{
  "type": "URL",
  "indicator": "https://t.me/repacks_by_xetrin",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://t.me/repacks_by_xetrin",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "alexa",
        "message": "Alexa rank: #326",
        "name": "Listed on Alexa"
      },
      {
        "source": "akamai",
        "message": "Akamai rank: #7511",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain t.me",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain t.me",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3942078608,
      "indicator": "https://t.me/repacks_by_xetrin",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "66bf266b6fcd9faea7066e4a",
          "name": "Malwarebytes - Compromised Host | Injector | Simba | System Hijacking",
          "description": "\"Bundled Files: Malwarebytes.Premium.prem.com:\nMalicious noses sound in Malwarebytes with capabilities to infect entire system, bios (all). Complete CnC. High priority malicious.\nALF:JASYP:PUAWin32/Bibado!atmn\nBackdoor.Win32.Shiz.ivr\nGeneric\nSimda\nVirTool:Win32/Injector.gen!BQ\nWin.Trojan.Agent-316098\nWin.Trojan.Agent-316117",
          "modified": "2024-09-15T07:02:25.374000",
          "created": "2024-08-16T10:14:03.907000",
          "tags": [
            "historical ssl",
            "threat network",
            "infrastructure",
            "referrer",
            "adversaries",
            "information",
            "win32diskdrive",
            "win32processor",
            "windows",
            "registry run",
            "registers",
            "flow t1574",
            "dll sideloading",
            "powershell",
            "window",
            "modify registry",
            "e1203 windows",
            "catalog tree",
            "analysis ob0001",
            "b0001 memory",
            "b0002 guard",
            "virtual machine",
            "detection b0009",
            "check registry",
            "check",
            "cnamazon rsa",
            "m02 oamazon",
            "number",
            "cus subject",
            "data",
            "m01 oamazon",
            "dns resolutions",
            "ip traffic",
            "memory pattern",
            "domains",
            "hashes",
            "user",
            "peexe c",
            "text c",
            "menu c",
            "menuprograms c",
            "games c",
            "text",
            "ttf c",
            "file system",
            "defender c",
            "desktop",
            "analyzer paste",
            "iocs",
            "hostnames",
            "url https",
            "samples",
            "generic malware",
            "tag count",
            "tue apr",
            "analyzer threat",
            "url summary",
            "ip summary",
            "summary",
            "sample",
            "first",
            "generic",
            "united",
            "mail spammer",
            "host",
            "cins active",
            "poor reputation",
            "detection list",
            "ip address",
            "blacklist",
            "malicious host",
            "team http",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "fuery",
            "malware",
            "presenoker",
            "team",
            "riskware",
            "artemis",
            "passive dns",
            "as44273 host",
            "urls",
            "scan endpoints",
            "all scoreblue",
            "pulse pulses",
            "files",
            "domain",
            "files ip",
            "unknown",
            "germany unknown",
            "bq aug",
            "virtool",
            "ipv4",
            "main",
            "related pulses",
            "file samples",
            "files matching",
            "show",
            "search",
            "date hash",
            "showing",
            "next",
            "win32",
            "nxdomain",
            "ip related",
            "gmt content",
            "type",
            "x frame",
            "sameorigin x",
            "xss protection",
            "encrypt",
            "asnone united",
            "title error",
            "pulse submit",
            "url analysis",
            "date",
            "status",
            "creation date",
            "name servers",
            "hostname",
            "urls http",
            "msie",
            "windows nt",
            "slcc2",
            "media center",
            "suspicious",
            "verisign",
            "simda",
            "copy",
            "possible",
            "class",
            "write",
            "code",
            "win32 exe",
            "available from",
            "services",
            "registry tech",
            "server",
            "registrar abuse",
            "dnssec",
            "registrant name",
            "ninite",
            "dns replication",
            "technology",
            "bq jun",
            "bq jul",
            "domain status",
            "domain name",
            "contact email",
            "contact phone",
            "full name",
            "algorithm",
            "v3 serial",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "usage",
            "info",
            "avast avg",
            "entries",
            "exclusionpath",
            "created",
            "shell commands",
            "processes tree",
            "silent log",
            "norestart",
            "k wersvcgroup",
            "pss s",
            "k wsappx",
            "signals mutexes",
            "mutexes",
            "global",
            "synchronization",
            "dataset",
            "system property",
            "lookups",
            "select index",
            "macaddress",
            "adaptertypeid0",
            "win32bios",
            "index0",
            "where index0",
            "select uuid",
            "self-delete",
            "persistence",
            "macro-powershell",
            "long-sleeps",
            "calls-wmi",
            "checks-bios",
            "checks-disk-space",
            "checks-memory-available",
            "checks-network-adapters",
            "checks-usb-bus",
            "checks-user-input",
            "crypto",
            "detect-debug-environment",
            "dos batch",
            "file type",
            "pe resource",
            "malicious",
            "socks5systemz",
            "nushell",
            "autodiscovery",
            "cookietheft",
            "twitter ad",
            "dos batch file",
            "t1064 executes",
            "mitre att",
            "ta0002 command",
            "t1059 uses",
            "dlls privilege",
            "dlls defense",
            "evasion ta0005"
          ],
          "references": [
            "Researched: Malwarebytes.Premium.v5.1.6.RePack.by.xetrin.zip",
            "MALWARE BANKER TROJAN EVADER Researched: block.malwarebytes.com",
            "Crowdsourced IDS rules: Matches rule (port_scan) UDP portsweep",
            "Crowdsourced Sigma: Matches rule Registry Persistence via Service in Safe Mode by frack113",
            "Crowdsourced Sigma: Matches rule Hiding Files with Attrib.exe by Sami Ruohonen | Matches rule Non Interactive PowerShell Process Spawned by Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements",
            "Crowdsourced Sigma: Matches rule New Root Certificate Installed Via Certutil.EXE by oscd.community, @redcanary, Zach Stanford @svch0st",
            "Crowdsourced Sigma: Matches rule Powershell Defender Exclusion by Florian Roth (Nextron Systems)",
            "Crowdsourced Sigma: Matches rule Windows Defender Exclusions Added - PowerShell by Tim Rauch, Elastic (idea)",
            "Crowdsourced Sigma: Matches rule Potential Persistence Via Custom Protocol Handler by Nasreddine Bencherchali (Nextron Systems)",
            "VirTool:Win32/Injector.gen!BQ - FileHash-SHA256 e3244c33eac9709cac1840b1b131ea25bb7c32652c7badbefe94a06038e2778e",
            "Antivirus Detections: Win.Trojan.Carberp-6809884-0 ,  VirTool:Win32/Injector.gen!BQ  Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0 Yara Detections generic_shellcode_downloader Alerts injection_inter_process injection_create_remote_thread cape_detected_threat",
            "IDS Detections: Backdoor.Win32.Shiz.ivr Checkin Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz",
            "IDS Detections: Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0",
            "Yara Detections: generic_shellcode_downloader",
            "Alerts: injection_inter_process injection_create_remote_thread cape_detected_threat cape_extracted_content",
            "Silent Uninstalling.cmd | DosS | PUA.HackTool | FileHash-SHA256 26b6f985a431cbb246f62f6058958990bb468a79487c502e5815e78d6e88fe53"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent-316098",
              "display_name": "Win.Trojan.Agent-316098",
              "target": null
            },
            {
              "id": "Win.Trojan.Istbar-231",
              "display_name": "Win.Trojan.Istbar-231",
              "target": null
            },
            {
              "id": "ALF:JASYP:PUAWin32/Bibado!atmn",
              "display_name": "ALF:JASYP:PUAWin32/Bibado!atmn",
              "target": null
            },
            {
              "id": "VirTool:Win32/Injector.gen!BQ",
              "display_name": "VirTool:Win32/Injector.gen!BQ",
              "target": "/malware/VirTool:Win32/Injector.gen!BQ"
            },
            {
              "id": "Backdoor.Win32.Shiz.ivr",
              "display_name": "Backdoor.Win32.Shiz.ivr",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent-316117",
              "display_name": "Win.Trojan.Agent-316117",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1091",
              "name": "Replication Through Removable Media",
              "display_name": "T1091 - Replication Through Removable Media"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1120",
              "name": "Peripheral Device Discovery",
              "display_name": "T1120 - Peripheral Device Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1848,
            "FileHash-MD5": 1826,
            "FileHash-SHA1": 1296,
            "domain": 152,
            "hostname": 265,
            "URL": 132,
            "email": 2
          },
          "indicator_count": 5521,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 232,
          "modified_text": "626 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c52fe96ef88583efb8484f",
          "name": "Compromised Host - Malwarebytes | Injector | Simba | System Hijacking",
          "description": "",
          "modified": "2024-09-15T07:02:25.374000",
          "created": "2024-08-21T00:08:09.738000",
          "tags": [
            "historical ssl",
            "threat network",
            "infrastructure",
            "referrer",
            "adversaries",
            "information",
            "win32diskdrive",
            "win32processor",
            "windows",
            "registry run",
            "registers",
            "flow t1574",
            "dll sideloading",
            "powershell",
            "window",
            "modify registry",
            "e1203 windows",
            "catalog tree",
            "analysis ob0001",
            "b0001 memory",
            "b0002 guard",
            "virtual machine",
            "detection b0009",
            "check registry",
            "check",
            "cnamazon rsa",
            "m02 oamazon",
            "number",
            "cus subject",
            "data",
            "m01 oamazon",
            "dns resolutions",
            "ip traffic",
            "memory pattern",
            "domains",
            "hashes",
            "user",
            "peexe c",
            "text c",
            "menu c",
            "menuprograms c",
            "games c",
            "text",
            "ttf c",
            "file system",
            "defender c",
            "desktop",
            "analyzer paste",
            "iocs",
            "hostnames",
            "url https",
            "samples",
            "generic malware",
            "tag count",
            "tue apr",
            "analyzer threat",
            "url summary",
            "ip summary",
            "summary",
            "sample",
            "first",
            "generic",
            "united",
            "mail spammer",
            "host",
            "cins active",
            "poor reputation",
            "detection list",
            "ip address",
            "blacklist",
            "malicious host",
            "team http",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "fuery",
            "malware",
            "presenoker",
            "team",
            "riskware",
            "artemis",
            "passive dns",
            "as44273 host",
            "urls",
            "scan endpoints",
            "all scoreblue",
            "pulse pulses",
            "files",
            "domain",
            "files ip",
            "unknown",
            "germany unknown",
            "bq aug",
            "virtool",
            "ipv4",
            "main",
            "related pulses",
            "file samples",
            "files matching",
            "show",
            "search",
            "date hash",
            "showing",
            "next",
            "win32",
            "nxdomain",
            "ip related",
            "gmt content",
            "type",
            "x frame",
            "sameorigin x",
            "xss protection",
            "encrypt",
            "asnone united",
            "title error",
            "pulse submit",
            "url analysis",
            "date",
            "status",
            "creation date",
            "name servers",
            "hostname",
            "urls http",
            "msie",
            "windows nt",
            "slcc2",
            "media center",
            "suspicious",
            "verisign",
            "simda",
            "copy",
            "possible",
            "class",
            "write",
            "code",
            "win32 exe",
            "available from",
            "services",
            "registry tech",
            "server",
            "registrar abuse",
            "dnssec",
            "registrant name",
            "ninite",
            "dns replication",
            "technology",
            "bq jun",
            "bq jul",
            "domain status",
            "domain name",
            "contact email",
            "contact phone",
            "full name",
            "algorithm",
            "v3 serial",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "usage",
            "info",
            "avast avg",
            "entries",
            "exclusionpath",
            "created",
            "shell commands",
            "processes tree",
            "silent log",
            "norestart",
            "k wersvcgroup",
            "pss s",
            "k wsappx",
            "signals mutexes",
            "mutexes",
            "global",
            "synchronization",
            "dataset",
            "system property",
            "lookups",
            "select index",
            "macaddress",
            "adaptertypeid0",
            "win32bios",
            "index0",
            "where index0",
            "select uuid",
            "self-delete",
            "persistence",
            "macro-powershell",
            "long-sleeps",
            "calls-wmi",
            "checks-bios",
            "checks-disk-space",
            "checks-memory-available",
            "checks-network-adapters",
            "checks-usb-bus",
            "checks-user-input",
            "crypto",
            "detect-debug-environment",
            "dos batch",
            "file type",
            "pe resource",
            "malicious",
            "socks5systemz",
            "nushell",
            "autodiscovery",
            "cookietheft",
            "twitter ad",
            "dos batch file",
            "t1064 executes",
            "mitre att",
            "ta0002 command",
            "t1059 uses",
            "dlls privilege",
            "dlls defense",
            "evasion ta0005"
          ],
          "references": [
            "Researched: Malwarebytes.Premium.v5.1.6.RePack.by.xetrin.zip",
            "MALWARE BANKER TROJAN EVADER Researched: block.malwarebytes.com",
            "Crowdsourced IDS rules: Matches rule (port_scan) UDP portsweep",
            "Crowdsourced Sigma: Matches rule Registry Persistence via Service in Safe Mode by frack113",
            "Crowdsourced Sigma: Matches rule Hiding Files with Attrib.exe by Sami Ruohonen | Matches rule Non Interactive PowerShell Process Spawned by Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements",
            "Crowdsourced Sigma: Matches rule New Root Certificate Installed Via Certutil.EXE by oscd.community, @redcanary, Zach Stanford @svch0st",
            "Crowdsourced Sigma: Matches rule Powershell Defender Exclusion by Florian Roth (Nextron Systems)",
            "Crowdsourced Sigma: Matches rule Windows Defender Exclusions Added - PowerShell by Tim Rauch, Elastic (idea)",
            "Crowdsourced Sigma: Matches rule Potential Persistence Via Custom Protocol Handler by Nasreddine Bencherchali (Nextron Systems)",
            "VirTool:Win32/Injector.gen!BQ - FileHash-SHA256 e3244c33eac9709cac1840b1b131ea25bb7c32652c7badbefe94a06038e2778e",
            "Antivirus Detections: Win.Trojan.Carberp-6809884-0 ,  VirTool:Win32/Injector.gen!BQ  Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0 Yara Detections generic_shellcode_downloader Alerts injection_inter_process injection_create_remote_thread cape_detected_threat",
            "IDS Detections: Backdoor.Win32.Shiz.ivr Checkin Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz",
            "IDS Detections: Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0",
            "Yara Detections: generic_shellcode_downloader",
            "Alerts: injection_inter_process injection_create_remote_thread cape_detected_threat cape_extracted_content",
            "Silent Uninstalling.cmd | DosS | PUA.HackTool | FileHash-SHA256 26b6f985a431cbb246f62f6058958990bb468a79487c502e5815e78d6e88fe53"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent-316098",
              "display_name": "Win.Trojan.Agent-316098",
              "target": null
            },
            {
              "id": "Win.Trojan.Istbar-231",
              "display_name": "Win.Trojan.Istbar-231",
              "target": null
            },
            {
              "id": "ALF:JASYP:PUAWin32/Bibado!atmn",
              "display_name": "ALF:JASYP:PUAWin32/Bibado!atmn",
              "target": null
            },
            {
              "id": "VirTool:Win32/Injector.gen!BQ",
              "display_name": "VirTool:Win32/Injector.gen!BQ",
              "target": "/malware/VirTool:Win32/Injector.gen!BQ"
            },
            {
              "id": "Backdoor.Win32.Shiz.ivr",
              "display_name": "Backdoor.Win32.Shiz.ivr",
              "target": null
            },
            {
              "id": "Simda",
              "display_name": "Simda",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent-316117",
              "display_name": "Win.Trojan.Agent-316117",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1091",
              "name": "Replication Through Removable Media",
              "display_name": "T1091 - Replication Through Removable Media"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1120",
              "name": "Peripheral Device Discovery",
              "display_name": "T1120 - Peripheral Device Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "66bf266b6fcd9faea7066e4a",
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1848,
            "FileHash-MD5": 1826,
            "FileHash-SHA1": 1296,
            "domain": 152,
            "hostname": 265,
            "URL": 132,
            "email": 2
          },
          "indicator_count": 5521,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "626 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Crowdsourced Sigma: Matches rule Potential Persistence Via Custom Protocol Handler by Nasreddine Bencherchali (Nextron Systems)",
        "IDS Detections: Backdoor.Win32.Shiz.ivr Checkin Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz",
        "IDS Detections: Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0",
        "Crowdsourced Sigma: Matches rule Powershell Defender Exclusion by Florian Roth (Nextron Systems)",
        "MALWARE BANKER TROJAN EVADER Researched: block.malwarebytes.com",
        "Researched: Malwarebytes.Premium.v5.1.6.RePack.by.xetrin.zip",
        "Yara Detections: generic_shellcode_downloader",
        "VirTool:Win32/Injector.gen!BQ - FileHash-SHA256 e3244c33eac9709cac1840b1b131ea25bb7c32652c7badbefe94a06038e2778e",
        "Crowdsourced Sigma: Matches rule Windows Defender Exclusions Added - PowerShell by Tim Rauch, Elastic (idea)",
        "Antivirus Detections: Win.Trojan.Carberp-6809884-0 ,  VirTool:Win32/Injector.gen!BQ  Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0 Yara Detections generic_shellcode_downloader Alerts injection_inter_process injection_create_remote_thread cape_detected_threat",
        "Silent Uninstalling.cmd | DosS | PUA.HackTool | FileHash-SHA256 26b6f985a431cbb246f62f6058958990bb468a79487c502e5815e78d6e88fe53",
        "Crowdsourced Sigma: Matches rule New Root Certificate Installed Via Certutil.EXE by oscd.community, @redcanary, Zach Stanford @svch0st",
        "Crowdsourced Sigma: Matches rule Registry Persistence via Service in Safe Mode by frack113",
        "Alerts: injection_inter_process injection_create_remote_thread cape_detected_threat cape_extracted_content",
        "Crowdsourced IDS rules: Matches rule (port_scan) UDP portsweep",
        "Crowdsourced Sigma: Matches rule Hiding Files with Attrib.exe by Sami Ruohonen | Matches rule Non Interactive PowerShell Process Spawned by Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Simda",
            "Win.trojan.agent-316098",
            "Win.trojan.istbar-231",
            "Win.trojan.agent-316117",
            "Virtool:win32/injector.gen!bq",
            "Alf:jasyp:puawin32/bibado!atmn",
            "Backdoor.win32.shiz.ivr",
            "Generic"
          ],
          "industries": [],
          "unique_indicators": 5833
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/t.me",
    "whois": "http://whois.domaintools.com/t.me",
    "domain": "t.me",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "66bf266b6fcd9faea7066e4a",
      "name": "Malwarebytes - Compromised Host | Injector | Simba | System Hijacking",
      "description": "\"Bundled Files: Malwarebytes.Premium.prem.com:\nMalicious noses sound in Malwarebytes with capabilities to infect entire system, bios (all). Complete CnC. High priority malicious.\nALF:JASYP:PUAWin32/Bibado!atmn\nBackdoor.Win32.Shiz.ivr\nGeneric\nSimda\nVirTool:Win32/Injector.gen!BQ\nWin.Trojan.Agent-316098\nWin.Trojan.Agent-316117",
      "modified": "2024-09-15T07:02:25.374000",
      "created": "2024-08-16T10:14:03.907000",
      "tags": [
        "historical ssl",
        "threat network",
        "infrastructure",
        "referrer",
        "adversaries",
        "information",
        "win32diskdrive",
        "win32processor",
        "windows",
        "registry run",
        "registers",
        "flow t1574",
        "dll sideloading",
        "powershell",
        "window",
        "modify registry",
        "e1203 windows",
        "catalog tree",
        "analysis ob0001",
        "b0001 memory",
        "b0002 guard",
        "virtual machine",
        "detection b0009",
        "check registry",
        "check",
        "cnamazon rsa",
        "m02 oamazon",
        "number",
        "cus subject",
        "data",
        "m01 oamazon",
        "dns resolutions",
        "ip traffic",
        "memory pattern",
        "domains",
        "hashes",
        "user",
        "peexe c",
        "text c",
        "menu c",
        "menuprograms c",
        "games c",
        "text",
        "ttf c",
        "file system",
        "defender c",
        "desktop",
        "analyzer paste",
        "iocs",
        "hostnames",
        "url https",
        "samples",
        "generic malware",
        "tag count",
        "tue apr",
        "analyzer threat",
        "url summary",
        "ip summary",
        "summary",
        "sample",
        "first",
        "generic",
        "united",
        "mail spammer",
        "host",
        "cins active",
        "poor reputation",
        "detection list",
        "ip address",
        "blacklist",
        "malicious host",
        "team http",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "fuery",
        "malware",
        "presenoker",
        "team",
        "riskware",
        "artemis",
        "passive dns",
        "as44273 host",
        "urls",
        "scan endpoints",
        "all scoreblue",
        "pulse pulses",
        "files",
        "domain",
        "files ip",
        "unknown",
        "germany unknown",
        "bq aug",
        "virtool",
        "ipv4",
        "main",
        "related pulses",
        "file samples",
        "files matching",
        "show",
        "search",
        "date hash",
        "showing",
        "next",
        "win32",
        "nxdomain",
        "ip related",
        "gmt content",
        "type",
        "x frame",
        "sameorigin x",
        "xss protection",
        "encrypt",
        "asnone united",
        "title error",
        "pulse submit",
        "url analysis",
        "date",
        "status",
        "creation date",
        "name servers",
        "hostname",
        "urls http",
        "msie",
        "windows nt",
        "slcc2",
        "media center",
        "suspicious",
        "verisign",
        "simda",
        "copy",
        "possible",
        "class",
        "write",
        "code",
        "win32 exe",
        "available from",
        "services",
        "registry tech",
        "server",
        "registrar abuse",
        "dnssec",
        "registrant name",
        "ninite",
        "dns replication",
        "technology",
        "bq jun",
        "bq jul",
        "domain status",
        "domain name",
        "contact email",
        "contact phone",
        "full name",
        "algorithm",
        "v3 serial",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "usage",
        "info",
        "avast avg",
        "entries",
        "exclusionpath",
        "created",
        "shell commands",
        "processes tree",
        "silent log",
        "norestart",
        "k wersvcgroup",
        "pss s",
        "k wsappx",
        "signals mutexes",
        "mutexes",
        "global",
        "synchronization",
        "dataset",
        "system property",
        "lookups",
        "select index",
        "macaddress",
        "adaptertypeid0",
        "win32bios",
        "index0",
        "where index0",
        "select uuid",
        "self-delete",
        "persistence",
        "macro-powershell",
        "long-sleeps",
        "calls-wmi",
        "checks-bios",
        "checks-disk-space",
        "checks-memory-available",
        "checks-network-adapters",
        "checks-usb-bus",
        "checks-user-input",
        "crypto",
        "detect-debug-environment",
        "dos batch",
        "file type",
        "pe resource",
        "malicious",
        "socks5systemz",
        "nushell",
        "autodiscovery",
        "cookietheft",
        "twitter ad",
        "dos batch file",
        "t1064 executes",
        "mitre att",
        "ta0002 command",
        "t1059 uses",
        "dlls privilege",
        "dlls defense",
        "evasion ta0005"
      ],
      "references": [
        "Researched: Malwarebytes.Premium.v5.1.6.RePack.by.xetrin.zip",
        "MALWARE BANKER TROJAN EVADER Researched: block.malwarebytes.com",
        "Crowdsourced IDS rules: Matches rule (port_scan) UDP portsweep",
        "Crowdsourced Sigma: Matches rule Registry Persistence via Service in Safe Mode by frack113",
        "Crowdsourced Sigma: Matches rule Hiding Files with Attrib.exe by Sami Ruohonen | Matches rule Non Interactive PowerShell Process Spawned by Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements",
        "Crowdsourced Sigma: Matches rule New Root Certificate Installed Via Certutil.EXE by oscd.community, @redcanary, Zach Stanford @svch0st",
        "Crowdsourced Sigma: Matches rule Powershell Defender Exclusion by Florian Roth (Nextron Systems)",
        "Crowdsourced Sigma: Matches rule Windows Defender Exclusions Added - PowerShell by Tim Rauch, Elastic (idea)",
        "Crowdsourced Sigma: Matches rule Potential Persistence Via Custom Protocol Handler by Nasreddine Bencherchali (Nextron Systems)",
        "VirTool:Win32/Injector.gen!BQ - FileHash-SHA256 e3244c33eac9709cac1840b1b131ea25bb7c32652c7badbefe94a06038e2778e",
        "Antivirus Detections: Win.Trojan.Carberp-6809884-0 ,  VirTool:Win32/Injector.gen!BQ  Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0 Yara Detections generic_shellcode_downloader Alerts injection_inter_process injection_create_remote_thread cape_detected_threat",
        "IDS Detections: Backdoor.Win32.Shiz.ivr Checkin Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz",
        "IDS Detections: Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0",
        "Yara Detections: generic_shellcode_downloader",
        "Alerts: injection_inter_process injection_create_remote_thread cape_detected_threat cape_extracted_content",
        "Silent Uninstalling.cmd | DosS | PUA.HackTool | FileHash-SHA256 26b6f985a431cbb246f62f6058958990bb468a79487c502e5815e78d6e88fe53"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "Win.Trojan.Agent-316098",
          "display_name": "Win.Trojan.Agent-316098",
          "target": null
        },
        {
          "id": "Win.Trojan.Istbar-231",
          "display_name": "Win.Trojan.Istbar-231",
          "target": null
        },
        {
          "id": "ALF:JASYP:PUAWin32/Bibado!atmn",
          "display_name": "ALF:JASYP:PUAWin32/Bibado!atmn",
          "target": null
        },
        {
          "id": "VirTool:Win32/Injector.gen!BQ",
          "display_name": "VirTool:Win32/Injector.gen!BQ",
          "target": "/malware/VirTool:Win32/Injector.gen!BQ"
        },
        {
          "id": "Backdoor.Win32.Shiz.ivr",
          "display_name": "Backdoor.Win32.Shiz.ivr",
          "target": null
        },
        {
          "id": "Simda",
          "display_name": "Simda",
          "target": null
        },
        {
          "id": "Win.Trojan.Agent-316117",
          "display_name": "Win.Trojan.Agent-316117",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1091",
          "name": "Replication Through Removable Media",
          "display_name": "T1091 - Replication Through Removable Media"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1120",
          "name": "Peripheral Device Discovery",
          "display_name": "T1120 - Peripheral Device Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1848,
        "FileHash-MD5": 1826,
        "FileHash-SHA1": 1296,
        "domain": 152,
        "hostname": 265,
        "URL": 132,
        "email": 2
      },
      "indicator_count": 5521,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 232,
      "modified_text": "626 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66c52fe96ef88583efb8484f",
      "name": "Compromised Host - Malwarebytes | Injector | Simba | System Hijacking",
      "description": "",
      "modified": "2024-09-15T07:02:25.374000",
      "created": "2024-08-21T00:08:09.738000",
      "tags": [
        "historical ssl",
        "threat network",
        "infrastructure",
        "referrer",
        "adversaries",
        "information",
        "win32diskdrive",
        "win32processor",
        "windows",
        "registry run",
        "registers",
        "flow t1574",
        "dll sideloading",
        "powershell",
        "window",
        "modify registry",
        "e1203 windows",
        "catalog tree",
        "analysis ob0001",
        "b0001 memory",
        "b0002 guard",
        "virtual machine",
        "detection b0009",
        "check registry",
        "check",
        "cnamazon rsa",
        "m02 oamazon",
        "number",
        "cus subject",
        "data",
        "m01 oamazon",
        "dns resolutions",
        "ip traffic",
        "memory pattern",
        "domains",
        "hashes",
        "user",
        "peexe c",
        "text c",
        "menu c",
        "menuprograms c",
        "games c",
        "text",
        "ttf c",
        "file system",
        "defender c",
        "desktop",
        "analyzer paste",
        "iocs",
        "hostnames",
        "url https",
        "samples",
        "generic malware",
        "tag count",
        "tue apr",
        "analyzer threat",
        "url summary",
        "ip summary",
        "summary",
        "sample",
        "first",
        "generic",
        "united",
        "mail spammer",
        "host",
        "cins active",
        "poor reputation",
        "detection list",
        "ip address",
        "blacklist",
        "malicious host",
        "team http",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "fuery",
        "malware",
        "presenoker",
        "team",
        "riskware",
        "artemis",
        "passive dns",
        "as44273 host",
        "urls",
        "scan endpoints",
        "all scoreblue",
        "pulse pulses",
        "files",
        "domain",
        "files ip",
        "unknown",
        "germany unknown",
        "bq aug",
        "virtool",
        "ipv4",
        "main",
        "related pulses",
        "file samples",
        "files matching",
        "show",
        "search",
        "date hash",
        "showing",
        "next",
        "win32",
        "nxdomain",
        "ip related",
        "gmt content",
        "type",
        "x frame",
        "sameorigin x",
        "xss protection",
        "encrypt",
        "asnone united",
        "title error",
        "pulse submit",
        "url analysis",
        "date",
        "status",
        "creation date",
        "name servers",
        "hostname",
        "urls http",
        "msie",
        "windows nt",
        "slcc2",
        "media center",
        "suspicious",
        "verisign",
        "simda",
        "copy",
        "possible",
        "class",
        "write",
        "code",
        "win32 exe",
        "available from",
        "services",
        "registry tech",
        "server",
        "registrar abuse",
        "dnssec",
        "registrant name",
        "ninite",
        "dns replication",
        "technology",
        "bq jun",
        "bq jul",
        "domain status",
        "domain name",
        "contact email",
        "contact phone",
        "full name",
        "algorithm",
        "v3 serial",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "usage",
        "info",
        "avast avg",
        "entries",
        "exclusionpath",
        "created",
        "shell commands",
        "processes tree",
        "silent log",
        "norestart",
        "k wersvcgroup",
        "pss s",
        "k wsappx",
        "signals mutexes",
        "mutexes",
        "global",
        "synchronization",
        "dataset",
        "system property",
        "lookups",
        "select index",
        "macaddress",
        "adaptertypeid0",
        "win32bios",
        "index0",
        "where index0",
        "select uuid",
        "self-delete",
        "persistence",
        "macro-powershell",
        "long-sleeps",
        "calls-wmi",
        "checks-bios",
        "checks-disk-space",
        "checks-memory-available",
        "checks-network-adapters",
        "checks-usb-bus",
        "checks-user-input",
        "crypto",
        "detect-debug-environment",
        "dos batch",
        "file type",
        "pe resource",
        "malicious",
        "socks5systemz",
        "nushell",
        "autodiscovery",
        "cookietheft",
        "twitter ad",
        "dos batch file",
        "t1064 executes",
        "mitre att",
        "ta0002 command",
        "t1059 uses",
        "dlls privilege",
        "dlls defense",
        "evasion ta0005"
      ],
      "references": [
        "Researched: Malwarebytes.Premium.v5.1.6.RePack.by.xetrin.zip",
        "MALWARE BANKER TROJAN EVADER Researched: block.malwarebytes.com",
        "Crowdsourced IDS rules: Matches rule (port_scan) UDP portsweep",
        "Crowdsourced Sigma: Matches rule Registry Persistence via Service in Safe Mode by frack113",
        "Crowdsourced Sigma: Matches rule Hiding Files with Attrib.exe by Sami Ruohonen | Matches rule Non Interactive PowerShell Process Spawned by Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements",
        "Crowdsourced Sigma: Matches rule New Root Certificate Installed Via Certutil.EXE by oscd.community, @redcanary, Zach Stanford @svch0st",
        "Crowdsourced Sigma: Matches rule Powershell Defender Exclusion by Florian Roth (Nextron Systems)",
        "Crowdsourced Sigma: Matches rule Windows Defender Exclusions Added - PowerShell by Tim Rauch, Elastic (idea)",
        "Crowdsourced Sigma: Matches rule Potential Persistence Via Custom Protocol Handler by Nasreddine Bencherchali (Nextron Systems)",
        "VirTool:Win32/Injector.gen!BQ - FileHash-SHA256 e3244c33eac9709cac1840b1b131ea25bb7c32652c7badbefe94a06038e2778e",
        "Antivirus Detections: Win.Trojan.Carberp-6809884-0 ,  VirTool:Win32/Injector.gen!BQ  Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0 Yara Detections generic_shellcode_downloader Alerts injection_inter_process injection_create_remote_thread cape_detected_threat",
        "IDS Detections: Backdoor.Win32.Shiz.ivr Checkin Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz",
        "IDS Detections: Unsupported/Fake Internet Explorer Version MSIE 2. Unsupported/Fake Windows NT Version 5.0",
        "Yara Detections: generic_shellcode_downloader",
        "Alerts: injection_inter_process injection_create_remote_thread cape_detected_threat cape_extracted_content",
        "Silent Uninstalling.cmd | DosS | PUA.HackTool | FileHash-SHA256 26b6f985a431cbb246f62f6058958990bb468a79487c502e5815e78d6e88fe53"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "Win.Trojan.Agent-316098",
          "display_name": "Win.Trojan.Agent-316098",
          "target": null
        },
        {
          "id": "Win.Trojan.Istbar-231",
          "display_name": "Win.Trojan.Istbar-231",
          "target": null
        },
        {
          "id": "ALF:JASYP:PUAWin32/Bibado!atmn",
          "display_name": "ALF:JASYP:PUAWin32/Bibado!atmn",
          "target": null
        },
        {
          "id": "VirTool:Win32/Injector.gen!BQ",
          "display_name": "VirTool:Win32/Injector.gen!BQ",
          "target": "/malware/VirTool:Win32/Injector.gen!BQ"
        },
        {
          "id": "Backdoor.Win32.Shiz.ivr",
          "display_name": "Backdoor.Win32.Shiz.ivr",
          "target": null
        },
        {
          "id": "Simda",
          "display_name": "Simda",
          "target": null
        },
        {
          "id": "Win.Trojan.Agent-316117",
          "display_name": "Win.Trojan.Agent-316117",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1091",
          "name": "Replication Through Removable Media",
          "display_name": "T1091 - Replication Through Removable Media"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1120",
          "name": "Peripheral Device Discovery",
          "display_name": "T1120 - Peripheral Device Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "66bf266b6fcd9faea7066e4a",
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1848,
        "FileHash-MD5": 1826,
        "FileHash-SHA1": 1296,
        "domain": 152,
        "hostname": 265,
        "URL": 132,
        "email": 2
      },
      "indicator_count": 5521,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "626 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://t.me/repacks_by_xetrin",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://t.me/repacks_by_xetrin",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780537069.842748
}