gelsenicine"
          ],
          "industries": [
            "Technology",
            "Government"
          ]
        },
        "other": {
          "adversary": [
            "Project Wood",
            "Gelsemium"
          ],
          "malware_families": [
            "Windows",
            "Trojanspy",
            "Gelsevirine",
            "Java",
            "Invisibleferret",
            "Wolfsbane",
            "Vant",
            "Firewood",
            "Project wood",
            "Linux",
            "Gelsemium - s0666",
            "Msi",
            "Gelsemine",
            "Mekotio banking",
            "Gelsenicine",
            "Gelsemium"
          ],
          "industries": [
            "Technology",
            "Government"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "67400d74e667ab8c476122e8",
      "name": "Unveiling WolfsBane: Linux counterpart to Gelsevirine",
      "description": "ESET researchers have discovered previously unknown Linux backdoors attributed to the China-aligned Gelsemium APT group. The main backdoor, named WolfsBane, is the Linux equivalent of Gelsemium's Gelsevirine backdoor for Windows. Another backdoor, FireWood, is connected to the group's Project Wood malware. These tools are designed for cyberespionage, targeting system information, credentials, and specific files. The malware uses sophisticated techniques for persistence, stealth, and command execution. This discovery marks Gelsemium's first known use of Linux malware, indicating a shift in APT tactics towards exploiting vulnerabilities in internet-facing Linux systems.",
      "modified": "2024-12-22T04:02:40.049000",
      "created": "2024-11-22T04:49:56.508000",
      "tags": [
        "linux",
        "wolfsbane",
        "rootkit",
        "apt",
        "backdoor",
        "persistence",
        "gelsevirine",
        "cyberespionage",
        "project wood",
        "firewood"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
      ],
      "public": 1,
      "adversary": "Gelsemium",
      "targeted_countries": [
        "Philippines",
        "Singapore",
        "Taiwan"
      ],
      "malware_families": [
        {
          "id": "WolfsBane",
          "display_name": "WolfsBane",
          "target": null
        },
        {
          "id": "FireWood",
          "display_name": "FireWood",
          "target": null
        },
        {
          "id": "Gelsemium - S0666",
          "display_name": "Gelsemium - S0666",
          "target": null
        },
        {
          "id": "Gelsevirine",
          "display_name": "Gelsevirine",
          "target": null
        },
        {
          "id": "Gelsenicine",
          "display_name": "Gelsenicine",
          "target": null
        },
        {
          "id": "Gelsemine",
          "display_name": "Gelsemine",
          "target": null
        },
        {
          "id": "Project Wood",
          "display_name": "Project Wood",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Government",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 74,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 27,
        "FileHash-SHA1": 70,
        "FileHash-SHA256": 27,
        "domain": 3,
        "hostname": 10
      },
      "indicator_count": 137,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386457,
      "modified_text": "524 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5fa1ee5c64dc0e2060647954",
      "name": "Malware - Malware Domain Feed V2 - November 03 2020",
      "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
      "modified": "2026-05-28T12:10:48.255000",
      "created": "2020-11-03T23:57:16.317000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 130371,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "otxrobottwo_testing",
        "id": "83138",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45551,
        "domain": 66442
      },
      "indicator_count": 111993,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 970,
      "modified_text": "2 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67c0cdc35112c5919563a334",
      "name": "Intel is bad awy",
      "description": "",
      "modified": "2025-03-29T20:01:20.482000",
      "created": "2025-02-27T20:40:35.539000",
      "tags": [
        "sign",
        "github",
        "find",
        "view",
        "search",
        "strong",
        "code issues",
        "pull",
        "breadcrumbs",
        "damn",
        "star",
        "footer",
        "sha1",
        "helldown linux",
        "iocs helldown",
        "windows payload",
        "icon",
        "darkrace",
        "donex",
        "ransom",
        "defanged file",
        "hashes",
        "ipv4",
        "sha256",
        "c2 ip",
        "address",
        "plugin",
        "brazanbamboo c2",
        "panel",
        "archive file",
        "bha006",
        "telegram bot",
        "token",
        "chat id",
        "sha256 hashes",
        "iocs",
        "intermediary",
        "landing",
        "aitm server",
        "compromise note",
        "hashes payload",
        "loader",
        "dropper",
        "ips https",
        "urls https",
        "duoyi",
        "ioc url",
        "ipv4 address",
        "c2 server",
        "sample sha256",
        "remcos",
        "decrypted",
        "urls http",
        "payload",
        "amos stealer",
        "stealc c2",
        "rhadamanthys c2",
        "phishing urls",
        "google meet",
        "amos steaker",
        "html payload",
        "stealc payload",
        "md5 hashes",
        "sha1 hashes",
        "iocs zip",
        "lnk file",
        "msi file",
        "payload url",
        "eldorado",
        "linux",
        "service dll",
        "cheat engine",
        "c2 domain",
        "compromise",
        "urls",
        "iocs files",
        "network ip",
        "domain",
        "malware hash",
        "noopldr type1",
        "noopldr type2",
        "download url",
        "email addresses",
        "block",
        "ioc http",
        "iocs hash",
        "url https",
        "ghostgambit",
        "hidden rootkit",
        "gh0strat",
        "mekotio banking",
        "financial",
        "latin america",
        "detected",
        "zipmsi",
        "downloader",
        "ip address",
        "cobalt strike",
        "first seen",
        "seen",
        "pantegana",
        "tls certificate",
        "fingerprint",
        "samples",
        "trojanspy",
        "msi",
        "subdomains",
        "reddit",
        "wetransfer",
        "ioc hash",
        "file hashes",
        "ip addresses",
        "fake captcha",
        "html",
        "hta script",
        "lumma payload",
        "filehashsha256",
        "indicator type",
        "sha256 lnk",
        "ports",
        "first stage",
        "md5 file",
        "domains",
        "reddelta c2",
        "servers",
        "octoberdecember",
        "shortcut",
        "files",
        "solo airfield",
        "quoc",
        "bctt",
        "kongtuke",
        "mintsloader c2",
        "js download",
        "c2 http",
        "boinc c2",
        "c2 address",
        "analyzed",
        "file name",
        "na stark",
        "na majestic",
        "description",
        "trojanized",
        "beavertail",
        "anydesk module",
        "domain hosting",
        "first",
        "details",
        "monitor",
        "sites",
        "fake chrome",
        "payload host",
        "c2 https",
        "examples",
        "atomic stealer",
        "c2 servers",
        "cthulhu stealer",
        "server http",
        "l files",
        "original",
        "iocs malicious",
        "mirrowsimps",
        "defanged",
        "strike loaders",
        "plugx",
        "plugx c2",
        "sspiuacbypass",
        "malware",
        "malware c2",
        "filehashmd5",
        "site",
        "orgvgodpayment",
        "quite solsjoas",
        "ioc sha256",
        "similar sha256",
        "http",
        "url hundreds",
        "url samples",
        "filehash",
        "guidloader",
        "finaldraft elf",
        "type name",
        "reference",
        "finaldraft",
        "sha256 pfman",
        "pathloader",
        "atomic https",
        "systembc",
        "ghostsocks",
        "invisibleferret",
        "vant",
        "rspackcore",
        "monero",
        "sha256 hash",
        "code snippets",
        "psexec",
        "ituneshelper",
        "pscp",
        "sftp",
        "googleupdate",
        "meshagent",
        "ultravnc",
        "file",
        "bootkitty iocs",
        "phpsert",
        "phpsert variant",
        "createdump tool",
        "visual studio",
        "code",
        "server",
        "sql injection",
        "studio code",
        "ssh access",
        "hta file",
        "vbshower c2",
        "powershower c2",
        "cloud",
        "hta md5",
        "domain name",
        "links",
        "c http",
        "horns",
        "version",
        "version b",
        "version c",
        "version d",
        "version e",
        "burnsrat c",
        "a http",
        "github users",
        "shell commands",
        "vssadmin delete",
        "userprofile",
        "public",
        "registry keys",
        "phobos",
        "lettointago",
        "carljohnson1948",
        "samuelwhite1821",
        "file hash",
        "lockbit",
        "indicatortype",
        "data",
        "mlpea",
        "w32neshtad",
        "gmer",
        "neshta",
        "opswat oesis",
        "v4 removal"
      ],
      "references": [
        "Bootkitty",
        "Glove-Stealer",
        "Fake Discount Sites Exploit Black Friday",
        "Helldown Ransomware",
        "HawkEye Malware",
        "PXA Stealer",
        "Iranian Hackers Use GitHub and Phishing to Evade Detection in SnailResin Attack",
        "BrazenBamboo",
        "SpyGlace",
        "RustyStealer and New Ymir Ransomware",
        "PyPI-AIOCPA",
        "Python NodeStealer",
        "romcom-exploits-firefox-and-windows",
        "Rockstar-Phishing",
        "Silent Skimmer Gets Loud (Again)",
        "SteelFox Trojan",
        "WezRat Malware",
        "Avast-Anti-Root-KIt",
        "Winos4.0 RAT",
        "APT36",
        "WolfsBane Backdoor",
        "APT-K-47",
        "Remcos RAT",
        "babbleloader",
        "Bitter APT",
        "UAC-0194\u2019s Exploitation of CVE-2024-43451 in Ukraine for Phishing",
        "CloudScout_ Evasive Panda scouting cloud services",
        "clickfix-tactic",
        "Akira Ransomware",
        "Bumblebee Malware",
        "ELDORADO RANSOMWARE",
        "Evasive Panda Uses MACMA and MgBot Malware to Target US and Taiwan",
        "Demodex rootkit",
        "BugSleep Malware",
        "HotPage.exe (malware)",
        "Qilin Ransomware",
        "NOOPDOOR Malware",
        "Shadowroot Ransomware",
        "play ransomware",
        "MALLOX RANSOMWARE",
        "New Malware Campaign Abusing RDPWrapper and Tailscale to Target Cryptocurrency Users",
        "ACR Stealer",
        "Suspicious Domains Exploiting the Recent CrowdStrike Outage!",
        "Gh0stGambit",
        "MEKOTIO BANKING TROJAN",
        "TAG-100",
        "Fake game sites lead to information stealers",
        "Chrome Extensions Hijacked, 2.6 Million Users Impacted",
        "macOS Users Targeted by the New Variant of Banshee Infostealer",
        "Hundreds of fake Reddit sites push Lumma Stealer malware",
        "GamaCopy APT Group Mimicking GamaRedon",
        "InvisibleFerret Malware Leveraging Python for Targeted Attacks",
        "Fake CAPTCHA Campaign That Spreads LUMMA Info Stealer",
        "REF5961 Group Deploys EAGERBEE Backdoor Against Critical Sectors",
        "Phishing Campaigns Fuel Compiled AutoIt Malware Distribution",
        "The great Google Ads heist_ criminals ransack advertiser accounts via fake Google ads",
        "New Star Blizzard spear-phishing campaign targets WhatsApp accounts",
        "RansomHub Affiliate leverages Python-based backdoor",
        "Sliver Implant Targets German Entities with DLL Sideloading and Proxying Techniques",
        "Advanced Evasion Techniques Used by NonEuclid RAT",
        "The Return of PlugX Malware with Fresh Tricks",
        "The Growing Risk of Sneaky 2FA for Microsoft and Gmail Accounts",
        "Weaponized Software Targeting Chinese Organizations",
        "Threat Surge as Lumma Stealer Expands Its Reach",
        "Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain",
        "MintsLoader_Stealc",
        "North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks",
        "North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware",
        "Rat Race_ ValleyRAT Malware Targets Organizations with New Delivery Techniques",
        "Salt Typhoon  Target U.S. Telecom Networks",
        "SecTopRAT",
        "Stealers on the Rise",
        "Snake Keylogger",
        "AsyncRAT Reloaded",
        "The BadPilot campaign_ Seashell Blizzard subgroup conducts multiyear global access operation",
        "FatalRAT",
        "SystemBC RAT Poses New Risks to Linux System",
        "Unveiling Silent Lynx APT Targeting Entities Across Kyrgyzstan & Neighbouring Nations",
        "FERRET Malware Targets macOS in Sophisticated North Korean Attacks",
        "Espionage Campaign Targeting South Asian Entities",
        "Astral Stealer Strikes Again Stealing More Than Just Your Cookies",
        "The New Ransomware Menace Vgod Gains Momentum",
        "Microsoft Advertisers Phished via Malicious Google Ads",
        "LegionLoader Malware Expands Global Reach",
        "NEW.txt",
        "From Stealers to Ransomware PureCrypter Delivers It All",
        "New Phishing Campaign Abuses Webflow, SEO, and Fake CAPTCHAs",
        "FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux",
        "LockBit Ransomware Attack Leveraging Cobalt Strike",
        "Rspack_Compromised_Packages",
        "SmokeLoader",
        "Sock5Systemz-PROXY-AM",
        "solana-backdoor",
        "U.S. Organization in China Targeted by Attackers",
        "UAC-0185 attacks warned by CERT-UA",
        "BellaCpp",
        "bootkitty(logofail)",
        "Visual Studio Code Remote tunnels",
        "Cloud Atlas seen using a new tool in its attacks",
        "Christmas-Themed LNK Files Used for Malware Delivery",
        "DarkGate",
        "MirrorFace Campain",
        "horns-hooves",
        "Developers Targeted by New \u2018OtterCookie\u2019 Malware with Fake Job Offers",
        "NetSupport RAT and BurnsRAT",
        "Cybercriminals Leverage Fake CAPTCHAs for Malware Delivery",
        "MUT-1244-GitHub",
        "Phobos ransomware",
        "Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data",
        "PUMAKIT",
        "OtterCookie used by Contagious Interview",
        "Ransomware-Lockbit3-IOCs.csv"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mekotio Banking",
          "display_name": "Mekotio Banking",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "MSI",
          "display_name": "MSI",
          "target": null
        },
        {
          "id": "InvisibleFerret",
          "display_name": "InvisibleFerret",
          "target": null
        },
        {
          "id": "Vant",
          "display_name": "Vant",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 84,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Badderawy",
        "id": "310597",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 950,
        "FileHash-SHA1": 847,
        "FileHash-SHA256": 1060,
        "hostname": 1158,
        "domain": 867,
        "URL": 813,
        "email": 77,
        "CIDR": 2,
        "CVE": 9
      },
      "indicator_count": 5783,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 27,
      "modified_text": "427 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6757e0235277e8122c8d1bb6",
      "name": "Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
      "description": "",
      "modified": "2024-12-22T04:02:40.049000",
      "created": "2024-12-10T06:30:59.144000",
      "tags": [
        "linux",
        "wolfsbane",
        "rootkit",
        "apt",
        "backdoor",
        "persistence",
        "gelsevirine",
        "cyberespionage",
        "project wood",
        "firewood"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
      ],
      "public": 1,
      "adversary": "Gelsemium",
      "targeted_countries": [
        "Philippines",
        "Singapore",
        "Taiwan"
      ],
      "malware_families": [
        {
          "id": "WolfsBane",
          "display_name": "WolfsBane",
          "target": null
        },
        {
          "id": "FireWood",
          "display_name": "FireWood",
          "target": null
        },
        {
          "id": "Gelsemium - S0666",
          "display_name": "Gelsemium - S0666",
          "target": null
        },
        {
          "id": "Gelsevirine",
          "display_name": "Gelsevirine",
          "target": null
        },
        {
          "id": "Gelsenicine",
          "display_name": "Gelsenicine",
          "target": null
        },
        {
          "id": "Gelsemine",
          "display_name": "Gelsemine",
          "target": null
        },
        {
          "id": "Project Wood",
          "display_name": "Project Wood",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Government",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": "67400d74e667ab8c476122e8",
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 27,
        "FileHash-SHA1": 70,
        "FileHash-SHA256": 27,
        "domain": 3,
        "hostname": 10
      },
      "indicator_count": 137,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 277,
      "modified_text": "524 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6757e046f5ca1c9c37d701ed",
      "name": "Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
      "description": "",
      "modified": "2024-12-22T04:02:40.049000",
      "created": "2024-12-10T06:31:34.364000",
      "tags": [
        "linux",
        "wolfsbane",
        "rootkit",
        "apt",
        "backdoor",
        "persistence",
        "gelsevirine",
        "cyberespionage",
        "project wood",
        "firewood"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
      ],
      "public": 1,
      "adversary": "Gelsemium",
      "targeted_countries": [
        "Philippines",
        "Singapore",
        "Taiwan"
      ],
      "malware_families": [
        {
          "id": "WolfsBane",
          "display_name": "WolfsBane",
          "target": null
        },
        {
          "id": "FireWood",
          "display_name": "FireWood",
          "target": null
        },
        {
          "id": "Gelsemium - S0666",
          "display_name": "Gelsemium - S0666",
          "target": null
        },
        {
          "id": "Gelsevirine",
          "display_name": "Gelsevirine",
          "target": null
        },
        {
          "id": "Gelsenicine",
          "display_name": "Gelsenicine",
          "target": null
        },
        {
          "id": "Gelsemine",
          "display_name": "Gelsemine",
          "target": null
        },
        {
          "id": "Project Wood",
          "display_name": "Project Wood",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Government",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": "6757e0235277e8122c8d1bb6",
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 27,
        "FileHash-SHA1": 70,
        "FileHash-SHA256": 27,
        "domain": 3,
        "hostname": 10
      },
      "indicator_count": 137,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 277,
      "modified_text": "524 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6761584faa26234f0381eb4d",
      "name": " Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
      "description": "",
      "modified": "2024-12-22T04:02:40.049000",
      "created": "2024-12-17T10:54:07.508000",
      "tags": [
        "linux",
        "wolfsbane",
        "rootkit",
        "apt",
        "backdoor",
        "persistence",
        "gelsevirine",
        "cyberespionage",
        "project wood",
        "firewood"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
      ],
      "public": 1,
      "adversary": "Gelsemium",
      "targeted_countries": [
        "Philippines",
        "Singapore",
        "Taiwan"
      ],
      "malware_families": [
        {
          "id": "WolfsBane",
          "display_name": "WolfsBane",
          "target": null
        },
        {
          "id": "FireWood",
          "display_name": "FireWood",
          "target": null
        },
        {
          "id": "Gelsemium - S0666",
          "display_name": "Gelsemium - S0666",
          "target": null
        },
        {
          "id": "Gelsevirine",
          "display_name": "Gelsevirine",
          "target": null
        },
        {
          "id": "Gelsenicine",
          "display_name": "Gelsenicine",
          "target": null
        },
        {
          "id": "Gelsemine",
          "display_name": "Gelsemine",
          "target": null
        },
        {
          "id": "Project Wood",
          "display_name": "Project Wood",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Government",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": "6757e046f5ca1c9c37d701ed",
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 27,
        "FileHash-SHA1": 70,
        "FileHash-SHA256": 27,
        "domain": 3,
        "hostname": 10
      },
      "indicator_count": 137,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 277,
      "modified_text": "524 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "675076d8ddd32f8b486ee6bf",
      "name": "Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
      "description": "ESET Research has identified two new backdoors linked to China-aligned advanced persistent threat (APT) group Gelsemium, and found other tools potentially related to the group, which has a history of targeting sensitive data.",
      "modified": "2024-12-04T15:35:52.370000",
      "created": "2024-12-04T15:35:52.370000",
      "tags": [
        "strong",
        "wolfsbane",
        "gelsemium",
        "firewood",
        "figure",
        "linux",
        "c server",
        "project wood",
        "eset research",
        "gelsevirine",
        "virustotal",
        "execution",
        "persistence",
        "tips",
        "win32",
        "service",
        "install",
        "comment",
        "download",
        "path",
        "first",
        "podcast",
        "java",
        "windows"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/"
      ],
      "public": 1,
      "adversary": "Project Wood",
      "targeted_countries": [
        "Taiwan",
        "Philippines",
        "Singapore"
      ],
      "malware_families": [
        {
          "id": "Gelsevirine",
          "display_name": "Gelsevirine",
          "target": null
        },
        {
          "id": "Project Wood",
          "display_name": "Project Wood",
          "target": null
        },
        {
          "id": "Java",
          "display_name": "Java",
          "target": null
        },
        {
          "id": "Windows",
          "display_name": "Windows",
          "target": null
        },
        {
          "id": "Gelsemium",
          "display_name": "Gelsemium",
          "target": null
        },
        {
          "id": "Linux",
          "display_name": "Linux",
          "target": null
        },
        {
          "id": "FireWood",
          "display_name": "FireWood",
          "target": null
        },
        {
          "id": "WolfsBane",
          "display_name": "WolfsBane",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1037",
          "name": "Boot or Logon Initialization Scripts",
          "display_name": "T1037 - Boot or Logon Initialization Scripts"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1587",
          "name": "Develop Capabilities",
          "display_name": "T1587 - Develop Capabilities"
        },
        {
          "id": "T1505",
          "name": "Server Software Component",
          "display_name": "T1505 - Server Software Component"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "domain": 2,
        "hostname": 1
      },
      "indicator_count": 6,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "542 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6740553d6835cae0252e955c",
      "name": "Unveiling WolfsBane: Gelsemium\u2019s Linux counterpart to Gelsevirine",
      "description": "ESET Research has identified two new backdoors linked to China-aligned advanced persistent threat (APT) group Gelsemium, and found other tools potentially related to the group, which has a history of targeting sensitive data.",
      "modified": "2024-11-22T09:56:13.290000",
      "created": "2024-11-22T09:56:13.290000",
      "tags": [
        "strong",
        "wolfsbane",
        "gelsemium",
        "firewood",
        "figure",
        "linux",
        "c server",
        "project wood",
        "eset research",
        "gelsevirine",
        "virustotal",
        "execution",
        "persistence",
        "tips",
        "win32",
        "service",
        "install",
        "comment",
        "download",
        "path",
        "first",
        "life",
        "nspx30",
        "java",
        "windows"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/unveiling-wolfsbane-gelsemiums-linux-counterpart-to-gelsevirine/#Technical%20analysis"
      ],
      "public": 1,
      "adversary": "Project Wood",
      "targeted_countries": [
        "Taiwan",
        "Philippines",
        "Singapore"
      ],
      "malware_families": [
        {
          "id": "Gelsevirine",
          "display_name": "Gelsevirine",
          "target": null
        },
        {
          "id": "Project Wood",
          "display_name": "Project Wood",
          "target": null
        },
        {
          "id": "Java",
          "display_name": "Java",
          "target": null
        },
        {
          "id": "Windows",
          "display_name": "Windows",
          "target": null
        },
        {
          "id": "Gelsemium",
          "display_name": "Gelsemium",
          "target": null
        },
        {
          "id": "Linux",
          "display_name": "Linux",
          "target": null
        },
        {
          "id": "FireWood",
          "display_name": "FireWood",
          "target": null
        },
        {
          "id": "WolfsBane",
          "display_name": "WolfsBane",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1037",
          "name": "Boot or Logon Initialization Scripts",
          "display_name": "T1037 - Boot or Logon Initialization Scripts"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1587",
          "name": "Develop Capabilities",
          "display_name": "T1587 - Develop Capabilities"
        },
        {
          "id": "T1505",
          "name": "Server Software Component",
          "display_name": "T1505 - Server Software Component"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 1,
        "domain": 6,
        "hostname": 1
      },
      "indicator_count": 10,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "554 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c2b5461ad2cb2f9e8d342d",
      "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
      "description": "",
      "modified": "2024-02-06T22:40:06.188000",
      "created": "2024-02-06T22:40:06.188000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "5fa1ee5c64dc0e2060647954",
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45530,
        "domain": 66406
      },
      "indicator_count": 111936,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "843 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c2b543bc2adfd3eca5ff2b",
      "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
      "description": "",
      "modified": "2024-02-06T22:40:03.501000",
      "created": "2024-02-06T22:40:03.501000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "5fa1ee5c64dc0e2060647954",
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45530,
        "domain": 66406
      },
      "indicator_count": 111936,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "843 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "dsdsei.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "dsdsei.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780177572.9787927
}