{
  "type": "URL",
  "indicator": "https://obf-io.deobfuscate.io/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://obf-io.deobfuscate.io/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4068785917,
      "indicator": "https://obf-io.deobfuscate.io/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "69bbba3ed3b01bcf222ccc1d",
          "name": "EbeeMar2026 Pt3",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-04-18T08:06:12.483000",
          "created": "2026-03-19T08:56:30.058000",
          "tags": [
            "filehashsha256",
            "filehashmd5",
            "filehashsha1",
            "yara"
          ],
          "references": [
            "IOCs.2026.3.csv"
          ],
          "public": 1,
          "adversary": "ClipXDaemon, TENGU RANSOMWARE, A0Backdoor, GlassWorm, Operation CamelClone, VOID#GEIST",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 97,
            "URL": 96,
            "CVE": 3,
            "FileHash-MD5": 93,
            "FileHash-SHA1": 101,
            "FileHash-SHA256": 153,
            "domain": 156,
            "email": 9
          },
          "indicator_count": 708,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 40,
          "modified_text": "42 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b1a513f065525df442ae88",
          "name": "When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation",
          "description": "The following in-depth analysis of the most commonly-used CAPTCHA - the code used to secure the registration of a person using a password - has been published: (AS 202412).",
          "modified": "2026-04-10T17:01:02.103000",
          "created": "2026-03-11T17:23:31.303000",
          "tags": [
            "cybersecurity company",
            "managed detection and response",
            "exposure management",
            "managed security solutions",
            "vulnerability management",
            "exposure assessment platform",
            "vidar",
            "javascript",
            "iocs",
            "clickfix",
            "captcha",
            "rapid7",
            "wordpress",
            "vidar stealer",
            "impure stealer",
            "windows",
            "february",
            "stealc",
            "slovakia",
            "powershell",
            "twitter",
            "body",
            "polish",
            "turkish",
            "hungarian",
            "czech",
            "swedish",
            "loader",
            "python",
            "stealer",
            "rhadamanthys",
            "belarus",
            "exodus",
            "bitcoin",
            "sha256",
            "doubledonut",
            "vodkastealer",
            "htmlcss",
            "fake captcha",
            "html",
            "loader c2s",
            "must"
          ],
          "references": [
            "https://www.rapid7.com/blog/post/tr-malicious-websites-wordpress-compromise-advances-global-stealer-operation/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1584.006",
              "name": "Web Services",
              "display_name": "T1584.006 - Web Services"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1588.001",
              "name": "Malware",
              "display_name": "T1588.001 - Malware"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            },
            {
              "id": "T1608.004",
              "name": "Drive-by Target",
              "display_name": "T1608.004 - Drive-by Target"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027.002",
              "name": "Software Packing",
              "display_name": "T1027.002 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1497.001",
              "name": "System Checks",
              "display_name": "T1497.001 - System Checks"
            },
            {
              "id": "T1497.003",
              "name": "Time Based Evasion",
              "display_name": "T1497.003 - Time Based Evasion"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1552",
              "name": "Unsecured Credentials",
              "display_name": "T1552 - Unsecured Credentials"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1132.002",
              "name": "Non-Standard Encoding",
              "display_name": "T1132.002 - Non-Standard Encoding"
            },
            {
              "id": "T1573.001",
              "name": "Symmetric Cryptography",
              "display_name": "T1573.001 - Symmetric Cryptography"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1102.001",
              "name": "Dead Drop Resolver",
              "display_name": "T1102.001 - Dead Drop Resolver"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 65,
            "domain": 47,
            "hostname": 23,
            "FileHash-MD5": 5,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 22
          },
          "indicator_count": 166,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 541,
          "modified_text": "50 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "683ecc28d5d833c19956cbee",
          "name": "OtterCookie: Analysis of New Lazarus Group Malware",
          "description": "North Korean state-sponsored cyber-attack group Lazarus is continuing to target professionals in the tech, financial and crypto sectors with a new tool called OtterCookie, an analysis shows, including fake job offers.",
          "modified": "2025-07-03T10:00:53.370000",
          "created": "2025-06-03T10:19:20.970000",
          "tags": [
            "ottercookie",
            "invisibleferret",
            "beavertail",
            "mauro eldritch",
            "lazarus",
            "eldritch",
            "solana",
            "ck matrix",
            "lazarus group",
            "javascript",
            "exodus",
            "python",
            "uruguay",
            "team",
            "express",
            "next",
            "anydesk",
            "mamona",
            "dprk",
            "exodus wallet"
          ],
          "references": [
            "https://any.run/cybersecurity-blog/ottercookie-malware-analysis/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "Exodus Wallet",
              "display_name": "Exodus Wallet",
              "target": null
            },
            {
              "id": "Beavertail",
              "display_name": "Beavertail",
              "target": null
            },
            {
              "id": "OtterCookie",
              "display_name": "OtterCookie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            }
          ],
          "industries": [
            "Financial",
            "Cryptocurrency",
            "Crypto"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA256": 4,
            "URL": 15,
            "domain": 3,
            "hostname": 3
          },
          "indicator_count": 26,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 542,
          "modified_text": "331 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6851011a6c087abfa19e269b",
          "name": "Evolution of Tycoon 2FA Defense Evasion Mechanisms",
          "description": "The evolution of cybercriminals\u2019s tactics for bypassing two-factor authentication (2FA) is revealed in a study by security researchers at the Institute for Strategic Studies (ISS).",
          "modified": "2025-06-17T05:52:06.768000",
          "created": "2025-06-17T05:46:02.707000",
          "tags": [
            "tycoon",
            "stage",
            "mechanism",
            "april",
            "redirect",
            "attack detected",
            "ctrl",
            "page",
            "captcha",
            "post request",
            "shift",
            "meta",
            "generic",
            "telegram",
            "august",
            "find",
            "false",
            "model",
            "error",
            "stages",
            "date",
            "manipulation",
            "invisible",
            "saad tycoon",
            "encrypted"
          ],
          "references": [
            "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/",
            "https://socradar.io/tycoon-2fa-an-evolving-phishing-kit-phaas-threats/"
          ],
          "public": 1,
          "adversary": "Saad Tycoon",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Encrypted",
              "display_name": "Encrypted",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1111",
              "name": "Two-Factor Authentication Interception",
              "display_name": "T1111 - Two-Factor Authentication Interception"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "URL": 51,
            "domain": 4,
            "hostname": 25
          },
          "indicator_count": 81,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 542,
          "modified_text": "347 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "682ce996ee00bc29988d4ed4",
          "name": "Tycoon 2FA: Advanced Evasion Techniques in Phishing-as-a-Service",
          "description": "In May 2025, ANY.RUN researchers detailed the evolution of the Tycoon 2FA phishing kit, which targets Microsoft 365 and Gmail credentials. This Phishing-as-a-Service (PhaaS) platform employs sophisticated evasion techniques, including dynamic code generation, obfuscation, and traffic filtering, to bypass two-factor authentication (2FA) defenses. The kit uses an Adversary-in-the-Middle (AiTM) approach to capture session cookies, allowing attackers to reuse sessions and evade security measures. The continuous updates and enhancements in Tycoon 2FA's evasion tactics highlight the persistent threat it poses to corporate defenses.",
          "modified": "2025-05-20T20:44:06.988000",
          "created": "2025-05-20T20:44:06.988000",
          "tags": [
            "tycoon",
            "stage",
            "mechanism",
            "april",
            "redirect",
            "attack detected",
            "ctrl",
            "page",
            "captcha",
            "post request",
            "shift",
            "meta",
            "generic",
            "august",
            "find",
            "false",
            "model",
            "error",
            "stages",
            "date",
            "manipulation",
            "invisible",
            "saad tycoon",
            "encrypted"
          ],
          "references": [
            "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/"
          ],
          "public": 1,
          "adversary": "Saad Tycoon",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Encrypted",
              "display_name": "Encrypted",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1111",
              "name": "Two-Factor Authentication Interception",
              "display_name": "T1111 - Two-Factor Authentication Interception"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "URL": 39,
            "domain": 4,
            "hostname": 26
          },
          "indicator_count": 70,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 541,
          "modified_text": "375 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6826fd781ceaad59a92471f5",
          "name": "Evolution of Tycoon 2FA Defense Evasion Mechanisms: Analysis and Timeline",
          "description": "This article provides an in-depth analysis of the Tycoon 2FA phishing kit, focusing on its continuous evolution and the sophisticated techniques it employs to bypass two-factor authentication (2FA) for Microsoft 365 and Gmail. It explores various evasion mechanisms, including code obfuscation, CAPTCHA checks, and browser fingerprinting, detailing how these methods have changed over time. The study also offers practical tips for detecting Tycoon 2FA attacks, emphasizing the importance of behavioral analysis over signature-based detection.",
          "modified": "2025-05-16T08:55:20.294000",
          "created": "2025-05-16T08:55:20.294000",
          "tags": [
            "tycoon",
            "mechanism",
            "stage",
            "captcha",
            "shift",
            "april",
            "captchas",
            "mechanisms",
            "phaas",
            "tycoon2fa",
            "generic",
            "telegram",
            "august",
            "false",
            "model",
            "error",
            "stages",
            "saad tycoon"
          ],
          "references": [
            "https://medium.com/@anyrun/evolution-of-tycoon-2fa-defense-evasion-mechanisms-analysis-and-timeline-6ec263227daf"
          ],
          "public": 1,
          "adversary": "Saad Tycoon",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1111",
              "name": "Two-Factor Authentication Interception",
              "display_name": "T1111 - Two-Factor Authentication Interception"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "URL": 25,
            "domain": 4,
            "hostname": 24
          },
          "indicator_count": 54,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 540,
          "modified_text": "379 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.rapid7.com/blog/post/tr-malicious-websites-wordpress-compromise-advances-global-stealer-operation/",
        "IOCs.2026.3.csv",
        "https://socradar.io/tycoon-2fa-an-evolving-phishing-kit-phaas-threats/",
        "https://medium.com/@anyrun/evolution-of-tycoon-2fa-defense-evasion-mechanisms-analysis-and-timeline-6ec263227daf",
        "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/",
        "https://any.run/cybersecurity-blog/ottercookie-malware-analysis/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "ClipXDaemon, TENGU RANSOMWARE, A0Backdoor, GlassWorm, Operation CamelClone, VOID#GEIST",
            "Lazarus",
            "Saad Tycoon"
          ],
          "malware_families": [
            "Lazarus",
            "Ottercookie",
            "Beavertail",
            "Encrypted",
            "Exodus wallet"
          ],
          "industries": [
            "Cryptocurrency",
            "Crypto",
            "Financial"
          ],
          "unique_indicators": 929
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/deobfuscate.io",
    "whois": "http://whois.domaintools.com/deobfuscate.io",
    "domain": "deobfuscate.io",
    "hostname": "obf-io.deobfuscate.io"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "69bbba3ed3b01bcf222ccc1d",
      "name": "EbeeMar2026 Pt3",
      "description": "Multiple APT/threat actors, Malware and Campaigns",
      "modified": "2026-04-18T08:06:12.483000",
      "created": "2026-03-19T08:56:30.058000",
      "tags": [
        "filehashsha256",
        "filehashmd5",
        "filehashsha1",
        "yara"
      ],
      "references": [
        "IOCs.2026.3.csv"
      ],
      "public": 1,
      "adversary": "ClipXDaemon, TENGU RANSOMWARE, A0Backdoor, GlassWorm, Operation CamelClone, VOID#GEIST",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 97,
        "URL": 96,
        "CVE": 3,
        "FileHash-MD5": 93,
        "FileHash-SHA1": 101,
        "FileHash-SHA256": 153,
        "domain": 156,
        "email": 9
      },
      "indicator_count": 708,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 40,
      "modified_text": "42 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69b1a513f065525df442ae88",
      "name": "When Trusted Websites Turn Malicious: WordPress Compromises Advance Global Stealer Operation",
      "description": "The following in-depth analysis of the most commonly-used CAPTCHA - the code used to secure the registration of a person using a password - has been published: (AS 202412).",
      "modified": "2026-04-10T17:01:02.103000",
      "created": "2026-03-11T17:23:31.303000",
      "tags": [
        "cybersecurity company",
        "managed detection and response",
        "exposure management",
        "managed security solutions",
        "vulnerability management",
        "exposure assessment platform",
        "vidar",
        "javascript",
        "iocs",
        "clickfix",
        "captcha",
        "rapid7",
        "wordpress",
        "vidar stealer",
        "impure stealer",
        "windows",
        "february",
        "stealc",
        "slovakia",
        "powershell",
        "twitter",
        "body",
        "polish",
        "turkish",
        "hungarian",
        "czech",
        "swedish",
        "loader",
        "python",
        "stealer",
        "rhadamanthys",
        "belarus",
        "exodus",
        "bitcoin",
        "sha256",
        "doubledonut",
        "vodkastealer",
        "htmlcss",
        "fake captcha",
        "html",
        "loader c2s",
        "must"
      ],
      "references": [
        "https://www.rapid7.com/blog/post/tr-malicious-websites-wordpress-compromise-advances-global-stealer-operation/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1584.006",
          "name": "Web Services",
          "display_name": "T1584.006 - Web Services"
        },
        {
          "id": "T1587",
          "name": "Develop Capabilities",
          "display_name": "T1587 - Develop Capabilities"
        },
        {
          "id": "T1588.001",
          "name": "Malware",
          "display_name": "T1588.001 - Malware"
        },
        {
          "id": "T1608.001",
          "name": "Upload Malware",
          "display_name": "T1608.001 - Upload Malware"
        },
        {
          "id": "T1608.004",
          "name": "Drive-by Target",
          "display_name": "T1608.004 - Drive-by Target"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027.002",
          "name": "Software Packing",
          "display_name": "T1027.002 - Software Packing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1497.001",
          "name": "System Checks",
          "display_name": "T1497.001 - System Checks"
        },
        {
          "id": "T1497.003",
          "name": "Time Based Evasion",
          "display_name": "T1497.003 - Time Based Evasion"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1552",
          "name": "Unsecured Credentials",
          "display_name": "T1552 - Unsecured Credentials"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1132.002",
          "name": "Non-Standard Encoding",
          "display_name": "T1132.002 - Non-Standard Encoding"
        },
        {
          "id": "T1573.001",
          "name": "Symmetric Cryptography",
          "display_name": "T1573.001 - Symmetric Cryptography"
        },
        {
          "id": "T1104",
          "name": "Multi-Stage Channels",
          "display_name": "T1104 - Multi-Stage Channels"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1102.001",
          "name": "Dead Drop Resolver",
          "display_name": "T1102.001 - Dead Drop Resolver"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 65,
        "domain": 47,
        "hostname": 23,
        "FileHash-MD5": 5,
        "FileHash-SHA1": 4,
        "FileHash-SHA256": 22
      },
      "indicator_count": 166,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 541,
      "modified_text": "50 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "683ecc28d5d833c19956cbee",
      "name": "OtterCookie: Analysis of New Lazarus Group Malware",
      "description": "North Korean state-sponsored cyber-attack group Lazarus is continuing to target professionals in the tech, financial and crypto sectors with a new tool called OtterCookie, an analysis shows, including fake job offers.",
      "modified": "2025-07-03T10:00:53.370000",
      "created": "2025-06-03T10:19:20.970000",
      "tags": [
        "ottercookie",
        "invisibleferret",
        "beavertail",
        "mauro eldritch",
        "lazarus",
        "eldritch",
        "solana",
        "ck matrix",
        "lazarus group",
        "javascript",
        "exodus",
        "python",
        "uruguay",
        "team",
        "express",
        "next",
        "anydesk",
        "mamona",
        "dprk",
        "exodus wallet"
      ],
      "references": [
        "https://any.run/cybersecurity-blog/ottercookie-malware-analysis/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lazarus",
          "display_name": "Lazarus",
          "target": null
        },
        {
          "id": "Exodus Wallet",
          "display_name": "Exodus Wallet",
          "target": null
        },
        {
          "id": "Beavertail",
          "display_name": "Beavertail",
          "target": null
        },
        {
          "id": "OtterCookie",
          "display_name": "OtterCookie",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        }
      ],
      "industries": [
        "Financial",
        "Cryptocurrency",
        "Crypto"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA256": 4,
        "URL": 15,
        "domain": 3,
        "hostname": 3
      },
      "indicator_count": 26,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 542,
      "modified_text": "331 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6851011a6c087abfa19e269b",
      "name": "Evolution of Tycoon 2FA Defense Evasion Mechanisms",
      "description": "The evolution of cybercriminals\u2019s tactics for bypassing two-factor authentication (2FA) is revealed in a study by security researchers at the Institute for Strategic Studies (ISS).",
      "modified": "2025-06-17T05:52:06.768000",
      "created": "2025-06-17T05:46:02.707000",
      "tags": [
        "tycoon",
        "stage",
        "mechanism",
        "april",
        "redirect",
        "attack detected",
        "ctrl",
        "page",
        "captcha",
        "post request",
        "shift",
        "meta",
        "generic",
        "telegram",
        "august",
        "find",
        "false",
        "model",
        "error",
        "stages",
        "date",
        "manipulation",
        "invisible",
        "saad tycoon",
        "encrypted"
      ],
      "references": [
        "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/",
        "https://socradar.io/tycoon-2fa-an-evolving-phishing-kit-phaas-threats/"
      ],
      "public": 1,
      "adversary": "Saad Tycoon",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Encrypted",
          "display_name": "Encrypted",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1111",
          "name": "Two-Factor Authentication Interception",
          "display_name": "T1111 - Two-Factor Authentication Interception"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "URL": 51,
        "domain": 4,
        "hostname": 25
      },
      "indicator_count": 81,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 542,
      "modified_text": "347 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "682ce996ee00bc29988d4ed4",
      "name": "Tycoon 2FA: Advanced Evasion Techniques in Phishing-as-a-Service",
      "description": "In May 2025, ANY.RUN researchers detailed the evolution of the Tycoon 2FA phishing kit, which targets Microsoft 365 and Gmail credentials. This Phishing-as-a-Service (PhaaS) platform employs sophisticated evasion techniques, including dynamic code generation, obfuscation, and traffic filtering, to bypass two-factor authentication (2FA) defenses. The kit uses an Adversary-in-the-Middle (AiTM) approach to capture session cookies, allowing attackers to reuse sessions and evade security measures. The continuous updates and enhancements in Tycoon 2FA's evasion tactics highlight the persistent threat it poses to corporate defenses.",
      "modified": "2025-05-20T20:44:06.988000",
      "created": "2025-05-20T20:44:06.988000",
      "tags": [
        "tycoon",
        "stage",
        "mechanism",
        "april",
        "redirect",
        "attack detected",
        "ctrl",
        "page",
        "captcha",
        "post request",
        "shift",
        "meta",
        "generic",
        "august",
        "find",
        "false",
        "model",
        "error",
        "stages",
        "date",
        "manipulation",
        "invisible",
        "saad tycoon",
        "encrypted"
      ],
      "references": [
        "https://any.run/cybersecurity-blog/tycoon2fa-evasion-analysis/"
      ],
      "public": 1,
      "adversary": "Saad Tycoon",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Encrypted",
          "display_name": "Encrypted",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1111",
          "name": "Two-Factor Authentication Interception",
          "display_name": "T1111 - Two-Factor Authentication Interception"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "URL": 39,
        "domain": 4,
        "hostname": 26
      },
      "indicator_count": 70,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 541,
      "modified_text": "375 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6826fd781ceaad59a92471f5",
      "name": "Evolution of Tycoon 2FA Defense Evasion Mechanisms: Analysis and Timeline",
      "description": "This article provides an in-depth analysis of the Tycoon 2FA phishing kit, focusing on its continuous evolution and the sophisticated techniques it employs to bypass two-factor authentication (2FA) for Microsoft 365 and Gmail. It explores various evasion mechanisms, including code obfuscation, CAPTCHA checks, and browser fingerprinting, detailing how these methods have changed over time. The study also offers practical tips for detecting Tycoon 2FA attacks, emphasizing the importance of behavioral analysis over signature-based detection.",
      "modified": "2025-05-16T08:55:20.294000",
      "created": "2025-05-16T08:55:20.294000",
      "tags": [
        "tycoon",
        "mechanism",
        "stage",
        "captcha",
        "shift",
        "april",
        "captchas",
        "mechanisms",
        "phaas",
        "tycoon2fa",
        "generic",
        "telegram",
        "august",
        "false",
        "model",
        "error",
        "stages",
        "saad tycoon"
      ],
      "references": [
        "https://medium.com/@anyrun/evolution-of-tycoon-2fa-defense-evasion-mechanisms-analysis-and-timeline-6ec263227daf"
      ],
      "public": 1,
      "adversary": "Saad Tycoon",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1111",
          "name": "Two-Factor Authentication Interception",
          "display_name": "T1111 - Two-Factor Authentication Interception"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "URL": 25,
        "domain": 4,
        "hostname": 24
      },
      "indicator_count": 54,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 540,
      "modified_text": "379 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://obf-io.deobfuscate.io/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://obf-io.deobfuscate.io/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780180454.9893246
}