{
  "type": "URL",
  "indicator": "https://solutionconect.online/uu2/x3/JavaOracle.msi",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://solutionconect.online/uu2/x3/JavaOracle.msi",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3412908201,
      "indicator": "https://solutionconect.online/uu2/x3/JavaOracle.msi",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "6298718ccb0c8c00f0485af3",
          "name": "State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage",
          "description": "State-sponsored cyber-espionage groups around the world are using the ongoing Russia-Ukraine war as a bait for their attacks, according to research by Check Point Research and Kaspersky Technologies.",
          "modified": "2022-07-02T00:05:39.094000",
          "created": "2022-06-02T08:15:08.016000",
          "tags": [
            "el machete",
            "lyceum",
            "ukraine",
            "sidewinder",
            "apt",
            "cve201711882",
            "geopolitical conflict"
          ],
          "references": [
            "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
          ],
          "public": 1,
          "adversary": "El Machete, Lyceum, SideWinder",
          "targeted_countries": [
            "Venezuela, Bolivarian Republic of",
            "Israel",
            "Saudi Arabia",
            "Pakistan"
          ],
          "malware_families": [
            {
              "id": "Loki.Rat Backdoor",
              "display_name": "Loki.Rat Backdoor",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [
            "Energy",
            "Government",
            "Financial"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 361,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3,
            "URL": 8,
            "domain": 9,
            "FileHash-MD5": 36,
            "FileHash-SHA1": 32,
            "FileHash-SHA256": 49,
            "CVE": 1,
            "YARA": 5
          },
          "indicator_count": 143,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386496,
          "modified_text": "1429 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624c29baad734a210134b02c",
          "name": "State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage",
          "description": "Geopolitical tensions often make headlines and present a golden opportunity for threat actors to exploit the situation, especially those targeting high-profile victims. In the past month while the Russian invasion of Ukraine was unfolding, Check Point Research (CPR) has observed advanced persistent threat (APT) groups around the world launching new campaigns, or quickly adapting ongoing ones to target victims with spear-phishing emails using the war as a lure. The attackers use decoys ranging from official-looking documents to news articles or even job postings, depending on the targets and region. Many of these lure documents utilize malicious macros or template injection to gain an initial foothold into the targeted organizations, and then launch malware attacks.",
          "modified": "2022-05-05T00:01:02.977000",
          "created": "2022-04-05T11:36:25.752000",
          "tags": [
            "APT",
            "spear-phishing",
            "Ukraine",
            "geopolitical conflict"
          ],
          "references": [
            "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
          ],
          "public": 1,
          "adversary": "El Machete, SideWinder, Lyceum",
          "targeted_countries": [
            "Ukraine",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "Golang",
              "display_name": "Golang",
              "target": null
            },
            {
              "id": "SideWinder",
              "display_name": "SideWinder",
              "target": null
            },
            {
              "id": "Lyceum",
              "display_name": "Lyceum",
              "target": null
            },
            {
              "id": "El Machete",
              "display_name": "El Machete",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [
            "Maritime",
            "Energy",
            "Government",
            "Financial"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 269,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 9,
            "FileHash-MD5": 35,
            "FileHash-SHA1": 9,
            "FileHash-SHA256": 27,
            "CVE": 1,
            "URL": 4,
            "YARA": 5,
            "hostname": 1
          },
          "indicator_count": 91,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386500,
          "modified_text": "1487 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708f66513978034c1c91b0",
          "name": "Undefined Name",
          "description": "",
          "modified": "2023-12-06T15:12:38.363000",
          "created": "2023-12-06T15:12:38.363000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 256,
            "domain": 159,
            "FileHash-MD5": 179,
            "FileHash-SHA1": 168,
            "URL": 96,
            "IPv4": 85,
            "hostname": 21
          },
          "indicator_count": 964,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62a240e3ecd94ddae472eb6a",
          "name": "test",
          "description": "",
          "modified": "2022-07-09T00:01:52.431000",
          "created": "2022-06-09T18:50:11.481000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "626d6d47f6da18014c30df7e",
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "threatmanager",
            "id": "74623",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 179,
            "FileHash-SHA1": 168,
            "FileHash-SHA256": 256,
            "domain": 159,
            "IPv4": 85,
            "hostname": 21,
            "URL": 96
          },
          "indicator_count": 964,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 510,
          "modified_text": "1422 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624be75d683cfc55476c6350",
          "name": "State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage - Check Point Research",
          "description": "State-sponsored cyber-espionage groups around the world are using the ongoing Russia-Ukraine war as a bait for their operations, according to research by Check Point Research, a leading security firm.",
          "modified": "2022-05-05T00:01:02.977000",
          "created": "2022-04-05T06:53:17.579000",
          "tags": [
            "golang",
            "dns",
            "tcp",
            "http",
            "blogspot",
            "adobe.msi",
            "el machete",
            "lyceum",
            "c server",
            "ukraine",
            "python",
            "apt group",
            "middle east",
            "dnsdig",
            "saudi arabia",
            "nicaragua",
            "c communication",
            "sidewinder",
            "dark",
            "kremlin",
            "keylogger",
            "agent",
            "virustotal",
            "impact",
            "decoy",
            "cve201711882",
            "webdl"
          ],
          "references": [
            "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
          ],
          "public": 1,
          "adversary": "El Machete",
          "targeted_countries": [
            "China",
            "Iran, Islamic Republic of",
            "Venezuela, Bolivarian Republic of",
            "Nicaragua",
            "Pakistan",
            "Ukraine",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "Golang",
              "display_name": "Golang",
              "target": null
            },
            {
              "id": "DNS",
              "display_name": "DNS",
              "target": null
            },
            {
              "id": "TCP",
              "display_name": "TCP",
              "target": null
            },
            {
              "id": "HTTP",
              "display_name": "HTTP",
              "target": null
            },
            {
              "id": "Adobe.msi",
              "display_name": "Adobe.msi",
              "target": null
            },
            {
              "id": "BlogSpot",
              "display_name": "BlogSpot",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [
            "Maritime",
            "Energy",
            "Government",
            "Financial"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 5,
            "URL": 8,
            "domain": 9,
            "FileHash-MD5": 35,
            "FileHash-SHA1": 9,
            "FileHash-SHA256": 27,
            "CVE": 1,
            "YARA": 5
          },
          "indicator_count": 99,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 871,
          "modified_text": "1487 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6246de7550b019a8b4d3373b",
          "name": "El Machete Sidewinder Lyceum IOCs",
          "description": "El Machete APT: Facebook, Twitter, Instagram, Snapchat, Facebook and Twitter - here is the full list of comments made by people on the site, as well as those on Twitter.",
          "modified": "2022-05-01T00:02:33.075000",
          "created": "2022-04-01T11:13:57.858000",
          "tags": [
            "el machete",
            "sidewinder apt"
          ],
          "references": [
            "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "brazen.fox.thirteen",
            "id": "155136",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 8,
            "FileHash-MD5": 35,
            "FileHash-SHA1": 9,
            "FileHash-SHA256": 27,
            "URL": 3,
            "hostname": 1
          },
          "indicator_count": 83,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 131,
          "modified_text": "1491 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "El Machete, Lyceum, SideWinder",
            "El Machete, SideWinder, Lyceum"
          ],
          "malware_families": [
            "Golang",
            "Loki.rat backdoor",
            "Lyceum",
            "Sidewinder",
            "El machete"
          ],
          "industries": [
            "Financial",
            "Maritime",
            "Government",
            "Energy"
          ],
          "unique_indicators": 147
        },
        "other": {
          "adversary": [
            "El Machete"
          ],
          "malware_families": [
            "Golang",
            "Tcp",
            "Http",
            "Blogspot",
            "Dns",
            "Adobe.msi"
          ],
          "industries": [
            "Government",
            "Financial",
            "Maritime",
            "Energy"
          ],
          "unique_indicators": 973
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/solutionconect.online",
    "whois": "http://whois.domaintools.com/solutionconect.online",
    "domain": "solutionconect.online",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "6298718ccb0c8c00f0485af3",
      "name": "State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage",
      "description": "State-sponsored cyber-espionage groups around the world are using the ongoing Russia-Ukraine war as a bait for their attacks, according to research by Check Point Research and Kaspersky Technologies.",
      "modified": "2022-07-02T00:05:39.094000",
      "created": "2022-06-02T08:15:08.016000",
      "tags": [
        "el machete",
        "lyceum",
        "ukraine",
        "sidewinder",
        "apt",
        "cve201711882",
        "geopolitical conflict"
      ],
      "references": [
        "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
      ],
      "public": 1,
      "adversary": "El Machete, Lyceum, SideWinder",
      "targeted_countries": [
        "Venezuela, Bolivarian Republic of",
        "Israel",
        "Saudi Arabia",
        "Pakistan"
      ],
      "malware_families": [
        {
          "id": "Loki.Rat Backdoor",
          "display_name": "Loki.Rat Backdoor",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1203",
          "name": "Exploitation for Client Execution",
          "display_name": "T1203 - Exploitation for Client Execution"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [
        "Energy",
        "Government",
        "Financial"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 361,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3,
        "URL": 8,
        "domain": 9,
        "FileHash-MD5": 36,
        "FileHash-SHA1": 32,
        "FileHash-SHA256": 49,
        "CVE": 1,
        "YARA": 5
      },
      "indicator_count": 143,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386496,
      "modified_text": "1429 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "624c29baad734a210134b02c",
      "name": "State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage",
      "description": "Geopolitical tensions often make headlines and present a golden opportunity for threat actors to exploit the situation, especially those targeting high-profile victims. In the past month while the Russian invasion of Ukraine was unfolding, Check Point Research (CPR) has observed advanced persistent threat (APT) groups around the world launching new campaigns, or quickly adapting ongoing ones to target victims with spear-phishing emails using the war as a lure. The attackers use decoys ranging from official-looking documents to news articles or even job postings, depending on the targets and region. Many of these lure documents utilize malicious macros or template injection to gain an initial foothold into the targeted organizations, and then launch malware attacks.",
      "modified": "2022-05-05T00:01:02.977000",
      "created": "2022-04-05T11:36:25.752000",
      "tags": [
        "APT",
        "spear-phishing",
        "Ukraine",
        "geopolitical conflict"
      ],
      "references": [
        "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
      ],
      "public": 1,
      "adversary": "El Machete, SideWinder, Lyceum",
      "targeted_countries": [
        "Ukraine",
        "Russian Federation"
      ],
      "malware_families": [
        {
          "id": "Golang",
          "display_name": "Golang",
          "target": null
        },
        {
          "id": "SideWinder",
          "display_name": "SideWinder",
          "target": null
        },
        {
          "id": "Lyceum",
          "display_name": "Lyceum",
          "target": null
        },
        {
          "id": "El Machete",
          "display_name": "El Machete",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1127",
          "name": "Trusted Developer Utilities Proxy Execution",
          "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1203",
          "name": "Exploitation for Client Execution",
          "display_name": "T1203 - Exploitation for Client Execution"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1104",
          "name": "Multi-Stage Channels",
          "display_name": "T1104 - Multi-Stage Channels"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [
        "Maritime",
        "Energy",
        "Government",
        "Financial"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 269,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 9,
        "FileHash-MD5": 35,
        "FileHash-SHA1": 9,
        "FileHash-SHA256": 27,
        "CVE": 1,
        "URL": 4,
        "YARA": 5,
        "hostname": 1
      },
      "indicator_count": 91,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386500,
      "modified_text": "1487 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708f66513978034c1c91b0",
      "name": "Undefined Name",
      "description": "",
      "modified": "2023-12-06T15:12:38.363000",
      "created": "2023-12-06T15:12:38.363000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 256,
        "domain": 159,
        "FileHash-MD5": 179,
        "FileHash-SHA1": 168,
        "URL": 96,
        "IPv4": 85,
        "hostname": 21
      },
      "indicator_count": 964,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "62a240e3ecd94ddae472eb6a",
      "name": "test",
      "description": "",
      "modified": "2022-07-09T00:01:52.431000",
      "created": "2022-06-09T18:50:11.481000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "626d6d47f6da18014c30df7e",
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "threatmanager",
        "id": "74623",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 179,
        "FileHash-SHA1": 168,
        "FileHash-SHA256": 256,
        "domain": 159,
        "IPv4": 85,
        "hostname": 21,
        "URL": 96
      },
      "indicator_count": 964,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 510,
      "modified_text": "1422 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "624be75d683cfc55476c6350",
      "name": "State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage - Check Point Research",
      "description": "State-sponsored cyber-espionage groups around the world are using the ongoing Russia-Ukraine war as a bait for their operations, according to research by Check Point Research, a leading security firm.",
      "modified": "2022-05-05T00:01:02.977000",
      "created": "2022-04-05T06:53:17.579000",
      "tags": [
        "golang",
        "dns",
        "tcp",
        "http",
        "blogspot",
        "adobe.msi",
        "el machete",
        "lyceum",
        "c server",
        "ukraine",
        "python",
        "apt group",
        "middle east",
        "dnsdig",
        "saudi arabia",
        "nicaragua",
        "c communication",
        "sidewinder",
        "dark",
        "kremlin",
        "keylogger",
        "agent",
        "virustotal",
        "impact",
        "decoy",
        "cve201711882",
        "webdl"
      ],
      "references": [
        "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
      ],
      "public": 1,
      "adversary": "El Machete",
      "targeted_countries": [
        "China",
        "Iran, Islamic Republic of",
        "Venezuela, Bolivarian Republic of",
        "Nicaragua",
        "Pakistan",
        "Ukraine",
        "Russian Federation"
      ],
      "malware_families": [
        {
          "id": "Golang",
          "display_name": "Golang",
          "target": null
        },
        {
          "id": "DNS",
          "display_name": "DNS",
          "target": null
        },
        {
          "id": "TCP",
          "display_name": "TCP",
          "target": null
        },
        {
          "id": "HTTP",
          "display_name": "HTTP",
          "target": null
        },
        {
          "id": "Adobe.msi",
          "display_name": "Adobe.msi",
          "target": null
        },
        {
          "id": "BlogSpot",
          "display_name": "BlogSpot",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1127",
          "name": "Trusted Developer Utilities Proxy Execution",
          "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1203",
          "name": "Exploitation for Client Execution",
          "display_name": "T1203 - Exploitation for Client Execution"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1104",
          "name": "Multi-Stage Channels",
          "display_name": "T1104 - Multi-Stage Channels"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [
        "Maritime",
        "Energy",
        "Government",
        "Financial"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 5,
        "URL": 8,
        "domain": 9,
        "FileHash-MD5": 35,
        "FileHash-SHA1": 9,
        "FileHash-SHA256": 27,
        "CVE": 1,
        "YARA": 5
      },
      "indicator_count": 99,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 871,
      "modified_text": "1487 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6246de7550b019a8b4d3373b",
      "name": "El Machete Sidewinder Lyceum IOCs",
      "description": "El Machete APT: Facebook, Twitter, Instagram, Snapchat, Facebook and Twitter - here is the full list of comments made by people on the site, as well as those on Twitter.",
      "modified": "2022-05-01T00:02:33.075000",
      "created": "2022-04-01T11:13:57.858000",
      "tags": [
        "el machete",
        "sidewinder apt"
      ],
      "references": [
        "https://research.checkpoint.com/2022/state-sponsored-attack-groups-capitalise-on-russia-ukraine-war-for-cyber-espionage/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "brazen.fox.thirteen",
        "id": "155136",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 8,
        "FileHash-MD5": 35,
        "FileHash-SHA1": 9,
        "FileHash-SHA256": 27,
        "URL": 3,
        "hostname": 1
      },
      "indicator_count": 83,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 131,
      "modified_text": "1491 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://solutionconect.online/uu2/x3/JavaOracle.msi",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://solutionconect.online/uu2/x3/JavaOracle.msi",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780212290.1027968
}