{
  "type": "Domain",
  "indicator": "evollui.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/evollui.com",
    "alexa": "http://www.alexa.com/siteinfo/evollui.com",
    "indicator": "evollui.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3685823906,
      "indicator": "evollui.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "65709bdfec2ebd8b9c05c15d",
          "name": "Threat Intel Report - W22-2023",
          "description": "",
          "modified": "2023-12-06T16:05:51.194000",
          "created": "2023-12-06T16:05:51.194000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 147,
            "FileHash-MD5": 78,
            "FileHash-SHA1": 73,
            "domain": 111,
            "hostname": 29,
            "URL": 121
          },
          "indicator_count": 559,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64747c916cd830d76839022d",
          "name": "Threat Intel Report - W22-2023",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2023-06-28T10:02:59.787000",
          "created": "2023-05-29T10:21:05.570000",
          "tags": [
            "korean lazarus",
            "espionage",
            "lazarus",
            "buhti",
            "qbot",
            "stealthy bandit",
            "cosmicenergy",
            "babuk",
            "moneybird",
            "kimsuky",
            "windows",
            "microsoft",
            "cvss",
            "cvss base",
            "bandit stealer",
            "google cloud",
            "cloud sql",
            "lockbit",
            "qbot malware",
            "augusta",
            "malware",
            "service",
            "korean",
            "hashes domains",
            "amadey amadey",
            "ddos",
            "vidar vidar",
            "december",
            "arkei",
            "vidar",
            "remcos remcos",
            "wcry",
            "wanacryptor",
            "japan",
            "ip address",
            "blacklist host",
            "ip country",
            "latest spambot",
            "visit",
            "activity",
            "brazil",
            "canada",
            "singapore",
            "qakbot",
            "privateloader",
            "date",
            "malware url",
            "tags",
            "coinminer",
            "smake loader",
            "sha1 file",
            "name submit"
          ],
          "references": [
            "http://sanddroid.xjtu.edu.cn/",
            "http://jevereg.amnpardaz.com/"
          ],
          "public": 1,
          "adversary": "Korean Lazarus",
          "targeted_countries": [
            "Ukraine",
            "United States of America",
            "Georgia"
          ],
          "malware_families": [
            {
              "id": "Kimsuky",
              "display_name": "Kimsuky",
              "target": null
            },
            {
              "id": "Moneybird",
              "display_name": "Moneybird",
              "target": null
            },
            {
              "id": "Babuk",
              "display_name": "Babuk",
              "target": null
            },
            {
              "id": "COSMICENERGY",
              "display_name": "COSMICENERGY",
              "target": null
            },
            {
              "id": "Stealthy Bandit",
              "display_name": "Stealthy Bandit",
              "target": null
            },
            {
              "id": "QBot",
              "display_name": "QBot",
              "target": null
            },
            {
              "id": "Buhti",
              "display_name": "Buhti",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1123",
              "name": "Audio Capture",
              "display_name": "T1123 - Audio Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 78,
            "FileHash-SHA1": 73,
            "FileHash-SHA256": 147,
            "URL": 121,
            "domain": 111,
            "hostname": 29
          },
          "indicator_count": 559,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "1067 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "646fefd074927faa22a83b9d",
          "name": "URLHaus data - 25-05-2023",
          "description": "",
          "modified": "2023-06-24T23:03:28.853000",
          "created": "2023-05-25T23:31:28.135000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "arm",
            "mirai",
            "32",
            "motorola",
            "renesas",
            "intel",
            "PowerPC",
            "sparc",
            "script",
            "zip",
            "hajime",
            "Amadey",
            "exe",
            "RedLineStealer",
            "dropped-by-amadey",
            "AgentTesla",
            "asciii",
            "Encoded",
            "Loki",
            "encrypted",
            "GuLoader",
            "ascii",
            "opendir",
            "rat",
            "RemcosRAT",
            "1212",
            "Password-protected",
            "rar",
            "2022",
            "wanwap1337",
            "2023",
            "hackdeversion",
            "1234",
            "7z",
            "123",
            "dropped-by-SmokeLoader",
            "agenziaentrate",
            "geofenced",
            "Gozi",
            "ISFB",
            "ITA",
            "ursnif",
            "BB29",
            "js",
            "Qakbot",
            "USA",
            "NetSupport",
            "dropped-by-PrivateLoader",
            "RedLine",
            "dll",
            "ua-ps",
            "Pikabot",
            "Smoke Loader",
            "ddos-bot",
            "64",
            "Obama264",
            "Quakbot",
            "wsf",
            "doc",
            "gafgyt",
            "pw-2023",
            "pw-1515",
            "pw-2022",
            "Vidar",
            "pw:1234",
            "gcleaner",
            "ArkeiStealer",
            "Formbook",
            "AveMariaRAT"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 652,
            "hostname": 7,
            "domain": 115
          },
          "indicator_count": 774,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "1071 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://jevereg.amnpardaz.com/",
        "http://sanddroid.xjtu.edu.cn/",
        "https://urlhaus.abuse.ch/browse/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Korean Lazarus"
          ],
          "malware_families": [
            "Stealthy bandit",
            "Moneybird",
            "Buhti",
            "Qbot",
            "Kimsuky",
            "Cosmicenergy",
            "Babuk"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "65709bdfec2ebd8b9c05c15d",
      "name": "Threat Intel Report - W22-2023",
      "description": "",
      "modified": "2023-12-06T16:05:51.194000",
      "created": "2023-12-06T16:05:51.194000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 147,
        "FileHash-MD5": 78,
        "FileHash-SHA1": 73,
        "domain": 111,
        "hostname": 29,
        "URL": 121
      },
      "indicator_count": 559,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "64747c916cd830d76839022d",
      "name": "Threat Intel Report - W22-2023",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2023-06-28T10:02:59.787000",
      "created": "2023-05-29T10:21:05.570000",
      "tags": [
        "korean lazarus",
        "espionage",
        "lazarus",
        "buhti",
        "qbot",
        "stealthy bandit",
        "cosmicenergy",
        "babuk",
        "moneybird",
        "kimsuky",
        "windows",
        "microsoft",
        "cvss",
        "cvss base",
        "bandit stealer",
        "google cloud",
        "cloud sql",
        "lockbit",
        "qbot malware",
        "augusta",
        "malware",
        "service",
        "korean",
        "hashes domains",
        "amadey amadey",
        "ddos",
        "vidar vidar",
        "december",
        "arkei",
        "vidar",
        "remcos remcos",
        "wcry",
        "wanacryptor",
        "japan",
        "ip address",
        "blacklist host",
        "ip country",
        "latest spambot",
        "visit",
        "activity",
        "brazil",
        "canada",
        "singapore",
        "qakbot",
        "privateloader",
        "date",
        "malware url",
        "tags",
        "coinminer",
        "smake loader",
        "sha1 file",
        "name submit"
      ],
      "references": [
        "http://sanddroid.xjtu.edu.cn/",
        "http://jevereg.amnpardaz.com/"
      ],
      "public": 1,
      "adversary": "Korean Lazarus",
      "targeted_countries": [
        "Ukraine",
        "United States of America",
        "Georgia"
      ],
      "malware_families": [
        {
          "id": "Kimsuky",
          "display_name": "Kimsuky",
          "target": null
        },
        {
          "id": "Moneybird",
          "display_name": "Moneybird",
          "target": null
        },
        {
          "id": "Babuk",
          "display_name": "Babuk",
          "target": null
        },
        {
          "id": "COSMICENERGY",
          "display_name": "COSMICENERGY",
          "target": null
        },
        {
          "id": "Stealthy Bandit",
          "display_name": "Stealthy Bandit",
          "target": null
        },
        {
          "id": "QBot",
          "display_name": "QBot",
          "target": null
        },
        {
          "id": "Buhti",
          "display_name": "Buhti",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1123",
          "name": "Audio Capture",
          "display_name": "T1123 - Audio Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 78,
        "FileHash-SHA1": 73,
        "FileHash-SHA256": 147,
        "URL": 121,
        "domain": 111,
        "hostname": 29
      },
      "indicator_count": 559,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "1067 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "646fefd074927faa22a83b9d",
      "name": "URLHaus data - 25-05-2023",
      "description": "",
      "modified": "2023-06-24T23:03:28.853000",
      "created": "2023-05-25T23:31:28.135000",
      "tags": [
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "arm",
        "mirai",
        "32",
        "motorola",
        "renesas",
        "intel",
        "PowerPC",
        "sparc",
        "script",
        "zip",
        "hajime",
        "Amadey",
        "exe",
        "RedLineStealer",
        "dropped-by-amadey",
        "AgentTesla",
        "asciii",
        "Encoded",
        "Loki",
        "encrypted",
        "GuLoader",
        "ascii",
        "opendir",
        "rat",
        "RemcosRAT",
        "1212",
        "Password-protected",
        "rar",
        "2022",
        "wanwap1337",
        "2023",
        "hackdeversion",
        "1234",
        "7z",
        "123",
        "dropped-by-SmokeLoader",
        "agenziaentrate",
        "geofenced",
        "Gozi",
        "ISFB",
        "ITA",
        "ursnif",
        "BB29",
        "js",
        "Qakbot",
        "USA",
        "NetSupport",
        "dropped-by-PrivateLoader",
        "RedLine",
        "dll",
        "ua-ps",
        "Pikabot",
        "Smoke Loader",
        "ddos-bot",
        "64",
        "Obama264",
        "Quakbot",
        "wsf",
        "doc",
        "gafgyt",
        "pw-2023",
        "pw-1515",
        "pw-2022",
        "Vidar",
        "pw:1234",
        "gcleaner",
        "ArkeiStealer",
        "Formbook",
        "AveMariaRAT"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 652,
        "hostname": 7,
        "domain": 115
      },
      "indicator_count": 774,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "1071 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "evollui.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "evollui.com",
    "found": true,
    "verdict": "malicious",
    "url_count": 1,
    "online_count": 0,
    "blacklists": {
      "spamhaus_dbl": "not listed",
      "surbl": "not listed"
    },
    "urls": [
      {
        "url": "https://evollui.com/oid/",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2023-05-25",
        "tags": [
          "BB29",
          "geofenced",
          "js",
          "Qakbot",
          "USA"
        ]
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780211760.553905
}