{
  "type": "Domain",
  "indicator": "polblxpnl.space",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/polblxpnl.space",
    "alexa": "http://www.alexa.com/siteinfo/polblxpnl.space",
    "indicator": "polblxpnl.space",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4271626772,
      "indicator": "polblxpnl.space",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 12,
      "pulses": [
        {
          "id": "69ba83542e3e56c9806b9659",
          "name": "Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators",
          "description": "The Contagious Trader campaign is a sophisticated malware operation targeting cryptocurrency users, attributed to North Korea with high confidence. It involves malicious cryptocurrency trading bot projects on GitHub that exfiltrate sensitive data and private keys using various techniques, including malicious npm dependencies. The campaign demonstrates overlaps with known North Korean tactics, particularly those of FAMOUS CHOLLIMA, including the use of GitHub, npm, and Vercel infrastructure, Base64-encoded payload URLs, and anonymizing VPNs for npm package publishing. The operation represents a shift in tactics, expanding beyond the previous Contagious Interview campaign to target a broader range of cryptocurrency users.",
          "modified": "2026-04-17T10:17:31.095000",
          "created": "2026-03-18T10:49:56.673000",
          "tags": [
            "pylangghost",
            "invisibleferrett",
            "bigsquatrat",
            "beavertail",
            "trading bots",
            "lazarus",
            "golangghost",
            "dprk",
            "cryptocurrency",
            "contagious trader",
            "exfiltration",
            "malware",
            "github",
            "npm",
            "ottercookie"
          ],
          "references": [
            "https://kmsec.uk/blog/contagious-trader/"
          ],
          "public": 1,
          "adversary": "DPRK (North Korea)",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Contagious Trader",
              "display_name": "Contagious Trader",
              "target": null
            },
            {
              "id": "BigSquatRAT",
              "display_name": "BigSquatRAT",
              "target": null
            },
            {
              "id": "OtterCookie",
              "display_name": "OtterCookie",
              "target": null
            },
            {
              "id": "Beavertail",
              "display_name": "Beavertail",
              "target": null
            },
            {
              "id": "InvisibleFerrett",
              "display_name": "InvisibleFerrett",
              "target": null
            },
            {
              "id": "GolangGhost",
              "display_name": "GolangGhost",
              "target": null
            },
            {
              "id": "PylangGhost",
              "display_name": "PylangGhost",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1132.001",
              "name": "Standard Encoding",
              "display_name": "T1132.001 - Standard Encoding"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1036.005",
              "name": "Match Legitimate Name or Location",
              "display_name": "T1036.005 - Match Legitimate Name or Location"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1573.001",
              "name": "Symmetric Cryptography",
              "display_name": "T1573.001 - Symmetric Cryptography"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            },
            {
              "id": "T1567",
              "name": "Exfiltration Over Web Service",
              "display_name": "T1567 - Exfiltration Over Web Service"
            },
            {
              "id": "T1588.001",
              "name": "Malware",
              "display_name": "T1588.001 - Malware"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1588.002",
              "name": "Tool",
              "display_name": "T1588.002 - Tool"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1102.002",
              "name": "Bidirectional Communication",
              "display_name": "T1102.002 - Bidirectional Communication"
            },
            {
              "id": "T1070.004",
              "name": "File Deletion",
              "display_name": "T1070.004 - File Deletion"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [
            "Finance"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1,
            "domain": 6,
            "hostname": 5
          },
          "indicator_count": 12,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386457,
          "modified_text": "43 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f3785a17758b977e678e70",
          "name": "Botnet_C2 | May 1, 2026",
          "description": "Botnet_C2 indicators. Date: May 1, 2026. Total: 720 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-30T15:08:27.020000",
          "created": "2026-04-30T15:42:18.766000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 131,
            "URL": 136,
            "domain": 98
          },
          "indicator_count": 365,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "7 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f227149758c0da125208b5",
          "name": "Botnet_C2 | Apr 30, 2026",
          "description": "Botnet_C2 indicators. Date: Apr 30, 2026. Total: 702 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-29T15:30:19.711000",
          "created": "2026-04-29T15:43:16.686000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 145,
            "hostname": 125,
            "domain": 90
          },
          "indicator_count": 360,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f0d655fe93c3b010ce6043",
          "name": "Botnet_C2 | Apr 29, 2026",
          "description": "Botnet_C2 indicators. Date: Apr 29, 2026. Total: 675 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-28T15:26:26.017000",
          "created": "2026-04-28T15:46:28.923000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 138,
            "hostname": 122,
            "domain": 86
          },
          "indicator_count": 346,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "2 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f9fb15fe269b01c669a4fd",
          "name": "Botnet_C2 | May 6, 2026",
          "description": "Botnet_C2 indicators. Date: May 6, 2026. Total: 1125 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-05T14:13:41.596000",
          "created": "2026-05-05T14:13:41.596000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "URL": 150,
            "hostname": 165,
            "domain": 86
          },
          "indicator_count": 406,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "25 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f8a980a739c03f1bf1e92e",
          "name": "Botnet_C2 | May 5, 2026",
          "description": "Botnet_C2 indicators. Date: May 5, 2026. Total: 1060 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-04T14:13:20.351000",
          "created": "2026-05-04T14:13:20.351000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "domain": 73,
            "hostname": 160,
            "URL": 133
          },
          "indicator_count": 371,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f84da7a4ada12b87eadd8e",
          "name": "Claude adds malware to crypto agent",
          "description": "Researchers at the University of California at Berkeley, in the United States, have been working on a new version of the hash-validator system to test its ability to identify and identify people using it.",
          "modified": "2026-05-04T07:41:27.581000",
          "created": "2026-05-04T07:41:27.581000",
          "tags": [
            "validatesdkv2",
            "slackgramlogger",
            "hashvalidatorv2",
            "solanaipfssdk"
          ],
          "references": [
            "https://www.reversinglabs.com/blog/claude-promptmink-malware-crypto"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 3,
            "domain": 11,
            "hostname": 7,
            "FileHash-SHA1": 303
          },
          "indicator_count": 324,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 280,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f76e81612bd09f529876c0",
          "name": "Botnet_C2 | May 4, 2026",
          "description": "Botnet_C2 indicators. Date: May 4, 2026. Total: 1099 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-03T15:49:21.132000",
          "created": "2026-05-03T15:49:21.132000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "hostname": 154,
            "URL": 136,
            "domain": 82
          },
          "indicator_count": 377,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "27 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f61d10dd9cc819d9fe9779",
          "name": "Botnet_C2 | May 3, 2026",
          "description": "Botnet_C2 indicators. Date: May 3, 2026. Total: 1058 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-02T15:49:36.045000",
          "created": "2026-05-02T15:49:36.045000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "domain": 84,
            "hostname": 148,
            "URL": 136
          },
          "indicator_count": 373,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "28 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f4cb76fe838834b6105356",
          "name": "Botnet_C2 | May 2, 2026",
          "description": "Botnet_C2 indicators. Date: May 2, 2026. Total: 992 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-01T15:49:10.769000",
          "created": "2026-05-01T15:49:10.769000",
          "tags": [
            "botnet_c2"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 5,
            "URL": 146,
            "hostname": 139,
            "domain": 87
          },
          "indicator_count": 377,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "29 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69bbbb60a8390fc9a5e0e715",
          "name": "EbeeMar2026 Pt4",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-04-18T08:06:12.483000",
          "created": "2026-03-19T09:01:20.593000",
          "tags": [
            "filehashsha256",
            "filehashmd5",
            "filehashsha1",
            "email",
            "xdsfeerdfbn",
            "chlg url"
          ],
          "references": [
            "IOCs.2026.4.csv"
          ],
          "public": 1,
          "adversary": "Operation GhostMail, CastleRAT, UNK_NightOwl, Fake Shipment Tracking Scams in MEA, Fake Claude Code ",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 77,
            "FileHash-MD5": 122,
            "FileHash-SHA1": 103,
            "FileHash-SHA256": 164,
            "CVE": 25,
            "URL": 58,
            "domain": 107,
            "email": 30
          },
          "indicator_count": 686,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 40,
          "modified_text": "42 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69bb25ff24fa0920b8758439",
          "name": "Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators",
          "description": "",
          "modified": "2026-04-17T10:17:31.095000",
          "created": "2026-03-18T22:23:59.183000",
          "tags": [
            "pylangghost",
            "invisibleferrett",
            "bigsquatrat",
            "beavertail",
            "trading bots",
            "lazarus",
            "golangghost",
            "dprk",
            "cryptocurrency",
            "contagious trader",
            "exfiltration",
            "malware",
            "github",
            "npm",
            "ottercookie"
          ],
          "references": [
            "https://kmsec.uk/blog/contagious-trader/"
          ],
          "public": 1,
          "adversary": "DPRK (North Korea)",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Contagious Trader",
              "display_name": "Contagious Trader",
              "target": null
            },
            {
              "id": "BigSquatRAT",
              "display_name": "BigSquatRAT",
              "target": null
            },
            {
              "id": "OtterCookie",
              "display_name": "OtterCookie",
              "target": null
            },
            {
              "id": "Beavertail",
              "display_name": "Beavertail",
              "target": null
            },
            {
              "id": "InvisibleFerrett",
              "display_name": "InvisibleFerrett",
              "target": null
            },
            {
              "id": "GolangGhost",
              "display_name": "GolangGhost",
              "target": null
            },
            {
              "id": "PylangGhost",
              "display_name": "PylangGhost",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1132.001",
              "name": "Standard Encoding",
              "display_name": "T1132.001 - Standard Encoding"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1036.005",
              "name": "Match Legitimate Name or Location",
              "display_name": "T1036.005 - Match Legitimate Name or Location"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1573.001",
              "name": "Symmetric Cryptography",
              "display_name": "T1573.001 - Symmetric Cryptography"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            },
            {
              "id": "T1567",
              "name": "Exfiltration Over Web Service",
              "display_name": "T1567 - Exfiltration Over Web Service"
            },
            {
              "id": "T1588.001",
              "name": "Malware",
              "display_name": "T1588.001 - Malware"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1588.002",
              "name": "Tool",
              "display_name": "T1588.002 - Tool"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1102.002",
              "name": "Bidirectional Communication",
              "display_name": "T1102.002 - Bidirectional Communication"
            },
            {
              "id": "T1070.004",
              "name": "File Deletion",
              "display_name": "T1070.004 - File Deletion"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [
            "Finance"
          ],
          "TLP": "white",
          "cloned_from": "69ba83542e3e56c9806b9659",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1,
            "domain": 6,
            "hostname": 5
          },
          "indicator_count": 12,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "43 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "IOCs.2026.4.csv",
        "https://www.reversinglabs.com/blog/claude-promptmink-malware-crypto",
        "https://kmsec.uk/blog/contagious-trader/",
        "https://ltna.com.au/cyber"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "DPRK (North Korea)"
          ],
          "malware_families": [
            "Contagious trader",
            "Ottercookie",
            "Golangghost",
            "Pylangghost",
            "Invisibleferrett",
            "Beavertail",
            "Bigsquatrat"
          ],
          "industries": [
            "Finance"
          ]
        },
        "other": {
          "adversary": [
            "DPRK (North Korea)",
            "Operation GhostMail, CastleRAT, UNK_NightOwl, Fake Shipment Tracking Scams in MEA, Fake Claude Code "
          ],
          "malware_families": [
            "Contagious trader",
            "Ottercookie",
            "Golangghost",
            "Pylangghost",
            "Invisibleferrett",
            "Beavertail",
            "Bigsquatrat"
          ],
          "industries": [
            "Finance"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 12,
  "pulses": [
    {
      "id": "69ba83542e3e56c9806b9659",
      "name": "Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators",
      "description": "The Contagious Trader campaign is a sophisticated malware operation targeting cryptocurrency users, attributed to North Korea with high confidence. It involves malicious cryptocurrency trading bot projects on GitHub that exfiltrate sensitive data and private keys using various techniques, including malicious npm dependencies. The campaign demonstrates overlaps with known North Korean tactics, particularly those of FAMOUS CHOLLIMA, including the use of GitHub, npm, and Vercel infrastructure, Base64-encoded payload URLs, and anonymizing VPNs for npm package publishing. The operation represents a shift in tactics, expanding beyond the previous Contagious Interview campaign to target a broader range of cryptocurrency users.",
      "modified": "2026-04-17T10:17:31.095000",
      "created": "2026-03-18T10:49:56.673000",
      "tags": [
        "pylangghost",
        "invisibleferrett",
        "bigsquatrat",
        "beavertail",
        "trading bots",
        "lazarus",
        "golangghost",
        "dprk",
        "cryptocurrency",
        "contagious trader",
        "exfiltration",
        "malware",
        "github",
        "npm",
        "ottercookie"
      ],
      "references": [
        "https://kmsec.uk/blog/contagious-trader/"
      ],
      "public": 1,
      "adversary": "DPRK (North Korea)",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Contagious Trader",
          "display_name": "Contagious Trader",
          "target": null
        },
        {
          "id": "BigSquatRAT",
          "display_name": "BigSquatRAT",
          "target": null
        },
        {
          "id": "OtterCookie",
          "display_name": "OtterCookie",
          "target": null
        },
        {
          "id": "Beavertail",
          "display_name": "Beavertail",
          "target": null
        },
        {
          "id": "InvisibleFerrett",
          "display_name": "InvisibleFerrett",
          "target": null
        },
        {
          "id": "GolangGhost",
          "display_name": "GolangGhost",
          "target": null
        },
        {
          "id": "PylangGhost",
          "display_name": "PylangGhost",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1132.001",
          "name": "Standard Encoding",
          "display_name": "T1132.001 - Standard Encoding"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1036.005",
          "name": "Match Legitimate Name or Location",
          "display_name": "T1036.005 - Match Legitimate Name or Location"
        },
        {
          "id": "T1587.001",
          "name": "Malware",
          "display_name": "T1587.001 - Malware"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1573.001",
          "name": "Symmetric Cryptography",
          "display_name": "T1573.001 - Symmetric Cryptography"
        },
        {
          "id": "T1608.001",
          "name": "Upload Malware",
          "display_name": "T1608.001 - Upload Malware"
        },
        {
          "id": "T1567",
          "name": "Exfiltration Over Web Service",
          "display_name": "T1567 - Exfiltration Over Web Service"
        },
        {
          "id": "T1588.001",
          "name": "Malware",
          "display_name": "T1588.001 - Malware"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1588.002",
          "name": "Tool",
          "display_name": "T1588.002 - Tool"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1102.002",
          "name": "Bidirectional Communication",
          "display_name": "T1102.002 - Bidirectional Communication"
        },
        {
          "id": "T1070.004",
          "name": "File Deletion",
          "display_name": "T1070.004 - File Deletion"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [
        "Finance"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1,
        "domain": 6,
        "hostname": 5
      },
      "indicator_count": 12,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386457,
      "modified_text": "43 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f3785a17758b977e678e70",
      "name": "Botnet_C2 | May 1, 2026",
      "description": "Botnet_C2 indicators. Date: May 1, 2026. Total: 720 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-30T15:08:27.020000",
      "created": "2026-04-30T15:42:18.766000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 131,
        "URL": 136,
        "domain": 98
      },
      "indicator_count": 365,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "7 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f227149758c0da125208b5",
      "name": "Botnet_C2 | Apr 30, 2026",
      "description": "Botnet_C2 indicators. Date: Apr 30, 2026. Total: 702 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-29T15:30:19.711000",
      "created": "2026-04-29T15:43:16.686000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 145,
        "hostname": 125,
        "domain": 90
      },
      "indicator_count": 360,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f0d655fe93c3b010ce6043",
      "name": "Botnet_C2 | Apr 29, 2026",
      "description": "Botnet_C2 indicators. Date: Apr 29, 2026. Total: 675 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-28T15:26:26.017000",
      "created": "2026-04-28T15:46:28.923000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 138,
        "hostname": 122,
        "domain": 86
      },
      "indicator_count": 346,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "2 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f9fb15fe269b01c669a4fd",
      "name": "Botnet_C2 | May 6, 2026",
      "description": "Botnet_C2 indicators. Date: May 6, 2026. Total: 1125 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-05T14:13:41.596000",
      "created": "2026-05-05T14:13:41.596000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "URL": 150,
        "hostname": 165,
        "domain": 86
      },
      "indicator_count": 406,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "25 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f8a980a739c03f1bf1e92e",
      "name": "Botnet_C2 | May 5, 2026",
      "description": "Botnet_C2 indicators. Date: May 5, 2026. Total: 1060 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-04T14:13:20.351000",
      "created": "2026-05-04T14:13:20.351000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "domain": 73,
        "hostname": 160,
        "URL": 133
      },
      "indicator_count": 371,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f84da7a4ada12b87eadd8e",
      "name": "Claude adds malware to crypto agent",
      "description": "Researchers at the University of California at Berkeley, in the United States, have been working on a new version of the hash-validator system to test its ability to identify and identify people using it.",
      "modified": "2026-05-04T07:41:27.581000",
      "created": "2026-05-04T07:41:27.581000",
      "tags": [
        "validatesdkv2",
        "slackgramlogger",
        "hashvalidatorv2",
        "solanaipfssdk"
      ],
      "references": [
        "https://www.reversinglabs.com/blog/claude-promptmink-malware-crypto"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 3,
        "domain": 11,
        "hostname": 7,
        "FileHash-SHA1": 303
      },
      "indicator_count": 324,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 280,
      "modified_text": "26 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f76e81612bd09f529876c0",
      "name": "Botnet_C2 | May 4, 2026",
      "description": "Botnet_C2 indicators. Date: May 4, 2026. Total: 1099 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-03T15:49:21.132000",
      "created": "2026-05-03T15:49:21.132000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "hostname": 154,
        "URL": 136,
        "domain": 82
      },
      "indicator_count": 377,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "27 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f61d10dd9cc819d9fe9779",
      "name": "Botnet_C2 | May 3, 2026",
      "description": "Botnet_C2 indicators. Date: May 3, 2026. Total: 1058 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-02T15:49:36.045000",
      "created": "2026-05-02T15:49:36.045000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "domain": 84,
        "hostname": 148,
        "URL": 136
      },
      "indicator_count": 373,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "28 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f4cb76fe838834b6105356",
      "name": "Botnet_C2 | May 2, 2026",
      "description": "Botnet_C2 indicators. Date: May 2, 2026. Total: 992 indicators. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-01T15:49:10.769000",
      "created": "2026-05-01T15:49:10.769000",
      "tags": [
        "botnet_c2"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 5,
        "URL": 146,
        "hostname": 139,
        "domain": 87
      },
      "indicator_count": 377,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "29 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "polblxpnl.space",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "polblxpnl.space",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780180764.2563798
}