{
  "type": "URL",
  "indicator": "https://pricelala.com/coi/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://pricelala.com/coi/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3679503398,
      "indicator": "https://pricelala.com/coi/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "65a0194269f81650babf9b6c",
          "name": "Raspberry Robin | Hijacker | link: voyour-cams.xww.de | Monitoring",
          "description": "Raspberry Robin aka Worm.RaspberyRobin started out as an annoying, yet relatively low-profile threat that was often installed via USB drive.\nTo be able to act as a backdoor, malware needs to be active or you need to be able to trigger it remotely. Raspberry Robin gains persistence by adding itself to the RunOnce key in the CurrentUser registry hive of the user who executed the initial malware.\n\nBy using command-and-control (C2) servers hosted on Tor nodes the Raspberry Robin implant can be used to distribute other malware.",
          "modified": "2024-02-10T15:03:45.065000",
          "created": "2024-01-11T16:37:22.751000",
          "tags": [
            "ssl certificate",
            "whois record",
            "contacted",
            "threat roundup",
            "historical ssl",
            "december",
            "october",
            "august",
            "referrer",
            "execution",
            "raspberry robin",
            "ghost rat",
            "service",
            "dtrack",
            "download",
            "malware",
            "hijacker",
            "monitoring",
            "installer",
            "masquerading",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "nginx",
            "parked domain",
            "parking crew",
            "malware hosting",
            "dga parking",
            "msie",
            "cmd",
            "worm",
            "dga malvertizing"
          ],
          "references": [
            "voyour-cams.xww.de",
            "https://otx.alienvault.com/malware/Worm:Win32%2FBenjamin/samples",
            "https://www.malwarebytes.com/blog/news/2022/10/raspberry-robin-worm-used-as-ransomware-prelude"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "LokiBot",
              "display_name": "LokiBot",
              "target": null
            },
            {
              "id": "Ghost RAT",
              "display_name": "Ghost RAT",
              "target": null
            },
            {
              "id": "Worm:Win32/Benjamin",
              "display_name": "Worm:Win32/Benjamin",
              "target": "/malware/Worm:Win32/Benjamin"
            },
            {
              "id": "Raspberry Robin",
              "display_name": "Raspberry Robin",
              "target": null
            },
            {
              "id": "Roshtyak",
              "display_name": "Roshtyak",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1052.001",
              "name": "Exfiltration over USB",
              "display_name": "T1052.001 - Exfiltration over USB"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1038",
              "name": "DLL Search Order Hijacking",
              "display_name": "T1038 - DLL Search Order Hijacking"
            },
            {
              "id": "T1415",
              "name": "URL Scheme Hijacking",
              "display_name": "T1415 - URL Scheme Hijacking"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 81,
            "FileHash-SHA1": 83,
            "FileHash-SHA256": 3484,
            "URL": 7778,
            "domain": 2468,
            "hostname": 2348,
            "email": 2,
            "CVE": 1
          },
          "indicator_count": 16245,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "843 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "645d789f1dce2e8d9b7b749d",
          "name": "URLHaus data - 11-05-2023",
          "description": "",
          "modified": "2023-05-11T23:22:07.029000",
          "created": "2023-05-11T23:22:07.029000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "hajime",
            "arm",
            "mirai",
            "exe",
            "njRAT",
            "32",
            "Smoke Loader",
            "MassLogger",
            "opendir",
            "SnakeKeylogger",
            "AgentTesla",
            "hta",
            "rat",
            "RevengeRAT",
            "additionalpayloads",
            "RaccoonStealer",
            "raccoonv2",
            "RecordBreaker",
            "NetSupport",
            "zip",
            "ascii",
            "powershell",
            "ps",
            "doc",
            "dcrat",
            "CoinMiner",
            "ArkeiStealer",
            "RedLineStealer",
            "Password-protected",
            "rar",
            "gafgyt",
            "BB27",
            "geofenced",
            "js",
            "Qakbot",
            "USA",
            "Quakbot",
            "dll",
            "ua-ps",
            "Encoded",
            "RemcosRAT",
            "encrypted",
            "1231",
            "dropped-by-PrivateLoader",
            "dropped-by-SmokeLoader",
            "1234",
            "7z",
            "qbot",
            "1515",
            "SocGholish",
            "AveMariaRAT",
            "shellscript",
            "sparc",
            "motorola",
            "renesas",
            "BlackGuard",
            "intel",
            "PowerPC",
            "iso",
            "64",
            "Amadey",
            "banker",
            "BRA",
            "downloader",
            "smuggling",
            "trojan",
            "GuLoader",
            "RTF"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 911,
            "IPv4": 341,
            "domain": 265,
            "hostname": 10
          },
          "indicator_count": 1527,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1624,
          "modified_text": "1118 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "voyour-cams.xww.de",
        "https://www.malwarebytes.com/blog/news/2022/10/raspberry-robin-worm-used-as-ransomware-prelude",
        "https://otx.alienvault.com/malware/Worm:Win32%2FBenjamin/samples",
        "https://urlhaus.abuse.ch/browse/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Worm:win32/benjamin",
            "Ghost rat",
            "Lokibot",
            "Roshtyak",
            "Raspberry robin"
          ],
          "industries": [],
          "unique_indicators": 18297
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/pricelala.com",
    "whois": "http://whois.domaintools.com/pricelala.com",
    "domain": "pricelala.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "65a0194269f81650babf9b6c",
      "name": "Raspberry Robin | Hijacker | link: voyour-cams.xww.de | Monitoring",
      "description": "Raspberry Robin aka Worm.RaspberyRobin started out as an annoying, yet relatively low-profile threat that was often installed via USB drive.\nTo be able to act as a backdoor, malware needs to be active or you need to be able to trigger it remotely. Raspberry Robin gains persistence by adding itself to the RunOnce key in the CurrentUser registry hive of the user who executed the initial malware.\n\nBy using command-and-control (C2) servers hosted on Tor nodes the Raspberry Robin implant can be used to distribute other malware.",
      "modified": "2024-02-10T15:03:45.065000",
      "created": "2024-01-11T16:37:22.751000",
      "tags": [
        "ssl certificate",
        "whois record",
        "contacted",
        "threat roundup",
        "historical ssl",
        "december",
        "october",
        "august",
        "referrer",
        "execution",
        "raspberry robin",
        "ghost rat",
        "service",
        "dtrack",
        "download",
        "malware",
        "hijacker",
        "monitoring",
        "installer",
        "masquerading",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "nginx",
        "parked domain",
        "parking crew",
        "malware hosting",
        "dga parking",
        "msie",
        "cmd",
        "worm",
        "dga malvertizing"
      ],
      "references": [
        "voyour-cams.xww.de",
        "https://otx.alienvault.com/malware/Worm:Win32%2FBenjamin/samples",
        "https://www.malwarebytes.com/blog/news/2022/10/raspberry-robin-worm-used-as-ransomware-prelude"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "LokiBot",
          "display_name": "LokiBot",
          "target": null
        },
        {
          "id": "Ghost RAT",
          "display_name": "Ghost RAT",
          "target": null
        },
        {
          "id": "Worm:Win32/Benjamin",
          "display_name": "Worm:Win32/Benjamin",
          "target": "/malware/Worm:Win32/Benjamin"
        },
        {
          "id": "Raspberry Robin",
          "display_name": "Raspberry Robin",
          "target": null
        },
        {
          "id": "Roshtyak",
          "display_name": "Roshtyak",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1052.001",
          "name": "Exfiltration over USB",
          "display_name": "T1052.001 - Exfiltration over USB"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1038",
          "name": "DLL Search Order Hijacking",
          "display_name": "T1038 - DLL Search Order Hijacking"
        },
        {
          "id": "T1415",
          "name": "URL Scheme Hijacking",
          "display_name": "T1415 - URL Scheme Hijacking"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 81,
        "FileHash-SHA1": 83,
        "FileHash-SHA256": 3484,
        "URL": 7778,
        "domain": 2468,
        "hostname": 2348,
        "email": 2,
        "CVE": 1
      },
      "indicator_count": 16245,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "843 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "645d789f1dce2e8d9b7b749d",
      "name": "URLHaus data - 11-05-2023",
      "description": "",
      "modified": "2023-05-11T23:22:07.029000",
      "created": "2023-05-11T23:22:07.029000",
      "tags": [
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "hajime",
        "arm",
        "mirai",
        "exe",
        "njRAT",
        "32",
        "Smoke Loader",
        "MassLogger",
        "opendir",
        "SnakeKeylogger",
        "AgentTesla",
        "hta",
        "rat",
        "RevengeRAT",
        "additionalpayloads",
        "RaccoonStealer",
        "raccoonv2",
        "RecordBreaker",
        "NetSupport",
        "zip",
        "ascii",
        "powershell",
        "ps",
        "doc",
        "dcrat",
        "CoinMiner",
        "ArkeiStealer",
        "RedLineStealer",
        "Password-protected",
        "rar",
        "gafgyt",
        "BB27",
        "geofenced",
        "js",
        "Qakbot",
        "USA",
        "Quakbot",
        "dll",
        "ua-ps",
        "Encoded",
        "RemcosRAT",
        "encrypted",
        "1231",
        "dropped-by-PrivateLoader",
        "dropped-by-SmokeLoader",
        "1234",
        "7z",
        "qbot",
        "1515",
        "SocGholish",
        "AveMariaRAT",
        "shellscript",
        "sparc",
        "motorola",
        "renesas",
        "BlackGuard",
        "intel",
        "PowerPC",
        "iso",
        "64",
        "Amadey",
        "banker",
        "BRA",
        "downloader",
        "smuggling",
        "trojan",
        "GuLoader",
        "RTF"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 911,
        "IPv4": 341,
        "domain": 265,
        "hostname": 10
      },
      "indicator_count": 1527,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1624,
      "modified_text": "1118 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://pricelala.com/coi/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://pricelala.com/coi/",
    "type": "URL",
    "found": true,
    "verdict": "malicious",
    "url_status": "offline",
    "threat": "malware_download",
    "tags": [
      "BB27",
      "geofenced",
      "js",
      "Qakbot",
      "Quakbot",
      "USA"
    ],
    "date_added": "2023-05-11",
    "last_online": "2023-05-13",
    "reporter": "Cryptolaemus1",
    "host": "pricelala.com",
    "payloads": [
      {
        "filename": "Trxo.js",
        "file_type": "js",
        "md5": "66ddf2ce787048ef42149dc49da8239f",
        "sha256": "f42eb7c240517f8e8461d1c0eba13b117927c6c1cf03cad394706653abd9a7f0",
        "signature": "Quakbot",
        "first_seen": "2023-05-13"
      },
      {
        "filename": "Hjgp.js",
        "file_type": "js",
        "md5": "1c7f92e3326afaa1662ea7afc175e730",
        "sha256": "584035be5e8392ecd9839561056e8272e394af5fdf4800b86564c3f5aa314542",
        "signature": "Quakbot",
        "first_seen": "2023-05-13"
      },
      {
        "filename": "Dgqpo.js",
        "file_type": "js",
        "md5": "2f1355821a3f7708efbeef83731f2b18",
        "sha256": "ee5a9ed992eaa053ddb378a0e1ae9d06d2515e0e4552e4a5e6230f9d675b365e",
        "signature": "Quakbot",
        "first_seen": "2023-05-13"
      },
      {
        "filename": "Bezh.js",
        "file_type": "js",
        "md5": "dcd3e1f26ed417b06dcc5d17d807c696",
        "sha256": "a0fa4d7993ee7dd505581708a20acd483527051a50573f424aa015fd5e15be78",
        "signature": null,
        "first_seen": "2023-05-13"
      },
      {
        "filename": "Tdfs.js",
        "file_type": "js",
        "md5": "a9e18d18b134b5b4c29fe3b6a938d47d",
        "sha256": "b3576c6f202488a28c4f8016cac9045e81394710f0cb5f3a8b02d1f0528e7564",
        "signature": "Quakbot",
        "first_seen": "2023-05-13"
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780451015.7767487
}