{
  "type": "Domain",
  "indicator": "powershell.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/powershell.com",
    "alexa": "http://www.alexa.com/siteinfo/powershell.com",
    "indicator": "powershell.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2993757131,
      "indicator": "powershell.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 22,
      "pulses": [
        {
          "id": "6a02eb598920fbedf3e41342",
          "name": "CAPE Sandbox - Dropped Files are Unacceptable",
          "description": "these files were \"dropped\" to me pcchecking-main/Ultra scan script",
          "modified": "2026-05-12T10:43:56.692000",
          "created": "2026-05-12T08:56:57.100000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 376,
            "FileHash-SHA1": 144,
            "FileHash-SHA256": 285,
            "IPv4": 67,
            "URL": 154,
            "domain": 297,
            "hostname": 152,
            "email": 4,
            "YARA": 11
          },
          "indicator_count": 1490,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "18 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a02eb577acf40ff18578c13",
          "name": "CAPE Sandbox - Dropped Files are Unacceptable",
          "description": "these files were \"dropped\" to me pcchecking-main/Ultra scan script",
          "modified": "2026-05-12T10:00:02.785000",
          "created": "2026-05-12T08:56:55.407000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 368,
            "FileHash-SHA1": 142,
            "FileHash-SHA256": 281,
            "IPv4": 61,
            "URL": 104,
            "domain": 295,
            "hostname": 132,
            "email": 2
          },
          "indicator_count": 1385,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "18 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a02eb5bb415c3d8211f2a69",
          "name": "CAPE Sandbox - Dropped Files are Unacceptable",
          "description": "these files were \"dropped\" to me pcchecking-main/Ultra scan script",
          "modified": "2026-05-12T10:00:01.413000",
          "created": "2026-05-12T08:56:59.194000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 368,
            "FileHash-SHA1": 142,
            "FileHash-SHA256": 281,
            "IPv4": 59,
            "URL": 102,
            "domain": 71,
            "hostname": 117
          },
          "indicator_count": 1140,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "18 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a02eb5aebd8b5cd4e1a10b8",
          "name": "CAPE Sandbox - Dropped Files are Unacceptable",
          "description": "these files were \"dropped\" to me pcchecking-main/Ultra scan script",
          "modified": "2026-05-12T10:00:00.080000",
          "created": "2026-05-12T08:56:58.095000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 368,
            "FileHash-SHA1": 142,
            "FileHash-SHA256": 281,
            "IPv4": 59,
            "URL": 102,
            "domain": 71,
            "hostname": 118
          },
          "indicator_count": 1141,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "18 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fc18d0e4586dfaa5fc8e5e",
          "name": "VirusTotal report\n                    for Yandex.exe",
          "description": "[full report on the Yandex.exe malware, which was found on a Windows 11 operating system in the early hours of the morning, has been published by the University of South Africa.] Client changes iphone browser to Bing yesterday.",
          "modified": "2026-05-07T04:55:20.865000",
          "created": "2026-05-07T04:45:04.790000",
          "tags": [
            "pe file",
            "file type",
            "https",
            "sample",
            "performs dns",
            "tls version",
            "creates",
            "urls",
            "ms windows",
            "aslr",
            "code",
            "persistence",
            "defense evasion",
            "malicious",
            "next",
            "getqueryurl412",
            "update with",
            "arguments",
            "info",
            "service",
            "verifymodule128",
            "stopservice815",
            "watchicufile185",
            "getqueryurl409",
            "installertype4",
            "windows sandbox",
            "calls process",
            "default",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "file size",
            "path c",
            "sha1",
            "crc32",
            "win64",
            "accept",
            "shutdown",
            "guard",
            "powershell",
            "payload",
            "back",
            "bing"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
            "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
            "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
            "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
            "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1552",
              "name": "Unsecured Credentials",
              "display_name": "T1552 - Unsecured Credentials"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 422,
            "FileHash-SHA1": 190,
            "FileHash-SHA256": 789,
            "URL": 274,
            "domain": 95,
            "IPv4": 161,
            "hostname": 299,
            "email": 1
          },
          "indicator_count": 2231,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fc18cd07af71dd4c1048a1",
          "name": "VirusTotal report\n                    for Yandex.exe",
          "description": "[full report on the Yandex.exe malware, which was found on a Windows 11 operating system in the early hours of the morning, has been published by the University of South Africa.] Client changes iphone browser to Bing yesterday.",
          "modified": "2026-05-07T04:50:57.126000",
          "created": "2026-05-07T04:45:01.264000",
          "tags": [
            "pe file",
            "file type",
            "https",
            "sample",
            "performs dns",
            "tls version",
            "creates",
            "urls",
            "ms windows",
            "aslr",
            "code",
            "persistence",
            "defense evasion",
            "malicious",
            "next",
            "getqueryurl412",
            "update with",
            "arguments",
            "info",
            "service",
            "verifymodule128",
            "stopservice815",
            "watchicufile185",
            "getqueryurl409",
            "installertype4",
            "windows sandbox",
            "calls process",
            "default",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "file size",
            "path c",
            "sha1",
            "crc32",
            "win64",
            "accept",
            "shutdown",
            "guard",
            "powershell",
            "payload",
            "back",
            "bing"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
            "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
            "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
            "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
            "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1552",
              "name": "Unsecured Credentials",
              "display_name": "T1552 - Unsecured Credentials"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 422,
            "FileHash-SHA1": 189,
            "FileHash-SHA256": 789,
            "URL": 191,
            "domain": 74,
            "IPv4": 145,
            "hostname": 225,
            "email": 1
          },
          "indicator_count": 2036,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fc18ce74d03deacb8b8455",
          "name": "VirusTotal report\n                    for Yandex.exe",
          "description": "[full report on the Yandex.exe malware, which was found on a Windows 11 operating system in the early hours of the morning, has been published by the University of South Africa.] Client changes iphone browser to Bing yesterday.",
          "modified": "2026-05-07T04:50:56.098000",
          "created": "2026-05-07T04:45:02.466000",
          "tags": [
            "pe file",
            "file type",
            "https",
            "sample",
            "performs dns",
            "tls version",
            "creates",
            "urls",
            "ms windows",
            "aslr",
            "code",
            "persistence",
            "defense evasion",
            "malicious",
            "next",
            "getqueryurl412",
            "update with",
            "arguments",
            "info",
            "service",
            "verifymodule128",
            "stopservice815",
            "watchicufile185",
            "getqueryurl409",
            "installertype4",
            "windows sandbox",
            "calls process",
            "default",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "file size",
            "path c",
            "sha1",
            "crc32",
            "win64",
            "accept",
            "shutdown",
            "guard",
            "powershell",
            "payload",
            "back",
            "bing"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
            "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
            "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
            "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
            "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1552",
              "name": "Unsecured Credentials",
              "display_name": "T1552 - Unsecured Credentials"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 422,
            "FileHash-SHA1": 189,
            "FileHash-SHA256": 789,
            "URL": 191,
            "domain": 74,
            "IPv4": 145,
            "hostname": 225,
            "email": 1
          },
          "indicator_count": 2036,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fc18cf1d3c2127ee8a4c0c",
          "name": "VirusTotal report\n                    for Yandex.exe",
          "description": "[full report on the Yandex.exe malware, which was found on a Windows 11 operating system in the early hours of the morning, has been published by the University of South Africa.] Client changes iphone browser to Bing yesterday.",
          "modified": "2026-05-07T04:50:55.377000",
          "created": "2026-05-07T04:45:03.716000",
          "tags": [
            "pe file",
            "file type",
            "https",
            "sample",
            "performs dns",
            "tls version",
            "creates",
            "urls",
            "ms windows",
            "aslr",
            "code",
            "persistence",
            "defense evasion",
            "malicious",
            "next",
            "getqueryurl412",
            "update with",
            "arguments",
            "info",
            "service",
            "verifymodule128",
            "stopservice815",
            "watchicufile185",
            "getqueryurl409",
            "installertype4",
            "windows sandbox",
            "calls process",
            "default",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "file size",
            "path c",
            "sha1",
            "crc32",
            "win64",
            "accept",
            "shutdown",
            "guard",
            "powershell",
            "payload",
            "back",
            "bing"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
            "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
            "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
            "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
            "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1552",
              "name": "Unsecured Credentials",
              "display_name": "T1552 - Unsecured Credentials"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 422,
            "FileHash-SHA1": 189,
            "FileHash-SHA256": 789,
            "URL": 191,
            "domain": 74,
            "IPv4": 145,
            "hostname": 225,
            "email": 1
          },
          "indicator_count": 2036,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d389d979acb0e20217e451",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-05-06T10:13:24.260000",
          "created": "2026-04-06T10:24:25.849000",
          "tags": [
            "p2404",
            "strong",
            "sha256",
            "library",
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "none rticon",
            "info",
            "path",
            "win32",
            "accept",
            "null",
            "activator",
            "false",
            "black",
            "powershell",
            "error",
            "team",
            "code",
            "date",
            "download",
            "stop",
            "green",
            "class",
            "void",
            "cheap",
            "shutdown",
            "impact",
            "guard",
            "tools",
            "comspec",
            "enterprise",
            "terminal",
            "music",
            "desktop",
            "crypt32",
            "lockfile",
            "write",
            "open",
            "stub",
            "delta",
            "title",
            "body",
            "project",
            "windows sandbox",
            "calls process"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
            "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 172,
            "FileHash-SHA1": 151,
            "FileHash-SHA256": 121,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 596,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d389db09844fda2dd3d26d",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-05-06T10:13:24.260000",
          "created": "2026-04-06T10:24:27.141000",
          "tags": [
            "p2404",
            "strong",
            "sha256",
            "library",
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "none rticon",
            "info",
            "path",
            "win32",
            "accept",
            "null",
            "activator",
            "false",
            "black",
            "powershell",
            "error",
            "team",
            "code",
            "date",
            "download",
            "stop",
            "green",
            "class",
            "void",
            "cheap",
            "shutdown",
            "impact",
            "guard",
            "tools",
            "comspec",
            "enterprise",
            "terminal",
            "music",
            "desktop",
            "crypt32",
            "lockfile",
            "write",
            "open",
            "stub",
            "delta",
            "title",
            "body",
            "project",
            "windows sandbox",
            "calls process"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
            "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 172,
            "FileHash-SHA1": 151,
            "FileHash-SHA256": 121,
            "URL": 80,
            "domain": 17,
            "hostname": 59
          },
          "indicator_count": 600,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d389dab37e607e415f7304",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-05-06T10:13:24.260000",
          "created": "2026-04-06T10:24:26.731000",
          "tags": [
            "p2404",
            "strong",
            "sha256",
            "library",
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "none rticon",
            "info",
            "path",
            "win32",
            "accept",
            "null",
            "activator",
            "false",
            "black",
            "powershell",
            "error",
            "team",
            "code",
            "date",
            "download",
            "stop",
            "green",
            "class",
            "void",
            "cheap",
            "shutdown",
            "impact",
            "guard",
            "tools",
            "comspec",
            "enterprise",
            "terminal",
            "music",
            "desktop",
            "crypt32",
            "lockfile",
            "write",
            "open",
            "stub",
            "delta",
            "title",
            "body",
            "project",
            "windows sandbox",
            "calls process"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
            "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 172,
            "FileHash-SHA1": 151,
            "FileHash-SHA256": 121,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 596,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d3843cba399db62eeae702",
          "name": "CAPE Sandbox - Stalking",
          "description": "A full report on the latest Android operating system: PK.3.4.5.1 (c) on 1 January, 2026, to be published by the Google Research Institute (GRI).",
          "modified": "2026-05-06T10:13:24.260000",
          "created": "2026-04-06T10:00:28.397000",
          "tags": [
            "renewed",
            "8gbram",
            "windows10",
            "19inlcdmonitor",
            "desktop pc",
            "package",
            "intel core",
            "hard drive",
            "dvdrw",
            "wifi",
            "title",
            "blink",
            "date",
            "meta",
            "elite",
            "body",
            "https",
            "mitre attack",
            "network info",
            "tls version",
            "united",
            "overview",
            "zenbox android",
            "verdict",
            "guest system",
            "ultimate file",
            "fraud",
            "cloud",
            "next",
            "program",
            "processes extra",
            "overview zenbox",
            "info file",
            "file type",
            "default",
            "parent pid",
            "full path",
            "command line",
            "registry keys",
            "commands c",
            "k dcomlaunch",
            "files c",
            "devicecng c",
            "read registry"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/2533042959ad1fe050d14ab7536126910a2d240992bff397640382472b6a7c69_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469608&Signature=fK1I2%2FxXVm0l3ZiELwtstes8iVN402Ww%2By%2BgvxYOB0LiC2iO3J9cedWJk1hMIr4IfLSGKprfui8vANzR%2BkWfSd594S%2FFe9A59YKyOA2MFmQTBRXVy6O3xF1e1lPETp5Md%2FbGJCOzrZxdHyReyuk7cgdDDBAewptjJhfTYxql7F9X%2FB4qe9BYWPrvned2fFWfU%2F4G%2F4UBqY9Jj%2BG1CTP%2FaGqOdWFs0Q5cPYZ4bytp",
            "https://vtbehaviour.commondatastorage.googleapis.com/6c39ae0368703f254070a0648c0066115140c3e762d9bf5b52833a037a1e3743_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469752&Signature=Df%2Bamm33qFPdsDg6nWC5FQjse7h4fksSXqONp4nMEItb0gpBwqx66TqcCnFzQplUk6ExMge79qNZR2OElv63sX54D4fSGwI9nvHYhQoiVdZIgf4ct8dIAr%2BYO9jSx0WpPUVFsvf%2FXtXvm6jM5n5v7CGiyFRyAz8PES5g%2FcOlLt%2BDhsc8bhi%2FMU9mAkyyr5nFVPcTmUSHOTNXOeKDUlyRkQE6b9FEbFhUL1h3%2B%2FBVtysh",
            "https://vtbehaviour.commondatastorage.googleapis.com/5feceb66ffc86f38d952786c6d696c79c2dbc239dd4e91b46729d73a27fb57e9_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469810&Signature=Mj5ODxCW7tD5UNn6P11Ta7F2cmDLSJuEB7JSLFg%2FERfANmnRR5L7XzDwXxI5G48vkQFx0%2FBMtjMLwWHn6ZHKlt13rfzkvoOu5fJ%2Fb5lMJqUp1rSQIG0JLL80QAnXyJf2W8pL7MvK97Tr4jsCIUfd8ezliJtV5SmahV6Q8lYu2KJUnANrHkA10RFrcT4O26Vk7gbDsuC7caDXC6U9KXTTB0cpC77%2FV7w86ftN2JPXx6oEHUvSj02qsvhKwKQvmM",
            "https://vtbehaviour.commondatastorage.googleapis.com/5feceb66ffc86f38d952786c6d696c79c2dbc239dd4e91b46729d73a27fb57e9_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469831&Signature=ZlRZLvCaJ%2F9niupu9DFCvXvfgFpDEOsK%2FsH46CB2zEVUDjcQRNMDp9XXKKx0dekmHQbhl02yqygHPOA8Wty5duGtK216QCvKNkYpbpdOjN7xgAg3AsldciWbqeJr8N4I%2F1%2FPRSdVfB%2BNGaBJKxZG1RQkX206MSvX%2BeY%2FdeEYpq3NYdrPWlxdV0pa3yaqcMrf2s%2FCFSM%2FdO3xt5PKyXWG%2FDCNM5iiuXh8OT2ckhZhf%"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1221",
              "name": "Template Injection",
              "display_name": "T1221 - Template Injection"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1409",
              "name": "Access Stored Application Data",
              "display_name": "T1409 - Access Stored Application Data"
            },
            {
              "id": "T1421",
              "name": "System Network Connections Discovery",
              "display_name": "T1421 - System Network Connections Discovery"
            },
            {
              "id": "T1422",
              "name": "System Network Configuration Discovery",
              "display_name": "T1422 - System Network Configuration Discovery"
            },
            {
              "id": "T1426",
              "name": "System Information Discovery",
              "display_name": "T1426 - System Information Discovery"
            },
            {
              "id": "T1430",
              "name": "Location Tracking",
              "display_name": "T1430 - Location Tracking"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 781,
            "FileHash-SHA1": 509,
            "FileHash-SHA256": 539,
            "URL": 387,
            "hostname": 361,
            "domain": 100,
            "CIDR": 1,
            "email": 1
          },
          "indicator_count": 2679,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b4e829e206f1e64d6fa31b",
          "name": "CAPE Sandbox terrible chain",
          "description": "",
          "modified": "2026-04-13T04:23:40.153000",
          "created": "2026-03-14T04:46:33.543000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 150,
            "FileHash-SHA256": 123,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 598,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b4e828809a73c4baff9c5b",
          "name": "CAPE Sandbox terrible chain",
          "description": "",
          "modified": "2026-04-13T04:23:40.153000",
          "created": "2026-03-14T04:46:32.492000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 150,
            "FileHash-SHA256": 123,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 598,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b48ce57b26a7b8bb9222b8",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-04-12T22:04:09.704000",
          "created": "2026-03-13T22:17:09.654000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 150,
            "FileHash-SHA256": 123,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 598,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b48ce44221764174cb6aab",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-04-12T22:04:09.704000",
          "created": "2026-03-13T22:17:07.826000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 150,
            "FileHash-SHA256": 123,
            "URL": 78,
            "domain": 15,
            "hostname": 59
          },
          "indicator_count": 598,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b25caf4fec168b3c069622",
          "name": "CAPE Sandbox",
          "description": "Execution & Stealth (T1129, T1055)\nVector: Dynamic API Resolution (GetProcAddress) to bypass static analysis.\nInjection: Process Hollowing via VirtualProtect (RWX) into explorer.exe.\nEvasion: Decoy Unmapping (NtUnmapViewOfSectionEx) to trip EDR/AV hooks.\nMFA Bypass (T1082)\nTarget: SQLite browser profiles (Chrome/Edge/Safari).\nAction: Extraction of Network\\Cookies and Login Data.\nImpact: Clones active OAuth tokens to hijack authenticated sessions, rendering Multi-Factor Authentication (MFA) ineffective.\nInfrastructure (T1071)\nC2/Exfil: 150.171.27.12 / 168.61.215.74 (CDN-masked).\nRecon: Active probing of Port 135 (RPC) to identify Admin Workstations.\nOutcome: Global Wipe (T1496, T1542)\nAccess: Stolen Entra ID/Intune tokens provide \"Global Admin\" status.\nCommand: Unauthorized Remote Wipe triggers factory resets.",
          "modified": "2026-04-11T06:01:34.928000",
          "created": "2026-03-12T06:26:55.123000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 70,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 52,
            "URL": 16,
            "domain": 4,
            "hostname": 45
          },
          "indicator_count": 246,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "50 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b24e98bad4b40f1539fbc0",
          "name": "CAPE Sandbox Matrix exe",
          "description": "",
          "modified": "2026-04-11T05:45:14.190000",
          "created": "2026-03-12T05:26:48.932000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 70,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 52,
            "URL": 16,
            "domain": 4,
            "hostname": 45
          },
          "indicator_count": 246,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "50 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b24b64933638f706c0db6c",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-04-11T05:45:14.190000",
          "created": "2026-03-12T05:13:08.685000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 70,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 52,
            "URL": 16,
            "domain": 4,
            "hostname": 45
          },
          "indicator_count": 246,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "50 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b24b63bdf3752706e341dc",
          "name": "CAPE Sandbox",
          "description": "",
          "modified": "2026-04-11T05:45:14.190000",
          "created": "2026-03-12T05:13:07.427000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 70,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 52,
            "URL": 16,
            "domain": 4,
            "hostname": 45
          },
          "indicator_count": 246,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "50 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "699b907c5375efb7ce1639b8",
          "name": "Apple Redirects in Apple Support = IcedID | MITM attack",
          "description": "Researching targets former iPhone. Redirect in Apple support. [support.apple.com/ht^*^ redirects to support.apple.com/de/^*^*^] IcedID identified. | Environment: 3 -5 suspected compromised devices present. Behavior: iPhone reset itself twice, deleted passcodes, required new passcodes, compromised contacts notified target added a new device (FALSE) , threat actor stole Apple cash , added , Password storage, reset television. Targeted another device auto downloaded a Mimecast compromise, attached to iCloud , corrupted files downloaded. Emotet identified. Reset SmartTV. Browser bar AI:  mood swings. Overt changes, white screen, pink screens, thread erased. Identified OTX. as a honeypot also states it\u2019s legitimate. I dumped information. AI agents focused on victim leaving shreds of evidence , paper trail , w/ anyone ,anywhere.  AI model told truth \u2018I don\u2019t like you , you\u2019ve changed, you lied, you changed all facts .\u201d,etc. An acceptable baseline of communication established . #botnet  #command_and_control #IcedID",
          "modified": "2026-03-24T21:11:04.306000",
          "created": "2026-02-22T23:25:48.722000",
          "tags": [
            "dynamicloader",
            "tls handshake",
            "failure",
            "whitelisted",
            "akamai",
            "yara detections",
            "trojan",
            "write",
            "zeppelin",
            "malware",
            "hostile",
            "unknown",
            "port",
            "destination",
            "read c",
            "united",
            "as16625 akamai",
            "win32",
            "persistence",
            "execution",
            "passive dns",
            "urls",
            "otx logo",
            "all url",
            "http",
            "ip address",
            "related nids",
            "files location",
            "win32mydoom feb",
            "name servers",
            "servers",
            "worm",
            "virtool",
            "files",
            "ipv4",
            "reverse dns",
            "america flag",
            "america asn",
            "United States",
            "unknown ns",
            "asn as714",
            "invalid url",
            "mtb oct",
            "mtb sep",
            "lowfi",
            "trojanspy",
            "total",
            "push",
            "defender",
            "china unknown",
            "mtb apr",
            "ok server",
            "gmt content",
            "type",
            "accept",
            "show",
            "todo",
            "all filehash",
            "av detections",
            "shift",
            "url http",
            "url https",
            "hostname",
            "type indicator",
            "source hostname",
            "writeconsolew",
            "post https",
            "tlsv1",
            "medium",
            "write c",
            "dock",
            "command",
            "control",
            "icedid",
            "domain",
            "all domain",
            "status",
            "hostname add",
            "crlf line",
            "unicode text",
            "utf8",
            "ee fc",
            "yara rule",
            "ff d5",
            "ascii text",
            "f0 ff",
            "eb e1",
            "music",
            "next",
            "autorun",
            "suspicious",
            "compatibility",
            "mode",
            "entries",
            "lredmond",
            "stwashington",
            "search",
            "tls sni",
            "denmark",
            "body html",
            "head title",
            "title head",
            "body h1",
            "all ipv4",
            "url analysis",
            "users",
            "ff ff",
            "files domain",
            "files related",
            "url add",
            "flag united",
            "present apr",
            "location united",
            "asn asnone",
            "as16509",
            "moved",
            "title",
            "body",
            "code",
            "mydoom",
            "bot net",
            "mitm",
            "aquire",
            "hidden users",
            "no expiration",
            "filehashsha256",
            "expiration",
            "showing",
            "indicator role",
            "pulses url",
            "pulse show",
            "iot",
            "Iced iced baby"
          ],
          "references": [
            "support.apple.com/ht^*^*^*^ redirects to support.apple.com/de/^*^*^*^*^",
            "This is messy! OTX refreshed and deleted IoC\u2019s. Will continue researching",
            "IDS Detections: Observed IcedID CnC Domain in TLS SNI TLS Handshake Failure",
            "df57a01 c40f355a0f8a592294187d4fedc257 [Compatibility Mode] - Word",
            "div>  <p style=\"text-align: justify;\">   <img src=\"static/rId9.jpeg\"/>   </p> </div>",
            "Same legal , and quasi governmental pattern identified",
            "I apologize for the lack of reference.",
            "Requires further research.",
            "Will pulse remaining Apple IoC\u2019s in next pulse",
            "https://l.us-1.a.mimecastprotect.com/l",
            "It appears there are 5-7 known affected that I was able to find"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Germany",
            "Denmark",
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "Icedid",
              "display_name": "Icedid",
              "target": null
            },
            {
              "id": "Trojan:Win32/SmkLdr.H!MTB",
              "display_name": "Trojan:Win32/SmkLdr.H!MTB",
              "target": "/malware/Trojan:Win32/SmkLdr.H!MTB"
            },
            {
              "id": "#Lowfi:Lua:DllSuspiciousExport.A",
              "display_name": "#Lowfi:Lua:DllSuspiciousExport.A",
              "target": null
            },
            {
              "id": "MyDoom",
              "display_name": "MyDoom",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1158",
              "name": "Hidden Files and Directories",
              "display_name": "T1158 - Hidden Files and Directories"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1557",
              "name": "Man-in-the-Middle",
              "display_name": "T1557 - Man-in-the-Middle"
            },
            {
              "id": "T1147",
              "name": "Hidden Users",
              "display_name": "T1147 - Hidden Users"
            }
          ],
          "industries": [
            "Technology",
            "Telecom",
            "Legal"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 2051,
            "FileHash-SHA256": 1706,
            "URL": 6984,
            "domain": 1097,
            "FileHash-MD5": 401,
            "FileHash-SHA1": 276,
            "SSLCertFingerprint": 9,
            "email": 13,
            "CVE": 1
          },
          "indicator_count": 12538,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 145,
          "modified_text": "67 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64f7efd15e05f08f517c1f9f",
          "name": "Ferventcoder.com malware server java.exe",
          "description": "283,000 files, communicating, 200 files, referring, all infected, worms, chargers, various malware.",
          "modified": "2023-10-06T08:04:19.660000",
          "created": "2023-09-06T03:19:45.968000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Hell-On-A-Stick",
            "id": "186907",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 143,
            "FileHash-SHA1": 141,
            "FileHash-SHA256": 1779,
            "domain": 51,
            "email": 1,
            "URL": 126,
            "hostname": 54
          },
          "indicator_count": 2295,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 52,
          "modified_text": "967 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
        "https://vtbehaviour.commondatastorage.googleapis.com/5feceb66ffc86f38d952786c6d696c79c2dbc239dd4e91b46729d73a27fb57e9_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469810&Signature=Mj5ODxCW7tD5UNn6P11Ta7F2cmDLSJuEB7JSLFg%2FERfANmnRR5L7XzDwXxI5G48vkQFx0%2FBMtjMLwWHn6ZHKlt13rfzkvoOu5fJ%2Fb5lMJqUp1rSQIG0JLL80QAnXyJf2W8pL7MvK97Tr4jsCIUfd8ezliJtV5SmahV6Q8lYu2KJUnANrHkA10RFrcT4O26Vk7gbDsuC7caDXC6U9KXTTB0cpC77%2FV7w86ftN2JPXx6oEHUvSj02qsvhKwKQvmM",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0",
        "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI",
        "https://l.us-1.a.mimecastprotect.com/l",
        "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
        "https://vtbehaviour.commondatastorage.googleapis.com/6c39ae0368703f254070a0648c0066115140c3e762d9bf5b52833a037a1e3743_Zenbox%20android.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469752&Signature=Df%2Bamm33qFPdsDg6nWC5FQjse7h4fksSXqONp4nMEItb0gpBwqx66TqcCnFzQplUk6ExMge79qNZR2OElv63sX54D4fSGwI9nvHYhQoiVdZIgf4ct8dIAr%2BYO9jSx0WpPUVFsvf%2FXtXvm6jM5n5v7CGiyFRyAz8PES5g%2FcOlLt%2BDhsc8bhi%2FMU9mAkyyr5nFVPcTmUSHOTNXOeKDUlyRkQE6b9FEbFhUL1h3%2B%2FBVtysh",
        "Requires further research.",
        "https://vtbehaviour.commondatastorage.googleapis.com/2533042959ad1fe050d14ab7536126910a2d240992bff397640382472b6a7c69_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469608&Signature=fK1I2%2FxXVm0l3ZiELwtstes8iVN402Ww%2By%2BgvxYOB0LiC2iO3J9cedWJk1hMIr4IfLSGKprfui8vANzR%2BkWfSd594S%2FFe9A59YKyOA2MFmQTBRXVy6O3xF1e1lPETp5Md%2FbGJCOzrZxdHyReyuk7cgdDDBAewptjJhfTYxql7F9X%2FB4qe9BYWPrvned2fFWfU%2F4G%2F4UBqY9Jj%2BG1CTP%2FaGqOdWFs0Q5cPYZ4bytp",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
        "div>  <p style=\"text-align: justify;\">   <img src=\"static/rId9.jpeg\"/>   </p> </div>",
        "It appears there are 5-7 known affected that I was able to find",
        "Same legal , and quasi governmental pattern identified",
        "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
        "Will pulse remaining Apple IoC\u2019s in next pulse",
        "support.apple.com/ht^*^*^*^ redirects to support.apple.com/de/^*^*^*^*^",
        "https://vtbehaviour.commondatastorage.googleapis.com/5feceb66ffc86f38d952786c6d696c79c2dbc239dd4e91b46729d73a27fb57e9_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775469831&Signature=ZlRZLvCaJ%2F9niupu9DFCvXvfgFpDEOsK%2FsH46CB2zEVUDjcQRNMDp9XXKKx0dekmHQbhl02yqygHPOA8Wty5duGtK216QCvKNkYpbpdOjN7xgAg3AsldciWbqeJr8N4I%2F1%2FPRSdVfB%2BNGaBJKxZG1RQkX206MSvX%2BeY%2FdeEYpq3NYdrPWlxdV0pa3yaqcMrf2s%2FCFSM%2FdO3xt5PKyXWG%2FDCNM5iiuXh8OT2ckhZhf%",
        "This is messy! OTX refreshed and deleted IoC\u2019s. Will continue researching",
        "df57a01 c40f355a0f8a592294187d4fedc257 [Compatibility Mode] - Word",
        "IDS Detections: Observed IcedID CnC Domain in TLS SNI TLS Handshake Failure",
        "I apologize for the lack of reference."
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Mydoom",
            "Icedid",
            "#lowfi:lua:dllsuspiciousexport.a",
            "Trojan:win32/smkldr.h!mtb"
          ],
          "industries": [
            "Technology",
            "Telecom",
            "Legal"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 22,
  "pulses": [
    {
      "id": "6a02eb598920fbedf3e41342",
      "name": "CAPE Sandbox - Dropped Files are Unacceptable",
      "description": "these files were \"dropped\" to me pcchecking-main/Ultra scan script",
      "modified": "2026-05-12T10:43:56.692000",
      "created": "2026-05-12T08:56:57.100000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 376,
        "FileHash-SHA1": 144,
        "FileHash-SHA256": 285,
        "IPv4": 67,
        "URL": 154,
        "domain": 297,
        "hostname": 152,
        "email": 4,
        "YARA": 11
      },
      "indicator_count": 1490,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "18 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a02eb577acf40ff18578c13",
      "name": "CAPE Sandbox - Dropped Files are Unacceptable",
      "description": "these files were \"dropped\" to me pcchecking-main/Ultra scan script",
      "modified": "2026-05-12T10:00:02.785000",
      "created": "2026-05-12T08:56:55.407000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 368,
        "FileHash-SHA1": 142,
        "FileHash-SHA256": 281,
        "IPv4": 61,
        "URL": 104,
        "domain": 295,
        "hostname": 132,
        "email": 2
      },
      "indicator_count": 1385,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "18 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a02eb5bb415c3d8211f2a69",
      "name": "CAPE Sandbox - Dropped Files are Unacceptable",
      "description": "these files were \"dropped\" to me pcchecking-main/Ultra scan script",
      "modified": "2026-05-12T10:00:01.413000",
      "created": "2026-05-12T08:56:59.194000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 368,
        "FileHash-SHA1": 142,
        "FileHash-SHA256": 281,
        "IPv4": 59,
        "URL": 102,
        "domain": 71,
        "hostname": 117
      },
      "indicator_count": 1140,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "18 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a02eb5aebd8b5cd4e1a10b8",
      "name": "CAPE Sandbox - Dropped Files are Unacceptable",
      "description": "these files were \"dropped\" to me pcchecking-main/Ultra scan script",
      "modified": "2026-05-12T10:00:00.080000",
      "created": "2026-05-12T08:56:58.095000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 368,
        "FileHash-SHA1": 142,
        "FileHash-SHA256": 281,
        "IPv4": 59,
        "URL": 102,
        "domain": 71,
        "hostname": 118
      },
      "indicator_count": 1141,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "18 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fc18d0e4586dfaa5fc8e5e",
      "name": "VirusTotal report\n                    for Yandex.exe",
      "description": "[full report on the Yandex.exe malware, which was found on a Windows 11 operating system in the early hours of the morning, has been published by the University of South Africa.] Client changes iphone browser to Bing yesterday.",
      "modified": "2026-05-07T04:55:20.865000",
      "created": "2026-05-07T04:45:04.790000",
      "tags": [
        "pe file",
        "file type",
        "https",
        "sample",
        "performs dns",
        "tls version",
        "creates",
        "urls",
        "ms windows",
        "aslr",
        "code",
        "persistence",
        "defense evasion",
        "malicious",
        "next",
        "getqueryurl412",
        "update with",
        "arguments",
        "info",
        "service",
        "verifymodule128",
        "stopservice815",
        "watchicufile185",
        "getqueryurl409",
        "installertype4",
        "windows sandbox",
        "calls process",
        "default",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "file size",
        "path c",
        "sha1",
        "crc32",
        "win64",
        "accept",
        "shutdown",
        "guard",
        "powershell",
        "payload",
        "back",
        "bing"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
        "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1552",
          "name": "Unsecured Credentials",
          "display_name": "T1552 - Unsecured Credentials"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 422,
        "FileHash-SHA1": 190,
        "FileHash-SHA256": 789,
        "URL": 274,
        "domain": 95,
        "IPv4": 161,
        "hostname": 299,
        "email": 1
      },
      "indicator_count": 2231,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fc18cd07af71dd4c1048a1",
      "name": "VirusTotal report\n                    for Yandex.exe",
      "description": "[full report on the Yandex.exe malware, which was found on a Windows 11 operating system in the early hours of the morning, has been published by the University of South Africa.] Client changes iphone browser to Bing yesterday.",
      "modified": "2026-05-07T04:50:57.126000",
      "created": "2026-05-07T04:45:01.264000",
      "tags": [
        "pe file",
        "file type",
        "https",
        "sample",
        "performs dns",
        "tls version",
        "creates",
        "urls",
        "ms windows",
        "aslr",
        "code",
        "persistence",
        "defense evasion",
        "malicious",
        "next",
        "getqueryurl412",
        "update with",
        "arguments",
        "info",
        "service",
        "verifymodule128",
        "stopservice815",
        "watchicufile185",
        "getqueryurl409",
        "installertype4",
        "windows sandbox",
        "calls process",
        "default",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "file size",
        "path c",
        "sha1",
        "crc32",
        "win64",
        "accept",
        "shutdown",
        "guard",
        "powershell",
        "payload",
        "back",
        "bing"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
        "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1552",
          "name": "Unsecured Credentials",
          "display_name": "T1552 - Unsecured Credentials"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 422,
        "FileHash-SHA1": 189,
        "FileHash-SHA256": 789,
        "URL": 191,
        "domain": 74,
        "IPv4": 145,
        "hostname": 225,
        "email": 1
      },
      "indicator_count": 2036,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fc18ce74d03deacb8b8455",
      "name": "VirusTotal report\n                    for Yandex.exe",
      "description": "[full report on the Yandex.exe malware, which was found on a Windows 11 operating system in the early hours of the morning, has been published by the University of South Africa.] Client changes iphone browser to Bing yesterday.",
      "modified": "2026-05-07T04:50:56.098000",
      "created": "2026-05-07T04:45:02.466000",
      "tags": [
        "pe file",
        "file type",
        "https",
        "sample",
        "performs dns",
        "tls version",
        "creates",
        "urls",
        "ms windows",
        "aslr",
        "code",
        "persistence",
        "defense evasion",
        "malicious",
        "next",
        "getqueryurl412",
        "update with",
        "arguments",
        "info",
        "service",
        "verifymodule128",
        "stopservice815",
        "watchicufile185",
        "getqueryurl409",
        "installertype4",
        "windows sandbox",
        "calls process",
        "default",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "file size",
        "path c",
        "sha1",
        "crc32",
        "win64",
        "accept",
        "shutdown",
        "guard",
        "powershell",
        "payload",
        "back",
        "bing"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
        "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1552",
          "name": "Unsecured Credentials",
          "display_name": "T1552 - Unsecured Credentials"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 422,
        "FileHash-SHA1": 189,
        "FileHash-SHA256": 789,
        "URL": 191,
        "domain": 74,
        "IPv4": 145,
        "hostname": 225,
        "email": 1
      },
      "indicator_count": 2036,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fc18cf1d3c2127ee8a4c0c",
      "name": "VirusTotal report\n                    for Yandex.exe",
      "description": "[full report on the Yandex.exe malware, which was found on a Windows 11 operating system in the early hours of the morning, has been published by the University of South Africa.] Client changes iphone browser to Bing yesterday.",
      "modified": "2026-05-07T04:50:55.377000",
      "created": "2026-05-07T04:45:03.716000",
      "tags": [
        "pe file",
        "file type",
        "https",
        "sample",
        "performs dns",
        "tls version",
        "creates",
        "urls",
        "ms windows",
        "aslr",
        "code",
        "persistence",
        "defense evasion",
        "malicious",
        "next",
        "getqueryurl412",
        "update with",
        "arguments",
        "info",
        "service",
        "verifymodule128",
        "stopservice815",
        "watchicufile185",
        "getqueryurl409",
        "installertype4",
        "windows sandbox",
        "calls process",
        "default",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "file size",
        "path c",
        "sha1",
        "crc32",
        "win64",
        "accept",
        "shutdown",
        "guard",
        "powershell",
        "payload",
        "back",
        "bing"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778128970&Signature=KvxEPuInqFwT1UVxhsUutlnt3Dx3pU%2FZPwCzlabMUZ%2BszI8kfcRbaoWeF5WPYmdf%2FEJWcFuOn%2FHMXzsDaz9mzSs6e%2F31BBO%2Bzn%2Bgsu6PQlevS5%2BPJLSpQQGdvdYxWvjgQtcWfWfdxLulfLOuewCybKwivHDsIS8nxzL4eilUywa96vdRGkU%2BzsWCuRt1DQdteRL%2B4xHM9Iw1lubk48EQZuLZn3%2BHW0WbWmPcpUDlpXmqRt%2",
        "https://www.virustotal.com/ui/file_behaviours/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_CAPE%20Sandbox/html",
        "https://vtbehaviour.commondatastorage.googleapis.com/88becfbea4b9c499c5d01f64204d5114ae0112d0853f0b752262cb831e3e30be_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129039&Signature=EvKpA%2FXa5Pim74y4ZyibLmu25RPaoFGwevAkAPfFbDMkvRXR3nSFuc8fVUtVm9cJPOxY5wIDwaEi%2FLJ9U9W0rvqiycITY9SGa7Vzv97CcCn6PTLJjwF2FShIZiE%2F3eg4zoFce1VJm7HNuAOkyhbu2qCGvF9aqduRhC3CpTxYAepP1kC2GZutTpWIjioblhbRHCSZ5Iz0zRjQaPTUea8mrqeQV2nFqz%2BDwKLItcpvI9yz5mZ7",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129141&Signature=CcrEA1ECv4wxj8UIdmJUnDUBSvoB167GojRL%2BfBa0mcSCEUDoTqJbuuDr0RdXoVPApAzwPy4sOskH98XfBt8CdHdW3GrxPCHjBQAPEn0vhKZPDzoZ4ABLKke%2BYz6uYY0gsF1HVfKzP5N%2FE1i5i2ufi5NAQ6HzeQLM3ynBwu6mwjG%2BrafkkgSaMV00ksubUJfq0zNgvrwUMp%2FS5gFLv66%2F%2B912bzg%2F7Qxk7HpJS3uzwjWJZ",
        "https://vtbehaviour.commondatastorage.googleapis.com/a86b6c59331a4bec79fbbe3b2e5bad589cd60824422d2662488ff6ec7db9cb17_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778129187&Signature=v%2FFdZTv2ZW8gkxMEiHXNqP%2BlysqiATUfJI4Sehiwpl6WMhtq%2BVWfqpe1WfCGvm2J4C1wbISRKhmXGECw7RM0BEKhPwTclqhKJwdtjPMZg%2BKxA5cYmTKM5xgkm0nf1bODU83vDlIhg1ue2cGQhGekvFc0J22ioNQvPNRhwSROTuqvRX9M6cFyV4S2OSwaPzfj24c8GEv%2FyUkWuUsxjSENS5gMNplle9E4Z%2B18BsVsSLO0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1552",
          "name": "Unsecured Credentials",
          "display_name": "T1552 - Unsecured Credentials"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 422,
        "FileHash-SHA1": 189,
        "FileHash-SHA256": 789,
        "URL": 191,
        "domain": 74,
        "IPv4": 145,
        "hostname": 225,
        "email": 1
      },
      "indicator_count": 2036,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d389d979acb0e20217e451",
      "name": "CAPE Sandbox",
      "description": "",
      "modified": "2026-05-06T10:13:24.260000",
      "created": "2026-04-06T10:24:25.849000",
      "tags": [
        "p2404",
        "strong",
        "sha256",
        "library",
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "none rticon",
        "info",
        "path",
        "win32",
        "accept",
        "null",
        "activator",
        "false",
        "black",
        "powershell",
        "error",
        "team",
        "code",
        "date",
        "download",
        "stop",
        "green",
        "class",
        "void",
        "cheap",
        "shutdown",
        "impact",
        "guard",
        "tools",
        "comspec",
        "enterprise",
        "terminal",
        "music",
        "desktop",
        "crypt32",
        "lockfile",
        "write",
        "open",
        "stub",
        "delta",
        "title",
        "body",
        "project",
        "windows sandbox",
        "calls process"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
        "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 172,
        "FileHash-SHA1": 151,
        "FileHash-SHA256": 121,
        "URL": 78,
        "domain": 15,
        "hostname": 59
      },
      "indicator_count": 596,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d389db09844fda2dd3d26d",
      "name": "CAPE Sandbox",
      "description": "",
      "modified": "2026-05-06T10:13:24.260000",
      "created": "2026-04-06T10:24:27.141000",
      "tags": [
        "p2404",
        "strong",
        "sha256",
        "library",
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "none rticon",
        "info",
        "path",
        "win32",
        "accept",
        "null",
        "activator",
        "false",
        "black",
        "powershell",
        "error",
        "team",
        "code",
        "date",
        "download",
        "stop",
        "green",
        "class",
        "void",
        "cheap",
        "shutdown",
        "impact",
        "guard",
        "tools",
        "comspec",
        "enterprise",
        "terminal",
        "music",
        "desktop",
        "crypt32",
        "lockfile",
        "write",
        "open",
        "stub",
        "delta",
        "title",
        "body",
        "project",
        "windows sandbox",
        "calls process"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/f65b955b42f6834de9bd8b084cdab903144a4ddaf38222a1408b4dda59fc3c25_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471046&Signature=m8P0sVa9IvW1ZUOv%2BlJipa01bT4c79dbjaPj0vJUplT1orO5ImM8ekzIM2p0n75b9OEnqifkI5qLdfWrbmw1MrpBdv2Hs%2FONRoVZLAcoIvGCFqtOm1ICKHXI7AQepGbQIIKcchoCtZCxiNmnqeLqW7rvtLrzc7vMo1bjRvzVK03X83b1Ap5vCgvQmNvbBgeaA9McOs4JBMiOjb2%2FtrBU0yB4aY1eKvhfKIsVis5sY90Ljch5h8umrIYl",
        "https://vtbehaviour.commondatastorage.googleapis.com/04debe133ee8e0c49579e2cc84b9ddae38a9ada8d5e64409055573f59f8b374d_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1775471300&Signature=llYVmKPsFPumnoaQibMHdribcji6%2FleUI8SnqlNHmcEnMAkiee7AsqjLt4hAuJ2ohPNbUL3Pcp%2FdiSxG0ou5IxM59BKrDeFqeHfJga%2BFZPNwU9puoAbZeeNlEaDuk76OjORjSNUMwTg3Z%2Fqq5grDxUUbQ7tO6Yvc58%2FJ26Mbgh2DSdT8qT6wcBZD9RUcie7RY5wMC1TDAalZdS5wiqTw1I412KZa0Ka9Q8pN0jBXaionvI"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 172,
        "FileHash-SHA1": 151,
        "FileHash-SHA256": 121,
        "URL": 80,
        "domain": 17,
        "hostname": 59
      },
      "indicator_count": 600,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "powershell.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "powershell.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780211256.080183
}