{
  "type": "Domain",
  "indicator": "patternapplauderw.shop",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/patternapplauderw.shop",
    "alexa": "http://www.alexa.com/siteinfo/patternapplauderw.shop",
    "indicator": "patternapplauderw.shop",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3901752044,
      "indicator": "patternapplauderw.shop",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 24,
      "pulses": [
        {
          "id": "6723f395217b63c2bbdfc819",
          "name": "Threat actors use copyright infringement phishing lure to deploy infostealers",
          "description": "An unknown threat actor is conducting a phishing campaign targeting Facebook business and advertising account users in Taiwan. The campaign uses emails impersonating legal departments, claiming copyright infringement to lure victims into downloading malware. The attackers abuse Google's Appspot domains, short URLs, and Dropbox to deliver information stealers, employing various evasion techniques. The malware includes LummaC2 and Rhadamanthys stealers, which are embedded in legitimate binaries. The campaign specifically targets traditional Chinese speakers and uses well-known company names in Taiwan and Hong Kong to increase credibility. The infection chain involves encrypted archives, fake PDF executables, and sophisticated loaders that employ anti-analysis techniques and ensure persistence on infected systems.",
          "modified": "2024-11-01T17:25:51.972000",
          "created": "2024-10-31T21:16:05.513000",
          "tags": [
            "infostealer",
            "phishing",
            "facebook",
            "rhadamanthys",
            "evasion",
            "lummac2",
            "copyright",
            "taiwan",
            "obfuscation"
          ],
          "references": [
            "https://blog.talosintelligence.com/threat-actors-use-copyright-infringement-phishing-lure-to-deploy-infostealers/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Hong Kong",
            "Taiwan"
          ],
          "malware_families": [
            {
              "id": "LummaC2",
              "display_name": "LummaC2",
              "target": null
            },
            {
              "id": "Rhadamanthys",
              "display_name": "Rhadamanthys",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1053.005",
              "name": "Scheduled Task",
              "display_name": "T1053.005 - Scheduled Task"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1573.001",
              "name": "Symmetric Cryptography",
              "display_name": "T1573.001 - Symmetric Cryptography"
            },
            {
              "id": "T1566.001",
              "name": "Spearphishing Attachment",
              "display_name": "T1566.001 - Spearphishing Attachment"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027.001",
              "name": "Binary Padding",
              "display_name": "T1027.001 - Binary Padding"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1102.002",
              "name": "Bidirectional Communication",
              "display_name": "T1102.002 - Bidirectional Communication"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1055.001",
              "name": "Dynamic-link Library Injection",
              "display_name": "T1055.001 - Dynamic-link Library Injection"
            }
          ],
          "industries": [
            "Media",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 53,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 23,
            "domain": 35
          },
          "indicator_count": 60,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386454,
          "modified_text": "575 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c8523d0dd3d95ed18e5555",
          "name": "Decoding the Stealthy Memory-Only Malware",
          "description": "This intelligence report provides an in-depth analysis of a complex, multi-stage malware campaign called PEAKLIGHT. It details the infection chain, starting with movie lure ZIP files containing malicious LNK files that initiate a JavaScript dropper. This dropper then executes a PowerShell downloader script, PEAKLIGHT, responsible for retrieving additional payloads from a content delivery network. The report examines different variations of PEAKLIGHT and the malware it delivers, including LUMMAC.V2, SHADOWLADDER, and CRYPTBOT. The analysis highlights the obfuscation techniques employed by the threat actors, such as system binary proxy execution and CDN abuse.",
          "modified": "2024-09-22T09:06:06.424000",
          "created": "2024-08-23T09:11:24.544000",
          "tags": [
            "lummac.v2",
            "javascript",
            "infostealer",
            "shadowladder",
            "obfuscation",
            "malware",
            "cryptbot",
            "powershell"
          ],
          "references": [
            "https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "LUMMAC.V2",
              "display_name": "LUMMAC.V2",
              "target": null
            },
            {
              "id": "CRYPTBOT",
              "display_name": "CRYPTBOT",
              "target": null
            },
            {
              "id": "SHADOWLADDER",
              "display_name": "SHADOWLADDER",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1218.005",
              "name": "Mshta",
              "display_name": "T1218.005 - Mshta"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 209,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 22,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 4,
            "URL": 6,
            "domain": 12
          },
          "indicator_count": 48,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386453,
          "modified_text": "615 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a168016405a2c708172810",
          "name": "The tapestry of threats targeting Hamster Kombat players",
          "description": "This analysis delves into the various malicious threats capitalizing on the immense popularity of the Hamster Kombat mobile game. It reveals that cybercriminals are exploiting players' interests by distributing Android spyware disguised as the game through unofficial channels, as well as creating fake app stores delivering unwanted ads. Additionally, it uncovers GitHub repositories purporting to offer automation tools but actually containing Windows-based Lumma Stealer cryptors. The report serves as a cautionary tale about the risks of obtaining games and software from unverified sources.",
          "modified": "2024-08-23T20:04:28.012000",
          "created": "2024-07-24T20:45:53.535000",
          "tags": [
            "spyware",
            "android"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/tap-estry-threats-targeting-hamster-kombat-players/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Ratel",
              "display_name": "Ratel",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            },
            {
              "id": "T1055.012",
              "name": "Process Hollowing",
              "display_name": "T1055.012 - Process Hollowing"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 259,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 18,
            "domain": 24
          },
          "indicator_count": 42,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386454,
          "modified_text": "645 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a1340291e4d22ac1862e84",
          "name": "Stargazers Ghost Network",
          "description": "Check Point Research identified a sophisticated network of GitHub accounts distributing malware through malicious repositories. The Stargazers Ghost Network consists of different types of accounts performing various actions like starring, forking, and subscribing to give an appearance of legitimacy. This network functions as a Distribution as a Service (DaaS), allowing threat actors to share malicious content. The operator, tracked as Stargazer Goblin, provides and maintains the network, distributing malware families like Atlantida Stealer, Rhadamanthys, Lumma Stealer, and RedLine. With over 3,000 active Ghost accounts, the network has earned an estimated $100,000 since its inception in August 2022. This new era of malware distribution utilizes ghost accounts across platforms, potentially employing AI for targeted campaigns.",
          "modified": "2024-08-23T17:00:14.164000",
          "created": "2024-07-24T17:04:02.942000",
          "tags": [
            "botnets",
            "infostealers"
          ],
          "references": [
            "https://research.checkpoint.com/2024/stargazers-ghost-network/"
          ],
          "public": 1,
          "adversary": "Stargazer Goblin",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Atlantida Stealer",
              "display_name": "Atlantida Stealer",
              "target": null
            },
            {
              "id": "Rhadamanthys",
              "display_name": "Rhadamanthys",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "RisePro",
              "display_name": "RisePro",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1086",
              "name": "PowerShell",
              "display_name": "T1086 - PowerShell"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 290,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 11,
            "domain": 21
          },
          "indicator_count": 38,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386455,
          "modified_text": "645 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "691b8869e00b107fa20d9482",
          "name": "ThreatFix",
          "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
          "modified": "2026-01-23T11:01:07.175000",
          "created": "2025-11-17T20:41:11.797000",
          "tags": [
            "",
            "ransomware",
            "malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "",
              "display_name": "",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "zlepos384",
            "id": "103244",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8010,
            "FileHash-SHA1": 7922,
            "FileHash-SHA256": 8893,
            "URL": 57004,
            "domain": 36018,
            "hostname": 96473
          },
          "indicator_count": 214320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "127 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "688b0dde98e8d32361238f0f",
          "name": "Emmenhtal Loader Campaign deliver various payloads                                         [IMEBEEIMFINE]",
          "description": "",
          "modified": "2025-08-29T09:03:58.967000",
          "created": "2025-07-31T06:31:58.326000",
          "tags": [],
          "references": [
            "Emmenhtal.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6889ebeb317457163ab8fa42",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 395,
            "BitcoinAddress": 1,
            "CVE": 6,
            "FileHash-MD5": 240,
            "FileHash-SHA1": 123,
            "FileHash-SHA256": 392,
            "domain": 182,
            "email": 1,
            "hostname": 181
          },
          "indicator_count": 1521,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6889ebeb317457163ab8fa42",
          "name": "Emmenhtal loader",
          "description": "Campaigns that used Emmenhtal to deliver various payloads",
          "modified": "2025-08-29T09:03:58.967000",
          "created": "2025-07-30T09:54:51.943000",
          "tags": [],
          "references": [
            "Emmenhtal.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 395,
            "BitcoinAddress": 1,
            "CVE": 6,
            "FileHash-MD5": 240,
            "FileHash-SHA1": 123,
            "FileHash-SHA256": 392,
            "domain": 182,
            "email": 1,
            "hostname": 181
          },
          "indicator_count": 1521,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 42,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "672f6ed2b564f00b7c5cb13f",
          "name": "Threatfox Recent Additions",
          "description": "",
          "modified": "2025-06-13T19:00:02.811000",
          "created": "2024-11-09T14:16:50.032000",
          "tags": [],
          "references": [
            "",
            "https://threatfox.abuse.ch/export/csv/recent/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 96,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ameermane",
            "id": "77501",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 47587,
            "URL": 18714,
            "FileHash-SHA256": 36311,
            "FileHash-MD5": 1630,
            "FileHash-SHA1": 418,
            "hostname": 18190
          },
          "indicator_count": 122850,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 144,
          "modified_text": "351 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67617edafa11fa408b73322c",
          "name": "ACTIVIDAD MALICIOSA | Relacionada con Lumma Stealer 17-12-2024",
          "description": "Lumma Stealer es un tipo de software malicioso dise\u00f1ado para robar informaci\u00f3n confidencial de los dispositivos infectados. Este malware se infiltra en los sistemas y extrae datos personales, como nombres de usuario, contrase\u00f1as, informaci\u00f3n bancaria y detalles de tarjetas de cr\u00e9dito. LummaStealer puede afectar varias cuentas, incluidas redes sociales, correos electr\u00f3nicos y monederos de criptomonedas. Los delincuentes pueden usar la informaci\u00f3n robada para chantaje, suplantaci\u00f3n de identidad, y realizar transacciones fraudulentas, lo que puede causar serios problemas de privacidad y p\u00e9rdidas econ\u00f3micas significativas para las v\u00edctimas.",
          "modified": "2025-01-16T13:03:38.406000",
          "created": "2024-12-17T13:38:34.760000",
          "tags": [
            "access",
            "discovery",
            "ta0001 initial",
            "t1003 data",
            "local system",
            "t1033 system",
            "t1057 process",
            "t1082 system",
            "t1087 account"
          ],
          "references": [
            "https://darfe.es/ciberwiki/index.php?title=Lumma",
            "https://www.virustotal.com/graph/embed/gec57b97e0f194fd38738be6392abba6f180fe9d93be24891af76fb2c7bec3638?theme=dark",
            "https://www.virustotal.com/gui/collection/bf70caf191025dfa3e68e8bc63882880ae2ca60f72ece512aaee246b487c5ad6"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "esoporteingenieria2020",
            "id": "121604",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA1": 25,
            "FileHash-SHA256": 27,
            "URL": 301,
            "domain": 665,
            "hostname": 8
          },
          "indicator_count": 1052,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 267,
          "modified_text": "499 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "674c9f48cd2a512e28ef6523",
          "name": "ACTIVIDAD MALICIOSA | Relacionada con LummaStealer 01-12-2024",
          "description": "Lumma Stealer es un tipo de software malicioso dise\u00f1ado para robar informaci\u00f3n confidencial de los dispositivos infectados. Este malware se infiltra en los sistemas y extrae datos personales, como nombres de usuario, contrase\u00f1as, informaci\u00f3n bancaria y detalles de tarjetas de cr\u00e9dito. LummaStealer puede afectar varias cuentas, incluidas redes sociales, correos electr\u00f3nicos y monederos de criptomonedas. Los delincuentes pueden usar la informaci\u00f3n robada para chantaje, suplantaci\u00f3n de identidad, y realizar transacciones fraudulentas, lo que puede causar serios problemas de privacidad y p\u00e9rdidas econ\u00f3micas significativas para las v\u00edctimas.",
          "modified": "2024-12-31T17:05:00.863000",
          "created": "2024-12-01T17:39:20.573000",
          "tags": [
            "http",
            "access",
            "discovery",
            "uexfvbqog9i67m",
            "mmirygls1g",
            "vt51x7b9cwn7e4x",
            "v2fnqdfylkobc",
            "tcticas",
            "ta0001 initial",
            "t1003 data"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g31920c46027f42a085f0a4040c4609fcccba0ba580b3451893964f393d84ac65?theme=dark",
            "https://www.virustotal.com/gui/collection/9419ada66b99877877ab2cbbe22a5e2de65cd18153db39736cb4fe1d06cc1129",
            "https://darfe.es/ciberwiki/index.php?title=Lumma"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "esoporteingenieria2020",
            "id": "121604",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1161,
            "FileHash-SHA1": 1159,
            "FileHash-SHA256": 1167,
            "URL": 255,
            "domain": 665,
            "hostname": 8
          },
          "indicator_count": 4415,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 266,
          "modified_text": "515 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "672de9e87b6aed420bc96128",
          "name": "Threat actors use copyright infringement phishing lure to deploy infostealers",
          "description": "A round-up of the latest research from security firm Cisco Talos, as part of its annual security review, on the subject of copyright infringement and cyber-security, and the threat posed by an unknown threat actor.",
          "modified": "2024-12-08T10:02:06.586000",
          "created": "2024-11-08T10:37:28.217000",
          "tags": [
            "threat spotlight",
            "threats",
            "redacted",
            "lummac2",
            "cisco secure",
            "rar file",
            "information",
            "taiwan",
            "eps file",
            "lummac2 stealer",
            "rhadamanthys",
            "google",
            "facebook",
            "virustotal",
            "umbrella",
            "medusalocker"
          ],
          "references": [
            "https://blog.talosintelligence.com/threat-actors-use-copyright-infringement-phishing-lure-to-deploy-infostealers/",
            "https://raw.githubusercontent.com/Cisco-Talos/IOCs/refs/heads/main/2024/10/threat-actors-use-copyright-infringement-phishing-lure-to-deploy-infostealers.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Taiwan"
          ],
          "malware_families": [
            {
              "id": "MedusaLocker",
              "display_name": "MedusaLocker",
              "target": null
            },
            {
              "id": "LummaC2",
              "display_name": "LummaC2",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            }
          ],
          "industries": [
            "Industrial"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 22,
            "FileHash-SHA1": 22,
            "FileHash-SHA256": 23,
            "URL": 2,
            "domain": 35
          },
          "indicator_count": 104,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "538 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67289dbcf153559e9a657bc4",
          "name": "Xi\u016b g\u01d2u Phishing Campaign Spreads Across Five Nations",
          "description": "",
          "modified": "2024-12-04T10:01:42.870000",
          "created": "2024-11-04T10:11:08.652000",
          "tags": [
            "urls"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 22,
            "FileHash-SHA1": 22,
            "FileHash-SHA256": 23,
            "URL": 2,
            "domain": 497,
            "hostname": 13
          },
          "indicator_count": 579,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 499,
          "modified_text": "542 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67429f73a3f45fa88890276d",
          "name": "StreamMining",
          "description": "",
          "modified": "2024-11-24T03:37:23.616000",
          "created": "2024-11-24T03:37:23.616000",
          "tags": [
            "eliminar",
            "leer ms",
            "wishlist vista",
            "poltica",
            "secadores",
            "vista",
            "sala",
            "vaporal",
            "utensilios",
            "belleza equipos",
            "ciudad"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "670f94e03014212e19fa5a77",
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "rivocado",
            "id": "300960",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "URL": 170,
            "domain": 11158,
            "hostname": 3549
          },
          "indicator_count": 14883,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 25,
          "modified_text": "552 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67429f7224d433f384b935c8",
          "name": "StreamMining",
          "description": "",
          "modified": "2024-11-24T03:37:22.551000",
          "created": "2024-11-24T03:37:22.551000",
          "tags": [
            "eliminar",
            "leer ms",
            "wishlist vista",
            "poltica",
            "secadores",
            "vista",
            "sala",
            "vaporal",
            "utensilios",
            "belleza equipos",
            "ciudad"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "670f94e03014212e19fa5a77",
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "rivocado",
            "id": "300960",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "URL": 170,
            "domain": 11158,
            "hostname": 3549
          },
          "indicator_count": 14883,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 20,
          "modified_text": "552 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "670f94e03014212e19fa5a77",
          "name": "Malicious-Dangerous-Domain&URL-New-IOC List",
          "description": "By Helaly",
          "modified": "2024-11-15T10:01:11.688000",
          "created": "2024-10-16T10:26:40.893000",
          "tags": [
            "eliminar",
            "leer ms",
            "wishlist vista",
            "poltica",
            "secadores",
            "vista",
            "sala",
            "vaporal",
            "utensilios",
            "belleza equipos",
            "ciudad"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 39659,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Eslam-ElHelaly",
            "id": "259630",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_259630/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "URL": 170,
            "domain": 11158,
            "hostname": 3549
          },
          "indicator_count": 14883,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 80,
          "modified_text": "561 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66cfad5b197151f30fff52d4",
          "name": "PEAKLIGHT Malware Decoding the Stealthy Memory",
          "description": "IOC{Indicators of Compromise} - a full list of the key words and phrases used to describe a person's position on a subject of political or social change.. and.",
          "modified": "2024-09-27T23:05:06.750000",
          "created": "2024-08-28T23:06:03.184000",
          "tags": [
            "compromise",
            "domains",
            "urls"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 17,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 15,
            "URL": 15,
            "domain": 12,
            "hostname": 4
          },
          "indicator_count": 78,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 499,
          "modified_text": "609 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66cd83c0717511523a98ec1e",
          "name": "PEAKLIGHT: Decoding the Stealthy Memory-Only Malware | Google Cloud Blog",
          "description": "A security firm, Mandiant, has identified a new method of distributing malware-as-a-service, and identified the final downloader for the malware, known as PEAKLIGHT.",
          "modified": "2024-09-26T07:01:24.325000",
          "created": "2024-08-27T07:44:00.648000",
          "tags": [
            "powershell",
            "base64",
            "stealth",
            "configuration",
            "variation",
            "base64 decoding",
            "decompression",
            "ecb mode",
            "gzip",
            "powershell code",
            "logic",
            "base64-encoded",
            "cryptbot.autoit",
            "lummac.v2",
            "shadowladder",
            "javascript",
            "peaklight"
          ],
          "references": [
            "https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Base64-Encoded",
              "display_name": "Base64-Encoded",
              "target": null
            },
            {
              "id": "CRYPTBOT.AUTOIT",
              "display_name": "CRYPTBOT.AUTOIT",
              "target": null
            },
            {
              "id": "LummaC.V2",
              "display_name": "LummaC.V2",
              "target": null
            },
            {
              "id": "SHADOWLADDER",
              "display_name": "SHADOWLADDER",
              "target": null
            },
            {
              "id": "JavaScript",
              "display_name": "JavaScript",
              "target": null
            },
            {
              "id": "PEAKLIGHT",
              "display_name": "PEAKLIGHT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 22,
            "FileHash-SHA1": 20,
            "FileHash-SHA256": 20,
            "URL": 19,
            "domain": 13,
            "hostname": 4
          },
          "indicator_count": 98,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "611 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6654198962e43dc463f692c2",
          "name": "DOH IP & URL IOC",
          "description": "The following is the full text of the report on the findings of this year's World Cup in Brazil, which was held at the same time as the 2016 Olympics in Rio de Janeiro, Brazil.",
          "modified": "2024-09-25T04:01:33.267000",
          "created": "2024-05-27T05:26:33.698000",
          "tags": [
            "iocs https"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 59,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fueledbycoffeeDXB",
            "id": "272228",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 270,
            "CIDR": 1,
            "domain": 116,
            "hostname": 33,
            "FileHash-MD5": 1
          },
          "indicator_count": 421,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 31,
          "modified_text": "612 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c8d7a891f033f73d62091f",
          "name": "New Memory-Only Malware Dropper, PEAKLIGHT, Discovered",
          "description": "A sophisticated, memory-only malware dropper named PEAKLIGHT, discovered by Mandiant, has emerged as a serious threat due to its ability to evade detection and deliver malware-as-a-service (MaaS) infostealers across various sectors.\n\nPEAKLIGHT's advanced multi-stage attack, which exploits legitimate utilities and content delivery networks, highlights a concerning shift in cyber threats, making it difficult to detect and eradicate. PEAKLIGHT escalates the risk of data breaches, particularly in high-value sectors, presenting a significant challenge to cyber resilience.",
          "modified": "2024-09-22T18:03:57.639000",
          "created": "2024-08-23T18:40:40.424000",
          "tags": [
            "threattype/malware",
            "malwaretype/Dropper",
            "threattype/Malware Delivery",
            "malwaretype/Memory-only",
            "threattype/LNK File",
            "industries/all industries"
          ],
          "references": [
            "https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "PEAKLIGHT",
              "display_name": "PEAKLIGHT",
              "target": null
            },
            {
              "id": "SHADOWLADDER",
              "display_name": "SHADOWLADDER",
              "target": null
            },
            {
              "id": "CryptBot",
              "display_name": "CryptBot",
              "target": null
            },
            {
              "id": "LummaC",
              "display_name": "LummaC",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1218.005",
              "name": "Mshta",
              "display_name": "T1218.005 - Mshta"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "eric.ford",
            "id": "42510",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_42510/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 18,
            "domain": 12
          },
          "indicator_count": 30,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 130,
          "modified_text": "615 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c8b54dacf0a8b428859db3",
          "name": "PEAKLIGHT: Decoding the Stealthy Memory-Only Malware | Google Cloud Blog",
          "description": "",
          "modified": "2024-09-22T16:04:24.657000",
          "created": "2024-08-23T16:14:05.119000",
          "tags": [
            "powershell",
            "base64",
            "stealth",
            "configuration",
            "variation",
            "base64 decoding",
            "decompression",
            "ecb mode",
            "gzip",
            "powershell code",
            "logic"
          ],
          "references": [
            "https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AustinBH",
            "id": "147442",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 22,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 4,
            "URL": 19,
            "domain": 12,
            "hostname": 4
          },
          "indicator_count": 65,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "615 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a304aad2c34800518cddff",
          "name": "Stargazers Ghost Network Distributes Malicious Links and Malware",
          "description": "",
          "modified": "2024-08-25T02:00:19.116000",
          "created": "2024-07-26T02:06:34.150000",
          "tags": [
            "hashes",
            "sha256",
            "cyber",
            "threat",
            "july",
            "time",
            "crypto cyber",
            "defence",
            "classification",
            "domains"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 9,
            "FileHash-SHA1": 9,
            "FileHash-SHA256": 11,
            "URL": 19,
            "domain": 19
          },
          "indicator_count": 67,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 499,
          "modified_text": "643 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a23f4012f93523c0e63160",
          "name": "Hamster Kombat Users are Targeted by Threat Actors",
          "description": "The full list of names and names of people who have made headlines over the past 12 months has been released.. and it's not easy to identify. the ones that have done the job.",
          "modified": "2024-08-24T12:01:46.240000",
          "created": "2024-07-25T12:04:16.024000",
          "tags": [
            "domains"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 11,
            "FileHash-SHA1": 19,
            "FileHash-SHA256": 11,
            "domain": 25
          },
          "indicator_count": 66,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 500,
          "modified_text": "644 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a214de6866b58132771967",
          "name": "Stargazers Ghost Network - Check Point Research",
          "description": "",
          "modified": "2024-08-24T09:03:31.766000",
          "created": "2024-07-25T09:03:26.825000",
          "tags": [
            "github",
            "ghost",
            "network",
            "gmt4",
            "check point",
            "research",
            "rhadamanthys",
            "ghost network",
            "gmt0",
            "github ghost",
            "twitch",
            "august",
            "discord",
            "service",
            "risepro",
            "download",
            "span",
            "lumma stealer",
            "malware",
            "null",
            "dllimport",
            "twitter",
            "goblin",
            "redline",
            "chat",
            "python",
            "form",
            "powershell",
            "stealer",
            "victor",
            "phishing",
            "crack",
            "template",
            "february",
            "june",
            "facebook"
          ],
          "references": [
            "https://research.checkpoint.com/2024/stargazers-ghost-network/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "bluenumberone",
            "id": "246058",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 10,
            "FileHash-SHA1": 10,
            "FileHash-SHA256": 14,
            "URL": 30,
            "domain": 23,
            "hostname": 2
          },
          "indicator_count": 89,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "644 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a20f4ba9460da5b00a193e",
          "name": "Stargazers Ghost Network - Check Point Research",
          "description": "Check Point Research has identified a network of \u201cGhost\u201d accounts that distribute malware via phishing repositories on the web, and is tracking the group behind the operation, which could be worth as much as $100,000.",
          "modified": "2024-08-24T08:05:53.769000",
          "created": "2024-07-25T08:39:39.811000",
          "tags": [
            "github",
            "ghost",
            "network",
            "gmt4",
            "check point",
            "research",
            "rhadamanthys",
            "ghost network",
            "gmt0",
            "github ghost",
            "twitch",
            "august",
            "discord",
            "service",
            "risepro",
            "download",
            "span",
            "lumma stealer",
            "malware",
            "null",
            "dllimport",
            "twitter",
            "goblin",
            "redline",
            "chat",
            "python",
            "form",
            "powershell",
            "stealer",
            "victor",
            "phishing",
            "crack",
            "template",
            "february",
            "june",
            "facebook",
            "threat",
            "win32.redline",
            "lumma",
            "go",
            "atlantida"
          ],
          "references": [
            "https://research.checkpoint.com/2024/stargazers-ghost-network/"
          ],
          "public": 1,
          "adversary": "Threat",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GitHub",
              "display_name": "GitHub",
              "target": null
            },
            {
              "id": "RisePro",
              "display_name": "RisePro",
              "target": null
            },
            {
              "id": "Rhadamanthys",
              "display_name": "Rhadamanthys",
              "target": null
            },
            {
              "id": "Win32.RedLine",
              "display_name": "Win32.RedLine",
              "target": null
            },
            {
              "id": "Lumma",
              "display_name": "Lumma",
              "target": null
            },
            {
              "id": "GO",
              "display_name": "GO",
              "target": null
            },
            {
              "id": "Atlantida",
              "display_name": "Atlantida",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 10,
            "FileHash-SHA1": 10,
            "FileHash-SHA256": 14,
            "URL": 40,
            "domain": 23,
            "hostname": 2
          },
          "indicator_count": 99,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "644 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/refs/heads/main/2024/10/threat-actors-use-copyright-infringement-phishing-lure-to-deploy-infostealers.txt",
        "https://www.virustotal.com/gui/collection/bf70caf191025dfa3e68e8bc63882880ae2ca60f72ece512aaee246b487c5ad6",
        "https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware/",
        "https://www.virustotal.com/graph/embed/gec57b97e0f194fd38738be6392abba6f180fe9d93be24891af76fb2c7bec3638?theme=dark",
        "https://threatfox.abuse.ch/export/csv/recent/",
        "https://blog.talosintelligence.com/threat-actors-use-copyright-infringement-phishing-lure-to-deploy-infostealers/",
        "https://www.welivesecurity.com/en/eset-research/tap-estry-threats-targeting-hamster-kombat-players/",
        "https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware",
        "https://www.virustotal.com/gui/collection/9419ada66b99877877ab2cbbe22a5e2de65cd18153db39736cb4fe1d06cc1129",
        "https://research.checkpoint.com/2024/stargazers-ghost-network/",
        "https://darfe.es/ciberwiki/index.php?title=Lumma",
        "Emmenhtal.pdf",
        "https://www.virustotal.com/graph/embed/g31920c46027f42a085f0a4040c4609fcccba0ba580b3451893964f393d84ac65?theme=dark"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "Stargazer Goblin"
          ],
          "malware_families": [
            "Rhadamanthys",
            "Cryptbot",
            "Lummac2",
            "Ratel",
            "Atlantida stealer",
            "Shadowladder",
            "Redline",
            "Lumma stealer",
            "Lummac.v2",
            "Risepro"
          ],
          "industries": [
            "Technology",
            "Media"
          ]
        },
        "other": {
          "adversary": [
            "Threat"
          ],
          "malware_families": [
            "",
            "Rhadamanthys",
            "Lumma",
            "Base64-encoded",
            "Shadowladder",
            "Lummac",
            "Risepro",
            "Github",
            "Lummac2",
            "Win32.redline",
            "Cryptbot.autoit",
            "Cryptbot",
            "Medusalocker",
            "Go",
            "Javascript",
            "Atlantida",
            "Lumma stealer",
            "Lummac.v2",
            "Peaklight"
          ],
          "industries": [
            "Industrial"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 24,
  "pulses": [
    {
      "id": "6723f395217b63c2bbdfc819",
      "name": "Threat actors use copyright infringement phishing lure to deploy infostealers",
      "description": "An unknown threat actor is conducting a phishing campaign targeting Facebook business and advertising account users in Taiwan. The campaign uses emails impersonating legal departments, claiming copyright infringement to lure victims into downloading malware. The attackers abuse Google's Appspot domains, short URLs, and Dropbox to deliver information stealers, employing various evasion techniques. The malware includes LummaC2 and Rhadamanthys stealers, which are embedded in legitimate binaries. The campaign specifically targets traditional Chinese speakers and uses well-known company names in Taiwan and Hong Kong to increase credibility. The infection chain involves encrypted archives, fake PDF executables, and sophisticated loaders that employ anti-analysis techniques and ensure persistence on infected systems.",
      "modified": "2024-11-01T17:25:51.972000",
      "created": "2024-10-31T21:16:05.513000",
      "tags": [
        "infostealer",
        "phishing",
        "facebook",
        "rhadamanthys",
        "evasion",
        "lummac2",
        "copyright",
        "taiwan",
        "obfuscation"
      ],
      "references": [
        "https://blog.talosintelligence.com/threat-actors-use-copyright-infringement-phishing-lure-to-deploy-infostealers/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Hong Kong",
        "Taiwan"
      ],
      "malware_families": [
        {
          "id": "LummaC2",
          "display_name": "LummaC2",
          "target": null
        },
        {
          "id": "Rhadamanthys",
          "display_name": "Rhadamanthys",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1053.005",
          "name": "Scheduled Task",
          "display_name": "T1053.005 - Scheduled Task"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1573.001",
          "name": "Symmetric Cryptography",
          "display_name": "T1573.001 - Symmetric Cryptography"
        },
        {
          "id": "T1566.001",
          "name": "Spearphishing Attachment",
          "display_name": "T1566.001 - Spearphishing Attachment"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027.001",
          "name": "Binary Padding",
          "display_name": "T1027.001 - Binary Padding"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1102.002",
          "name": "Bidirectional Communication",
          "display_name": "T1102.002 - Bidirectional Communication"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1055.001",
          "name": "Dynamic-link Library Injection",
          "display_name": "T1055.001 - Dynamic-link Library Injection"
        }
      ],
      "industries": [
        "Media",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 53,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 23,
        "domain": 35
      },
      "indicator_count": 60,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386454,
      "modified_text": "575 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66c8523d0dd3d95ed18e5555",
      "name": "Decoding the Stealthy Memory-Only Malware",
      "description": "This intelligence report provides an in-depth analysis of a complex, multi-stage malware campaign called PEAKLIGHT. It details the infection chain, starting with movie lure ZIP files containing malicious LNK files that initiate a JavaScript dropper. This dropper then executes a PowerShell downloader script, PEAKLIGHT, responsible for retrieving additional payloads from a content delivery network. The report examines different variations of PEAKLIGHT and the malware it delivers, including LUMMAC.V2, SHADOWLADDER, and CRYPTBOT. The analysis highlights the obfuscation techniques employed by the threat actors, such as system binary proxy execution and CDN abuse.",
      "modified": "2024-09-22T09:06:06.424000",
      "created": "2024-08-23T09:11:24.544000",
      "tags": [
        "lummac.v2",
        "javascript",
        "infostealer",
        "shadowladder",
        "obfuscation",
        "malware",
        "cryptbot",
        "powershell"
      ],
      "references": [
        "https://cloud.google.com/blog/topics/threat-intelligence/peaklight-decoding-stealthy-memory-only-malware"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "LUMMAC.V2",
          "display_name": "LUMMAC.V2",
          "target": null
        },
        {
          "id": "CRYPTBOT",
          "display_name": "CRYPTBOT",
          "target": null
        },
        {
          "id": "SHADOWLADDER",
          "display_name": "SHADOWLADDER",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1218.005",
          "name": "Mshta",
          "display_name": "T1218.005 - Mshta"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 209,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 22,
        "FileHash-SHA1": 4,
        "FileHash-SHA256": 4,
        "URL": 6,
        "domain": 12
      },
      "indicator_count": 48,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386453,
      "modified_text": "615 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66a168016405a2c708172810",
      "name": "The tapestry of threats targeting Hamster Kombat players",
      "description": "This analysis delves into the various malicious threats capitalizing on the immense popularity of the Hamster Kombat mobile game. It reveals that cybercriminals are exploiting players' interests by distributing Android spyware disguised as the game through unofficial channels, as well as creating fake app stores delivering unwanted ads. Additionally, it uncovers GitHub repositories purporting to offer automation tools but actually containing Windows-based Lumma Stealer cryptors. The report serves as a cautionary tale about the risks of obtaining games and software from unverified sources.",
      "modified": "2024-08-23T20:04:28.012000",
      "created": "2024-07-24T20:45:53.535000",
      "tags": [
        "spyware",
        "android"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/tap-estry-threats-targeting-hamster-kombat-players/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Ratel",
          "display_name": "Ratel",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        },
        {
          "id": "T1055.012",
          "name": "Process Hollowing",
          "display_name": "T1055.012 - Process Hollowing"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 259,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 18,
        "domain": 24
      },
      "indicator_count": 42,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386454,
      "modified_text": "645 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66a1340291e4d22ac1862e84",
      "name": "Stargazers Ghost Network",
      "description": "Check Point Research identified a sophisticated network of GitHub accounts distributing malware through malicious repositories. The Stargazers Ghost Network consists of different types of accounts performing various actions like starring, forking, and subscribing to give an appearance of legitimacy. This network functions as a Distribution as a Service (DaaS), allowing threat actors to share malicious content. The operator, tracked as Stargazer Goblin, provides and maintains the network, distributing malware families like Atlantida Stealer, Rhadamanthys, Lumma Stealer, and RedLine. With over 3,000 active Ghost accounts, the network has earned an estimated $100,000 since its inception in August 2022. This new era of malware distribution utilizes ghost accounts across platforms, potentially employing AI for targeted campaigns.",
      "modified": "2024-08-23T17:00:14.164000",
      "created": "2024-07-24T17:04:02.942000",
      "tags": [
        "botnets",
        "infostealers"
      ],
      "references": [
        "https://research.checkpoint.com/2024/stargazers-ghost-network/"
      ],
      "public": 1,
      "adversary": "Stargazer Goblin",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Atlantida Stealer",
          "display_name": "Atlantida Stealer",
          "target": null
        },
        {
          "id": "Rhadamanthys",
          "display_name": "Rhadamanthys",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        },
        {
          "id": "RisePro",
          "display_name": "RisePro",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1086",
          "name": "PowerShell",
          "display_name": "T1086 - PowerShell"
        },
        {
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "display_name": "T1490 - Inhibit System Recovery"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 290,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3,
        "FileHash-SHA1": 3,
        "FileHash-SHA256": 11,
        "domain": 21
      },
      "indicator_count": 38,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386455,
      "modified_text": "645 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "691b8869e00b107fa20d9482",
      "name": "ThreatFix",
      "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
      "modified": "2026-01-23T11:01:07.175000",
      "created": "2025-11-17T20:41:11.797000",
      "tags": [
        "",
        "ransomware",
        "malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "",
          "display_name": "",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "zlepos384",
        "id": "103244",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8010,
        "FileHash-SHA1": 7922,
        "FileHash-SHA256": 8893,
        "URL": 57004,
        "domain": 36018,
        "hostname": 96473
      },
      "indicator_count": 214320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "127 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "688b0dde98e8d32361238f0f",
      "name": "Emmenhtal Loader Campaign deliver various payloads                                         [IMEBEEIMFINE]",
      "description": "",
      "modified": "2025-08-29T09:03:58.967000",
      "created": "2025-07-31T06:31:58.326000",
      "tags": [],
      "references": [
        "Emmenhtal.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6889ebeb317457163ab8fa42",
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 395,
        "BitcoinAddress": 1,
        "CVE": 6,
        "FileHash-MD5": 240,
        "FileHash-SHA1": 123,
        "FileHash-SHA256": 392,
        "domain": 182,
        "email": 1,
        "hostname": 181
      },
      "indicator_count": 1521,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "274 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6889ebeb317457163ab8fa42",
      "name": "Emmenhtal loader",
      "description": "Campaigns that used Emmenhtal to deliver various payloads",
      "modified": "2025-08-29T09:03:58.967000",
      "created": "2025-07-30T09:54:51.943000",
      "tags": [],
      "references": [
        "Emmenhtal.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 27,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 395,
        "BitcoinAddress": 1,
        "CVE": 6,
        "FileHash-MD5": 240,
        "FileHash-SHA1": 123,
        "FileHash-SHA256": 392,
        "domain": 182,
        "email": 1,
        "hostname": 181
      },
      "indicator_count": 1521,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 42,
      "modified_text": "274 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "672f6ed2b564f00b7c5cb13f",
      "name": "Threatfox Recent Additions",
      "description": "",
      "modified": "2025-06-13T19:00:02.811000",
      "created": "2024-11-09T14:16:50.032000",
      "tags": [],
      "references": [
        "",
        "https://threatfox.abuse.ch/export/csv/recent/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 96,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ameermane",
        "id": "77501",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 47587,
        "URL": 18714,
        "FileHash-SHA256": 36311,
        "FileHash-MD5": 1630,
        "FileHash-SHA1": 418,
        "hostname": 18190
      },
      "indicator_count": 122850,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 144,
      "modified_text": "351 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67617edafa11fa408b73322c",
      "name": "ACTIVIDAD MALICIOSA | Relacionada con Lumma Stealer 17-12-2024",
      "description": "Lumma Stealer es un tipo de software malicioso dise\u00f1ado para robar informaci\u00f3n confidencial de los dispositivos infectados. Este malware se infiltra en los sistemas y extrae datos personales, como nombres de usuario, contrase\u00f1as, informaci\u00f3n bancaria y detalles de tarjetas de cr\u00e9dito. LummaStealer puede afectar varias cuentas, incluidas redes sociales, correos electr\u00f3nicos y monederos de criptomonedas. Los delincuentes pueden usar la informaci\u00f3n robada para chantaje, suplantaci\u00f3n de identidad, y realizar transacciones fraudulentas, lo que puede causar serios problemas de privacidad y p\u00e9rdidas econ\u00f3micas significativas para las v\u00edctimas.",
      "modified": "2025-01-16T13:03:38.406000",
      "created": "2024-12-17T13:38:34.760000",
      "tags": [
        "access",
        "discovery",
        "ta0001 initial",
        "t1003 data",
        "local system",
        "t1033 system",
        "t1057 process",
        "t1082 system",
        "t1087 account"
      ],
      "references": [
        "https://darfe.es/ciberwiki/index.php?title=Lumma",
        "https://www.virustotal.com/graph/embed/gec57b97e0f194fd38738be6392abba6f180fe9d93be24891af76fb2c7bec3638?theme=dark",
        "https://www.virustotal.com/gui/collection/bf70caf191025dfa3e68e8bc63882880ae2ca60f72ece512aaee246b487c5ad6"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "esoporteingenieria2020",
        "id": "121604",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA1": 25,
        "FileHash-SHA256": 27,
        "URL": 301,
        "domain": 665,
        "hostname": 8
      },
      "indicator_count": 1052,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 267,
      "modified_text": "499 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "674c9f48cd2a512e28ef6523",
      "name": "ACTIVIDAD MALICIOSA | Relacionada con LummaStealer 01-12-2024",
      "description": "Lumma Stealer es un tipo de software malicioso dise\u00f1ado para robar informaci\u00f3n confidencial de los dispositivos infectados. Este malware se infiltra en los sistemas y extrae datos personales, como nombres de usuario, contrase\u00f1as, informaci\u00f3n bancaria y detalles de tarjetas de cr\u00e9dito. LummaStealer puede afectar varias cuentas, incluidas redes sociales, correos electr\u00f3nicos y monederos de criptomonedas. Los delincuentes pueden usar la informaci\u00f3n robada para chantaje, suplantaci\u00f3n de identidad, y realizar transacciones fraudulentas, lo que puede causar serios problemas de privacidad y p\u00e9rdidas econ\u00f3micas significativas para las v\u00edctimas.",
      "modified": "2024-12-31T17:05:00.863000",
      "created": "2024-12-01T17:39:20.573000",
      "tags": [
        "http",
        "access",
        "discovery",
        "uexfvbqog9i67m",
        "mmirygls1g",
        "vt51x7b9cwn7e4x",
        "v2fnqdfylkobc",
        "tcticas",
        "ta0001 initial",
        "t1003 data"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g31920c46027f42a085f0a4040c4609fcccba0ba580b3451893964f393d84ac65?theme=dark",
        "https://www.virustotal.com/gui/collection/9419ada66b99877877ab2cbbe22a5e2de65cd18153db39736cb4fe1d06cc1129",
        "https://darfe.es/ciberwiki/index.php?title=Lumma"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "esoporteingenieria2020",
        "id": "121604",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1161,
        "FileHash-SHA1": 1159,
        "FileHash-SHA256": 1167,
        "URL": 255,
        "domain": 665,
        "hostname": 8
      },
      "indicator_count": 4415,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 266,
      "modified_text": "515 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "patternapplauderw.shop",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "patternapplauderw.shop",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780177586.1142626
}