{
  "type": "Domain",
  "indicator": "malwareandstuff.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/malwareandstuff.com",
    "alexa": "http://www.alexa.com/siteinfo/malwareandstuff.com",
    "indicator": "malwareandstuff.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2221808291,
      "indicator": "malwareandstuff.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "67ff12aea0b9ba91d923da14",
          "name": "Threat Actor Profile: El Machete",
          "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
          "modified": "2025-04-16T02:15:10.602000",
          "created": "2025-04-16T02:15:10.602000",
          "tags": [
            "threat_actor",
            "unknown",
            "T1497",
            "T1114",
            "T1566.001",
            "T1059.003",
            "T1081",
            "T1059.006",
            "T1059",
            "T1566.002",
            "T1082",
            "T1027",
            "T1071.001",
            "T1566",
            "T1041",
            "T1105",
            "T1204.001",
            "T1049",
            "T1055",
            "T1036",
            "T1503",
            "T1114.001",
            "T1053",
            "T1140",
            "T1012",
            "T1071",
            "T1112",
            "T1036.005",
            "T1547",
            "T1057",
            "T1008",
            "T1518",
            "T1021",
            "T1011",
            "T1060",
            "T1539",
            "T1587",
            "T1087",
            "T1095",
            "T1102",
            "T1070",
            "T1130",
            "T1552",
            "T1106",
            "T1190",
            "T1007",
            "T1133",
            "T1090",
            "T1016",
            "T1137",
            "T1119",
            "T1124",
            "T1005",
            "T1059.001",
            "T1115",
            "T1562.001",
            "T1543",
            "T1078",
            "T1083",
            "T1530",
            "T1085",
            "T1003",
            "T1120",
            "T1218",
            "T1048",
            "T1553",
            "T1490",
            "T1497.003",
            "T1571",
            "T1204.002",
            "T1595.002",
            "T1102.002",
            "T1583.003",
            "T1027.009",
            "T1027.013",
            "T1132",
            "T1562",
            "T1110",
            "T1059.005",
            "T1218.007",
            "T1204",
            "T1550",
            "T1136",
            "T1555",
            "T1176",
            "T1204_-_User_Execution",
            "T1566_-_Phishing",
            "T1561",
            "T1583",
            "T1485",
            "T1127",
            "T1595",
            "T1573",
            "T1189",
            "T1486",
            "T1531",
            "T1529",
            "T1053.005",
            "T1047.",
            "target:Dominican Republic",
            "target:Venezuela",
            "target:Italy",
            "target:Colombia",
            "target:Ecuador",
            "target:Guatemala",
            "target:Belgium",
            "target:Malaysia",
            "target:Brazil",
            "target:France",
            "target:Indonesia",
            "target:United Kingdom",
            "target:China",
            "target:Germany",
            "target:Mexico",
            "target:Argentina",
            "target:Netherlands",
            "target:Japan",
            "target:Bolivia",
            "target:Yibuti",
            "target:Vietnam",
            "target:Fiyi",
            "target:Cuba",
            "target:Camboya",
            "target:Taiw\u00e1n",
            "target:United States",
            "target:Sweden",
            "target:Ukraine",
            "target:South Korea",
            "target:Nicaragua",
            "target:Canada",
            "target:Russia",
            "target:otros"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 9,
            "hostname": 18,
            "domain": 59
          },
          "indicator_count": 86,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 56,
          "modified_text": "410 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ff1245d4dc2a56e5561a57",
          "name": "Threat Actor Profile: El Machete",
          "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
          "modified": "2025-04-16T02:13:25.801000",
          "created": "2025-04-16T02:13:25.801000",
          "tags": [
            "threat_actor",
            "unknown",
            "T1497",
            "T1114",
            "T1566.001",
            "T1059.003",
            "T1081",
            "T1059.006",
            "T1059",
            "T1566.002",
            "T1082",
            "T1027",
            "T1071.001",
            "T1566",
            "T1041",
            "T1105",
            "T1204.001",
            "T1049",
            "T1055",
            "T1036",
            "T1503",
            "T1114.001",
            "T1053",
            "T1140",
            "T1012",
            "T1071",
            "T1112",
            "T1036.005",
            "T1547",
            "T1057",
            "T1008",
            "T1518",
            "T1021",
            "T1011",
            "T1060",
            "T1539",
            "T1587",
            "T1087",
            "T1095",
            "T1102",
            "T1070",
            "T1130",
            "T1552",
            "T1106",
            "T1190",
            "T1007",
            "T1133",
            "T1090",
            "T1016",
            "T1137",
            "T1119",
            "T1124",
            "T1005",
            "T1059.001",
            "T1115",
            "T1562.001",
            "T1543",
            "T1078",
            "T1083",
            "T1530",
            "T1085",
            "T1003",
            "T1120",
            "T1218",
            "T1048",
            "T1553",
            "T1490",
            "T1497.003",
            "T1571",
            "T1204.002",
            "T1595.002",
            "T1102.002",
            "T1583.003",
            "T1027.009",
            "T1027.013",
            "T1132",
            "T1562",
            "T1110",
            "T1059.005",
            "T1218.007",
            "T1204",
            "T1550",
            "T1136",
            "T1555",
            "T1176",
            "T1204_-_User_Execution",
            "T1566_-_Phishing",
            "T1561",
            "T1583",
            "T1485",
            "T1127",
            "T1595",
            "T1573",
            "T1189",
            "T1486",
            "T1531",
            "T1529",
            "T1053.005",
            "T1047.",
            "target:Dominican Republic",
            "target:Venezuela",
            "target:Italy",
            "target:Colombia",
            "target:Ecuador",
            "target:Guatemala",
            "target:Belgium",
            "target:Malaysia",
            "target:Brazil",
            "target:France",
            "target:Indonesia",
            "target:United Kingdom",
            "target:China",
            "target:Germany",
            "target:Mexico",
            "target:Argentina",
            "target:Netherlands",
            "target:Japan",
            "target:Bolivia",
            "target:Yibuti",
            "target:Vietnam",
            "target:Fiyi",
            "target:Cuba",
            "target:Camboya",
            "target:Taiw\u00e1n",
            "target:United States",
            "target:Sweden",
            "target:Ukraine",
            "target:South Korea",
            "target:Nicaragua",
            "target:Canada",
            "target:Russia",
            "target:otros"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 9,
            "hostname": 18,
            "domain": 59
          },
          "indicator_count": 86,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 56,
          "modified_text": "410 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6773390f17d71879c414676a",
          "name": "El Machete",
          "description": "El Machete es un grupo de ciberespionaje activo desde al menos 2014, enfocado en atacar principalmente a naciones de habla hispana. Este grupo es conocido por su sofisticada malware y t\u00e1cticas de exfiltraci\u00f3n de datos, con un enfoque en objetivos de alto perfil, como agencias gubernamentales y organizaciones estrat\u00e9gicas.",
          "modified": "2025-01-30T00:00:18.927000",
          "created": "2024-12-31T00:21:35.813000",
          "tags": [
            "cve201711882",
            "cve20201472",
            "El Machete"
          ],
          "references": [],
          "public": 1,
          "adversary": "El Machete",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 473,
            "FileHash-SHA1": 471,
            "FileHash-SHA256": 500,
            "CVE": 9,
            "domain": 60,
            "hostname": 18
          },
          "indicator_count": 1531,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 60,
          "modified_text": "486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67733b72d522398f5ea0a12d",
          "name": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar",
          "description": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar con Intereses en la Administraci\u00f3n P\u00fablica de la Rep\u00fablica Dominicana, Diciembre 2024",
          "modified": "2025-01-30T00:00:18.927000",
          "created": "2024-12-31T00:31:46.858000",
          "tags": [
            "cve201711882",
            "cve20201472"
          ],
          "references": [],
          "public": 1,
          "adversary": "El Machete, TAG-100, Mirage, Unamed_Grooup",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2631,
            "FileHash-SHA1": 2168,
            "FileHash-SHA256": 3401,
            "CVE": 25,
            "domain": 977,
            "hostname": 1226
          },
          "indicator_count": 10428,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6503d7178561b166376e753c",
          "name": "Fake Cisco Webex Google Ads Push Malware",
          "description": "",
          "modified": "2024-08-30T06:04:45.782000",
          "created": "2023-09-15T04:01:27.988000",
          "tags": [
            "webex",
            "google",
            "batloader",
            "urls",
            "cisco",
            "google search",
            "ad campaign",
            "webex logo",
            "mexico",
            "google ads",
            "virustotal",
            "nebula",
            "powershell",
            "python",
            "danabot",
            "group",
            "please",
            "team",
            "proofpoint",
            "eset research",
            "push",
            "cisa",
            "crowdstrike",
            "red dev",
            "dennis",
            "malware",
            "redline stealer",
            "trojan",
            "zloader",
            "evolution",
            "netwire rc",
            "jackal",
            "agent tesla",
            "twitter",
            "ave maria",
            "oilrig",
            "mask",
            "machete",
            "panda",
            "back",
            "nullmixer",
            "privateloader",
            "mars stealer",
            "ytstealer",
            "defense",
            "cobalt strike",
            "miner",
            "zeus",
            "mount locker",
            "quasar rat",
            "ransomware",
            "trickbot",
            "nanocore rat",
            "defensor id",
            "ctb locker",
            "wannacryptor",
            "stealer",
            "predator",
            "tiger",
            "attack",
            "download",
            "ixeshe",
            "aluminum",
            "msupdater",
            "nettraveler",
            "keyboy",
            "sednit",
            "sofacy",
            "oceanlotus",
            "holmium",
            "scarcruft",
            "venus",
            "sykipot",
            "leviathan",
            "amoeba",
            "hoodoo",
            "dragon",
            "star",
            "matanbuchus",
            "comnie",
            "termite",
            "emdivi",
            "greenbug",
            "careto",
            "cobalt",
            "cyber",
            "icefog",
            "trident",
            "dnspionage",
            "darkhotel",
            "luder",
            "nemim",
            "tapaoux",
            "pioneer",
            "havex",
            "evilnum",
            "carbanak",
            "gcman",
            "ghostnet",
            "bitter",
            "infy",
            "karakurt",
            "kinsing",
            "mercury",
            "naikon",
            "nitro",
            "strongpity",
            "powerpool",
            "indra",
            "sauron",
            "sidewinder",
            "redalpha",
            "mantis",
            "rocke",
            "mimic",
            "silence",
            "guardian",
            "teamspy",
            "teamtnt",
            "teamxrat",
            "turla",
            "snake",
            "wraith",
            "pfinet",
            "krypton",
            "zoopark",
            "unit",
            "threat response",
            "pla unit",
            "change",
            "intel",
            "ursnif",
            "tools",
            "jason",
            "vidar",
            "green",
            "hive",
            "stealth mango"
          ],
          "references": [
            "September 15th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3249 - Fake Cisco Webex Google Ads Push Malware.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Ursnif",
              "display_name": "Ursnif",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 120,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 2,
            "URL": 31,
            "domain": 33,
            "FileHash-SHA1": 1,
            "YARA": 1,
            "hostname": 3
          },
          "indicator_count": 71,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 500,
          "modified_text": "639 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "September 15th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3249 - Fake Cisco Webex Google Ads Push Malware.pdf"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "El Machete, TAG-100, Mirage, Unamed_Grooup",
            "El Machete"
          ],
          "malware_families": [
            "Ursnif"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "67ff12aea0b9ba91d923da14",
      "name": "Threat Actor Profile: El Machete",
      "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
      "modified": "2025-04-16T02:15:10.602000",
      "created": "2025-04-16T02:15:10.602000",
      "tags": [
        "threat_actor",
        "unknown",
        "T1497",
        "T1114",
        "T1566.001",
        "T1059.003",
        "T1081",
        "T1059.006",
        "T1059",
        "T1566.002",
        "T1082",
        "T1027",
        "T1071.001",
        "T1566",
        "T1041",
        "T1105",
        "T1204.001",
        "T1049",
        "T1055",
        "T1036",
        "T1503",
        "T1114.001",
        "T1053",
        "T1140",
        "T1012",
        "T1071",
        "T1112",
        "T1036.005",
        "T1547",
        "T1057",
        "T1008",
        "T1518",
        "T1021",
        "T1011",
        "T1060",
        "T1539",
        "T1587",
        "T1087",
        "T1095",
        "T1102",
        "T1070",
        "T1130",
        "T1552",
        "T1106",
        "T1190",
        "T1007",
        "T1133",
        "T1090",
        "T1016",
        "T1137",
        "T1119",
        "T1124",
        "T1005",
        "T1059.001",
        "T1115",
        "T1562.001",
        "T1543",
        "T1078",
        "T1083",
        "T1530",
        "T1085",
        "T1003",
        "T1120",
        "T1218",
        "T1048",
        "T1553",
        "T1490",
        "T1497.003",
        "T1571",
        "T1204.002",
        "T1595.002",
        "T1102.002",
        "T1583.003",
        "T1027.009",
        "T1027.013",
        "T1132",
        "T1562",
        "T1110",
        "T1059.005",
        "T1218.007",
        "T1204",
        "T1550",
        "T1136",
        "T1555",
        "T1176",
        "T1204_-_User_Execution",
        "T1566_-_Phishing",
        "T1561",
        "T1583",
        "T1485",
        "T1127",
        "T1595",
        "T1573",
        "T1189",
        "T1486",
        "T1531",
        "T1529",
        "T1053.005",
        "T1047.",
        "target:Dominican Republic",
        "target:Venezuela",
        "target:Italy",
        "target:Colombia",
        "target:Ecuador",
        "target:Guatemala",
        "target:Belgium",
        "target:Malaysia",
        "target:Brazil",
        "target:France",
        "target:Indonesia",
        "target:United Kingdom",
        "target:China",
        "target:Germany",
        "target:Mexico",
        "target:Argentina",
        "target:Netherlands",
        "target:Japan",
        "target:Bolivia",
        "target:Yibuti",
        "target:Vietnam",
        "target:Fiyi",
        "target:Cuba",
        "target:Camboya",
        "target:Taiw\u00e1n",
        "target:United States",
        "target:Sweden",
        "target:Ukraine",
        "target:South Korea",
        "target:Nicaragua",
        "target:Canada",
        "target:Russia",
        "target:otros"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 9,
        "hostname": 18,
        "domain": 59
      },
      "indicator_count": 86,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 56,
      "modified_text": "410 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67ff1245d4dc2a56e5561a57",
      "name": "Threat Actor Profile: El Machete",
      "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
      "modified": "2025-04-16T02:13:25.801000",
      "created": "2025-04-16T02:13:25.801000",
      "tags": [
        "threat_actor",
        "unknown",
        "T1497",
        "T1114",
        "T1566.001",
        "T1059.003",
        "T1081",
        "T1059.006",
        "T1059",
        "T1566.002",
        "T1082",
        "T1027",
        "T1071.001",
        "T1566",
        "T1041",
        "T1105",
        "T1204.001",
        "T1049",
        "T1055",
        "T1036",
        "T1503",
        "T1114.001",
        "T1053",
        "T1140",
        "T1012",
        "T1071",
        "T1112",
        "T1036.005",
        "T1547",
        "T1057",
        "T1008",
        "T1518",
        "T1021",
        "T1011",
        "T1060",
        "T1539",
        "T1587",
        "T1087",
        "T1095",
        "T1102",
        "T1070",
        "T1130",
        "T1552",
        "T1106",
        "T1190",
        "T1007",
        "T1133",
        "T1090",
        "T1016",
        "T1137",
        "T1119",
        "T1124",
        "T1005",
        "T1059.001",
        "T1115",
        "T1562.001",
        "T1543",
        "T1078",
        "T1083",
        "T1530",
        "T1085",
        "T1003",
        "T1120",
        "T1218",
        "T1048",
        "T1553",
        "T1490",
        "T1497.003",
        "T1571",
        "T1204.002",
        "T1595.002",
        "T1102.002",
        "T1583.003",
        "T1027.009",
        "T1027.013",
        "T1132",
        "T1562",
        "T1110",
        "T1059.005",
        "T1218.007",
        "T1204",
        "T1550",
        "T1136",
        "T1555",
        "T1176",
        "T1204_-_User_Execution",
        "T1566_-_Phishing",
        "T1561",
        "T1583",
        "T1485",
        "T1127",
        "T1595",
        "T1573",
        "T1189",
        "T1486",
        "T1531",
        "T1529",
        "T1053.005",
        "T1047.",
        "target:Dominican Republic",
        "target:Venezuela",
        "target:Italy",
        "target:Colombia",
        "target:Ecuador",
        "target:Guatemala",
        "target:Belgium",
        "target:Malaysia",
        "target:Brazil",
        "target:France",
        "target:Indonesia",
        "target:United Kingdom",
        "target:China",
        "target:Germany",
        "target:Mexico",
        "target:Argentina",
        "target:Netherlands",
        "target:Japan",
        "target:Bolivia",
        "target:Yibuti",
        "target:Vietnam",
        "target:Fiyi",
        "target:Cuba",
        "target:Camboya",
        "target:Taiw\u00e1n",
        "target:United States",
        "target:Sweden",
        "target:Ukraine",
        "target:South Korea",
        "target:Nicaragua",
        "target:Canada",
        "target:Russia",
        "target:otros"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 9,
        "hostname": 18,
        "domain": 59
      },
      "indicator_count": 86,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 56,
      "modified_text": "410 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6773390f17d71879c414676a",
      "name": "El Machete",
      "description": "El Machete es un grupo de ciberespionaje activo desde al menos 2014, enfocado en atacar principalmente a naciones de habla hispana. Este grupo es conocido por su sofisticada malware y t\u00e1cticas de exfiltraci\u00f3n de datos, con un enfoque en objetivos de alto perfil, como agencias gubernamentales y organizaciones estrat\u00e9gicas.",
      "modified": "2025-01-30T00:00:18.927000",
      "created": "2024-12-31T00:21:35.813000",
      "tags": [
        "cve201711882",
        "cve20201472",
        "El Machete"
      ],
      "references": [],
      "public": 1,
      "adversary": "El Machete",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 473,
        "FileHash-SHA1": 471,
        "FileHash-SHA256": 500,
        "CVE": 9,
        "domain": 60,
        "hostname": 18
      },
      "indicator_count": 1531,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 60,
      "modified_text": "486 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67733b72d522398f5ea0a12d",
      "name": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar",
      "description": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar con Intereses en la Administraci\u00f3n P\u00fablica de la Rep\u00fablica Dominicana, Diciembre 2024",
      "modified": "2025-01-30T00:00:18.927000",
      "created": "2024-12-31T00:31:46.858000",
      "tags": [
        "cve201711882",
        "cve20201472"
      ],
      "references": [],
      "public": 1,
      "adversary": "El Machete, TAG-100, Mirage, Unamed_Grooup",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2631,
        "FileHash-SHA1": 2168,
        "FileHash-SHA256": 3401,
        "CVE": 25,
        "domain": 977,
        "hostname": 1226
      },
      "indicator_count": 10428,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "486 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6503d7178561b166376e753c",
      "name": "Fake Cisco Webex Google Ads Push Malware",
      "description": "",
      "modified": "2024-08-30T06:04:45.782000",
      "created": "2023-09-15T04:01:27.988000",
      "tags": [
        "webex",
        "google",
        "batloader",
        "urls",
        "cisco",
        "google search",
        "ad campaign",
        "webex logo",
        "mexico",
        "google ads",
        "virustotal",
        "nebula",
        "powershell",
        "python",
        "danabot",
        "group",
        "please",
        "team",
        "proofpoint",
        "eset research",
        "push",
        "cisa",
        "crowdstrike",
        "red dev",
        "dennis",
        "malware",
        "redline stealer",
        "trojan",
        "zloader",
        "evolution",
        "netwire rc",
        "jackal",
        "agent tesla",
        "twitter",
        "ave maria",
        "oilrig",
        "mask",
        "machete",
        "panda",
        "back",
        "nullmixer",
        "privateloader",
        "mars stealer",
        "ytstealer",
        "defense",
        "cobalt strike",
        "miner",
        "zeus",
        "mount locker",
        "quasar rat",
        "ransomware",
        "trickbot",
        "nanocore rat",
        "defensor id",
        "ctb locker",
        "wannacryptor",
        "stealer",
        "predator",
        "tiger",
        "attack",
        "download",
        "ixeshe",
        "aluminum",
        "msupdater",
        "nettraveler",
        "keyboy",
        "sednit",
        "sofacy",
        "oceanlotus",
        "holmium",
        "scarcruft",
        "venus",
        "sykipot",
        "leviathan",
        "amoeba",
        "hoodoo",
        "dragon",
        "star",
        "matanbuchus",
        "comnie",
        "termite",
        "emdivi",
        "greenbug",
        "careto",
        "cobalt",
        "cyber",
        "icefog",
        "trident",
        "dnspionage",
        "darkhotel",
        "luder",
        "nemim",
        "tapaoux",
        "pioneer",
        "havex",
        "evilnum",
        "carbanak",
        "gcman",
        "ghostnet",
        "bitter",
        "infy",
        "karakurt",
        "kinsing",
        "mercury",
        "naikon",
        "nitro",
        "strongpity",
        "powerpool",
        "indra",
        "sauron",
        "sidewinder",
        "redalpha",
        "mantis",
        "rocke",
        "mimic",
        "silence",
        "guardian",
        "teamspy",
        "teamtnt",
        "teamxrat",
        "turla",
        "snake",
        "wraith",
        "pfinet",
        "krypton",
        "zoopark",
        "unit",
        "threat response",
        "pla unit",
        "change",
        "intel",
        "ursnif",
        "tools",
        "jason",
        "vidar",
        "green",
        "hive",
        "stealth mango"
      ],
      "references": [
        "September 15th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3249 - Fake Cisco Webex Google Ads Push Malware.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Ursnif",
          "display_name": "Ursnif",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 120,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "cryptocti",
        "id": "110256",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 2,
        "URL": 31,
        "domain": 33,
        "FileHash-SHA1": 1,
        "YARA": 1,
        "hostname": 3
      },
      "indicator_count": 71,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 500,
      "modified_text": "639 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "malwareandstuff.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "malwareandstuff.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780233981.2771661
}