{
  "type": "Domain",
  "indicator": "el3ctrn.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/el3ctrn.com",
    "alexa": "http://www.alexa.com/siteinfo/el3ctrn.com",
    "indicator": "el3ctrn.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3691636859,
      "indicator": "el3ctrn.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "65709c176bf14908e11e80d8",
          "name": "TechM-Threat Intel Report - W23-2023",
          "description": "",
          "modified": "2023-12-06T16:06:47.815000",
          "created": "2023-12-06T16:06:47.815000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 130,
            "FileHash-MD5": 46,
            "FileHash-SHA1": 46,
            "domain": 125,
            "hostname": 42,
            "URL": 123,
            "CVE": 1
          },
          "indicator_count": 513,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "647da78794bf55c527ee8400",
          "name": "TechM-Threat Intel Report - W23-2023",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2023-07-05T08:04:41.483000",
          "created": "2023-06-05T09:14:47.526000",
          "tags": [
            "kimsuky",
            "linux",
            "blackcat",
            "romcom",
            "qbot",
            "remote access",
            "cvss",
            "cvss base",
            "jetpack plugin",
            "million",
            "latin america",
            "camaro dragon",
            "strikes",
            "python code",
            "gigabyte",
            "dark pink",
            "romcom rat",
            "royal",
            "rokrat",
            "scarcruft",
            "indonesia",
            "exploit",
            "hashes domains",
            "ip address",
            "blacklist host",
            "ip country",
            "latest spambot",
            "visit",
            "activity",
            "china",
            "singapore",
            "romania",
            "quakbot",
            "stealc",
            "anydesk",
            "guloader",
            "date",
            "malware url",
            "tags",
            "agenttesla",
            "rhadamanthy",
            "privateloader",
            "smoke loader",
            "sha1 file",
            "name submit"
          ],
          "references": [
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time",
            "https://www.dnsbl.info/"
          ],
          "public": 1,
          "adversary": "Kimsuky",
          "targeted_countries": [
            "Viet Nam",
            "Thailand",
            "Indonesia",
            "Brunei Darussalam",
            "Belgium",
            "United States of America",
            "Korea, Democratic People's Republic of",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "Remote Access",
              "display_name": "Remote Access",
              "target": null
            },
            {
              "id": "QBot",
              "display_name": "QBot",
              "target": null
            },
            {
              "id": "RomCom",
              "display_name": "RomCom",
              "target": null
            },
            {
              "id": "BlackCat",
              "display_name": "BlackCat",
              "target": null
            },
            {
              "id": "Linux",
              "display_name": "Linux",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1495",
              "name": "Firmware Corruption",
              "display_name": "T1495 - Firmware Corruption"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [
            "Media",
            "Social Engineering"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 46,
            "FileHash-SHA1": 46,
            "FileHash-SHA256": 130,
            "URL": 123,
            "domain": 125,
            "hostname": 42,
            "CVE": 1
          },
          "indicator_count": 513,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 107,
          "modified_text": "1060 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "647bcc5f5b41279e2affcb8d",
          "name": "URLHaus data - 03-06-2023",
          "description": "",
          "modified": "2023-07-03T23:01:02.051000",
          "created": "2023-06-03T23:27:27.342000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "mirai",
            "arm",
            "dropped-by-amadey",
            "32",
            "bashlite",
            "gafgyt",
            "64",
            "shellscript",
            "hajime",
            "exe",
            "Loki",
            "Amadey",
            "Raccoon",
            "pw-2022",
            "rar",
            "1234",
            "7z",
            "Password-protected",
            "pw-2023",
            "pw-1515",
            "RedLineStealer",
            "RemcosRAT",
            "RTF"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 884,
            "hostname": 1,
            "domain": 3
          },
          "indicator_count": 888,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "1062 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.dnsbl.info/",
        "https://urlhaus.abuse.ch/browse/",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Kimsuky"
          ],
          "malware_families": [
            "Remote access",
            "Blackcat",
            "Linux",
            "Romcom",
            "Qbot"
          ],
          "industries": [
            "Media",
            "Social engineering"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "65709c176bf14908e11e80d8",
      "name": "TechM-Threat Intel Report - W23-2023",
      "description": "",
      "modified": "2023-12-06T16:06:47.815000",
      "created": "2023-12-06T16:06:47.815000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 130,
        "FileHash-MD5": 46,
        "FileHash-SHA1": 46,
        "domain": 125,
        "hostname": 42,
        "URL": 123,
        "CVE": 1
      },
      "indicator_count": 513,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "647da78794bf55c527ee8400",
      "name": "TechM-Threat Intel Report - W23-2023",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2023-07-05T08:04:41.483000",
      "created": "2023-06-05T09:14:47.526000",
      "tags": [
        "kimsuky",
        "linux",
        "blackcat",
        "romcom",
        "qbot",
        "remote access",
        "cvss",
        "cvss base",
        "jetpack plugin",
        "million",
        "latin america",
        "camaro dragon",
        "strikes",
        "python code",
        "gigabyte",
        "dark pink",
        "romcom rat",
        "royal",
        "rokrat",
        "scarcruft",
        "indonesia",
        "exploit",
        "hashes domains",
        "ip address",
        "blacklist host",
        "ip country",
        "latest spambot",
        "visit",
        "activity",
        "china",
        "singapore",
        "romania",
        "quakbot",
        "stealc",
        "anydesk",
        "guloader",
        "date",
        "malware url",
        "tags",
        "agenttesla",
        "rhadamanthy",
        "privateloader",
        "smoke loader",
        "sha1 file",
        "name submit"
      ],
      "references": [
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time",
        "https://www.dnsbl.info/"
      ],
      "public": 1,
      "adversary": "Kimsuky",
      "targeted_countries": [
        "Viet Nam",
        "Thailand",
        "Indonesia",
        "Brunei Darussalam",
        "Belgium",
        "United States of America",
        "Korea, Democratic People's Republic of",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "Remote Access",
          "display_name": "Remote Access",
          "target": null
        },
        {
          "id": "QBot",
          "display_name": "QBot",
          "target": null
        },
        {
          "id": "RomCom",
          "display_name": "RomCom",
          "target": null
        },
        {
          "id": "BlackCat",
          "display_name": "BlackCat",
          "target": null
        },
        {
          "id": "Linux",
          "display_name": "Linux",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1495",
          "name": "Firmware Corruption",
          "display_name": "T1495 - Firmware Corruption"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [
        "Media",
        "Social Engineering"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 46,
        "FileHash-SHA1": 46,
        "FileHash-SHA256": 130,
        "URL": 123,
        "domain": 125,
        "hostname": 42,
        "CVE": 1
      },
      "indicator_count": 513,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 107,
      "modified_text": "1060 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "647bcc5f5b41279e2affcb8d",
      "name": "URLHaus data - 03-06-2023",
      "description": "",
      "modified": "2023-07-03T23:01:02.051000",
      "created": "2023-06-03T23:27:27.342000",
      "tags": [
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "mirai",
        "arm",
        "dropped-by-amadey",
        "32",
        "bashlite",
        "gafgyt",
        "64",
        "shellscript",
        "hajime",
        "exe",
        "Loki",
        "Amadey",
        "Raccoon",
        "pw-2022",
        "rar",
        "1234",
        "7z",
        "Password-protected",
        "pw-2023",
        "pw-1515",
        "RedLineStealer",
        "RemcosRAT",
        "RTF"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 884,
        "hostname": 1,
        "domain": 3
      },
      "indicator_count": 888,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1621,
      "modified_text": "1062 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "el3ctrn.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "el3ctrn.com",
    "found": true,
    "verdict": "malicious",
    "url_count": 1,
    "online_count": 0,
    "blacklists": {
      "spamhaus_dbl": "not listed",
      "surbl": "not listed"
    },
    "urls": [
      {
        "url": "https://el3ctrn.com/download/El3ctron.rar",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2023-06-03",
        "tags": [
          "pw-1515",
          "rar",
          "RedLineStealer"
        ]
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780211909.429867
}