{
  "type": "URL",
  "indicator": "https://dscriy.chtq.net",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://dscriy.chtq.net",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4039111138,
      "indicator": "https://dscriy.chtq.net",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "6889ebeb317457163ab8fa42",
          "name": "Emmenhtal loader",
          "description": "Campaigns that used Emmenhtal to deliver various payloads",
          "modified": "2025-08-29T09:03:58.967000",
          "created": "2025-07-30T09:54:51.943000",
          "tags": [],
          "references": [
            "Emmenhtal.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 395,
            "BitcoinAddress": 1,
            "CVE": 6,
            "FileHash-MD5": 240,
            "FileHash-SHA1": 123,
            "FileHash-SHA256": 392,
            "domain": 182,
            "email": 1,
            "hostname": 181
          },
          "indicator_count": 1521,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 42,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "688b0dde98e8d32361238f0f",
          "name": "Emmenhtal Loader Campaign deliver various payloads                                         [IMEBEEIMFINE]",
          "description": "",
          "modified": "2025-08-29T09:03:58.967000",
          "created": "2025-07-31T06:31:58.326000",
          "tags": [],
          "references": [
            "Emmenhtal.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6889ebeb317457163ab8fa42",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 395,
            "BitcoinAddress": 1,
            "CVE": 6,
            "FileHash-MD5": 240,
            "FileHash-SHA1": 123,
            "FileHash-SHA256": 392,
            "domain": 182,
            "email": 1,
            "hostname": 181
          },
          "indicator_count": 1521,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67b8c8c79c31a847649a026f",
          "name": "Ransomware or Espionage? Green Nailao Campaign Blurs the Line Between Cybercrime and State-Sponsored Operations",
          "description": "This intelligence report details how the Green Nailao campaign leverages cyberespionage-linked tools alongside ransomware, raising questions about the attackers' true intent. The campaign targeted organizations across multiple industries, with discrepancies in victim reporting complicating the understanding of its full scale. This report analyzes the attackers' tactics, techniques, and procedures (TTPs), explores potential motivations, and provides detection strategies, mitigation recommendations, and threat-hunting guidance.",
          "modified": "2025-03-23T18:04:46.257000",
          "created": "2025-02-21T18:41:11.695000",
          "tags": [],
          "references": [
            "https://documents.trendmicro.com/assets/txt/UpdatedShadowpad-IOCsmqLCZpB.txt",
            "https://github.com/cert-orangecyberdefense/cti/blob/main/green_nailao/iocs",
            "https://www.trendmicro.com/en_us/research/25/b/updated-shadowpad-malware-leads-to-ransomware-deployment.html",
            "https://www.orangecyberdefense.com/global/blog/cert-news/meet-nailaolocker-a-ransomware-distributed-in-europe-by-shadowpad-and-plugx-backdoors#c137076"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Italy",
            "France",
            "Spain",
            "United Kingdom of Great Britain and Northern Ireland",
            "India",
            "Kazakhstan",
            "Thailand",
            "Viet Nam",
            "Argentina"
          ],
          "malware_families": [
            {
              "id": "ShadowPad",
              "display_name": "ShadowPad",
              "target": null
            },
            {
              "id": "PlugX",
              "display_name": "PlugX",
              "target": null
            },
            {
              "id": "NailaoLocker",
              "display_name": "NailaoLocker",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1078.004",
              "name": "Cloud Accounts",
              "display_name": "T1078.004 - Cloud Accounts"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "T1560.001",
              "name": "Archive via Utility",
              "display_name": "T1560.001 - Archive via Utility"
            }
          ],
          "industries": [
            "Health Care and Social Assistance",
            "Manufacturing",
            "Finance and Insurance",
            "Utilities",
            "Transportation and Warehousing",
            "Mining, Quarrying, and Oil & Gas Extraction",
            "Educational Services",
            "Arts, Entertainment, and Recreation",
            "Information"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "eric.ford",
            "id": "42510",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_42510/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1,
            "hostname": 11,
            "CVE": 1
          },
          "indicator_count": 13,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 130,
          "modified_text": "433 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Emmenhtal.pdf",
        "https://documents.trendmicro.com/assets/txt/UpdatedShadowpad-IOCsmqLCZpB.txt",
        "https://www.trendmicro.com/en_us/research/25/b/updated-shadowpad-malware-leads-to-ransomware-deployment.html",
        "https://www.orangecyberdefense.com/global/blog/cert-news/meet-nailaolocker-a-ransomware-distributed-in-europe-by-shadowpad-and-plugx-backdoors#c137076",
        "https://github.com/cert-orangecyberdefense/cti/blob/main/green_nailao/iocs"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Shadowpad",
            "Plugx",
            "Nailaolocker"
          ],
          "industries": [
            "Arts, entertainment, and recreation",
            "Manufacturing",
            "Finance and insurance",
            "Information",
            "Transportation and warehousing",
            "Health care and social assistance",
            "Utilities",
            "Educational services",
            "Mining, quarrying, and oil & gas extraction"
          ],
          "unique_indicators": 1692
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/chtq.net",
    "whois": "http://whois.domaintools.com/chtq.net",
    "domain": "chtq.net",
    "hostname": "dscriy.chtq.net"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "6889ebeb317457163ab8fa42",
      "name": "Emmenhtal loader",
      "description": "Campaigns that used Emmenhtal to deliver various payloads",
      "modified": "2025-08-29T09:03:58.967000",
      "created": "2025-07-30T09:54:51.943000",
      "tags": [],
      "references": [
        "Emmenhtal.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 27,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 395,
        "BitcoinAddress": 1,
        "CVE": 6,
        "FileHash-MD5": 240,
        "FileHash-SHA1": 123,
        "FileHash-SHA256": 392,
        "domain": 182,
        "email": 1,
        "hostname": 181
      },
      "indicator_count": 1521,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 42,
      "modified_text": "274 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "688b0dde98e8d32361238f0f",
      "name": "Emmenhtal Loader Campaign deliver various payloads                                         [IMEBEEIMFINE]",
      "description": "",
      "modified": "2025-08-29T09:03:58.967000",
      "created": "2025-07-31T06:31:58.326000",
      "tags": [],
      "references": [
        "Emmenhtal.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6889ebeb317457163ab8fa42",
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 395,
        "BitcoinAddress": 1,
        "CVE": 6,
        "FileHash-MD5": 240,
        "FileHash-SHA1": 123,
        "FileHash-SHA256": 392,
        "domain": 182,
        "email": 1,
        "hostname": 181
      },
      "indicator_count": 1521,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "274 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67b8c8c79c31a847649a026f",
      "name": "Ransomware or Espionage? Green Nailao Campaign Blurs the Line Between Cybercrime and State-Sponsored Operations",
      "description": "This intelligence report details how the Green Nailao campaign leverages cyberespionage-linked tools alongside ransomware, raising questions about the attackers' true intent. The campaign targeted organizations across multiple industries, with discrepancies in victim reporting complicating the understanding of its full scale. This report analyzes the attackers' tactics, techniques, and procedures (TTPs), explores potential motivations, and provides detection strategies, mitigation recommendations, and threat-hunting guidance.",
      "modified": "2025-03-23T18:04:46.257000",
      "created": "2025-02-21T18:41:11.695000",
      "tags": [],
      "references": [
        "https://documents.trendmicro.com/assets/txt/UpdatedShadowpad-IOCsmqLCZpB.txt",
        "https://github.com/cert-orangecyberdefense/cti/blob/main/green_nailao/iocs",
        "https://www.trendmicro.com/en_us/research/25/b/updated-shadowpad-malware-leads-to-ransomware-deployment.html",
        "https://www.orangecyberdefense.com/global/blog/cert-news/meet-nailaolocker-a-ransomware-distributed-in-europe-by-shadowpad-and-plugx-backdoors#c137076"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Italy",
        "France",
        "Spain",
        "United Kingdom of Great Britain and Northern Ireland",
        "India",
        "Kazakhstan",
        "Thailand",
        "Viet Nam",
        "Argentina"
      ],
      "malware_families": [
        {
          "id": "ShadowPad",
          "display_name": "ShadowPad",
          "target": null
        },
        {
          "id": "PlugX",
          "display_name": "PlugX",
          "target": null
        },
        {
          "id": "NailaoLocker",
          "display_name": "NailaoLocker",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1133",
          "name": "External Remote Services",
          "display_name": "T1133 - External Remote Services"
        },
        {
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "display_name": "T1490 - Inhibit System Recovery"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1078.004",
          "name": "Cloud Accounts",
          "display_name": "T1078.004 - Cloud Accounts"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "T1560.001",
          "name": "Archive via Utility",
          "display_name": "T1560.001 - Archive via Utility"
        }
      ],
      "industries": [
        "Health Care and Social Assistance",
        "Manufacturing",
        "Finance and Insurance",
        "Utilities",
        "Transportation and Warehousing",
        "Mining, Quarrying, and Oil & Gas Extraction",
        "Educational Services",
        "Arts, Entertainment, and Recreation",
        "Information"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "eric.ford",
        "id": "42510",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_42510/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1,
        "hostname": 11,
        "CVE": 1
      },
      "indicator_count": 13,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 130,
      "modified_text": "433 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://dscriy.chtq.net",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://dscriy.chtq.net",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780212412.068768
}