{
  "type": "Domain",
  "indicator": "kernelfire.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/kernelfire.com",
    "alexa": "http://www.alexa.com/siteinfo/kernelfire.com",
    "indicator": "kernelfire.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3765073653,
      "indicator": "kernelfire.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "655f6d7ac217661e4bc37f4d",
          "name": "Qbot | Miscellaneous Attacks",
          "description": "The following is a full list of links between malware and cyber-attackers, following a series of alerts from Phishtank, the UK-based cyber security firm, and the US government.",
          "modified": "2023-12-23T07:03:55.171000",
          "created": "2023-11-23T15:19:22.356000",
          "tags": [
            "pattern match",
            "ascii text",
            "file",
            "jpeg image",
            "exif standard",
            "tiff image",
            "png image",
            "united",
            "baseline",
            "rgba",
            "date",
            "class",
            "unknown",
            "hybrid",
            "accept",
            "local",
            "click",
            "strings",
            "generator",
            "critical",
            "error",
            "firehol",
            "detection list",
            "ip address",
            "blacklist",
            "botnet command",
            "control server",
            "noname057",
            "facebook",
            "phishtank",
            "blacklist http",
            "organization",
            "ssl certificate",
            "whois record",
            "contacted",
            "historical ssl",
            "n64xtx0vpihxzc",
            "whois whois",
            "qpyrn6pd http",
            "referrer",
            "execution",
            "communicating",
            "core",
            "discord",
            "hiddentear",
            "metro",
            "probe",
            "ransomexx",
            "quasar",
            "asyncrat",
            "bleachgap",
            "formbook",
            "nanocore",
            "roblox",
            "heur",
            "cyber threat",
            "engineering",
            "malware",
            "phishing",
            "malicious site",
            "phishing site",
            "covid19",
            "team",
            "bank",
            "cobalt strike",
            "artemis",
            "download",
            "zbot",
            "suppobox",
            "service",
            "downloader",
            "virut",
            "malicious",
            "emotet",
            "stealer",
            "exploit",
            "generic",
            "dropper",
            "unruy",
            "agent",
            "unsafe",
            "ramnit",
            "redline stealer",
            "smsspy",
            "bradesco",
            "fakealert",
            "qakbot",
            "outbreak",
            "qbot",
            "bankerx",
            "riskware",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "crack",
            "win64",
            "squirrelwaffle",
            "pony",
            "binder",
            "virustotal",
            "azorult",
            "zeus",
            "nymaim",
            "matsnu",
            "simda",
            "runescape",
            "cutwail",
            "dnspionage",
            "redirector",
            "fusioncore",
            "iframe",
            "killav",
            "raccoon",
            "daum",
            "installcore",
            "ransomware",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "presenoker",
            "downldr",
            "alexa",
            "applicunwnt",
            "opencandy",
            "cleaner",
            "wacatac",
            "xrat",
            "xtrat",
            "dbatloader",
            "infy",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "keygen",
            "fareit",
            "secrisk",
            "phish",
            "deepscan",
            "trojanspy",
            "maltiverse",
            "qpyrn6pd",
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
            "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
            "*otc.greatcall.com    [Botnetwork]",
            "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
            "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
            "tulach.cc.     [Malevolent | Modified description]",
            "https://tulach.cc/ [phishing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
            "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
            "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
          ],
          "public": 1,
          "adversary": "Qbot",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Roblox",
              "display_name": "Roblox",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 82,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 897,
            "FileHash-SHA1": 479,
            "URL": 9847,
            "domain": 2344,
            "hostname": 2398,
            "CVE": 22,
            "FileHash-SHA256": 4712
          },
          "indicator_count": 20699,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "890 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "655f6d89b33758a190399f39",
          "name": "Qbot | Miscellaneous Attacks",
          "description": "The following is a full list of links between malware and cyber-attackers, following a series of alerts from Phishtank, the UK-based cyber security firm, and the US government.",
          "modified": "2023-12-23T07:03:55.171000",
          "created": "2023-11-23T15:19:37.838000",
          "tags": [
            "pattern match",
            "ascii text",
            "file",
            "jpeg image",
            "exif standard",
            "tiff image",
            "png image",
            "united",
            "baseline",
            "rgba",
            "date",
            "class",
            "unknown",
            "hybrid",
            "accept",
            "local",
            "click",
            "strings",
            "generator",
            "critical",
            "error",
            "firehol",
            "detection list",
            "ip address",
            "blacklist",
            "botnet command",
            "control server",
            "noname057",
            "facebook",
            "phishtank",
            "blacklist http",
            "organization",
            "ssl certificate",
            "whois record",
            "contacted",
            "historical ssl",
            "n64xtx0vpihxzc",
            "whois whois",
            "qpyrn6pd http",
            "referrer",
            "execution",
            "communicating",
            "core",
            "discord",
            "hiddentear",
            "metro",
            "probe",
            "ransomexx",
            "quasar",
            "asyncrat",
            "bleachgap",
            "formbook",
            "nanocore",
            "roblox",
            "heur",
            "cyber threat",
            "engineering",
            "malware",
            "phishing",
            "malicious site",
            "phishing site",
            "covid19",
            "team",
            "bank",
            "cobalt strike",
            "artemis",
            "download",
            "zbot",
            "suppobox",
            "service",
            "downloader",
            "virut",
            "malicious",
            "emotet",
            "stealer",
            "exploit",
            "generic",
            "dropper",
            "unruy",
            "agent",
            "unsafe",
            "ramnit",
            "redline stealer",
            "smsspy",
            "bradesco",
            "fakealert",
            "qakbot",
            "outbreak",
            "qbot",
            "bankerx",
            "riskware",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "crack",
            "win64",
            "squirrelwaffle",
            "pony",
            "binder",
            "virustotal",
            "azorult",
            "zeus",
            "nymaim",
            "matsnu",
            "simda",
            "runescape",
            "cutwail",
            "dnspionage",
            "redirector",
            "fusioncore",
            "iframe",
            "killav",
            "raccoon",
            "daum",
            "installcore",
            "ransomware",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "presenoker",
            "downldr",
            "alexa",
            "applicunwnt",
            "opencandy",
            "cleaner",
            "wacatac",
            "xrat",
            "xtrat",
            "dbatloader",
            "infy",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "keygen",
            "fareit",
            "secrisk",
            "phish",
            "deepscan",
            "trojanspy",
            "maltiverse",
            "qpyrn6pd",
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
            "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
            "*otc.greatcall.com    [Botnetwork]",
            "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
            "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
            "tulach.cc.     [Malevolent | Modified description]",
            "https://tulach.cc/ [phishing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
            "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
            "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
          ],
          "public": 1,
          "adversary": "Qbot",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Roblox",
              "display_name": "Roblox",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 84,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 897,
            "FileHash-SHA1": 479,
            "URL": 9847,
            "domain": 2344,
            "hostname": 2398,
            "CVE": 22,
            "FileHash-SHA256": 4712
          },
          "indicator_count": 20699,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "890 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "655f6edffd3910161c2ad1a2",
          "name": "D26A | DNSpionage| Qbot | Tulach Malaware | https://theanimallawfirm.com/ | FakeAlert",
          "description": "",
          "modified": "2023-12-23T07:03:55.171000",
          "created": "2023-11-23T15:25:19.843000",
          "tags": [
            "pattern match",
            "ascii text",
            "file",
            "jpeg image",
            "exif standard",
            "tiff image",
            "png image",
            "united",
            "baseline",
            "rgba",
            "date",
            "class",
            "unknown",
            "hybrid",
            "accept",
            "local",
            "click",
            "strings",
            "generator",
            "critical",
            "error",
            "firehol",
            "detection list",
            "ip address",
            "blacklist",
            "botnet command",
            "control server",
            "noname057",
            "facebook",
            "phishtank",
            "blacklist http",
            "organization",
            "ssl certificate",
            "whois record",
            "contacted",
            "historical ssl",
            "n64xtx0vpihxzc",
            "whois whois",
            "qpyrn6pd http",
            "referrer",
            "execution",
            "communicating",
            "core",
            "discord",
            "hiddentear",
            "metro",
            "probe",
            "ransomexx",
            "quasar",
            "asyncrat",
            "bleachgap",
            "formbook",
            "nanocore",
            "roblox",
            "heur",
            "cyber threat",
            "engineering",
            "malware",
            "phishing",
            "malicious site",
            "phishing site",
            "covid19",
            "team",
            "bank",
            "cobalt strike",
            "artemis",
            "download",
            "zbot",
            "suppobox",
            "service",
            "downloader",
            "virut",
            "malicious",
            "emotet",
            "stealer",
            "exploit",
            "generic",
            "dropper",
            "unruy",
            "agent",
            "unsafe",
            "ramnit",
            "redline stealer",
            "smsspy",
            "bradesco",
            "fakealert",
            "qakbot",
            "outbreak",
            "qbot",
            "bankerx",
            "riskware",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "crack",
            "win64",
            "squirrelwaffle",
            "pony",
            "binder",
            "virustotal",
            "azorult",
            "zeus",
            "nymaim",
            "matsnu",
            "simda",
            "runescape",
            "cutwail",
            "dnspionage",
            "redirector",
            "fusioncore",
            "iframe",
            "killav",
            "raccoon",
            "daum",
            "installcore",
            "ransomware",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "presenoker",
            "downldr",
            "alexa",
            "applicunwnt",
            "opencandy",
            "cleaner",
            "wacatac",
            "xrat",
            "xtrat",
            "dbatloader",
            "infy",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "keygen",
            "fareit",
            "secrisk",
            "phish",
            "deepscan",
            "trojanspy",
            "maltiverse",
            "qpyrn6pd",
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
            "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
            "*otc.greatcall.com    [Botnetwork]",
            "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
            "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
            "tulach.cc.     [Malevolent | Modified description]",
            "https://tulach.cc/ [phishing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
            "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
            "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
          ],
          "public": 1,
          "adversary": "Qbot",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Roblox",
              "display_name": "Roblox",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "655f6d89b33758a190399f39",
          "export_count": 86,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 897,
            "FileHash-SHA1": 479,
            "URL": 9847,
            "domain": 2344,
            "hostname": 2398,
            "CVE": 22,
            "FileHash-SHA256": 4712
          },
          "indicator_count": 20699,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "890 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "655e7e82c65d8e9106e6a227",
          "name": "https://theanimallawfirm.com/",
          "description": "",
          "modified": "2023-12-22T21:04:18.086000",
          "created": "2023-11-22T22:19:46.485000",
          "tags": [
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "n64xtx0vpihxzc",
            "qpyrn6pd",
            "detection list",
            "blacklist http",
            "cisco umbrella",
            "site",
            "site top",
            "alexa top",
            "safe site",
            "heur",
            "html",
            "site safe",
            "million",
            "malware",
            "artemis",
            "win64",
            "downldr",
            "presenoker",
            "fakealert",
            "riskware",
            "qakbot",
            "applicunwnt",
            "opencandy",
            "fusioncore",
            "cleaner",
            "wacatac",
            "exploit",
            "iframe",
            "dbatloader",
            "raccoon",
            "service",
            "agent",
            "alexa",
            "xtrat",
            "team",
            "phish",
            "deepscan",
            "crack",
            "suspicious",
            "phishing",
            "xrat",
            "cve201711882",
            "d26a",
            "maltiverse",
            "trojanspy",
            "united",
            "cyber threat",
            "engineering",
            "malicious site",
            "bank",
            "phishing site",
            "covid19",
            "facebook",
            "download",
            "emotet",
            "stealer",
            "suppobox",
            "downloader",
            "unsafe",
            "malicious",
            "smsspy",
            "cobalt strike",
            "generic",
            "dropper",
            "formbook",
            "unruy",
            "virut",
            "azorult",
            "zbot",
            "matsnu",
            "cutwail",
            "bradesco",
            "outbreak",
            "qbot",
            "bankerx",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "squirrelwaffle",
            "pony",
            "binder",
            "ramnit",
            "virustotal",
            "zeus",
            "nymaim",
            "simda",
            "runescape",
            "dnspionage",
            "redirector",
            "killav",
            "dcrat",
            "alien",
            "astaroth",
            "filerepmalware",
            "control server",
            "asyncrat",
            "redline stealer",
            "daum",
            "name verdict"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "D26A",
              "display_name": "D26A",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 62,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 592,
            "FileHash-SHA1": 320,
            "FileHash-SHA256": 1159,
            "URL": 1257,
            "domain": 1219,
            "hostname": 403,
            "CVE": 15
          },
          "indicator_count": 4965,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "891 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "655e7ed63ab06f2006c90b1c",
          "name": "DNSpionage, ",
          "description": "",
          "modified": "2023-12-22T21:04:18.086000",
          "created": "2023-11-22T22:21:10.853000",
          "tags": [
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "n64xtx0vpihxzc",
            "qpyrn6pd",
            "detection list",
            "blacklist http",
            "cisco umbrella",
            "site",
            "site top",
            "alexa top",
            "safe site",
            "heur",
            "html",
            "site safe",
            "million",
            "malware",
            "artemis",
            "win64",
            "downldr",
            "presenoker",
            "fakealert",
            "riskware",
            "qakbot",
            "applicunwnt",
            "opencandy",
            "fusioncore",
            "cleaner",
            "wacatac",
            "exploit",
            "iframe",
            "dbatloader",
            "raccoon",
            "service",
            "agent",
            "alexa",
            "xtrat",
            "team",
            "phish",
            "deepscan",
            "crack",
            "suspicious",
            "phishing",
            "xrat",
            "cve201711882",
            "d26a",
            "maltiverse",
            "trojanspy",
            "united",
            "cyber threat",
            "engineering",
            "malicious site",
            "bank",
            "phishing site",
            "covid19",
            "facebook",
            "download",
            "emotet",
            "stealer",
            "suppobox",
            "downloader",
            "unsafe",
            "malicious",
            "smsspy",
            "cobalt strike",
            "generic",
            "dropper",
            "formbook",
            "unruy",
            "virut",
            "azorult",
            "zbot",
            "matsnu",
            "cutwail",
            "bradesco",
            "outbreak",
            "qbot",
            "bankerx",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "squirrelwaffle",
            "pony",
            "binder",
            "ramnit",
            "virustotal",
            "zeus",
            "nymaim",
            "simda",
            "runescape",
            "dnspionage",
            "redirector",
            "killav",
            "dcrat",
            "alien",
            "astaroth",
            "filerepmalware",
            "control server",
            "asyncrat",
            "redline stealer",
            "daum",
            "name verdict"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "D26A",
              "display_name": "D26A",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "655e7e82c65d8e9106e6a227",
          "export_count": 64,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 592,
            "FileHash-SHA1": 320,
            "FileHash-SHA256": 1159,
            "URL": 1257,
            "domain": 1219,
            "hostname": 403,
            "CVE": 15
          },
          "indicator_count": 4965,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "891 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "656a9f3ad7db0aa9475e86d0",
          "name": "https://theanimallawfirm.com/",
          "description": "",
          "modified": "2023-12-22T21:04:18.086000",
          "created": "2023-12-02T03:06:34.870000",
          "tags": [
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "n64xtx0vpihxzc",
            "qpyrn6pd",
            "detection list",
            "blacklist http",
            "cisco umbrella",
            "site",
            "site top",
            "alexa top",
            "safe site",
            "heur",
            "html",
            "site safe",
            "million",
            "malware",
            "artemis",
            "win64",
            "downldr",
            "presenoker",
            "fakealert",
            "riskware",
            "qakbot",
            "applicunwnt",
            "opencandy",
            "fusioncore",
            "cleaner",
            "wacatac",
            "exploit",
            "iframe",
            "dbatloader",
            "raccoon",
            "service",
            "agent",
            "alexa",
            "xtrat",
            "team",
            "phish",
            "deepscan",
            "crack",
            "suspicious",
            "phishing",
            "xrat",
            "cve201711882",
            "d26a",
            "maltiverse",
            "trojanspy",
            "united",
            "cyber threat",
            "engineering",
            "malicious site",
            "bank",
            "phishing site",
            "covid19",
            "facebook",
            "download",
            "emotet",
            "stealer",
            "suppobox",
            "downloader",
            "unsafe",
            "malicious",
            "smsspy",
            "cobalt strike",
            "generic",
            "dropper",
            "formbook",
            "unruy",
            "virut",
            "azorult",
            "zbot",
            "matsnu",
            "cutwail",
            "bradesco",
            "outbreak",
            "qbot",
            "bankerx",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "squirrelwaffle",
            "pony",
            "binder",
            "ramnit",
            "virustotal",
            "zeus",
            "nymaim",
            "simda",
            "runescape",
            "dnspionage",
            "redirector",
            "killav",
            "dcrat",
            "alien",
            "astaroth",
            "filerepmalware",
            "control server",
            "asyncrat",
            "redline stealer",
            "daum",
            "name verdict"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "D26A",
              "display_name": "D26A",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "655e7e82c65d8e9106e6a227",
          "export_count": 45,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 592,
            "FileHash-SHA1": 320,
            "FileHash-SHA256": 1159,
            "URL": 1257,
            "domain": 1219,
            "hostname": 403,
            "CVE": 15
          },
          "indicator_count": 4965,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "891 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a7dda4ef145116f1593a",
          "name": "Packed.VMProt/ Packed.VMProtect Apple|  iOS | Mac attack techapply.com",
          "description": "",
          "modified": "2023-12-06T16:57:01.831000",
          "created": "2023-12-06T16:57:01.831000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 5,
            "hostname": 551,
            "FileHash-SHA256": 650,
            "FileHash-MD5": 425,
            "FileHash-SHA1": 224,
            "URL": 1019,
            "domain": 485,
            "email": 2,
            "FilePath": 2
          },
          "indicator_count": 3363,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a7d867bfb30b452b94d0",
          "name": "Packed.VMProt/ Packed.VMProtect Apple|  iOS | Mac attack techapply.com",
          "description": "",
          "modified": "2023-12-06T16:56:56.522000",
          "created": "2023-12-06T16:56:56.522000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 5,
            "hostname": 551,
            "FileHash-SHA256": 650,
            "FileHash-MD5": 425,
            "FileHash-SHA1": 224,
            "URL": 1019,
            "domain": 485,
            "email": 2,
            "FilePath": 2
          },
          "indicator_count": 3363,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "651f175a87ed5eba41657bf3",
          "name": "Packed.VMProt/ Packed.VMProtect Apple|  iOS | Mac attack techapply.com",
          "description": "Significantly infected Apple ID. and various devices; spyrixkeylogger, spyware, networm, tracking, beacons, injection, full control iOS and apple devices as well as OS. Appears as investigated. Not a lawful investigated. 5+ year (analysis reveals dated CVE's and malware specially targets individual) of spying, tagging, targeting, cyber criminal, cyber harassment, unlocker, disabled apple IDs. Interface / dummy core, collection, webdisk harvesting, cyber criminal behavior. Possible red teaming. js user, code written for a variety programs/systems, C2, relay router. robots. \ncyber threat.\nhired\ntargeted \nbotnets\nmalware\nAI",
          "modified": "2023-11-04T16:00:22.229000",
          "created": "2023-10-05T20:06:50.075000",
          "tags": [
            "engineering",
            "united",
            "cyber threat",
            "team",
            "malware",
            "telefonica co",
            "heur",
            "malicious site",
            "ip reputation",
            "bambernek pony",
            "zeus",
            "nymaim",
            "facebook",
            "raccoon",
            "download",
            "kronos",
            "ramnit",
            "simda",
            "bank",
            "phishing",
            "citadel",
            "zbot",
            "pykspa",
            "agent",
            "maltiverse",
            "noname057",
            "copyright",
            "reserved",
            "flag",
            "date",
            "name server",
            "markmonitor",
            "server",
            "organization",
            "germany germany",
            "sample",
            "session details",
            "click",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "exit node",
            "traffic group",
            "suricata alerts",
            "event category",
            "analysis",
            "malicious url",
            "windows nt",
            "wow64",
            "response",
            "gmt contenttype",
            "gecko host",
            "vary",
            "gmt etag",
            "general gets",
            "script",
            "parking crew",
            "apple",
            "apple id",
            "tsara",
            "tsara brashears",
            "spyware",
            "cyber criminal",
            "cyber stalking",
            "track",
            "track iphone",
            "accept all platforms",
            "infringement",
            "intellectual property",
            "suricata",
            "alert",
            "red team",
            "happywifehappylife",
            "malicious",
            "revenge",
            "posts",
            "post",
            "post to web",
            "post to server",
            "exploit",
            "command_and_control",
            "toggle",
            "logon",
            "login",
            "privilege",
            "ios",
            "attack",
            "mitre",
            "Packed.VMProt",
            "apple engineering",
            "abuse",
            "cve",
            "robots",
            "arizona",
            "bounce",
            "canada",
            "croatia",
            "base64_encoded",
            "%samplepath%",
            "tagging",
            "png image",
            "PSI-USA, Inc. dba Domain Robot Organization",
            "dns",
            "query",
            "evasive",
            "crack",
            "record type",
            "ttl value",
            "dns replication",
            "santa fe",
            "available from",
            "registrar abuse",
            "iana id",
            "domain status",
            "creation date",
            "registrar url",
            "code",
            "dapato",
            "predator",
            "win64",
            "conduit",
            "fakeinstaller",
            "installpack",
            "generic",
            "downloader",
            "spyrixkeylogger",
            "bitminer",
            "loadmoney",
            "filetour",
            "wacatac",
            "fusioncore",
            "cleaner",
            "networm",
            "mediaget",
            "softonic",
            "trojan",
            "encpk",
            "qbot",
            "swrort",
            "kraddare",
            "systweak",
            "iobit",
            "installcore",
            "artemis",
            "riskware",
            "dllinject",
            "driverpack",
            "trojanspy",
            "webtoolbar",
            "cisco umbrella",
            "ip hostname",
            "safe site",
            "site",
            "targeted",
            "AI",
            "dllinject"
          ],
          "references": [
            "Spyware",
            "Parking Crew Spyware",
            "c.parkingcrew.net 185.53.178.30 TTL: 9\tPSI-USA, Inc. dba Domain Robot Organization: Team Internet AG Name Server: NS-1403.AWSDNS-47.ORG",
            "http://service.appleid.apple.online.hqvce.techapply.com/apple/f625bbcc3a59f078ffa95159c719501e/index.php?itunes=_connect-run&secure=5540zef1415405412104ef151511d7f84f5ze1f510eec8bd0e",
            "service.appleid.apple.online.hqvce.techapply.com 76.223.35.103 TTL: 600\tTitanic Hosting, Inc. Name Server: NS1.DNE.COM",
            "d38psrni17bvxu.cloudfront.net 18.239.196.136 TTL: 60\tMarkMonitor, Inc. Organization: Amazon.com, Inc. Name Server: NS-1306.AWSDNS-35.ORG",
            "https://www.hybrid-analysis.com/sample/6450c8bb8cec78135dd4891507099d1407ef1d9af40bc250251eb99888c20f7e/651eda366e1436b384026c6d",
            "wTools",
            "Research and Analysis",
            "go.microsoft.com 184.26.158.64 TTL: 2672\tMarkMonitor, Inc. Organization: Microsoft Corporation Name Server: NS1.MSFT.NET",
            "dllinject"
          ],
          "public": 1,
          "adversary": "Cyber Criminal",
          "targeted_countries": [
            "Argentina",
            "Ireland",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Looquer",
              "display_name": "Looquer",
              "target": null
            },
            {
              "id": "TinyZBot - S0004",
              "display_name": "TinyZBot - S0004",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "Bambernek Pony",
              "display_name": "Bambernek Pony",
              "target": null
            },
            {
              "id": "Ransom:Win32/Nymaim",
              "display_name": "Ransom:Win32/Nymaim",
              "target": "/malware/Ransom:Win32/Nymaim"
            },
            {
              "id": "Backdoor:Win32/Simda",
              "display_name": "Backdoor:Win32/Simda",
              "target": "/malware/Backdoor:Win32/Simda"
            },
            {
              "id": "TrojanSpy:Win32/Kronos",
              "display_name": "TrojanSpy:Win32/Kronos",
              "target": "/malware/TrojanSpy:Win32/Kronos"
            },
            {
              "id": "Trojan:Win32/Raccoonstealer",
              "display_name": "Trojan:Win32/Raccoonstealer",
              "target": "/malware/Trojan:Win32/Raccoonstealer"
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "Spammer:Win32/Noname",
              "display_name": "Spammer:Win32/Noname",
              "target": "/malware/Spammer:Win32/Noname"
            },
            {
              "id": "Worm:Win32/Pykspa",
              "display_name": "Worm:Win32/Pykspa",
              "target": "/malware/Worm:Win32/Pykspa"
            },
            {
              "id": "Banker",
              "display_name": "Banker",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Razy",
              "display_name": "Trojan:MSIL/Razy",
              "target": "/malware/Trojan:MSIL/Razy"
            },
            {
              "id": "Trojan:Win32/Wacatac",
              "display_name": "Trojan:Win32/Wacatac",
              "target": "/malware/Trojan:Win32/Wacatac"
            },
            {
              "id": "ALF:PUA:Win32/IObit",
              "display_name": "ALF:PUA:Win32/IObit",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Kraddare",
              "display_name": "TrojanDownloader:Win32/Kraddare",
              "target": "/malware/TrojanDownloader:Win32/Kraddare"
            },
            {
              "id": "ALF:PUA:Win32/FusionCore",
              "display_name": "ALF:PUA:Win32/FusionCore",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
              "display_name": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
              "target": null
            },
            {
              "id": "Trojan:Win32/Qbot",
              "display_name": "Trojan:Win32/Qbot",
              "target": "/malware/Trojan:Win32/Qbot"
            },
            {
              "id": "Trojan:Win32/InstallCore",
              "display_name": "Trojan:Win32/InstallCore",
              "target": "/malware/Trojan:Win32/InstallCore"
            },
            {
              "id": "ALF:JASYP:PUAWin32/Systweak",
              "display_name": "ALF:JASYP:PUAWin32/Systweak",
              "target": null
            },
            {
              "id": "Trojan:Win32/Dapato",
              "display_name": "Trojan:Win32/Dapato",
              "target": "/malware/Trojan:Win32/Dapato"
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1132.001",
              "name": "Standard Encoding",
              "display_name": "T1132.001 - Standard Encoding"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "TA0037",
              "name": "Command and Control",
              "display_name": "TA0037 - Command and Control"
            },
            {
              "id": "T1070.003",
              "name": "Clear Command History",
              "display_name": "T1070.003 - Clear Command History"
            },
            {
              "id": "T1001.003",
              "name": "Protocol Impersonation",
              "display_name": "T1001.003 - Protocol Impersonation"
            },
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 34,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 485,
            "hostname": 551,
            "URL": 1019,
            "FileHash-SHA256": 650,
            "CVE": 5,
            "FileHash-MD5": 425,
            "FileHash-SHA1": 224,
            "FilePath": 2,
            "email": 2
          },
          "indicator_count": 3363,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "939 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "651f177187ed5eba41657bf4",
          "name": "Packed.VMProt/ Packed.VMProtect Apple|  iOS | Mac attack techapply.com",
          "description": "Significantly infected Apple ID. and various devices; spyrixkeylogger, spyware, networm, tracking, beacons, injection, full control iOS and apple devices as well as OS. Appears as investigated. Not a lawful investigated. 5+ year (analysis reveals dated CVE's and malware specially targets individual) of spying, tagging, targeting, cyber criminal, cyber harassment, unlocker, disabled apple IDs. Interface / dummy core, collection, webdisk harvesting, cyber criminal behavior. Possible red teaming. js user, code written for a variety programs/systems, C2, relay router. robots. \ncyber threat.\nhired\ntargeted \nbotnets\nmalware\nAI",
          "modified": "2023-11-04T16:00:22.229000",
          "created": "2023-10-05T20:07:13.805000",
          "tags": [
            "engineering",
            "united",
            "cyber threat",
            "team",
            "malware",
            "telefonica co",
            "heur",
            "malicious site",
            "ip reputation",
            "bambernek pony",
            "zeus",
            "nymaim",
            "facebook",
            "raccoon",
            "download",
            "kronos",
            "ramnit",
            "simda",
            "bank",
            "phishing",
            "citadel",
            "zbot",
            "pykspa",
            "agent",
            "maltiverse",
            "noname057",
            "copyright",
            "reserved",
            "flag",
            "date",
            "name server",
            "markmonitor",
            "server",
            "organization",
            "germany germany",
            "sample",
            "session details",
            "click",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "exit node",
            "traffic group",
            "suricata alerts",
            "event category",
            "analysis",
            "malicious url",
            "windows nt",
            "wow64",
            "response",
            "gmt contenttype",
            "gecko host",
            "vary",
            "gmt etag",
            "general gets",
            "script",
            "parking crew",
            "apple",
            "apple id",
            "tsara",
            "tsara brashears",
            "spyware",
            "cyber criminal",
            "cyber stalking",
            "track",
            "track iphone",
            "accept all platforms",
            "infringement",
            "intellectual property",
            "suricata",
            "alert",
            "red team",
            "happywifehappylife",
            "malicious",
            "revenge",
            "posts",
            "post",
            "post to web",
            "post to server",
            "exploit",
            "command_and_control",
            "toggle",
            "logon",
            "login",
            "privilege",
            "ios",
            "attack",
            "mitre",
            "Packed.VMProt",
            "apple engineering",
            "abuse",
            "cve",
            "robots",
            "arizona",
            "bounce",
            "canada",
            "croatia",
            "base64_encoded",
            "%samplepath%",
            "tagging",
            "png image",
            "PSI-USA, Inc. dba Domain Robot Organization",
            "dns",
            "query",
            "evasive",
            "crack",
            "record type",
            "ttl value",
            "dns replication",
            "santa fe",
            "available from",
            "registrar abuse",
            "iana id",
            "domain status",
            "creation date",
            "registrar url",
            "code",
            "dapato",
            "predator",
            "win64",
            "conduit",
            "fakeinstaller",
            "installpack",
            "generic",
            "downloader",
            "spyrixkeylogger",
            "bitminer",
            "loadmoney",
            "filetour",
            "wacatac",
            "fusioncore",
            "cleaner",
            "networm",
            "mediaget",
            "softonic",
            "trojan",
            "encpk",
            "qbot",
            "swrort",
            "kraddare",
            "systweak",
            "iobit",
            "installcore",
            "artemis",
            "riskware",
            "dllinject",
            "driverpack",
            "trojanspy",
            "webtoolbar",
            "cisco umbrella",
            "ip hostname",
            "safe site",
            "site",
            "targeted",
            "AI",
            "dllinject"
          ],
          "references": [
            "Spyware",
            "Parking Crew Spyware",
            "c.parkingcrew.net 185.53.178.30 TTL: 9\tPSI-USA, Inc. dba Domain Robot Organization: Team Internet AG Name Server: NS-1403.AWSDNS-47.ORG",
            "http://service.appleid.apple.online.hqvce.techapply.com/apple/f625bbcc3a59f078ffa95159c719501e/index.php?itunes=_connect-run&secure=5540zef1415405412104ef151511d7f84f5ze1f510eec8bd0e",
            "service.appleid.apple.online.hqvce.techapply.com 76.223.35.103 TTL: 600\tTitanic Hosting, Inc. Name Server: NS1.DNE.COM",
            "d38psrni17bvxu.cloudfront.net 18.239.196.136 TTL: 60\tMarkMonitor, Inc. Organization: Amazon.com, Inc. Name Server: NS-1306.AWSDNS-35.ORG",
            "https://www.hybrid-analysis.com/sample/6450c8bb8cec78135dd4891507099d1407ef1d9af40bc250251eb99888c20f7e/651eda366e1436b384026c6d",
            "wTools",
            "Research and Analysis",
            "go.microsoft.com 184.26.158.64 TTL: 2672\tMarkMonitor, Inc. Organization: Microsoft Corporation Name Server: NS1.MSFT.NET",
            "dllinject"
          ],
          "public": 1,
          "adversary": "Cyber Criminal",
          "targeted_countries": [
            "Argentina",
            "Ireland",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Looquer",
              "display_name": "Looquer",
              "target": null
            },
            {
              "id": "TinyZBot - S0004",
              "display_name": "TinyZBot - S0004",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "Bambernek Pony",
              "display_name": "Bambernek Pony",
              "target": null
            },
            {
              "id": "Ransom:Win32/Nymaim",
              "display_name": "Ransom:Win32/Nymaim",
              "target": "/malware/Ransom:Win32/Nymaim"
            },
            {
              "id": "Backdoor:Win32/Simda",
              "display_name": "Backdoor:Win32/Simda",
              "target": "/malware/Backdoor:Win32/Simda"
            },
            {
              "id": "TrojanSpy:Win32/Kronos",
              "display_name": "TrojanSpy:Win32/Kronos",
              "target": "/malware/TrojanSpy:Win32/Kronos"
            },
            {
              "id": "Trojan:Win32/Raccoonstealer",
              "display_name": "Trojan:Win32/Raccoonstealer",
              "target": "/malware/Trojan:Win32/Raccoonstealer"
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "Spammer:Win32/Noname",
              "display_name": "Spammer:Win32/Noname",
              "target": "/malware/Spammer:Win32/Noname"
            },
            {
              "id": "Worm:Win32/Pykspa",
              "display_name": "Worm:Win32/Pykspa",
              "target": "/malware/Worm:Win32/Pykspa"
            },
            {
              "id": "Banker",
              "display_name": "Banker",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Razy",
              "display_name": "Trojan:MSIL/Razy",
              "target": "/malware/Trojan:MSIL/Razy"
            },
            {
              "id": "Trojan:Win32/Wacatac",
              "display_name": "Trojan:Win32/Wacatac",
              "target": "/malware/Trojan:Win32/Wacatac"
            },
            {
              "id": "ALF:PUA:Win32/IObit",
              "display_name": "ALF:PUA:Win32/IObit",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Kraddare",
              "display_name": "TrojanDownloader:Win32/Kraddare",
              "target": "/malware/TrojanDownloader:Win32/Kraddare"
            },
            {
              "id": "ALF:PUA:Win32/FusionCore",
              "display_name": "ALF:PUA:Win32/FusionCore",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
              "display_name": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
              "target": null
            },
            {
              "id": "Trojan:Win32/Qbot",
              "display_name": "Trojan:Win32/Qbot",
              "target": "/malware/Trojan:Win32/Qbot"
            },
            {
              "id": "Trojan:Win32/InstallCore",
              "display_name": "Trojan:Win32/InstallCore",
              "target": "/malware/Trojan:Win32/InstallCore"
            },
            {
              "id": "ALF:JASYP:PUAWin32/Systweak",
              "display_name": "ALF:JASYP:PUAWin32/Systweak",
              "target": null
            },
            {
              "id": "Trojan:Win32/Dapato",
              "display_name": "Trojan:Win32/Dapato",
              "target": "/malware/Trojan:Win32/Dapato"
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1132.001",
              "name": "Standard Encoding",
              "display_name": "T1132.001 - Standard Encoding"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "TA0037",
              "name": "Command and Control",
              "display_name": "TA0037 - Command and Control"
            },
            {
              "id": "T1070.003",
              "name": "Clear Command History",
              "display_name": "T1070.003 - Clear Command History"
            },
            {
              "id": "T1001.003",
              "name": "Protocol Impersonation",
              "display_name": "T1001.003 - Protocol Impersonation"
            },
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 37,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 485,
            "hostname": 551,
            "URL": 1019,
            "FileHash-SHA256": 650,
            "CVE": 5,
            "FileHash-MD5": 425,
            "FileHash-SHA1": 224,
            "FilePath": 2,
            "email": 2
          },
          "indicator_count": 3363,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "939 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f14eabcb037c4257b827b",
          "name": "Packed.VMProt/ Packed.VMProtect Apple| iOS | Mac attack techapply.com",
          "description": "",
          "modified": "2023-11-04T16:00:22.229000",
          "created": "2023-10-30T02:28:58.264000",
          "tags": [
            "engineering",
            "united",
            "cyber threat",
            "team",
            "malware",
            "telefonica co",
            "heur",
            "malicious site",
            "ip reputation",
            "bambernek pony",
            "zeus",
            "nymaim",
            "facebook",
            "raccoon",
            "download",
            "kronos",
            "ramnit",
            "simda",
            "bank",
            "phishing",
            "citadel",
            "zbot",
            "pykspa",
            "agent",
            "maltiverse",
            "noname057",
            "copyright",
            "reserved",
            "flag",
            "date",
            "name server",
            "markmonitor",
            "server",
            "organization",
            "germany germany",
            "sample",
            "session details",
            "click",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "exit node",
            "traffic group",
            "suricata alerts",
            "event category",
            "analysis",
            "malicious url",
            "windows nt",
            "wow64",
            "response",
            "gmt contenttype",
            "gecko host",
            "vary",
            "gmt etag",
            "general gets",
            "script",
            "parking crew",
            "apple",
            "apple id",
            "tsara",
            "tsara brashears",
            "spyware",
            "cyber criminal",
            "cyber stalking",
            "track",
            "track iphone",
            "accept all platforms",
            "infringement",
            "intellectual property",
            "suricata",
            "alert",
            "red team",
            "happywifehappylife",
            "malicious",
            "revenge",
            "posts",
            "post",
            "post to web",
            "post to server",
            "exploit",
            "command_and_control",
            "toggle",
            "logon",
            "login",
            "privilege",
            "ios",
            "attack",
            "mitre",
            "Packed.VMProt",
            "apple engineering",
            "abuse",
            "cve",
            "robots",
            "arizona",
            "bounce",
            "canada",
            "croatia",
            "base64_encoded",
            "%samplepath%",
            "tagging",
            "png image",
            "PSI-USA, Inc. dba Domain Robot Organization",
            "dns",
            "query",
            "evasive",
            "crack",
            "record type",
            "ttl value",
            "dns replication",
            "santa fe",
            "available from",
            "registrar abuse",
            "iana id",
            "domain status",
            "creation date",
            "registrar url",
            "code",
            "dapato",
            "predator",
            "win64",
            "conduit",
            "fakeinstaller",
            "installpack",
            "generic",
            "downloader",
            "spyrixkeylogger",
            "bitminer",
            "loadmoney",
            "filetour",
            "wacatac",
            "fusioncore",
            "cleaner",
            "networm",
            "mediaget",
            "softonic",
            "trojan",
            "encpk",
            "qbot",
            "swrort",
            "kraddare",
            "systweak",
            "iobit",
            "installcore",
            "artemis",
            "riskware",
            "dllinject",
            "driverpack",
            "trojanspy",
            "webtoolbar",
            "cisco umbrella",
            "ip hostname",
            "safe site",
            "site",
            "targeted",
            "AI",
            "dllinject"
          ],
          "references": [
            "Spyware",
            "Parking Crew Spyware",
            "c.parkingcrew.net 185.53.178.30 TTL: 9\tPSI-USA, Inc. dba Domain Robot Organization: Team Internet AG Name Server: NS-1403.AWSDNS-47.ORG",
            "http://service.appleid.apple.online.hqvce.techapply.com/apple/f625bbcc3a59f078ffa95159c719501e/index.php?itunes=_connect-run&secure=5540zef1415405412104ef151511d7f84f5ze1f510eec8bd0e",
            "service.appleid.apple.online.hqvce.techapply.com 76.223.35.103 TTL: 600\tTitanic Hosting, Inc. Name Server: NS1.DNE.COM",
            "d38psrni17bvxu.cloudfront.net 18.239.196.136 TTL: 60\tMarkMonitor, Inc. Organization: Amazon.com, Inc. Name Server: NS-1306.AWSDNS-35.ORG",
            "https://www.hybrid-analysis.com/sample/6450c8bb8cec78135dd4891507099d1407ef1d9af40bc250251eb99888c20f7e/651eda366e1436b384026c6d",
            "wTools",
            "Research and Analysis",
            "go.microsoft.com 184.26.158.64 TTL: 2672\tMarkMonitor, Inc. Organization: Microsoft Corporation Name Server: NS1.MSFT.NET",
            "dllinject"
          ],
          "public": 1,
          "adversary": "Cyber Criminal",
          "targeted_countries": [
            "Argentina",
            "Ireland",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Looquer",
              "display_name": "Looquer",
              "target": null
            },
            {
              "id": "TinyZBot - S0004",
              "display_name": "TinyZBot - S0004",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "Bambernek Pony",
              "display_name": "Bambernek Pony",
              "target": null
            },
            {
              "id": "Ransom:Win32/Nymaim",
              "display_name": "Ransom:Win32/Nymaim",
              "target": "/malware/Ransom:Win32/Nymaim"
            },
            {
              "id": "Backdoor:Win32/Simda",
              "display_name": "Backdoor:Win32/Simda",
              "target": "/malware/Backdoor:Win32/Simda"
            },
            {
              "id": "TrojanSpy:Win32/Kronos",
              "display_name": "TrojanSpy:Win32/Kronos",
              "target": "/malware/TrojanSpy:Win32/Kronos"
            },
            {
              "id": "Trojan:Win32/Raccoonstealer",
              "display_name": "Trojan:Win32/Raccoonstealer",
              "target": "/malware/Trojan:Win32/Raccoonstealer"
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "Spammer:Win32/Noname",
              "display_name": "Spammer:Win32/Noname",
              "target": "/malware/Spammer:Win32/Noname"
            },
            {
              "id": "Worm:Win32/Pykspa",
              "display_name": "Worm:Win32/Pykspa",
              "target": "/malware/Worm:Win32/Pykspa"
            },
            {
              "id": "Banker",
              "display_name": "Banker",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Razy",
              "display_name": "Trojan:MSIL/Razy",
              "target": "/malware/Trojan:MSIL/Razy"
            },
            {
              "id": "Trojan:Win32/Wacatac",
              "display_name": "Trojan:Win32/Wacatac",
              "target": "/malware/Trojan:Win32/Wacatac"
            },
            {
              "id": "ALF:PUA:Win32/IObit",
              "display_name": "ALF:PUA:Win32/IObit",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Kraddare",
              "display_name": "TrojanDownloader:Win32/Kraddare",
              "target": "/malware/TrojanDownloader:Win32/Kraddare"
            },
            {
              "id": "ALF:PUA:Win32/FusionCore",
              "display_name": "ALF:PUA:Win32/FusionCore",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
              "display_name": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
              "target": null
            },
            {
              "id": "Trojan:Win32/Qbot",
              "display_name": "Trojan:Win32/Qbot",
              "target": "/malware/Trojan:Win32/Qbot"
            },
            {
              "id": "Trojan:Win32/InstallCore",
              "display_name": "Trojan:Win32/InstallCore",
              "target": "/malware/Trojan:Win32/InstallCore"
            },
            {
              "id": "ALF:JASYP:PUAWin32/Systweak",
              "display_name": "ALF:JASYP:PUAWin32/Systweak",
              "target": null
            },
            {
              "id": "Trojan:Win32/Dapato",
              "display_name": "Trojan:Win32/Dapato",
              "target": "/malware/Trojan:Win32/Dapato"
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1132.001",
              "name": "Standard Encoding",
              "display_name": "T1132.001 - Standard Encoding"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "TA0037",
              "name": "Command and Control",
              "display_name": "TA0037 - Command and Control"
            },
            {
              "id": "T1070.003",
              "name": "Clear Command History",
              "display_name": "T1070.003 - Clear Command History"
            },
            {
              "id": "T1001.003",
              "name": "Protocol Impersonation",
              "display_name": "T1001.003 - Protocol Impersonation"
            },
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "651f177187ed5eba41657bf4",
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 485,
            "hostname": 551,
            "URL": 1019,
            "FileHash-SHA256": 650,
            "CVE": 5,
            "FileHash-MD5": 425,
            "FileHash-SHA1": 224,
            "FilePath": 2,
            "email": 2
          },
          "indicator_count": 3363,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "939 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "wTools",
        "go.microsoft.com 184.26.158.64 TTL: 2672\tMarkMonitor, Inc. Organization: Microsoft Corporation Name Server: NS1.MSFT.NET",
        "c.parkingcrew.net 185.53.178.30 TTL: 9\tPSI-USA, Inc. dba Domain Robot Organization: Team Internet AG Name Server: NS-1403.AWSDNS-47.ORG",
        "d38psrni17bvxu.cloudfront.net 18.239.196.136 TTL: 60\tMarkMonitor, Inc. Organization: Amazon.com, Inc. Name Server: NS-1306.AWSDNS-35.ORG",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
        "Parking Crew Spyware",
        "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
        "Spyware",
        "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]",
        "https://www.hybrid-analysis.com/sample/6450c8bb8cec78135dd4891507099d1407ef1d9af40bc250251eb99888c20f7e/651eda366e1436b384026c6d",
        "http://service.appleid.apple.online.hqvce.techapply.com/apple/f625bbcc3a59f078ffa95159c719501e/index.php?itunes=_connect-run&secure=5540zef1415405412104ef151511d7f84f5ze1f510eec8bd0e",
        "service.appleid.apple.online.hqvce.techapply.com 76.223.35.103 TTL: 600\tTitanic Hosting, Inc. Name Server: NS1.DNE.COM",
        "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
        "*otc.greatcall.com    [Botnetwork]",
        "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
        "dllinject",
        "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
        "tulach.cc.     [Malevolent | Modified description]",
        "https://tulach.cc/ [phishing]",
        "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
        "Research and Analysis"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Cyber Criminal",
            "Qbot"
          ],
          "malware_families": [
            "Trojan:win32/wacatac",
            "Looquer",
            "Packed.vmprotect",
            "Alf:pua:win32/iobit",
            "Alf:heraklezeval:pua:win32/spyrixkeylogger",
            "Trojanspy",
            "Roblox",
            "Trojan:win32/dapato",
            "Banker",
            "Tinyzbot - s0004",
            "Trojan:win32/installcore",
            "Trojandownloader:win32/kraddare",
            "Alf:jasyp:puawin32/systweak",
            "D26a",
            "Trojan:msil/razy",
            "Trojan:win32/qbot",
            "Tulach malware",
            "Ransom:win32/nymaim",
            "Bambernek pony",
            "Backdoor:win32/simda",
            "Alf:pua:win32/fusioncore",
            "Ramnit",
            "Spammer:win32/noname",
            "Trojanspy:win32/kronos",
            "Webtoolbar",
            "Maltiverse",
            "Worm:win32/pykspa",
            "Trojan:win32/raccoonstealer"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "655f6d7ac217661e4bc37f4d",
      "name": "Qbot | Miscellaneous Attacks",
      "description": "The following is a full list of links between malware and cyber-attackers, following a series of alerts from Phishtank, the UK-based cyber security firm, and the US government.",
      "modified": "2023-12-23T07:03:55.171000",
      "created": "2023-11-23T15:19:22.356000",
      "tags": [
        "pattern match",
        "ascii text",
        "file",
        "jpeg image",
        "exif standard",
        "tiff image",
        "png image",
        "united",
        "baseline",
        "rgba",
        "date",
        "class",
        "unknown",
        "hybrid",
        "accept",
        "local",
        "click",
        "strings",
        "generator",
        "critical",
        "error",
        "firehol",
        "detection list",
        "ip address",
        "blacklist",
        "botnet command",
        "control server",
        "noname057",
        "facebook",
        "phishtank",
        "blacklist http",
        "organization",
        "ssl certificate",
        "whois record",
        "contacted",
        "historical ssl",
        "n64xtx0vpihxzc",
        "whois whois",
        "qpyrn6pd http",
        "referrer",
        "execution",
        "communicating",
        "core",
        "discord",
        "hiddentear",
        "metro",
        "probe",
        "ransomexx",
        "quasar",
        "asyncrat",
        "bleachgap",
        "formbook",
        "nanocore",
        "roblox",
        "heur",
        "cyber threat",
        "engineering",
        "malware",
        "phishing",
        "malicious site",
        "phishing site",
        "covid19",
        "team",
        "bank",
        "cobalt strike",
        "artemis",
        "download",
        "zbot",
        "suppobox",
        "service",
        "downloader",
        "virut",
        "malicious",
        "emotet",
        "stealer",
        "exploit",
        "generic",
        "dropper",
        "unruy",
        "agent",
        "unsafe",
        "ramnit",
        "redline stealer",
        "smsspy",
        "bradesco",
        "fakealert",
        "qakbot",
        "outbreak",
        "qbot",
        "bankerx",
        "riskware",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "crack",
        "win64",
        "squirrelwaffle",
        "pony",
        "binder",
        "virustotal",
        "azorult",
        "zeus",
        "nymaim",
        "matsnu",
        "simda",
        "runescape",
        "cutwail",
        "dnspionage",
        "redirector",
        "fusioncore",
        "iframe",
        "killav",
        "raccoon",
        "daum",
        "installcore",
        "ransomware",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "presenoker",
        "downldr",
        "alexa",
        "applicunwnt",
        "opencandy",
        "cleaner",
        "wacatac",
        "xrat",
        "xtrat",
        "dbatloader",
        "infy",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "keygen",
        "fareit",
        "secrisk",
        "phish",
        "deepscan",
        "trojanspy",
        "maltiverse",
        "qpyrn6pd",
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample"
      ],
      "references": [
        "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
        "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
        "*otc.greatcall.com    [Botnetwork]",
        "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
        "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
        "tulach.cc.     [Malevolent | Modified description]",
        "https://tulach.cc/ [phishing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
        "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
        "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
      ],
      "public": 1,
      "adversary": "Qbot",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Roblox",
          "display_name": "Roblox",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 82,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 897,
        "FileHash-SHA1": 479,
        "URL": 9847,
        "domain": 2344,
        "hostname": 2398,
        "CVE": 22,
        "FileHash-SHA256": 4712
      },
      "indicator_count": 20699,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "890 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "655f6d89b33758a190399f39",
      "name": "Qbot | Miscellaneous Attacks",
      "description": "The following is a full list of links between malware and cyber-attackers, following a series of alerts from Phishtank, the UK-based cyber security firm, and the US government.",
      "modified": "2023-12-23T07:03:55.171000",
      "created": "2023-11-23T15:19:37.838000",
      "tags": [
        "pattern match",
        "ascii text",
        "file",
        "jpeg image",
        "exif standard",
        "tiff image",
        "png image",
        "united",
        "baseline",
        "rgba",
        "date",
        "class",
        "unknown",
        "hybrid",
        "accept",
        "local",
        "click",
        "strings",
        "generator",
        "critical",
        "error",
        "firehol",
        "detection list",
        "ip address",
        "blacklist",
        "botnet command",
        "control server",
        "noname057",
        "facebook",
        "phishtank",
        "blacklist http",
        "organization",
        "ssl certificate",
        "whois record",
        "contacted",
        "historical ssl",
        "n64xtx0vpihxzc",
        "whois whois",
        "qpyrn6pd http",
        "referrer",
        "execution",
        "communicating",
        "core",
        "discord",
        "hiddentear",
        "metro",
        "probe",
        "ransomexx",
        "quasar",
        "asyncrat",
        "bleachgap",
        "formbook",
        "nanocore",
        "roblox",
        "heur",
        "cyber threat",
        "engineering",
        "malware",
        "phishing",
        "malicious site",
        "phishing site",
        "covid19",
        "team",
        "bank",
        "cobalt strike",
        "artemis",
        "download",
        "zbot",
        "suppobox",
        "service",
        "downloader",
        "virut",
        "malicious",
        "emotet",
        "stealer",
        "exploit",
        "generic",
        "dropper",
        "unruy",
        "agent",
        "unsafe",
        "ramnit",
        "redline stealer",
        "smsspy",
        "bradesco",
        "fakealert",
        "qakbot",
        "outbreak",
        "qbot",
        "bankerx",
        "riskware",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "crack",
        "win64",
        "squirrelwaffle",
        "pony",
        "binder",
        "virustotal",
        "azorult",
        "zeus",
        "nymaim",
        "matsnu",
        "simda",
        "runescape",
        "cutwail",
        "dnspionage",
        "redirector",
        "fusioncore",
        "iframe",
        "killav",
        "raccoon",
        "daum",
        "installcore",
        "ransomware",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "presenoker",
        "downldr",
        "alexa",
        "applicunwnt",
        "opencandy",
        "cleaner",
        "wacatac",
        "xrat",
        "xtrat",
        "dbatloader",
        "infy",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "keygen",
        "fareit",
        "secrisk",
        "phish",
        "deepscan",
        "trojanspy",
        "maltiverse",
        "qpyrn6pd",
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample"
      ],
      "references": [
        "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
        "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
        "*otc.greatcall.com    [Botnetwork]",
        "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
        "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
        "tulach.cc.     [Malevolent | Modified description]",
        "https://tulach.cc/ [phishing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
        "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
        "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
      ],
      "public": 1,
      "adversary": "Qbot",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Roblox",
          "display_name": "Roblox",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 84,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 897,
        "FileHash-SHA1": 479,
        "URL": 9847,
        "domain": 2344,
        "hostname": 2398,
        "CVE": 22,
        "FileHash-SHA256": 4712
      },
      "indicator_count": 20699,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "890 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "655f6edffd3910161c2ad1a2",
      "name": "D26A | DNSpionage| Qbot | Tulach Malaware | https://theanimallawfirm.com/ | FakeAlert",
      "description": "",
      "modified": "2023-12-23T07:03:55.171000",
      "created": "2023-11-23T15:25:19.843000",
      "tags": [
        "pattern match",
        "ascii text",
        "file",
        "jpeg image",
        "exif standard",
        "tiff image",
        "png image",
        "united",
        "baseline",
        "rgba",
        "date",
        "class",
        "unknown",
        "hybrid",
        "accept",
        "local",
        "click",
        "strings",
        "generator",
        "critical",
        "error",
        "firehol",
        "detection list",
        "ip address",
        "blacklist",
        "botnet command",
        "control server",
        "noname057",
        "facebook",
        "phishtank",
        "blacklist http",
        "organization",
        "ssl certificate",
        "whois record",
        "contacted",
        "historical ssl",
        "n64xtx0vpihxzc",
        "whois whois",
        "qpyrn6pd http",
        "referrer",
        "execution",
        "communicating",
        "core",
        "discord",
        "hiddentear",
        "metro",
        "probe",
        "ransomexx",
        "quasar",
        "asyncrat",
        "bleachgap",
        "formbook",
        "nanocore",
        "roblox",
        "heur",
        "cyber threat",
        "engineering",
        "malware",
        "phishing",
        "malicious site",
        "phishing site",
        "covid19",
        "team",
        "bank",
        "cobalt strike",
        "artemis",
        "download",
        "zbot",
        "suppobox",
        "service",
        "downloader",
        "virut",
        "malicious",
        "emotet",
        "stealer",
        "exploit",
        "generic",
        "dropper",
        "unruy",
        "agent",
        "unsafe",
        "ramnit",
        "redline stealer",
        "smsspy",
        "bradesco",
        "fakealert",
        "qakbot",
        "outbreak",
        "qbot",
        "bankerx",
        "riskware",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "crack",
        "win64",
        "squirrelwaffle",
        "pony",
        "binder",
        "virustotal",
        "azorult",
        "zeus",
        "nymaim",
        "matsnu",
        "simda",
        "runescape",
        "cutwail",
        "dnspionage",
        "redirector",
        "fusioncore",
        "iframe",
        "killav",
        "raccoon",
        "daum",
        "installcore",
        "ransomware",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "presenoker",
        "downldr",
        "alexa",
        "applicunwnt",
        "opencandy",
        "cleaner",
        "wacatac",
        "xrat",
        "xtrat",
        "dbatloader",
        "infy",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "keygen",
        "fareit",
        "secrisk",
        "phish",
        "deepscan",
        "trojanspy",
        "maltiverse",
        "qpyrn6pd",
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample"
      ],
      "references": [
        "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
        "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
        "*otc.greatcall.com    [Botnetwork]",
        "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
        "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
        "tulach.cc.     [Malevolent | Modified description]",
        "https://tulach.cc/ [phishing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
        "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
        "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
      ],
      "public": 1,
      "adversary": "Qbot",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Roblox",
          "display_name": "Roblox",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "655f6d89b33758a190399f39",
      "export_count": 86,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 897,
        "FileHash-SHA1": 479,
        "URL": 9847,
        "domain": 2344,
        "hostname": 2398,
        "CVE": 22,
        "FileHash-SHA256": 4712
      },
      "indicator_count": 20699,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "890 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "655e7e82c65d8e9106e6a227",
      "name": "https://theanimallawfirm.com/",
      "description": "",
      "modified": "2023-12-22T21:04:18.086000",
      "created": "2023-11-22T22:19:46.485000",
      "tags": [
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "n64xtx0vpihxzc",
        "qpyrn6pd",
        "detection list",
        "blacklist http",
        "cisco umbrella",
        "site",
        "site top",
        "alexa top",
        "safe site",
        "heur",
        "html",
        "site safe",
        "million",
        "malware",
        "artemis",
        "win64",
        "downldr",
        "presenoker",
        "fakealert",
        "riskware",
        "qakbot",
        "applicunwnt",
        "opencandy",
        "fusioncore",
        "cleaner",
        "wacatac",
        "exploit",
        "iframe",
        "dbatloader",
        "raccoon",
        "service",
        "agent",
        "alexa",
        "xtrat",
        "team",
        "phish",
        "deepscan",
        "crack",
        "suspicious",
        "phishing",
        "xrat",
        "cve201711882",
        "d26a",
        "maltiverse",
        "trojanspy",
        "united",
        "cyber threat",
        "engineering",
        "malicious site",
        "bank",
        "phishing site",
        "covid19",
        "facebook",
        "download",
        "emotet",
        "stealer",
        "suppobox",
        "downloader",
        "unsafe",
        "malicious",
        "smsspy",
        "cobalt strike",
        "generic",
        "dropper",
        "formbook",
        "unruy",
        "virut",
        "azorult",
        "zbot",
        "matsnu",
        "cutwail",
        "bradesco",
        "outbreak",
        "qbot",
        "bankerx",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "squirrelwaffle",
        "pony",
        "binder",
        "ramnit",
        "virustotal",
        "zeus",
        "nymaim",
        "simda",
        "runescape",
        "dnspionage",
        "redirector",
        "killav",
        "dcrat",
        "alien",
        "astaroth",
        "filerepmalware",
        "control server",
        "asyncrat",
        "redline stealer",
        "daum",
        "name verdict"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "D26A",
          "display_name": "D26A",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 62,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 592,
        "FileHash-SHA1": 320,
        "FileHash-SHA256": 1159,
        "URL": 1257,
        "domain": 1219,
        "hostname": 403,
        "CVE": 15
      },
      "indicator_count": 4965,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "891 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "655e7ed63ab06f2006c90b1c",
      "name": "DNSpionage, ",
      "description": "",
      "modified": "2023-12-22T21:04:18.086000",
      "created": "2023-11-22T22:21:10.853000",
      "tags": [
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "n64xtx0vpihxzc",
        "qpyrn6pd",
        "detection list",
        "blacklist http",
        "cisco umbrella",
        "site",
        "site top",
        "alexa top",
        "safe site",
        "heur",
        "html",
        "site safe",
        "million",
        "malware",
        "artemis",
        "win64",
        "downldr",
        "presenoker",
        "fakealert",
        "riskware",
        "qakbot",
        "applicunwnt",
        "opencandy",
        "fusioncore",
        "cleaner",
        "wacatac",
        "exploit",
        "iframe",
        "dbatloader",
        "raccoon",
        "service",
        "agent",
        "alexa",
        "xtrat",
        "team",
        "phish",
        "deepscan",
        "crack",
        "suspicious",
        "phishing",
        "xrat",
        "cve201711882",
        "d26a",
        "maltiverse",
        "trojanspy",
        "united",
        "cyber threat",
        "engineering",
        "malicious site",
        "bank",
        "phishing site",
        "covid19",
        "facebook",
        "download",
        "emotet",
        "stealer",
        "suppobox",
        "downloader",
        "unsafe",
        "malicious",
        "smsspy",
        "cobalt strike",
        "generic",
        "dropper",
        "formbook",
        "unruy",
        "virut",
        "azorult",
        "zbot",
        "matsnu",
        "cutwail",
        "bradesco",
        "outbreak",
        "qbot",
        "bankerx",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "squirrelwaffle",
        "pony",
        "binder",
        "ramnit",
        "virustotal",
        "zeus",
        "nymaim",
        "simda",
        "runescape",
        "dnspionage",
        "redirector",
        "killav",
        "dcrat",
        "alien",
        "astaroth",
        "filerepmalware",
        "control server",
        "asyncrat",
        "redline stealer",
        "daum",
        "name verdict"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "D26A",
          "display_name": "D26A",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "655e7e82c65d8e9106e6a227",
      "export_count": 64,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 592,
        "FileHash-SHA1": 320,
        "FileHash-SHA256": 1159,
        "URL": 1257,
        "domain": 1219,
        "hostname": 403,
        "CVE": 15
      },
      "indicator_count": 4965,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "891 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "656a9f3ad7db0aa9475e86d0",
      "name": "https://theanimallawfirm.com/",
      "description": "",
      "modified": "2023-12-22T21:04:18.086000",
      "created": "2023-12-02T03:06:34.870000",
      "tags": [
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "n64xtx0vpihxzc",
        "qpyrn6pd",
        "detection list",
        "blacklist http",
        "cisco umbrella",
        "site",
        "site top",
        "alexa top",
        "safe site",
        "heur",
        "html",
        "site safe",
        "million",
        "malware",
        "artemis",
        "win64",
        "downldr",
        "presenoker",
        "fakealert",
        "riskware",
        "qakbot",
        "applicunwnt",
        "opencandy",
        "fusioncore",
        "cleaner",
        "wacatac",
        "exploit",
        "iframe",
        "dbatloader",
        "raccoon",
        "service",
        "agent",
        "alexa",
        "xtrat",
        "team",
        "phish",
        "deepscan",
        "crack",
        "suspicious",
        "phishing",
        "xrat",
        "cve201711882",
        "d26a",
        "maltiverse",
        "trojanspy",
        "united",
        "cyber threat",
        "engineering",
        "malicious site",
        "bank",
        "phishing site",
        "covid19",
        "facebook",
        "download",
        "emotet",
        "stealer",
        "suppobox",
        "downloader",
        "unsafe",
        "malicious",
        "smsspy",
        "cobalt strike",
        "generic",
        "dropper",
        "formbook",
        "unruy",
        "virut",
        "azorult",
        "zbot",
        "matsnu",
        "cutwail",
        "bradesco",
        "outbreak",
        "qbot",
        "bankerx",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "squirrelwaffle",
        "pony",
        "binder",
        "ramnit",
        "virustotal",
        "zeus",
        "nymaim",
        "simda",
        "runescape",
        "dnspionage",
        "redirector",
        "killav",
        "dcrat",
        "alien",
        "astaroth",
        "filerepmalware",
        "control server",
        "asyncrat",
        "redline stealer",
        "daum",
        "name verdict"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "D26A",
          "display_name": "D26A",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "655e7e82c65d8e9106e6a227",
      "export_count": 45,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 592,
        "FileHash-SHA1": 320,
        "FileHash-SHA256": 1159,
        "URL": 1257,
        "domain": 1219,
        "hostname": 403,
        "CVE": 15
      },
      "indicator_count": 4965,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "891 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a7dda4ef145116f1593a",
      "name": "Packed.VMProt/ Packed.VMProtect Apple|  iOS | Mac attack techapply.com",
      "description": "",
      "modified": "2023-12-06T16:57:01.831000",
      "created": "2023-12-06T16:57:01.831000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 5,
        "hostname": 551,
        "FileHash-SHA256": 650,
        "FileHash-MD5": 425,
        "FileHash-SHA1": 224,
        "URL": 1019,
        "domain": 485,
        "email": 2,
        "FilePath": 2
      },
      "indicator_count": 3363,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a7d867bfb30b452b94d0",
      "name": "Packed.VMProt/ Packed.VMProtect Apple|  iOS | Mac attack techapply.com",
      "description": "",
      "modified": "2023-12-06T16:56:56.522000",
      "created": "2023-12-06T16:56:56.522000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 5,
        "hostname": 551,
        "FileHash-SHA256": 650,
        "FileHash-MD5": 425,
        "FileHash-SHA1": 224,
        "URL": 1019,
        "domain": 485,
        "email": 2,
        "FilePath": 2
      },
      "indicator_count": 3363,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "651f175a87ed5eba41657bf3",
      "name": "Packed.VMProt/ Packed.VMProtect Apple|  iOS | Mac attack techapply.com",
      "description": "Significantly infected Apple ID. and various devices; spyrixkeylogger, spyware, networm, tracking, beacons, injection, full control iOS and apple devices as well as OS. Appears as investigated. Not a lawful investigated. 5+ year (analysis reveals dated CVE's and malware specially targets individual) of spying, tagging, targeting, cyber criminal, cyber harassment, unlocker, disabled apple IDs. Interface / dummy core, collection, webdisk harvesting, cyber criminal behavior. Possible red teaming. js user, code written for a variety programs/systems, C2, relay router. robots. \ncyber threat.\nhired\ntargeted \nbotnets\nmalware\nAI",
      "modified": "2023-11-04T16:00:22.229000",
      "created": "2023-10-05T20:06:50.075000",
      "tags": [
        "engineering",
        "united",
        "cyber threat",
        "team",
        "malware",
        "telefonica co",
        "heur",
        "malicious site",
        "ip reputation",
        "bambernek pony",
        "zeus",
        "nymaim",
        "facebook",
        "raccoon",
        "download",
        "kronos",
        "ramnit",
        "simda",
        "bank",
        "phishing",
        "citadel",
        "zbot",
        "pykspa",
        "agent",
        "maltiverse",
        "noname057",
        "copyright",
        "reserved",
        "flag",
        "date",
        "name server",
        "markmonitor",
        "server",
        "organization",
        "germany germany",
        "sample",
        "session details",
        "click",
        "misc attack",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "exit node",
        "traffic group",
        "suricata alerts",
        "event category",
        "analysis",
        "malicious url",
        "windows nt",
        "wow64",
        "response",
        "gmt contenttype",
        "gecko host",
        "vary",
        "gmt etag",
        "general gets",
        "script",
        "parking crew",
        "apple",
        "apple id",
        "tsara",
        "tsara brashears",
        "spyware",
        "cyber criminal",
        "cyber stalking",
        "track",
        "track iphone",
        "accept all platforms",
        "infringement",
        "intellectual property",
        "suricata",
        "alert",
        "red team",
        "happywifehappylife",
        "malicious",
        "revenge",
        "posts",
        "post",
        "post to web",
        "post to server",
        "exploit",
        "command_and_control",
        "toggle",
        "logon",
        "login",
        "privilege",
        "ios",
        "attack",
        "mitre",
        "Packed.VMProt",
        "apple engineering",
        "abuse",
        "cve",
        "robots",
        "arizona",
        "bounce",
        "canada",
        "croatia",
        "base64_encoded",
        "%samplepath%",
        "tagging",
        "png image",
        "PSI-USA, Inc. dba Domain Robot Organization",
        "dns",
        "query",
        "evasive",
        "crack",
        "record type",
        "ttl value",
        "dns replication",
        "santa fe",
        "available from",
        "registrar abuse",
        "iana id",
        "domain status",
        "creation date",
        "registrar url",
        "code",
        "dapato",
        "predator",
        "win64",
        "conduit",
        "fakeinstaller",
        "installpack",
        "generic",
        "downloader",
        "spyrixkeylogger",
        "bitminer",
        "loadmoney",
        "filetour",
        "wacatac",
        "fusioncore",
        "cleaner",
        "networm",
        "mediaget",
        "softonic",
        "trojan",
        "encpk",
        "qbot",
        "swrort",
        "kraddare",
        "systweak",
        "iobit",
        "installcore",
        "artemis",
        "riskware",
        "dllinject",
        "driverpack",
        "trojanspy",
        "webtoolbar",
        "cisco umbrella",
        "ip hostname",
        "safe site",
        "site",
        "targeted",
        "AI",
        "dllinject"
      ],
      "references": [
        "Spyware",
        "Parking Crew Spyware",
        "c.parkingcrew.net 185.53.178.30 TTL: 9\tPSI-USA, Inc. dba Domain Robot Organization: Team Internet AG Name Server: NS-1403.AWSDNS-47.ORG",
        "http://service.appleid.apple.online.hqvce.techapply.com/apple/f625bbcc3a59f078ffa95159c719501e/index.php?itunes=_connect-run&secure=5540zef1415405412104ef151511d7f84f5ze1f510eec8bd0e",
        "service.appleid.apple.online.hqvce.techapply.com 76.223.35.103 TTL: 600\tTitanic Hosting, Inc. Name Server: NS1.DNE.COM",
        "d38psrni17bvxu.cloudfront.net 18.239.196.136 TTL: 60\tMarkMonitor, Inc. Organization: Amazon.com, Inc. Name Server: NS-1306.AWSDNS-35.ORG",
        "https://www.hybrid-analysis.com/sample/6450c8bb8cec78135dd4891507099d1407ef1d9af40bc250251eb99888c20f7e/651eda366e1436b384026c6d",
        "wTools",
        "Research and Analysis",
        "go.microsoft.com 184.26.158.64 TTL: 2672\tMarkMonitor, Inc. Organization: Microsoft Corporation Name Server: NS1.MSFT.NET",
        "dllinject"
      ],
      "public": 1,
      "adversary": "Cyber Criminal",
      "targeted_countries": [
        "Argentina",
        "Ireland",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Looquer",
          "display_name": "Looquer",
          "target": null
        },
        {
          "id": "TinyZBot - S0004",
          "display_name": "TinyZBot - S0004",
          "target": null
        },
        {
          "id": "Ramnit",
          "display_name": "Ramnit",
          "target": null
        },
        {
          "id": "Bambernek Pony",
          "display_name": "Bambernek Pony",
          "target": null
        },
        {
          "id": "Ransom:Win32/Nymaim",
          "display_name": "Ransom:Win32/Nymaim",
          "target": "/malware/Ransom:Win32/Nymaim"
        },
        {
          "id": "Backdoor:Win32/Simda",
          "display_name": "Backdoor:Win32/Simda",
          "target": "/malware/Backdoor:Win32/Simda"
        },
        {
          "id": "TrojanSpy:Win32/Kronos",
          "display_name": "TrojanSpy:Win32/Kronos",
          "target": "/malware/TrojanSpy:Win32/Kronos"
        },
        {
          "id": "Trojan:Win32/Raccoonstealer",
          "display_name": "Trojan:Win32/Raccoonstealer",
          "target": "/malware/Trojan:Win32/Raccoonstealer"
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "Spammer:Win32/Noname",
          "display_name": "Spammer:Win32/Noname",
          "target": "/malware/Spammer:Win32/Noname"
        },
        {
          "id": "Worm:Win32/Pykspa",
          "display_name": "Worm:Win32/Pykspa",
          "target": "/malware/Worm:Win32/Pykspa"
        },
        {
          "id": "Banker",
          "display_name": "Banker",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Razy",
          "display_name": "Trojan:MSIL/Razy",
          "target": "/malware/Trojan:MSIL/Razy"
        },
        {
          "id": "Trojan:Win32/Wacatac",
          "display_name": "Trojan:Win32/Wacatac",
          "target": "/malware/Trojan:Win32/Wacatac"
        },
        {
          "id": "ALF:PUA:Win32/IObit",
          "display_name": "ALF:PUA:Win32/IObit",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Kraddare",
          "display_name": "TrojanDownloader:Win32/Kraddare",
          "target": "/malware/TrojanDownloader:Win32/Kraddare"
        },
        {
          "id": "ALF:PUA:Win32/FusionCore",
          "display_name": "ALF:PUA:Win32/FusionCore",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
          "display_name": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
          "target": null
        },
        {
          "id": "Trojan:Win32/Qbot",
          "display_name": "Trojan:Win32/Qbot",
          "target": "/malware/Trojan:Win32/Qbot"
        },
        {
          "id": "Trojan:Win32/InstallCore",
          "display_name": "Trojan:Win32/InstallCore",
          "target": "/malware/Trojan:Win32/InstallCore"
        },
        {
          "id": "ALF:JASYP:PUAWin32/Systweak",
          "display_name": "ALF:JASYP:PUAWin32/Systweak",
          "target": null
        },
        {
          "id": "Trojan:Win32/Dapato",
          "display_name": "Trojan:Win32/Dapato",
          "target": "/malware/Trojan:Win32/Dapato"
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1132.001",
          "name": "Standard Encoding",
          "display_name": "T1132.001 - Standard Encoding"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "TA0037",
          "name": "Command and Control",
          "display_name": "TA0037 - Command and Control"
        },
        {
          "id": "T1070.003",
          "name": "Clear Command History",
          "display_name": "T1070.003 - Clear Command History"
        },
        {
          "id": "T1001.003",
          "name": "Protocol Impersonation",
          "display_name": "T1001.003 - Protocol Impersonation"
        },
        {
          "id": "T1505",
          "name": "Server Software Component",
          "display_name": "T1505 - Server Software Component"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 34,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 485,
        "hostname": 551,
        "URL": 1019,
        "FileHash-SHA256": 650,
        "CVE": 5,
        "FileHash-MD5": 425,
        "FileHash-SHA1": 224,
        "FilePath": 2,
        "email": 2
      },
      "indicator_count": 3363,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "939 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "651f177187ed5eba41657bf4",
      "name": "Packed.VMProt/ Packed.VMProtect Apple|  iOS | Mac attack techapply.com",
      "description": "Significantly infected Apple ID. and various devices; spyrixkeylogger, spyware, networm, tracking, beacons, injection, full control iOS and apple devices as well as OS. Appears as investigated. Not a lawful investigated. 5+ year (analysis reveals dated CVE's and malware specially targets individual) of spying, tagging, targeting, cyber criminal, cyber harassment, unlocker, disabled apple IDs. Interface / dummy core, collection, webdisk harvesting, cyber criminal behavior. Possible red teaming. js user, code written for a variety programs/systems, C2, relay router. robots. \ncyber threat.\nhired\ntargeted \nbotnets\nmalware\nAI",
      "modified": "2023-11-04T16:00:22.229000",
      "created": "2023-10-05T20:07:13.805000",
      "tags": [
        "engineering",
        "united",
        "cyber threat",
        "team",
        "malware",
        "telefonica co",
        "heur",
        "malicious site",
        "ip reputation",
        "bambernek pony",
        "zeus",
        "nymaim",
        "facebook",
        "raccoon",
        "download",
        "kronos",
        "ramnit",
        "simda",
        "bank",
        "phishing",
        "citadel",
        "zbot",
        "pykspa",
        "agent",
        "maltiverse",
        "noname057",
        "copyright",
        "reserved",
        "flag",
        "date",
        "name server",
        "markmonitor",
        "server",
        "organization",
        "germany germany",
        "sample",
        "session details",
        "click",
        "misc attack",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "exit node",
        "traffic group",
        "suricata alerts",
        "event category",
        "analysis",
        "malicious url",
        "windows nt",
        "wow64",
        "response",
        "gmt contenttype",
        "gecko host",
        "vary",
        "gmt etag",
        "general gets",
        "script",
        "parking crew",
        "apple",
        "apple id",
        "tsara",
        "tsara brashears",
        "spyware",
        "cyber criminal",
        "cyber stalking",
        "track",
        "track iphone",
        "accept all platforms",
        "infringement",
        "intellectual property",
        "suricata",
        "alert",
        "red team",
        "happywifehappylife",
        "malicious",
        "revenge",
        "posts",
        "post",
        "post to web",
        "post to server",
        "exploit",
        "command_and_control",
        "toggle",
        "logon",
        "login",
        "privilege",
        "ios",
        "attack",
        "mitre",
        "Packed.VMProt",
        "apple engineering",
        "abuse",
        "cve",
        "robots",
        "arizona",
        "bounce",
        "canada",
        "croatia",
        "base64_encoded",
        "%samplepath%",
        "tagging",
        "png image",
        "PSI-USA, Inc. dba Domain Robot Organization",
        "dns",
        "query",
        "evasive",
        "crack",
        "record type",
        "ttl value",
        "dns replication",
        "santa fe",
        "available from",
        "registrar abuse",
        "iana id",
        "domain status",
        "creation date",
        "registrar url",
        "code",
        "dapato",
        "predator",
        "win64",
        "conduit",
        "fakeinstaller",
        "installpack",
        "generic",
        "downloader",
        "spyrixkeylogger",
        "bitminer",
        "loadmoney",
        "filetour",
        "wacatac",
        "fusioncore",
        "cleaner",
        "networm",
        "mediaget",
        "softonic",
        "trojan",
        "encpk",
        "qbot",
        "swrort",
        "kraddare",
        "systweak",
        "iobit",
        "installcore",
        "artemis",
        "riskware",
        "dllinject",
        "driverpack",
        "trojanspy",
        "webtoolbar",
        "cisco umbrella",
        "ip hostname",
        "safe site",
        "site",
        "targeted",
        "AI",
        "dllinject"
      ],
      "references": [
        "Spyware",
        "Parking Crew Spyware",
        "c.parkingcrew.net 185.53.178.30 TTL: 9\tPSI-USA, Inc. dba Domain Robot Organization: Team Internet AG Name Server: NS-1403.AWSDNS-47.ORG",
        "http://service.appleid.apple.online.hqvce.techapply.com/apple/f625bbcc3a59f078ffa95159c719501e/index.php?itunes=_connect-run&secure=5540zef1415405412104ef151511d7f84f5ze1f510eec8bd0e",
        "service.appleid.apple.online.hqvce.techapply.com 76.223.35.103 TTL: 600\tTitanic Hosting, Inc. Name Server: NS1.DNE.COM",
        "d38psrni17bvxu.cloudfront.net 18.239.196.136 TTL: 60\tMarkMonitor, Inc. Organization: Amazon.com, Inc. Name Server: NS-1306.AWSDNS-35.ORG",
        "https://www.hybrid-analysis.com/sample/6450c8bb8cec78135dd4891507099d1407ef1d9af40bc250251eb99888c20f7e/651eda366e1436b384026c6d",
        "wTools",
        "Research and Analysis",
        "go.microsoft.com 184.26.158.64 TTL: 2672\tMarkMonitor, Inc. Organization: Microsoft Corporation Name Server: NS1.MSFT.NET",
        "dllinject"
      ],
      "public": 1,
      "adversary": "Cyber Criminal",
      "targeted_countries": [
        "Argentina",
        "Ireland",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Looquer",
          "display_name": "Looquer",
          "target": null
        },
        {
          "id": "TinyZBot - S0004",
          "display_name": "TinyZBot - S0004",
          "target": null
        },
        {
          "id": "Ramnit",
          "display_name": "Ramnit",
          "target": null
        },
        {
          "id": "Bambernek Pony",
          "display_name": "Bambernek Pony",
          "target": null
        },
        {
          "id": "Ransom:Win32/Nymaim",
          "display_name": "Ransom:Win32/Nymaim",
          "target": "/malware/Ransom:Win32/Nymaim"
        },
        {
          "id": "Backdoor:Win32/Simda",
          "display_name": "Backdoor:Win32/Simda",
          "target": "/malware/Backdoor:Win32/Simda"
        },
        {
          "id": "TrojanSpy:Win32/Kronos",
          "display_name": "TrojanSpy:Win32/Kronos",
          "target": "/malware/TrojanSpy:Win32/Kronos"
        },
        {
          "id": "Trojan:Win32/Raccoonstealer",
          "display_name": "Trojan:Win32/Raccoonstealer",
          "target": "/malware/Trojan:Win32/Raccoonstealer"
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "Spammer:Win32/Noname",
          "display_name": "Spammer:Win32/Noname",
          "target": "/malware/Spammer:Win32/Noname"
        },
        {
          "id": "Worm:Win32/Pykspa",
          "display_name": "Worm:Win32/Pykspa",
          "target": "/malware/Worm:Win32/Pykspa"
        },
        {
          "id": "Banker",
          "display_name": "Banker",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Razy",
          "display_name": "Trojan:MSIL/Razy",
          "target": "/malware/Trojan:MSIL/Razy"
        },
        {
          "id": "Trojan:Win32/Wacatac",
          "display_name": "Trojan:Win32/Wacatac",
          "target": "/malware/Trojan:Win32/Wacatac"
        },
        {
          "id": "ALF:PUA:Win32/IObit",
          "display_name": "ALF:PUA:Win32/IObit",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Kraddare",
          "display_name": "TrojanDownloader:Win32/Kraddare",
          "target": "/malware/TrojanDownloader:Win32/Kraddare"
        },
        {
          "id": "ALF:PUA:Win32/FusionCore",
          "display_name": "ALF:PUA:Win32/FusionCore",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
          "display_name": "ALF:HeraklezEval:PUA:Win32/SpyrixKeylogger",
          "target": null
        },
        {
          "id": "Trojan:Win32/Qbot",
          "display_name": "Trojan:Win32/Qbot",
          "target": "/malware/Trojan:Win32/Qbot"
        },
        {
          "id": "Trojan:Win32/InstallCore",
          "display_name": "Trojan:Win32/InstallCore",
          "target": "/malware/Trojan:Win32/InstallCore"
        },
        {
          "id": "ALF:JASYP:PUAWin32/Systweak",
          "display_name": "ALF:JASYP:PUAWin32/Systweak",
          "target": null
        },
        {
          "id": "Trojan:Win32/Dapato",
          "display_name": "Trojan:Win32/Dapato",
          "target": "/malware/Trojan:Win32/Dapato"
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1132.001",
          "name": "Standard Encoding",
          "display_name": "T1132.001 - Standard Encoding"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "TA0037",
          "name": "Command and Control",
          "display_name": "TA0037 - Command and Control"
        },
        {
          "id": "T1070.003",
          "name": "Clear Command History",
          "display_name": "T1070.003 - Clear Command History"
        },
        {
          "id": "T1001.003",
          "name": "Protocol Impersonation",
          "display_name": "T1001.003 - Protocol Impersonation"
        },
        {
          "id": "T1505",
          "name": "Server Software Component",
          "display_name": "T1505 - Server Software Component"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 37,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 485,
        "hostname": 551,
        "URL": 1019,
        "FileHash-SHA256": 650,
        "CVE": 5,
        "FileHash-MD5": 425,
        "FileHash-SHA1": 224,
        "FilePath": 2,
        "email": 2
      },
      "indicator_count": 3363,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "939 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "kernelfire.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "kernelfire.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780277320.5770903
}