{
  "type": "URL",
  "indicator": "https://amanext.com/Setup.exe",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://amanext.com/Setup.exe",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3726696643,
      "indicator": "https://amanext.com/Setup.exe",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "64c787bdcf6f10ade6ee0038",
          "name": "Threat Intel Report - W31-2023",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2023-08-30T10:04:30.756000",
          "created": "2023-07-31T10:06:53.509000",
          "tags": [
            "sha1 file",
            "name submit",
            "date",
            "modiloader",
            "stealc",
            "guloader",
            "icedid",
            "formbook",
            "malware url",
            "tags",
            "coinminer",
            "trickbot",
            "stealer",
            "url http",
            "smoke loader",
            "week rank",
            "dofoil",
            "url https",
            "bladabindi",
            "njw0rm",
            "rats",
            "hashes",
            "domains",
            "ivanti",
            "vmware",
            "mobile",
            "epmm",
            "cvss",
            "cvss base",
            "jumpcloud hack",
            "opsec",
            "vpn performance",
            "microsoft",
            "lazarus",
            "zimbra",
            "backconnect",
            "stark",
            "asyncrat",
            "gameover",
            "anydesk",
            "winscp",
            "maximus",
            "cobalt strike",
            "blackcat",
            "remcos",
            "deploys graphicalproton",
            "pupy",
            "android",
            "mirai"
          ],
          "references": [
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time",
            "https://www.spamhaus.org/xbl/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "IcedID",
              "display_name": "IcedID",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Deploys GraphicalProton",
              "display_name": "Deploys GraphicalProton",
              "target": null
            },
            {
              "id": "Pupy",
              "display_name": "Pupy",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Android",
              "display_name": "Android",
              "target": null
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1195",
              "name": "Supply Chain Compromise",
              "display_name": "T1195 - Supply Chain Compromise"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            }
          ],
          "industries": [
            "Diplomatic",
            "Banking",
            "Bank"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 67,
            "FileHash-SHA1": 64,
            "FileHash-SHA256": 124,
            "URL": 129,
            "domain": 38,
            "hostname": 65
          },
          "indicator_count": 487,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 107,
          "modified_text": "1005 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64c45218c8f93c1fce74e4ba",
          "name": "URLHaus data - 28-07-2023",
          "description": "",
          "modified": "2023-08-27T23:02:33.461000",
          "created": "2023-07-28T23:41:12.725000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "arm",
            "mirai",
            "hajime",
            "AgentTesla",
            "exe",
            "njRAT",
            "remcos rat",
            "Formbook",
            "dll",
            "Stealc",
            "dropped-by-SmokeLoader",
            "RedLineStealer",
            "32",
            "PowerPC",
            "motorola",
            "renesas",
            "intel",
            "bashlite",
            "gafgyt",
            "sparc",
            "dropped-by-PrivateLoader",
            "encrypted",
            "PrivateLoader",
            "LummaStealer",
            "script",
            "AVrecon",
            "botnet",
            "c2",
            "geofenced",
            "Gozi",
            "Intuit ITA",
            "ITA",
            "Loader",
            "ursnif",
            "opendir",
            "GuLoader",
            "DarkCloud",
            "dofoil",
            "Smoke Loader",
            "ISFB",
            "plugin",
            "rat",
            "RemcosRAT",
            "iso",
            "64",
            "discord",
            "infostealer",
            "Lumma",
            "RedLine",
            "CoinMiner",
            "RTF",
            "AsyncRAT",
            "SocGholish"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 634,
            "domain": 8,
            "hostname": 3
          },
          "indicator_count": 645,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "1007 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/",
        "https://www.spamhaus.org/xbl/",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Lazarus"
          ],
          "malware_families": [
            "Mirai",
            "Pupy",
            "Icedid",
            "Deploys graphicalproton",
            "Android",
            "Remcos",
            "Cobalt strike"
          ],
          "industries": [
            "Banking",
            "Diplomatic",
            "Bank"
          ],
          "unique_indicators": 1560
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/amanext.com",
    "whois": "http://whois.domaintools.com/amanext.com",
    "domain": "amanext.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "64c787bdcf6f10ade6ee0038",
      "name": "Threat Intel Report - W31-2023",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2023-08-30T10:04:30.756000",
      "created": "2023-07-31T10:06:53.509000",
      "tags": [
        "sha1 file",
        "name submit",
        "date",
        "modiloader",
        "stealc",
        "guloader",
        "icedid",
        "formbook",
        "malware url",
        "tags",
        "coinminer",
        "trickbot",
        "stealer",
        "url http",
        "smoke loader",
        "week rank",
        "dofoil",
        "url https",
        "bladabindi",
        "njw0rm",
        "rats",
        "hashes",
        "domains",
        "ivanti",
        "vmware",
        "mobile",
        "epmm",
        "cvss",
        "cvss base",
        "jumpcloud hack",
        "opsec",
        "vpn performance",
        "microsoft",
        "lazarus",
        "zimbra",
        "backconnect",
        "stark",
        "asyncrat",
        "gameover",
        "anydesk",
        "winscp",
        "maximus",
        "cobalt strike",
        "blackcat",
        "remcos",
        "deploys graphicalproton",
        "pupy",
        "android",
        "mirai"
      ],
      "references": [
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time",
        "https://www.spamhaus.org/xbl/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "IcedID",
          "display_name": "IcedID",
          "target": null
        },
        {
          "id": "Remcos",
          "display_name": "Remcos",
          "target": null
        },
        {
          "id": "Deploys GraphicalProton",
          "display_name": "Deploys GraphicalProton",
          "target": null
        },
        {
          "id": "Pupy",
          "display_name": "Pupy",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Android",
          "display_name": "Android",
          "target": null
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1195",
          "name": "Supply Chain Compromise",
          "display_name": "T1195 - Supply Chain Compromise"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        }
      ],
      "industries": [
        "Diplomatic",
        "Banking",
        "Bank"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 67,
        "FileHash-SHA1": 64,
        "FileHash-SHA256": 124,
        "URL": 129,
        "domain": 38,
        "hostname": 65
      },
      "indicator_count": 487,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 107,
      "modified_text": "1005 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64c45218c8f93c1fce74e4ba",
      "name": "URLHaus data - 28-07-2023",
      "description": "",
      "modified": "2023-08-27T23:02:33.461000",
      "created": "2023-07-28T23:41:12.725000",
      "tags": [
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "arm",
        "mirai",
        "hajime",
        "AgentTesla",
        "exe",
        "njRAT",
        "remcos rat",
        "Formbook",
        "dll",
        "Stealc",
        "dropped-by-SmokeLoader",
        "RedLineStealer",
        "32",
        "PowerPC",
        "motorola",
        "renesas",
        "intel",
        "bashlite",
        "gafgyt",
        "sparc",
        "dropped-by-PrivateLoader",
        "encrypted",
        "PrivateLoader",
        "LummaStealer",
        "script",
        "AVrecon",
        "botnet",
        "c2",
        "geofenced",
        "Gozi",
        "Intuit ITA",
        "ITA",
        "Loader",
        "ursnif",
        "opendir",
        "GuLoader",
        "DarkCloud",
        "dofoil",
        "Smoke Loader",
        "ISFB",
        "plugin",
        "rat",
        "RemcosRAT",
        "iso",
        "64",
        "discord",
        "infostealer",
        "Lumma",
        "RedLine",
        "CoinMiner",
        "RTF",
        "AsyncRAT",
        "SocGholish"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 634,
        "domain": 8,
        "hostname": 3
      },
      "indicator_count": 645,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1621,
      "modified_text": "1007 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://amanext.com/Setup.exe",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://amanext.com/Setup.exe",
    "type": "URL",
    "found": true,
    "verdict": "malicious",
    "url_status": "offline",
    "threat": "malware_download",
    "tags": [
      "dropped-by-PrivateLoader",
      "Stealc"
    ],
    "date_added": "2023-07-28",
    "last_online": "2023-07-30",
    "reporter": "andretavare5",
    "host": "amanext.com",
    "payloads": [
      {
        "filename": null,
        "file_type": "exe",
        "md5": "9bb0bf48749cecfeadc4e6be1a2ad5ef",
        "sha256": "912a69862b4f70093e5fb456a70b75c7c1ff187ef42cbbcabb68c6c7936eed78",
        "signature": "Stealc",
        "first_seen": "2023-07-29"
      },
      {
        "filename": null,
        "file_type": "exe",
        "md5": "7f5d2780dfbbab6889b8d08cec6c51c2",
        "sha256": "cead24187e759a0ddf49d1a67476fe0284b586c1aa5066c189879a143e7966be",
        "signature": "Stealc",
        "first_seen": "2023-07-29"
      },
      {
        "filename": null,
        "file_type": "exe",
        "md5": "9a1691fc8575d42eca60aacc9a14018d",
        "sha256": "7dd9fc492a8732971eae35e782c2324d05c35edf3652971303118bdfc44c9fdf",
        "signature": "Stealc",
        "first_seen": "2023-07-28"
      },
      {
        "filename": null,
        "file_type": "exe",
        "md5": "1050aa5a1eaaa9f59f66b2e0f7702dd3",
        "sha256": "528a04c98597c2ab37c0d9d536707c2dcd2d1f7bdc0a26fc9b24a8a3035eaf88",
        "signature": "Stealc",
        "first_seen": "2023-07-28"
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780265669.8422742
}