{
  "type": "URL",
  "indicator": "https://web.zaocloud2stage.stc-dev.net",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://web.zaocloud2stage.stc-dev.net",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4173284069,
      "indicator": "https://web.zaocloud2stage.stc-dev.net",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6a1b57af6e1986d0628bca12",
          "name": "SystemBC RAT, Quant Loader, and LogMeIn.com, combined to execute a multi-stage Corporate Styled Network Intrusion",
          "description": "\"Living off the Land\" Takeover (LogMeIn.com)\u201c\nINCIDENT REPORT: HIGH-VALUE TARGET NETWORK INTRUSION Threat Profile: Human-operated corporate-grade attack chain targeting an isolated device.Vector: Local network exposure (compromised router/neighboring device) or physical media (USB).Attack Chain Stages:Quant Script: Obfuscated entry file bypassing network filters.SystemBC RAT: Creates a silent, persistent SOCKS5/Tor tunnel for attacker commands.LogMeIn Abuse: Attackers use legitimate remote software to control the device undetected.Crowti (CryptoWall): Final ransomware payload to encrypt high-value data.Key Observations: Because the target device lacked direct internet access, adversaries are actively abusing the local network infrastructure or physical proximity to bridge the gap. \n\nI\u2019m open to other opinions regarding this report. I have been unwell and my thinking has been  unclear and even off as I focus on getting well.\nThank you.",
          "modified": "2026-05-30T21:33:35.237000",
          "created": "2026-05-30T21:33:35.237000",
          "tags": [
            "united",
            "unknown aaaa",
            "servers",
            "certificate",
            "urls",
            "logmein",
            "ipv4",
            "url analysis",
            "files",
            "america flag",
            "level",
            "data upload",
            "extraction",
            "failed",
            "enter sc",
            "extri data",
            "include review",
            "stop typ",
            "domain don",
            "united states",
            "america asn",
            "net20525119201",
            "amazon data",
            "net20525119202",
            "address range",
            "cidr",
            "network name",
            "allocation type",
            "whois server",
            "entity adsn1",
            "handle",
            "sc data",
            "netherlands asn",
            "as204601 zomro",
            "dns resolutions",
            "log id",
            "gmtn",
            "timestamp",
            "tls web",
            "expiresfri",
            "path",
            "httponly",
            "salford",
            "sectigo limited",
            "sectigo rsa",
            "accept",
            "organization",
            "false",
            "authentication",
            "ocsp",
            "c179044d",
            "b89a",
            "d4n timestamp",
            "df9b",
            "post na",
            "lredmond",
            "stwa",
            "cnmicrosoft tls",
            "g2 rsa",
            "ca ocsp",
            "rmm domain",
            "search",
            "flashpix",
            "write",
            "unknown",
            "malware",
            "encrypt",
            "high",
            "medium",
            "write c",
            "template",
            "registers",
            "moved",
            "record value",
            "tls sni",
            "observed rmm",
            "omicrosoft",
            "stwashington",
            "server ca",
            "extr data",
            "error",
            "a50 data",
            "pattern match",
            "ascii text",
            "mitre att",
            "ck id",
            "general",
            "local",
            "click",
            "strings",
            "u extractio",
            "extrac data",
            "learn",
            "command",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "spawns",
            "signing defense",
            "discovery att",
            "code signing",
            "defense evasion",
            "t1480.002",
            "mrasn",
            "cachecontrol",
            "connection",
            "date tue",
            "gmt etag",
            "self",
            "etag w/\"leknjhepnj99sn\"",
            "name servers",
            "extre data",
            "observed dns",
            "query",
            "show",
            "localsm05208304",
            "localsm03520304",
            "title error",
            "all ipv4",
            "reverse dns",
            "as14618",
            "extraction data",
            "creato touc",
            "digice rsa",
            "sh certific",
            "hid iv",
            "trojandropper",
            "backdoor",
            "present may",
            "please",
            "x msedge",
            "exploit",
            "as8068",
            "av detection",
            "ratio",
            "ids detections",
            "content length",
            "content type",
            "x powered",
            "asn as16509",
            "x vercel",
            "vercel",
            "gmt content",
            "ransom",
            "dynamicloader",
            "msie",
            "windows nt",
            "wow64",
            "slcc2",
            "media center",
            "sysv",
            "buildid",
            "germany as8560",
            "yara detections",
            "contacted",
            "elf",
            "filehash",
            "av detections",
            "alerts",
            "analysis date",
            "file score",
            "low risk",
            "elf executable",
            "exec amd6464",
            "linux",
            "elf64 operation",
            "unix",
            "compiler",
            "elf info",
            "progbits",
            "offset size",
            "flags",
            "null",
            "hashes o",
            "get http",
            "post http",
            "entries",
            "trojan",
            "pegasus",
            "apple",
            "amazonaws",
            "smtp",
            "self-delete",
            "service-scan",
            "applayer",
            "madagascar",
            "qnapcrypt",
            "mal_elf_systembc_rat",
            "rat",
            "hacktool code",
            "systembc",
            "t1064",
            "create",
            "modify system",
            "process",
            "t1543 privile",
            "ta0004 cr",
            "t1543",
            "creation date",
            "whois show",
            "emails",
            "name logmein",
            "org logmein",
            "summer st",
            "date hash",
            "avast avg",
            "mtb jul",
            "k jun",
            "ai",
            "ai report",
            "appleremotesupport",
            "remotelyanywhere",
            "pegasus related"
          ],
          "references": [
            "https://www.logmein.com/products/resolve \u2022 http://devices-iot.console.gotoresolve.com/",
            "https://adservice.google.com.uy/clk \u2022 adservice.google.com.uy",
            "Amazonaws.com \u2022 Amazon.com",
            "screenmaxxxing.com \u2022 wiki.xxkcamffk.cc \u2022 playfoundermode.com",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ \u2022  www.anyxxxtube.net",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "103.246.145.111 \u2022 http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel",
            "13.107.226.70 \u2022 13.107.253.70 - Malware Hosting",
            "http://212.33.237.86/images/1/report.php",
            "http://watchhers.net/index.php",
            "remoteexecution-runner-api.services.gotoresolve.com",
            "firebaseremoteconfig.googleapis.com",
            "alerts-frontend-api-fd-stage.services-stage.gotoresolve.com",
            "alerts-monitor-api-fd-prodeu.services.gotoresolve.com",
            "testpaging SHA256 756f0b598741a6fdff640a158b6b490472e546d411da2850836b9a8ca76afdc1",
            "Yara Detections: is__elf",
            "IP\u2019s Contacted:  104.17.118.12  57.144.248.1  176.114.120.24  80.12.24.14  95.163.61.73  142.251.98.113  212.227.17.162  77.88.44.55  142.93.142.17  104.18.14.206",
            "Domains Contacted: checkip.amazonaws.com vk.com arena.ai www.yandex.ru stripchat.com",
            "Names: testpaging upof6w.exe",
            "Names: 2026-04-07_259af8b0d0bc540384a06bb730cee9cd_qnapcrypt ELF Info",
            "https://cdn.console.gotoresolve.com/applet",
            "Crowdsourced Signa: Matches rule Suspicious Outbound SMTP",
            "Suspicious DNS Query for IP post), Thomas Patzke Lookup Service APls by Brandon George (blog Crowdsourced)",
            "Crowdsourced IDS: Matches rule ET DROP Spamhaus DROP Listed Traffic Inbound group 60",
            "Matches rule ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com)",
            "Matches rule ET INFO External IP Check (checkip .amazonaws .com)",
            "ET HUNTING Suspicious User-Agent Observed (Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
            "Matches rule SURICATA Applayer Detect protocol only one direction",
            "SystemBC to map the backend network secretly, and a hijacked or fraudulent LogMeIn account ->",
            "to act as their human-controlled, \"living off the land\" command station.",
            "Attack ChainThreat actors chain these three specific components together to bypass traditional ->",
            "security filters:[Quant Script (Initial Drop)] \u2794 [SystemBC (SOCKS5/Tor Tunnel)] \u2794",
            "[LogMeIn.com (Legitimate Remote Access)] \u2794 [Ransomware]",
            "RaaS attack designed to deploy ransomware against \u2018high value\u2019 targets or corporations.",
            "In this specific attack chain, the threat actors use the Quant Loader script for initial entry,",
            "The Entry Vector (Quant Loader): A user interacts with a phishing link or malicious archive file.",
            "An obfuscated Quant Loader script runs natively in the background, evading anti-malware detection",
            "by pulling its primary files over public SMB shares.",
            "The Persistent Backdoor (SystemBC RAT): Quant Loader downloads and executes SystemBC.",
            "SystemBC sets up a scheduled task to stay persistent and opens a stealthy SOCKS5 proxy or Tor network tunnel.",
            "This lets the threat actor route malicious command traffic into the local corporate network undetected.",
            "Once inside the network, attackers avoid deploying more loud hacking tools & Download or abuse LogMeIn[.]com software.",
            "Because LogMeIn is a legitimate remote management tool used by actual IT departments,",
            "its outbound traffic to logmein.com domains looks completely normal to firewalls.",
            "The Objective: The hackers use the trusted LogMeIn connection to freely move laterally, steal data, turn off local security defenses, and deploy network-wide ransomware",
            "remoteexecution-runner-api.services.gotoresolve.com\t\u2022 appleremotesupport.com\t\u2022",
            "firebaseremoteconfig.googleapis.com \u2022 remoteexecution-runner-api.services.gotoresolve.com",
            "remotelyanywhere.com \u2022,http://watchhers.net/index.php \u2022 firebaseremoteconfig.googleapis.com",
            "appleremotesupport.com \u2022 remotelyanywhere.com",
            "Immediate Recommendations: Disconnect all routers and isolate the network.",
            "Air-gap the target device (disable Wi-Fi, pull cables). Expensive : Dispose of all devices.",
            "Change all credentials from a separate, clean network.",
            "If possible: Move to Switzerland"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransom:Win32/Crowti.A",
              "display_name": "Ransom:Win32/Crowti.A",
              "target": "/malware/Ransom:Win32/Crowti.A"
            },
            {
              "id": "Trojan.Systembc/yxgdgz",
              "display_name": "Trojan.Systembc/yxgdgz",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Nivdort.CW",
              "display_name": "TrojanSpy:Win32/Nivdort.CW",
              "target": "/malware/TrojanSpy:Win32/Nivdort.CW"
            },
            {
              "id": "Win.Downloader.Nemucod-6769668-0",
              "display_name": "Win.Downloader.Nemucod-6769668-0",
              "target": null
            },
            {
              "id": "TrojanDownloader:JS/Swabfex.P",
              "display_name": "TrojanDownloader:JS/Swabfex.P",
              "target": "/malware/TrojanDownloader:JS/Swabfex.P"
            },
            {
              "id": "Win.Downloader.Nemucod-6769668-0",
              "display_name": "Win.Downloader.Nemucod-6769668-0",
              "target": null
            },
            {
              "id": "Doc.Downloader.EmotetRed02220-9938909-0",
              "display_name": "Doc.Downloader.EmotetRed02220-9938909-0",
              "target": null
            },
            {
              "id": "TrojanDropper:Win32/Cutwail.gen!K",
              "display_name": "TrojanDropper:Win32/Cutwail.gen!K",
              "target": "/malware/TrojanDropper:Win32/Cutwail.gen!K"
            },
            {
              "id": "Win.Trojan.Gh0stRAT-9955419-1",
              "display_name": "Win.Trojan.Gh0stRAT-9955419-1",
              "target": null
            },
            {
              "id": "Win.Trojan.Hupigon-6989556-0",
              "display_name": "Win.Trojan.Hupigon-6989556-0",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/Cassini_6d4ebdc9!ibt",
              "display_name": "ALF:Trojan:Win32/Cassini_6d4ebdc9!ibt",
              "target": null
            },
            {
              "id": "Win.Malware.Jaik-9968280-0",
              "display_name": "Win.Malware.Jaik-9968280-0",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "T1543.002",
              "name": "Systemd Service",
              "display_name": "T1543.002 - Systemd Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 275,
            "FileHash-SHA1": 243,
            "FileHash-SHA256": 1320,
            "URL": 897,
            "domain": 796,
            "email": 7,
            "hostname": 783,
            "IPv4": 446,
            "CIDR": 2,
            "SSLCertFingerprint": 33
          },
          "indicator_count": 4802,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "10 hours ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69589dd49ec0010e69444d66",
          "name": "AgentTesla affecting a video game platform currently downed",
          "description": "DeadByDayLight.com is being crushed by malware attacks. I only researched one of the Trojans found. AgentTesla. I\u2019m definitely not a gamer, found it interesting the peripheral whilst researching. Research led link as it relates to related Pulse/a.",
          "modified": "2026-02-02T03:02:34.652000",
          "created": "2026-01-03T04:40:52.240000",
          "tags": [
            "aaaa",
            "united",
            "present sep",
            "present aug",
            "present jun",
            "present jan",
            "ip address",
            "name servers",
            "iocs",
            "data upload",
            "extraction",
            "review iocs",
            "ada indicator",
            "find suggested",
            "type a",
            "passive dns",
            "urls",
            "domain",
            "address",
            "asn as16509",
            "trojandropper",
            "subid",
            "title error",
            "ipv4",
            "twitter",
            "win32",
            "servers",
            "hostname add",
            "url analysis",
            "ms windows",
            "pe32",
            "intel",
            "memcommit",
            "caption",
            "f im",
            "read c",
            "mozilla",
            "service",
            "write",
            "persistence",
            "execution",
            "malware",
            "next",
            "united states",
            "yara detections",
            "alerts",
            "analysis date",
            "suspicious ua",
            "nsisdl",
            "less see",
            "all ip",
            "contacted",
            "tech broism",
            "palantir"
          ],
          "references": [
            "https://deadbydaylight.com",
            "Win.Trojan.Generic-9884244-0 ,  ALF:Trojan:MSIL/AgentTesla.KM",
            "IDS Detections: Observed Suspicious UA (NSISDL/1.2 (Mozilla)) Nullsoft Mozilla UA (NSISDL)",
            "Yara Detections: Nullsoft_NSIS",
            "Alerts: network_icmp antivm_generic_services persistence_autorun creates_largekey",
            "Alerts: creates_service dumped_buffer network_cnc_http network_http allocates_rwx",
            "Alerts: antivm_disk_size infostealer_browser creates_exe creates_shortcut",
            "Alerts: queries_programs uses_windows_utilities antivm_queries_computername",
            "Alerts: exe_appdata has_wmi antivm_network_adapters privilege_luid_check",
            "IP\u2019s Contacted  34.233.61.169  54.192.76.30  54.230.125.59",
            "Domains Contacted proxel.bytefence.com logs.bytefence.com",
            "Domains related/not pulsed: video-lal.com/videos/tsara-brashears-dead-by-daylight.html",
            "gossamer-containers.washington.palantircloud.com \u2022",
            "sandboxes-ranunculus.palantirfedstart.com \u2022  eureka-bah-usgc-1.palantirfedstart.com \u2022",
            "http://2.palantirfedstart.com/ \u2022 http://authorium-docs-stg.palantirfedstart.com",
            "https://sandboxes-ranunculus.palantirfedstart.com/t",
            "http://lsauth-vault.palantirfedstart.com  \u2022 http://mugwort-container-registry.palantirfedstart.com/",
            "https://containers-specterops-mckinley.palantirfedstart.com/",
            "https://mugwort-container-registry.palantirfedstart.com/ \u2022 https://ohrid-usgc-1.palantirfedstart.com",
            "https://authorium-docs-stg.palantirfedstart.com \u2022 https://chelan-containers.palantirfedstart.com",
            "https://containers-manuka-usgc-1.palantirfedstart.com \u2022 rizkly.palantirfedstart.com",
            "palantirfedstart.com \u2022 rizkly.palantirfedstart.com \u2022",
            "https://kalpak.palantirfedstart.com/ \u2022 https://lsauth-vault.palantirfedstart.com/",
            "primer-delta-endpoints-staging.palantirfedstart.com",
            "http://containers-manuka-usgc-1.palantirfedstart.com \u2022http://kalpak.palantirfedstart.com",
            "http://ohrid-usgc-1.palantirfedstart.com \u2022 http://sandboxes-ranunculus.palantirfedstart.com",
            "http://sundog-ge-traces.palantirfedstart.com \u2022 https://2.palantirfedstart.com/u"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Win.Trojan.Generic-9884244-0 ,",
              "display_name": "Win.Trojan.Generic-9884244-0 ,",
              "target": null
            },
            {
              "id": "alf:Trojan:MSIL/AgentTesla.KM",
              "display_name": "alf:Trojan:MSIL/AgentTesla.KM",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1023",
              "name": "Shortcut Modification",
              "display_name": "T1023 - Shortcut Modification"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4342,
            "domain": 767,
            "hostname": 1456,
            "FileHash-SHA256": 233,
            "FileHash-MD5": 99,
            "FileHash-SHA1": 63,
            "email": 3,
            "SSLCertFingerprint": 1
          },
          "indicator_count": 6964,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 141,
          "modified_text": "118 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "remoteexecution-runner-api.services.gotoresolve.com\t\u2022 appleremotesupport.com\t\u2022",
        "http://212.33.237.86/images/1/report.php",
        "https://cdn.console.gotoresolve.com/applet",
        "alerts-monitor-api-fd-prodeu.services.gotoresolve.com",
        "Matches rule ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com)",
        "remoteexecution-runner-api.services.gotoresolve.com",
        "In this specific attack chain, the threat actors use the Quant Loader script for initial entry,",
        "IP\u2019s Contacted  34.233.61.169  54.192.76.30  54.230.125.59",
        "gossamer-containers.washington.palantircloud.com \u2022",
        "primer-delta-endpoints-staging.palantirfedstart.com",
        "Immediate Recommendations: Disconnect all routers and isolate the network.",
        "Names: 2026-04-07_259af8b0d0bc540384a06bb730cee9cd_qnapcrypt ELF Info",
        "to act as their human-controlled, \"living off the land\" command station.",
        "sandboxes-ranunculus.palantirfedstart.com \u2022  eureka-bah-usgc-1.palantirfedstart.com \u2022",
        "Alerts: queries_programs uses_windows_utilities antivm_queries_computername",
        "https://kalpak.palantirfedstart.com/ \u2022 https://lsauth-vault.palantirfedstart.com/",
        "13.107.226.70 \u2022 13.107.253.70 - Malware Hosting",
        "https://containers-manuka-usgc-1.palantirfedstart.com \u2022 rizkly.palantirfedstart.com",
        "Attack ChainThreat actors chain these three specific components together to bypass traditional ->",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ \u2022  www.anyxxxtube.net",
        "Domains related/not pulsed: video-lal.com/videos/tsara-brashears-dead-by-daylight.html",
        "Air-gap the target device (disable Wi-Fi, pull cables). Expensive : Dispose of all devices.",
        "by pulling its primary files over public SMB shares.",
        "Names: testpaging upof6w.exe",
        "screenmaxxxing.com \u2022 wiki.xxkcamffk.cc \u2022 playfoundermode.com",
        "Alerts: creates_service dumped_buffer network_cnc_http network_http allocates_rwx",
        "This lets the threat actor route malicious command traffic into the local corporate network undetected.",
        "firebaseremoteconfig.googleapis.com",
        "Alerts: exe_appdata has_wmi antivm_network_adapters privilege_luid_check",
        "its outbound traffic to logmein.com domains looks completely normal to firewalls.",
        "Once inside the network, attackers avoid deploying more loud hacking tools & Download or abuse LogMeIn[.]com software.",
        "Domains Contacted proxel.bytefence.com logs.bytefence.com",
        "Matches rule SURICATA Applayer Detect protocol only one direction",
        "The Entry Vector (Quant Loader): A user interacts with a phishing link or malicious archive file.",
        "Crowdsourced Signa: Matches rule Suspicious Outbound SMTP",
        "Matches rule ET INFO External IP Check (checkip .amazonaws .com)",
        "security filters:[Quant Script (Initial Drop)] \u2794 [SystemBC (SOCKS5/Tor Tunnel)] \u2794",
        "http://ohrid-usgc-1.palantirfedstart.com \u2022 http://sandboxes-ranunculus.palantirfedstart.com",
        "Suspicious DNS Query for IP post), Thomas Patzke Lookup Service APls by Brandon George (blog Crowdsourced)",
        "appleremotesupport.com \u2022 remotelyanywhere.com",
        "http://2.palantirfedstart.com/ \u2022 http://authorium-docs-stg.palantirfedstart.com",
        "Yara Detections: Nullsoft_NSIS",
        "RaaS attack designed to deploy ransomware against \u2018high value\u2019 targets or corporations.",
        "https://authorium-docs-stg.palantirfedstart.com \u2022 https://chelan-containers.palantirfedstart.com",
        "Amazonaws.com \u2022 Amazon.com",
        "alerts-frontend-api-fd-stage.services-stage.gotoresolve.com",
        "The Persistent Backdoor (SystemBC RAT): Quant Loader downloads and executes SystemBC.",
        "Change all credentials from a separate, clean network.",
        "remotelyanywhere.com \u2022,http://watchhers.net/index.php \u2022 firebaseremoteconfig.googleapis.com",
        "Because LogMeIn is a legitimate remote management tool used by actual IT departments,",
        "http://lsauth-vault.palantirfedstart.com  \u2022 http://mugwort-container-registry.palantirfedstart.com/",
        "[LogMeIn.com (Legitimate Remote Access)] \u2794 [Ransomware]",
        "The Objective: The hackers use the trusted LogMeIn connection to freely move laterally, steal data, turn off local security defenses, and deploy network-wide ransomware",
        "https://adservice.google.com.uy/clk \u2022 adservice.google.com.uy",
        "https://deadbydaylight.com",
        "http://sundog-ge-traces.palantirfedstart.com \u2022 https://2.palantirfedstart.com/u",
        "Domains Contacted: checkip.amazonaws.com vk.com arena.ai www.yandex.ru stripchat.com",
        "An obfuscated Quant Loader script runs natively in the background, evading anti-malware detection",
        "Win.Trojan.Generic-9884244-0 ,  ALF:Trojan:MSIL/AgentTesla.KM",
        "https://www.logmein.com/products/resolve \u2022 http://devices-iot.console.gotoresolve.com/",
        "SystemBC sets up a scheduled task to stay persistent and opens a stealthy SOCKS5 proxy or Tor network tunnel.",
        "SystemBC to map the backend network secretly, and a hijacked or fraudulent LogMeIn account ->",
        "IDS Detections: Observed Suspicious UA (NSISDL/1.2 (Mozilla)) Nullsoft Mozilla UA (NSISDL)",
        "IP\u2019s Contacted:  104.17.118.12  57.144.248.1  176.114.120.24  80.12.24.14  95.163.61.73  142.251.98.113  212.227.17.162  77.88.44.55  142.93.142.17  104.18.14.206",
        "palantirfedstart.com \u2022 rizkly.palantirfedstart.com \u2022",
        "103.246.145.111 \u2022 http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel",
        "Yara Detections: is__elf",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "http://containers-manuka-usgc-1.palantirfedstart.com \u2022http://kalpak.palantirfedstart.com",
        "testpaging SHA256 756f0b598741a6fdff640a158b6b490472e546d411da2850836b9a8ca76afdc1",
        "http://watchhers.net/index.php",
        "ET HUNTING Suspicious User-Agent Observed (Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
        "https://mugwort-container-registry.palantirfedstart.com/ \u2022 https://ohrid-usgc-1.palantirfedstart.com",
        "https://containers-specterops-mckinley.palantirfedstart.com/",
        "firebaseremoteconfig.googleapis.com \u2022 remoteexecution-runner-api.services.gotoresolve.com",
        "Crowdsourced IDS: Matches rule ET DROP Spamhaus DROP Listed Traffic Inbound group 60",
        "Alerts: antivm_disk_size infostealer_browser creates_exe creates_shortcut",
        "https://sandboxes-ranunculus.palantirfedstart.com/t",
        "If possible: Move to Switzerland",
        "Alerts: network_icmp antivm_generic_services persistence_autorun creates_largekey"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Ransom:win32/crowti.a",
            "Trojandropper:win32/cutwail.gen!k",
            "Trojanspy:win32/nivdort.cw",
            "Alf:trojan:msil/agenttesla.km",
            "Trojan.systembc/yxgdgz",
            "Win.trojan.hupigon-6989556-0",
            "Alf:trojan:win32/cassini_6d4ebdc9!ibt",
            "Win.trojan.generic-9884244-0 ,",
            "Win.trojan.gh0strat-9955419-1",
            "Doc.downloader.emotetred02220-9938909-0",
            "Trojandownloader:js/swabfex.p",
            "Win.downloader.nemucod-6769668-0",
            "Win.malware.jaik-9968280-0"
          ],
          "industries": [],
          "unique_indicators": 11778
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/stc-dev.net",
    "whois": "http://whois.domaintools.com/stc-dev.net",
    "domain": "stc-dev.net",
    "hostname": "web.zaocloud2stage.stc-dev.net"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6a1b57af6e1986d0628bca12",
      "name": "SystemBC RAT, Quant Loader, and LogMeIn.com, combined to execute a multi-stage Corporate Styled Network Intrusion",
      "description": "\"Living off the Land\" Takeover (LogMeIn.com)\u201c\nINCIDENT REPORT: HIGH-VALUE TARGET NETWORK INTRUSION Threat Profile: Human-operated corporate-grade attack chain targeting an isolated device.Vector: Local network exposure (compromised router/neighboring device) or physical media (USB).Attack Chain Stages:Quant Script: Obfuscated entry file bypassing network filters.SystemBC RAT: Creates a silent, persistent SOCKS5/Tor tunnel for attacker commands.LogMeIn Abuse: Attackers use legitimate remote software to control the device undetected.Crowti (CryptoWall): Final ransomware payload to encrypt high-value data.Key Observations: Because the target device lacked direct internet access, adversaries are actively abusing the local network infrastructure or physical proximity to bridge the gap. \n\nI\u2019m open to other opinions regarding this report. I have been unwell and my thinking has been  unclear and even off as I focus on getting well.\nThank you.",
      "modified": "2026-05-30T21:33:35.237000",
      "created": "2026-05-30T21:33:35.237000",
      "tags": [
        "united",
        "unknown aaaa",
        "servers",
        "certificate",
        "urls",
        "logmein",
        "ipv4",
        "url analysis",
        "files",
        "america flag",
        "level",
        "data upload",
        "extraction",
        "failed",
        "enter sc",
        "extri data",
        "include review",
        "stop typ",
        "domain don",
        "united states",
        "america asn",
        "net20525119201",
        "amazon data",
        "net20525119202",
        "address range",
        "cidr",
        "network name",
        "allocation type",
        "whois server",
        "entity adsn1",
        "handle",
        "sc data",
        "netherlands asn",
        "as204601 zomro",
        "dns resolutions",
        "log id",
        "gmtn",
        "timestamp",
        "tls web",
        "expiresfri",
        "path",
        "httponly",
        "salford",
        "sectigo limited",
        "sectigo rsa",
        "accept",
        "organization",
        "false",
        "authentication",
        "ocsp",
        "c179044d",
        "b89a",
        "d4n timestamp",
        "df9b",
        "post na",
        "lredmond",
        "stwa",
        "cnmicrosoft tls",
        "g2 rsa",
        "ca ocsp",
        "rmm domain",
        "search",
        "flashpix",
        "write",
        "unknown",
        "malware",
        "encrypt",
        "high",
        "medium",
        "write c",
        "template",
        "registers",
        "moved",
        "record value",
        "tls sni",
        "observed rmm",
        "omicrosoft",
        "stwashington",
        "server ca",
        "extr data",
        "error",
        "a50 data",
        "pattern match",
        "ascii text",
        "mitre att",
        "ck id",
        "general",
        "local",
        "click",
        "strings",
        "u extractio",
        "extrac data",
        "learn",
        "command",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "spawns",
        "signing defense",
        "discovery att",
        "code signing",
        "defense evasion",
        "t1480.002",
        "mrasn",
        "cachecontrol",
        "connection",
        "date tue",
        "gmt etag",
        "self",
        "etag w/\"leknjhepnj99sn\"",
        "name servers",
        "extre data",
        "observed dns",
        "query",
        "show",
        "localsm05208304",
        "localsm03520304",
        "title error",
        "all ipv4",
        "reverse dns",
        "as14618",
        "extraction data",
        "creato touc",
        "digice rsa",
        "sh certific",
        "hid iv",
        "trojandropper",
        "backdoor",
        "present may",
        "please",
        "x msedge",
        "exploit",
        "as8068",
        "av detection",
        "ratio",
        "ids detections",
        "content length",
        "content type",
        "x powered",
        "asn as16509",
        "x vercel",
        "vercel",
        "gmt content",
        "ransom",
        "dynamicloader",
        "msie",
        "windows nt",
        "wow64",
        "slcc2",
        "media center",
        "sysv",
        "buildid",
        "germany as8560",
        "yara detections",
        "contacted",
        "elf",
        "filehash",
        "av detections",
        "alerts",
        "analysis date",
        "file score",
        "low risk",
        "elf executable",
        "exec amd6464",
        "linux",
        "elf64 operation",
        "unix",
        "compiler",
        "elf info",
        "progbits",
        "offset size",
        "flags",
        "null",
        "hashes o",
        "get http",
        "post http",
        "entries",
        "trojan",
        "pegasus",
        "apple",
        "amazonaws",
        "smtp",
        "self-delete",
        "service-scan",
        "applayer",
        "madagascar",
        "qnapcrypt",
        "mal_elf_systembc_rat",
        "rat",
        "hacktool code",
        "systembc",
        "t1064",
        "create",
        "modify system",
        "process",
        "t1543 privile",
        "ta0004 cr",
        "t1543",
        "creation date",
        "whois show",
        "emails",
        "name logmein",
        "org logmein",
        "summer st",
        "date hash",
        "avast avg",
        "mtb jul",
        "k jun",
        "ai",
        "ai report",
        "appleremotesupport",
        "remotelyanywhere",
        "pegasus related"
      ],
      "references": [
        "https://www.logmein.com/products/resolve \u2022 http://devices-iot.console.gotoresolve.com/",
        "https://adservice.google.com.uy/clk \u2022 adservice.google.com.uy",
        "Amazonaws.com \u2022 Amazon.com",
        "screenmaxxxing.com \u2022 wiki.xxkcamffk.cc \u2022 playfoundermode.com",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ \u2022  www.anyxxxtube.net",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "103.246.145.111 \u2022 http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel",
        "13.107.226.70 \u2022 13.107.253.70 - Malware Hosting",
        "http://212.33.237.86/images/1/report.php",
        "http://watchhers.net/index.php",
        "remoteexecution-runner-api.services.gotoresolve.com",
        "firebaseremoteconfig.googleapis.com",
        "alerts-frontend-api-fd-stage.services-stage.gotoresolve.com",
        "alerts-monitor-api-fd-prodeu.services.gotoresolve.com",
        "testpaging SHA256 756f0b598741a6fdff640a158b6b490472e546d411da2850836b9a8ca76afdc1",
        "Yara Detections: is__elf",
        "IP\u2019s Contacted:  104.17.118.12  57.144.248.1  176.114.120.24  80.12.24.14  95.163.61.73  142.251.98.113  212.227.17.162  77.88.44.55  142.93.142.17  104.18.14.206",
        "Domains Contacted: checkip.amazonaws.com vk.com arena.ai www.yandex.ru stripchat.com",
        "Names: testpaging upof6w.exe",
        "Names: 2026-04-07_259af8b0d0bc540384a06bb730cee9cd_qnapcrypt ELF Info",
        "https://cdn.console.gotoresolve.com/applet",
        "Crowdsourced Signa: Matches rule Suspicious Outbound SMTP",
        "Suspicious DNS Query for IP post), Thomas Patzke Lookup Service APls by Brandon George (blog Crowdsourced)",
        "Crowdsourced IDS: Matches rule ET DROP Spamhaus DROP Listed Traffic Inbound group 60",
        "Matches rule ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com)",
        "Matches rule ET INFO External IP Check (checkip .amazonaws .com)",
        "ET HUNTING Suspicious User-Agent Observed (Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
        "Matches rule SURICATA Applayer Detect protocol only one direction",
        "SystemBC to map the backend network secretly, and a hijacked or fraudulent LogMeIn account ->",
        "to act as their human-controlled, \"living off the land\" command station.",
        "Attack ChainThreat actors chain these three specific components together to bypass traditional ->",
        "security filters:[Quant Script (Initial Drop)] \u2794 [SystemBC (SOCKS5/Tor Tunnel)] \u2794",
        "[LogMeIn.com (Legitimate Remote Access)] \u2794 [Ransomware]",
        "RaaS attack designed to deploy ransomware against \u2018high value\u2019 targets or corporations.",
        "In this specific attack chain, the threat actors use the Quant Loader script for initial entry,",
        "The Entry Vector (Quant Loader): A user interacts with a phishing link or malicious archive file.",
        "An obfuscated Quant Loader script runs natively in the background, evading anti-malware detection",
        "by pulling its primary files over public SMB shares.",
        "The Persistent Backdoor (SystemBC RAT): Quant Loader downloads and executes SystemBC.",
        "SystemBC sets up a scheduled task to stay persistent and opens a stealthy SOCKS5 proxy or Tor network tunnel.",
        "This lets the threat actor route malicious command traffic into the local corporate network undetected.",
        "Once inside the network, attackers avoid deploying more loud hacking tools & Download or abuse LogMeIn[.]com software.",
        "Because LogMeIn is a legitimate remote management tool used by actual IT departments,",
        "its outbound traffic to logmein.com domains looks completely normal to firewalls.",
        "The Objective: The hackers use the trusted LogMeIn connection to freely move laterally, steal data, turn off local security defenses, and deploy network-wide ransomware",
        "remoteexecution-runner-api.services.gotoresolve.com\t\u2022 appleremotesupport.com\t\u2022",
        "firebaseremoteconfig.googleapis.com \u2022 remoteexecution-runner-api.services.gotoresolve.com",
        "remotelyanywhere.com \u2022,http://watchhers.net/index.php \u2022 firebaseremoteconfig.googleapis.com",
        "appleremotesupport.com \u2022 remotelyanywhere.com",
        "Immediate Recommendations: Disconnect all routers and isolate the network.",
        "Air-gap the target device (disable Wi-Fi, pull cables). Expensive : Dispose of all devices.",
        "Change all credentials from a separate, clean network.",
        "If possible: Move to Switzerland"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Ransom:Win32/Crowti.A",
          "display_name": "Ransom:Win32/Crowti.A",
          "target": "/malware/Ransom:Win32/Crowti.A"
        },
        {
          "id": "Trojan.Systembc/yxgdgz",
          "display_name": "Trojan.Systembc/yxgdgz",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Nivdort.CW",
          "display_name": "TrojanSpy:Win32/Nivdort.CW",
          "target": "/malware/TrojanSpy:Win32/Nivdort.CW"
        },
        {
          "id": "Win.Downloader.Nemucod-6769668-0",
          "display_name": "Win.Downloader.Nemucod-6769668-0",
          "target": null
        },
        {
          "id": "TrojanDownloader:JS/Swabfex.P",
          "display_name": "TrojanDownloader:JS/Swabfex.P",
          "target": "/malware/TrojanDownloader:JS/Swabfex.P"
        },
        {
          "id": "Win.Downloader.Nemucod-6769668-0",
          "display_name": "Win.Downloader.Nemucod-6769668-0",
          "target": null
        },
        {
          "id": "Doc.Downloader.EmotetRed02220-9938909-0",
          "display_name": "Doc.Downloader.EmotetRed02220-9938909-0",
          "target": null
        },
        {
          "id": "TrojanDropper:Win32/Cutwail.gen!K",
          "display_name": "TrojanDropper:Win32/Cutwail.gen!K",
          "target": "/malware/TrojanDropper:Win32/Cutwail.gen!K"
        },
        {
          "id": "Win.Trojan.Gh0stRAT-9955419-1",
          "display_name": "Win.Trojan.Gh0stRAT-9955419-1",
          "target": null
        },
        {
          "id": "Win.Trojan.Hupigon-6989556-0",
          "display_name": "Win.Trojan.Hupigon-6989556-0",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/Cassini_6d4ebdc9!ibt",
          "display_name": "ALF:Trojan:Win32/Cassini_6d4ebdc9!ibt",
          "target": null
        },
        {
          "id": "Win.Malware.Jaik-9968280-0",
          "display_name": "Win.Malware.Jaik-9968280-0",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1069.002",
          "name": "Domain Groups",
          "display_name": "T1069.002 - Domain Groups"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "T1543.002",
          "name": "Systemd Service",
          "display_name": "T1543.002 - Systemd Service"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 275,
        "FileHash-SHA1": 243,
        "FileHash-SHA256": 1320,
        "URL": 897,
        "domain": 796,
        "email": 7,
        "hostname": 783,
        "IPv4": 446,
        "CIDR": 2,
        "SSLCertFingerprint": 33
      },
      "indicator_count": 4802,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "10 hours ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69589dd49ec0010e69444d66",
      "name": "AgentTesla affecting a video game platform currently downed",
      "description": "DeadByDayLight.com is being crushed by malware attacks. I only researched one of the Trojans found. AgentTesla. I\u2019m definitely not a gamer, found it interesting the peripheral whilst researching. Research led link as it relates to related Pulse/a.",
      "modified": "2026-02-02T03:02:34.652000",
      "created": "2026-01-03T04:40:52.240000",
      "tags": [
        "aaaa",
        "united",
        "present sep",
        "present aug",
        "present jun",
        "present jan",
        "ip address",
        "name servers",
        "iocs",
        "data upload",
        "extraction",
        "review iocs",
        "ada indicator",
        "find suggested",
        "type a",
        "passive dns",
        "urls",
        "domain",
        "address",
        "asn as16509",
        "trojandropper",
        "subid",
        "title error",
        "ipv4",
        "twitter",
        "win32",
        "servers",
        "hostname add",
        "url analysis",
        "ms windows",
        "pe32",
        "intel",
        "memcommit",
        "caption",
        "f im",
        "read c",
        "mozilla",
        "service",
        "write",
        "persistence",
        "execution",
        "malware",
        "next",
        "united states",
        "yara detections",
        "alerts",
        "analysis date",
        "suspicious ua",
        "nsisdl",
        "less see",
        "all ip",
        "contacted",
        "tech broism",
        "palantir"
      ],
      "references": [
        "https://deadbydaylight.com",
        "Win.Trojan.Generic-9884244-0 ,  ALF:Trojan:MSIL/AgentTesla.KM",
        "IDS Detections: Observed Suspicious UA (NSISDL/1.2 (Mozilla)) Nullsoft Mozilla UA (NSISDL)",
        "Yara Detections: Nullsoft_NSIS",
        "Alerts: network_icmp antivm_generic_services persistence_autorun creates_largekey",
        "Alerts: creates_service dumped_buffer network_cnc_http network_http allocates_rwx",
        "Alerts: antivm_disk_size infostealer_browser creates_exe creates_shortcut",
        "Alerts: queries_programs uses_windows_utilities antivm_queries_computername",
        "Alerts: exe_appdata has_wmi antivm_network_adapters privilege_luid_check",
        "IP\u2019s Contacted  34.233.61.169  54.192.76.30  54.230.125.59",
        "Domains Contacted proxel.bytefence.com logs.bytefence.com",
        "Domains related/not pulsed: video-lal.com/videos/tsara-brashears-dead-by-daylight.html",
        "gossamer-containers.washington.palantircloud.com \u2022",
        "sandboxes-ranunculus.palantirfedstart.com \u2022  eureka-bah-usgc-1.palantirfedstart.com \u2022",
        "http://2.palantirfedstart.com/ \u2022 http://authorium-docs-stg.palantirfedstart.com",
        "https://sandboxes-ranunculus.palantirfedstart.com/t",
        "http://lsauth-vault.palantirfedstart.com  \u2022 http://mugwort-container-registry.palantirfedstart.com/",
        "https://containers-specterops-mckinley.palantirfedstart.com/",
        "https://mugwort-container-registry.palantirfedstart.com/ \u2022 https://ohrid-usgc-1.palantirfedstart.com",
        "https://authorium-docs-stg.palantirfedstart.com \u2022 https://chelan-containers.palantirfedstart.com",
        "https://containers-manuka-usgc-1.palantirfedstart.com \u2022 rizkly.palantirfedstart.com",
        "palantirfedstart.com \u2022 rizkly.palantirfedstart.com \u2022",
        "https://kalpak.palantirfedstart.com/ \u2022 https://lsauth-vault.palantirfedstart.com/",
        "primer-delta-endpoints-staging.palantirfedstart.com",
        "http://containers-manuka-usgc-1.palantirfedstart.com \u2022http://kalpak.palantirfedstart.com",
        "http://ohrid-usgc-1.palantirfedstart.com \u2022 http://sandboxes-ranunculus.palantirfedstart.com",
        "http://sundog-ge-traces.palantirfedstart.com \u2022 https://2.palantirfedstart.com/u"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Win.Trojan.Generic-9884244-0 ,",
          "display_name": "Win.Trojan.Generic-9884244-0 ,",
          "target": null
        },
        {
          "id": "alf:Trojan:MSIL/AgentTesla.KM",
          "display_name": "alf:Trojan:MSIL/AgentTesla.KM",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1023",
          "name": "Shortcut Modification",
          "display_name": "T1023 - Shortcut Modification"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4342,
        "domain": 767,
        "hostname": 1456,
        "FileHash-SHA256": 233,
        "FileHash-MD5": 99,
        "FileHash-SHA1": 63,
        "email": 3,
        "SSLCertFingerprint": 1
      },
      "indicator_count": 6964,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 141,
      "modified_text": "118 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://web.zaocloud2stage.stc-dev.net",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://web.zaocloud2stage.stc-dev.net",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780213078.680269
}