{
  "type": "Domain",
  "indicator": "lysynun.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/lysynun.com",
    "alexa": "http://www.alexa.com/siteinfo/lysynun.com",
    "indicator": "lysynun.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 144247530,
      "indicator": "lysynun.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "688c8526be7a4df33863b5c5",
          "name": "VirusTotal - Shiz.ivr",
          "description": "*Win.Trojan.Shiz.ivr\n*PWS:Win32/Simda.D\n*virtool #injection#infostealer #network #cnc #block_not #virustotal_google #cnc #checking #procmem_yara\n#injection_inter_process\n#injection_create_remote_thread\n#antidebug_windows\n#multiple_useragents\n#network_fake_useragent\n#persistence_autorun\n#cape_detected_threat\n#antiav_detectfile\n#modify_proxy\n#deletes_self\n#infostealer_cookies\n#injection_createremotethread\n#suricata_alert\n~ vashti",
          "modified": "2025-08-31T08:01:04.297000",
          "created": "2025-08-01T09:13:10.510000",
          "tags": [
            "dynamicloader",
            "unknown",
            "msie",
            "windows nt",
            "slcc2",
            "media center",
            "suspicious",
            "search",
            "high",
            "show",
            "copy",
            "possible",
            "write",
            "internal",
            "malware",
            "push",
            "local",
            "next",
            "contacted",
            "domains",
            "pulses",
            "related tags",
            "file type",
            "date april",
            "pm size",
            "sha1 sha256",
            "imphash pehash",
            "virustotal api",
            "bq jul",
            "united",
            "trojan",
            "backdoor",
            "virtool",
            "cnc beacon",
            "entries",
            "path max",
            "passive dns",
            "next associated",
            "cookie",
            "twitter",
            "body",
            "date",
            "medium",
            "simda",
            "global"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 10303,
            "hostname": 1413,
            "FileHash-SHA256": 1868,
            "domain": 1877,
            "FileHash-MD5": 357,
            "FileHash-SHA1": 348,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 16168,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 149,
          "modified_text": "273 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6786a59af06fee17c8decf9d",
          "name": "netcfg",
          "description": "000ceafd276003f46d06828bb0459b3ccdc2b44013a313b69d6270a224199034",
          "modified": "2025-05-31T02:36:52.299000",
          "created": "2025-01-14T17:57:46.687000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 222,
            "domain": 216,
            "hostname": 4,
            "FileHash-SHA256": 1
          },
          "indicator_count": 443,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "365 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a4293d5bc5c915eac829e0",
          "name": "Ransom:Win32/Crowti.A : Android Windows | Win.Trojan.Simda CnC",
          "description": "",
          "modified": "2024-08-25T21:00:52.039000",
          "created": "2024-07-26T22:54:53.598000",
          "tags": [
            "united",
            "unknown",
            "a domains",
            "accept",
            "link",
            "passive dns",
            "encrypt",
            "trmp",
            "ok server",
            "date",
            "meta",
            "whois lookup",
            "create date",
            "domain",
            "expiry date",
            "update date",
            "update",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr10",
            "validity",
            "public key",
            "info",
            "key algorithm",
            "dns replication",
            "subdomains",
            "first",
            "historical ssl",
            "record type",
            "ttl value",
            "cname",
            "certificates",
            "show",
            "entries",
            "yara rule",
            "delete",
            "search",
            "intel",
            "ms windows",
            "copy",
            "binary file",
            "get updates",
            "write",
            "as44273 host",
            "redacted for",
            "moved",
            "record value",
            "as54113",
            "body",
            "scan endpoints",
            "all scoreblue",
            "pulse submit",
            "url analysis",
            "urls",
            "files",
            "ip address",
            "files ip",
            "address domain",
            "as61969 team",
            "germany unknown",
            "msie",
            "chrome",
            "precondition",
            "gmt content",
            "united kingdom",
            "as396982 google",
            "as8075",
            "ireland unknown",
            "as21301",
            "aaaa",
            "status",
            "sha1",
            "windows nt",
            "sha256",
            "size",
            "ascii text",
            "pattern match",
            "mitre att",
            "ck id",
            "show technique",
            "span",
            "format",
            "click",
            "hybrid",
            "twitter",
            "generator",
            "tsvt",
            "strings",
            "download",
            "path",
            "contact",
            "suspicious",
            "invalid url",
            "open ports",
            "body html",
            "head title",
            "title head",
            "body h1",
            "reference",
            "bad request",
            "server",
            "version",
            "trojandropper",
            "ransom",
            "checkin",
            "ipv4",
            "trojan",
            "virtool",
            "http post",
            "theme directory",
            "without referer",
            "cycbot",
            "http response",
            "final url",
            "status code",
            "body length",
            "kb body",
            "headers server",
            "gmt etag",
            "gmt date",
            "referrer",
            "code signing",
            "serial number",
            "ca valid",
            "from",
            "valid",
            "valid usage",
            "verisign time",
            "stamping",
            "thumbprint",
            "class",
            "error",
            "info header",
            "name md5",
            "type",
            "language",
            "contained",
            "overlay",
            "gandi sas",
            "dynadot",
            "registrar",
            "dynadot inc",
            "cloudflare",
            "net technology",
            "corporation",
            "bigrock",
            "dynadot llc",
            "namecheap",
            "ip detections",
            "country",
            "contacted",
            "defense evasion",
            "access ta0006",
            "ta0009 command",
            "control ta0011",
            "impact ta0034",
            "impact ta0040",
            "ta0040",
            "samplepath",
            "pattern urls",
            "pattern domains",
            "memory pattern",
            "domains domain",
            "ip traffic",
            "typo squatting",
            "realteck audio",
            "phish",
            "mr windows",
            "partru",
            "goog mal",
            "android windows",
            "maze",
            "apple",
            "malware",
            "worm",
            "skynet",
            "microsoft",
            "trojan evader",
            "simda cnc",
            "showing",
            "filehash",
            "pulse pulses",
            "av detections",
            "ids detections",
            "delphi",
            "network",
            "crowdstrike"
          ],
          "references": [
            "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
            "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
            "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
            "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
            "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
            "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
            "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
            "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
            "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
            "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
            "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
            "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6",
            "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
            "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
            "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
            "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
            "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
            "BigRock: gadyzyh.com",
            "Matches rule ET INFO Namecheap URL",
            "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
            "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
            "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
            "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
            "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
            "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
            "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
            "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
            "Matches rule Windows Processes Suspicious Parent Directory by vburov"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Australia",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "TrojanDownloader:Win32/Upatre.E",
              "display_name": "TrojanDownloader:Win32/Upatre.E",
              "target": "/malware/TrojanDownloader:Win32/Upatre.E"
            },
            {
              "id": "Ransom:Win32/Crowti.A",
              "display_name": "Ransom:Win32/Crowti.A",
              "target": "/malware/Ransom:Win32/Crowti.A"
            },
            {
              "id": "Cycbot",
              "display_name": "Cycbot",
              "target": null
            },
            {
              "id": "VirTool:Win32/Injector",
              "display_name": "VirTool:Win32/Injector",
              "target": "/malware/VirTool:Win32/Injector"
            },
            {
              "id": "Win.Trojan.Simda",
              "display_name": "Win.Trojan.Simda",
              "target": null
            },
            {
              "id": "TEL:Win32/Qjwmonkey.A",
              "display_name": "TEL:Win32/Qjwmonkey.A",
              "target": "/malware/TEL:Win32/Qjwmonkey.A"
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 549,
            "domain": 1182,
            "hostname": 590,
            "URL": 961,
            "FileHash-SHA256": 2466,
            "FileHash-MD5": 562,
            "SSLCertFingerprint": 7,
            "email": 4
          },
          "indicator_count": 6321,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "644 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Matches rule Windows Processes Suspicious Parent Directory by vburov",
        "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
        "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
        "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
        "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
        "Matches rule ET INFO Namecheap URL",
        "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
        "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6",
        "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
        "BigRock: gadyzyh.com",
        "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
        "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
        "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
        "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
        "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
        "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
        "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
        "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
        "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
        "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Virtool:win32/injector",
            "Cycbot",
            "Ransom:win32/crowti.a",
            "Tel:win32/qjwmonkey.a",
            "Trojandownloader:win32/upatre.e",
            "Win.trojan.simda"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "688c8526be7a4df33863b5c5",
      "name": "VirusTotal - Shiz.ivr",
      "description": "*Win.Trojan.Shiz.ivr\n*PWS:Win32/Simda.D\n*virtool #injection#infostealer #network #cnc #block_not #virustotal_google #cnc #checking #procmem_yara\n#injection_inter_process\n#injection_create_remote_thread\n#antidebug_windows\n#multiple_useragents\n#network_fake_useragent\n#persistence_autorun\n#cape_detected_threat\n#antiav_detectfile\n#modify_proxy\n#deletes_self\n#infostealer_cookies\n#injection_createremotethread\n#suricata_alert\n~ vashti",
      "modified": "2025-08-31T08:01:04.297000",
      "created": "2025-08-01T09:13:10.510000",
      "tags": [
        "dynamicloader",
        "unknown",
        "msie",
        "windows nt",
        "slcc2",
        "media center",
        "suspicious",
        "search",
        "high",
        "show",
        "copy",
        "possible",
        "write",
        "internal",
        "malware",
        "push",
        "local",
        "next",
        "contacted",
        "domains",
        "pulses",
        "related tags",
        "file type",
        "date april",
        "pm size",
        "sha1 sha256",
        "imphash pehash",
        "virustotal api",
        "bq jul",
        "united",
        "trojan",
        "backdoor",
        "virtool",
        "cnc beacon",
        "entries",
        "path max",
        "passive dns",
        "next associated",
        "cookie",
        "twitter",
        "body",
        "date",
        "medium",
        "simda",
        "global"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 10303,
        "hostname": 1413,
        "FileHash-SHA256": 1868,
        "domain": 1877,
        "FileHash-MD5": 357,
        "FileHash-SHA1": 348,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 16168,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 149,
      "modified_text": "273 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6786a59af06fee17c8decf9d",
      "name": "netcfg",
      "description": "000ceafd276003f46d06828bb0459b3ccdc2b44013a313b69d6270a224199034",
      "modified": "2025-05-31T02:36:52.299000",
      "created": "2025-01-14T17:57:46.687000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 222,
        "domain": 216,
        "hostname": 4,
        "FileHash-SHA256": 1
      },
      "indicator_count": 443,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "365 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66a4293d5bc5c915eac829e0",
      "name": "Ransom:Win32/Crowti.A : Android Windows | Win.Trojan.Simda CnC",
      "description": "",
      "modified": "2024-08-25T21:00:52.039000",
      "created": "2024-07-26T22:54:53.598000",
      "tags": [
        "united",
        "unknown",
        "a domains",
        "accept",
        "link",
        "passive dns",
        "encrypt",
        "trmp",
        "ok server",
        "date",
        "meta",
        "whois lookup",
        "create date",
        "domain",
        "expiry date",
        "update date",
        "update",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr10",
        "validity",
        "public key",
        "info",
        "key algorithm",
        "dns replication",
        "subdomains",
        "first",
        "historical ssl",
        "record type",
        "ttl value",
        "cname",
        "certificates",
        "show",
        "entries",
        "yara rule",
        "delete",
        "search",
        "intel",
        "ms windows",
        "copy",
        "binary file",
        "get updates",
        "write",
        "as44273 host",
        "redacted for",
        "moved",
        "record value",
        "as54113",
        "body",
        "scan endpoints",
        "all scoreblue",
        "pulse submit",
        "url analysis",
        "urls",
        "files",
        "ip address",
        "files ip",
        "address domain",
        "as61969 team",
        "germany unknown",
        "msie",
        "chrome",
        "precondition",
        "gmt content",
        "united kingdom",
        "as396982 google",
        "as8075",
        "ireland unknown",
        "as21301",
        "aaaa",
        "status",
        "sha1",
        "windows nt",
        "sha256",
        "size",
        "ascii text",
        "pattern match",
        "mitre att",
        "ck id",
        "show technique",
        "span",
        "format",
        "click",
        "hybrid",
        "twitter",
        "generator",
        "tsvt",
        "strings",
        "download",
        "path",
        "contact",
        "suspicious",
        "invalid url",
        "open ports",
        "body html",
        "head title",
        "title head",
        "body h1",
        "reference",
        "bad request",
        "server",
        "version",
        "trojandropper",
        "ransom",
        "checkin",
        "ipv4",
        "trojan",
        "virtool",
        "http post",
        "theme directory",
        "without referer",
        "cycbot",
        "http response",
        "final url",
        "status code",
        "body length",
        "kb body",
        "headers server",
        "gmt etag",
        "gmt date",
        "referrer",
        "code signing",
        "serial number",
        "ca valid",
        "from",
        "valid",
        "valid usage",
        "verisign time",
        "stamping",
        "thumbprint",
        "class",
        "error",
        "info header",
        "name md5",
        "type",
        "language",
        "contained",
        "overlay",
        "gandi sas",
        "dynadot",
        "registrar",
        "dynadot inc",
        "cloudflare",
        "net technology",
        "corporation",
        "bigrock",
        "dynadot llc",
        "namecheap",
        "ip detections",
        "country",
        "contacted",
        "defense evasion",
        "access ta0006",
        "ta0009 command",
        "control ta0011",
        "impact ta0034",
        "impact ta0040",
        "ta0040",
        "samplepath",
        "pattern urls",
        "pattern domains",
        "memory pattern",
        "domains domain",
        "ip traffic",
        "typo squatting",
        "realteck audio",
        "phish",
        "mr windows",
        "partru",
        "goog mal",
        "android windows",
        "maze",
        "apple",
        "malware",
        "worm",
        "skynet",
        "microsoft",
        "trojan evader",
        "simda cnc",
        "showing",
        "filehash",
        "pulse pulses",
        "av detections",
        "ids detections",
        "delphi",
        "network",
        "crowdstrike"
      ],
      "references": [
        "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
        "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
        "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
        "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
        "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
        "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
        "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6",
        "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
        "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
        "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
        "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
        "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
        "BigRock: gadyzyh.com",
        "Matches rule ET INFO Namecheap URL",
        "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
        "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
        "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
        "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
        "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
        "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
        "Matches rule Windows Processes Suspicious Parent Directory by vburov"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Australia",
        "Netherlands"
      ],
      "malware_families": [
        {
          "id": "TrojanDownloader:Win32/Upatre.E",
          "display_name": "TrojanDownloader:Win32/Upatre.E",
          "target": "/malware/TrojanDownloader:Win32/Upatre.E"
        },
        {
          "id": "Ransom:Win32/Crowti.A",
          "display_name": "Ransom:Win32/Crowti.A",
          "target": "/malware/Ransom:Win32/Crowti.A"
        },
        {
          "id": "Cycbot",
          "display_name": "Cycbot",
          "target": null
        },
        {
          "id": "VirTool:Win32/Injector",
          "display_name": "VirTool:Win32/Injector",
          "target": "/malware/VirTool:Win32/Injector"
        },
        {
          "id": "Win.Trojan.Simda",
          "display_name": "Win.Trojan.Simda",
          "target": null
        },
        {
          "id": "TEL:Win32/Qjwmonkey.A",
          "display_name": "TEL:Win32/Qjwmonkey.A",
          "target": "/malware/TEL:Win32/Qjwmonkey.A"
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 549,
        "domain": 1182,
        "hostname": 590,
        "URL": 961,
        "FileHash-SHA256": 2466,
        "FileHash-MD5": 562,
        "SSLCertFingerprint": 7,
        "email": 4
      },
      "indicator_count": 6321,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "644 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "lysynun.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "lysynun.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780269504.1146636
}