{
  "type": "URL",
  "indicator": "https://obf-io.deobfuscate.io",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://obf-io.deobfuscate.io",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4069711312,
      "indicator": "https://obf-io.deobfuscate.io",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6957582a5ec95aeb9a62faac",
          "name": "EbeeDec2025 Pt6",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-02-01T14:01:43.935000",
          "created": "2026-01-02T05:31:22.506000",
          "tags": [
            "filehashsha1",
            "filehashsha256",
            "filehashmd5"
          ],
          "references": [
            "IOC-Dec 2025.csv"
          ],
          "public": 1,
          "adversary": "DNS requests to deliver MgBot, Arcane Werewolf, MEDUSA LOCKER, HoneyMyte",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 4,
            "FileHash-MD5": 157,
            "FileHash-SHA1": 82,
            "FileHash-SHA256": 103,
            "URL": 41,
            "domain": 59,
            "hostname": 26,
            "email": 2
          },
          "indicator_count": 474,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 38,
          "modified_text": "118 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68cd3e87c34598454648d266",
          "name": "Magecart Skimmer Analysis: From One Tweet to a Campaign.",
          "description": "Recent investigations into Magecart campaigns have revealed a sophisticated approach to malicious JavaScript injection aimed at skimming payment data from compromised ecommerce websites. The analysis began with an initial observation from a single tweet referencing the potential involvement of a Magecart-style operation specifically targeting http://cc-analytics.com. This prompted further inquiry into the methods used by threat actors.\n\nKey to understanding the attack technique was the deobfuscation of malicious scripts. Analysts utilized a debugging method by prefixing the script with \"debugger;\" and executing it in browser developer tools. Additionally, they employed Python to decode the obfuscated strings, which utilized hexadecimal values and \\x representations, thereby simplifying the extraction of relevant content.",
          "modified": "2025-10-19T11:00:08.739000",
          "created": "2025-09-19T11:29:11.054000",
          "tags": [
            "urlscan",
            "point",
            "debugger",
            "python trick",
            "python",
            "collect credit",
            "process my",
            "dom reference",
            "ip address",
            "magecart"
          ],
          "references": [
            "https://blog.himanshuanand.com/posts/15-09-2025-magecart-skimmer-analysis/"
          ],
          "public": 1,
          "adversary": "Magecart",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Magecart",
              "display_name": "Magecart",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1056.002",
              "name": "GUI Input Capture",
              "display_name": "T1056.002 - GUI Input Capture"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1204.001",
              "name": "Malicious Link",
              "display_name": "T1204.001 - Malicious Link"
            },
            {
              "id": "T1583.006",
              "name": "Web Services",
              "display_name": "T1583.006 - Web Services"
            }
          ],
          "industries": [
            "Ecommerce"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4,
            "domain": 15,
            "hostname": 27
          },
          "indicator_count": 46,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 539,
          "modified_text": "223 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "683ecc28d5d833c19956cbee",
          "name": "OtterCookie: Analysis of New Lazarus Group Malware",
          "description": "North Korean state-sponsored cyber-attack group Lazarus is continuing to target professionals in the tech, financial and crypto sectors with a new tool called OtterCookie, an analysis shows, including fake job offers.",
          "modified": "2025-07-03T10:00:53.370000",
          "created": "2025-06-03T10:19:20.970000",
          "tags": [
            "ottercookie",
            "invisibleferret",
            "beavertail",
            "mauro eldritch",
            "lazarus",
            "eldritch",
            "solana",
            "ck matrix",
            "lazarus group",
            "javascript",
            "exodus",
            "python",
            "uruguay",
            "team",
            "express",
            "next",
            "anydesk",
            "mamona",
            "dprk",
            "exodus wallet"
          ],
          "references": [
            "https://any.run/cybersecurity-blog/ottercookie-malware-analysis/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "Exodus Wallet",
              "display_name": "Exodus Wallet",
              "target": null
            },
            {
              "id": "Beavertail",
              "display_name": "Beavertail",
              "target": null
            },
            {
              "id": "OtterCookie",
              "display_name": "OtterCookie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            }
          ],
          "industries": [
            "Financial",
            "Cryptocurrency",
            "Crypto"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA256": 4,
            "URL": 15,
            "domain": 3,
            "hostname": 3
          },
          "indicator_count": 26,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 542,
          "modified_text": "331 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6851011a6c087abfa19e269b",
          "name": "Evolution of Tycoon 2FA Defense Evasion Mechanisms",
          "description": "The evolution of cybercriminals\u2019s tactics for bypassing two-factor authentication (2FA) is revealed in a study by security researchers at the Institute for Strategic Studies (ISS).",
          "modified": "2025-06-17T05:52:06.768000",
          "created": "2025-06-17T05:46:02.707000",
          "tags": [
            "tycoon",
            "stage",
            "mechanism",
            "april",
            "redirect",
            "attack detected",
            "ctrl",
            "page",
            "captcha",
            "post request",
            "shift",
            "meta",
            "generic",
            "telegram",
            "august",
            "find",
            "false",
            "model",
            "error",
            "stages",
            "date",
            "manipulation",
            "invisible",
            "saad tycoon",
            "encrypted"
          ],
          "references": [
            "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/",
            "https://socradar.io/tycoon-2fa-an-evolving-phishing-kit-phaas-threats/"
          ],
          "public": 1,
          "adversary": "Saad Tycoon",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Encrypted",
              "display_name": "Encrypted",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1111",
              "name": "Two-Factor Authentication Interception",
              "display_name": "T1111 - Two-Factor Authentication Interception"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "URL": 51,
            "domain": 4,
            "hostname": 25
          },
          "indicator_count": 81,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 542,
          "modified_text": "347 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "682ce996ee00bc29988d4ed4",
          "name": "Tycoon 2FA: Advanced Evasion Techniques in Phishing-as-a-Service",
          "description": "In May 2025, ANY.RUN researchers detailed the evolution of the Tycoon 2FA phishing kit, which targets Microsoft 365 and Gmail credentials. This Phishing-as-a-Service (PhaaS) platform employs sophisticated evasion techniques, including dynamic code generation, obfuscation, and traffic filtering, to bypass two-factor authentication (2FA) defenses. The kit uses an Adversary-in-the-Middle (AiTM) approach to capture session cookies, allowing attackers to reuse sessions and evade security measures. The continuous updates and enhancements in Tycoon 2FA's evasion tactics highlight the persistent threat it poses to corporate defenses.",
          "modified": "2025-05-20T20:44:06.988000",
          "created": "2025-05-20T20:44:06.988000",
          "tags": [
            "tycoon",
            "stage",
            "mechanism",
            "april",
            "redirect",
            "attack detected",
            "ctrl",
            "page",
            "captcha",
            "post request",
            "shift",
            "meta",
            "generic",
            "august",
            "find",
            "false",
            "model",
            "error",
            "stages",
            "date",
            "manipulation",
            "invisible",
            "saad tycoon",
            "encrypted"
          ],
          "references": [
            "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/"
          ],
          "public": 1,
          "adversary": "Saad Tycoon",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Encrypted",
              "display_name": "Encrypted",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1111",
              "name": "Two-Factor Authentication Interception",
              "display_name": "T1111 - Two-Factor Authentication Interception"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "URL": 39,
            "domain": 4,
            "hostname": 26
          },
          "indicator_count": 70,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 541,
          "modified_text": "375 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://blog.himanshuanand.com/posts/15-09-2025-magecart-skimmer-analysis/",
        "https://socradar.io/tycoon-2fa-an-evolving-phishing-kit-phaas-threats/",
        "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/",
        "https://any.run/cybersecurity-blog/ottercookie-malware-analysis/",
        "IOC-Dec 2025.csv"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "DNS requests to deliver MgBot, Arcane Werewolf, MEDUSA LOCKER, HoneyMyte",
            "Magecart",
            "Lazarus",
            "Saad Tycoon"
          ],
          "malware_families": [
            "Magecart",
            "Lazarus",
            "Encrypted",
            "Exodus wallet",
            "Ottercookie",
            "Beavertail"
          ],
          "industries": [
            "Financial",
            "Ecommerce",
            "Crypto",
            "Cryptocurrency"
          ],
          "unique_indicators": 554
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/deobfuscate.io",
    "whois": "http://whois.domaintools.com/deobfuscate.io",
    "domain": "deobfuscate.io",
    "hostname": "obf-io.deobfuscate.io"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6957582a5ec95aeb9a62faac",
      "name": "EbeeDec2025 Pt6",
      "description": "Multiple APT/threat actors, Malware and Campaigns",
      "modified": "2026-02-01T14:01:43.935000",
      "created": "2026-01-02T05:31:22.506000",
      "tags": [
        "filehashsha1",
        "filehashsha256",
        "filehashmd5"
      ],
      "references": [
        "IOC-Dec 2025.csv"
      ],
      "public": 1,
      "adversary": "DNS requests to deliver MgBot, Arcane Werewolf, MEDUSA LOCKER, HoneyMyte",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 4,
        "FileHash-MD5": 157,
        "FileHash-SHA1": 82,
        "FileHash-SHA256": 103,
        "URL": 41,
        "domain": 59,
        "hostname": 26,
        "email": 2
      },
      "indicator_count": 474,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 38,
      "modified_text": "118 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68cd3e87c34598454648d266",
      "name": "Magecart Skimmer Analysis: From One Tweet to a Campaign.",
      "description": "Recent investigations into Magecart campaigns have revealed a sophisticated approach to malicious JavaScript injection aimed at skimming payment data from compromised ecommerce websites. The analysis began with an initial observation from a single tweet referencing the potential involvement of a Magecart-style operation specifically targeting http://cc-analytics.com. This prompted further inquiry into the methods used by threat actors.\n\nKey to understanding the attack technique was the deobfuscation of malicious scripts. Analysts utilized a debugging method by prefixing the script with \"debugger;\" and executing it in browser developer tools. Additionally, they employed Python to decode the obfuscated strings, which utilized hexadecimal values and \\x representations, thereby simplifying the extraction of relevant content.",
      "modified": "2025-10-19T11:00:08.739000",
      "created": "2025-09-19T11:29:11.054000",
      "tags": [
        "urlscan",
        "point",
        "debugger",
        "python trick",
        "python",
        "collect credit",
        "process my",
        "dom reference",
        "ip address",
        "magecart"
      ],
      "references": [
        "https://blog.himanshuanand.com/posts/15-09-2025-magecart-skimmer-analysis/"
      ],
      "public": 1,
      "adversary": "Magecart",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Magecart",
          "display_name": "Magecart",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1056.002",
          "name": "GUI Input Capture",
          "display_name": "T1056.002 - GUI Input Capture"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1204.001",
          "name": "Malicious Link",
          "display_name": "T1204.001 - Malicious Link"
        },
        {
          "id": "T1583.006",
          "name": "Web Services",
          "display_name": "T1583.006 - Web Services"
        }
      ],
      "industries": [
        "Ecommerce"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4,
        "domain": 15,
        "hostname": 27
      },
      "indicator_count": 46,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 539,
      "modified_text": "223 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "683ecc28d5d833c19956cbee",
      "name": "OtterCookie: Analysis of New Lazarus Group Malware",
      "description": "North Korean state-sponsored cyber-attack group Lazarus is continuing to target professionals in the tech, financial and crypto sectors with a new tool called OtterCookie, an analysis shows, including fake job offers.",
      "modified": "2025-07-03T10:00:53.370000",
      "created": "2025-06-03T10:19:20.970000",
      "tags": [
        "ottercookie",
        "invisibleferret",
        "beavertail",
        "mauro eldritch",
        "lazarus",
        "eldritch",
        "solana",
        "ck matrix",
        "lazarus group",
        "javascript",
        "exodus",
        "python",
        "uruguay",
        "team",
        "express",
        "next",
        "anydesk",
        "mamona",
        "dprk",
        "exodus wallet"
      ],
      "references": [
        "https://any.run/cybersecurity-blog/ottercookie-malware-analysis/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lazarus",
          "display_name": "Lazarus",
          "target": null
        },
        {
          "id": "Exodus Wallet",
          "display_name": "Exodus Wallet",
          "target": null
        },
        {
          "id": "Beavertail",
          "display_name": "Beavertail",
          "target": null
        },
        {
          "id": "OtterCookie",
          "display_name": "OtterCookie",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        }
      ],
      "industries": [
        "Financial",
        "Cryptocurrency",
        "Crypto"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA256": 4,
        "URL": 15,
        "domain": 3,
        "hostname": 3
      },
      "indicator_count": 26,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 542,
      "modified_text": "331 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6851011a6c087abfa19e269b",
      "name": "Evolution of Tycoon 2FA Defense Evasion Mechanisms",
      "description": "The evolution of cybercriminals\u2019s tactics for bypassing two-factor authentication (2FA) is revealed in a study by security researchers at the Institute for Strategic Studies (ISS).",
      "modified": "2025-06-17T05:52:06.768000",
      "created": "2025-06-17T05:46:02.707000",
      "tags": [
        "tycoon",
        "stage",
        "mechanism",
        "april",
        "redirect",
        "attack detected",
        "ctrl",
        "page",
        "captcha",
        "post request",
        "shift",
        "meta",
        "generic",
        "telegram",
        "august",
        "find",
        "false",
        "model",
        "error",
        "stages",
        "date",
        "manipulation",
        "invisible",
        "saad tycoon",
        "encrypted"
      ],
      "references": [
        "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/",
        "https://socradar.io/tycoon-2fa-an-evolving-phishing-kit-phaas-threats/"
      ],
      "public": 1,
      "adversary": "Saad Tycoon",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Encrypted",
          "display_name": "Encrypted",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1111",
          "name": "Two-Factor Authentication Interception",
          "display_name": "T1111 - Two-Factor Authentication Interception"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "URL": 51,
        "domain": 4,
        "hostname": 25
      },
      "indicator_count": 81,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 542,
      "modified_text": "347 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "682ce996ee00bc29988d4ed4",
      "name": "Tycoon 2FA: Advanced Evasion Techniques in Phishing-as-a-Service",
      "description": "In May 2025, ANY.RUN researchers detailed the evolution of the Tycoon 2FA phishing kit, which targets Microsoft 365 and Gmail credentials. This Phishing-as-a-Service (PhaaS) platform employs sophisticated evasion techniques, including dynamic code generation, obfuscation, and traffic filtering, to bypass two-factor authentication (2FA) defenses. The kit uses an Adversary-in-the-Middle (AiTM) approach to capture session cookies, allowing attackers to reuse sessions and evade security measures. The continuous updates and enhancements in Tycoon 2FA's evasion tactics highlight the persistent threat it poses to corporate defenses.",
      "modified": "2025-05-20T20:44:06.988000",
      "created": "2025-05-20T20:44:06.988000",
      "tags": [
        "tycoon",
        "stage",
        "mechanism",
        "april",
        "redirect",
        "attack detected",
        "ctrl",
        "page",
        "captcha",
        "post request",
        "shift",
        "meta",
        "generic",
        "august",
        "find",
        "false",
        "model",
        "error",
        "stages",
        "date",
        "manipulation",
        "invisible",
        "saad tycoon",
        "encrypted"
      ],
      "references": [
        "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/"
      ],
      "public": 1,
      "adversary": "Saad Tycoon",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Encrypted",
          "display_name": "Encrypted",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1111",
          "name": "Two-Factor Authentication Interception",
          "display_name": "T1111 - Two-Factor Authentication Interception"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "URL": 39,
        "domain": 4,
        "hostname": 26
      },
      "indicator_count": 70,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 541,
      "modified_text": "375 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://obf-io.deobfuscate.io",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://obf-io.deobfuscate.io",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780180264.1931589
}