{
  "type": "Domain",
  "indicator": "mtext.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/mtext.com",
    "alexa": "http://www.alexa.com/siteinfo/mtext.com",
    "indicator": "mtext.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4069284655,
      "indicator": "mtext.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "6a1fc3671bc3d0f5ce8b06e6",
          "name": "Grok \u2022 X \u2022 Twitter Vflooder | SystemBC | QNAPCrypt",
          "description": "I continue to research issues affecting iOS and other smart devices, browsers, search engines and targeted individuals.\nI will limit my comments as further evaluation is required. Twitter appears to be used as a weapon to abuse of several targeted persons and their schools or businesses. Research is required to determine how. Is Twitter / X a weapon or is it abused by threat actors. Ongoing attacks dating back at least 5 years. || \n*DESCRIPTION: Detects systembc RAT REFERENCE: https://www.linkedin.com/posts/any-run_systembc-rat-explorewithanyrun-activity-7289971333671645184-Sefp/?utm_source=share&utm_medium=member_ios RULE_AUTHOR: X__Junior\n\n#malicious #spyware #twitter #x #ai_ agents #seen_before #systembc #vtflooder #qnapcrypt #cve #checkin #scripiting #injection #extraction #gobinary #operation",
          "modified": "2026-06-03T06:02:15.229000",
          "created": "2026-06-03T06:02:15.229000",
          "tags": [
            "sysv",
            "buildid",
            "united",
            "windows nt",
            "msie",
            "germany as8560",
            "yara detections",
            "contacted",
            "z74457024643q1",
            "systembc",
            "trojan",
            "elf executable",
            "exec amd6464",
            "linux",
            "elf64 operation",
            "unix",
            "compiler",
            "debugging",
            "go binary",
            "injection",
            "header elf64",
            "v exec",
            "executable file",
            "advanced micro",
            "note",
            "strtab",
            "gmbh",
            "gandi sas",
            "group india",
            "private limited",
            "qnapcrypt",
            "hacktool",
            "chrome",
            "yandex",
            "stripchat",
            "amazonaws",
            "mal_elf_systembc",
            "apple ios",
            "ios",
            "apple",
            "telhash",
            "data upload",
            "cursor",
            "se data",
            "extraction",
            "n https",
            "data",
            "failed",
            "cve cve20246387",
            "log id",
            "gmtn",
            "path",
            "secure",
            "self",
            "samesitenone",
            "encrypt",
            "d8n timestamp",
            "timestamp",
            "organization",
            "false",
            "certificate",
            "search",
            "emails",
            "twitter",
            "twitter spyware",
            "twitter vtflooder",
            "x",
            "unknown aaaa",
            "present jun",
            "ip address",
            "belize unknown",
            "unknown ns",
            "grok x",
            "cursor agents",
            "ai",
            "url url",
            "url hostnams",
            "hostn url",
            "url data",
            "belize",
            "a domains",
            "moved",
            "alone email",
            "gmt server",
            "url analysis",
            "accept",
            "namecheap",
            "namecheap inc",
            "namesilo",
            "expim",
            "url https",
            "dynamicloader",
            "host",
            "ff d5",
            "yara rule",
            "ee fc",
            "generic http",
            "exe upload",
            "f0 ff",
            "eb e1",
            "write",
            "vflooder",
            "malware",
            "upload inbound",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "checkin generic",
            "http exe",
            "upload inbound",
            "outbound yara",
            "nrv2x",
            "upxoepplace",
            "google",
            "adversaries",
            "adversarial attacks",
            "techniques",
            "create",
            "modify system",
            "process t1064",
            "t1543 systemd",
            "technir create",
            "full reports",
            "v tcp",
            "help",
            "ja3 digests",
            "hashes o",
            "et http",
            "get http",
            "post http",
            "dns resolutions",
            "cams",
            "adult content",
            "ff bb",
            "ff ff",
            "f7 b9",
            "c1 e8",
            "copy",
            "markus",
            "august",
            "title",
            "gamehack",
            "alberta.ca",
            "songculture",
            "lizardsquad"
          ],
          "references": [
            "FileHash-SHA256 756f0b598741a6fdff640a158b6b490472e546d411da2850836b9a8ca76afdc1",
            "TelfHash t135324a7149bc74b5b6a6d910b3a3b4b8a6772d6566f434f51023ad84ffc1e801ce283b",
            "Names: testpaging \u2022 upof6w.exe \u2022 2026-04-07_259af8b0d0bc540384a06bb730cee9cd_qnapcrypt",
            "Yara Detections: is__elf IP\u2019s",
            "IP\u2019s Contacted: 104.17.118.12  57.144.248.1  176.114.120.24  80.12.24.14  95.163.61.73  142.251.98.113",
            "IP\u2019s Contacted: 212.227.17.162  77.88.44.55  142.93.142.17  104.18.14.206",
            "Domains Contacted: checkip.amazonaws.com vk.com arena.ai www.yandex.ru stripchat.com",
            "ELF - ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked,",
            "Go BuildID=qBC61D7N3q3H7j2Pq55o/WsPsx2ArOJ0T24axAUMZ/K6isHEI8QMyAMkIM3HH8/QQevOAoeyrO7eZGdBARa,",
            "BuildID[sha1]=068f07f6460b85817e4be47c18c10d1a1fbef817, stripped",
            "motherlesslive.com",
            "blackbox21.shop",
            "passwordreset.gscs.ca  \u2022 https://passwordreset.gscs.ca/",
            "alberta.ca impacts an OTX user",
            "https://stripchat.org/ \u2022  27bsmextreme.tech \u2022 35bsmextreme.tech  \u2022 46bsmextreme.tech  \u2022",
            "FileHash-SHA256 9da8632065cc24646086ff5fb769c452f777aa6c2470a02a16d209baabd1e4b5",
            "storage/analyses/1000549/network 9da8632065cc24646086f f5 fb769c45\"",
            "? Con*-cted jp-\u0661\u0660\u0661\u0660\u0660\u0660.--- \u0644\u062d\u0645\u0627",
            "https://arena.ai/apple-touch-icon-dark.png",
            "https://www.forbes.com/consent/ketch/?toURL=https://www.forbes.com/2009/07/28/hackers-iphone-apple-technology-security-hackers.html",
            "nr-data.net \u2022 push.apple.com",
            "https://twitter.com/PORNO_SEXYBABES \u2022 twitter.com",
            "Vtflooder-9783271-0 -> 7476476bdc93726f46f75f5bdd5ce6c619d73f7ee82b7d93ad835c993ff14661",
            "Win.Malware.Vtflooder-9783271-0 -> Domains Contacted twitter.com www.virustotal.com",
            "IP\u2019s Contacted 162.159.140.229  34.54.88.138",
            "IDS Detections: Win32/Vflooder.B Checkin \u2022 Generic HTTP EXE Upload Inbound \u2022 Generic HTTP EXE Upload Outbound",
            "Yara Detections: SUSP_Imphash_Mar23_2 ,  UPX ,  Nrv2x ,  UPX_OEP_place ,   ,   UPXv20MarkusLaszloReiser",
            "Yara Detections: UPX20030XMarkusOberhumerLaszloMolnarJohnReiser",
            "Yara Detections: UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser",
            "Alerts: procmem_yara suricata_alert dynamic_function_loading network_cnc_https_generic reads_self",
            "Alerts: network_cnc_http network_http packer_unknown_pe_section_name injection_rwx dead_connect exec_crash",
            "Sigma: Matches rule Suspicious Outbound SMTP Connections by frack113",
            "Suspicious DNS Query for IP Lookup Service APls by Brandon George (blog post) Thomas Patzke",
            "Crowdsourced IDS: ET DROP Spamhaus Listed Traffic Inbound group 60",
            "Matches rule ET INFO External IP Lookup Domain in DNS Lookup (checkip amazonaws .com)",
            "Matches rule ET INFO External IP Check (checkip.amazonaws.com)",
            "ET HUNTING Suspicious User-Agent Observed (Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
            "(Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
            "Matches rule SURICATA Applayer Detect protocol only one direction virustotal.com",
            "DESCRIPTION: Detects systembc RAT REFERENCE: https://www.linkedin.com/posts/any-run_systembc-rat-explorewithanyrun-activity-7289971333671645184-Sefp/?utm_source=share&utm_medium=member_ios RULE_AUTHOR: X__Junior",
            "https://www.linkedin.com/posts/any-run_systembc-rat-explorewithanyrun-activity-7289971333671645184-Sefp/?utm_source=share&utm_medium=member_ios RULE_AUTHOR: X__Junior",
            "https://docs.cursor.com/en/cli/reference/slash-commands",
            "https://api.cursor.com/v0/agents/",
            "https://grok.com/imagine/agent/d5e99582-a7e7-4138-b129-780e171ba9ac",
            "beacons.bcp.gvt.com \u2022 http://vtboss.yolox.net/md5.php \u2022 finanse.mf.gov.pl",
            "cdn10.mypornvid.fun impacted a targeted individual",
            "https://click.italiansexclub.fun/click/HpdeyDt6",
            "https://sexfortokens.com/hotmilfbitch",
            "Win.Malware.Gamehack-6822792-0 IDS Detections Riskware/Cheathappens Checkin (songculture attack)"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Trojan.Systembc/yxgdgz",
              "display_name": "Trojan.Systembc/yxgdgz",
              "target": null
            },
            {
              "id": "CVE-2023-22518",
              "display_name": "CVE-2023-22518",
              "target": null
            },
            {
              "id": "CVE-2024-6387",
              "display_name": "CVE-2024-6387",
              "target": null
            },
            {
              "id": "CVE-2025-20393",
              "display_name": "CVE-2025-20393",
              "target": null
            },
            {
              "id": "Win.Malware.Vtflooder-6722904-1",
              "display_name": "Win.Malware.Vtflooder-6722904-1",
              "target": null
            },
            {
              "id": "Trojan:Win32/Vflooder",
              "display_name": "Trojan:Win32/Vflooder",
              "target": "/malware/Trojan:Win32/Vflooder"
            },
            {
              "id": "QNAPCrypt",
              "display_name": "QNAPCrypt",
              "target": null
            },
            {
              "id": "Win.Malware.Gamehack-6822792-0",
              "display_name": "Win.Malware.Gamehack-6822792-0",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "TA0028",
              "name": "Persistence",
              "display_name": "TA0028 - Persistence"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "T1543.002",
              "name": "Systemd Service",
              "display_name": "T1543.002 - Systemd Service"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "T1457",
              "name": "Malicious Media Content",
              "display_name": "T1457 - Malicious Media Content"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1468",
              "name": "Remotely Track Device Without Authorization",
              "display_name": "T1468 - Remotely Track Device Without Authorization"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1262,
            "FileHash-MD5": 164,
            "FileHash-SHA1": 207,
            "IPv4": 180,
            "URL": 1780,
            "domain": 370,
            "hostname": 708,
            "CVE": 3,
            "email": 4,
            "SSLCertFingerprint": 4
          },
          "indicator_count": 4682,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "16 hours ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "695fd5fa266f9ea34c8f5c45",
          "name": "Cats and Kittens Attack Mirai Botnet and how it may target Threat Exchange users",
          "description": "Cat attacks related to LummaC2 attacks,info stealing, domain seizures, etc. Including are references to the Lumma C2 with cats and Aura Stealer attacks. Same attack group , includes Mirai Botnet. Has the group become a larger , stronger adversary? \nSony Music connection. I\u2019m aware (The US Department of Justice and Microsoft disrupted LummaC2 infostealing-malware through domain seizures, taking down over 2,300 associated domains. The FBI and CISA by AlienVault) Further research necessary.",
          "modified": "2026-02-07T14:04:48.556000",
          "created": "2026-01-08T16:06:18.126000",
          "tags": [
            "levelblue labs",
            "mirai",
            "windows",
            "ck ids",
            "application",
            "network denial",
            "service",
            "contacted",
            "search",
            "unknown",
            "top source",
            "top destination",
            "source source",
            "china as4812",
            "av detections",
            "ids detections",
            "yara detections",
            "alerts",
            "analysis date",
            "enter",
            "udp include",
            "country",
            "unique",
            "unique asns",
            "ip hostname",
            "reverse ip",
            "lookup country",
            "china as17429",
            "taiwan as3462",
            "new caledonia",
            "as18200 office",
            "china as4538",
            "china as9394",
            "india as137654",
            "japan as2514",
            "japan as9365",
            "china as45083",
            "endian",
            "linux",
            "apple",
            "linux subsys",
            "lang c",
            "linenum",
            "lsyms",
            "machine",
            "static",
            "va",
            "os linux",
            "nx",
            "relocs",
            "intel 8038",
            "elf32",
            "malware distribution",
            "domain seizures",
            "infostealing malware",
            "cat-themed domains",
            "gather victim",
            "t1589",
            "t1568",
            "t1590",
            "web protocols",
            "drop resolver",
            "t1568 t1590",
            "show",
            "filehash",
            "md5 add",
            "pulse pulses",
            "copy",
            "affected _and_fixed",
            "thank you"
          ],
          "references": [
            "cat-are-here.ru",
            "Antivirus Detections:  Unix.Trojan.Mirai-10028259-0  | Mirai (ELF) Mirai (Windows",
            "Yara Detections: LZMA",
            "IP\u2019s Contacted: 32.227.223.238 107.74.143.88 69.196.71.159 96.16.197.80  101.80.61.229 125.101.205.34",
            "IP\u2019s Contacted: 16.85.50.206 215.160.125.18 40.71.227.8 57.122.151.130",
            "All Domains Contacted: thekittler.ru newkittler.ru cats-master.ru",
            "https://otx.alienvault.com/indicator/file/b57042ed9a7d7dbe1f7c7f32de74d2b367ee835d",
            "https://otx.alienvault.com/indicator/domain/cat-are-here.ru",
            "CloudFlare IP\u2019s: 104.18.36.237 ,104.18.37.237",
            "CloudFlare Domain: apple-dns.net",
            "Cloudflare URL: https://forms.sonymusicfans.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js",
            "https://forms.sonymusicfans.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js",
            "http://213.209.143.24/ppc \u2022  http://213.209.143.24/rep.i486 \u2022  http://213.209.143.24/rep.sh4",
            "http://213.209.143.24/x32 \u2022 https://250-mail.simswap.in \u2022  https://mail.simswap.in",
            "http://kittler.ru/arm5 \u2022  http://kittler.ru/mpsl \u2022 http://thekittler.ru/rep.arm7",
            "http://kittler.ru/rep.sh4 \u2022  http://kittler.ru/x32 \u2022 http://cats-master.ru/x86_64",
            "sonymusicfans.com \u2022 forms.sonymusicfans.com \u2022 image.emails.sonymusicfans.com \u2022 url8878.e.sonymusicfans.com",
            "https://forms.sonymusicfans.com/campaign/cannons-all-i-need-pre-add-pre-save/",
            "https://forms.sonymusicfans.com/wp-content/plugins/smf-core/assets/css/campaign_333c4e8b19a72989caf8.css",
            "https://view.emails.sonymusicfans.com/Error.aspx",
            "URL http://url8878.e.sonymusicfans.com/ls/click \u2022 https://forms.sonymusicfans.com/campaign/all",
            "http://url8878.e.sonymusicfans.com/ \u2022 http://url8878.e.sonymusicfans.com/ls/click",
            "https://forms.sonymusicfans.com/campaign/all \u2022 https://forms.sonymusicfans.com/campaign/mmph/",
            "https://image.emails.sonymusicfans.com/lib/fe9a12747566007d70/m/1/eb6e3ce4-7a7b-4435-a2cd-968f7277e6e0.png",
            "https://image.emails.sonymusicfans.com/lib/fe9412747566057a72/m/1/b381d305-8e17-49be-bc99-e5fab3a7cd17.gif",
            "push.apple.com \u2022 emails.redvue.com \u2022 apple-dns.net \u2022 57.122.151.130 \u2022 https://teja8.kuikr.com/i6/20181130/Apple",
            "Tracking LummaC2 Infrastructure with Cats (byAlienVault) https://otx.alienvault.com/pulse/6839003a3028827e1ebbfb1a",
            "Interesting relationships: LummaC2 , Mirai Botnet , Sony Music Group , Apple",
            "https://otx.alienvault.com/pulse/694898db3a9999fecfd893cb"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai (ELF)",
              "display_name": "Mirai (ELF)",
              "target": null
            },
            {
              "id": "Mirai (Windows)",
              "display_name": "Mirai (Windows)",
              "target": null
            },
            {
              "id": "Unix.Trojan.Mirai-10028259-0",
              "display_name": "Unix.Trojan.Mirai-10028259-0",
              "target": null
            },
            {
              "id": "Unix.Trojan.Gafgyt-6981160-0",
              "display_name": "Unix.Trojan.Gafgyt-6981160-0",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1595",
              "name": "Active Scanning",
              "display_name": "T1595 - Active Scanning"
            },
            {
              "id": "TA0001",
              "name": "Initial Access",
              "display_name": "TA0001 - Initial Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1589",
              "name": "Gather Victim Identity Information",
              "display_name": "T1589 - Gather Victim Identity Information"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1584.001",
              "name": "Domains",
              "display_name": "T1584.001 - Domains"
            },
            {
              "id": "T1102.001",
              "name": "Dead Drop Resolver",
              "display_name": "T1102.001 - Dead Drop Resolver"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 74,
            "FileHash-SHA1": 74,
            "FileHash-SHA256": 1067,
            "URL": 2140,
            "domain": 247,
            "hostname": 674,
            "CVE": 2
          },
          "indicator_count": 4278,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 147,
          "modified_text": "116 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68be993e9615b0e3e813b707",
          "name": "MalBeacon - Apple Tor Project | Hostile",
          "description": "Google.com is the world's largest web server, with an address address of 2.5 million users.. and a domain of 1.6 million servers. \u00c2\u00a31.3bn",
          "modified": "2025-10-08T08:03:50.685000",
          "created": "2025-09-08T08:52:14.428000",
          "tags": [
            "present mar",
            "present aug",
            "present jun",
            "france unknown",
            "present jan",
            "present dec",
            "present may",
            "present apr",
            "passive dns",
            "tor exit",
            "ipv4",
            "reverse dns",
            "location france",
            "france asn",
            "as15557",
            "courier",
            "accept",
            "genco labs",
            "comments",
            "authority",
            "fileversion",
            "g2 c",
            "llc st",
            "md5 add",
            "lowfi",
            "united",
            "backdoor",
            "win32",
            "hacktool",
            "trojan",
            "present sep",
            "aaaa",
            "moved",
            "ip address",
            "apache",
            "ipv4 add",
            "america flag",
            "gaithersburg",
            "united states",
            "yara detections",
            "malware",
            "port",
            "destination",
            "read c",
            "msie",
            "windows nt",
            "wow64",
            "hostile",
            "write",
            "markus",
            "local",
            "unknown",
            "apple",
            "urls",
            "domain",
            "x apple",
            "unknown aaaa",
            "hostname add",
            "files",
            "files ip",
            "delete c",
            "crlf line",
            "cheat service",
            "checkin",
            "high",
            "total",
            "delete",
            "python",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "spawns",
            "command",
            "found",
            "defense evasion",
            "t1480 execution",
            "command decode",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "general",
            "path",
            "click",
            "strings",
            "meta",
            "thus",
            "contact",
            "main",
            "dynamicloader",
            "medium",
            "wine emulator",
            "dynamic",
            "reads",
            "patchcache",
            "pe section",
            "code overlap",
            "blackie virus",
            "intel",
            "ms windows",
            "pe32",
            "regsetvalueexa",
            "regdword",
            "pe32 executable",
            "delphi",
            "dock",
            "execution",
            "explorer",
            "next",
            "evasion att",
            "file defense",
            "dynamic api",
            "discovery att",
            "prefetch8",
            "prefetch1",
            "mitre att",
            "ck matrix",
            "localappdata",
            "yara signature",
            "process",
            "a domains",
            "malbeacon",
            "about contact",
            "portal open",
            "menu close",
            "menu home",
            "content home",
            "portal",
            "beaconing",
            "internet",
            "dark",
            "type indicator",
            "added active",
            "related pulses",
            "url https",
            "url http",
            "china unknown",
            "location china",
            "china asn",
            "as174 cogent",
            "twitter",
            "virgin islands",
            "creation date",
            "germany unknown",
            "unknown ns",
            "domain add",
            "tulach type",
            "response ip",
            "address google",
            "safe browsing",
            "status",
            "search",
            "date",
            "name servers",
            "showing",
            "record value",
            "error",
            "code",
            "content type",
            "access",
            "length",
            "title",
            "mtb may",
            "useragent",
            "next associated",
            "gmt cache",
            "sameorigin",
            "mozilla",
            "trojandropper",
            "monitored target",
            "packed"
          ],
          "references": [
            "80.125.71.115",
            "Yara Detections: Armadillov171",
            "https://malbeacon.com/",
            "prod-lt-playstoregatewayadapter-pa.googleapis.com \u2022 redirector.gvt1.com \u2022 torexit.net-137.ampr.org"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Win.Trojan.Shodi",
              "display_name": "Win.Trojan.Shodi",
              "target": null
            },
            {
              "id": "HackTool:Win64/Patcher!MSR",
              "display_name": "HackTool:Win64/Patcher!MSR",
              "target": "/malware/HackTool:Win64/Patcher!MSR"
            },
            {
              "id": "Win.Malware.Lazy",
              "display_name": "Win.Malware.Lazy",
              "target": null
            },
            {
              "id": "VirTool:MSIL/CryptInject.YA!MTB",
              "display_name": "VirTool:MSIL/CryptInject.YA!MTB",
              "target": "/malware/VirTool:MSIL/CryptInject.YA!MTB"
            },
            {
              "id": "Ransom:Win32/Gojdue",
              "display_name": "Ransom:Win32/Gojdue",
              "target": "/malware/Ransom:Win32/Gojdue"
            },
            {
              "id": "ALF:HeraklezEval:TrojanDownloader:HTML/Adodb",
              "display_name": "ALF:HeraklezEval:TrojanDownloader:HTML/Adodb",
              "target": null
            },
            {
              "id": "Meredrop",
              "display_name": "Meredrop",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "AutoRun",
              "display_name": "AutoRun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1067",
              "name": "Bootkit",
              "display_name": "T1067 - Bootkit"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 852,
            "FileHash-MD5": 508,
            "FileHash-SHA1": 407,
            "FileHash-SHA256": 4566,
            "URL": 3778,
            "domain": 789,
            "email": 8,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 10910,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 149,
          "modified_text": "238 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68be67235f5f2397b6c0f8f1",
          "name": "Deauth - https://otx.alienvault.com/pulse/682a36a50c5a60afa9d2f754",
          "description": "",
          "modified": "2025-09-08T05:18:27.530000",
          "created": "2025-09-08T05:18:27.530000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "682a36a50c5a60afa9d2f754",
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 77,
            "FileHash-MD5": 115,
            "FileHash-SHA1": 115,
            "FileHash-SHA256": 1378,
            "URL": 16,
            "hostname": 202
          },
          "indicator_count": 1903,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "268 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6830ca10f16af5c6c7110161",
          "name": "Malware Hosting || Apple browser agent transmits data to New Relic",
          "description": "IOC (https://www.delphi.ai/bill-clinton)Title: Delphi: || application-name\nDelphi\nmask-icon\n/safari-pinned-tab.svg?v=2 (favicons is a line of code that loads another SVG image, one called safari-pinned-tab. svg . to support Safari's pinned tab functionality, which existed before other browsers had SVG favicon support.)||\n\u2022142.251.143.202- exploit_source  |\t\t \n\u2022185.199.108.133 - malware_hosting |\t\n*185.199.109.133 - malware_hosting. |\n\u2022185.199.110.133 - malware_hosting | \nhttps://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian -phishing |\n185.199.111.133\nmalware_hosting\t\n|| malicious features,, malicious code, .ai , exploit, spyware, apple monitoring nr-data.net > transmits data to New Relic, || IIOC may have expired or be parked.",
          "modified": "2025-06-22T18:05:31.015000",
          "created": "2025-05-23T19:18:40.395000",
          "tags": [
            "delphi meta",
            "tags viewport",
            "delphi maskicon",
            "utc google",
            "tag manager",
            "gtmmszhw3t7",
            "utc g3j5p98dsnr",
            "utc linkedin",
            "insight tag",
            "date sun",
            "gmt contenttype",
            "connection",
            "cachecontrol",
            "slug",
            "miss",
            "server",
            "status code",
            "body length",
            "kb body"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 120,
            "FileHash-SHA1": 120,
            "FileHash-SHA256": 579,
            "URL": 8,
            "domain": 12,
            "hostname": 45
          },
          "indicator_count": 884,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "346 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "682a36a50c5a60afa9d2f754",
          "name": "On Apple iOS device - update 18.5 | 80.125.71.115 | | Malicious Google\u2019sorry index\u2019",
          "description": "RMS MODULE attack on individuals iOS newly purchased devices. Apple updates ineffective. \nCloud backups to other unknown devices only. Attacker aimed a Deauther/ Signal jamming watch aimed at target while was parked on residential street in a city in USA . \nPhishing\nHosts contacted \nSSH credential attacks\nDESCRIPTION: An adversary coming from this source IP address controlled a botnet.\n*tulach\n#targeting\nTags: #malware #adversary #attribution\nMore Information: https://MalBeacon.com\nSociete Francaise Du Radiotelephone - SFR SA",
          "modified": "2025-06-17T19:02:57.604000",
          "created": "2025-05-18T19:36:03.066000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 77,
            "FileHash-MD5": 115,
            "FileHash-SHA1": 115,
            "FileHash-SHA256": 1378,
            "URL": 16,
            "hostname": 202
          },
          "indicator_count": 1903,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 145,
          "modified_text": "351 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.forbes.com/consent/ketch/?toURL=https://www.forbes.com/2009/07/28/hackers-iphone-apple-technology-security-hackers.html",
        "Yara Detections: Armadillov171",
        "Win.Malware.Gamehack-6822792-0 IDS Detections Riskware/Cheathappens Checkin (songculture attack)",
        "Sigma: Matches rule Suspicious Outbound SMTP Connections by frack113",
        "https://malbeacon.com/",
        "IDS Detections: Win32/Vflooder.B Checkin \u2022 Generic HTTP EXE Upload Inbound \u2022 Generic HTTP EXE Upload Outbound",
        "https://www.linkedin.com/posts/any-run_systembc-rat-explorewithanyrun-activity-7289971333671645184-Sefp/?utm_source=share&utm_medium=member_ios RULE_AUTHOR: X__Junior",
        "IP\u2019s Contacted: 16.85.50.206 215.160.125.18 40.71.227.8 57.122.151.130",
        "IP\u2019s Contacted 162.159.140.229  34.54.88.138",
        "https://image.emails.sonymusicfans.com/lib/fe9412747566057a72/m/1/b381d305-8e17-49be-bc99-e5fab3a7cd17.gif",
        "Interesting relationships: LummaC2 , Mirai Botnet , Sony Music Group , Apple",
        "(Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
        "Yara Detections: UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser",
        "blackbox21.shop",
        "Alerts: network_cnc_http network_http packer_unknown_pe_section_name injection_rwx dead_connect exec_crash",
        "sonymusicfans.com \u2022 forms.sonymusicfans.com \u2022 image.emails.sonymusicfans.com \u2022 url8878.e.sonymusicfans.com",
        "CloudFlare Domain: apple-dns.net",
        "Alerts: procmem_yara suricata_alert dynamic_function_loading network_cnc_https_generic reads_self",
        "https://forms.sonymusicfans.com/campaign/cannons-all-i-need-pre-add-pre-save/",
        "Domains Contacted: checkip.amazonaws.com vk.com arena.ai www.yandex.ru stripchat.com",
        "? Con*-cted jp-\u0661\u0660\u0661\u0660\u0660\u0660.--- \u0644\u062d\u0645\u0627",
        "passwordreset.gscs.ca  \u2022 https://passwordreset.gscs.ca/",
        "Go BuildID=qBC61D7N3q3H7j2Pq55o/WsPsx2ArOJ0T24axAUMZ/K6isHEI8QMyAMkIM3HH8/QQevOAoeyrO7eZGdBARa,",
        "All Domains Contacted: thekittler.ru newkittler.ru cats-master.ru",
        "FileHash-SHA256 9da8632065cc24646086ff5fb769c452f777aa6c2470a02a16d209baabd1e4b5",
        "http://213.209.143.24/x32 \u2022 https://250-mail.simswap.in \u2022  https://mail.simswap.in",
        "TelfHash t135324a7149bc74b5b6a6d910b3a3b4b8a6772d6566f434f51023ad84ffc1e801ce283b",
        "IP\u2019s Contacted: 212.227.17.162  77.88.44.55  142.93.142.17  104.18.14.206",
        "push.apple.com \u2022 emails.redvue.com \u2022 apple-dns.net \u2022 57.122.151.130 \u2022 https://teja8.kuikr.com/i6/20181130/Apple",
        "storage/analyses/1000549/network 9da8632065cc24646086f f5 fb769c45\"",
        "Yara Detections: LZMA",
        "IP\u2019s Contacted: 104.17.118.12  57.144.248.1  176.114.120.24  80.12.24.14  95.163.61.73  142.251.98.113",
        "cat-are-here.ru",
        "https://docs.cursor.com/en/cli/reference/slash-commands",
        "https://otx.alienvault.com/indicator/domain/cat-are-here.ru",
        "Antivirus Detections:  Unix.Trojan.Mirai-10028259-0  | Mirai (ELF) Mirai (Windows",
        "nr-data.net \u2022 push.apple.com",
        "80.125.71.115",
        "prod-lt-playstoregatewayadapter-pa.googleapis.com \u2022 redirector.gvt1.com \u2022 torexit.net-137.ampr.org",
        "Matches rule SURICATA Applayer Detect protocol only one direction virustotal.com",
        "beacons.bcp.gvt.com \u2022 http://vtboss.yolox.net/md5.php \u2022 finanse.mf.gov.pl",
        "https://forms.sonymusicfans.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js",
        "Win.Malware.Vtflooder-9783271-0 -> Domains Contacted twitter.com www.virustotal.com",
        "http://213.209.143.24/ppc \u2022  http://213.209.143.24/rep.i486 \u2022  http://213.209.143.24/rep.sh4",
        "FileHash-SHA256 756f0b598741a6fdff640a158b6b490472e546d411da2850836b9a8ca76afdc1",
        "DESCRIPTION: Detects systembc RAT REFERENCE: https://www.linkedin.com/posts/any-run_systembc-rat-explorewithanyrun-activity-7289971333671645184-Sefp/?utm_source=share&utm_medium=member_ios RULE_AUTHOR: X__Junior",
        "https://twitter.com/PORNO_SEXYBABES \u2022 twitter.com",
        "Vtflooder-9783271-0 -> 7476476bdc93726f46f75f5bdd5ce6c619d73f7ee82b7d93ad835c993ff14661",
        "Yara Detections: SUSP_Imphash_Mar23_2 ,  UPX ,  Nrv2x ,  UPX_OEP_place ,   ,   UPXv20MarkusLaszloReiser",
        "http://kittler.ru/rep.sh4 \u2022  http://kittler.ru/x32 \u2022 http://cats-master.ru/x86_64",
        "Names: testpaging \u2022 upof6w.exe \u2022 2026-04-07_259af8b0d0bc540384a06bb730cee9cd_qnapcrypt",
        "http://url8878.e.sonymusicfans.com/ \u2022 http://url8878.e.sonymusicfans.com/ls/click",
        "IP\u2019s Contacted: 32.227.223.238 107.74.143.88 69.196.71.159 96.16.197.80  101.80.61.229 125.101.205.34",
        "Yara Detections: is__elf IP\u2019s",
        "Yara Detections: UPX20030XMarkusOberhumerLaszloMolnarJohnReiser",
        "https://sexfortokens.com/hotmilfbitch",
        "Crowdsourced IDS: ET DROP Spamhaus Listed Traffic Inbound group 60",
        "URL http://url8878.e.sonymusicfans.com/ls/click \u2022 https://forms.sonymusicfans.com/campaign/all",
        "Suspicious DNS Query for IP Lookup Service APls by Brandon George (blog post) Thomas Patzke",
        "CloudFlare IP\u2019s: 104.18.36.237 ,104.18.37.237",
        "Cloudflare URL: https://forms.sonymusicfans.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js",
        "https://grok.com/imagine/agent/d5e99582-a7e7-4138-b129-780e171ba9ac",
        "cdn10.mypornvid.fun impacted a targeted individual",
        "https://stripchat.org/ \u2022  27bsmextreme.tech \u2022 35bsmextreme.tech  \u2022 46bsmextreme.tech  \u2022",
        "Matches rule ET INFO External IP Check (checkip.amazonaws.com)",
        "ET HUNTING Suspicious User-Agent Observed (Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
        "BuildID[sha1]=068f07f6460b85817e4be47c18c10d1a1fbef817, stripped",
        "https://click.italiansexclub.fun/click/HpdeyDt6",
        "Tracking LummaC2 Infrastructure with Cats (byAlienVault) https://otx.alienvault.com/pulse/6839003a3028827e1ebbfb1a",
        "ELF - ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked,",
        "https://image.emails.sonymusicfans.com/lib/fe9a12747566007d70/m/1/eb6e3ce4-7a7b-4435-a2cd-968f7277e6e0.png",
        "Matches rule ET INFO External IP Lookup Domain in DNS Lookup (checkip amazonaws .com)",
        "alberta.ca impacts an OTX user",
        "https://view.emails.sonymusicfans.com/Error.aspx",
        "https://forms.sonymusicfans.com/wp-content/plugins/smf-core/assets/css/campaign_333c4e8b19a72989caf8.css",
        "https://forms.sonymusicfans.com/campaign/all \u2022 https://forms.sonymusicfans.com/campaign/mmph/",
        "https://otx.alienvault.com/indicator/file/b57042ed9a7d7dbe1f7c7f32de74d2b367ee835d",
        "https://arena.ai/apple-touch-icon-dark.png",
        "motherlesslive.com",
        "https://otx.alienvault.com/pulse/694898db3a9999fecfd893cb",
        "https://api.cursor.com/v0/agents/",
        "http://kittler.ru/arm5 \u2022  http://kittler.ru/mpsl \u2022 http://thekittler.ru/rep.arm7"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Win.malware.vtflooder-6722904-1",
            "Hacktool:win64/patcher!msr",
            "Meredrop",
            "Mirai (elf)",
            "Win.malware.gamehack-6822792-0",
            "Win.malware.lazy",
            "Virtool:msil/cryptinject.ya!mtb",
            "Unix.trojan.gafgyt-6981160-0",
            "Ransom:win32/gojdue",
            "Mirai (windows)",
            "Trojan.systembc/yxgdgz",
            "Tulach",
            "Alf:heraklezeval:trojandownloader:html/adodb",
            "Trojan:win32/vflooder",
            "Autorun",
            "Cve-2025-20393",
            "Qnapcrypt",
            "Cve-2023-22518",
            "Unix.trojan.mirai-10028259-0",
            "Win.trojan.shodi",
            "Cve-2024-6387"
          ],
          "industries": [
            "Telecommunications"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "6a1fc3671bc3d0f5ce8b06e6",
      "name": "Grok \u2022 X \u2022 Twitter Vflooder | SystemBC | QNAPCrypt",
      "description": "I continue to research issues affecting iOS and other smart devices, browsers, search engines and targeted individuals.\nI will limit my comments as further evaluation is required. Twitter appears to be used as a weapon to abuse of several targeted persons and their schools or businesses. Research is required to determine how. Is Twitter / X a weapon or is it abused by threat actors. Ongoing attacks dating back at least 5 years. || \n*DESCRIPTION: Detects systembc RAT REFERENCE: https://www.linkedin.com/posts/any-run_systembc-rat-explorewithanyrun-activity-7289971333671645184-Sefp/?utm_source=share&utm_medium=member_ios RULE_AUTHOR: X__Junior\n\n#malicious #spyware #twitter #x #ai_ agents #seen_before #systembc #vtflooder #qnapcrypt #cve #checkin #scripiting #injection #extraction #gobinary #operation",
      "modified": "2026-06-03T06:02:15.229000",
      "created": "2026-06-03T06:02:15.229000",
      "tags": [
        "sysv",
        "buildid",
        "united",
        "windows nt",
        "msie",
        "germany as8560",
        "yara detections",
        "contacted",
        "z74457024643q1",
        "systembc",
        "trojan",
        "elf executable",
        "exec amd6464",
        "linux",
        "elf64 operation",
        "unix",
        "compiler",
        "debugging",
        "go binary",
        "injection",
        "header elf64",
        "v exec",
        "executable file",
        "advanced micro",
        "note",
        "strtab",
        "gmbh",
        "gandi sas",
        "group india",
        "private limited",
        "qnapcrypt",
        "hacktool",
        "chrome",
        "yandex",
        "stripchat",
        "amazonaws",
        "mal_elf_systembc",
        "apple ios",
        "ios",
        "apple",
        "telhash",
        "data upload",
        "cursor",
        "se data",
        "extraction",
        "n https",
        "data",
        "failed",
        "cve cve20246387",
        "log id",
        "gmtn",
        "path",
        "secure",
        "self",
        "samesitenone",
        "encrypt",
        "d8n timestamp",
        "timestamp",
        "organization",
        "false",
        "certificate",
        "search",
        "emails",
        "twitter",
        "twitter spyware",
        "twitter vtflooder",
        "x",
        "unknown aaaa",
        "present jun",
        "ip address",
        "belize unknown",
        "unknown ns",
        "grok x",
        "cursor agents",
        "ai",
        "url url",
        "url hostnams",
        "hostn url",
        "url data",
        "belize",
        "a domains",
        "moved",
        "alone email",
        "gmt server",
        "url analysis",
        "accept",
        "namecheap",
        "namecheap inc",
        "namesilo",
        "expim",
        "url https",
        "dynamicloader",
        "host",
        "ff d5",
        "yara rule",
        "ee fc",
        "generic http",
        "exe upload",
        "f0 ff",
        "eb e1",
        "write",
        "vflooder",
        "malware",
        "upload inbound",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "checkin generic",
        "http exe",
        "upload inbound",
        "outbound yara",
        "nrv2x",
        "upxoepplace",
        "google",
        "adversaries",
        "adversarial attacks",
        "techniques",
        "create",
        "modify system",
        "process t1064",
        "t1543 systemd",
        "technir create",
        "full reports",
        "v tcp",
        "help",
        "ja3 digests",
        "hashes o",
        "et http",
        "get http",
        "post http",
        "dns resolutions",
        "cams",
        "adult content",
        "ff bb",
        "ff ff",
        "f7 b9",
        "c1 e8",
        "copy",
        "markus",
        "august",
        "title",
        "gamehack",
        "alberta.ca",
        "songculture",
        "lizardsquad"
      ],
      "references": [
        "FileHash-SHA256 756f0b598741a6fdff640a158b6b490472e546d411da2850836b9a8ca76afdc1",
        "TelfHash t135324a7149bc74b5b6a6d910b3a3b4b8a6772d6566f434f51023ad84ffc1e801ce283b",
        "Names: testpaging \u2022 upof6w.exe \u2022 2026-04-07_259af8b0d0bc540384a06bb730cee9cd_qnapcrypt",
        "Yara Detections: is__elf IP\u2019s",
        "IP\u2019s Contacted: 104.17.118.12  57.144.248.1  176.114.120.24  80.12.24.14  95.163.61.73  142.251.98.113",
        "IP\u2019s Contacted: 212.227.17.162  77.88.44.55  142.93.142.17  104.18.14.206",
        "Domains Contacted: checkip.amazonaws.com vk.com arena.ai www.yandex.ru stripchat.com",
        "ELF - ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked,",
        "Go BuildID=qBC61D7N3q3H7j2Pq55o/WsPsx2ArOJ0T24axAUMZ/K6isHEI8QMyAMkIM3HH8/QQevOAoeyrO7eZGdBARa,",
        "BuildID[sha1]=068f07f6460b85817e4be47c18c10d1a1fbef817, stripped",
        "motherlesslive.com",
        "blackbox21.shop",
        "passwordreset.gscs.ca  \u2022 https://passwordreset.gscs.ca/",
        "alberta.ca impacts an OTX user",
        "https://stripchat.org/ \u2022  27bsmextreme.tech \u2022 35bsmextreme.tech  \u2022 46bsmextreme.tech  \u2022",
        "FileHash-SHA256 9da8632065cc24646086ff5fb769c452f777aa6c2470a02a16d209baabd1e4b5",
        "storage/analyses/1000549/network 9da8632065cc24646086f f5 fb769c45\"",
        "? Con*-cted jp-\u0661\u0660\u0661\u0660\u0660\u0660.--- \u0644\u062d\u0645\u0627",
        "https://arena.ai/apple-touch-icon-dark.png",
        "https://www.forbes.com/consent/ketch/?toURL=https://www.forbes.com/2009/07/28/hackers-iphone-apple-technology-security-hackers.html",
        "nr-data.net \u2022 push.apple.com",
        "https://twitter.com/PORNO_SEXYBABES \u2022 twitter.com",
        "Vtflooder-9783271-0 -> 7476476bdc93726f46f75f5bdd5ce6c619d73f7ee82b7d93ad835c993ff14661",
        "Win.Malware.Vtflooder-9783271-0 -> Domains Contacted twitter.com www.virustotal.com",
        "IP\u2019s Contacted 162.159.140.229  34.54.88.138",
        "IDS Detections: Win32/Vflooder.B Checkin \u2022 Generic HTTP EXE Upload Inbound \u2022 Generic HTTP EXE Upload Outbound",
        "Yara Detections: SUSP_Imphash_Mar23_2 ,  UPX ,  Nrv2x ,  UPX_OEP_place ,   ,   UPXv20MarkusLaszloReiser",
        "Yara Detections: UPX20030XMarkusOberhumerLaszloMolnarJohnReiser",
        "Yara Detections: UPXV200V290MarkusOberhumerLaszloMolnarJohnReiser",
        "Alerts: procmem_yara suricata_alert dynamic_function_loading network_cnc_https_generic reads_self",
        "Alerts: network_cnc_http network_http packer_unknown_pe_section_name injection_rwx dead_connect exec_crash",
        "Sigma: Matches rule Suspicious Outbound SMTP Connections by frack113",
        "Suspicious DNS Query for IP Lookup Service APls by Brandon George (blog post) Thomas Patzke",
        "Crowdsourced IDS: ET DROP Spamhaus Listed Traffic Inbound group 60",
        "Matches rule ET INFO External IP Lookup Domain in DNS Lookup (checkip amazonaws .com)",
        "Matches rule ET INFO External IP Check (checkip.amazonaws.com)",
        "ET HUNTING Suspicious User-Agent Observed (Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
        "(Mozilla/5.0 (Windows NT XX.X Win64 x64) AppleWebKit/XXX.XX)",
        "Matches rule SURICATA Applayer Detect protocol only one direction virustotal.com",
        "DESCRIPTION: Detects systembc RAT REFERENCE: https://www.linkedin.com/posts/any-run_systembc-rat-explorewithanyrun-activity-7289971333671645184-Sefp/?utm_source=share&utm_medium=member_ios RULE_AUTHOR: X__Junior",
        "https://www.linkedin.com/posts/any-run_systembc-rat-explorewithanyrun-activity-7289971333671645184-Sefp/?utm_source=share&utm_medium=member_ios RULE_AUTHOR: X__Junior",
        "https://docs.cursor.com/en/cli/reference/slash-commands",
        "https://api.cursor.com/v0/agents/",
        "https://grok.com/imagine/agent/d5e99582-a7e7-4138-b129-780e171ba9ac",
        "beacons.bcp.gvt.com \u2022 http://vtboss.yolox.net/md5.php \u2022 finanse.mf.gov.pl",
        "cdn10.mypornvid.fun impacted a targeted individual",
        "https://click.italiansexclub.fun/click/HpdeyDt6",
        "https://sexfortokens.com/hotmilfbitch",
        "Win.Malware.Gamehack-6822792-0 IDS Detections Riskware/Cheathappens Checkin (songculture attack)"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Trojan.Systembc/yxgdgz",
          "display_name": "Trojan.Systembc/yxgdgz",
          "target": null
        },
        {
          "id": "CVE-2023-22518",
          "display_name": "CVE-2023-22518",
          "target": null
        },
        {
          "id": "CVE-2024-6387",
          "display_name": "CVE-2024-6387",
          "target": null
        },
        {
          "id": "CVE-2025-20393",
          "display_name": "CVE-2025-20393",
          "target": null
        },
        {
          "id": "Win.Malware.Vtflooder-6722904-1",
          "display_name": "Win.Malware.Vtflooder-6722904-1",
          "target": null
        },
        {
          "id": "Trojan:Win32/Vflooder",
          "display_name": "Trojan:Win32/Vflooder",
          "target": "/malware/Trojan:Win32/Vflooder"
        },
        {
          "id": "QNAPCrypt",
          "display_name": "QNAPCrypt",
          "target": null
        },
        {
          "id": "Win.Malware.Gamehack-6822792-0",
          "display_name": "Win.Malware.Gamehack-6822792-0",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "TA0028",
          "name": "Persistence",
          "display_name": "TA0028 - Persistence"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "T1543.002",
          "name": "Systemd Service",
          "display_name": "T1543.002 - Systemd Service"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "T1457",
          "name": "Malicious Media Content",
          "display_name": "T1457 - Malicious Media Content"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1587.001",
          "name": "Malware",
          "display_name": "T1587.001 - Malware"
        },
        {
          "id": "T1468",
          "name": "Remotely Track Device Without Authorization",
          "display_name": "T1468 - Remotely Track Device Without Authorization"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1262,
        "FileHash-MD5": 164,
        "FileHash-SHA1": 207,
        "IPv4": 180,
        "URL": 1780,
        "domain": 370,
        "hostname": 708,
        "CVE": 3,
        "email": 4,
        "SSLCertFingerprint": 4
      },
      "indicator_count": 4682,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "16 hours ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "695fd5fa266f9ea34c8f5c45",
      "name": "Cats and Kittens Attack Mirai Botnet and how it may target Threat Exchange users",
      "description": "Cat attacks related to LummaC2 attacks,info stealing, domain seizures, etc. Including are references to the Lumma C2 with cats and Aura Stealer attacks. Same attack group , includes Mirai Botnet. Has the group become a larger , stronger adversary? \nSony Music connection. I\u2019m aware (The US Department of Justice and Microsoft disrupted LummaC2 infostealing-malware through domain seizures, taking down over 2,300 associated domains. The FBI and CISA by AlienVault) Further research necessary.",
      "modified": "2026-02-07T14:04:48.556000",
      "created": "2026-01-08T16:06:18.126000",
      "tags": [
        "levelblue labs",
        "mirai",
        "windows",
        "ck ids",
        "application",
        "network denial",
        "service",
        "contacted",
        "search",
        "unknown",
        "top source",
        "top destination",
        "source source",
        "china as4812",
        "av detections",
        "ids detections",
        "yara detections",
        "alerts",
        "analysis date",
        "enter",
        "udp include",
        "country",
        "unique",
        "unique asns",
        "ip hostname",
        "reverse ip",
        "lookup country",
        "china as17429",
        "taiwan as3462",
        "new caledonia",
        "as18200 office",
        "china as4538",
        "china as9394",
        "india as137654",
        "japan as2514",
        "japan as9365",
        "china as45083",
        "endian",
        "linux",
        "apple",
        "linux subsys",
        "lang c",
        "linenum",
        "lsyms",
        "machine",
        "static",
        "va",
        "os linux",
        "nx",
        "relocs",
        "intel 8038",
        "elf32",
        "malware distribution",
        "domain seizures",
        "infostealing malware",
        "cat-themed domains",
        "gather victim",
        "t1589",
        "t1568",
        "t1590",
        "web protocols",
        "drop resolver",
        "t1568 t1590",
        "show",
        "filehash",
        "md5 add",
        "pulse pulses",
        "copy",
        "affected _and_fixed",
        "thank you"
      ],
      "references": [
        "cat-are-here.ru",
        "Antivirus Detections:  Unix.Trojan.Mirai-10028259-0  | Mirai (ELF) Mirai (Windows",
        "Yara Detections: LZMA",
        "IP\u2019s Contacted: 32.227.223.238 107.74.143.88 69.196.71.159 96.16.197.80  101.80.61.229 125.101.205.34",
        "IP\u2019s Contacted: 16.85.50.206 215.160.125.18 40.71.227.8 57.122.151.130",
        "All Domains Contacted: thekittler.ru newkittler.ru cats-master.ru",
        "https://otx.alienvault.com/indicator/file/b57042ed9a7d7dbe1f7c7f32de74d2b367ee835d",
        "https://otx.alienvault.com/indicator/domain/cat-are-here.ru",
        "CloudFlare IP\u2019s: 104.18.36.237 ,104.18.37.237",
        "CloudFlare Domain: apple-dns.net",
        "Cloudflare URL: https://forms.sonymusicfans.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js",
        "https://forms.sonymusicfans.com/cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js",
        "http://213.209.143.24/ppc \u2022  http://213.209.143.24/rep.i486 \u2022  http://213.209.143.24/rep.sh4",
        "http://213.209.143.24/x32 \u2022 https://250-mail.simswap.in \u2022  https://mail.simswap.in",
        "http://kittler.ru/arm5 \u2022  http://kittler.ru/mpsl \u2022 http://thekittler.ru/rep.arm7",
        "http://kittler.ru/rep.sh4 \u2022  http://kittler.ru/x32 \u2022 http://cats-master.ru/x86_64",
        "sonymusicfans.com \u2022 forms.sonymusicfans.com \u2022 image.emails.sonymusicfans.com \u2022 url8878.e.sonymusicfans.com",
        "https://forms.sonymusicfans.com/campaign/cannons-all-i-need-pre-add-pre-save/",
        "https://forms.sonymusicfans.com/wp-content/plugins/smf-core/assets/css/campaign_333c4e8b19a72989caf8.css",
        "https://view.emails.sonymusicfans.com/Error.aspx",
        "URL http://url8878.e.sonymusicfans.com/ls/click \u2022 https://forms.sonymusicfans.com/campaign/all",
        "http://url8878.e.sonymusicfans.com/ \u2022 http://url8878.e.sonymusicfans.com/ls/click",
        "https://forms.sonymusicfans.com/campaign/all \u2022 https://forms.sonymusicfans.com/campaign/mmph/",
        "https://image.emails.sonymusicfans.com/lib/fe9a12747566007d70/m/1/eb6e3ce4-7a7b-4435-a2cd-968f7277e6e0.png",
        "https://image.emails.sonymusicfans.com/lib/fe9412747566057a72/m/1/b381d305-8e17-49be-bc99-e5fab3a7cd17.gif",
        "push.apple.com \u2022 emails.redvue.com \u2022 apple-dns.net \u2022 57.122.151.130 \u2022 https://teja8.kuikr.com/i6/20181130/Apple",
        "Tracking LummaC2 Infrastructure with Cats (byAlienVault) https://otx.alienvault.com/pulse/6839003a3028827e1ebbfb1a",
        "Interesting relationships: LummaC2 , Mirai Botnet , Sony Music Group , Apple",
        "https://otx.alienvault.com/pulse/694898db3a9999fecfd893cb"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai (ELF)",
          "display_name": "Mirai (ELF)",
          "target": null
        },
        {
          "id": "Mirai (Windows)",
          "display_name": "Mirai (Windows)",
          "target": null
        },
        {
          "id": "Unix.Trojan.Mirai-10028259-0",
          "display_name": "Unix.Trojan.Mirai-10028259-0",
          "target": null
        },
        {
          "id": "Unix.Trojan.Gafgyt-6981160-0",
          "display_name": "Unix.Trojan.Gafgyt-6981160-0",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1595",
          "name": "Active Scanning",
          "display_name": "T1595 - Active Scanning"
        },
        {
          "id": "TA0001",
          "name": "Initial Access",
          "display_name": "TA0001 - Initial Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1589",
          "name": "Gather Victim Identity Information",
          "display_name": "T1589 - Gather Victim Identity Information"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1584.001",
          "name": "Domains",
          "display_name": "T1584.001 - Domains"
        },
        {
          "id": "T1102.001",
          "name": "Dead Drop Resolver",
          "display_name": "T1102.001 - Dead Drop Resolver"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 74,
        "FileHash-SHA1": 74,
        "FileHash-SHA256": 1067,
        "URL": 2140,
        "domain": 247,
        "hostname": 674,
        "CVE": 2
      },
      "indicator_count": 4278,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 147,
      "modified_text": "116 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68be993e9615b0e3e813b707",
      "name": "MalBeacon - Apple Tor Project | Hostile",
      "description": "Google.com is the world's largest web server, with an address address of 2.5 million users.. and a domain of 1.6 million servers. \u00c2\u00a31.3bn",
      "modified": "2025-10-08T08:03:50.685000",
      "created": "2025-09-08T08:52:14.428000",
      "tags": [
        "present mar",
        "present aug",
        "present jun",
        "france unknown",
        "present jan",
        "present dec",
        "present may",
        "present apr",
        "passive dns",
        "tor exit",
        "ipv4",
        "reverse dns",
        "location france",
        "france asn",
        "as15557",
        "courier",
        "accept",
        "genco labs",
        "comments",
        "authority",
        "fileversion",
        "g2 c",
        "llc st",
        "md5 add",
        "lowfi",
        "united",
        "backdoor",
        "win32",
        "hacktool",
        "trojan",
        "present sep",
        "aaaa",
        "moved",
        "ip address",
        "apache",
        "ipv4 add",
        "america flag",
        "gaithersburg",
        "united states",
        "yara detections",
        "malware",
        "port",
        "destination",
        "read c",
        "msie",
        "windows nt",
        "wow64",
        "hostile",
        "write",
        "markus",
        "local",
        "unknown",
        "apple",
        "urls",
        "domain",
        "x apple",
        "unknown aaaa",
        "hostname add",
        "files",
        "files ip",
        "delete c",
        "crlf line",
        "cheat service",
        "checkin",
        "high",
        "total",
        "delete",
        "python",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "spawns",
        "command",
        "found",
        "defense evasion",
        "t1480 execution",
        "command decode",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "general",
        "path",
        "click",
        "strings",
        "meta",
        "thus",
        "contact",
        "main",
        "dynamicloader",
        "medium",
        "wine emulator",
        "dynamic",
        "reads",
        "patchcache",
        "pe section",
        "code overlap",
        "blackie virus",
        "intel",
        "ms windows",
        "pe32",
        "regsetvalueexa",
        "regdword",
        "pe32 executable",
        "delphi",
        "dock",
        "execution",
        "explorer",
        "next",
        "evasion att",
        "file defense",
        "dynamic api",
        "discovery att",
        "prefetch8",
        "prefetch1",
        "mitre att",
        "ck matrix",
        "localappdata",
        "yara signature",
        "process",
        "a domains",
        "malbeacon",
        "about contact",
        "portal open",
        "menu close",
        "menu home",
        "content home",
        "portal",
        "beaconing",
        "internet",
        "dark",
        "type indicator",
        "added active",
        "related pulses",
        "url https",
        "url http",
        "china unknown",
        "location china",
        "china asn",
        "as174 cogent",
        "twitter",
        "virgin islands",
        "creation date",
        "germany unknown",
        "unknown ns",
        "domain add",
        "tulach type",
        "response ip",
        "address google",
        "safe browsing",
        "status",
        "search",
        "date",
        "name servers",
        "showing",
        "record value",
        "error",
        "code",
        "content type",
        "access",
        "length",
        "title",
        "mtb may",
        "useragent",
        "next associated",
        "gmt cache",
        "sameorigin",
        "mozilla",
        "trojandropper",
        "monitored target",
        "packed"
      ],
      "references": [
        "80.125.71.115",
        "Yara Detections: Armadillov171",
        "https://malbeacon.com/",
        "prod-lt-playstoregatewayadapter-pa.googleapis.com \u2022 redirector.gvt1.com \u2022 torexit.net-137.ampr.org"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Win.Trojan.Shodi",
          "display_name": "Win.Trojan.Shodi",
          "target": null
        },
        {
          "id": "HackTool:Win64/Patcher!MSR",
          "display_name": "HackTool:Win64/Patcher!MSR",
          "target": "/malware/HackTool:Win64/Patcher!MSR"
        },
        {
          "id": "Win.Malware.Lazy",
          "display_name": "Win.Malware.Lazy",
          "target": null
        },
        {
          "id": "VirTool:MSIL/CryptInject.YA!MTB",
          "display_name": "VirTool:MSIL/CryptInject.YA!MTB",
          "target": "/malware/VirTool:MSIL/CryptInject.YA!MTB"
        },
        {
          "id": "Ransom:Win32/Gojdue",
          "display_name": "Ransom:Win32/Gojdue",
          "target": "/malware/Ransom:Win32/Gojdue"
        },
        {
          "id": "ALF:HeraklezEval:TrojanDownloader:HTML/Adodb",
          "display_name": "ALF:HeraklezEval:TrojanDownloader:HTML/Adodb",
          "target": null
        },
        {
          "id": "Meredrop",
          "display_name": "Meredrop",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "AutoRun",
          "display_name": "AutoRun",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1067",
          "name": "Bootkit",
          "display_name": "T1067 - Bootkit"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 852,
        "FileHash-MD5": 508,
        "FileHash-SHA1": 407,
        "FileHash-SHA256": 4566,
        "URL": 3778,
        "domain": 789,
        "email": 8,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 10910,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 149,
      "modified_text": "238 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68be67235f5f2397b6c0f8f1",
      "name": "Deauth - https://otx.alienvault.com/pulse/682a36a50c5a60afa9d2f754",
      "description": "",
      "modified": "2025-09-08T05:18:27.530000",
      "created": "2025-09-08T05:18:27.530000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "682a36a50c5a60afa9d2f754",
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 77,
        "FileHash-MD5": 115,
        "FileHash-SHA1": 115,
        "FileHash-SHA256": 1378,
        "URL": 16,
        "hostname": 202
      },
      "indicator_count": 1903,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "268 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6830ca10f16af5c6c7110161",
      "name": "Malware Hosting || Apple browser agent transmits data to New Relic",
      "description": "IOC (https://www.delphi.ai/bill-clinton)Title: Delphi: || application-name\nDelphi\nmask-icon\n/safari-pinned-tab.svg?v=2 (favicons is a line of code that loads another SVG image, one called safari-pinned-tab. svg . to support Safari's pinned tab functionality, which existed before other browsers had SVG favicon support.)||\n\u2022142.251.143.202- exploit_source  |\t\t \n\u2022185.199.108.133 - malware_hosting |\t\n*185.199.109.133 - malware_hosting. |\n\u2022185.199.110.133 - malware_hosting | \nhttps://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian -phishing |\n185.199.111.133\nmalware_hosting\t\n|| malicious features,, malicious code, .ai , exploit, spyware, apple monitoring nr-data.net > transmits data to New Relic, || IIOC may have expired or be parked.",
      "modified": "2025-06-22T18:05:31.015000",
      "created": "2025-05-23T19:18:40.395000",
      "tags": [
        "delphi meta",
        "tags viewport",
        "delphi maskicon",
        "utc google",
        "tag manager",
        "gtmmszhw3t7",
        "utc g3j5p98dsnr",
        "utc linkedin",
        "insight tag",
        "date sun",
        "gmt contenttype",
        "connection",
        "cachecontrol",
        "slug",
        "miss",
        "server",
        "status code",
        "body length",
        "kb body"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 120,
        "FileHash-SHA1": 120,
        "FileHash-SHA256": 579,
        "URL": 8,
        "domain": 12,
        "hostname": 45
      },
      "indicator_count": 884,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "346 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "682a36a50c5a60afa9d2f754",
      "name": "On Apple iOS device - update 18.5 | 80.125.71.115 | | Malicious Google\u2019sorry index\u2019",
      "description": "RMS MODULE attack on individuals iOS newly purchased devices. Apple updates ineffective. \nCloud backups to other unknown devices only. Attacker aimed a Deauther/ Signal jamming watch aimed at target while was parked on residential street in a city in USA . \nPhishing\nHosts contacted \nSSH credential attacks\nDESCRIPTION: An adversary coming from this source IP address controlled a botnet.\n*tulach\n#targeting\nTags: #malware #adversary #attribution\nMore Information: https://MalBeacon.com\nSociete Francaise Du Radiotelephone - SFR SA",
      "modified": "2025-06-17T19:02:57.604000",
      "created": "2025-05-18T19:36:03.066000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 77,
        "FileHash-MD5": 115,
        "FileHash-SHA1": 115,
        "FileHash-SHA256": 1378,
        "URL": 16,
        "hostname": 202
      },
      "indicator_count": 1903,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 145,
      "modified_text": "351 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "mtext.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "mtext.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780524309.5286295
}