{
  "type": "Domain",
  "indicator": "file.name",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/file.name",
    "alexa": "http://www.alexa.com/siteinfo/file.name",
    "indicator": "file.name",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 14297815,
      "indicator": "file.name",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 38,
      "pulses": [
        {
          "id": "6a1447f25db6bc082d5093cb",
          "name": "RemotePE: The Lazarus RAT that lives in memory",
          "description": "A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.",
          "modified": "2026-05-25T15:15:11.630000",
          "created": "2026-05-25T13:00:34.674000",
          "tags": [
            "poolrat",
            "pondrat",
            "dpapiloader",
            "themeforestrat",
            "hellsgate",
            "remotepeloader",
            "remotepe"
          ],
          "references": [
            "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "DPAPILoader",
              "display_name": "DPAPILoader",
              "target": null
            },
            {
              "id": "RemotePELoader",
              "display_name": "RemotePELoader",
              "target": null
            },
            {
              "id": "RemotePE",
              "display_name": "RemotePE",
              "target": null
            },
            {
              "id": "ThemeForestRAT",
              "display_name": "ThemeForestRAT",
              "target": null
            },
            {
              "id": "PondRAT",
              "display_name": "PondRAT",
              "target": null
            },
            {
              "id": "POOLRAT",
              "display_name": "POOLRAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1543.003",
              "name": "Windows Service",
              "display_name": "T1543.003 - Windows Service"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1562.006",
              "name": "Indicator Blocking",
              "display_name": "T1562.006 - Indicator Blocking"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1027.002",
              "name": "Software Packing",
              "display_name": "T1027.002 - Software Packing"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1480.001",
              "name": "Environmental Keying",
              "display_name": "T1480.001 - Environmental Keying"
            }
          ],
          "industries": [
            "Finance"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 8,
            "URL": 2,
            "domain": 8,
            "hostname": 1
          },
          "indicator_count": 28,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386485,
          "modified_text": "5 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68b87b65a4bb4c1c6d37b3a2",
          "name": "Three Lazarus RATs coming for your cheese",
          "description": "This report analyzes three remote access trojans (RATs) used by a Lazarus subgroup targeting financial and cryptocurrency organizations: PondRAT, ThemeForestRAT, and RemotePE. It details an incident response case from 2024 involving social engineering and possible zero-day exploitation. PondRAT is described as a simple initial access tool, while ThemeForestRAT is a more capable memory-only RAT used in conjunction. RemotePE appears to be an advanced RAT deployed in later attack stages. The analysis reveals connections between these tools and previously known Lazarus malware like POOLRAT. The report highlights the actor's persistence, sophistication, and continued threat to financial targets.",
          "modified": "2025-10-03T17:00:17.123000",
          "created": "2025-09-03T17:31:17.494000",
          "tags": [
            "financial",
            "rat",
            "themeforestrat",
            "zero-day",
            "remotepe",
            "poolrat",
            "pondrat",
            "cryptocurrency",
            "social engineering"
          ],
          "references": [
            "https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1070.006",
              "name": "Timestomp",
              "display_name": "T1070.006 - Timestomp"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1588.001",
              "name": "Malware",
              "display_name": "T1588.001 - Malware"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "display_name": "T1048 - Exfiltration Over Alternative Protocol"
            },
            {
              "id": "T1588.002",
              "name": "Tool",
              "display_name": "T1588.002 - Tool"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1204.001",
              "name": "Malicious Link",
              "display_name": "T1204.001 - Malicious Link"
            },
            {
              "id": "T1078.003",
              "name": "Local Accounts",
              "display_name": "T1078.003 - Local Accounts"
            }
          ],
          "industries": [
            "Finance"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 49,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 27,
            "FileHash-SHA1": 33,
            "FileHash-SHA256": 48,
            "domain": 22,
            "hostname": 6
          },
          "indicator_count": 136,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386484,
          "modified_text": "239 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a141e8c7ad40a0af45a7a56",
          "name": "monitored target - credit Q Vashti (clone)",
          "description": "",
          "modified": "2026-05-31T05:22:37.048000",
          "created": "2026-05-25T10:03:56.699000",
          "tags": [
            "indicator",
            "source",
            "ck id",
            "show technique",
            "mitre att",
            "ck matrix",
            "openservice",
            "sha384",
            "file",
            "virtualfree",
            "path",
            "getprocaddress",
            "pattern match",
            "potential ip",
            "open",
            "date",
            "click",
            "error",
            "null",
            "false",
            "stream",
            "enterprise",
            "body",
            "crypto",
            "compiler",
            "entropy",
            "refresh",
            "download",
            "factory",
            "bind",
            "strings",
            "twitter",
            "roboto",
            "contact",
            "window",
            "tools",
            "span",
            "value",
            "access type",
            "file execution",
            "setval",
            "userprofile",
            "debugger",
            "hybrid",
            "persistence",
            "general",
            "suspicious",
            "target"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1029",
              "name": "Scheduled Transfer",
              "display_name": "T1029 - Scheduled Transfer"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1213",
              "name": "Data from Information Repositories",
              "display_name": "T1213 - Data from Information Repositories"
            },
            {
              "id": "T1217",
              "name": "Browser Bookmark Discovery",
              "display_name": "T1217 - Browser Bookmark Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1559",
              "name": "Inter-Process Communication",
              "display_name": "T1559 - Inter-Process Communication"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1565",
              "name": "Data Manipulation",
              "display_name": "T1565 - Data Manipulation"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "68409862e1722725233acace",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 54,
            "FileHash-SHA1": 35,
            "FileHash-SHA256": 24,
            "SSLCertFingerprint": 3,
            "URL": 294,
            "domain": 317,
            "hostname": 648,
            "email": 3
          },
          "indicator_count": 1378,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "13 minutes ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5fa1852d337eca8e99c2ec32",
          "name": "Malware - Malware Domain Feed V2 - November 03 2020",
          "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
          "modified": "2026-05-30T03:19:46.084000",
          "created": "2020-11-03T16:28:29.011000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 552488,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 3,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "otxrobottwo",
            "id": "78495",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 49967,
            "domain": 75353
          },
          "indicator_count": 125320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1727,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a15ad403ba61be50e09d42e",
          "name": "research indicators tlp: amber",
          "description": "This post is not a reflection of any companies tagged.",
          "modified": "2026-05-29T09:50:48.467000",
          "created": "2026-05-26T14:25:04.421000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 53,
            "URL": 131,
            "hostname": 73,
            "domain": 21,
            "FileHash-MD5": 17,
            "FileHash-SHA1": 26,
            "IPv4": 1
          },
          "indicator_count": 322,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1814b55e1559397600e7f7",
          "name": "EbeeMay2026 Pt5",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-05-28T10:11:01.506000",
          "created": "2026-05-28T10:11:01.506000",
          "tags": [
            "filehashsha256",
            "filehashmd5",
            "filehashsha1",
            "redacted",
            "ipv62a12",
            "ipv62a03",
            "localappdata",
            "cve20234966 cve",
            "cve20136282 cve",
            "cve20132597 cve"
          ],
          "references": [
            "IOCs-MAY4.csv"
          ],
          "public": 1,
          "adversary": "RemotePE, ClayRat, Nimbus Manticore, SonicWall SSL VPN exploitation, ModeloRAT",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 79,
            "URL": 57,
            "CIDR": 3,
            "CVE": 15,
            "FileHash-MD5": 151,
            "FileHash-SHA1": 113,
            "FileHash-SHA256": 164,
            "domain": 137,
            "email": 4,
            "hostname": 47
          },
          "indicator_count": 770,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 39,
          "modified_text": "2 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a15279470f40ea28e34fa55",
          "name": "RemotePE: The Lazarus RAT that lives in memory",
          "description": "",
          "modified": "2026-05-26T04:54:44.854000",
          "created": "2026-05-26T04:54:44.854000",
          "tags": [
            "poolrat",
            "pondrat",
            "dpapiloader",
            "themeforestrat",
            "hellsgate",
            "remotepeloader",
            "remotepe"
          ],
          "references": [
            "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "DPAPILoader",
              "display_name": "DPAPILoader",
              "target": null
            },
            {
              "id": "RemotePELoader",
              "display_name": "RemotePELoader",
              "target": null
            },
            {
              "id": "RemotePE",
              "display_name": "RemotePE",
              "target": null
            },
            {
              "id": "ThemeForestRAT",
              "display_name": "ThemeForestRAT",
              "target": null
            },
            {
              "id": "PondRAT",
              "display_name": "PondRAT",
              "target": null
            },
            {
              "id": "POOLRAT",
              "display_name": "POOLRAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1543.003",
              "name": "Windows Service",
              "display_name": "T1543.003 - Windows Service"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1562.006",
              "name": "Indicator Blocking",
              "display_name": "T1562.006 - Indicator Blocking"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1027.002",
              "name": "Software Packing",
              "display_name": "T1027.002 - Software Packing"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1480.001",
              "name": "Environmental Keying",
              "display_name": "T1480.001 - Environmental Keying"
            }
          ],
          "industries": [
            "Finance"
          ],
          "TLP": "white",
          "cloned_from": "6a1447f25db6bc082d5093cb",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 8,
            "URL": 2,
            "domain": 8,
            "hostname": 1
          },
          "indicator_count": 28,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 278,
          "modified_text": "5 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a151218eba755efd0f0b4a9",
          "name": "IOC - RemotePE: The Lazarus RAT that lives in memory",
          "description": "",
          "modified": "2026-05-26T03:23:33.245000",
          "created": "2026-05-26T03:23:04.561000",
          "tags": [
            "poolrat",
            "pondrat",
            "dpapiloader",
            "themeforestrat",
            "hellsgate",
            "remotepeloader",
            "remotepe"
          ],
          "references": [
            "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "DPAPILoader",
              "display_name": "DPAPILoader",
              "target": null
            },
            {
              "id": "RemotePELoader",
              "display_name": "RemotePELoader",
              "target": null
            },
            {
              "id": "RemotePE",
              "display_name": "RemotePE",
              "target": null
            },
            {
              "id": "ThemeForestRAT",
              "display_name": "ThemeForestRAT",
              "target": null
            },
            {
              "id": "PondRAT",
              "display_name": "PondRAT",
              "target": null
            },
            {
              "id": "POOLRAT",
              "display_name": "POOLRAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1543.003",
              "name": "Windows Service",
              "display_name": "T1543.003 - Windows Service"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1562.006",
              "name": "Indicator Blocking",
              "display_name": "T1562.006 - Indicator Blocking"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1027.002",
              "name": "Software Packing",
              "display_name": "T1027.002 - Software Packing"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1480.001",
              "name": "Environmental Keying",
              "display_name": "T1480.001 - Environmental Keying"
            }
          ],
          "industries": [
            "Finance"
          ],
          "TLP": "white",
          "cloned_from": "6a1447f25db6bc082d5093cb",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "celestre",
            "id": "295357",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 8,
            "domain": 8,
            "hostname": 1
          },
          "indicator_count": 22,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "5 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d389db09844fda2dd3d26d",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-05-06T10:13:24.260000",
          "created": "2026-04-06T10:24:27.141000",
          "tags": [
            "p2404",
            "strong",
            "sha256",
            "library",
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "none rticon",
            "info",
            "path",
            "win32",
            "accept",
            "null",
            "activator",
            "false",
            "black",
            "powershell",
            "error",
            "team",
            "code",
            "date",
            "download",
            "stop",
            "green",
            "class",
            "void",
            "cheap",
            "shutdown",
            "impact",
            "guard",
            "tools",
            "comspec",
            "enterprise",
            "terminal",
            "music",
            "desktop",
            "crypt32",
            "lockfile",
            "write",
            "open",
            "stub",
            "delta",
            "title",
            "body",
            "project",
            "windows sandbox",
            "calls process"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
            "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 172,
            "FileHash-SHA1": 151,
            "FileHash-SHA256": 121,
            "URL": 80,
            "domain": 17,
            "hostname": 59
          },
          "indicator_count": 600,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d389dab37e607e415f7304",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-05-06T10:13:24.260000",
          "created": "2026-04-06T10:24:26.731000",
          "tags": [
            "p2404",
            "strong",
            "sha256",
            "library",
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "none rticon",
            "info",
            "path",
            "win32",
            "accept",
            "null",
            "activator",
            "false",
            "black",
            "powershell",
            "error",
            "team",
            "code",
            "date",
            "download",
            "stop",
            "green",
            "class",
            "void",
            "cheap",
            "shutdown",
            "impact",
            "guard",
            "tools",
            "comspec",
            "enterprise",
            "terminal",
            "music",
            "desktop",
            "crypt32",
            "lockfile",
            "write",
            "open",
            "stub",
            "delta",
            "title",
            "body",
            "project",
            "windows sandbox",
            "calls process"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
            "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 172,
            "FileHash-SHA1": 151,
            "FileHash-SHA256": 121,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 596,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d389d979acb0e20217e451",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-05-06T10:13:24.260000",
          "created": "2026-04-06T10:24:25.849000",
          "tags": [
            "p2404",
            "strong",
            "sha256",
            "library",
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "none rticon",
            "info",
            "path",
            "win32",
            "accept",
            "null",
            "activator",
            "false",
            "black",
            "powershell",
            "error",
            "team",
            "code",
            "date",
            "download",
            "stop",
            "green",
            "class",
            "void",
            "cheap",
            "shutdown",
            "impact",
            "guard",
            "tools",
            "comspec",
            "enterprise",
            "terminal",
            "music",
            "desktop",
            "crypt32",
            "lockfile",
            "write",
            "open",
            "stub",
            "delta",
            "title",
            "body",
            "project",
            "windows sandbox",
            "calls process"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
            "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 172,
            "FileHash-SHA1": 151,
            "FileHash-SHA256": 121,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 596,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d3843cba399db62eeae702",
          "name": "CAPE Sandbox - Stalking",
          "description": "A full report on the latest Android operating system: PK.3.4.5.1 (c) on 1 January, 2026, to be published by the Google Research Institute (GRI).",
          "modified": "2026-05-06T10:13:24.260000",
          "created": "2026-04-06T10:00:28.397000",
          "tags": [
            "renewed",
            "8gbram",
            "windows10",
            "19inlcdmonitor",
            "desktop pc",
            "package",
            "intel core",
            "hard drive",
            "dvdrw",
            "wifi",
            "title",
            "blink",
            "date",
            "meta",
            "elite",
            "body",
            "https",
            "mitre attack",
            "network info",
            "tls version",
            "united",
            "overview",
            "zenbox android",
            "verdict",
            "guest system",
            "ultimate file",
            "fraud",
            "cloud",
            "next",
            "program",
            "processes extra",
            "overview zenbox",
            "info file",
            "file type",
            "default",
            "parent pid",
            "full path",
            "command line",
            "registry keys",
            "commands c",
            "k dcomlaunch",
            "files c",
            "devicecng c",
            "read registry"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/2533042959ad1fe050d14ab7536126910a2d240992bff397640382472b6a7c69_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469608&Signature=fK1I2%2FxXVm0l3ZiELwtstes8iVN402Ww%2By%2BgvxYOB0LiC2iO3J9cedWJk1hMIr4IfLSGKprfui8vANzR%2BkWfSd594S%2FFe9A59YKyOA2MFmQTBRXVy6O3xF1e1lPETp5Md%2FbGJCOzrZxdHyReyuk7cgdDDBAewptjJhfTYxql7F9X%2FB4qe9BYWPrvned2fFWfU%2F4G%2F4UBqY9Jj%2BG1CTP%2FaGqOdWFs0Q5cPYZ4bytp",
            "https://vtbehaviour.commondatastorage.googleapis.com/6c39ae0368703f254070a0648c0066115140c3e762d9bf5b52833a037a1e3743_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469752&Signature=Df%2Bamm33qFPdsDg6nWC5FQjse7h4fksSXqONp4nMEItb0gpBwqx66TqcCnFzQplUk6ExMge79qNZR2OElv63sX54D4fSGwI9nvHYhQoiVdZIgf4ct8dIAr%2BYO9jSx0WpPUVFsvf%2FXtXvm6jM5n5v7CGiyFRyAz8PES5g%2FcOlLt%2BDhsc8bhi%2FMU9mAkyyr5nFVPcTmUSHOTNXOeKDUlyRkQE6b9FEbFhUL1h3%2B%2FBVtysh",
            "https://vtbehaviour.commondatastorage.googleapis.com/5feceb66ffc86f38d952786c6d696c79c2dbc239dd4e91b46729d73a27fb57e9_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469810&Signature=Mj5ODxCW7tD5UNn6P11Ta7F2cmDLSJuEB7JSLFg%2FERfANmnRR5L7XzDwXxI5G48vkQFx0%2FBMtjMLwWHn6ZHKlt13rfzkvoOu5fJ%2Fb5lMJqUp1rSQIG0JLL80QAnXyJf2W8pL7MvK97Tr4jsCIUfd8ezliJtV5SmahV6Q8lYu2KJUnANrHkA10RFrcT4O26Vk7gbDsuC7caDXC6U9KXTTB0cpC77%2FV7w86ftN2JPXx6oEHUvSj02qsvhKwKQvmM",
            "https://vtbehaviour.commondatastorage.googleapis.com/5feceb66ffc86f38d952786c6d696c79c2dbc239dd4e91b46729d73a27fb57e9_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469831&Signature=ZlRZLvCaJ%2F9niupu9DFCvXvfgFpDEOsK%2FsH46CB2zEVUDjcQRNMDp9XXKKx0dekmHQbhl02yqygHPOA8Wty5duGtK216QCvKNkYpbpdOjN7xgAg3AsldciWbqeJr8N4I%2F1%2FPRSdVfB%2BNGaBJKxZG1RQkX206MSvX%2BeY%2FdeEYpq3NYdrPWlxdV0pa3yaqcMrf2s%2FCFSM%2FdO3xt5PKyXWG%2FDCNM5iiuXh8OT2ckhZhf%"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1221",
              "name": "Template Injection",
              "display_name": "T1221 - Template Injection"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1409",
              "name": "Access Stored Application Data",
              "display_name": "T1409 - Access Stored Application Data"
            },
            {
              "id": "T1421",
              "name": "System Network Connections Discovery",
              "display_name": "T1421 - System Network Connections Discovery"
            },
            {
              "id": "T1422",
              "name": "System Network Configuration Discovery",
              "display_name": "T1422 - System Network Configuration Discovery"
            },
            {
              "id": "T1426",
              "name": "System Information Discovery",
              "display_name": "T1426 - System Information Discovery"
            },
            {
              "id": "T1430",
              "name": "Location Tracking",
              "display_name": "T1430 - Location Tracking"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 781,
            "FileHash-SHA1": 509,
            "FileHash-SHA256": 539,
            "URL": 387,
            "hostname": 361,
            "domain": 100,
            "CIDR": 1,
            "email": 1
          },
          "indicator_count": 2679,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b4e829e206f1e64d6fa31b",
          "name": "CAPE Sandbox terrible chain",
          "description": "",
          "modified": "2026-04-13T04:23:40.153000",
          "created": "2026-03-14T04:46:33.543000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 150,
            "FileHash-SHA256": 123,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 598,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b4e828809a73c4baff9c5b",
          "name": "CAPE Sandbox terrible chain",
          "description": "",
          "modified": "2026-04-13T04:23:40.153000",
          "created": "2026-03-14T04:46:32.492000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 150,
            "FileHash-SHA256": 123,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 598,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b48ce57b26a7b8bb9222b8",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-04-12T22:04:09.704000",
          "created": "2026-03-13T22:17:09.654000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 150,
            "FileHash-SHA256": 123,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 598,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b48ce44221764174cb6aab",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-04-12T22:04:09.704000",
          "created": "2026-03-13T22:17:07.826000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 150,
            "FileHash-SHA256": 123,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 598,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6968c4b882bd113c669e4db5",
          "name": "EbeeJan2026 Pt2",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-02-14T10:04:01.416000",
          "created": "2026-01-15T10:43:04.641000",
          "tags": [],
          "references": [
            "IOCs.pdf"
          ],
          "public": 1,
          "adversary": "ValleyRAT_S2, DeVixorMalware, SHADOW#REACTOR, Fake Fortinet Sites, Phishing campaign with QR codes",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 56,
            "URL": 46,
            "FileHash-MD5": 129,
            "FileHash-SHA1": 123,
            "FileHash-SHA256": 148,
            "hostname": 25
          },
          "indicator_count": 527,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 38,
          "modified_text": "105 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69665d5c109a09813bce8749",
          "name": "Booking.com Phishing Campaign Targeting Hotels and Customers - Sekoia.io Blog",
          "description": "A new report from cybersecurity firm Sekoia.io examines a sophisticated phishing campaign targeting Booking.com and its customers around the world, as well as the impact of infostealing malware.",
          "modified": "2026-02-12T14:01:38.116000",
          "created": "2026-01-13T14:57:32.880000",
          "tags": [
            "purerat",
            "clickfix",
            "booking",
            "powershell",
            "zip archive",
            "run registry",
            "october",
            "sekoia soc",
            "ip address",
            "c2 server",
            "facebook",
            "malicious",
            "april",
            "date",
            "refresh",
            "quirkyloader",
            "purecrypter",
            "twitter",
            "cluster",
            "clearfake",
            "malware",
            "threat"
          ],
          "references": [
            "https://blog.sekoia.io/phishing-campaigns-i-paid-twice-targeting-booking-com-hotels-and-customers/"
          ],
          "public": 1,
          "adversary": "Threat",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "PureRAT",
              "display_name": "PureRAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Hospitality",
            "Hotel",
            "Banking"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 5,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 4,
            "URL": 28,
            "domain": 70,
            "hostname": 2
          },
          "indicator_count": 113,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "107 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68b84c7dfb263fc48538cf3c",
          "name": "Three Lazarus RATs coming for your cheese &#8211; Fox-IT International blog",
          "description": "A team of researchers from Fox-IT and NCC Group has identified and identified the Lazarus cyber-attack group, which targets companies active in the cryptocurrency sector and financial services sector in 2024 and 2025.",
          "modified": "2025-10-03T14:02:44.172000",
          "created": "2025-09-03T14:11:09.744000",
          "tags": [
            "pondrat",
            "themeforestrat",
            "poolrat",
            "remotepe",
            "c2 server",
            "windows",
            "linux",
            "figure",
            "perfhloader",
            "rats",
            "telegram",
            "lazarus",
            "python",
            "format",
            "sequel",
            "virustotal",
            "window",
            "quasar",
            "facebook",
            "sessionenv",
            "applejeus",
            "macos"
          ],
          "references": [
            "https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "SessionEnv",
              "display_name": "SessionEnv",
              "target": null
            },
            {
              "id": "AppleJeus",
              "display_name": "AppleJeus",
              "target": null
            },
            {
              "id": "Linux",
              "display_name": "Linux",
              "target": null
            },
            {
              "id": "macOS",
              "display_name": "macOS",
              "target": null
            },
            {
              "id": "Windows",
              "display_name": "Windows",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            }
          ],
          "industries": [
            "Cryptocurrency",
            "Social Engineering",
            "Investment",
            "Government",
            "Military"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "mengkuong",
            "id": "239193",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_239193/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 9,
            "FileHash-SHA256": 27,
            "URL": 2,
            "YARA": 6,
            "domain": 21,
            "hostname": 4
          },
          "indicator_count": 80,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 50,
          "modified_text": "239 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68b831b11d8f6e579f7fdc80",
          "name": "Three Lazarus RATs coming for your cheese &#8211; Fox-IT International blog",
          "description": "",
          "modified": "2025-10-03T12:02:47.515000",
          "created": "2025-09-03T12:16:49.788000",
          "tags": [
            "pondrat",
            "themeforestrat",
            "poolrat",
            "remotepe",
            "c2 server",
            "windows",
            "linux",
            "figure",
            "perfhloader",
            "rats",
            "telegram",
            "lazarus",
            "python",
            "format",
            "sequel",
            "virustotal",
            "window",
            "quasar",
            "facebook"
          ],
          "references": [
            "https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 9,
            "FileHash-SHA256": 27,
            "URL": 2,
            "YARA": 6,
            "domain": 21,
            "hostname": 4
          },
          "indicator_count": 80,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 864,
          "modified_text": "239 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68b7a59fdd4296256bfea85f",
          "name": "IOC \u2014 Three Lazarus RATs coming for your cheese",
          "description": "In the past few years, Fox-IT and NCC Group have conducted multiple incident response cases involving a Lazarus subgroup that specifically targets organizations in the financial and cryptocurrency sector. This Lazarus subgroup overlaps with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. This actor uses different remote access trojans (RATs) in their operations, known as PondRAT5, ThemeForestRAT and RemotePE. In this article, we analyse and discuss these three.",
          "modified": "2025-10-03T02:01:54.389000",
          "created": "2025-09-03T02:19:11.565000",
          "tags": [
            "filename actor",
            "fast reverse",
            "unknown",
            "pondrat c2",
            "cisa",
            "pondrat linux",
            "dll phantom",
            "localappdata",
            "dpapiloader",
            "proxy server",
            "comment",
            "quasar"
          ],
          "references": [
            "https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "celestre",
            "id": "295357",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 24,
            "domain": 19,
            "hostname": 3
          },
          "indicator_count": 60,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "240 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68409862e1722725233acace",
          "name": "Monitored Target- bounty-50872035906958562",
          "description": "Monitored Target- bounty-50872035906958562\n(Whitelisted?)\n\u2022 Spyware\nAccesses potentially sensitive information from local browsers |\n\u2022Found a string that may be used as part of an injection method |\n\u2022 Stealer/Phishing\n\u2022 Reads FTP client related files\n\u2022 Persistence\n\u2022 Creates a fake system process\n\u2022 Modifies System Certificates Settings\n\u2022 Modifies auto-execute functionality by setting/creating a value in the registry\n\u2022 Modifies auto-execute functionality to enable the debugger hack\n\u2022 Writes data to a remote process\n\u2022 Writes to the hosts file\n\u2022 Fingerprint\nQueries +",
          "modified": "2025-07-04T18:05:18.397000",
          "created": "2025-06-04T19:02:57.999000",
          "tags": [
            "indicator",
            "source",
            "ck id",
            "show technique",
            "mitre att",
            "ck matrix",
            "openservice",
            "sha384",
            "file",
            "virtualfree",
            "path",
            "getprocaddress",
            "pattern match",
            "potential ip",
            "open",
            "date",
            "click",
            "error",
            "null",
            "false",
            "stream",
            "enterprise",
            "body",
            "crypto",
            "compiler",
            "entropy",
            "refresh",
            "download",
            "factory",
            "bind",
            "strings",
            "twitter",
            "roboto",
            "contact",
            "window",
            "tools",
            "span",
            "value",
            "access type",
            "file execution",
            "setval",
            "userprofile",
            "debugger",
            "hybrid",
            "persistence",
            "general",
            "suspicious",
            "target"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1029",
              "name": "Scheduled Transfer",
              "display_name": "T1029 - Scheduled Transfer"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1213",
              "name": "Data from Information Repositories",
              "display_name": "T1213 - Data from Information Repositories"
            },
            {
              "id": "T1217",
              "name": "Browser Bookmark Discovery",
              "display_name": "T1217 - Browser Bookmark Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1559",
              "name": "Inter-Process Communication",
              "display_name": "T1559 - Inter-Process Communication"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1565",
              "name": "Data Manipulation",
              "display_name": "T1565 - Data Manipulation"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 54,
            "FileHash-SHA1": 35,
            "FileHash-SHA256": 24,
            "SSLCertFingerprint": 3,
            "URL": 294,
            "domain": 317,
            "hostname": 648,
            "email": 3
          },
          "indicator_count": 1378,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "330 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67f5555b6ce863d998e83e26",
          "name": "macOS Threat Infrastructure Leveraging Remote Agents via remotewd.com and rtmsprod.net",
          "description": "This pulse identifies an actively observed macOS-focused remote access infrastructure abusing trusted native Apple agents (ARDAgent.app, SSMenuAgent.app) and communicating with a distributed network of C2-like endpoints under domains such as remotewd.com, idsremoteurlconnectionagent.app, and rtmsprod.net.\n\nThe infrastructure is composed of dynamically generated subdomains \u2014 many in the form of device-<UUID>.remotewd.com \u2014 indicative of automated deployment, system tracking, or per-host remote access configurations.\n\nAdditional indicators include HTTP/S URLs pointing directly to embedded binary paths within macOS agents, suggesting possible delivery vectors, staging, or persistence techniques.\n\nThis campaign shows signs of structured, programmatic targeting and is highly likely to be pre-operational infrastructure for wide-scale surveillance or access operations. All listed indicators should be considered high-risk. If observed in your environment, initiate a full forensic and IR process immediately.",
          "modified": "2025-05-11T19:03:59.885000",
          "created": "2025-04-08T16:56:59.641000",
          "tags": [
            "generated from",
            "do not",
            "edit uri",
            "urls",
            "edit",
            "rewriteengine",
            "rewritecond",
            "rewriterule",
            "r301",
            "xml2encalias",
            "beralloct",
            "berbvarrayadd",
            "berbvarrayfree",
            "berbvdup",
            "berbvecadd",
            "berbvecfree",
            "berbvfree",
            "berdump",
            "berdup",
            "berdupbv",
            "laerrordomain",
            "laerrornoncekey",
            "lamechanismtree",
            "lacontext",
            "ladomainstate",
            "laenvironment",
            "lanotification",
            "laprivatekey",
            "lapublickey",
            "laright",
            "apple swift",
            "o librarylevel",
            "combine import",
            "foundation",
            "swift import",
            "mcpeerid",
            "mcsession",
            "property",
            "copyright",
            "protocol",
            "class",
            "bonjour",
            "ascii lowercase",
            "abc company",
            "section",
            "bonjour txt",
            "note",
            "ui element",
            "utf8 encoding",
            "nscopying",
            "nsdictionary",
            "nsstring",
            "mcextern",
            "attribute",
            "mcextern extern",
            "mcexternweak",
            "nsenum",
            "nsinteger",
            "mcerrorcode",
            "mcerrorunknown",
            "mcerrortimedout",
            "peer",
            "example",
            "bonjour apis",
            "stop",
            "tags",
            "session",
            "nsprogress",
            "nserror",
            "nsurl",
            "nsarray",
            "create",
            "nsuinteger",
            "notifies",
            "mcsession api",
            "interface",
            "dbictrace",
            "dbivporth",
            "dbictracelevel",
            "dbdtffoo",
            "dbihseterrchar",
            "dbicstate",
            "dbictraceflags",
            "provides macros",
            "dbi release",
            "only",
            "sqlsuccess",
            "odbc",
            "sqlok",
            "tim bunce",
            "england",
            "sql cli",
            "sql datatype",
            "sqlguid",
            "sqlwlongvarchar",
            "main",
            "beware",
            "sv sth",
            "sv dbh",
            "impsth",
            "impdbh",
            "sv keysv",
            "sv params",
            "sv attr",
            "sv attribs",
            "sv drh",
            "void",
            "fri jul",
            "mixed",
            "dbixsrevision",
            "plsvundef",
            "license",
            "spagain",
            "perlioprintf",
            "dbiclogpio",
            "putback",
            "ireland",
            "gnu general",
            "super",
            "magic",
            "dbicflags",
            "dbis",
            "svrv",
            "null",
            "imp2com",
            "dbicactivekids",
            "dbicfiadestroy",
            "sv h",
            "dbicdbistate",
            "code",
            "copy",
            "refer",
            "trace",
            "error",
            "unknown",
            "hookopcheckh",
            "startexternc",
            "hookopcheckcb",
            "userdata",
            "endexternc",
            "isinternalbuild",
            "kickmcxdforuid",
            "loadappkit",
            "ardconfig",
            "authenticator",
            "dsauthenticator",
            "dsnode",
            "dsrecord",
            "group",
            "hostconfig",
            "apfsvolumelock",
            "apfsvolumerole",
            "aoskgetosinfo",
            "aoskgetuserinfo",
            "aosaddappleid",
            "aosdisablepcs",
            "aosenablepcs",
            "aoslog",
            "aoslogforce",
            "aosrelaycookie",
            "didfailcallback",
            "kaosaccountkey",
            "kapcsbundle",
            "kapcspath",
            "kjsonextension",
            "apcsbucketid",
            "apcsreports",
            "apconfiguration",
            "apversiondata",
            "apversionhelper",
            "systemvolumesvm",
            "name size",
            "identifier",
            "gb disk0s3",
            "devdisk3",
            "apfs container",
            "scheme",
            "physical store",
            "macintosh hd",
            "apfs snapshot",
            "preboot",
            "refs address",
            "size wired",
            "name",
            "version",
            "uuid",
            "linked against",
            "renderer",
            "helper",
            "chrome helper",
            "contains",
            "cloud ui",
            "macintosh",
            "khtml",
            "gecko",
            "ui helper",
            "plugin",
            "service",
            "good",
            "battery power",
            "apfs encryption",
            "jumpcloud go",
            "chrome web",
            "store",
            "privacy badger",
            "flowcrypt",
            "encrypt gmail",
            "simple",
            "google",
            "b2b phone",
            "number",
            "apollo",
            "future",
            "exccrash",
            "sigkill",
            "code signature",
            "invalid",
            "sigabrt",
            "protonvpn",
            "excguard",
            "excbreakpoint",
            "sigtrap",
            "excbadaccess",
            "appl",
            "english",
            "adobe crash",
            "adobe",
            "acrobat dcadobe",
            "processor",
            "uninstaller",
            "assistant",
            "install",
            "cloud",
            "dock",
            "calendar",
            "music",
            "terminal",
            "tips",
            "installer",
            "updater",
            "proton",
            "tools",
            "stub",
            "python",
            "clock",
            "powershell",
            "team",
            "rave scout",
            "cookies",
            "public folder",
            "key cert",
            "sign",
            "crl sign",
            "root ca",
            "authority",
            "public primary",
            "global root",
            "verisign",
            "academic",
            "premium",
            "adaptive",
            "interactive",
            "background",
            "standard",
            "launchd sandbox",
            "s mdworker",
            "agent",
            "command line",
            "progress",
            "yubico",
            "macos13action",
            "disableoverride",
            "disableairdrop",
            "denyactivation",
            "enable",
            "loginwindowtext",
            "jumpcloud",
            "autoupdate",
            "loggingoption",
            "enablefirewall",
            "arm64e",
            "apple m2",
            "mac142",
            "kjqqtw7pqt",
            "daemon",
            "server",
            "open directory",
            "user",
            "account",
            "kerberos admin",
            "kerberos change",
            "device daemon",
            "network",
            "desktop",
            "screensaver",
            "bridge",
            "aesxtsarm",
            "aesecbarm",
            "sha512vngarmhw",
            "sha384vngarmhw",
            "sha256vngarm",
            "sha1vngarm",
            "darwin kernel",
            "wed mar",
            "wkarraycreate",
            "wkbooleancreate",
            "wkcontextcreate",
            "wkdatacreate",
            "wkdatagettypeid",
            "wkdoublecreate",
            "wkframecopyurl",
            "wkgettypeid",
            "wkimagecreate",
            "wkpagecandelete",
            "webview",
            "notice",
            "this software",
            "including",
            "but not",
            "limited to",
            "redistribution",
            "is provided",
            "by apple",
            "direct",
            "damage",
            "apiavailable",
            "webkit",
            "nsswiftname",
            "document",
            "a block",
            "as is",
            "hasinclude",
            "wkdownload",
            "abstract",
            "wkerrorcode",
            "wkerrorunknown",
            "discussion",
            "bool",
            "whether",
            "wkcontentworld",
            "wkwebview",
            "javascript",
            "nsunavailable",
            "vaargs",
            "nsswiftasync",
            "wkswiftasync",
            "wkcookiepolicy",
            "wkswiftuiactor",
            "nshttpcookie",
            "targetosiphone",
            "wknavigation",
            "decides",
            "boolean value",
            "apideprecated",
            "methodkind",
            "wkerrordomain",
            "wkscriptmessage",
            "promise",
            "fulfill",
            "const",
            "url scheme",
            "mark",
            "wkuserscript",
            "targetosvision",
            "param",
            "wkframeinfo",
            "targetosios",
            "pass",
            "window",
            "mime type",
            "link",
            "nsimage",
            "returns",
            "nsset",
            "checks",
            "matches",
            "a boolean",
            "defaults",
            "wkwebextension",
            "cgsize",
            "uiimage",
            "apis",
            "nsdate",
            "wkcontentmode",
            "wkextern",
            "possible",
            "cgfloat",
            "media",
            "cgrect",
            "apiunavailable",
            "framework",
            "nsswiftuiactor",
            "targetoswatch",
            "confirms",
            "apple upgrade",
            "nsstring user",
            "nsobject",
            "provider",
            "apple",
            "password",
            "uicontrol",
            "nscontrol",
            "asuseragerange",
            "check",
            "opaque user",
            "apple id",
            "initiate",
            "asauthorization",
            "operation",
            "state",
            "nserrorenum",
            "nsdata",
            "relying party",
            "asapiavailable",
            "perform",
            "realm",
            "http response",
            "authorization",
            "http",
            "oauth",
            "saml",
            "a byte",
            "nsdata userid",
            "relying",
            "a string",
            "nsdata readdata",
            "bool didwrite",
            "a cose",
            "nsdata first",
            "nsdata second",
            "nsstring name",
            "bool appid",
            "targetosxr",
            "nsstring appid",
            "bluetooth",
            "mdm profile",
            "nsurl url",
            "returns yes",
            "a state",
            "a json",
            "web token",
            "private seckeys",
            "enables",
            "keychain",
            "asswiftsendable",
            "cose algorithm",
            "ecdsa",
            "sha256",
            "cose curve",
            "p256",
            "nullable",
            "bool success",
            "remove",
            "call",
            "complete",
            "initializes",
            "time code",
            "extensions",
            "asextern extern",
            "asextern",
            "nsswiftsendable",
            "prepare",
            "list",
            "nsextension",
            "attempt",
            "nsstring label",
            "creates",
            "nsstring code",
            "a key",
            "webauthn",
            "nssecurecoding",
            "input",
            "output",
            "initialize",
            "nsinteger rank",
            "json",
            "inputs",
            "hash",
            "nsstring origin",
            "settings app",
            "extension",
            "https urls",
            "safari",
            "cancel",
            "nsuuid uuid",
            "r uftpexu",
            "nsmutabledata",
            "vnsdate",
            "mprcjy",
            "postfix",
            "domain",
            "canonical",
            "tables",
            "ldap",
            "post",
            "replace user",
            "address",
            "wietse venema",
            "bugs",
            "mail",
            "aliases",
            "postfix version",
            "restrict",
            "sample",
            "person",
            "basic system",
            "general",
            "reject empty",
            "postfix smtp",
            "ipv6 host",
            "reject",
            "reply",
            "access",
            "prior",
            "hold",
            "info",
            "mail delivery",
            "charset",
            "system",
            "report",
            "postfix dsn",
            "mail returned",
            "this",
            "generic",
            "smtp",
            "isp mail",
            "mime",
            "headerchecks",
            "readme files",
            "filters while",
            "posix",
            "empty",
            "body",
            "write",
            "date",
            "smtp server",
            "specify",
            "mx host",
            "unix password",
            "user unknown",
            "pathbin",
            "postfix queue",
            "unix",
            "cyrus",
            "path",
            "uucp",
            "shell",
            "local",
            "program",
            "agreement",
            "contributor",
            "recipient",
            "contribution",
            "the program",
            "corporation",
            "contributors",
            "product x",
            "as expressly",
            "arch",
            "arch x8664",
            "pipe wall",
            "wimplicit",
            "ranlib",
            "warn",
            "switch",
            "start",
            "systype",
            "outlook",
            "postfix master",
            "begin",
            "server admin",
            "mail backend",
            "modern smtp",
            "iana",
            "many",
            "postfix pipe",
            "recent cyrus",
            "amos gouaux",
            "old example",
            "or even",
            "lutz jaenicke",
            "technology",
            "cottbus",
            "germany",
            "openssl package",
            "openssl project",
            "europe",
            "remember that",
            "use of",
            "file",
            "update",
            "usrsbin",
            "file format",
            "no group",
            "daemondirectory",
            "deliver mail",
            "transport",
            "description",
            "result format",
            "virtual",
            "virtual alias",
            "redirect mail",
            "relocated",
            "matches user",
            "synopsis",
            "lastname",
            "firstname",
            "apple computer",
            "tcpip",
            "supported",
            "quantum",
            "facility",
            "level",
            "level info",
            "broadcast",
            "ignore",
            "rules",
            "sender",
            "automounter map",
            "use directory",
            "get home",
            "home autohome",
            "true",
            "t option",
            "mount",
            "force",
            "environment",
            "automountdenv",
            "promptcommand",
            "shellsessiondir",
            "histfile",
            "histfilesize",
            "myvar",
            "histtimeformat",
            "arrange",
            "bashrematch",
            "tell",
            "ps1h",
            "make bash",
            "s checkwinsize",
            "etcbashrc",
            "termprogram",
            "inpck",
            "nnnbaud",
            "berkeley",
            "parity",
            "pc entry",
            "pass8",
            "parenb istrip",
            "fixed speed",
            "entry",
            "clocal mode",
            "maxhistsize",
            "promptmode",
            "verbose end",
            "etcirbrcloaded",
            "default",
            "setup",
            "history file",
            "kernel",
            "readline",
            "jabber",
            "group database",
            "dovecot",
            "postfix scsd",
            "networkd",
            "searchpaths",
            "freebsd",
            "tmpdir",
            "fcodes",
            "prunepaths",
            "vartmp",
            "prunedirs",
            "filesystems",
            "nroff",
            "manpath",
            "uncomment",
            "manpager",
            "whatispager",
            "manlocale",
            "every",
            "manpath optman",
            "maybe",
            "troff",
            "status mailfrom",
            "returnpath via",
            "pidfile",
            "flags",
            "bcgjnuwz",
            "bin usrsbin",
            "sbin",
            "default pf",
            "care",
            "audio",
            "user database",
            "unix copy",
            "gate daemon",
            "bashno",
            "r etcbashrc",
            "rfc1323",
            "m1460",
            "macos x",
            "signature",
            "linux",
            "opera",
            "xp sp1",
            "windows sp1",
            "nmap syn",
            "m265",
            "synack",
            "mind",
            "macos",
            "warp",
            "ipv6",
            "internet",
            "icmp",
            "cisco",
            "monitoring",
            "argus",
            "chaos",
            "rsvp",
            "encapsulation",
            "aris",
            "isis",
            "netbootmount",
            "netbootshadow",
            "computername",
            "localonly",
            "localnetbootdir",
            "netboot",
            "define",
            "purpose",
            "networkonly",
            "waiting",
            "networkup",
            "term",
            "devnull",
            "common setup",
            "configure",
            "set command",
            "dns hostname",
            "dns query",
            "see also",
            "kame",
            "sunnet manager",
            "rpcsrc",
            "netlicense",
            "ftpd",
            "bindash binksh",
            "binsh bintcsh",
            "jumpcloud ldap",
            "smb2",
            "security",
            "workgroup",
            "standalone",
            "samba server",
            "enforce",
            "smb3",
            "example share",
            "improper use",
            "ctrlc",
            "none",
            "fax reception",
            "hardwired",
            "0007",
            "must",
            "visudo",
            "blocksize",
            "charset lang",
            "language lcall",
            "lines columns",
            "lscolors",
            "sshauthsock",
            "orion",
            "setup user",
            "home",
            "zdotdir",
            "delete",
            "beep",
            "vendor",
            "kf10",
            "kf11",
            "kf12",
            "kf13",
            "backspace",
            "insert",
            "resume",
            "termsessionid",
            "savehist",
            "sharehistory",
            "h do",
            "volume",
            "de l",
            "l uuid",
            "m tra",
            "n est",
            "suuid",
            "prfen",
            "fusion",
            "syst",
            "look",
            "executant",
            "alla",
            "over",
            "test",
            "overie",
            "zapis",
            "rapid",
            "disco usa",
            "de macos",
            "nie s",
            "i denne",
            "adgjmpsvx",
            "diskgthis disk",
            "01k8x j",
            "34disk",
            "levy kytt",
            "dict",
            "array",
            "plist",
            "apple root",
            "code signing",
            "inode64r",
            "xofkoxzh",
            "integer",
            "doctype",
            "brain",
            "abcd",
            "ogwo",
            "boaw",
            "cobwa",
            "uhawavauatsh",
            "ip bitmap",
            "foewdc",
            "could",
            "ip block",
            "funcs",
            "cogwo",
            "trash",
            "double",
            "hunt",
            "affa",
            "carr",
            "crypto",
            "docwbac",
            "q1b0",
            "q1 0",
            "h h5",
            "docwbag",
            "slice",
            "format",
            "zero",
            "alfa",
            "hera",
            "lelei",
            "hehe",
            "hisp",
            "fail",
            "katy",
            "zakk",
            "eodwcbgao",
            "hhk8di",
            "alma",
            "topo",
            "open",
            "huhk",
            "piper",
            "hehx",
            "eh ui",
            "h20hph",
            "hif h",
            "hmhhihqhyla hq",
            "r11b0",
            "target",
            "uus10u",
            "hifh",
            "loghookfailed",
            "loghook",
            "hell",
            "q1b 0",
            "f duh",
            "aqw1",
            "1160"
          ],
          "references": [
            "index.html.en",
            "bind.html",
            "caching.html",
            "BUILDING",
            "configuring.html",
            "content-negotiation.html",
            "custom-error.html",
            "convenience.map",
            "LDAP.tbd",
            "lber.h",
            "ldap.h",
            "LocalAuthentication.tbd",
            "arm64e-apple-macos.swiftinterface",
            "x86_64-apple-ios-macabi.swiftinterface",
            "arm64e-apple-ios-macabi.swiftinterface",
            "x86_64-apple-macos.swiftinterface",
            "MultipeerConnectivity.tbd",
            "module.modulemap",
            "MCNearbyServiceAdvertiser.h",
            "MCPeerID.h",
            "MCError.h",
            "MCNearbyServiceBrowser.h",
            "MCAdvertiserAssistant.h",
            "MultipeerConnectivity.apinotes",
            "MultipeerConnectivity.h",
            "MCSession.h",
            "MCBrowserViewController.h",
            "dbivport.h",
            "dbi_sql.h",
            "dbd_xsh.h",
            "dbixs_rev.h",
            "Driver_xst.h",
            "DBIXS.h",
            "hook_op_check.h",
            "Admin.tbd",
            "AirPlayReceiver.tbd",
            "apfs_boot_mount.tbd",
            "AOSKit.tbd",
            "APConfigurationSystem.tbd",
            "AppleFirmwareUpdate.tbd",
            "launchdaemons.txt",
            "preboot_archive_errors.log",
            "mounts.txt",
            "launchagents.txt",
            "disk_structure.txt",
            "user_launchagents.txt",
            "security_status.txt",
            "kexts.txt",
            "process_list.txt",
            "battery.csv",
            "diskEncryption.csv",
            "chromeExtensions.csv",
            "crashes.csv",
            "interfaceAddrs.csv",
            "kernel.csv",
            "interfaceDetails.csv",
            "etcHosts.csv",
            "applications.csv",
            "mounts.csv",
            "sharedFolders.csv",
            "certificates.csv",
            "sharingPreferences.csv",
            "launchD.csv",
            "usbDevices.csv",
            "managedPolicies.csv",
            "systemInfo.csv",
            "users.csv",
            "sipConfig.csv",
            "systemControls.csv",
            "canonical",
            "aliases",
            "custom_header_checks",
            "access",
            "bounce.cf.default",
            "generic",
            "header_checks",
            "main.cf.default",
            "LICENSE",
            "makedefs.out",
            "main.cf",
            "master.cf.default",
            "main.cf.proto",
            "master.cf.proto",
            "master.cf",
            "TLS_LICENSE",
            "postfix-files",
            "transport",
            "virtual",
            "relocated",
            "afpovertcp.cfg",
            "asl.conf",
            "auto_home",
            "auto_master",
            "autofs.conf",
            "bashrc_Apple_Terminal",
            "com.apple.screensharing.agent.launchd",
            "bashrc",
            "command_args.json",
            "csh.cshrc",
            "csh.login",
            "find.codes",
            "csh.logout",
            "ftpusers",
            "gettytab",
            "irbrc",
            "kern_loader.conf",
            "group",
            "locate.rc",
            "man.conf",
            "mail.rc",
            "manpaths",
            "networks",
            "nfs.conf",
            "newsyslog.conf",
            "ntp_opendirectory.conf",
            "ntp.conf",
            "notify.conf",
            "paths",
            "pf.conf",
            "passwd",
            "profile",
            "pf.os",
            "protocols",
            "rc.netboot",
            "rc.common",
            "rmtab",
            "resolv.conf",
            "rtadvd.conf",
            "rpc",
            "shells",
            "smb.conf",
            "sudo_lecture",
            "ttys",
            "syslog.conf",
            "xtab",
            "sudoers",
            "zprofile",
            "zshrc",
            "zshrc_Apple_Terminal",
            "CodeResources",
            "version.plist",
            "Info.plist"
          ],
          "public": 1,
          "adversary": "DragonForce Malaysia Hacker Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lastname",
              "display_name": "Lastname",
              "target": null
            },
            {
              "id": "Firstname",
              "display_name": "Firstname",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 66,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ilyailya",
            "id": "298851",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 4449,
            "domain": 3847,
            "URL": 14263,
            "FileHash-SHA256": 2356,
            "FileHash-MD5": 223,
            "FileHash-SHA1": 523,
            "email": 223,
            "CVE": 40,
            "CIDR": 12,
            "SSLCertFingerprint": 302
          },
          "indicator_count": 26238,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 37,
          "modified_text": "384 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6710059101b736e38b9cd2b0",
          "name": "Black Basta",
          "description": "Black Basta is a financially motivated ransomware group that began operations in 2022. It targets organizations across various sectors, including manufacturing, healthcare, and finance, using a double extortion method. The group encrypts victims' systems and threatens to leak stolen data unless a ransom is paid. Their ransomware spreads via phishing campaigns, exploiting vulnerabilities in systems. Black Basta is known for collaborating with other cybercriminals, which enhances the impact and sophistication of their attacks.",
          "modified": "2024-11-15T17:03:59.652000",
          "created": "2024-10-16T18:27:29.179000",
          "tags": [
            "strong",
            "black basta",
            "cisa",
            "powershell",
            "ransomware",
            "cobalt strike",
            "phishing",
            "mimikatz",
            "qakbot",
            "psexec",
            "bits",
            "webdav",
            "winscp",
            "conti",
            "anydesk",
            "quick assist",
            "netsupport",
            "windows",
            "blackbasta",
            "batloader",
            "rclone",
            "vmware esxi",
            "netcat",
            "qbot",
            "emotet",
            "trickbot",
            "pinkslipbot",
            "team",
            "C++",
            "Linux",
            "ChaCha20",
            "RSA-4096",
            "ConnectWise",
            "ZeroLogon",
            "NoPac",
            "PrintNightmare",
            "CVE-2024-1709",
            "CVE-2024-26169",
            "CVE-2020-1472",
            "CVE-2021-42278",
            "CVE-2021-42287",
            "CVE-2021-34527",
            "BITSAdmin",
            "Cobalt Strike",
            "Netcat",
            "ScreenConnect",
            "NetSupport Manager",
            "SystemBC",
            "Qakbot",
            "WMI",
            "RClone",
            "SoftPerfect",
            "BackStab",
            "EvilProxy",
            "Splashtop",
            "WinSCP",
            "C2",
            "CVE-2022-30190",
            "Storm-1811",
            "spear phishing",
            "Coroxy",
            "cobeacon",
            "RaaS",
            "aa24-131a",
            "wandering spider",
            "Conti",
            "wizard spider",
            "BGH"
          ],
          "references": [
            "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a",
            "https://blog.qualys.com/vulnerabilities-threat-research/2024/09/19/black-basta-ransomware-what-you-need-to-know",
            "https://www.rapid7.com/blog/post/2024/05/10/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators/",
            "https://darktrace.com/blog/black-basta-old-dogs-with-new-tricks",
            "https://www.fortinet.com/blog/threat-research/ransomware-roundup-black-basta",
            "https://www.cybereason.com/blog/threat-alert-aggressive-qakbot-campaign-and-the-black-basta-ransomware-group-targeting-u.s.-companies",
            "https://www.cve.org/CVERecord?id=CVE-2020-1472",
            "https://www.cve.org/CVERecord?id=CVE-2021-34527",
            "https://www.cve.org/CVERecord?id=CVE-2021-42278",
            "https://www.cve.org/CVERecord?id=CVE-2021-42287",
            "https://www.cve.org/CVERecord?id=CVE-2024-1709",
            "https://www.cve.org/CVERecord?id=CVE-2024-26169",
            "https://www.cve.org/CVERecord?id=CVE-2022-30190",
            "https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/",
            "https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/",
            "https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbasta"
          ],
          "public": 1,
          "adversary": "Black Basta",
          "targeted_countries": [
            "United States of America",
            "Germany",
            "Canada",
            "Australia",
            "New Zealand",
            "Japan",
            "France",
            "United Kingdom of Great Britain and Northern Ireland",
            "Italy",
            "Switzerland"
          ],
          "malware_families": [
            {
              "id": "Conti",
              "display_name": "Conti",
              "target": null
            },
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Black Basta",
              "display_name": "Black Basta",
              "target": null
            },
            {
              "id": "Primary NetSupport",
              "display_name": "Primary NetSupport",
              "target": null
            },
            {
              "id": "NetSupport",
              "display_name": "NetSupport",
              "target": null
            },
            {
              "id": "Basta Linux",
              "display_name": "Basta Linux",
              "target": null
            },
            {
              "id": "Widespread QBot",
              "display_name": "Widespread QBot",
              "target": null
            },
            {
              "id": "Qbot",
              "display_name": "Qbot",
              "target": null
            },
            {
              "id": "TrojanDownloader:O97M/Qakbot",
              "display_name": "TrojanDownloader:O97M/Qakbot",
              "target": "/malware/TrojanDownloader:O97M/Qakbot"
            },
            {
              "id": "Trojan:Win32/QBot",
              "display_name": "Trojan:Win32/QBot",
              "target": "/malware/Trojan:Win32/QBot"
            },
            {
              "id": "Trojan:Win32/Qakbot",
              "display_name": "Trojan:Win32/Qakbot",
              "target": "/malware/Trojan:Win32/Qakbot"
            },
            {
              "id": "TrojanSpy:Win32/Qakbot",
              "display_name": "TrojanSpy:Win32/Qakbot",
              "target": "/malware/TrojanSpy:Win32/Qakbot"
            },
            {
              "id": "Behavior:Win32/Qakbot",
              "display_name": "Behavior:Win32/Qakbot",
              "target": "/malware/Behavior:Win32/Qakbot"
            },
            {
              "id": "Behavior:Win32/Basta",
              "display_name": "Behavior:Win32/Basta",
              "target": "/malware/Behavior:Win32/Basta"
            },
            {
              "id": "Ransom:Win32/Basta",
              "display_name": "Ransom:Win32/Basta",
              "target": "/malware/Ransom:Win32/Basta"
            },
            {
              "id": "Trojan:Win32/Basta",
              "display_name": "Trojan:Win32/Basta",
              "target": "/malware/Trojan:Win32/Basta"
            },
            {
              "id": "Behavior:Win32/CobaltStrike",
              "display_name": "Behavior:Win32/CobaltStrike",
              "target": "/malware/Behavior:Win32/CobaltStrike"
            },
            {
              "id": "Backdoor:Win64/CobaltStrike",
              "display_name": "Backdoor:Win64/CobaltStrike",
              "target": "/malware/Backdoor:Win64/CobaltStrike"
            },
            {
              "id": "HackTool:Win64/CobaltStrike",
              "display_name": "HackTool:Win64/CobaltStrike",
              "target": "/malware/HackTool:Win64/CobaltStrike"
            },
            {
              "id": "TrojanDropper:PowerShell/Cobacis",
              "display_name": "TrojanDropper:PowerShell/Cobacis",
              "target": "/malware/TrojanDropper:PowerShell/Cobacis"
            },
            {
              "id": "Trojan:Win64/TurtleLoader.CS",
              "display_name": "Trojan:Win64/TurtleLoader.CS",
              "target": "/malware/Trojan:Win64/TurtleLoader.CS"
            },
            {
              "id": "Exploit:Win32/ShellCode.BN",
              "display_name": "Exploit:Win32/ShellCode.BN",
              "target": "/malware/Exploit:Win32/ShellCode.BN"
            },
            {
              "id": "Behavior:Win32/SystemBC",
              "display_name": "Behavior:Win32/SystemBC",
              "target": "/malware/Behavior:Win32/SystemBC"
            },
            {
              "id": "Trojan: Win32/SystemBC",
              "display_name": "Trojan: Win32/SystemBC",
              "target": "/malware/Trojan: Win32/SystemBC"
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1531",
              "name": "Account Access Removal",
              "display_name": "T1531 - Account Access Removal"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1550",
              "name": "Use Alternate Authentication Material",
              "display_name": "T1550 - Use Alternate Authentication Material"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1570",
              "name": "Lateral Tool Transfer",
              "display_name": "T1570 - Lateral Tool Transfer"
            },
            {
              "id": "T1572",
              "name": "Protocol Tunneling",
              "display_name": "T1572 - Protocol Tunneling"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1185",
              "name": "Man in the Browser",
              "display_name": "T1185 - Man in the Browser"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1187",
              "name": "Forced Authentication",
              "display_name": "T1187 - Forced Authentication"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1195",
              "name": "Supply Chain Compromise",
              "display_name": "T1195 - Supply Chain Compromise"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            }
          ],
          "industries": [
            "Critical Infrastructure",
            "Healthcare",
            "Manufacturing",
            "Construction",
            "Retail",
            "Legal",
            "Finance",
            "Technology",
            "Emergency Services",
            "Media",
            "Transportation"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 52,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "v0od0o.exe",
            "id": "273579",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 111,
            "FileHash-SHA1": 110,
            "FileHash-SHA256": 148,
            "CVE": 7,
            "domain": 113,
            "hostname": 62,
            "URL": 4
          },
          "indicator_count": 555,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 27,
          "modified_text": "561 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "672025a446db1f324cbda420",
          "name": "Katz and Mouse Game:  MaaS Infostealers Adapt to Patched Chrome Defenses \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2024-10-29T00:00:36.726000",
          "created": "2024-10-29T00:00:36.726000",
          "tags": [
            "chrome",
            "stealc",
            "lumma",
            "google",
            "september",
            "chromekatz",
            "google chrome",
            "chrome process",
            "windows",
            "july",
            "team",
            "vidar",
            "metastealer",
            "legacy"
          ],
          "references": [
            "https://www.elastic.co/security-labs/katz-and-mouse-game"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ChrisTan0",
            "id": "262536",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 2,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 5,
            "YARA": 1,
            "domain": 4
          },
          "indicator_count": 15,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 42,
          "modified_text": "579 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66ed3d4f6c14a7f20638ec81",
          "name": "Black Basta Ransomware: What You Need to Know | Qualys Security Blog",
          "description": "Black Basta is a ransomware-as-a-service group operating as a service and is known to exploit vulnerabilities and vulnerabilities to gain access to critical systems and data, according to Qualys.",
          "modified": "2024-09-20T09:15:59.733000",
          "created": "2024-09-20T09:15:59.733000",
          "tags": [
            "black basta",
            "appdata",
            "qualys edr",
            "qakbot",
            "cobalt strike",
            "response",
            "xxxxxx",
            "ransom note",
            "mitre att",
            "overview black",
            "april",
            "defender",
            "systembc",
            "mimikatz",
            "winscp",
            "mega",
            "ransomware",
            "powershell",
            "boom",
            "fin7",
            "conti"
          ],
          "references": [
            "https://blog.qualys.com/vulnerabilities-threat-research/2024/09/19/black-basta-ransomware-what-you-need-to-know"
          ],
          "public": 1,
          "adversary": "FIN7",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Conti",
              "display_name": "Conti",
              "target": null
            },
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Black Basta",
              "display_name": "Black Basta",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            }
          ],
          "industries": [
            "Critical Infrastructure"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 59,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 81,
            "CVE": 6,
            "domain": 25
          },
          "indicator_count": 230,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 865,
          "modified_text": "617 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "667a92f2267424e1b819a68a",
          "name": "GrimResource - Microsoft Management Console for initial access and evasion \u2014 Elastic Security Labs",
          "description": "A novel, in-the-wild code execution technique leveraging Microsoft Management Console files (MSC) has been identified by Elastic Security researchers and was first spotted in the wild in June 2016 and is currently being investigated by VirusTotal.",
          "modified": "2024-06-25T09:50:42.069000",
          "created": "2024-06-25T09:50:42.069000",
          "tags": [
            "msc file",
            "vbscript",
            "mmc console",
            "grimresource",
            "console",
            "pastaloader",
            "execution",
            "windows script",
            "rwx memory",
            "jscript",
            "june",
            "virustotal",
            "cobalt strike"
          ],
          "references": [
            "https://www.elastic.co/security-labs/grimresource"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "bluenumberone",
            "id": "246058",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 3
          },
          "indicator_count": 8,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "704 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65b239b451841d46725b938a",
          "name": "New Go-based Malware Loader Discovered I Arctic Wolf",
          "description": "Arctic Wolf Solutions offers a comprehensive guide to how to prevent cyber attacks, as well as the best ways to protect your own IT environment from the growing threat of malware and other cyber-threats.",
          "modified": "2024-02-24T10:01:25.769000",
          "created": "2024-01-25T10:36:36.809000",
          "tags": [
            "cherryloader",
            "arctic wolf",
            "printspoofer",
            "juicypotatong",
            "path",
            "python script",
            "encrypted",
            "decrypted",
            "ip address",
            "xor loop",
            "rijndael",
            "restart"
          ],
          "references": [
            "https://arcticwolf.com/resources/blog/cherryloader-a-new-go-based-loader-discovered-in-recent-intrusions/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "CherryLoader",
              "display_name": "CherryLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 4,
            "FileHash-SHA256": 10,
            "domain": 2
          },
          "indicator_count": 16,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "826 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c37c54dd9e78f85c0fa",
          "name": "\u7ea2\u674f\u89c6\u9891 malware",
          "description": "",
          "modified": "2023-12-06T14:59:03.859000",
          "created": "2023-12-06T14:59:03.859000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1686,
            "hostname": 2218,
            "URL": 5740,
            "domain": 901,
            "FileHash-MD5": 3
          },
          "indicator_count": 10548,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65607608c2de990f5f2065e4",
          "name": "Elastic catches DPRK passing out KANDYKORN \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2023-12-04T07:05:12.406000",
          "created": "2023-11-24T10:08:08.673000",
          "tags": [
            "sugarloader",
            "command",
            "kandykorn",
            "lazarus group",
            "discord",
            "eql query",
            "dprk",
            "c2 server",
            "google drive",
            "ref7001",
            "python",
            "virustotal",
            "dropper",
            "loader",
            "swift",
            "kill",
            "model",
            "malware",
            "lazarus",
            "macos",
            "findertools"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "SUGARLOADER",
              "display_name": "SUGARLOADER",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1008",
              "name": "Fallback Channels",
              "display_name": "T1008 - Fallback Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6545ee2587c61e9e6e119c43",
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "santravault1",
            "id": "217419",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_217419/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 3,
            "URL": 2,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 18,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 75,
          "modified_text": "908 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6545ee0e27e6274f9e66b973",
          "name": "Elastic catches DPRK passing out KANDYKORN \u2014 Elastic Security Labs",
          "description": "A novel intrusion targeting blockchain engineers of a crypto exchange platform was carried out by the Democratic Republic of Korea (D DPRK), according to Elastic Security Labs, who identified the North Korean state as the Lazarus Group.",
          "modified": "2023-12-04T07:05:12.406000",
          "created": "2023-11-04T07:09:02.366000",
          "tags": [
            "sugarloader",
            "command",
            "kandykorn",
            "lazarus group",
            "discord",
            "eql query",
            "dprk",
            "c2 server",
            "google drive",
            "ref7001",
            "python",
            "virustotal",
            "dropper",
            "loader",
            "swift",
            "kill",
            "model",
            "malware",
            "lazarus",
            "macos",
            "findertools"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "SUGARLOADER",
              "display_name": "SUGARLOADER",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1008",
              "name": "Fallback Channels",
              "display_name": "T1008 - Fallback Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 3,
            "URL": 2,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 18,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "908 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6545ee2587c61e9e6e119c43",
          "name": "Elastic catches DPRK passing out KANDYKORN \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2023-12-04T07:05:12.406000",
          "created": "2023-11-04T07:09:25.543000",
          "tags": [
            "sugarloader",
            "command",
            "kandykorn",
            "lazarus group",
            "discord",
            "eql query",
            "dprk",
            "c2 server",
            "google drive",
            "ref7001",
            "python",
            "virustotal",
            "dropper",
            "loader",
            "swift",
            "kill",
            "model",
            "malware",
            "lazarus",
            "macos",
            "findertools"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "SUGARLOADER",
              "display_name": "SUGARLOADER",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1008",
              "name": "Fallback Channels",
              "display_name": "T1008 - Fallback Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6545ee0e27e6274f9e66b973",
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 3,
            "URL": 2,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 18,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 276,
          "modified_text": "908 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65424d2787b756c2301208df",
          "name": "Elastic catches DPRK passing out KANDYKORN \u2014 Elastic Security Labs",
          "description": "A novel intrusion targeting blockchain engineers of a crypto exchange platform was carried out by the Democratic Republic of Korea (D DPRK), according to Elastic Security Labs, who identified the North Korean state as the Lazarus Group.",
          "modified": "2023-12-01T13:00:03.967000",
          "created": "2023-11-01T13:05:43.927000",
          "tags": [
            "sugarloader",
            "command",
            "kandykorn",
            "lazarus group",
            "discord",
            "eql query",
            "dprk",
            "c2 server",
            "google drive",
            "ref7001",
            "python",
            "virustotal",
            "dropper",
            "loader",
            "write",
            "june",
            "jokerspy",
            "swift",
            "kill",
            "april",
            "model",
            "malware",
            "lazarus",
            "macos",
            "findertools"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "macOS",
              "display_name": "macOS",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "SUGARLOADER",
              "display_name": "SUGARLOADER",
              "target": null
            },
            {
              "id": "FinderTools",
              "display_name": "FinderTools",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1008",
              "name": "Fallback Channels",
              "display_name": "T1008 - Fallback Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 3,
            "URL": 3,
            "domain": 4,
            "hostname": 9
          },
          "indicator_count": 20,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 864,
          "modified_text": "911 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64520cce3fe76f7af80a6cda",
          "name": "Elastic Security Labs discovers the LOBSHOT malware | Elastic",
          "description": "",
          "modified": "2023-05-03T07:27:10.400000",
          "created": "2023-05-03T07:27:10.400000",
          "tags": [
            "lobshot",
            "security labs",
            "google ads",
            "hidden virtual",
            "yara signature"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6450b06a0dd67d58d571eaf8",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1,
            "IPv4": 1,
            "URL": 1,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 9,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "1123 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6450b06a0dd67d58d571eaf8",
          "name": "Elastic Security Labs discovers the LOBSHOT malware | Elastic",
          "description": "",
          "modified": "2023-05-02T06:40:42.269000",
          "created": "2023-05-02T06:40:42.269000",
          "tags": [
            "lobshot",
            "security labs",
            "google ads",
            "hidden virtual",
            "yara signature"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1,
            "IPv4": 1,
            "URL": 1,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 9,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1124 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62606584633e2b9a3bc935b9",
          "name": "\u7ea2\u674f\u89c6\u9891 malware",
          "description": "function s(t,e), o, is a new type of function, which throws new TypeError when it comes to trying to make a function out of its own language or its form.",
          "modified": "2022-05-20T00:01:19.453000",
          "created": "2022-04-20T19:56:52.162000",
          "tags": [
            "typeof t",
            "typeof define",
            "moztransform",
            "success",
            "error",
            "make sure",
            "stop",
            "ajax",
            "action",
            "click",
            "open",
            "active",
            "button",
            "toggle btn",
            "body",
            "scroll",
            "isotope",
            "preloader",
            "function",
            "javascript",
            "mit license",
            "typeof module",
            "gplv3",
            "license",
            "copyright",
            "metafizzy",
            "math",
            "typeof",
            "typeerror",
            "hidden",
            "show",
            "typeof n",
            "version",
            "hide",
            "focusin",
            "focusout",
            "shown",
            "startr",
            "endr",
            "federico zivolo",
            "distributed",
            "html",
            "statict",
            "flip",
            "regexp",
            "null",
            "void",
            "width",
            "object",
            "pseudo",
            "child",
            "class",
            "date",
            "accept",
            "webpackrequire",
            "name",
            "number",
            "arraybuffer",
            "iterator",
            "typedarray",
            "prototype",
            "string",
            "index",
            "meta",
            "target",
            "infinity",
            "zero",
            "epsilon",
            "observer",
            "android",
            "trim",
            "enumerate",
            "freeze",
            "internal",
            "bind",
            "window",
            "next",
            "find",
            "this",
            "rest",
            "middle",
            "canvas",
            "slidercaptcha",
            "createelement",
            "textdanger",
            "plugin",
            "rgba",
            "imagedata",
            "false",
            "touchstart",
            "trident",
            "applewebkit",
            "safari",
            "base",
            "presto",
            "gecko",
            "khtml",
            "micromessenger",
            "typeof e",
            "swiper",
            "most",
            "september",
            "customevent",
            "image",
            "typeof c",
            "twitter",
            "bootstrap",
            "rolemenu",
            "typeof f",
            "typeof g",
            "cookie plugin",
            "https",
            "klaus hartl",
            "register",
            "nodecommonjs",
            "factory",
            "jquery",
            "write",
            "typeof b",
            "array",
            "sufeffxa0",
            "attr",
            "\u706b\u7bad\u5185\u6d4b\u7b7e\u540d",
            "0x1d9131",
            "0x180bcc",
            "0x4b6177",
            "0x13f349",
            "0x3bcb54",
            "0xbbe80d",
            "0x57b7de",
            "0x2ea74e",
            "0x4fb0f2",
            "0x25f113",
            "push",
            "shift",
            "tencent",
            "barrio",
            "slice",
            "symbol",
            "typeof window",
            "maximum",
            "typeof symbol",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "ufe0fg",
            "ud83dudc6cud83c",
            "ud83dudc6dud83c",
            "welcome",
            "datav66d78640",
            "datav2f8052f5",
            "90deg",
            "datav5f1e575c",
            "datave97d7462",
            "helvetica neue",
            "helvetica",
            "10px",
            "pingfang sc",
            "arial",
            "45deg",
            "typenumber",
            "opacity0",
            "mozopacity0",
            "khtmlopacity0",
            "opacity100",
            "event",
            "boolean",
            "uint8array",
            "errordetails",
            "info",
            "checker",
            "generator",
            "blink",
            "keepalive",
            "4096",
            "unknown",
            "meteor",
            "rhino",
            "mini",
            "comment",
            "verify",
            "yeke",
            "codec",
            "media",
            "live",
            "speed",
            "headname",
            "axiostimeout",
            "apiurl",
            "bmi86hjtsk",
            "root",
            "length",
            "indexof",
            "x0ax20x20x20x20",
            "location",
            "0x10",
            "0x18",
            "history",
            "config",
            "cookie",
            "onload",
            "video",
            "afunction",
            "indexnotice",
            "sitehome",
            "x20trnf",
            "please",
            "strong"
          ],
          "references": [
            "xfe-URL-sys95.com-stix2-2.1-export.json",
            "https://2001.habyc.com/?channelNo=2001#/home",
            "https://sdk.51.la/event/js-sdk-event.min.js?u=JdoUNv3VSW0GHUpw",
            "https://2001.habyc.com/static/js/chunk-7d5d3bac.efb700c7.js",
            "https://sdk.51.la/js-sdk-pro.min.js",
            "https://2001.habyc.com/js/config.js",
            "xfe-URL-2001.habyc.com-stix2-2.1-export.json",
            "https://2001.habyc.com/static/js/chunk-vendors.9d7684f4.js",
            "xfe-URL-habyc.com-stix2-2.1-export.json",
            "https://2001.habyc.com/static/css/chunk-vendors.6a41b67e.css",
            "https://2001.habyc.com/static/css/app.88afcfd8.css",
            "https://2001.habyc.com/static/css/chunk-7d5d3bac.e1a32335.css",
            "https://2001.dwlww.com/?channelNo=2001#/home",
            "https://2001.dwlww.com/static/js/chunk-7d5d3bac.efb700c7.js",
            "https://2001.dwlww.com/js/config.js",
            "https://2001.dwlww.com/static/js/chunk-vendors.9d7684f4.js",
            "https://2001.dwlww.com/static/js/app.9d5d18d7.js",
            "https://2001.dwlww.com/static/css/chunk-vendors.6a41b67e.css",
            "https://2001.dwlww.com/static/css/app.88afcfd8.css",
            "https://2001.dwlww.com/static/css/chunk-7d5d3bac.e1a32335.css",
            "https://www.tidio.com/talk/kv6vcosd7tmhsetmarsoawzaglejnny4",
            "https://chatting.page/kv6vcosd7tmhsetmarsoawzaglejnny4",
            "https://widget-v4.tidiochat.com/code/kv6vcosd7tmhsetmarsoawzaglejnny4.js",
            "https://m4244.com:35003/",
            "https://www.8098.app:21568/?agent=7691755704",
            "https://www.8098.app:21568/js/jquery-1.11.3.min.js",
            "https://www.8098.app:21568/js/xinstall_inner_e.min.js?v=1004",
            "https://app.ynsdty.cn//package/GmCC6WISh",
            "https://app.ynsdty.cn/dist/js/jquery.min.js",
            "https://app.ynsdty.cn/dist/js/jquery.cookie.js",
            "https://app.ynsdty.cn/dist/vendors/bootstrap/js/bootstrap.min.js",
            "https://app.ynsdty.cn/dist/vendors/swiper/swiper.min.js",
            "https://app.ynsdty.cn/dist/js/app.base.js",
            "https://app.ynsdty.cn/dist/js/longbow.slidercaptcha.js",
            "https://app.ynsdty.cn/dist/vendors/core-js/core.js",
            "xfe-URL-sun.net.hk-stix2-2.1-export.json",
            "https://www.sunnetwork.com.sg/sun_21/js/vendor/jquery-3.5.0.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/popper.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/bootstrap.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/isotope.pkgd.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/imagesloaded.pkgd.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/main.js",
            "https://www.sunnetwork.com.sg/sun_21/js/ajax-form.js",
            "https://www.sunnetwork.com.sg/sun_21/js/slick.min.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 901,
            "URL": 5740,
            "hostname": 2218,
            "FileHash-SHA256": 1686,
            "FileHash-MD5": 3
          },
          "indicator_count": 10548,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1472 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625028edfe0ff22af87b9d66",
          "name": "Virustotal.com",
          "description": "If you want to know how to delete an object from your browser, try these three-second-long, four-point-result-results-free-to-get-it-out-the-objectIterator.",
          "modified": "2022-04-08T12:22:05.307000",
          "created": "2022-04-08T12:22:05.307000",
          "tags": [
            "symbol",
            "object",
            "string",
            "denis pushkarev",
            "json",
            "corejs",
            "source",
            "etrt",
            "atfunction",
            "stfunction",
            "error",
            "typeerror",
            "asynciterator",
            "generator",
            "typeof l",
            "nonce",
            "script",
            "please do",
            "not copy",
            "and paste",
            "this code",
            "cgrecaptchacfg",
            "ngrecaptcha",
            "recaptchaapi",
            "render",
            "waaa",
            "bufferwriter",
            "bufferreader",
            "qace",
            "search",
            "cafebabe",
            "c2c url",
            "jgfunilwcpc",
            "gmbh",
            "return",
            "freemium gmbh",
            "open xml",
            "virustotal",
            "keep learning",
            "select",
            "uint8array",
            "array",
            "null",
            "function",
            "math",
            "edge",
            "number",
            "date",
            "this",
            "verify",
            "android",
            "iframe",
            "void",
            "trident",
            "span",
            "form",
            "click",
            "enterprise",
            "infinity",
            "template",
            "next",
            "body"
          ],
          "references": [
            "https://www.gstatic.com/recaptcha/releases/Y-cOIEkAqcfDdup_qnnmkxIC/recaptcha__en.js",
            "https://www.virustotal.com/gui/main.6d41e0dc139508f21963.js",
            "https://www.recaptcha.net/recaptcha/api.js?render=explicit",
            "https://www.virustotal.com/gui/polyfills/regenerator-runtime.95dc763885f05111a2f88232a2d0cf2d.js",
            "https://www.virustotal.com/gui/polyfills/core-js.c92df5c57caa3e436cd3ef38e4b4f503.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "WAAA",
              "display_name": "WAAA",
              "target": null
            },
            {
              "id": "QACE",
              "display_name": "QACE",
              "target": null
            },
            {
              "id": "BufferReader",
              "display_name": "BufferReader",
              "target": null
            },
            {
              "id": "BufferWriter",
              "display_name": "BufferWriter",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 392,
            "URL": 1356,
            "domain": 330,
            "FileHash-SHA256": 177
          },
          "indicator_count": 2255,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1513 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "624a5795ec3cb505e626ba10",
          "name": "ylnedriuopegrle33689.org is the WAF",
          "description": "function m(b,c,e) is a new type of Float32Array, which can be used as a \"flip-flap\" to create new units for each of its three functions.",
          "modified": "2022-04-04T02:27:33.664000",
          "created": "2022-04-04T02:27:33.664000",
          "tags": [
            "typeof o",
            "datavde206a4a",
            "span",
            "helvetica neue",
            "135deg",
            "2022 2022",
            "webkitkeyframes",
            "90deg",
            "font awesome",
            "license",
            "font",
            "object",
            "boolean",
            "string",
            "number",
            "refresh",
            "viewbox",
            "dxeu",
            "nrt3",
            "uszq",
            "dmi4",
            "error",
            "imel",
            "date",
            "regexp",
            "left",
            "typeof h",
            "array",
            "color x",
            "y blur",
            "shapiro",
            "shim",
            "hooks",
            "alpha",
            "green",
            "d9d9d9",
            "n color",
            "datav71159637",
            "datav9306cb64",
            "info",
            "android",
            "canvas"
          ],
          "references": [
            "http://ylnedriuopegrle33689.org/mobile/static/lib/velocity.min.js",
            "http://ylnedriuopegrle33689.org/mobile/static/js/0.fc97dceb0dbb60948b0f.js",
            "http://ylnedriuopegrle33689.org/mobile/static/css/app.726f146ac9040074723077dbffe13bf7.css",
            "http://ylnedriuopegrle33689.org/mobile/static/js/app.9074e5240bf3d0f7b264.js",
            "http://ylnedriuopegrle33689.org/mobile/static/js/manifest.2cf63ac462750c8b3a2f.js",
            "http://ylnedriuopegrle33689.org/mobile/static/js/151.f5cad57280238b18aa58.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 99,
            "URL": 495,
            "hostname": 153,
            "FileHash-SHA256": 79
          },
          "indicator_count": 826,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1518 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI",
        "https://www.sunnetwork.com.sg/sun_21/js/isotope.pkgd.min.js",
        "https://vtbehaviour.commondatastorage.googleapis.com/2533042959ad1fe050d14ab7536126910a2d240992bff397640382472b6a7c69_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469608&Signature=fK1I2%2FxXVm0l3ZiELwtstes8iVN402Ww%2By%2BgvxYOB0LiC2iO3J9cedWJk1hMIr4IfLSGKprfui8vANzR%2BkWfSd594S%2FFe9A59YKyOA2MFmQTBRXVy6O3xF1e1lPETp5Md%2FbGJCOzrZxdHyReyuk7cgdDDBAewptjJhfTYxql7F9X%2FB4qe9BYWPrvned2fFWfU%2F4G%2F4UBqY9Jj%2BG1CTP%2FaGqOdWFs0Q5cPYZ4bytp",
        "afpovertcp.cfg",
        "rpc",
        "https://sdk.51.la/event/js-sdk-event.min.js?u=JdoUNv3VSW0GHUpw",
        "process_list.txt",
        "group",
        "https://www.sunnetwork.com.sg/sun_21/js/vendor/jquery-3.5.0.min.js",
        "configuring.html",
        "lber.h",
        "https://app.ynsdty.cn/dist/js/longbow.slidercaptcha.js",
        "Admin.tbd",
        "https://2001.habyc.com/js/config.js",
        "virtual",
        "rtadvd.conf",
        "launchdaemons.txt",
        "Driver_xst.h",
        "auto_home",
        "https://chatting.page/kv6vcosd7tmhsetmarsoawzaglejnny4",
        "https://www.virustotal.com/gui/polyfills/core-js.c92df5c57caa3e436cd3ef38e4b4f503.js",
        "com.apple.screensharing.agent.launchd",
        "AppleFirmwareUpdate.tbd",
        "https://2001.habyc.com/static/js/chunk-vendors.9d7684f4.js",
        "systemControls.csv",
        "battery.csv",
        "xtab",
        "https://app.ynsdty.cn/dist/vendors/core-js/core.js",
        "https://2001.habyc.com/static/css/chunk-vendors.6a41b67e.css",
        "launchD.csv",
        "chromeExtensions.csv",
        "MCAdvertiserAssistant.h",
        "launchagents.txt",
        "sipConfig.csv",
        "https://www.cybereason.com/blog/threat-alert-aggressive-qakbot-campaign-and-the-black-basta-ransomware-group-targeting-u.s.-companies",
        "LDAP.tbd",
        "etcHosts.csv",
        "https://2001.habyc.com/static/css/app.88afcfd8.css",
        "https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese/",
        "x86_64-apple-macos.swiftinterface",
        "usbDevices.csv",
        "master.cf.proto",
        "transport",
        "interfaceAddrs.csv",
        "xfe-URL-sys95.com-stix2-2.1-export.json",
        "https://2001.dwlww.com/?channelNo=2001#/home",
        "https://www.8098.app:21568/js/xinstall_inner_e.min.js?v=1004",
        "http://ylnedriuopegrle33689.org/mobile/static/js/manifest.2cf63ac462750c8b3a2f.js",
        "http://ylnedriuopegrle33689.org/mobile/static/js/0.fc97dceb0dbb60948b0f.js",
        "https://2001.dwlww.com/js/config.js",
        "protocols",
        "https://www.sunnetwork.com.sg/sun_21/js/ajax-form.js",
        "gettytab",
        "module.modulemap",
        "AirPlayReceiver.tbd",
        "postfix-files",
        "https://www.sunnetwork.com.sg/sun_21/js/main.js",
        "https://www.sunnetwork.com.sg/sun_21/js/bootstrap.min.js",
        "ntp_opendirectory.conf",
        "https://2001.habyc.com/?channelNo=2001#/home",
        "auto_master",
        "rc.netboot",
        "https://2001.dwlww.com/static/js/chunk-7d5d3bac.efb700c7.js",
        "https://2001.dwlww.com/static/js/app.9d5d18d7.js",
        "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
        "crashes.csv",
        "MCBrowserViewController.h",
        "x86_64-apple-ios-macabi.swiftinterface",
        "irbrc",
        "main.cf",
        "networks",
        "relocated",
        "master.cf",
        "https://blog.qualys.com/vulnerabilities-threat-research/2024/09/19/black-basta-ransomware-what-you-need-to-know",
        "sharingPreferences.csv",
        "sudoers",
        "https://sdk.51.la/js-sdk-pro.min.js",
        "https://2001.habyc.com/static/css/chunk-7d5d3bac.e1a32335.css",
        "IOCs.pdf",
        "https://app.ynsdty.cn//package/GmCC6WISh",
        "MCSession.h",
        "https://www.sunnetwork.com.sg/sun_21/js/slick.min.js",
        "xfe-URL-sun.net.hk-stix2-2.1-export.json",
        "https://www.recaptcha.net/recaptcha/api.js?render=explicit",
        "notify.conf",
        "rmtab",
        "xfe-URL-2001.habyc.com-stix2-2.1-export.json",
        "IOCs-MAY4.csv",
        "AOSKit.tbd",
        "syslog.conf",
        "main.cf.default",
        "TLS_LICENSE",
        "rc.common",
        "https://vtbehaviour.commondatastorage.googleapis.com/6c39ae0368703f254070a0648c0066115140c3e762d9bf5b52833a037a1e3743_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469752&Signature=Df%2Bamm33qFPdsDg6nWC5FQjse7h4fksSXqONp4nMEItb0gpBwqx66TqcCnFzQplUk6ExMge79qNZR2OElv63sX54D4fSGwI9nvHYhQoiVdZIgf4ct8dIAr%2BYO9jSx0WpPUVFsvf%2FXtXvm6jM5n5v7CGiyFRyAz8PES5g%2FcOlLt%2BDhsc8bhi%2FMU9mAkyyr5nFVPcTmUSHOTNXOeKDUlyRkQE6b9FEbFhUL1h3%2B%2FBVtysh",
        "https://2001.dwlww.com/static/js/chunk-vendors.9d7684f4.js",
        "bind.html",
        "https://www.elastic.co/security-labs/katz-and-mouse-game",
        "https://app.ynsdty.cn/dist/vendors/swiper/swiper.min.js",
        "pf.os",
        "users.csv",
        "https://darktrace.com/blog/black-basta-old-dogs-with-new-tricks",
        "https://app.ynsdty.cn/dist/vendors/bootstrap/js/bootstrap.min.js",
        "https://www.cve.org/CVERecord?id=CVE-2022-30190",
        "https://app.ynsdty.cn/dist/js/jquery.cookie.js",
        "https://www.fortinet.com/blog/threat-research/ransomware-roundup-black-basta",
        "csh.cshrc",
        "https://www.cve.org/CVERecord?id=CVE-2021-42278",
        "aliases",
        "csh.login",
        "custom-error.html",
        "dbixs_rev.h",
        "caching.html",
        "bounce.cf.default",
        "LocalAuthentication.tbd",
        "https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/",
        "https://www.cve.org/CVERecord?id=CVE-2021-34527",
        "http://ylnedriuopegrle33689.org/mobile/static/js/app.9074e5240bf3d0f7b264.js",
        "locate.rc",
        "kernel.csv",
        "ntp.conf",
        "diskEncryption.csv",
        "ttys",
        "zprofile",
        "https://arcticwolf.com/resources/blog/cherryloader-a-new-go-based-loader-discovered-in-recent-intrusions/",
        "MultipeerConnectivity.tbd",
        "https://www.8098.app:21568/js/jquery-1.11.3.min.js",
        "MCNearbyServiceBrowser.h",
        "resolv.conf",
        "find.codes",
        "user_launchagents.txt",
        "version.plist",
        "https://www.cve.org/CVERecord?id=CVE-2020-1472",
        "makedefs.out",
        "header_checks",
        "pf.conf",
        "interfaceDetails.csv",
        "DBIXS.h",
        "applications.csv",
        "https://app.ynsdty.cn/dist/js/app.base.js",
        "asl.conf",
        "MCError.h",
        "dbi_sql.h",
        "https://m4244.com:35003/",
        "http://ylnedriuopegrle33689.org/mobile/static/js/151.f5cad57280238b18aa58.js",
        "security_status.txt",
        "https://vtbehaviour.commondatastorage.googleapis.com/5feceb66ffc86f38d952786c6d696c79c2dbc239dd4e91b46729d73a27fb57e9_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469810&Signature=Mj5ODxCW7tD5UNn6P11Ta7F2cmDLSJuEB7JSLFg%2FERfANmnRR5L7XzDwXxI5G48vkQFx0%2FBMtjMLwWHn6ZHKlt13rfzkvoOu5fJ%2Fb5lMJqUp1rSQIG0JLL80QAnXyJf2W8pL7MvK97Tr4jsCIUfd8ezliJtV5SmahV6Q8lYu2KJUnANrHkA10RFrcT4O26Vk7gbDsuC7caDXC6U9KXTTB0cpC77%2FV7w86ftN2JPXx6oEHUvSj02qsvhKwKQvmM",
        "https://vtbehaviour.commondatastorage.googleapis.com/5feceb66ffc86f38d952786c6d696c79c2dbc239dd4e91b46729d73a27fb57e9_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469831&Signature=ZlRZLvCaJ%2F9niupu9DFCvXvfgFpDEOsK%2FsH46CB2zEVUDjcQRNMDp9XXKKx0dekmHQbhl02yqygHPOA8Wty5duGtK216QCvKNkYpbpdOjN7xgAg3AsldciWbqeJr8N4I%2F1%2FPRSdVfB%2BNGaBJKxZG1RQkX206MSvX%2BeY%2FdeEYpq3NYdrPWlxdV0pa3yaqcMrf2s%2FCFSM%2FdO3xt5PKyXWG%2FDCNM5iiuXh8OT2ckhZhf%",
        "arm64e-apple-ios-macabi.swiftinterface",
        "kexts.txt",
        "mounts.csv",
        "command_args.json",
        "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn",
        "index.html.en",
        "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a",
        "MCNearbyServiceAdvertiser.h",
        "sharedFolders.csv",
        "shells",
        "nfs.conf",
        "certificates.csv",
        "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f",
        "zshrc_Apple_Terminal",
        "convenience.map",
        "https://www.cve.org/CVERecord?id=CVE-2021-42287",
        "smb.conf",
        "https://app.ynsdty.cn/dist/js/jquery.min.js",
        "managedPolicies.csv",
        "disk_structure.txt",
        "ldap.h",
        "hook_op_check.h",
        "https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese",
        "https://www.tidio.com/talk/kv6vcosd7tmhsetmarsoawzaglejnny4",
        "https://widget-v4.tidiochat.com/code/kv6vcosd7tmhsetmarsoawzaglejnny4.js",
        "passwd",
        "https://www.virustotal.com/gui/main.6d41e0dc139508f21963.js",
        "https://www.8098.app:21568/?agent=7691755704",
        "preboot_archive_errors.log",
        "systemInfo.csv",
        "dbivport.h",
        "man.conf",
        "apfs_boot_mount.tbd",
        "CodeResources",
        "https://blog.sekoia.io/phishing-campaigns-i-paid-twice-targeting-booking-com-hotels-and-customers/",
        "bashrc_Apple_Terminal",
        "mail.rc",
        "mounts.txt",
        "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware",
        "https://www.sunnetwork.com.sg/sun_21/js/popper.min.js",
        "master.cf.default",
        "https://www.cve.org/CVERecord?id=CVE-2024-26169",
        "csh.logout",
        "paths",
        "manpaths",
        "https://2001.dwlww.com/static/css/app.88afcfd8.css",
        "dbd_xsh.h",
        "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/",
        "MultipeerConnectivity.h",
        "https://www.elastic.co/security-labs/grimresource",
        "content-negotiation.html",
        "bashrc",
        "Info.plist",
        "arm64e-apple-macos.swiftinterface",
        "MultipeerConnectivity.apinotes",
        "canonical",
        "newsyslog.conf",
        "sudo_lecture",
        "profile",
        "https://www.cve.org/CVERecord?id=CVE-2024-1709",
        "kern_loader.conf",
        "https://2001.dwlww.com/static/css/chunk-vendors.6a41b67e.css",
        "http://ylnedriuopegrle33689.org/mobile/static/lib/velocity.min.js",
        "https://2001.habyc.com/static/js/chunk-7d5d3bac.efb700c7.js",
        "xfe-URL-habyc.com-stix2-2.1-export.json",
        "autofs.conf",
        "zshrc",
        "generic",
        "https://www.sunnetwork.com.sg/sun_21/js/imagesloaded.pkgd.min.js",
        "https://www.gstatic.com/recaptcha/releases/Y-cOIEkAqcfDdup_qnnmkxIC/recaptcha__en.js",
        "https://www.rapid7.com/blog/post/2024/05/10/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators/",
        "MCPeerID.h",
        "main.cf.proto",
        "custom_header_checks",
        "https://www.virustotal.com/gui/polyfills/regenerator-runtime.95dc763885f05111a2f88232a2d0cf2d.js",
        "https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbasta",
        "http://ylnedriuopegrle33689.org/mobile/static/css/app.726f146ac9040074723077dbffe13bf7.css",
        "LICENSE",
        "access",
        "https://2001.dwlww.com/static/css/chunk-7d5d3bac.e1a32335.css",
        "APConfigurationSystem.tbd",
        "ftpusers",
        "https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/",
        "BUILDING"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "Lazarus"
          ],
          "malware_families": [
            "Themeforestrat",
            "Pondrat",
            "Remotepeloader",
            "Dpapiloader",
            "Remotepe",
            "Poolrat"
          ],
          "industries": [
            "Finance"
          ]
        },
        "other": {
          "adversary": [
            "Black Basta",
            "ValleyRAT_S2, DeVixorMalware, SHADOW#REACTOR, Fake Fortinet Sites, Phishing campaign with QR codes",
            "DragonForce Malaysia Hacker Group",
            "Lazarus",
            "Threat",
            "RemotePE, ClayRat, Nimbus Manticore, SonicWall SSL VPN exploitation, ModeloRAT",
            "FIN7"
          ],
          "malware_families": [
            "Bufferwriter",
            "Primary netsupport",
            "Trojandropper:powershell/cobacis",
            "Behavior:win32/cobaltstrike",
            "Hacktool:win64/cobaltstrike",
            "Trojan:win64/turtleloader.cs",
            "Sessionenv",
            "Netsupport",
            "Linux",
            "Poolrat",
            "Trojan:win32/qakbot",
            "Purerat",
            "Remotepeloader",
            "Behavior:win32/qakbot",
            "Dpapiloader",
            "Widespread qbot",
            "Qbot",
            "Trojanspy:win32/qakbot",
            "Lazarus",
            "Behavior:win32/systembc",
            "Firstname",
            "Trojan:win32/basta",
            "Sugarloader",
            "Qace",
            "Windows",
            "Trojandownloader:o97m/qakbot",
            "Exploit:win32/shellcode.bn",
            "Trojan: win32/systembc",
            "Black basta",
            "Cobalt strike",
            "Remotepe",
            "Qakbot",
            "Trojan:win32/qbot",
            "Backdoor:win64/cobaltstrike",
            "Applejeus",
            "Findertools",
            "Basta linux",
            "Themeforestrat",
            "Pondrat",
            "Lastname",
            "Bufferreader",
            "Behavior:win32/basta",
            "Waaa",
            "Cherryloader",
            "Conti",
            "Macos",
            "Ransom:win32/basta"
          ],
          "industries": [
            "Investment",
            "Critical infrastructure",
            "Retail",
            "Legal",
            "Banking",
            "Transportation",
            "Hotel",
            "Construction",
            "Emergency services",
            "Healthcare",
            "Technology",
            "Cryptocurrency",
            "Media",
            "Military",
            "Manufacturing",
            "Hospitality",
            "Government",
            "Finance",
            "Social engineering"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 38,
  "pulses": [
    {
      "id": "6a1447f25db6bc082d5093cb",
      "name": "RemotePE: The Lazarus RAT that lives in memory",
      "description": "A sophisticated memory-only toolset used by a North Korean Lazarus subgroup targeting financial and cryptocurrency organizations consists of three malware families forming a chain. DPAPILoader decrypts and loads RemotePELoader from disk using Windows Data Protection API. RemotePELoader beacons to command-and-control servers and retrieves RemotePE, a fully-fledged remote access trojan executed entirely in memory without filesystem artifacts. The toolset employs environmental keying via DPAPI, EDR evasion through HellsGate technique and ETW patching, actor-in-the-loop payload delivery, and shared hosting infrastructure on Namecheap. RemotePE features comprehensive RAT capabilities including file operations, process management, command execution, and a plugin system for dynamically loading additional payloads, while maintaining persistence through masquerading as legitimate Windows services.",
      "modified": "2026-05-25T15:15:11.630000",
      "created": "2026-05-25T13:00:34.674000",
      "tags": [
        "poolrat",
        "pondrat",
        "dpapiloader",
        "themeforestrat",
        "hellsgate",
        "remotepeloader",
        "remotepe"
      ],
      "references": [
        "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "DPAPILoader",
          "display_name": "DPAPILoader",
          "target": null
        },
        {
          "id": "RemotePELoader",
          "display_name": "RemotePELoader",
          "target": null
        },
        {
          "id": "RemotePE",
          "display_name": "RemotePE",
          "target": null
        },
        {
          "id": "ThemeForestRAT",
          "display_name": "ThemeForestRAT",
          "target": null
        },
        {
          "id": "PondRAT",
          "display_name": "PondRAT",
          "target": null
        },
        {
          "id": "POOLRAT",
          "display_name": "POOLRAT",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1543.003",
          "name": "Windows Service",
          "display_name": "T1543.003 - Windows Service"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1562.006",
          "name": "Indicator Blocking",
          "display_name": "T1562.006 - Indicator Blocking"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1027.002",
          "name": "Software Packing",
          "display_name": "T1027.002 - Software Packing"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1480.001",
          "name": "Environmental Keying",
          "display_name": "T1480.001 - Environmental Keying"
        }
      ],
      "industries": [
        "Finance"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 8,
        "URL": 2,
        "domain": 8,
        "hostname": 1
      },
      "indicator_count": 28,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386485,
      "modified_text": "5 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68b87b65a4bb4c1c6d37b3a2",
      "name": "Three Lazarus RATs coming for your cheese",
      "description": "This report analyzes three remote access trojans (RATs) used by a Lazarus subgroup targeting financial and cryptocurrency organizations: PondRAT, ThemeForestRAT, and RemotePE. It details an incident response case from 2024 involving social engineering and possible zero-day exploitation. PondRAT is described as a simple initial access tool, while ThemeForestRAT is a more capable memory-only RAT used in conjunction. RemotePE appears to be an advanced RAT deployed in later attack stages. The analysis reveals connections between these tools and previously known Lazarus malware like POOLRAT. The report highlights the actor's persistence, sophistication, and continued threat to financial targets.",
      "modified": "2025-10-03T17:00:17.123000",
      "created": "2025-09-03T17:31:17.494000",
      "tags": [
        "financial",
        "rat",
        "themeforestrat",
        "zero-day",
        "remotepe",
        "poolrat",
        "pondrat",
        "cryptocurrency",
        "social engineering"
      ],
      "references": [
        "https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1070.006",
          "name": "Timestomp",
          "display_name": "T1070.006 - Timestomp"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1588.001",
          "name": "Malware",
          "display_name": "T1588.001 - Malware"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "display_name": "T1048 - Exfiltration Over Alternative Protocol"
        },
        {
          "id": "T1588.002",
          "name": "Tool",
          "display_name": "T1588.002 - Tool"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1204.001",
          "name": "Malicious Link",
          "display_name": "T1204.001 - Malicious Link"
        },
        {
          "id": "T1078.003",
          "name": "Local Accounts",
          "display_name": "T1078.003 - Local Accounts"
        }
      ],
      "industries": [
        "Finance"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 49,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 27,
        "FileHash-SHA1": 33,
        "FileHash-SHA256": 48,
        "domain": 22,
        "hostname": 6
      },
      "indicator_count": 136,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386484,
      "modified_text": "239 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a141e8c7ad40a0af45a7a56",
      "name": "monitored target - credit Q Vashti (clone)",
      "description": "",
      "modified": "2026-05-31T05:22:37.048000",
      "created": "2026-05-25T10:03:56.699000",
      "tags": [
        "indicator",
        "source",
        "ck id",
        "show technique",
        "mitre att",
        "ck matrix",
        "openservice",
        "sha384",
        "file",
        "virtualfree",
        "path",
        "getprocaddress",
        "pattern match",
        "potential ip",
        "open",
        "date",
        "click",
        "error",
        "null",
        "false",
        "stream",
        "enterprise",
        "body",
        "crypto",
        "compiler",
        "entropy",
        "refresh",
        "download",
        "factory",
        "bind",
        "strings",
        "twitter",
        "roboto",
        "contact",
        "window",
        "tools",
        "span",
        "value",
        "access type",
        "file execution",
        "setval",
        "userprofile",
        "debugger",
        "hybrid",
        "persistence",
        "general",
        "suspicious",
        "target"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1569",
          "name": "System Services",
          "display_name": "T1569 - System Services"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1029",
          "name": "Scheduled Transfer",
          "display_name": "T1029 - Scheduled Transfer"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1124",
          "name": "System Time Discovery",
          "display_name": "T1124 - System Time Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1213",
          "name": "Data from Information Repositories",
          "display_name": "T1213 - Data from Information Repositories"
        },
        {
          "id": "T1217",
          "name": "Browser Bookmark Discovery",
          "display_name": "T1217 - Browser Bookmark Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1559",
          "name": "Inter-Process Communication",
          "display_name": "T1559 - Inter-Process Communication"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1565",
          "name": "Data Manipulation",
          "display_name": "T1565 - Data Manipulation"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "68409862e1722725233acace",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 54,
        "FileHash-SHA1": 35,
        "FileHash-SHA256": 24,
        "SSLCertFingerprint": 3,
        "URL": 294,
        "domain": 317,
        "hostname": 648,
        "email": 3
      },
      "indicator_count": 1378,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "13 minutes ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5fa1852d337eca8e99c2ec32",
      "name": "Malware - Malware Domain Feed V2 - November 03 2020",
      "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
      "modified": "2026-05-30T03:19:46.084000",
      "created": "2020-11-03T16:28:29.011000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 552488,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 3,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "otxrobottwo",
        "id": "78495",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_78495/resized/80/avatar_ba5a8acdbd.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 49967,
        "domain": 75353
      },
      "indicator_count": 125320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1727,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a15ad403ba61be50e09d42e",
      "name": "research indicators tlp: amber",
      "description": "This post is not a reflection of any companies tagged.",
      "modified": "2026-05-29T09:50:48.467000",
      "created": "2026-05-26T14:25:04.421000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 53,
        "URL": 131,
        "hostname": 73,
        "domain": 21,
        "FileHash-MD5": 17,
        "FileHash-SHA1": 26,
        "IPv4": 1
      },
      "indicator_count": 322,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1814b55e1559397600e7f7",
      "name": "EbeeMay2026 Pt5",
      "description": "Multiple APT/threat actors, Malware and Campaigns",
      "modified": "2026-05-28T10:11:01.506000",
      "created": "2026-05-28T10:11:01.506000",
      "tags": [
        "filehashsha256",
        "filehashmd5",
        "filehashsha1",
        "redacted",
        "ipv62a12",
        "ipv62a03",
        "localappdata",
        "cve20234966 cve",
        "cve20136282 cve",
        "cve20132597 cve"
      ],
      "references": [
        "IOCs-MAY4.csv"
      ],
      "public": 1,
      "adversary": "RemotePE, ClayRat, Nimbus Manticore, SonicWall SSL VPN exploitation, ModeloRAT",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 79,
        "URL": 57,
        "CIDR": 3,
        "CVE": 15,
        "FileHash-MD5": 151,
        "FileHash-SHA1": 113,
        "FileHash-SHA256": 164,
        "domain": 137,
        "email": 4,
        "hostname": 47
      },
      "indicator_count": 770,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 39,
      "modified_text": "2 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a15279470f40ea28e34fa55",
      "name": "RemotePE: The Lazarus RAT that lives in memory",
      "description": "",
      "modified": "2026-05-26T04:54:44.854000",
      "created": "2026-05-26T04:54:44.854000",
      "tags": [
        "poolrat",
        "pondrat",
        "dpapiloader",
        "themeforestrat",
        "hellsgate",
        "remotepeloader",
        "remotepe"
      ],
      "references": [
        "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "DPAPILoader",
          "display_name": "DPAPILoader",
          "target": null
        },
        {
          "id": "RemotePELoader",
          "display_name": "RemotePELoader",
          "target": null
        },
        {
          "id": "RemotePE",
          "display_name": "RemotePE",
          "target": null
        },
        {
          "id": "ThemeForestRAT",
          "display_name": "ThemeForestRAT",
          "target": null
        },
        {
          "id": "PondRAT",
          "display_name": "PondRAT",
          "target": null
        },
        {
          "id": "POOLRAT",
          "display_name": "POOLRAT",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1543.003",
          "name": "Windows Service",
          "display_name": "T1543.003 - Windows Service"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1562.006",
          "name": "Indicator Blocking",
          "display_name": "T1562.006 - Indicator Blocking"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1027.002",
          "name": "Software Packing",
          "display_name": "T1027.002 - Software Packing"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1480.001",
          "name": "Environmental Keying",
          "display_name": "T1480.001 - Environmental Keying"
        }
      ],
      "industries": [
        "Finance"
      ],
      "TLP": "white",
      "cloned_from": "6a1447f25db6bc082d5093cb",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 8,
        "URL": 2,
        "domain": 8,
        "hostname": 1
      },
      "indicator_count": 28,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 278,
      "modified_text": "5 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a151218eba755efd0f0b4a9",
      "name": "IOC - RemotePE: The Lazarus RAT that lives in memory",
      "description": "",
      "modified": "2026-05-26T03:23:33.245000",
      "created": "2026-05-26T03:23:04.561000",
      "tags": [
        "poolrat",
        "pondrat",
        "dpapiloader",
        "themeforestrat",
        "hellsgate",
        "remotepeloader",
        "remotepe"
      ],
      "references": [
        "https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "DPAPILoader",
          "display_name": "DPAPILoader",
          "target": null
        },
        {
          "id": "RemotePELoader",
          "display_name": "RemotePELoader",
          "target": null
        },
        {
          "id": "RemotePE",
          "display_name": "RemotePE",
          "target": null
        },
        {
          "id": "ThemeForestRAT",
          "display_name": "ThemeForestRAT",
          "target": null
        },
        {
          "id": "PondRAT",
          "display_name": "PondRAT",
          "target": null
        },
        {
          "id": "POOLRAT",
          "display_name": "POOLRAT",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1543.003",
          "name": "Windows Service",
          "display_name": "T1543.003 - Windows Service"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1562.006",
          "name": "Indicator Blocking",
          "display_name": "T1562.006 - Indicator Blocking"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1027.002",
          "name": "Software Packing",
          "display_name": "T1027.002 - Software Packing"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1480.001",
          "name": "Environmental Keying",
          "display_name": "T1480.001 - Environmental Keying"
        }
      ],
      "industries": [
        "Finance"
      ],
      "TLP": "white",
      "cloned_from": "6a1447f25db6bc082d5093cb",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "celestre",
        "id": "295357",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2,
        "FileHash-SHA1": 3,
        "FileHash-SHA256": 8,
        "domain": 8,
        "hostname": 1
      },
      "indicator_count": 22,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "5 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d389db09844fda2dd3d26d",
      "name": "CAPE Sandbox",
      "description": "",
      "modified": "2026-05-06T10:13:24.260000",
      "created": "2026-04-06T10:24:27.141000",
      "tags": [
        "p2404",
        "strong",
        "sha256",
        "library",
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "none rticon",
        "info",
        "path",
        "win32",
        "accept",
        "null",
        "activator",
        "false",
        "black",
        "powershell",
        "error",
        "team",
        "code",
        "date",
        "download",
        "stop",
        "green",
        "class",
        "void",
        "cheap",
        "shutdown",
        "impact",
        "guard",
        "tools",
        "comspec",
        "enterprise",
        "terminal",
        "music",
        "desktop",
        "crypt32",
        "lockfile",
        "write",
        "open",
        "stub",
        "delta",
        "title",
        "body",
        "project",
        "windows sandbox",
        "calls process"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
        "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 172,
        "FileHash-SHA1": 151,
        "FileHash-SHA256": 121,
        "URL": 80,
        "domain": 17,
        "hostname": 59
      },
      "indicator_count": 600,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d389dab37e607e415f7304",
      "name": "CAPE Sandbox",
      "description": "",
      "modified": "2026-05-06T10:13:24.260000",
      "created": "2026-04-06T10:24:26.731000",
      "tags": [
        "p2404",
        "strong",
        "sha256",
        "library",
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "none rticon",
        "info",
        "path",
        "win32",
        "accept",
        "null",
        "activator",
        "false",
        "black",
        "powershell",
        "error",
        "team",
        "code",
        "date",
        "download",
        "stop",
        "green",
        "class",
        "void",
        "cheap",
        "shutdown",
        "impact",
        "guard",
        "tools",
        "comspec",
        "enterprise",
        "terminal",
        "music",
        "desktop",
        "crypt32",
        "lockfile",
        "write",
        "open",
        "stub",
        "delta",
        "title",
        "body",
        "project",
        "windows sandbox",
        "calls process"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
        "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 172,
        "FileHash-SHA1": 151,
        "FileHash-SHA256": 121,
        "URL": 78,
        "domain": 15,
        "hostname": 59
      },
      "indicator_count": 596,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "file.name",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "file.name",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780205755.8609233
}