{
  "type": "Domain",
  "indicator": "mobiletechwally.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/mobiletechwally.com",
    "alexa": "http://www.alexa.com/siteinfo/mobiletechwally.com",
    "indicator": "mobiletechwally.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4165302450,
      "indicator": "mobiletechwally.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "69fea69182246b3dfd8cf790",
          "name": "CREDIT Q.VASHTI [clone: ET Malware Playtech Downloader for Online Gaming]",
          "description": "",
          "modified": "2026-05-09T05:16:24.802000",
          "created": "2026-05-09T03:14:25.220000",
          "tags": [
            "installer.exe",
            "process32nextw",
            "regsetvalueexa",
            "regopenkeyexw",
            "regdword",
            "medium",
            "regbinary",
            "pupadware",
            "http header",
            "regsetvalueexw",
            "loader",
            "suspicious",
            "persistence",
            "execution",
            "malware",
            "win32 exe",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "os2 executable",
            "pe32 compiler",
            "ltcgc",
            "techniques y",
            "none",
            "scripting inte",
            "registry",
            "elevati t1548",
            "hijack execut",
            "y none",
            "info",
            "abuse elevation",
            "control mec",
            "flow l",
            "plugins",
            "plugx",
            "backdoor",
            "trojan",
            "autoit",
            "crossrider",
            "modify",
            "bootkit",
            "abuse",
            "casino",
            "bet",
            "ah",
            "army",
            "sabey",
            "ahmann",
            "dora true",
            "persistence",
            "injection",
            "graham tech",
            "danger",
            "gambling",
            "intellectual property",
            "theft",
            "bonu$",
            "dago",
            "colorado"
          ],
          "references": [
            "installer.exe | FileHash-SHA256 000002f7c809714f3dd89443c0b12d7f397c7dfe6108a448571e378b84c9f229",
            "Christopher P \u2018Buzz\u2019 Ahman | Brian Sabey | Tulach | Graham Tech",
            "Yara: Detections: stack_string | ConventionEngine_Keyword_Install |",
            "Yara: research_pe_signed_outside_timestamp [anomaly] xor_0x20_xord_javascript [Obfuscation]",
            "IDS Detections: Playtech Installer PUP/Adware | Playtech Downloader Online Gaming Checkin",
            "IDS Detections: Suspicious User-Agent containing Loader | Observed C: \\\\ filepath observed in HTTP header",
            "CS Yara: Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
            "CS IDS: Matches rule ET MALWARE Playtech Downloader Online Gaming Checkin",
            "CS IDS:  Matches rule (http_inspect) HTTP Content-Length message body was truncated",
            "CS IDS: Matches rule SURICATA STREAM excessive retransmissions Unique rule identifier: This rule belongs to a private collection.",
            "http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom/index.7ze",
            "cache.download2.casino.com",
            "thebeautifulbet.com",
            "Trojan:Win32/Blihan.A -Yara Detections:  KBysPacker028BetaShoooo",
            "http://geo.web-installer-assets.com/,onSuccessId:8,onFailureId:9",
            "http://geo.web-installer-assets.com/H",
            "http://geo.web-installer-assets.com/.hook_reg_dialog_skip_registration",
            "authrootstl.cab",
            "ET MALWARE Playtech Downloader Online Gaming Checkin Malware",
            "Command and Control Activity Detected",
            "Proofpoint Emerging Threats Open X Context for the matching alerts",
            "Rule references https://www.virustotal.com/gui/search/00740d7d15862efb3",
            "Destination IP: 157.185.156.194 Destination port: 80 Hostname: cache.download2.casino.com",
            "URL: http://cache.download2.casino.com/download/casino/client"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Trojan.Playtech/Crossrider",
              "display_name": "Trojan.Playtech/Crossrider",
              "target": null
            },
            {
              "id": "Trojan.Winterlove-28",
              "display_name": "Trojan.Winterlove-28",
              "target": null
            },
            {
              "id": "TEL:Backdoor:Win32/PlugX",
              "display_name": "TEL:Backdoor:Win32/PlugX",
              "target": null
            },
            {
              "id": "Trojan:Win32/Zbot.SIBG!MTB",
              "display_name": "Trojan:Win32/Zbot.SIBG!MTB",
              "target": "/malware/Trojan:Win32/Zbot.SIBG!MTB"
            },
            {
              "id": "#Lowfi:LUA:AutoItLargeFile",
              "display_name": "#Lowfi:LUA:AutoItLargeFile",
              "target": null
            },
            {
              "id": "TELPER:HSTR:CLEAN:Ninite",
              "display_name": "TELPER:HSTR:CLEAN:Ninite",
              "target": null
            },
            {
              "id": "#VirTool:Win32|Obfuscator.ADB",
              "display_name": "#VirTool:Win32|Obfuscator.ADB",
              "target": null
            },
            {
              "id": "Worm:Win32/Mofksys.RND!MTB",
              "display_name": "Worm:Win32/Mofksys.RND!MTB",
              "target": "/malware/Worm:Win32/Mofksys.RND!MTB"
            },
            {
              "id": "Trojan:Win32/Blihan.A",
              "display_name": "Trojan:Win32/Blihan.A",
              "target": "/malware/Trojan:Win32/Blihan.A"
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1067",
              "name": "Bootkit",
              "display_name": "T1067 - Bootkit"
            },
            {
              "id": "T1037",
              "name": "Boot or Logon Initialization Scripts",
              "display_name": "T1037 - Boot or Logon Initialization Scripts"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "T1444",
              "name": "Masquerade as Legitimate Application",
              "display_name": "T1444 - Masquerade as Legitimate Application"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1463",
              "name": "Manipulate Device Communication",
              "display_name": "T1463 - Manipulate Device Communication"
            },
            {
              "id": "T1401",
              "name": "Device Administrator Permissions",
              "display_name": "T1401 - Device Administrator Permissions"
            },
            {
              "id": "T1413",
              "name": "Access Sensitive Data in Device Logs",
              "display_name": "T1413 - Access Sensitive Data in Device Logs"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6945800991b5d80bdbcd2168",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 338,
            "URL": 160,
            "hostname": 115,
            "domain": 82
          },
          "indicator_count": 710,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "22 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6945800991b5d80bdbcd2168",
          "name": "ET MALWARE Playtech Downloader Online Gaming Checkin Illegal Operations",
          "description": "Related to multiple illegal operations.\nAppears to be an illegal gambling operation with many fronts. (In this instance. This compromise is obviously not exclusive to the content I present)\n\nTip: by NPDJoke - Thank you! \nDangerous. Not fully confirmed by me- involvement of Colorado Mafia Families.\nConfirmed: Colorado has a very rich history of mafia crimes including gambling involving doctors to food manufacturers. Multiple fronts. The entire \u2018Family\u2019 associations, etc, is diversified, working in many roles such as medical professionals, lawyers, music , computer engineers, hackers.  Colorado is beautiful but very corrupt.\nConfirmed: The wrong suspects jailed, jabbed, and sometimes murderd.",
          "modified": "2026-01-18T16:03:33.514000",
          "created": "2025-12-19T16:40:41.842000",
          "tags": [
            "installer.exe",
            "process32nextw",
            "regsetvalueexa",
            "regopenkeyexw",
            "regdword",
            "medium",
            "regbinary",
            "pupadware",
            "http header",
            "regsetvalueexw",
            "loader",
            "suspicious",
            "persistence",
            "execution",
            "malware",
            "win32 exe",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "os2 executable",
            "pe32 compiler",
            "ltcgc",
            "techniques y",
            "none",
            "scripting inte",
            "registry",
            "elevati t1548",
            "hijack execut",
            "y none",
            "info",
            "abuse elevation",
            "control mec",
            "flow l",
            "plugins",
            "plugx",
            "backdoor",
            "trojan",
            "autoit",
            "crossrider",
            "modify",
            "bootkit",
            "abuse",
            "casino",
            "bet",
            "ah",
            "army",
            "sabey",
            "ahmann",
            "dora true",
            "persistence",
            "injection",
            "graham tech",
            "danger",
            "gambling",
            "intellectual property",
            "theft",
            "bonu$",
            "dago",
            "colorado"
          ],
          "references": [
            "installer.exe | FileHash-SHA256 000002f7c809714f3dd89443c0b12d7f397c7dfe6108a448571e378b84c9f229",
            "Christopher P \u2018Buzz\u2019 Ahman | Brian Sabey | Tulach | Graham Tech",
            "Yara: Detections: stack_string | ConventionEngine_Keyword_Install |",
            "Yara: research_pe_signed_outside_timestamp [anomaly] xor_0x20_xord_javascript [Obfuscation]",
            "IDS Detections: Playtech Installer PUP/Adware | Playtech Downloader Online Gaming Checkin",
            "IDS Detections: Suspicious User-Agent containing Loader | Observed C: \\\\ filepath observed in HTTP header",
            "CS Yara: Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
            "CS IDS: Matches rule ET MALWARE Playtech Downloader Online Gaming Checkin",
            "CS IDS:  Matches rule (http_inspect) HTTP Content-Length message body was truncated",
            "CS IDS: Matches rule SURICATA STREAM excessive retransmissions Unique rule identifier: This rule belongs to a private collection.",
            "http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom/index.7ze",
            "cache.download2.casino.com",
            "thebeautifulbet.com",
            "Trojan:Win32/Blihan.A -Yara Detections:  KBysPacker028BetaShoooo",
            "http://geo.web-installer-assets.com/,onSuccessId:8,onFailureId:9",
            "http://geo.web-installer-assets.com/H",
            "http://geo.web-installer-assets.com/.hook_reg_dialog_skip_registration",
            "authrootstl.cab",
            "ET MALWARE Playtech Downloader Online Gaming Checkin Malware",
            "Command and Control Activity Detected",
            "Proofpoint Emerging Threats Open X Context for the matching alerts",
            "Rule references https://www.virustotal.com/gui/search/00740d7d15862efb3",
            "Destination IP: 157.185.156.194 Destination port: 80 Hostname: cache.download2.casino.com",
            "URL: http://cache.download2.casino.com/download/casino/client"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Trojan.Playtech/Crossrider",
              "display_name": "Trojan.Playtech/Crossrider",
              "target": null
            },
            {
              "id": "Trojan.Winterlove-28",
              "display_name": "Trojan.Winterlove-28",
              "target": null
            },
            {
              "id": "TEL:Backdoor:Win32/PlugX",
              "display_name": "TEL:Backdoor:Win32/PlugX",
              "target": null
            },
            {
              "id": "Trojan:Win32/Zbot.SIBG!MTB",
              "display_name": "Trojan:Win32/Zbot.SIBG!MTB",
              "target": "/malware/Trojan:Win32/Zbot.SIBG!MTB"
            },
            {
              "id": "#Lowfi:LUA:AutoItLargeFile",
              "display_name": "#Lowfi:LUA:AutoItLargeFile",
              "target": null
            },
            {
              "id": "TELPER:HSTR:CLEAN:Ninite",
              "display_name": "TELPER:HSTR:CLEAN:Ninite",
              "target": null
            },
            {
              "id": "#VirTool:Win32|Obfuscator.ADB",
              "display_name": "#VirTool:Win32|Obfuscator.ADB",
              "target": null
            },
            {
              "id": "Worm:Win32/Mofksys.RND!MTB",
              "display_name": "Worm:Win32/Mofksys.RND!MTB",
              "target": "/malware/Worm:Win32/Mofksys.RND!MTB"
            },
            {
              "id": "Trojan:Win32/Blihan.A",
              "display_name": "Trojan:Win32/Blihan.A",
              "target": "/malware/Trojan:Win32/Blihan.A"
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1067",
              "name": "Bootkit",
              "display_name": "T1067 - Bootkit"
            },
            {
              "id": "T1037",
              "name": "Boot or Logon Initialization Scripts",
              "display_name": "T1037 - Boot or Logon Initialization Scripts"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "T1444",
              "name": "Masquerade as Legitimate Application",
              "display_name": "T1444 - Masquerade as Legitimate Application"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1463",
              "name": "Manipulate Device Communication",
              "display_name": "T1463 - Manipulate Device Communication"
            },
            {
              "id": "T1401",
              "name": "Device Administrator Permissions",
              "display_name": "T1401 - Device Administrator Permissions"
            },
            {
              "id": "T1413",
              "name": "Access Sensitive Data in Device Logs",
              "display_name": "T1413 - Access Sensitive Data in Device Logs"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 338,
            "URL": 159,
            "hostname": 115,
            "domain": 82
          },
          "indicator_count": 709,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 144,
          "modified_text": "133 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "ET MALWARE Playtech Downloader Online Gaming Checkin Malware",
        "installer.exe | FileHash-SHA256 000002f7c809714f3dd89443c0b12d7f397c7dfe6108a448571e378b84c9f229",
        "CS IDS: Matches rule ET MALWARE Playtech Downloader Online Gaming Checkin",
        "http://geo.web-installer-assets.com/H",
        "Yara: Detections: stack_string | ConventionEngine_Keyword_Install |",
        "CS IDS: Matches rule SURICATA STREAM excessive retransmissions Unique rule identifier: This rule belongs to a private collection.",
        "URL: http://cache.download2.casino.com/download/casino/client",
        "http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom/index.7ze",
        "http://geo.web-installer-assets.com/.hook_reg_dialog_skip_registration",
        "Trojan:Win32/Blihan.A -Yara Detections:  KBysPacker028BetaShoooo",
        "CS IDS:  Matches rule (http_inspect) HTTP Content-Length message body was truncated",
        "Rule references https://www.virustotal.com/gui/search/00740d7d15862efb3",
        "cache.download2.casino.com",
        "CS Yara: Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
        "authrootstl.cab",
        "http://geo.web-installer-assets.com/,onSuccessId:8,onFailureId:9",
        "IDS Detections: Suspicious User-Agent containing Loader | Observed C: \\\\ filepath observed in HTTP header",
        "thebeautifulbet.com",
        "Christopher P \u2018Buzz\u2019 Ahman | Brian Sabey | Tulach | Graham Tech",
        "Command and Control Activity Detected",
        "Yara: research_pe_signed_outside_timestamp [anomaly] xor_0x20_xord_javascript [Obfuscation]",
        "Proofpoint Emerging Threats Open X Context for the matching alerts",
        "Destination IP: 157.185.156.194 Destination port: 80 Hostname: cache.download2.casino.com",
        "IDS Detections: Playtech Installer PUP/Adware | Playtech Downloader Online Gaming Checkin"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Trojan:win32/zbot.sibg!mtb",
            "#virtool:win32|obfuscator.adb",
            "#lowfi:lua:autoitlargefile",
            "Trojan:win32/blihan.a",
            "Telper:hstr:clean:ninite",
            "Trojan.playtech/crossrider",
            "Tel:backdoor:win32/plugx",
            "Trojan.winterlove-28",
            "Worm:win32/mofksys.rnd!mtb"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "69fea69182246b3dfd8cf790",
      "name": "CREDIT Q.VASHTI [clone: ET Malware Playtech Downloader for Online Gaming]",
      "description": "",
      "modified": "2026-05-09T05:16:24.802000",
      "created": "2026-05-09T03:14:25.220000",
      "tags": [
        "installer.exe",
        "process32nextw",
        "regsetvalueexa",
        "regopenkeyexw",
        "regdword",
        "medium",
        "regbinary",
        "pupadware",
        "http header",
        "regsetvalueexw",
        "loader",
        "suspicious",
        "persistence",
        "execution",
        "malware",
        "win32 exe",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "os2 executable",
        "pe32 compiler",
        "ltcgc",
        "techniques y",
        "none",
        "scripting inte",
        "registry",
        "elevati t1548",
        "hijack execut",
        "y none",
        "info",
        "abuse elevation",
        "control mec",
        "flow l",
        "plugins",
        "plugx",
        "backdoor",
        "trojan",
        "autoit",
        "crossrider",
        "modify",
        "bootkit",
        "abuse",
        "casino",
        "bet",
        "ah",
        "army",
        "sabey",
        "ahmann",
        "dora true",
        "persistence",
        "injection",
        "graham tech",
        "danger",
        "gambling",
        "intellectual property",
        "theft",
        "bonu$",
        "dago",
        "colorado"
      ],
      "references": [
        "installer.exe | FileHash-SHA256 000002f7c809714f3dd89443c0b12d7f397c7dfe6108a448571e378b84c9f229",
        "Christopher P \u2018Buzz\u2019 Ahman | Brian Sabey | Tulach | Graham Tech",
        "Yara: Detections: stack_string | ConventionEngine_Keyword_Install |",
        "Yara: research_pe_signed_outside_timestamp [anomaly] xor_0x20_xord_javascript [Obfuscation]",
        "IDS Detections: Playtech Installer PUP/Adware | Playtech Downloader Online Gaming Checkin",
        "IDS Detections: Suspicious User-Agent containing Loader | Observed C: \\\\ filepath observed in HTTP header",
        "CS Yara: Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
        "CS IDS: Matches rule ET MALWARE Playtech Downloader Online Gaming Checkin",
        "CS IDS:  Matches rule (http_inspect) HTTP Content-Length message body was truncated",
        "CS IDS: Matches rule SURICATA STREAM excessive retransmissions Unique rule identifier: This rule belongs to a private collection.",
        "http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom/index.7ze",
        "cache.download2.casino.com",
        "thebeautifulbet.com",
        "Trojan:Win32/Blihan.A -Yara Detections:  KBysPacker028BetaShoooo",
        "http://geo.web-installer-assets.com/,onSuccessId:8,onFailureId:9",
        "http://geo.web-installer-assets.com/H",
        "http://geo.web-installer-assets.com/.hook_reg_dialog_skip_registration",
        "authrootstl.cab",
        "ET MALWARE Playtech Downloader Online Gaming Checkin Malware",
        "Command and Control Activity Detected",
        "Proofpoint Emerging Threats Open X Context for the matching alerts",
        "Rule references https://www.virustotal.com/gui/search/00740d7d15862efb3",
        "Destination IP: 157.185.156.194 Destination port: 80 Hostname: cache.download2.casino.com",
        "URL: http://cache.download2.casino.com/download/casino/client"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Trojan.Playtech/Crossrider",
          "display_name": "Trojan.Playtech/Crossrider",
          "target": null
        },
        {
          "id": "Trojan.Winterlove-28",
          "display_name": "Trojan.Winterlove-28",
          "target": null
        },
        {
          "id": "TEL:Backdoor:Win32/PlugX",
          "display_name": "TEL:Backdoor:Win32/PlugX",
          "target": null
        },
        {
          "id": "Trojan:Win32/Zbot.SIBG!MTB",
          "display_name": "Trojan:Win32/Zbot.SIBG!MTB",
          "target": "/malware/Trojan:Win32/Zbot.SIBG!MTB"
        },
        {
          "id": "#Lowfi:LUA:AutoItLargeFile",
          "display_name": "#Lowfi:LUA:AutoItLargeFile",
          "target": null
        },
        {
          "id": "TELPER:HSTR:CLEAN:Ninite",
          "display_name": "TELPER:HSTR:CLEAN:Ninite",
          "target": null
        },
        {
          "id": "#VirTool:Win32|Obfuscator.ADB",
          "display_name": "#VirTool:Win32|Obfuscator.ADB",
          "target": null
        },
        {
          "id": "Worm:Win32/Mofksys.RND!MTB",
          "display_name": "Worm:Win32/Mofksys.RND!MTB",
          "target": "/malware/Worm:Win32/Mofksys.RND!MTB"
        },
        {
          "id": "Trojan:Win32/Blihan.A",
          "display_name": "Trojan:Win32/Blihan.A",
          "target": "/malware/Trojan:Win32/Blihan.A"
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1067",
          "name": "Bootkit",
          "display_name": "T1067 - Bootkit"
        },
        {
          "id": "T1037",
          "name": "Boot or Logon Initialization Scripts",
          "display_name": "T1037 - Boot or Logon Initialization Scripts"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "T1444",
          "name": "Masquerade as Legitimate Application",
          "display_name": "T1444 - Masquerade as Legitimate Application"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1463",
          "name": "Manipulate Device Communication",
          "display_name": "T1463 - Manipulate Device Communication"
        },
        {
          "id": "T1401",
          "name": "Device Administrator Permissions",
          "display_name": "T1401 - Device Administrator Permissions"
        },
        {
          "id": "T1413",
          "name": "Access Sensitive Data in Device Logs",
          "display_name": "T1413 - Access Sensitive Data in Device Logs"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1459",
          "name": "Device Unlock Code Guessing or Brute Force",
          "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6945800991b5d80bdbcd2168",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 338,
        "URL": 160,
        "hostname": 115,
        "domain": 82
      },
      "indicator_count": 710,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "22 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6945800991b5d80bdbcd2168",
      "name": "ET MALWARE Playtech Downloader Online Gaming Checkin Illegal Operations",
      "description": "Related to multiple illegal operations.\nAppears to be an illegal gambling operation with many fronts. (In this instance. This compromise is obviously not exclusive to the content I present)\n\nTip: by NPDJoke - Thank you! \nDangerous. Not fully confirmed by me- involvement of Colorado Mafia Families.\nConfirmed: Colorado has a very rich history of mafia crimes including gambling involving doctors to food manufacturers. Multiple fronts. The entire \u2018Family\u2019 associations, etc, is diversified, working in many roles such as medical professionals, lawyers, music , computer engineers, hackers.  Colorado is beautiful but very corrupt.\nConfirmed: The wrong suspects jailed, jabbed, and sometimes murderd.",
      "modified": "2026-01-18T16:03:33.514000",
      "created": "2025-12-19T16:40:41.842000",
      "tags": [
        "installer.exe",
        "process32nextw",
        "regsetvalueexa",
        "regopenkeyexw",
        "regdword",
        "medium",
        "regbinary",
        "pupadware",
        "http header",
        "regsetvalueexw",
        "loader",
        "suspicious",
        "persistence",
        "execution",
        "malware",
        "win32 exe",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "os2 executable",
        "pe32 compiler",
        "ltcgc",
        "techniques y",
        "none",
        "scripting inte",
        "registry",
        "elevati t1548",
        "hijack execut",
        "y none",
        "info",
        "abuse elevation",
        "control mec",
        "flow l",
        "plugins",
        "plugx",
        "backdoor",
        "trojan",
        "autoit",
        "crossrider",
        "modify",
        "bootkit",
        "abuse",
        "casino",
        "bet",
        "ah",
        "army",
        "sabey",
        "ahmann",
        "dora true",
        "persistence",
        "injection",
        "graham tech",
        "danger",
        "gambling",
        "intellectual property",
        "theft",
        "bonu$",
        "dago",
        "colorado"
      ],
      "references": [
        "installer.exe | FileHash-SHA256 000002f7c809714f3dd89443c0b12d7f397c7dfe6108a448571e378b84c9f229",
        "Christopher P \u2018Buzz\u2019 Ahman | Brian Sabey | Tulach | Graham Tech",
        "Yara: Detections: stack_string | ConventionEngine_Keyword_Install |",
        "Yara: research_pe_signed_outside_timestamp [anomaly] xor_0x20_xord_javascript [Obfuscation]",
        "IDS Detections: Playtech Installer PUP/Adware | Playtech Downloader Online Gaming Checkin",
        "IDS Detections: Suspicious User-Agent containing Loader | Observed C: \\\\ filepath observed in HTTP header",
        "CS Yara: Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
        "CS IDS: Matches rule ET MALWARE Playtech Downloader Online Gaming Checkin",
        "CS IDS:  Matches rule (http_inspect) HTTP Content-Length message body was truncated",
        "CS IDS: Matches rule SURICATA STREAM excessive retransmissions Unique rule identifier: This rule belongs to a private collection.",
        "http://fallback.playtech-installer.com/playtech_compressed_assets/casino_casinocom/index.7ze",
        "cache.download2.casino.com",
        "thebeautifulbet.com",
        "Trojan:Win32/Blihan.A -Yara Detections:  KBysPacker028BetaShoooo",
        "http://geo.web-installer-assets.com/,onSuccessId:8,onFailureId:9",
        "http://geo.web-installer-assets.com/H",
        "http://geo.web-installer-assets.com/.hook_reg_dialog_skip_registration",
        "authrootstl.cab",
        "ET MALWARE Playtech Downloader Online Gaming Checkin Malware",
        "Command and Control Activity Detected",
        "Proofpoint Emerging Threats Open X Context for the matching alerts",
        "Rule references https://www.virustotal.com/gui/search/00740d7d15862efb3",
        "Destination IP: 157.185.156.194 Destination port: 80 Hostname: cache.download2.casino.com",
        "URL: http://cache.download2.casino.com/download/casino/client"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Trojan.Playtech/Crossrider",
          "display_name": "Trojan.Playtech/Crossrider",
          "target": null
        },
        {
          "id": "Trojan.Winterlove-28",
          "display_name": "Trojan.Winterlove-28",
          "target": null
        },
        {
          "id": "TEL:Backdoor:Win32/PlugX",
          "display_name": "TEL:Backdoor:Win32/PlugX",
          "target": null
        },
        {
          "id": "Trojan:Win32/Zbot.SIBG!MTB",
          "display_name": "Trojan:Win32/Zbot.SIBG!MTB",
          "target": "/malware/Trojan:Win32/Zbot.SIBG!MTB"
        },
        {
          "id": "#Lowfi:LUA:AutoItLargeFile",
          "display_name": "#Lowfi:LUA:AutoItLargeFile",
          "target": null
        },
        {
          "id": "TELPER:HSTR:CLEAN:Ninite",
          "display_name": "TELPER:HSTR:CLEAN:Ninite",
          "target": null
        },
        {
          "id": "#VirTool:Win32|Obfuscator.ADB",
          "display_name": "#VirTool:Win32|Obfuscator.ADB",
          "target": null
        },
        {
          "id": "Worm:Win32/Mofksys.RND!MTB",
          "display_name": "Worm:Win32/Mofksys.RND!MTB",
          "target": "/malware/Worm:Win32/Mofksys.RND!MTB"
        },
        {
          "id": "Trojan:Win32/Blihan.A",
          "display_name": "Trojan:Win32/Blihan.A",
          "target": "/malware/Trojan:Win32/Blihan.A"
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1067",
          "name": "Bootkit",
          "display_name": "T1067 - Bootkit"
        },
        {
          "id": "T1037",
          "name": "Boot or Logon Initialization Scripts",
          "display_name": "T1037 - Boot or Logon Initialization Scripts"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "T1444",
          "name": "Masquerade as Legitimate Application",
          "display_name": "T1444 - Masquerade as Legitimate Application"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1463",
          "name": "Manipulate Device Communication",
          "display_name": "T1463 - Manipulate Device Communication"
        },
        {
          "id": "T1401",
          "name": "Device Administrator Permissions",
          "display_name": "T1401 - Device Administrator Permissions"
        },
        {
          "id": "T1413",
          "name": "Access Sensitive Data in Device Logs",
          "display_name": "T1413 - Access Sensitive Data in Device Logs"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1459",
          "name": "Device Unlock Code Guessing or Brute Force",
          "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 338,
        "URL": 159,
        "hostname": 115,
        "domain": 82
      },
      "indicator_count": 709,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 144,
      "modified_text": "133 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "mobiletechwally.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "mobiletechwally.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780262479.6975365
}