{
  "type": "Domain",
  "indicator": "ktotv.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/ktotv.com",
    "alexa": "http://www.alexa.com/siteinfo/ktotv.com",
    "indicator": "ktotv.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3909584296,
      "indicator": "ktotv.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "69a02837827feb0b78fa3ad2",
          "name": "The Belasco Chain",
          "description": "The adversary delivers a masterclass in \"Regular Belasco\" stagecraft, utilizing authentic Adobe PIDs to construct a \"living library\" of legitimacy where mundane metadata like SOPHIA.json acts as Gatsby\u2019s \"real but uncut\" volumes to mask a hollowed-out interior. This is a triumph of performative evasion; while researchers marvel at the realism of the set-dressing, MSI50B8.tmp and MSI4F2F.tmp wait in the wings of the Windows\\Installer directory, invisible to the human eye and using NGEN hijacking to bake illicit scripts directly into the OS framework. By employing Cryptnet certificates as \"stage lighting\" to mask C2 handshakes, the malware doesn't just attend the system\u2019s party\u2014it rewrites the invitation to own the house. Unlike the tragic end at West Egg, this Belasco chain is a play that refuses to end; it simply resets the stage, ensuring the performance continues as long as the \"green light\" of the C2 remains active.",
          "modified": "2026-05-31T01:02:14",
          "created": "2026-02-26T11:02:15.932000",
          "tags": [
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "file type",
            "sha1",
            "sha256",
            "crc32",
            "filenames c"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2813,
            "FileHash-SHA1": 2576,
            "FileHash-SHA256": 8145,
            "domain": 1903,
            "hostname": 1502,
            "URL": 1359,
            "email": 46,
            "CVE": 54,
            "CIDR": 3,
            "YARA": 7,
            "JA3": 1,
            "IPv4": 11
          },
          "indicator_count": 18420,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 74,
          "modified_text": "4 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a03cc521e13c5d6d34555d0",
          "name": "Judgement Day. VirusTotal report                    for index.html",
          "description": "[Apple.com has sent a series of \"fl flushMessages\" to its servers, but what exactly is the data and what is it going to get out of the system and how does it feel?]",
          "modified": "2026-05-15T10:22:00.139000",
          "created": "2026-05-13T00:56:50.182000",
          "tags": [
            "darwin kernel",
            "version",
            "wed feb",
            "apfs4kobjs",
            "instagram",
            "mosaic",
            "free",
            "get http",
            "dns resolutions",
            "ip traffic",
            "pattern domains",
            "memory pattern",
            "urls https",
            "tls sni",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr13",
            "validity",
            "subject public",
            "key info",
            "performs dns",
            "https",
            "urls",
            "united",
            "mitre attack",
            "network info",
            "processes extra",
            "t1055 process",
            "layer protocol",
            "overview",
            "phishing",
            "defense evasion",
            "next",
            "default",
            "parent pid",
            "full path",
            "command line",
            "k netsvcs",
            "k localservice",
            "s w32time",
            "event provider",
            "device",
            "registry keys"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 132,
            "FileHash-MD5": 43,
            "FileHash-SHA1": 6,
            "hostname": 364,
            "IPv4": 75,
            "URL": 574,
            "Mutex": 1,
            "FileHash-SHA256": 404
          },
          "indicator_count": 1599,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "15 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66762a4ccb10185d774ddbde",
          "name": "Lazarus Group - Emotet | Sony Music",
          "description": "Is the Lazarus Group still attacking Sony Music, affiliated, former, contacts, aspiring prospects and independent artists?\n\nA Denver Studio owner had former Sony leadership role was fully infected with Pegasus, Mirai and  a Lazarus Group affiliation seen. An independent Denver publishing company and artists were greatly targeted and continue to be. A songwriter known to have recorded at Denver Studio had songs pirated. Tori Kelly and Justin Bieber recorded over chops copy written by artist. Strangely legally affiliated. A rumor suggests Lazarus group & Anonymous are hacker made up of government employees, police officers, attorneys and PI's. The government affiliated IP's are give rumors some weight. Hackers will hack anything, \nMost popular beliefs are artist was targeted and therefore the studio where she target worked from often. Denver Studio report scrubbed by HistoryKillerPro & other Unknown Stealers.",
          "modified": "2024-07-22T01:04:09.406000",
          "created": "2024-06-22T01:35:08.834000",
          "tags": [
            "url https",
            "url http",
            "active related",
            "pulses hostname",
            "ipv4",
            "showing",
            "entries",
            "active",
            "passive dns",
            "as2527 sony",
            "all scoreblue",
            "pulse pulses",
            "urls",
            "files",
            "reverse dns",
            "location chiba",
            "united",
            "unknown",
            "date",
            "moved",
            "search",
            "gmt content",
            "domain",
            "body",
            "encrypt",
            "as58061 scalaxy",
            "asn as58061",
            "dns resolutions",
            "expiration",
            "no expiration",
            "hostname",
            "iocs",
            "filehashsha256",
            "scan endpoints",
            "next",
            "report spam",
            "lazarus created",
            "minutes ago",
            "amber tags",
            "filehashsha1",
            "group",
            "tip oriented",
            "threat research",
            "android10",
            "type indicator",
            "role title",
            "creation date",
            "emails",
            "pulse submit",
            "url analysis",
            "germany unknown",
            "aaaa",
            "cname",
            "as209453 gandi",
            "as209453",
            "france unknown",
            "ireland unknown",
            "susp",
            "backdoor",
            "win32",
            "meta",
            "cookie",
            "pragma",
            "open ports",
            "as20940",
            "status",
            "certificate",
            "rsa sha256",
            "record value",
            "historical ssl",
            "referrer",
            "collection",
            "vt graph",
            "glaxosmithkline",
            "cyber threat",
            "heur",
            "phishing",
            "team",
            "malicious site",
            "control server",
            "coalition",
            "team phishing",
            "engineering",
            "emotet",
            "malware",
            "malicious",
            "download",
            "cobalt strike",
            "binder",
            "dropper",
            "formbook",
            "facebook",
            "artemis",
            "azorult",
            "bank",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "hostnames",
            "detection list",
            "blacklist",
            "a domains",
            "bitdefender",
            "leader",
            "as15133 verizon",
            "melbourne it",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers date",
            "gmt contenttype",
            "connection",
            "ip address",
            "web redirection",
            "sha1",
            "ascii text",
            "sha256",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "pattern match",
            "hybrid",
            "starfield",
            "format",
            "june",
            "local",
            "click",
            "strings",
            "contact",
            "loki"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
            "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
            "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
            "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
            "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
            "Server: Web redirection - http://loki.com/download",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
          ],
          "public": 1,
          "adversary": "Lazarus Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Win.Trojan.DarkKomet-1",
              "display_name": "Win.Trojan.DarkKomet-1",
              "target": null
            },
            {
              "id": "VirTool:Win32/CeeInject",
              "display_name": "VirTool:Win32/CeeInject",
              "target": "/malware/VirTool:Win32/CeeInject"
            },
            {
              "id": "Backdoor:MSIL/Bladabindi",
              "display_name": "Backdoor:MSIL/Bladabindi",
              "target": "/malware/Backdoor:MSIL/Bladabindi"
            },
            {
              "id": "Win32:Evo-gen",
              "display_name": "Win32:Evo-gen",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Susp]",
              "display_name": "Win32:Evo-gen\\ [Susp]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [
            "Entertainment",
            "Technology",
            "Media"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 50,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3528,
            "domain": 1453,
            "hostname": 1542,
            "FileHash-SHA256": 757,
            "FileHash-SHA1": 66,
            "FileHash-MD5": 79,
            "email": 5,
            "CVE": 4,
            "SSLCertFingerprint": 14
          },
          "indicator_count": 7448,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 234,
          "modified_text": "678 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "667648f0bc130bdaa294ea19",
          "name": "Sony Music | Emotet  - Lazarus Affiliated",
          "description": "",
          "modified": "2024-07-22T01:04:09.406000",
          "created": "2024-06-22T03:45:52.401000",
          "tags": [
            "url https",
            "url http",
            "active related",
            "pulses hostname",
            "ipv4",
            "showing",
            "entries",
            "active",
            "passive dns",
            "as2527 sony",
            "all scoreblue",
            "pulse pulses",
            "urls",
            "files",
            "reverse dns",
            "location chiba",
            "united",
            "unknown",
            "date",
            "moved",
            "search",
            "gmt content",
            "domain",
            "body",
            "encrypt",
            "as58061 scalaxy",
            "asn as58061",
            "dns resolutions",
            "expiration",
            "no expiration",
            "hostname",
            "iocs",
            "filehashsha256",
            "scan endpoints",
            "next",
            "report spam",
            "lazarus created",
            "minutes ago",
            "amber tags",
            "filehashsha1",
            "group",
            "tip oriented",
            "threat research",
            "android10",
            "type indicator",
            "role title",
            "creation date",
            "emails",
            "pulse submit",
            "url analysis",
            "germany unknown",
            "aaaa",
            "cname",
            "as209453 gandi",
            "as209453",
            "france unknown",
            "ireland unknown",
            "susp",
            "backdoor",
            "win32",
            "meta",
            "cookie",
            "pragma",
            "open ports",
            "as20940",
            "status",
            "certificate",
            "rsa sha256",
            "record value",
            "historical ssl",
            "referrer",
            "collection",
            "vt graph",
            "glaxosmithkline",
            "cyber threat",
            "heur",
            "phishing",
            "team",
            "malicious site",
            "control server",
            "coalition",
            "team phishing",
            "engineering",
            "emotet",
            "malware",
            "malicious",
            "download",
            "cobalt strike",
            "binder",
            "dropper",
            "formbook",
            "facebook",
            "artemis",
            "azorult",
            "bank",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "hostnames",
            "detection list",
            "blacklist",
            "a domains",
            "bitdefender",
            "leader",
            "as15133 verizon",
            "melbourne it",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers date",
            "gmt contenttype",
            "connection",
            "ip address",
            "web redirection",
            "sha1",
            "ascii text",
            "sha256",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "pattern match",
            "hybrid",
            "starfield",
            "format",
            "june",
            "local",
            "click",
            "strings",
            "contact",
            "loki"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
            "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
            "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
            "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
            "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
            "Server: Web redirection - http://loki.com/download",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
          ],
          "public": 1,
          "adversary": "Lazarus Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Win.Trojan.DarkKomet-1",
              "display_name": "Win.Trojan.DarkKomet-1",
              "target": null
            },
            {
              "id": "VirTool:Win32/CeeInject",
              "display_name": "VirTool:Win32/CeeInject",
              "target": "/malware/VirTool:Win32/CeeInject"
            },
            {
              "id": "Backdoor:MSIL/Bladabindi",
              "display_name": "Backdoor:MSIL/Bladabindi",
              "target": "/malware/Backdoor:MSIL/Bladabindi"
            },
            {
              "id": "Win32:Evo-gen",
              "display_name": "Win32:Evo-gen",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Susp]",
              "display_name": "Win32:Evo-gen\\ [Susp]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [
            "Entertainment",
            "Technology",
            "Media"
          ],
          "TLP": "green",
          "cloned_from": "66762a4ccb10185d774ddbde",
          "export_count": 47,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3528,
            "domain": 1453,
            "hostname": 1542,
            "FileHash-SHA256": 757,
            "FileHash-SHA1": 66,
            "FileHash-MD5": 79,
            "email": 5,
            "CVE": 4,
            "SSLCertFingerprint": 14
          },
          "indicator_count": 7448,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 232,
          "modified_text": "678 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6681f340f8c0223ae0ce199d",
          "name": "Bitdefender Ransomware| | Sony Music |  Lazarus Affiliated",
          "description": "",
          "modified": "2024-07-22T01:04:09.406000",
          "created": "2024-07-01T00:07:28.402000",
          "tags": [
            "url https",
            "url http",
            "active related",
            "pulses hostname",
            "ipv4",
            "showing",
            "entries",
            "active",
            "passive dns",
            "as2527 sony",
            "all scoreblue",
            "pulse pulses",
            "urls",
            "files",
            "reverse dns",
            "location chiba",
            "united",
            "unknown",
            "date",
            "moved",
            "search",
            "gmt content",
            "domain",
            "body",
            "encrypt",
            "as58061 scalaxy",
            "asn as58061",
            "dns resolutions",
            "expiration",
            "no expiration",
            "hostname",
            "iocs",
            "filehashsha256",
            "scan endpoints",
            "next",
            "report spam",
            "lazarus created",
            "minutes ago",
            "amber tags",
            "filehashsha1",
            "group",
            "tip oriented",
            "threat research",
            "android10",
            "type indicator",
            "role title",
            "creation date",
            "emails",
            "pulse submit",
            "url analysis",
            "germany unknown",
            "aaaa",
            "cname",
            "as209453 gandi",
            "as209453",
            "france unknown",
            "ireland unknown",
            "susp",
            "backdoor",
            "win32",
            "meta",
            "cookie",
            "pragma",
            "open ports",
            "as20940",
            "status",
            "certificate",
            "rsa sha256",
            "record value",
            "historical ssl",
            "referrer",
            "collection",
            "vt graph",
            "glaxosmithkline",
            "cyber threat",
            "heur",
            "phishing",
            "team",
            "malicious site",
            "control server",
            "coalition",
            "team phishing",
            "engineering",
            "emotet",
            "malware",
            "malicious",
            "download",
            "cobalt strike",
            "binder",
            "dropper",
            "formbook",
            "facebook",
            "artemis",
            "azorult",
            "bank",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "hostnames",
            "detection list",
            "blacklist",
            "a domains",
            "bitdefender",
            "leader",
            "as15133 verizon",
            "melbourne it",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers date",
            "gmt contenttype",
            "connection",
            "ip address",
            "web redirection",
            "sha1",
            "ascii text",
            "sha256",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "pattern match",
            "hybrid",
            "starfield",
            "format",
            "june",
            "local",
            "click",
            "strings",
            "contact",
            "loki"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
            "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
            "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
            "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
            "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
            "Server: Web redirection - http://loki.com/download",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
            "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
          ],
          "public": 1,
          "adversary": "Lazarus Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Win.Trojan.DarkKomet-1",
              "display_name": "Win.Trojan.DarkKomet-1",
              "target": null
            },
            {
              "id": "VirTool:Win32/CeeInject",
              "display_name": "VirTool:Win32/CeeInject",
              "target": "/malware/VirTool:Win32/CeeInject"
            },
            {
              "id": "Backdoor:MSIL/Bladabindi",
              "display_name": "Backdoor:MSIL/Bladabindi",
              "target": "/malware/Backdoor:MSIL/Bladabindi"
            },
            {
              "id": "Win32:Evo-gen",
              "display_name": "Win32:Evo-gen",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Susp]",
              "display_name": "Win32:Evo-gen\\ [Susp]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [
            "Entertainment",
            "Technology",
            "Media"
          ],
          "TLP": "green",
          "cloned_from": "667648f0bc130bdaa294ea19",
          "export_count": 6847,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3528,
            "domain": 1453,
            "hostname": 1542,
            "FileHash-SHA256": 757,
            "FileHash-SHA1": 66,
            "FileHash-MD5": 79,
            "email": 5,
            "CVE": 4,
            "SSLCertFingerprint": 14
          },
          "indicator_count": 7448,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "678 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
        "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
        "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
        "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
        "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
        "Server: Web redirection - http://loki.com/download"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Lazarus Group"
          ],
          "malware_families": [
            "Win32:evo-gen\\ [susp]",
            "Mirai",
            "Backdoor:msil/bladabindi",
            "Virtool:win32/ceeinject",
            "Win32:evo-gen",
            "Win.trojan.darkkomet-1"
          ],
          "industries": [
            "Entertainment",
            "Technology",
            "Media"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "69a02837827feb0b78fa3ad2",
      "name": "The Belasco Chain",
      "description": "The adversary delivers a masterclass in \"Regular Belasco\" stagecraft, utilizing authentic Adobe PIDs to construct a \"living library\" of legitimacy where mundane metadata like SOPHIA.json acts as Gatsby\u2019s \"real but uncut\" volumes to mask a hollowed-out interior. This is a triumph of performative evasion; while researchers marvel at the realism of the set-dressing, MSI50B8.tmp and MSI4F2F.tmp wait in the wings of the Windows\\Installer directory, invisible to the human eye and using NGEN hijacking to bake illicit scripts directly into the OS framework. By employing Cryptnet certificates as \"stage lighting\" to mask C2 handshakes, the malware doesn't just attend the system\u2019s party\u2014it rewrites the invitation to own the house. Unlike the tragic end at West Egg, this Belasco chain is a play that refuses to end; it simply resets the stage, ensuring the performance continues as long as the \"green light\" of the C2 remains active.",
      "modified": "2026-05-31T01:02:14",
      "created": "2026-02-26T11:02:15.932000",
      "tags": [
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "file type",
        "sha1",
        "sha256",
        "crc32",
        "filenames c"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2813,
        "FileHash-SHA1": 2576,
        "FileHash-SHA256": 8145,
        "domain": 1903,
        "hostname": 1502,
        "URL": 1359,
        "email": 46,
        "CVE": 54,
        "CIDR": 3,
        "YARA": 7,
        "JA3": 1,
        "IPv4": 11
      },
      "indicator_count": 18420,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 74,
      "modified_text": "4 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a03cc521e13c5d6d34555d0",
      "name": "Judgement Day. VirusTotal report                    for index.html",
      "description": "[Apple.com has sent a series of \"fl flushMessages\" to its servers, but what exactly is the data and what is it going to get out of the system and how does it feel?]",
      "modified": "2026-05-15T10:22:00.139000",
      "created": "2026-05-13T00:56:50.182000",
      "tags": [
        "darwin kernel",
        "version",
        "wed feb",
        "apfs4kobjs",
        "instagram",
        "mosaic",
        "free",
        "get http",
        "dns resolutions",
        "ip traffic",
        "pattern domains",
        "memory pattern",
        "urls https",
        "tls sni",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr13",
        "validity",
        "subject public",
        "key info",
        "performs dns",
        "https",
        "urls",
        "united",
        "mitre attack",
        "network info",
        "processes extra",
        "t1055 process",
        "layer protocol",
        "overview",
        "phishing",
        "defense evasion",
        "next",
        "default",
        "parent pid",
        "full path",
        "command line",
        "k netsvcs",
        "k localservice",
        "s w32time",
        "event provider",
        "device",
        "registry keys"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 132,
        "FileHash-MD5": 43,
        "FileHash-SHA1": 6,
        "hostname": 364,
        "IPv4": 75,
        "URL": 574,
        "Mutex": 1,
        "FileHash-SHA256": 404
      },
      "indicator_count": 1599,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "15 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66762a4ccb10185d774ddbde",
      "name": "Lazarus Group - Emotet | Sony Music",
      "description": "Is the Lazarus Group still attacking Sony Music, affiliated, former, contacts, aspiring prospects and independent artists?\n\nA Denver Studio owner had former Sony leadership role was fully infected with Pegasus, Mirai and  a Lazarus Group affiliation seen. An independent Denver publishing company and artists were greatly targeted and continue to be. A songwriter known to have recorded at Denver Studio had songs pirated. Tori Kelly and Justin Bieber recorded over chops copy written by artist. Strangely legally affiliated. A rumor suggests Lazarus group & Anonymous are hacker made up of government employees, police officers, attorneys and PI's. The government affiliated IP's are give rumors some weight. Hackers will hack anything, \nMost popular beliefs are artist was targeted and therefore the studio where she target worked from often. Denver Studio report scrubbed by HistoryKillerPro & other Unknown Stealers.",
      "modified": "2024-07-22T01:04:09.406000",
      "created": "2024-06-22T01:35:08.834000",
      "tags": [
        "url https",
        "url http",
        "active related",
        "pulses hostname",
        "ipv4",
        "showing",
        "entries",
        "active",
        "passive dns",
        "as2527 sony",
        "all scoreblue",
        "pulse pulses",
        "urls",
        "files",
        "reverse dns",
        "location chiba",
        "united",
        "unknown",
        "date",
        "moved",
        "search",
        "gmt content",
        "domain",
        "body",
        "encrypt",
        "as58061 scalaxy",
        "asn as58061",
        "dns resolutions",
        "expiration",
        "no expiration",
        "hostname",
        "iocs",
        "filehashsha256",
        "scan endpoints",
        "next",
        "report spam",
        "lazarus created",
        "minutes ago",
        "amber tags",
        "filehashsha1",
        "group",
        "tip oriented",
        "threat research",
        "android10",
        "type indicator",
        "role title",
        "creation date",
        "emails",
        "pulse submit",
        "url analysis",
        "germany unknown",
        "aaaa",
        "cname",
        "as209453 gandi",
        "as209453",
        "france unknown",
        "ireland unknown",
        "susp",
        "backdoor",
        "win32",
        "meta",
        "cookie",
        "pragma",
        "open ports",
        "as20940",
        "status",
        "certificate",
        "rsa sha256",
        "record value",
        "historical ssl",
        "referrer",
        "collection",
        "vt graph",
        "glaxosmithkline",
        "cyber threat",
        "heur",
        "phishing",
        "team",
        "malicious site",
        "control server",
        "coalition",
        "team phishing",
        "engineering",
        "emotet",
        "malware",
        "malicious",
        "download",
        "cobalt strike",
        "binder",
        "dropper",
        "formbook",
        "facebook",
        "artemis",
        "azorult",
        "bank",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "hostnames",
        "detection list",
        "blacklist",
        "a domains",
        "bitdefender",
        "leader",
        "as15133 verizon",
        "melbourne it",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "headers date",
        "gmt contenttype",
        "connection",
        "ip address",
        "web redirection",
        "sha1",
        "ascii text",
        "sha256",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "pattern match",
        "hybrid",
        "starfield",
        "format",
        "june",
        "local",
        "click",
        "strings",
        "contact",
        "loki"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
        "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
        "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
        "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
        "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
        "Server: Web redirection - http://loki.com/download",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
      ],
      "public": 1,
      "adversary": "Lazarus Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Win.Trojan.DarkKomet-1",
          "display_name": "Win.Trojan.DarkKomet-1",
          "target": null
        },
        {
          "id": "VirTool:Win32/CeeInject",
          "display_name": "VirTool:Win32/CeeInject",
          "target": "/malware/VirTool:Win32/CeeInject"
        },
        {
          "id": "Backdoor:MSIL/Bladabindi",
          "display_name": "Backdoor:MSIL/Bladabindi",
          "target": "/malware/Backdoor:MSIL/Bladabindi"
        },
        {
          "id": "Win32:Evo-gen",
          "display_name": "Win32:Evo-gen",
          "target": null
        },
        {
          "id": "Win32:Evo-gen\\ [Susp]",
          "display_name": "Win32:Evo-gen\\ [Susp]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [
        "Entertainment",
        "Technology",
        "Media"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 50,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3528,
        "domain": 1453,
        "hostname": 1542,
        "FileHash-SHA256": 757,
        "FileHash-SHA1": 66,
        "FileHash-MD5": 79,
        "email": 5,
        "CVE": 4,
        "SSLCertFingerprint": 14
      },
      "indicator_count": 7448,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 234,
      "modified_text": "678 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "667648f0bc130bdaa294ea19",
      "name": "Sony Music | Emotet  - Lazarus Affiliated",
      "description": "",
      "modified": "2024-07-22T01:04:09.406000",
      "created": "2024-06-22T03:45:52.401000",
      "tags": [
        "url https",
        "url http",
        "active related",
        "pulses hostname",
        "ipv4",
        "showing",
        "entries",
        "active",
        "passive dns",
        "as2527 sony",
        "all scoreblue",
        "pulse pulses",
        "urls",
        "files",
        "reverse dns",
        "location chiba",
        "united",
        "unknown",
        "date",
        "moved",
        "search",
        "gmt content",
        "domain",
        "body",
        "encrypt",
        "as58061 scalaxy",
        "asn as58061",
        "dns resolutions",
        "expiration",
        "no expiration",
        "hostname",
        "iocs",
        "filehashsha256",
        "scan endpoints",
        "next",
        "report spam",
        "lazarus created",
        "minutes ago",
        "amber tags",
        "filehashsha1",
        "group",
        "tip oriented",
        "threat research",
        "android10",
        "type indicator",
        "role title",
        "creation date",
        "emails",
        "pulse submit",
        "url analysis",
        "germany unknown",
        "aaaa",
        "cname",
        "as209453 gandi",
        "as209453",
        "france unknown",
        "ireland unknown",
        "susp",
        "backdoor",
        "win32",
        "meta",
        "cookie",
        "pragma",
        "open ports",
        "as20940",
        "status",
        "certificate",
        "rsa sha256",
        "record value",
        "historical ssl",
        "referrer",
        "collection",
        "vt graph",
        "glaxosmithkline",
        "cyber threat",
        "heur",
        "phishing",
        "team",
        "malicious site",
        "control server",
        "coalition",
        "team phishing",
        "engineering",
        "emotet",
        "malware",
        "malicious",
        "download",
        "cobalt strike",
        "binder",
        "dropper",
        "formbook",
        "facebook",
        "artemis",
        "azorult",
        "bank",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "hostnames",
        "detection list",
        "blacklist",
        "a domains",
        "bitdefender",
        "leader",
        "as15133 verizon",
        "melbourne it",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "headers date",
        "gmt contenttype",
        "connection",
        "ip address",
        "web redirection",
        "sha1",
        "ascii text",
        "sha256",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "pattern match",
        "hybrid",
        "starfield",
        "format",
        "june",
        "local",
        "click",
        "strings",
        "contact",
        "loki"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
        "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
        "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
        "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
        "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
        "Server: Web redirection - http://loki.com/download",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
      ],
      "public": 1,
      "adversary": "Lazarus Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Win.Trojan.DarkKomet-1",
          "display_name": "Win.Trojan.DarkKomet-1",
          "target": null
        },
        {
          "id": "VirTool:Win32/CeeInject",
          "display_name": "VirTool:Win32/CeeInject",
          "target": "/malware/VirTool:Win32/CeeInject"
        },
        {
          "id": "Backdoor:MSIL/Bladabindi",
          "display_name": "Backdoor:MSIL/Bladabindi",
          "target": "/malware/Backdoor:MSIL/Bladabindi"
        },
        {
          "id": "Win32:Evo-gen",
          "display_name": "Win32:Evo-gen",
          "target": null
        },
        {
          "id": "Win32:Evo-gen\\ [Susp]",
          "display_name": "Win32:Evo-gen\\ [Susp]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [
        "Entertainment",
        "Technology",
        "Media"
      ],
      "TLP": "green",
      "cloned_from": "66762a4ccb10185d774ddbde",
      "export_count": 47,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3528,
        "domain": 1453,
        "hostname": 1542,
        "FileHash-SHA256": 757,
        "FileHash-SHA1": 66,
        "FileHash-MD5": 79,
        "email": 5,
        "CVE": 4,
        "SSLCertFingerprint": 14
      },
      "indicator_count": 7448,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 232,
      "modified_text": "678 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6681f340f8c0223ae0ce199d",
      "name": "Bitdefender Ransomware| | Sony Music |  Lazarus Affiliated",
      "description": "",
      "modified": "2024-07-22T01:04:09.406000",
      "created": "2024-07-01T00:07:28.402000",
      "tags": [
        "url https",
        "url http",
        "active related",
        "pulses hostname",
        "ipv4",
        "showing",
        "entries",
        "active",
        "passive dns",
        "as2527 sony",
        "all scoreblue",
        "pulse pulses",
        "urls",
        "files",
        "reverse dns",
        "location chiba",
        "united",
        "unknown",
        "date",
        "moved",
        "search",
        "gmt content",
        "domain",
        "body",
        "encrypt",
        "as58061 scalaxy",
        "asn as58061",
        "dns resolutions",
        "expiration",
        "no expiration",
        "hostname",
        "iocs",
        "filehashsha256",
        "scan endpoints",
        "next",
        "report spam",
        "lazarus created",
        "minutes ago",
        "amber tags",
        "filehashsha1",
        "group",
        "tip oriented",
        "threat research",
        "android10",
        "type indicator",
        "role title",
        "creation date",
        "emails",
        "pulse submit",
        "url analysis",
        "germany unknown",
        "aaaa",
        "cname",
        "as209453 gandi",
        "as209453",
        "france unknown",
        "ireland unknown",
        "susp",
        "backdoor",
        "win32",
        "meta",
        "cookie",
        "pragma",
        "open ports",
        "as20940",
        "status",
        "certificate",
        "rsa sha256",
        "record value",
        "historical ssl",
        "referrer",
        "collection",
        "vt graph",
        "glaxosmithkline",
        "cyber threat",
        "heur",
        "phishing",
        "team",
        "malicious site",
        "control server",
        "coalition",
        "team phishing",
        "engineering",
        "emotet",
        "malware",
        "malicious",
        "download",
        "cobalt strike",
        "binder",
        "dropper",
        "formbook",
        "facebook",
        "artemis",
        "azorult",
        "bank",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "hostnames",
        "detection list",
        "blacklist",
        "a domains",
        "bitdefender",
        "leader",
        "as15133 verizon",
        "melbourne it",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "headers date",
        "gmt contenttype",
        "connection",
        "ip address",
        "web redirection",
        "sha1",
        "ascii text",
        "sha256",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "pattern match",
        "hybrid",
        "starfield",
        "format",
        "june",
        "local",
        "click",
        "strings",
        "contact",
        "loki"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/url/http://accounts-upadates-informations-services-login-customer-id.marketingplus1.com/itunes",
        "Relationship: Louisiana Cyber Investigators Alliance (LCIA)",
        "https://otx.alienvault.com/indicator/url/http://dashboard.loki.com/files/LokiApplet.jar",
        "Ransomware: https://www.bitdefender.com.au/blog/businessinsights/hive-ransomwares-offspring-hunters-international-takes-the-stage",
        "Emotet: IPv4 104.18.41.100 | IPv4 104.18.45.108",
        "Server: Web redirection - http://loki.com/download",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: https://forms.sonymusicfans.com/campaign/jazmine-sullivan-heaux-tails-pre-save/",
        "Phishing: http://forms.sonymusicfans.com/campaign/old-dominion-newsletter-sign-up/?ss=0"
      ],
      "public": 1,
      "adversary": "Lazarus Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Win.Trojan.DarkKomet-1",
          "display_name": "Win.Trojan.DarkKomet-1",
          "target": null
        },
        {
          "id": "VirTool:Win32/CeeInject",
          "display_name": "VirTool:Win32/CeeInject",
          "target": "/malware/VirTool:Win32/CeeInject"
        },
        {
          "id": "Backdoor:MSIL/Bladabindi",
          "display_name": "Backdoor:MSIL/Bladabindi",
          "target": "/malware/Backdoor:MSIL/Bladabindi"
        },
        {
          "id": "Win32:Evo-gen",
          "display_name": "Win32:Evo-gen",
          "target": null
        },
        {
          "id": "Win32:Evo-gen\\ [Susp]",
          "display_name": "Win32:Evo-gen\\ [Susp]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [
        "Entertainment",
        "Technology",
        "Media"
      ],
      "TLP": "green",
      "cloned_from": "667648f0bc130bdaa294ea19",
      "export_count": 6847,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3528,
        "domain": 1453,
        "hostname": 1542,
        "FileHash-SHA256": 757,
        "FileHash-SHA1": 66,
        "FileHash-MD5": 79,
        "email": 5,
        "CVE": 4,
        "SSLCertFingerprint": 14
      },
      "indicator_count": 7448,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "678 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "ktotv.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "ktotv.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780204390.4844148
}