{
  "type": "Domain",
  "indicator": "process.name",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/process.name",
    "alexa": "http://www.alexa.com/siteinfo/process.name",
    "indicator": "process.name",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2952018669,
      "indicator": "process.name",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 46,
      "pulses": [
        {
          "id": "69d4e63921cbadb426b7cd2a",
          "name": "Detections for the Axios supply chain compromise",
          "description": "A supply chain attack targeting Axios npm package versions 1.14.1 and 0.30.4 introduced a malicious transitive dependency (plain-crypto-js@4.2.1) that executed during installation. The attack deploys cross-platform payloads across Linux, Windows, and macOS through a consistent pattern: Node.js spawns OS-native shells to retrieve and execute remote payloads in detached or hidden contexts. Linux victims receive a Python-based RAT, Windows systems get a PowerShell backdoor with registry persistence, and macOS hosts are compromised with a Mach-O binary backdoor. All variants beacon to the same C2 infrastructure, performing host fingerprinting, process enumeration, filesystem reconnaissance, and arbitrary code execution. The malicious activity is reliably detected through behavioral signatures focusing on unusual Node.js process ancestry and remote payload retrieval rather than static indicators.",
          "modified": "2026-05-07T11:10:38.058000",
          "created": "2026-04-07T11:10:49.715000",
          "tags": [
            "supply chain attack",
            "post-install execution",
            "axios"
          ],
          "references": [
            "https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "plain-crypto-js",
              "display_name": "plain-crypto-js",
              "target": null
            },
            {
              "id": "ld.py",
              "display_name": "ld.py",
              "target": null
            },
            {
              "id": "wt.exe",
              "display_name": "wt.exe",
              "target": null
            },
            {
              "id": "com.apple.act.mond",
              "display_name": "com.apple.act.mond",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1132.001",
              "name": "Standard Encoding",
              "display_name": "T1132.001 - Standard Encoding"
            },
            {
              "id": "T1036.005",
              "name": "Match Legitimate Name or Location",
              "display_name": "T1036.005 - Match Legitimate Name or Location"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1059.004",
              "name": "Unix Shell",
              "display_name": "T1059.004 - Unix Shell"
            },
            {
              "id": "T1055.012",
              "name": "Process Hollowing",
              "display_name": "T1055.012 - Process Hollowing"
            },
            {
              "id": "T1195.002",
              "name": "Compromise Software Supply Chain",
              "display_name": "T1195.002 - Compromise Software Supply Chain"
            },
            {
              "id": "T1027.003",
              "name": "Steganography",
              "display_name": "T1027.003 - Steganography"
            },
            {
              "id": "T1518.001",
              "name": "Security Software Discovery",
              "display_name": "T1518.001 - Security Software Discovery"
            },
            {
              "id": "T1543.001",
              "name": "Launch Agent",
              "display_name": "T1543.001 - Launch Agent"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 7,
            "URL": 1,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 23,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386492,
          "modified_text": "23 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ebff51da5765b1e4d9509e",
          "name": "From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic",
          "description": "Lazarus, a North Korean state-sponsored threat actor, has launched a new campaign called ClickFake Interview targeting cryptocurrency job seekers. This campaign, an evolution of the previously documented Contagious Interview, uses fake job interview websites to deploy the GolangGhost backdoor on Windows and macOS systems. The infection chain leverages the ClickFix tactic, downloading and executing malicious payloads during the interview process. The campaign primarily targets centralized finance (CeFi) entities, aligning with Lazarus' focus on cryptocurrency-related targets. Notable changes include targeting non-technical roles and using ReactJS-based websites for the fake interviews. The malware provides remote control and data theft capabilities, including browser information exfiltration.",
          "modified": "2025-05-01T14:02:57.427000",
          "created": "2025-04-01T14:59:29.783000",
          "tags": [
            "clickfix",
            "north korea",
            "golangghost",
            "cryptocurrency",
            "frostyferret",
            "backdoor",
            "job interviews",
            "cefi"
          ],
          "references": [
            "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GolangGhost",
              "display_name": "GolangGhost",
              "target": null
            },
            {
              "id": "FrostyFerret",
              "display_name": "FrostyFerret",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            }
          ],
          "industries": [
            "Finance",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 58,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 12,
            "URL": 7,
            "YARA": 9,
            "domain": 40,
            "hostname": 24
          },
          "indicator_count": 100,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386492,
          "modified_text": "394 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ce83659fb527eb96c998a2",
          "name": "Malicious Axios Packages Published to npm in New Supply Chain Compromise",
          "description": "A recent supply chain compromise has been identified affecting the widely utilized JavaScript HTTP client axios, wherein malicious versions of the package were published to npm using compromised maintainer credentials. The exploitation involves the deployment of a Remote Access Trojan (RAT) through a fabricated dependency labeled plain-crypto-js@4.2.1. Notably, this dependency is not directly imported by axios, functioning instead as a dropper that executes a postinstall script upon installation.",
          "modified": "2026-05-04T15:01:49.491000",
          "created": "2026-04-02T14:55:33.872000",
          "tags": [
            "truesec",
            "post body",
            "temp",
            "cicd",
            "rotate npm",
            "monitor",
            "npm supplychain",
            "risk detection",
            "urls",
            "network",
            "remote access"
          ],
          "references": [
            "https://www.truesec.com/hub/blog/malicious-axios-packages-npm-in-supply-chain-compromise",
            "https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan",
            "https://www.derp.ca/research/axios-npm-supply-chain-rat/",
            "https://socket.dev/blog/axios-npm-package-compromised",
            "https://socradar.io/blog/axios-npm-supply-chain-attack-2026-ciso-guide/",
            "https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust",
            "https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections",
            "https://www.crowdstrike.com/en-us/blog/stardust-chollima-likely-compromises-axios-npm-package/",
            "https://blog.nviso.eu/2026/04/03/the-axios-npm-supply-chain-incident-fake-dependency-real-backdoor/",
            "https://hunt.io/blog/axios-supply-chain-attack-ta444-bluenoroff",
            "https://www.zscaler.com/blogs/security-research/supply-chain-attacks-surge-march-2026",
            "https://blog.talosintelligence.com/axois-npm-supply-chain-incident/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1070.004",
              "name": "File Deletion",
              "display_name": "T1070.004 - File Deletion"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1195.001",
              "name": "Compromise Software Dependencies and Development Tools",
              "display_name": "T1195.001 - Compromise Software Dependencies and Development Tools"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 58,
            "FileHash-SHA1": 62,
            "FileHash-SHA256": 60,
            "URL": 28,
            "domain": 19,
            "email": 5,
            "hostname": 10,
            "CIDR": 2,
            "CVE": 2
          },
          "indicator_count": 246,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 544,
          "modified_text": "26 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69665d5c109a09813bce8749",
          "name": "Booking.com Phishing Campaign Targeting Hotels and Customers - Sekoia.io Blog",
          "description": "A new report from cybersecurity firm Sekoia.io examines a sophisticated phishing campaign targeting Booking.com and its customers around the world, as well as the impact of infostealing malware.",
          "modified": "2026-02-12T14:01:38.116000",
          "created": "2026-01-13T14:57:32.880000",
          "tags": [
            "purerat",
            "clickfix",
            "booking",
            "powershell",
            "zip archive",
            "run registry",
            "october",
            "sekoia soc",
            "ip address",
            "c2 server",
            "facebook",
            "malicious",
            "april",
            "date",
            "refresh",
            "quirkyloader",
            "purecrypter",
            "twitter",
            "cluster",
            "clearfake",
            "malware",
            "threat"
          ],
          "references": [
            "https://blog.sekoia.io/phishing-campaigns-i-paid-twice-targeting-booking-com-hotels-and-customers/"
          ],
          "public": 1,
          "adversary": "Threat",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "PureRAT",
              "display_name": "PureRAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Hospitality",
            "Hotel",
            "Banking"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 5,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 4,
            "URL": 28,
            "domain": 70,
            "hostname": 2
          },
          "indicator_count": 113,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "107 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "685504a184b712521ffeb975",
          "name": "Threat Advisory: LightPerlGirl Malware",
          "description": "The malware campaign centered around a threat actor utilizing a fake CAPTCHA popup dubbed ClickFix, which deceives users into executing malicious PowerShell commands. This initial compromise occurs when a user visits a compromised WordPress site that serves a JavaScript payload, mimicking a legitimate security check. The malicious dialog prompts the user to engage with a PowerShell command, which is obfuscated to evade detection. This command reaches out to a command-and-control (C2) server at cmbkz8kz1000108k2carjewzf.info and initiates a multi-stage infection process.",
          "modified": "2025-07-20T06:03:58.975000",
          "created": "2025-06-20T06:50:09.809000",
          "tags": [
            "todyl",
            "strong",
            "powershell",
            "c2 server",
            "urex",
            "exwpl",
            "helpio",
            "lightperlgirl",
            "runas",
            "ascii",
            "execution",
            "next",
            "info",
            "attack",
            "defender",
            "path",
            "main",
            "never",
            "hunt",
            "contact"
          ],
          "references": [
            "https://www.todyl.com/blog/threat-advisory-lightperlgirl-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "LightPerlGirl",
              "display_name": "LightPerlGirl",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1059.003",
              "name": "Windows Command Shell",
              "display_name": "T1059.003 - Windows Command Shell"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1218.012",
              "name": "Verclsid",
              "display_name": "T1218.012 - Verclsid"
            },
            {
              "id": "T1547.001",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1548.002",
              "name": "Bypass User Account Control",
              "display_name": "T1548.002 - Bypass User Account Control"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CIDR": 3,
            "URL": 25,
            "domain": 3,
            "hostname": 8
          },
          "indicator_count": 39,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 539,
          "modified_text": "315 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "684124ef2e8badb3e5395e43",
          "name": "Windows Defender Exclusions Added via PowerShell | Detection Rules Overview",
          "description": "The full text of this year's EU Referendum, which will take place on 26 November, has been published.. and it will not appear on BBC Radio 5 live or on iPlayer.",
          "modified": "2025-06-05T05:02:39.006000",
          "created": "2025-06-05T05:02:39.006000",
          "tags": [
            "logstash",
            "create",
            "kubernetes",
            "kibana",
            "elastic agent",
            "system",
            "google cloud",
            "filebeat",
            "elasticsearch",
            "agent",
            "error",
            "span",
            "project",
            "general",
            "powershell",
            "upgrade",
            "apache",
            "cloud",
            "curator",
            "icmp",
            "service",
            "monitoring",
            "install",
            "prometheus",
            "watcher",
            "date",
            "rest",
            "scroll",
            "hosts",
            "collector",
            "local",
            "benchmark",
            "graphite",
            "legacy",
            "tips",
            "codec",
            "defender",
            "spaces",
            "korean",
            "frozen",
            "score",
            "observer",
            "multi",
            "matrix",
            "trickbot",
            "virustotal",
            "false",
            "stop",
            "stack",
            "ms windows",
            "intel",
            "pe32",
            "pe32 executable"
          ],
          "references": [
            "https://www.elastic.co/guide/en/security/current/windows-defender-exclusions-added-via-powershell.html"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 4,
            "hostname": 17,
            "URL": 29,
            "FileHash-SHA256": 161,
            "FileHash-MD5": 107,
            "FileHash-SHA1": 105
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "360 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67f861c5c9347add1cf1889f",
          "name": "Lazarus ClickFake Interview Campaign: From Contagious to ClickFix Malware Tactics",
          "description": "In March 2025, cybersecurity analysts observed that the North Korean state-sponsored group Lazarus initiated a sub-campaign named \"ClickFake Interview,\" evolving from their earlier \"Contagious Interview\" operations. This campaign involves contacting individuals via social media, inviting them to fake job interviews on counterfeit cryptocurrency-related websites. During these interviews, users encounter fabricated technical issues prompting them to download malicious software, which subsequently installs backdoors on both Windows and macOS systems. This strategy allows Lazarus to gain unauthorized access to victims' devices, posing significant security risks. \ue200cite\ue202turn0search0\ue201\ue206",
          "modified": "2025-05-11T00:01:34.348000",
          "created": "2025-04-11T00:26:45.507000",
          "tags": [
            "lazarus",
            "windows",
            "golangghost",
            "cefi",
            "sekoia",
            "frostyferret",
            "clickfix tactic",
            "temp",
            "march",
            "dprk",
            "invisibleferret",
            "terminal",
            "macos",
            "sharpknot",
            "manuscrypt",
            "bluenoroff",
            "february",
            "beavertail",
            "path",
            "kraken",
            "robinhood"
          ],
          "references": [
            "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/#h-iocs-and-technical-details"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Armature_TIP",
            "id": "308911",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_308911/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 14,
            "YARA": 9,
            "domain": 40,
            "hostname": 25
          },
          "indicator_count": 109,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 43,
          "modified_text": "385 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67f33233092ab19b74879403",
          "name": "MacOS M2 Chip Infiltration: Game Center & XBOX Pod Game & Chat Server",
          "description": "pulse explores a variety of files, objects, and functions that could be associated with different system components, libraries, and protocols. It highlights a wide range of potential vulnerabilities that may exist in software related to system functions, APIs, data handling, and device interactions, including issues in devices like game controllers, HID devices, and platform-specific services (such as Apple and Android). The pulse references several components across different platforms (macOS, iOS, ARM architectures, and others), with a focus on low-level code, encryption libraries, system utilities, and network protocols like TCP, IP, and Bluetooth. The identified vulnerabilities could involve buffer overflows, deprecated functions, improper memory handling, and potential exploit vectors related to system security, performance, and integrity.",
          "modified": "2025-05-07T02:03:20.735000",
          "created": "2025-04-07T02:02:27.322000",
          "tags": [
            "helper macro",
            "param",
            "param inccache",
            "kerberos",
            "ccache",
            "api function",
            "ccapi",
            "api version",
            "param ioccache",
            "ccacheserver",
            "win32",
            "null",
            "code",
            "win64",
            "error",
            "union",
            "ccapideprecated",
            "ccacheapi",
            "ccapiv2h",
            "apple",
            "export",
            "united",
            "ccache api",
            "cplusplus",
            "x8664",
            "typedef",
            "patheq",
            "none",
            "popen",
            "terminate",
            "false",
            "winenv",
            "winexe",
            "frozen",
            "winservice",
            "python",
            "posixthreads",
            "pyhavecondvar",
            "ntthreads",
            "vista",
            "pyemulatedwincv",
            "ntddivista",
            "semaphore",
            "pycondt",
            "win7",
            "pybuildcore",
            "fall",
            "copyright",
            "technology",
            "all rights",
            "reserved",
            "america",
            "government",
            "within that",
            "klprincipal",
            "klloginoptions",
            "inpassword",
            "klboolean",
            "klindex inindex",
            "login",
            "klstatus",
            "kerberos login",
            "inst",
            "regexp",
            "typeof e",
            "function",
            "typeof t",
            "typeof o",
            "width",
            "typeof",
            "pseudo",
            "body",
            "sticky",
            "date",
            "class",
            "this",
            "void",
            "accept",
            "span",
            "krb5callconv",
            "apoptsreserved",
            "tktflgreserved",
            "kdcoptreserved",
            "krb5data",
            "eblock",
            "krb5address",
            "krb5keyblock",
            "service",
            "realm",
            "format",
            "general",
            "internal",
            "entropy",
            "mask",
            "mcpeerid",
            "mcsession",
            "property",
            "protocol",
            "create",
            "nsuinteger",
            "notifies",
            "mcsession api",
            "interface",
            "bonjour",
            "ascii lowercase",
            "abc company",
            "section",
            "bonjour txt",
            "mcextern",
            "attribute",
            "mcextern extern",
            "mcexternweak",
            "nsenum",
            "nsinteger",
            "mcerrorcode",
            "mcerrorunknown",
            "mcerrortimedout",
            "bonjour apis",
            "stop",
            "peer",
            "example",
            "tags",
            "session",
            "nsprogress",
            "nserror",
            "nsstring",
            "nsurl",
            "nsarray",
            "note",
            "ui element",
            "utf8 encoding",
            "nscopying",
            "nsdictionary",
            "webpackrequire",
            "webpackexports",
            "object",
            "adobe systems",
            "adobe",
            "incorporated",
            "dissemination",
            "touchmove",
            "window",
            "launch",
            "close",
            "core",
            "webview",
            "nwebpackrequire",
            "arraybuffer",
            "name",
            "typedarray",
            "prototype",
            "string",
            "number",
            "nvar",
            "meta",
            "infinity",
            "generator",
            "zero",
            "epsilon",
            "observer",
            "android",
            "freeze",
            "trim",
            "canvas",
            "simple",
            "bind",
            "fast",
            "next",
            "patch",
            "rest",
            "middle",
            "find",
            "enumerate",
            "facebook",
            "executor",
            "apiunavailable",
            "gamecontroller",
            "gcbuttoninput",
            "gcswitchinput",
            "nsobject",
            "apiavailable",
            "hid device",
            "cfstr",
            "iohiddeviceref",
            "boolean value",
            "c iohidmanager",
            "iohidmanager",
            "c iohiddevice",
            "issequential",
            "bool sequential",
            "bool canwrap",
            "nsset",
            "nsunavailable",
            "gcswitchelement",
            "bool",
            "share button",
            "xbox controller",
            "xbox elite",
            "xbox series",
            "gcxboxgamepad",
            "gcpoint2",
            "gcpoint2make",
            "gcpoint2 p",
            "cfinline bool",
            "gcpoint2equal",
            "gcpoint2 point1",
            "gcpoint2 point2",
            "gcrelativeinput",
            "isanalog",
            "bool analog",
            "hasinclude",
            "gcaxis2dinput",
            "gcpoint2 value",
            "gcaxiselement",
            "certain",
            "gcaxisinput",
            "gcbuttonelement",
            "gccontroller",
            "nsnotification",
            "chhapticengine",
            "gcmicrogamepad",
            "input",
            "menu button",
            "gcdevicelight",
            "gccolor",
            "x axis",
            "xvalue",
            "developers",
            "functionality",
            "options button",
            "sf symbols",
            "elements",
            "gcdevice",
            "gctouchstate",
            "gctouchstateup",
            "apideprecated",
            "gckeyboard",
            "gcmouse",
            "nsswiftname",
            "gcdevicebattery",
            "battery level",
            "direction pad",
            "directionapad",
            "thumbstick",
            "gcdevicecursor",
            "a controller",
            "gccolor color",
            "gcinputbuttona",
            "gcinputbuttonb",
            "button b",
            "check",
            "a element",
            "c nil",
            "nsenumerator",
            "siri remote",
            "equivalent",
            "down",
            "left",
            "right",
            "kindof",
            "handle button",
            "c device",
            "immediate input",
            "dualsense",
            "positional",
            "sony dualsense",
            "gcmotion",
            "dualshock",
            "uievent",
            "controllers",
            "uikit user",
            "uiview",
            "method",
            "nsdata",
            "axes",
            "nsdata source",
            "return",
            "nullable",
            "nsdata object",
            "button",
            "shoulder",
            "extended",
            "gamepad profile",
            "nsdata api",
            "gcgamepad",
            "sizeof",
            "standard",
            "gckeyboardinput",
            "keyboard",
            "nsstring const",
            "controller",
            "back buttons",
            "game controller",
            "back",
            "keypad",
            "delete",
            "insert",
            "home",
            "right arrow",
            "left arrow",
            "down arrow",
            "up arrow",
            "korean",
            "backspace",
            "alongside",
            "gckeyuparrow",
            "gckeycode const",
            "lang1",
            "gclinearinput",
            "gcquaternion",
            "gcacceleration",
            "y axis",
            "z axis",
            "gcmouse mouse",
            "gcmouse class",
            "mice",
            "gcmouseinput",
            "mouse profile",
            "scroll",
            "nsdata instance",
            "a alias",
            "press",
            "micro profile",
            "siri remotes",
            "b button",
            "a gcinput",
            "button a",
            "nsoptions",
            "examining",
            "c sfsymbolsname",
            "apple tv",
            "remote",
            "control center",
            "a set",
            "game",
            "gcracingwheel",
            "gcbundlewithpid",
            "gcinputbuttonx",
            "gcinputbuttony",
            "gcinputshifter",
            "gckeya",
            "gckeyb",
            "gckeybackslash",
            "rawvalue",
            "apple swift",
            "o librarylevel",
            "swift import",
            "element",
            "indices",
            "iterator",
            "subsequence",
            "kerberoscomerr",
            "const",
            "permission",
            "mit software",
            "suitability",
            "athena",
            "openvision",
            "gssdllimp",
            "gssapigenerich",
            "this software",
            "purpose",
            "disclaims all",
            "warranties with",
            "regard to",
            "constraint",
            "kerberosprofile",
            "krb5profileh",
            "const names",
            "newvalue",
            "1429577728l",
            "gnuc",
            "mach",
            "omuint32",
            "gssapikrb5h",
            "form",
            "uid form",
            "client function",
            "asrep",
            "including",
            "preauth",
            "db entry",
            "free",
            "pointer",
            "rock",
            "neither",
            "direct",
            "damage",
            "minorstatus",
            "gssbuffert",
            "gssctxidt",
            "gssoid",
            "gssnamet",
            "gsscredidt",
            "gssoidset",
            "gssapi",
            "first",
            "alcapi",
            "alcapientry",
            "alcboolean",
            "targetosmac",
            "alcdevice",
            "alcenum param",
            "alalch",
            "alcchar",
            "alcsizei",
            "capture",
            "but not",
            "limited",
            "openal cross",
            "apple computer",
            "redistribution",
            "is provided",
            "type",
            "alvoid",
            "alint",
            "openal",
            "aluint sid",
            "alenum",
            "alint value",
            "aluint property",
            "alvoid nonnull",
            "alfloat",
            "write",
            "openalopenalh",
            "umbrella header",
            "alenum param",
            "alapi",
            "aluint bid",
            "alsizei",
            "alfloat value",
            "alapientry",
            "aluint",
            "verify",
            "play",
            "speed",
            "bits",
            "albuffer3i",
            "albufferdata",
            "albufferf",
            "albufferfv",
            "albufferi",
            "albufferiv",
            "aldistancemodel",
            "aldopplerfactor",
            "algetbooleanv",
            "algetbuffer3f",
            "iousbhostdevice",
            "iousbhostobject",
            "iousbhostpipe",
            "iousbhoststream",
            "iousbhost",
            "brief",
            "usb host",
            "bool yes",
            "bool no",
            "advance",
            "iousbhostfamily",
            "kernel",
            "ioreturn status",
            "nsnumber",
            "ioreturn error",
            "usb device",
            "select",
            "commands",
            "enqueue",
            "nsmutabledata",
            "field",
            "enum",
            "options",
            "retrieve",
            "iosource",
            "current address",
            "bos descriptor",
            "extract",
            "a descriptor",
            "license",
            "io request",
            "abort",
            "discussion",
            "stream",
            "please",
            "swift api",
            "iousbbitrange",
            "iousbbitrange64",
            "iousbbit",
            "client",
            "usb controller",
            "usb descriptor",
            "unknown",
            "critical",
            "refer",
            "link",
            "send",
            "same",
            "common ui",
            "bluetooth",
            "service browser",
            "option",
            "1001",
            "cfstringref",
            "deprecated",
            "macos",
            "returns",
            "abstract",
            "nswindow",
            "creates",
            "mac os",
            "uuids",
            "uuid",
            "sdp service",
            "nsimage",
            "nsview",
            "mpasskeystring",
            "nsmutablearray",
            "uuid array",
            "ioreturn",
            "runmodal",
            "group",
            "command",
            "byte",
            "masks",
            "pduid",
            "l2cap",
            "range",
            "opcode",
            "packet",
            "major",
            "local",
            "profiles",
            "iobluetooth",
            "framework",
            "support",
            "host controller",
            "rfcomm",
            "minor class",
            "pseudoclass",
            "specific device",
            "headset",
            "peripheral",
            "desktop",
            "glasses",
            "device reset",
            "no hci",
            "hci controller",
            "returns number",
            "variable number",
            "packdata",
            "cstring",
            "pass",
            "path",
            "deprecated in",
            "obex session",
            "obexsessionref",
            "rfcomm channel",
            "obex",
            "does not",
            "l2cap channel",
            "inrefcon",
            "device",
            "length",
            "obex spec",
            "error code",
            "make",
            "headerid",
            "april",
            "alarm",
            "avrcplog",
            "audiolog",
            "bccmd16touint16",
            "bccmd16touint8",
            "bccmd32touint32",
            "hfplog",
            "obexcreatevcard",
            "obexsessionget",
            "uint16tobccmd16",
            "intents",
            "created",
            "andrea gottardo",
            "inimage",
            "intentsui",
            "project version",
            "inshortcut",
            "ibdesignable",
            "invoiceshortcut",
            "nsbundle",
            "siri",
            "beralloct",
            "berbvarrayadd",
            "berbvarrayfree",
            "berbvdup",
            "berbvecadd",
            "berbvecfree",
            "berbvfree",
            "berdump",
            "berdup",
            "berdupbv",
            "ldap",
            "vdspinput1",
            "vectorsize",
            "iirchannel",
            "osvkerndsplib",
            "pragmaonce",
            "paul chang",
            "fri mar",
            "original code",
            "apple operating",
            "modifications",
            "apple public",
            "source license",
            "version",
            "lframesize",
            "i386",
            "picify",
            "callmcount",
            "nonlazystub",
            "align",
            "roundtostack",
            "leaf",
            "import",
            "carnegie mellon",
            "carnegie",
            "inline void",
            "software",
            "school",
            "august",
            "xnuarchi386selh",
            "next computer",
            "mike demoney",
            "bruce martin",
            "state segment",
            "nxswappedfloat",
            "osswapint32",
            "inline float",
            "inline double",
            "osswapint64",
            "armlimitsh",
            "arm64",
            "useclangtypes",
            "bsdarmtypesh",
            "int8t",
            "gnuc typedef",
            "uint8t",
            "ansi c",
            "ansi",
            "use wchart",
            "armmcontexth",
            "mcontextt",
            "armparamh",
            "round",
            "darwinsizet",
            "darwinalign",
            "uint32t",
            "darwinalign32",
            "warranties",
            "a particular",
            "university",
            "armarch6zk",
            "armarch6k",
            "armarch4t",
            "armarch4",
            "http",
            "capbitnb",
            "legacy",
            "armfeatureflag",
            "california",
            "notice",
            "berkeley",
            "limited to",
            "define",
            "useclanglimits",
            "lp64",
            "ansisource",
            "darwincsource",
            "longmin",
            "ulongmax",
            "parameter",
            "vmmemcoherent",
            "vmmemearlyack",
            "vmmeminner",
            "vmmemrt",
            "vmmemguarded",
            "armmemorytypesh",
            "armpalroutinesh",
            "read",
            "struct",
            "booleant",
            "cluster",
            "devbsize",
            "mclbytes",
            "unix system",
            "laboratories",
            "devbshift",
            "thumb",
            "armv5",
            "armv7",
            "cache",
            "neon",
            "swift",
            "bsdarmprofileh",
            "xxx todo",
            "block",
            "mcount",
            "mcountinit",
            "mcountenter",
            "splhigh",
            "armthreadh",
            "armtraph",
            "dflssiz",
            "targetososx",
            "maxssiz",
            "rliminfinity",
            "maxcsiz",
            "bsdarmvmparamh",
            "dfldsiz",
            "maxdsiz",
            "xxx stack",
            "armsignal",
            "int64t",
            "armmachtypesh",
            "int32t",
            "methods",
            "thread",
            "hasapplepac",
            "atmatmtypesh",
            "libkernlocksh",
            "fortifysource",
            "libkerncopyioh",
            "sizedby",
            "darwinosinline",
            "stdcversion",
            "osswapint16",
            "libkerncrch",
            "blockexport",
            "vaargs",
            "blockrelease",
            "blockh",
            "collection",
            "blockcopy",
            "ososbaseh",
            "base",
            "byteoffset",
            "host endianess",
            "generic host",
            "generic",
            "osmalloc",
            "osmalloctag tag",
            "osmalloctag",
            "pci device",
            "uint32",
            "uint32 mask",
            "safecastptr",
            "sint32",
            "osaddatomic64",
            "uint8",
            "libkern c",
            "internal error",
            "core osreturn",
            "libkern",
            "values",
            "pragmamark",
            "kexts",
            "kext",
            "c string",
            "grab",
            "osostypesh",
            "boolean",
            "unsignedwide",
            "uint32 hi",
            "buildtime value",
            "libkernversionh",
            "versionmajor",
            "versionminor",
            "versionvariant",
            "versionrevision",
            "ostype",
            "osrelease",
            "libkernsysctlh",
            "instructions",
            "data cache",
            "future",
            "rbleft",
            "rbright",
            "rbgetparent",
            "splayright",
            "splayleft",
            "rbsetcolor",
            "rbblack",
            "rbgetcolor",
            "comp",
            "main",
            "stdc",
            "msdos",
            "windows",
            "sys16bit",
            "zlibdll",
            "zextern",
            "zconfh",
            "model",
            "zextern int",
            "zstreamerror",
            "znull",
            "zbuferror",
            "zmemerror",
            "zstreamend",
            "zdataerror",
            "zfinish",
            "enough",
            "possible",
            "trailer",
            "compiler",
            "countedby",
            "sparta",
            "osatomic",
            "ipcipctypesh",
            "ipcobjectnull",
            "ipcobjectdead",
            "osreturn",
            "nfskrpch",
            "xdrbuf",
            "xdrbuf xbp",
            "xbptr",
            "xbleft",
            "tlen",
            "lval",
            "xbcleanup",
            "xbtype",
            "xbflags",
            "nfsargsversion",
            "file",
            "packed",
            "nfshz",
            "mount",
            "term",
            "restrict",
            "stats",
            "nfsbitmapset",
            "nfsver3",
            "nfsxunsigned",
            "attr",
            "nfsprogram",
            "nfssmallfh",
            "which",
            "from",
            "mark",
            "obsolete",
            "ip address",
            "iaddrt",
            "netinetbootph",
            "nvmaxtext",
            "magic",
            "etheraddrlen",
            "target",
            "byteorder",
            "bigendian",
            "littleendian",
            "dest",
            "igmp",
            "ushort",
            "inpcbptr",
            "inpcblistentry",
            "ipsec",
            "pcbs",
            "cookie",
            "netinetinstath",
            "minimal",
            "result",
            "arp packet",
            "icmpparamprob",
            "icmpredirect",
            "address",
            "ditto",
            "ip filter",
            "ipv4",
            "ip packet",
            "inject",
            "wifi",
            "server",
            "tcpmaxnotifyack",
            "wired",
            "ecn setup",
            "notify",
            "slow",
            "definitions",
            "tcptmax",
            "retransmit",
            "mptcp",
            "tcpsclosewait",
            "tcpsestablished",
            "tcpstimewait",
            "tcpseq",
            "timer drift",
            "sack",
            "char",
            "icmp",
            "synack",
            "tcpoptnop",
            "syndata",
            "ver",
            "internet",
            "iopcidevice",
            "constant",
            "perst",
            "localonly",
            "iooptionbits",
            "optional access",
            "ioservice",
            "open",
            "pcidriverkith",
            "osmetaclassbase",
            "iorpc rpc",
            "auditpipeiobase",
            "auditsdeviobase",
            "ioctls",
            "data",
            "the software",
            "stdargh",
            "hasincludenext",
            "eli friedman",
            "as is",
            "hack",
            "atomic",
            "atomicseqcst",
            "clangstdatomich",
            "stdchosted",
            "stdboolh",
            "needwintt",
            "stddefh",
            "hasbuiltin",
            "const src",
            "xnumembersize",
            "const dst",
            "wcharmax",
            "wcharmin",
            "limits",
            "kernelstdinth",
            "lp64 typedef",
            "intmaxc",
            "uintmaxc",
            "ptrauth",
            "olddata",
            "value",
            "declkey",
            "abi pointer",
            "c function",
            "float16",
            "fltevalmethod",
            "legacy bsd",
            "c standard",
            "sincospi",
            "cosp",
            "x8664monotonich",
            "staticifentry",
            "hasmte",
            "vmmemorytypesh",
            "vmwimgdefault",
            "wimg",
            "extvectortype",
            "utilfunction",
            "aligned",
            "srcptr",
            "vmpmaph",
            "vmdyldpagerh",
            "vmvmfaulth",
            "vmvmmaph",
            "development",
            "debug",
            "vmvmoptionsh",
            "vmvmpageouth",
            "kasantbi",
            "machvmmemtagh",
            "given",
            "vmmemtagptrsize",
            "vmmemtagtagsize",
            "copy",
            "vmsharedregionh",
            "vfsvfssupporth",
            "veclib",
            "master",
            "world wide",
            "various",
            "veclibtypes",
            "carbonlib",
            "availability",
            "carbon",
            "noncarbon cfm",
            "vbasicops",
            "shift",
            "vforceh",
            "vdsplength n",
            "realp",
            "nonnull",
            "vector",
            "dspsplitcomplex",
            "ieee",
            "dspcomplex",
            "uuiduuidh",
            "uuiddefine",
            "public",
            "uuid library",
            "kernelserver",
            "simpleroutine",
            "undkey",
            "execution",
            "strings array",
            "user",
            "title string",
            "info",
            "1024",
            "xmldatat",
            "undreplyref",
            "kernsuccess",
            "osaction",
            "targetosiphone",
            "istargetvendor",
            "targetcpux8664",
            "targetosunix",
            "targetcpuppc",
            "targetcpuppc64",
            "targetcpux86",
            "targetrtmaccfm",
            "bridge",
            "svflags",
            "svpavreal",
            "svpavreify",
            "xpvav",
            "svany",
            "avfillp",
            "for apidoc",
            "mutableav",
            "avrealoff",
            "pltopenv",
            "stmtstart",
            "stmtend",
            "copfile",
            "plcurstackinfo",
            "copfilegv",
            "cophinthashget",
            "loop",
            "stack",
            "beware",
            "orig",
            "loops",
            "this file",
            "the build",
            "plbitcount",
            "u8 value",
            "cvflags",
            "xpvcv",
            "mutableptr",
            "perlcore",
            "cvgv",
            "cvfile",
            "cvfmethod",
            "cvflvalue",
            "cvfconst",
            "anon",
            "doinit extconst",
            "ebcdic",
            "extconst u8",
            "index",
            "ascii platform",
            "confusingly",
            "u8 pla2e",
            "pla2e",
            "u8 ple2a",
            "guard",
            "declspec",
            "extconst",
            "ext externc",
            "init",
            "larry wall",
            "gnu general",
            "readme file",
            "multiplicity",
            "plsawampersand",
            "do not",
            "perliogetc",
            "perlioputc",
            "perliostdoutf",
            "perlio",
            "perlfeatureh",
            "featuresubbit",
            "featuremyrefbit",
            "featurefcbit",
            "featureisabit",
            "featuresaybit",
            "featurestatebit",
            "featuretrybit",
            "hintfeaturemask",
            "ffspace",
            "process",
            "ffdecimal",
            "ffend",
            "gvgp",
            "gvflags",
            "gvnamehek",
            "svtype",
            "gvegv",
            "gvstash",
            "gvxpvgv",
            "svtpvgv",
            "svtpvlv",
            "super",
            "edit directly",
            "djgpp",
            "bitbucket",
            "perlsysinitbody",
            "perlioinit",
            "perlsystermbody",
            "w macros",
            "wexitstatus",
            "shpath",
            "mkdir",
            "rotl64",
            "rotl32",
            "rotate x",
            "rotr32",
            "can64bithash",
            "rotr64",
            "ivsize",
            "u8to16le",
            "rotluv",
            "rotruv",
            "sbox32maxlen",
            "plhashstate",
            "perlhash",
            "perl",
            "usehashseed",
            "perlseenhvfunch",
            "perlhashseed",
            "siphash24",
            "siphash13",
            "seed",
            "c program",
            "c type",
            "c compiler",
            "gcc attribute",
            "longsize",
            "c preprocessor",
            "install",
            "kill",
            "cont",
            "thus",
            "ext declspec",
            "dext",
            "for apidocitem",
            "utf8",
            "ascii",
            "fitsin8bits",
            "nativetolatin1",
            "strwithlen",
            "u8 end",
            "test",
            "poison",
            "february",
            "cray",
            "prior",
            "behaviour",
            "except",
            "alpha",
            "perlvar",
            "perlvari",
            "perlvara",
            "padoffset",
            "true",
            "pmop",
            "hooks",
            "hook",
            "sv invlist",
            "perlinregcompc",
            "svcur",
            "perlinopc",
            "tointernalsize",
            "svtinvlist",
            "invlistlen",
            "strlen",
            "hvaux",
            "heklen",
            "svook",
            "hekutf8",
            "hekkey",
            "hekflags",
            "mutablehv",
            "hvnameheknn",
            "gosh",
            "leave",
            "iperlsock",
            "plsock",
            "iperlstdio",
            "plstdio",
            "iperlproc",
            "plproc",
            "iperllio",
            "pllio",
            "perlimplicitsys",
            "plink",
            "keypackage",
            "keyend",
            "keysub",
            "keydump",
            "keylog",
            "keysend",
            "keystate",
            "perlioclose",
            "perlmemcollxfrm",
            "nativetoneed",
            "plclocaleobj",
            "plno",
            "plwarnall",
            "plwarnnone",
            "plyes",
            "plzero",
            "plc9utf8dfatab",
            "nomathoms",
            "perlintokec",
            "perlinutf8c",
            "perlinsvc",
            "perlinregexecc",
            "debugging",
            "perlinlocalec",
            "pfinet",
            "snoop",
            "ccprint",
            "ccgraph",
            "cccharnamecont",
            "ccascii",
            "ccwordchar",
            "ccalphanumeric",
            "ccidfirst",
            "ccquotemeta",
            "ccalpha",
            "cccased",
            "ordinal",
            "magicvtablemax",
            "extra",
            "regex match",
            "env hash",
            "isa array",
            "debugger",
            "sig hash",
            "available",
            "shadow",
            "array length",
            "magic mg",
            "sv sv",
            "mgftainteddir",
            "hefsvkey",
            "mutablesv",
            "ssizet",
            "mgvtbl entry",
            "mgfbytes",
            "perlmagicsv 0",
            "special",
            "perlmagicarylen",
            "perlmagicrhash",
            "extra data",
            "perlmagicpos",
            "perlmagicsymtab",
            "provides",
            "dtrace probes",
            "stdioh",
            "stdioincluded",
            "sfioversion",
            "rxfpmfcharset",
            "rxfpmfmultiline",
            "rxfpmffold",
            "rxfpmfextended",
            "rxfpmfnocapture",
            "rxfpmfkeepcopy",
            "flags",
            "rxfpmfstrict",
            "ocshift",
            "plop",
            "perlbitfield16",
            "baseop op",
            "useithreads",
            "pmfonce",
            "padop",
            "perlcknull",
            "perlckfun",
            "opparg1mask",
            "opparg4mask",
            "opparg2mask",
            "perlckftst",
            "perlppftrowned",
            "perlckbitop",
            "perlckcmp",
            "perlcklfun",
            "dump",
            "chroot",
            "syscall",
            "flip",
            "undef",
            "crypt",
            "push",
            "stub",
            "trans",
            "predec",
            "flop",
            "prtf",
            "shutdown",
            "perlcontext cx",
            "perlmemlog",
            "c pointer",
            "cxtype",
            "logic",
            "toavamg",
            "tohvamg",
            "opftrread",
            "oplt",
            "opincmp",
            "opbitand",
            "opsbitor",
            "opsend",
            "opgetpeername",
            "opfteexec",
            "opftbinary",
            "opclose",
            "plparser",
            "yylex",
            "lexshared",
            "position",
            "repl",
            "memsize",
            "malloct",
            "perlmallocctlh",
            "uv nfree",
            "uv ntotal",
            "iv topbucket",
            "iv totalsbrk",
            "iv minbucket",
            "level",
            "plcomppad",
            "plcurpad",
            "uvxf",
            "ptr2uv",
            "avarray",
            "padnameflags",
            "plcopseqmax",
            "padlistarray",
            "c array",
            "padnametype",
            "incpushperl5lib",
            "appllibexp",
            "privlibexp",
            "defineincmacros",
            "perlfsversion",
            "perl5lib",
            "sitearchexp",
            "perllanginfoh",
            "hasnllanginfo",
            "ilanginfo",
            "codeset",
            "codeset 1",
            "dtfmt",
            "dtfmt 2",
            "dfmt",
            "dfmt 3",
            "sipround",
            "u8to64le",
            "fallthrough",
            "uint64c",
            "perlsiphashfnc",
            "siprounds",
            "strlen inlen",
            "sipfinalrounds",
            "could",
            "configure",
            "plout",
            "mine001",
            "argv",
            "plin",
            "localpatchcount",
            "perlapih",
            "xs code",
            "portingglossary",
            "first version",
            "brand",
            "symbols",
            "haswcrtomb",
            "perlionotstdio",
            "perlcallconv",
            "perlio f",
            "perlioh",
            "usestdio",
            "case",
            "bufsiz",
            "sizet",
            "perlstability",
            "perltypedefs",
            "perldtracehin",
            "perlloadedfile",
            "perlloadingfile",
            "perlopentry",
            "perlphasechange",
            "perlsubentry",
            "perlsubreturn",
            "generated",
            "perlcallconv iv",
            "sizet count",
            "sv arg",
            "mode",
            "perliofuncs tab",
            "stdchar",
            "perliolistt",
            "sv args",
            "mutex",
            "perlinterpreter",
            "sigsize",
            "perlioisstdio",
            "perlcallconv op",
            "perldokv",
            "perlppaassign",
            "perlppabs",
            "perlppaccept",
            "perlppadd",
            "perlppaeach",
            "perlppaelem",
            "public license",
            "free software",
            "foundation",
            "yydebug",
            "bison",
            "bareword",
            "funcmeth",
            "arrow",
            "targ",
            "pushs",
            "tops",
            "does",
            "xsub",
            "pops",
            "xpushs",
            "erange",
            "perlreentrapi",
            "perlreentrapi0",
            "hostentsize",
            "getgrentrproto",
            "getpwentrproto",
            "getnetentrproto",
            "grentbuffer",
            "grentsize",
            "hostenterrno",
            "redebugflag",
            "debugvtest",
            "debugr",
            "u16 nextoff",
            "argset",
            "u8 type",
            "nextoff",
            "strings",
            "problem",
            "june",
            "invert",
            "perlfpclass",
            "longdoublekind",
            "plstatusvalue",
            "pldebug",
            "numclasses",
            "locale",
            "grok",
            "pragma",
            "dword",
            "attack",
            "little",
            "lynx",
            "done",
            "reany",
            "rxpextflags",
            "rxextflags",
            "checkpoint cp",
            "rxftaintedseen",
            "rxfcopydone",
            "plsavestackix",
            "plsavestack",
            "plsavestackmax",
            "ssmaxpush",
            "enter",
            "debugscope",
            "state",
            "u32 state",
            "debugsbox32hash",
            "sbox32warn5",
            "line",
            "mutexunlock",
            "mutexinit",
            "noop",
            "mutexlock",
            "condinit",
            "detach",
            "panic",
            "usetm64",
            "should",
            "bsd extension",
            "configuration",
            "time64debug",
            "int64t nv",
            "gnu extension",
            "perltime64h",
            "time64t",
            "int64t int64",
            "int64 time64t",
            "i32 year",
            "tm64",
            "hastmtmgmtoff",
            "decide",
            "svpvx",
            "svgmagic",
            "bonk",
            "anything",
            "turn",
            "crash",
            "fstat",
            "perlmicro",
            "hasioctl",
            "hasutime",
            "hasgroup",
            "haspasswd",
            "usemybinmode",
            "idirent",
            "likely",
            "generated code",
            "utfebcdic",
            "unicode",
            "step",
            "ufeff",
            "u00a0",
            "u00df",
            "u00b5",
            "ufffd",
            "u017f",
            "u0300",
            "unlikely",
            "nativeutf8toi8",
            "utf8skip",
            "nativetouni",
            "lazy",
            "extrasize",
            "regnodemax",
            "exact",
            "match",
            "whilem",
            "anyof",
            "curly",
            "trie",
            "curlym",
            "eval",
            "star",
            "perlutilh",
            "hsmapiverlen",
            "hsxsverlenmax",
            "hskeyp",
            "tools",
            "sv vs",
            "perlversionlt",
            "svpvxnolenconst",
            "perlckwarner",
            "u32 err",
            "scroakxsusage",
            "pluumap",
            "warnings",
            "categories",
            "plcurcop",
            "perlckwarn",
            "perlckwarnd",
            "perlwarnisset",
            "perlwarnoff",
            "perlwarnbit",
            "xsversion",
            "xsreturn",
            "perlxshandshake",
            "plstackbase",
            "hskey",
            "zaphod32mix",
            "u8to32le",
            "zaphod32warn4",
            "zaphod32warn3",
            "zaphod32warn6",
            "perlform",
            "i8tonativeutf8",
            "warnutf8",
            "myshift",
            "c extension",
            "libs",
            "cflags",
            "afkuserlog",
            "kafkeventcancel",
            "kafkeventerror",
            "adamsbagmanager",
            "adjinglerequest",
            "isinternalbuild",
            "kickmcxdforuid",
            "loadappkit",
            "ardconfig",
            "authenticator",
            "dsauthenticator",
            "dsnode",
            "dsrecord",
            "hostconfig",
            "addtofront",
            "calcslope",
            "copyarray",
            "createcachenode",
            "defaultebecurve",
            "deletecache",
            "disablehcucache",
            "dumpcache",
            "dumpoutputhcu",
            "enablet1sim",
            "ascagent",
            "ascagentproxy",
            "asdevice",
            "ddrangecompare",
            "wdosloglauncher",
            "wdoslogprotocol",
            "findchar",
            "ddasllogger",
            "ddfilelogger",
            "ddlog",
            "ddlogfileinfo",
            "ddlogmessage",
            "ddloggernode",
            "mkurlparser",
            "mkerrordomain",
            "mkintegerhash",
            "mklonghash",
            "mkmaprectinset",
            "mkmaprectnull",
            "mkmaprectoffset",
            "mkmaprectworld",
            "mkmapsizeworld",
            "kextensionnonui",
            "wkarraycreate",
            "wkbooleancreate",
            "wkcontextcreate",
            "wkdatacreate",
            "wkdatagettypeid",
            "wkdoublecreate",
            "wkframecopyurl",
            "wkgettypeid",
            "wkimagecreate",
            "wkpagecandelete",
            "webkit",
            "methodkind",
            "wkerrordomain",
            "by apple",
            "document",
            "a block",
            "wkcontentworld",
            "wkwebview",
            "javascript",
            "wkerrorcode",
            "wkerrorunknown",
            "nsswiftasync",
            "wkswiftasync",
            "wkcookiepolicy",
            "nshttpcookie",
            "whether",
            "wknavigation",
            "wkdownload",
            "decides",
            "mime type",
            "wkscriptmessage",
            "wkframeinfo",
            "information",
            "url scheme",
            "wkcontentmode",
            "wkuserscript",
            "wkextern",
            "media",
            "promise",
            "fulfill",
            "cgfloat",
            "targetoswatch",
            "sign",
            "password",
            "provider",
            "uicontrol",
            "nscontrol",
            "opaque user",
            "apple id",
            "nsstring user",
            "asuseragerange",
            "initiate",
            "asauthorization",
            "confirms",
            "apple upgrade",
            "nserrorenum",
            "operation",
            "relying party",
            "targetosvision",
            "a byte",
            "nsdata userid",
            "relying",
            "a string",
            "asapiavailable",
            "http response",
            "authorization",
            "oauth",
            "saml",
            "nsdata readdata",
            "bool didwrite",
            "a cose",
            "nsstring name",
            "bool appid",
            "targetosxr",
            "a state",
            "a json",
            "web token",
            "private seckeys",
            "nsstring appid",
            "mdm profile",
            "nsurl url",
            "returns yes",
            "lacontext",
            "asswiftsendable",
            "keychain",
            "cose algorithm",
            "ecdsa",
            "sha256",
            "cose curve",
            "p256",
            "nsinteger rank",
            "enables",
            "bool success",
            "remove",
            "call",
            "complete",
            "prepare",
            "attempt",
            "list",
            "nsextension",
            "settings",
            "initializes",
            "a key",
            "extensions",
            "hash",
            "json",
            "initialize",
            "nsstring origin",
            "settings app",
            "urls",
            "https urls",
            "safari",
            "cancel",
            "nsuuid uuid",
            "asextern extern",
            "asextern",
            "nsswiftsendable",
            "uiwindow",
            "propertykind",
            "gkplayer",
            "n tags",
            "gkerrordomain",
            "gamecenter",
            "targetosios",
            "targetostv",
            "nsavailable",
            "gkachievement",
            "local player",
            "view",
            "present",
            "optional",
            "gkbaseplayer",
            "game center",
            "uiimage",
            "app store",
            "gkchallenge",
            "gklocalplayer",
            "nsdeprecated",
            "a singleton",
            "gkcloudplayer",
            "returns nil",
            "nsdeprecatedmac",
            "internal2",
            "internal3",
            "internal4",
            "gkscore",
            "gkextern",
            "gkextern extern",
            "gkexternweak",
            "gkerrorcode",
            "gkerrorunknown",
            "gkerrorunderage",
            "friendplayer",
            "standard view",
            "nsresponder",
            "parentwindow",
            "ibaction",
            "gkgamesession",
            "apis",
            "gkplayer player",
            "nsinteger score",
            "nsdate date",
            "gkleaderboard",
            "connect",
            "nsinteger value",
            "load",
            "gktransporttype",
            "nsstring title",
            "loads array",
            "localized",
            "gkmatch",
            "gkmatchrequest",
            "gkinvite",
            "gksession",
            "gksession api",
            "gamekit",
            "asynchronously",
            "welcome",
            "nstimeinterval",
            "delegate",
            "delivery",
            "gksenddatamode",
            "gksessionmode",
            "gkphotosize",
            "callbacks",
            "gkmatchdelegate",
            "gksavedgame",
            "default value",
            "gksessionerror",
            "gkvoicechat",
            "participant",
            "voice chat",
            "clienta"
          ],
          "references": [
            "CredentialsCache.h",
            "CredentialsCache2.h",
            "config.xml",
            "popen_spawn_win32.py",
            "pycore_condvar.h",
            "Kerberos.h",
            "KerberosLogin.h",
            "plugin.js",
            "krb5.h",
            "MultipeerConnectivity.tbd",
            "MCBrowserViewController.h",
            "MCNearbyServiceAdvertiser.h",
            "MCError.h",
            "MCAdvertiserAssistant.h",
            "MCNearbyServiceBrowser.h",
            "MultipeerConnectivity.apinotes",
            "MultipeerConnectivity.h",
            "MCSession.h",
            "MCPeerID.h",
            "canvas.html",
            "capture_0.bundle.js",
            "capture_resize.js",
            "GCRacingWheelInput.h",
            "GCSyntheticDeviceKeys.h",
            "GCSwitchPositionInput.h",
            "GCSteeringWheelElement.h",
            "GCSwitchElement.h",
            "GCTouchedStateInput.h",
            "GCXboxGamepad.h",
            "GCTypes.h",
            "GCRelativeInput.h",
            "GameController.h",
            "GCAxis2DInput.h",
            "GCAxisElement.h",
            "GCAxisInput.h",
            "GCButtonElement.h",
            "GCController.h",
            "GCColor.h",
            "GCControllerAxisInput.h",
            "GCControllerDirectionPad.h",
            "GCControllerInput.h",
            "GCControllerElement.h",
            "GCControllerTouchpad.h",
            "GCDevice.h",
            "GCDeviceBattery.h",
            "GCDeviceCursor.h",
            "GCDeviceHaptics.h",
            "GCDeviceLight.h",
            "GCDevicePhysicalInputState.h",
            "GCDevicePhysicalInputStateDiff.h",
            "GCDirectionalGamepad.h",
            "GCDirectionPadElement.h",
            "GCDevicePhysicalInput.h",
            "GCDualSenseAdaptiveTrigger.h",
            "GCDualSenseGamepad.h",
            "GCDualShockGamepad.h",
            "GCEventViewController.h",
            "GCExtendedGamepadSnapshot.h",
            "GCExtern.h",
            "GCExtendedGamepad.h",
            "GCGamepadSnapshot.h",
            "GCGearShifterElement.h",
            "GCGamepad.h",
            "GCKeyboard.h",
            "GCInputNames.h",
            "GCControllerButtonInput.h",
            "GCKeyNames.h",
            "GCKeyboardInput.h",
            "GCKeyCodes.h",
            "GCLinearInput.h",
            "GCMotion.h",
            "GCMouse.h",
            "GCMouseInput.h",
            "GCMicroGamepadSnapshot.h",
            "GCPhysicalInputElement.h",
            "GCMicroGamepad.h",
            "GCPhysicalInputProfile.h",
            "GCPhysicalInputSource.h",
            "GCPressedStateInput.h",
            "GCProductCategories.h",
            "GCRacingWheel.h",
            "GameController.tbd",
            "arm64e-apple-macos.swiftinterface",
            "x86_64-apple-macos.swiftinterface",
            "module.modulemap",
            "com_err.h",
            "gssapi_generic.h",
            "locate_plugin.h",
            "profile.h",
            "gssapi_krb5.h",
            "preauth_plugin.h",
            "gssapi.h",
            "alc.h",
            "oalStaticBufferExtension.h",
            "oalMacOSX_OALExtensions.h",
            "OpenAL.h",
            "al.h",
            "OpenAL.tbd",
            "IOUSBHost.tbd",
            "IOUSBHostCIEndpointStateMachine.h",
            "IOUSBHostCIControllerStateMachine.h",
            "IOUSBHost.h",
            "IOUSBHostCIPortStateMachine.h",
            "IOUSBHostCIDeviceStateMachine.h",
            "IOUSBHostControllerInterfaceHelpers.h",
            "IOUSBHostDevice.h",
            "IOUSBHostControllerInterface.h",
            "IOUSBHostDefinitions.h",
            "IOUSBHostInterface.h",
            "IOUSBHostIOSource.h",
            "AppleUSBDescriptorParsing.h",
            "IOUSBHostStream.h",
            "IOUSBHostObject.h",
            "IOUSBHostControllerInterfaceDefinitions.h",
            "IOUSBHostPipe.h",
            "IOBluetoothUIUserLib.h",
            "IOBluetoothUI.h",
            "IOBluetoothObjectPushUIController.h",
            "IOBluetoothDeviceSelectorController.h",
            "IOBluetoothPasskeyDisplay.h",
            "IOBluetoothPairingController.h",
            "IOBluetoothServiceBrowserController.h",
            "IOBluetoothUI.tbd",
            "Bluetooth.h",
            "IOBluetooth.h",
            "BluetoothAssignedNumbers.h",
            "IOBluetoothTypes.h",
            "IOBluetoothUtilities.h",
            "OBEXBluetooth.h",
            "IOBluetoothUserLib.h",
            "OBEX.h",
            "IOBluetooth.tbd",
            "INImage+IntentsUI.h",
            "IntentsUI.h",
            "INUIAddVoiceShortcutButton.h",
            "IntentsUI.apinotes",
            "INUIEditVoiceShortcutViewController.h",
            "INUIAddVoiceShortcutViewController.h",
            "LDAP.tbd",
            "OSvKernDSPLib.h",
            "cpu.h",
            "asm_help.h",
            "desc.h",
            "pio.h",
            "io.h",
            "sel.h",
            "reg_help.h",
            "tss.h",
            "table.h",
            "byte_order.h",
            "_limits.h",
            "_types.h",
            "_mcontext.h",
            "_param.h",
            "_endian.h",
            "arch.h",
            "cpuid_internal.h",
            "cpu_capabilities_public.h",
            "arm_features.inc",
            "endian.h",
            "locks.h",
            "limits.h",
            "atomic.h",
            "machine_cpuid.h",
            "memory_types.h",
            "pal_routines.h",
            "machine_routines.h",
            "param.h",
            "cpuid.h",
            "thread.h",
            "trap.h",
            "vmparam.h",
            "signal.h",
            "types.h",
            "AFKMemoryDescriptorOptions.h",
            "machine_machdep.h",
            "atm_types.h",
            "copyio.h",
            "_OSByteOrder.h",
            "crc.h",
            "Block.h",
            "OSBase.h",
            "OSByteOrder.h",
            "OSDebug.h",
            "OSMalloc.h",
            "OSAtomic.h",
            "OSReturn.h",
            "OSKextLib.h",
            "OSTypes.h",
            "version.h",
            "sysctl.h",
            "tree.h",
            "zconf.h",
            "zlib.h",
            "libkern.h",
            "kdp_callout.h",
            "kdp_en_debugger.h",
            "ipc_types.h",
            "krpc.h",
            "rpcv2.h",
            "xdr_subs.h",
            "nfs.h",
            "nfsproto.h",
            "bootp.h",
            "if_ether.h",
            "icmp6.h",
            "icmp_var.h",
            "igmp_var.h",
            "igmp.h",
            "in_pcb.h",
            "in_stat.h",
            "in_private.h",
            "in_arp.h",
            "in_var.h",
            "in_systm.h",
            "ip_var.h",
            "ip_icmp.h",
            "kpi_ipfilter.h",
            "ip6.h",
            "tcp_private.h",
            "ip.h",
            "tcp_timer.h",
            "tcp_fsm.h",
            "udp_var.h",
            "tcp_seq.h",
            "tcpip.h",
            "udp.h",
            "tcp_var.h",
            "tcp.h",
            "IOPCIFamilyDefinitions.h",
            "IOPCIDevice.iig",
            "PCIDriverKit.h",
            "IOPCIDevice.h",
            "audit_ioctl.h",
            "stdarg.h",
            "stdatomic.h",
            "stdbool.h",
            "stddef.h",
            "string.h",
            "stdint.h",
            "ptrauth.h",
            "math.h",
            "monotonic.h",
            "static_if.h",
            "machine_kpc.h",
            "machine_remote_time.h",
            "ipc_pthread_priority_types.h",
            "lz4_assembly_select.h",
            "vm_compressor_algorithms.h",
            "lz4.h",
            "pmap.h",
            "vm_dyld_pager.h",
            "vm_far.h",
            "vm_fault.h",
            "vm_map.h",
            "lz4_constants.h",
            "vm_options.h",
            "vm_pageout.h",
            "vm_memtag.h",
            "vm_shared_region.h",
            "vm_kern.h",
            "vfs_support.h",
            "vecLib.h",
            "vecLibTypes.h",
            "vBasicOps.h",
            "vForce.h",
            "vDSP.h",
            "uuid.h",
            "UNDReply.defs",
            "UNDRequest.defs",
            "KUNCUserNotifications.h",
            "UNDTypes.defs",
            "UNDTypes.h",
            "TargetConditionals.h",
            "apfs_boot_mount.tbd",
            "av.h",
            "cop.h",
            "bitcount.h",
            "cv.h",
            "ebcdic_tables.h",
            "EXTERN.h",
            "embedvar.h",
            "fakesdio.h",
            "feature.h",
            "form.h",
            "gv.h",
            "git_version.h",
            "dosish.h",
            "hv_macro.h",
            "hv_func.h",
            "config.h",
            "INTERN.h",
            "handy.h",
            "intrpvar.h",
            "invlist_inline.h",
            "hv.h",
            "iperlsys.h",
            "keywords.h",
            "libperl.tbd",
            "embed.h",
            "l1_char_class_tab.h",
            "mg_data.h",
            "mg_raw.h",
            "mg.h",
            "mg_vtable.h",
            "mydtrace.h",
            "nostdio.h",
            "op_reg_common.h",
            "op.h",
            "opcode.h",
            "inline.h",
            "overload.h",
            "opnames.h",
            "parser.h",
            "malloc_ctl.h",
            "pad.h",
            "perl_inc_macro.h",
            "perl_langinfo.h",
            "perl_siphash.h",
            "patchlevel.h",
            "perlapi.h",
            "metaconfig.h",
            "perlio.h",
            "perldtrace.h",
            "perliol.h",
            "perlvars.h",
            "perlsdio.h",
            "pp_proto.h",
            "perly.h",
            "pp.h",
            "reentr.h",
            "regcomp.h",
            "perl.h",
            "regexp.h",
            "scope.h",
            "sbox32_hash.h",
            "time64_config.h",
            "time64.h",
            "sv.h",
            "unixish.h",
            "uconfig.h",
            "utfebcdic.h",
            "unicode_constants.h",
            "utf8.h",
            "regnodes.h",
            "util.h",
            "vutil.h",
            "uudmap.h",
            "warnings.h",
            "XSUB.h",
            "zaphod32_hash.h",
            "encode.h",
            "python-3.9.pc",
            "python-3.9-embed.pc",
            "python3-embed.pc",
            "python3.pc",
            "AFKUser.tbd",
            "AdID.tbd",
            "Admin.tbd",
            "AirPlayReceiver.tbd",
            "AppSandbox.tbd",
            "ASEProcessing.tbd",
            "AuthenticationServicesCore.tbd",
            "WebGPU.tbd",
            "WebDriver.tbd",
            "MapKit.tbd",
            "SwiftUI.swiftoverlay",
            "WebKit.tbd",
            "WebKit.apinotes",
            "WKBackForwardList.h",
            "NSAttributedString.h",
            "WebKit.h",
            "WKBackForwardListItem.h",
            "WKContentRuleList.h",
            "WKContentRuleListStore.h",
            "WKContextMenuElementInfo.h",
            "WKDataDetectorTypes.h",
            "WKContentWorld.h",
            "WKError.h",
            "WKFoundation.h",
            "WKFindResult.h",
            "WKHTTPCookieStore.h",
            "WKFrameInfo.h",
            "WKNavigation.h",
            "WKFindConfiguration.h",
            "WKNavigationDelegate.h",
            "WKNavigationResponse.h",
            "WKOpenPanelParameters.h",
            "WebKitLegacy.h",
            "WKPreviewActionItem.h",
            "WKNavigationAction.h",
            "WKPreferences.h",
            "WKPreviewActionItemIdentifiers.h",
            "WKPreviewElementInfo.h",
            "WKProcessPool.h",
            "WKDownload.h",
            "WKPDFConfiguration.h",
            "WKScriptMessage.h",
            "WKSecurityOrigin.h",
            "WKScriptMessageHandler.h",
            "WKSnapshotConfiguration.h",
            "WKUIDelegate.h",
            "WKURLSchemeTask.h",
            "WKWebpagePreferences.h",
            "WKUserContentController.h",
            "WKWebsiteDataStore.h",
            "WKWebsiteDataRecord.h",
            "WKUserScript.h",
            "WKURLSchemeHandler.h",
            "WKWebViewConfiguration.h",
            "WKWebView.h",
            "WKScriptMessageHandlerWithReply.h",
            "WKWindowFeatures.h",
            "WKDownloadDelegate.h",
            "ASAccountAuthenticationModificationController.h",
            "ASAccountAuthenticationModificationViewController.h",
            "ASAuthorization.h",
            "ASAuthorizationAppleIDButton.h",
            "ASAccountAuthenticationModificationRequest.h",
            "ASAuthorizationAppleIDProvider.h",
            "ASAuthorizationAppleIDRequest.h",
            "ASAuthorizationAppleIDCredential.h",
            "ASAuthorizationController.h",
            "ASAuthorizationCredential.h",
            "ASAccountAuthenticationModificationExtensionContext.h",
            "ASAuthorizationError.h",
            "ASAuthorizationCustomMethod.h",
            "ASAuthorizationPasswordRequest.h",
            "ASAuthorizationOpenIDRequest.h",
            "ASAuthorizationPlatformPublicKeyCredentialDescriptor.h",
            "ASAuthorizationPlatformPublicKeyCredentialProvider.h",
            "ASAccountAuthenticationModificationReplacePasswordWithSignInWithAppleRequest.h",
            "ASAccountAuthenticationModificationUpgradePasswordToStrongPasswordRequest.h",
            "ASAuthorizationPlatformPublicKeyCredentialRegistrationRequest.h",
            "ASAuthorizationPlatformPublicKeyCredentialRegistration.h",
            "ASAuthorizationProvider.h",
            "ASAuthorizationPlatformPublicKeyCredentialAssertion.h",
            "ASAuthorizationPublicKeyCredentialAssertion.h",
            "ASAuthorizationPublicKeyCredentialAssertionRequest.h",
            "ASAuthorizationPublicKeyCredentialConstants.h",
            "ASAuthorizationProviderExtensionAuthorizationResult.h",
            "ASAuthorizationPublicKeyCredentialDescriptor.h",
            "ASAuthorizationPublicKeyCredentialLargeBlobAssertionOutput.h",
            "ASAuthorizationPasswordProvider.h",
            "ASAuthorizationPublicKeyCredentialLargeBlobRegistrationInput.h",
            "ASAuthorizationPublicKeyCredentialParameters.h",
            "ASAuthorizationPublicKeyCredentialLargeBlobRegistrationOutput.h",
            "ASAuthorizationPublicKeyCredentialRegistration.h",
            "ASAuthorizationPublicKeyCredentialRegistrationRequest.h",
            "ASAuthorizationPublicKeyCredentialLargeBlobAssertionInput.h",
            "ASAuthorizationSecurityKeyPublicKeyCredentialAssertion.h",
            "ASAuthorizationRequest.h",
            "ASAuthorizationPlatformPublicKeyCredentialAssertionRequest.h",
            "ASAuthorizationSecurityKeyPublicKeyCredentialProvider.h",
            "ASAuthorizationSingleSignOnCredential.h",
            "ASAuthorizationSecurityKeyPublicKeyCredentialDescriptor.h",
            "ASAuthorizationSecurityKeyPublicKeyCredentialAssertionRequest.h",
            "ASAuthorizationSecurityKeyPublicKeyCredentialRegistration.h",
            "ASAuthorizationSingleSignOnProvider.h",
            "ASAuthorizationWebBrowserExternallyAuthenticatableRequest.h",
            "ASAuthorizationWebBrowserPlatformPublicKeyCredentialAssertionRequest.h",
            "ASAuthorizationWebBrowserPlatformPublicKeyCredentialRegistrationRequest.h",
            "ASAuthorizationWebBrowserPublicKeyCredentialManager.h",
            "ASAuthorizationWebBrowserPlatformPublicKeyCredential.h",
            "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialAssertionRequest.h",
            "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialRegistrationRequest.h",
            "ASCOSEConstants.h",
            "ASCredentialIdentity.h",
            "ASAuthorizationSingleSignOnRequest.h",
            "ASCredentialIdentityStore.h",
            "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialProvider.h",
            "ASCredentialProviderExtensionContext.h",
            "ASCredentialProviderViewController.h",
            "ASAuthorizationSecurityKeyPublicKeyCredentialRegistrationRequest.h",
            "ASCredentialServiceIdentifier.h",
            "ASExtensionErrors.h",
            "ASAuthorizationProviderExtensionAuthorizationRequest.h",
            "ASCredentialRequest.h",
            "ASAuthorizationWebBrowserPlatformPublicKeyCredentialProvider.h",
            "ASPasskeyAssertionCredential.h",
            "ASPasskeyCredentialRequest.h",
            "ASPasskeyCredentialRequestParameters.h",
            "ASCredentialIdentityStoreState.h",
            "ASPasskeyRegistrationCredential.h",
            "ASPasswordCredential.h",
            "ASPublicKeyCredential.h",
            "ASPasskeyCredentialIdentity.h",
            "ASPublicKeyCredentialClientData.h",
            "ASSettingsHelper.h",
            "ASWebAuthenticationSessionCallback.h",
            "ASWebAuthenticationSession.h",
            "ASWebAuthenticationSessionRequest.h",
            "ASWebAuthenticationSessionWebBrowserSessionManager.h",
            "AuthenticationServices.h",
            "ASFoundation.h",
            "AuthenticationServices.apinotes",
            "ASWebAuthenticationSessionWebBrowserSessionHandling.h",
            "ASPasswordCredentialIdentity.h",
            "ASPasswordCredentialRequest.h",
            "GameKit.apinotes",
            "GKAccessPoint.h",
            "GameKit.h",
            "GKAchievement.h",
            "GKAchievementViewController.h",
            "GKBasePlayer.h",
            "GKAchievementDescription.h",
            "GKChallengeEventHandler.h",
            "GKCloudPlayer.h",
            "GKChallengesViewController.h",
            "GKChallenge.h",
            "GKDefines.h",
            "GKError.h",
            "GKEventListener.h",
            "GKFriendRequestComposeViewController.h",
            "GKDialogController.h",
            "GKGameSessionEventListener.h",
            "GKGameSessionError.h",
            "GKGameCenterViewController.h",
            "GKGameSessionSharingViewController.h",
            "GKLeaderboardEntry.h",
            "GKLeaderboard.h",
            "GKLeaderboardScore.h",
            "GKGameSession.h",
            "GKLeaderboardSet.h",
            "GKLocalPlayer.h",
            "GKLeaderboardViewController.h",
            "GKMatch.h",
            "GKMatchmaker.h",
            "GKMatchmakerViewController.h",
            "GKPeerPickerController.h",
            "GKNotificationBanner.h",
            "GKPublicConstants.h",
            "GKPlayer.h",
            "GKPublicProtocols.h",
            "GKSavedGameListener.h",
            "GKScore.h",
            "GKSessionError.h",
            "GKVoiceChat.h",
            "GKTurnBasedMatchmakerViewController.h",
            "GKSession.h",
            "GKTurnBasedMatch.h",
            "GKSavedGame.h",
            "GKVoiceChatService.h"
          ],
          "public": 1,
          "adversary": "Turla Group, FIN7, APT34, APT28, DragonForce Malaysia Hacker Group, Indonesia Islamic Warriors Counc",
          "targeted_countries": [
            "United States of America",
            "India",
            "Australia"
          ],
          "malware_families": [
            {
              "id": "OSAtomic",
              "display_name": "OSAtomic",
              "target": null
            },
            {
              "id": "OSReturn",
              "display_name": "OSReturn",
              "target": null
            },
            {
              "id": "Ver",
              "display_name": "Ver",
              "target": null
            },
            {
              "id": "Internet",
              "display_name": "Internet",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1123",
              "name": "Audio Capture",
              "display_name": "T1123 - Audio Capture"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 39,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ilyailya",
            "id": "298851",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1968,
            "domain": 526,
            "FileHash-SHA256": 207,
            "hostname": 972,
            "email": 55,
            "FileHash-SHA1": 9,
            "FileHash-MD5": 4,
            "CVE": 2,
            "CIDR": 10
          },
          "indicator_count": 3753,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 35,
          "modified_text": "389 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67eed1bef3ff35a5814d2d81",
          "name": "New GolangGhost Malware Linked to Lazarus Group\u2019s Cyber Campaign",
          "description": "North Korean hackers linked to the Lazarus Group are targeting job seekers in the cryptocurrency sector with a new social engineering tactic called ClickFix, deploying a previously unseen Go-based backdoor named GolangGhost on Windows and macOS systems. Researchers said the campaign, now tracked as ClickFake Interview, impersonates major crypto firms like Coinbase, Kraken, and Binance to lure victims.",
          "modified": "2025-05-03T18:03:35.754000",
          "created": "2025-04-03T18:21:50.101000",
          "tags": [
            "lazarus",
            "windows",
            "golangghost",
            "cefi",
            "sekoia",
            "frostyferret",
            "clickfix tactic",
            "temp",
            "march",
            "dprk",
            "invisibleferret",
            "terminal",
            "macos",
            "sharpknot",
            "manuscrypt",
            "bluenoroff",
            "february",
            "beavertail",
            "path",
            "kraken",
            "robinhood"
          ],
          "references": [
            "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Superpro",
            "id": "61676",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 10,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 14,
            "URL": 7,
            "YARA": 9,
            "domain": 40,
            "hostname": 25
          },
          "indicator_count": 108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 214,
          "modified_text": "392 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ee8daa5adeb254fb7d484e",
          "name": "From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic - Sekoia.io Blog",
          "description": "In March 2025, Bybit, an UAE-based crypto exchange platform, was targeted by Lazarus, a state-sponsored intrusion set attributed to the Democratic People\u2019s Republic of Korea (DPRK), leading to the theft of $1.5 billion, which represents a record-breaking crypto heist in history.",
          "modified": "2025-05-03T13:01:09.343000",
          "created": "2025-04-03T13:31:22.404000",
          "tags": [
            "lazarus",
            "windows",
            "golangghost",
            "cefi",
            "sekoia",
            "frostyferret",
            "clickfix tactic",
            "temp",
            "march",
            "dprk",
            "invisibleferret",
            "terminal",
            "macos",
            "sharpknot",
            "manuscrypt",
            "bluenoroff",
            "february",
            "beavertail",
            "path",
            "kraken",
            "robinhood"
          ],
          "references": [
            "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/#h-iocs-and-technical-details"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 10,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 14,
            "URL": 7,
            "YARA": 9,
            "domain": 40,
            "hostname": 25
          },
          "indicator_count": 108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "392 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ff12aea0b9ba91d923da14",
          "name": "Threat Actor Profile: El Machete",
          "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
          "modified": "2025-04-16T02:15:10.602000",
          "created": "2025-04-16T02:15:10.602000",
          "tags": [
            "threat_actor",
            "unknown",
            "T1497",
            "T1114",
            "T1566.001",
            "T1059.003",
            "T1081",
            "T1059.006",
            "T1059",
            "T1566.002",
            "T1082",
            "T1027",
            "T1071.001",
            "T1566",
            "T1041",
            "T1105",
            "T1204.001",
            "T1049",
            "T1055",
            "T1036",
            "T1503",
            "T1114.001",
            "T1053",
            "T1140",
            "T1012",
            "T1071",
            "T1112",
            "T1036.005",
            "T1547",
            "T1057",
            "T1008",
            "T1518",
            "T1021",
            "T1011",
            "T1060",
            "T1539",
            "T1587",
            "T1087",
            "T1095",
            "T1102",
            "T1070",
            "T1130",
            "T1552",
            "T1106",
            "T1190",
            "T1007",
            "T1133",
            "T1090",
            "T1016",
            "T1137",
            "T1119",
            "T1124",
            "T1005",
            "T1059.001",
            "T1115",
            "T1562.001",
            "T1543",
            "T1078",
            "T1083",
            "T1530",
            "T1085",
            "T1003",
            "T1120",
            "T1218",
            "T1048",
            "T1553",
            "T1490",
            "T1497.003",
            "T1571",
            "T1204.002",
            "T1595.002",
            "T1102.002",
            "T1583.003",
            "T1027.009",
            "T1027.013",
            "T1132",
            "T1562",
            "T1110",
            "T1059.005",
            "T1218.007",
            "T1204",
            "T1550",
            "T1136",
            "T1555",
            "T1176",
            "T1204_-_User_Execution",
            "T1566_-_Phishing",
            "T1561",
            "T1583",
            "T1485",
            "T1127",
            "T1595",
            "T1573",
            "T1189",
            "T1486",
            "T1531",
            "T1529",
            "T1053.005",
            "T1047.",
            "target:Dominican Republic",
            "target:Venezuela",
            "target:Italy",
            "target:Colombia",
            "target:Ecuador",
            "target:Guatemala",
            "target:Belgium",
            "target:Malaysia",
            "target:Brazil",
            "target:France",
            "target:Indonesia",
            "target:United Kingdom",
            "target:China",
            "target:Germany",
            "target:Mexico",
            "target:Argentina",
            "target:Netherlands",
            "target:Japan",
            "target:Bolivia",
            "target:Yibuti",
            "target:Vietnam",
            "target:Fiyi",
            "target:Cuba",
            "target:Camboya",
            "target:Taiw\u00e1n",
            "target:United States",
            "target:Sweden",
            "target:Ukraine",
            "target:South Korea",
            "target:Nicaragua",
            "target:Canada",
            "target:Russia",
            "target:otros"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 9,
            "hostname": 18,
            "domain": 59
          },
          "indicator_count": 86,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 56,
          "modified_text": "410 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ff1245d4dc2a56e5561a57",
          "name": "Threat Actor Profile: El Machete",
          "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
          "modified": "2025-04-16T02:13:25.801000",
          "created": "2025-04-16T02:13:25.801000",
          "tags": [
            "threat_actor",
            "unknown",
            "T1497",
            "T1114",
            "T1566.001",
            "T1059.003",
            "T1081",
            "T1059.006",
            "T1059",
            "T1566.002",
            "T1082",
            "T1027",
            "T1071.001",
            "T1566",
            "T1041",
            "T1105",
            "T1204.001",
            "T1049",
            "T1055",
            "T1036",
            "T1503",
            "T1114.001",
            "T1053",
            "T1140",
            "T1012",
            "T1071",
            "T1112",
            "T1036.005",
            "T1547",
            "T1057",
            "T1008",
            "T1518",
            "T1021",
            "T1011",
            "T1060",
            "T1539",
            "T1587",
            "T1087",
            "T1095",
            "T1102",
            "T1070",
            "T1130",
            "T1552",
            "T1106",
            "T1190",
            "T1007",
            "T1133",
            "T1090",
            "T1016",
            "T1137",
            "T1119",
            "T1124",
            "T1005",
            "T1059.001",
            "T1115",
            "T1562.001",
            "T1543",
            "T1078",
            "T1083",
            "T1530",
            "T1085",
            "T1003",
            "T1120",
            "T1218",
            "T1048",
            "T1553",
            "T1490",
            "T1497.003",
            "T1571",
            "T1204.002",
            "T1595.002",
            "T1102.002",
            "T1583.003",
            "T1027.009",
            "T1027.013",
            "T1132",
            "T1562",
            "T1110",
            "T1059.005",
            "T1218.007",
            "T1204",
            "T1550",
            "T1136",
            "T1555",
            "T1176",
            "T1204_-_User_Execution",
            "T1566_-_Phishing",
            "T1561",
            "T1583",
            "T1485",
            "T1127",
            "T1595",
            "T1573",
            "T1189",
            "T1486",
            "T1531",
            "T1529",
            "T1053.005",
            "T1047.",
            "target:Dominican Republic",
            "target:Venezuela",
            "target:Italy",
            "target:Colombia",
            "target:Ecuador",
            "target:Guatemala",
            "target:Belgium",
            "target:Malaysia",
            "target:Brazil",
            "target:France",
            "target:Indonesia",
            "target:United Kingdom",
            "target:China",
            "target:Germany",
            "target:Mexico",
            "target:Argentina",
            "target:Netherlands",
            "target:Japan",
            "target:Bolivia",
            "target:Yibuti",
            "target:Vietnam",
            "target:Fiyi",
            "target:Cuba",
            "target:Camboya",
            "target:Taiw\u00e1n",
            "target:United States",
            "target:Sweden",
            "target:Ukraine",
            "target:South Korea",
            "target:Nicaragua",
            "target:Canada",
            "target:Russia",
            "target:otros"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 9,
            "hostname": 18,
            "domain": 59
          },
          "indicator_count": 86,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 56,
          "modified_text": "410 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67c0cdc35112c5919563a334",
          "name": "Intel is bad awy",
          "description": "",
          "modified": "2025-03-29T20:01:20.482000",
          "created": "2025-02-27T20:40:35.539000",
          "tags": [
            "sign",
            "github",
            "find",
            "view",
            "search",
            "strong",
            "code issues",
            "pull",
            "breadcrumbs",
            "damn",
            "star",
            "footer",
            "sha1",
            "helldown linux",
            "iocs helldown",
            "windows payload",
            "icon",
            "darkrace",
            "donex",
            "ransom",
            "defanged file",
            "hashes",
            "ipv4",
            "sha256",
            "c2 ip",
            "address",
            "plugin",
            "brazanbamboo c2",
            "panel",
            "archive file",
            "bha006",
            "telegram bot",
            "token",
            "chat id",
            "sha256 hashes",
            "iocs",
            "intermediary",
            "landing",
            "aitm server",
            "compromise note",
            "hashes payload",
            "loader",
            "dropper",
            "ips https",
            "urls https",
            "duoyi",
            "ioc url",
            "ipv4 address",
            "c2 server",
            "sample sha256",
            "remcos",
            "decrypted",
            "urls http",
            "payload",
            "amos stealer",
            "stealc c2",
            "rhadamanthys c2",
            "phishing urls",
            "google meet",
            "amos steaker",
            "html payload",
            "stealc payload",
            "md5 hashes",
            "sha1 hashes",
            "iocs zip",
            "lnk file",
            "msi file",
            "payload url",
            "eldorado",
            "linux",
            "service dll",
            "cheat engine",
            "c2 domain",
            "compromise",
            "urls",
            "iocs files",
            "network ip",
            "domain",
            "malware hash",
            "noopldr type1",
            "noopldr type2",
            "download url",
            "email addresses",
            "block",
            "ioc http",
            "iocs hash",
            "url https",
            "ghostgambit",
            "hidden rootkit",
            "gh0strat",
            "mekotio banking",
            "financial",
            "latin america",
            "detected",
            "zipmsi",
            "downloader",
            "ip address",
            "cobalt strike",
            "first seen",
            "seen",
            "pantegana",
            "tls certificate",
            "fingerprint",
            "samples",
            "trojanspy",
            "msi",
            "subdomains",
            "reddit",
            "wetransfer",
            "ioc hash",
            "file hashes",
            "ip addresses",
            "fake captcha",
            "html",
            "hta script",
            "lumma payload",
            "filehashsha256",
            "indicator type",
            "sha256 lnk",
            "ports",
            "first stage",
            "md5 file",
            "domains",
            "reddelta c2",
            "servers",
            "octoberdecember",
            "shortcut",
            "files",
            "solo airfield",
            "quoc",
            "bctt",
            "kongtuke",
            "mintsloader c2",
            "js download",
            "c2 http",
            "boinc c2",
            "c2 address",
            "analyzed",
            "file name",
            "na stark",
            "na majestic",
            "description",
            "trojanized",
            "beavertail",
            "anydesk module",
            "domain hosting",
            "first",
            "details",
            "monitor",
            "sites",
            "fake chrome",
            "payload host",
            "c2 https",
            "examples",
            "atomic stealer",
            "c2 servers",
            "cthulhu stealer",
            "server http",
            "l files",
            "original",
            "iocs malicious",
            "mirrowsimps",
            "defanged",
            "strike loaders",
            "plugx",
            "plugx c2",
            "sspiuacbypass",
            "malware",
            "malware c2",
            "filehashmd5",
            "site",
            "orgvgodpayment",
            "quite solsjoas",
            "ioc sha256",
            "similar sha256",
            "http",
            "url hundreds",
            "url samples",
            "filehash",
            "guidloader",
            "finaldraft elf",
            "type name",
            "reference",
            "finaldraft",
            "sha256 pfman",
            "pathloader",
            "atomic https",
            "systembc",
            "ghostsocks",
            "invisibleferret",
            "vant",
            "rspackcore",
            "monero",
            "sha256 hash",
            "code snippets",
            "psexec",
            "ituneshelper",
            "pscp",
            "sftp",
            "googleupdate",
            "meshagent",
            "ultravnc",
            "file",
            "bootkitty iocs",
            "phpsert",
            "phpsert variant",
            "createdump tool",
            "visual studio",
            "code",
            "server",
            "sql injection",
            "studio code",
            "ssh access",
            "hta file",
            "vbshower c2",
            "powershower c2",
            "cloud",
            "hta md5",
            "domain name",
            "links",
            "c http",
            "horns",
            "version",
            "version b",
            "version c",
            "version d",
            "version e",
            "burnsrat c",
            "a http",
            "github users",
            "shell commands",
            "vssadmin delete",
            "userprofile",
            "public",
            "registry keys",
            "phobos",
            "lettointago",
            "carljohnson1948",
            "samuelwhite1821",
            "file hash",
            "lockbit",
            "indicatortype",
            "data",
            "mlpea",
            "w32neshtad",
            "gmer",
            "neshta",
            "opswat oesis",
            "v4 removal"
          ],
          "references": [
            "Bootkitty",
            "Glove-Stealer",
            "Fake Discount Sites Exploit Black Friday",
            "Helldown Ransomware",
            "HawkEye Malware",
            "PXA Stealer",
            "Iranian Hackers Use GitHub and Phishing to Evade Detection in SnailResin Attack",
            "BrazenBamboo",
            "SpyGlace",
            "RustyStealer and New Ymir Ransomware",
            "PyPI-AIOCPA",
            "Python NodeStealer",
            "romcom-exploits-firefox-and-windows",
            "Rockstar-Phishing",
            "Silent Skimmer Gets Loud (Again)",
            "SteelFox Trojan",
            "WezRat Malware",
            "Avast-Anti-Root-KIt",
            "Winos4.0 RAT",
            "APT36",
            "WolfsBane Backdoor",
            "APT-K-47",
            "Remcos RAT",
            "babbleloader",
            "Bitter APT",
            "UAC-0194\u2019s Exploitation of CVE-2024-43451 in Ukraine for Phishing",
            "CloudScout_ Evasive Panda scouting cloud services",
            "clickfix-tactic",
            "Akira Ransomware",
            "Bumblebee Malware",
            "ELDORADO RANSOMWARE",
            "Evasive Panda Uses MACMA and MgBot Malware to Target US and Taiwan",
            "Demodex rootkit",
            "BugSleep Malware",
            "HotPage.exe (malware)",
            "Qilin Ransomware",
            "NOOPDOOR Malware",
            "Shadowroot Ransomware",
            "play ransomware",
            "MALLOX RANSOMWARE",
            "New Malware Campaign Abusing RDPWrapper and Tailscale to Target Cryptocurrency Users",
            "ACR Stealer",
            "Suspicious Domains Exploiting the Recent CrowdStrike Outage!",
            "Gh0stGambit",
            "MEKOTIO BANKING TROJAN",
            "TAG-100",
            "Fake game sites lead to information stealers",
            "Chrome Extensions Hijacked, 2.6 Million Users Impacted",
            "macOS Users Targeted by the New Variant of Banshee Infostealer",
            "Hundreds of fake Reddit sites push Lumma Stealer malware",
            "GamaCopy APT Group Mimicking GamaRedon",
            "InvisibleFerret Malware Leveraging Python for Targeted Attacks",
            "Fake CAPTCHA Campaign That Spreads LUMMA Info Stealer",
            "REF5961 Group Deploys EAGERBEE Backdoor Against Critical Sectors",
            "Phishing Campaigns Fuel Compiled AutoIt Malware Distribution",
            "The great Google Ads heist_ criminals ransack advertiser accounts via fake Google ads",
            "New Star Blizzard spear-phishing campaign targets WhatsApp accounts",
            "RansomHub Affiliate leverages Python-based backdoor",
            "Sliver Implant Targets German Entities with DLL Sideloading and Proxying Techniques",
            "Advanced Evasion Techniques Used by NonEuclid RAT",
            "The Return of PlugX Malware with Fresh Tricks",
            "The Growing Risk of Sneaky 2FA for Microsoft and Gmail Accounts",
            "Weaponized Software Targeting Chinese Organizations",
            "Threat Surge as Lumma Stealer Expands Its Reach",
            "Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain",
            "MintsLoader_Stealc",
            "North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks",
            "North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware",
            "Rat Race_ ValleyRAT Malware Targets Organizations with New Delivery Techniques",
            "Salt Typhoon  Target U.S. Telecom Networks",
            "SecTopRAT",
            "Stealers on the Rise",
            "Snake Keylogger",
            "AsyncRAT Reloaded",
            "The BadPilot campaign_ Seashell Blizzard subgroup conducts multiyear global access operation",
            "FatalRAT",
            "SystemBC RAT Poses New Risks to Linux System",
            "Unveiling Silent Lynx APT Targeting Entities Across Kyrgyzstan & Neighbouring Nations",
            "FERRET Malware Targets macOS in Sophisticated North Korean Attacks",
            "Espionage Campaign Targeting South Asian Entities",
            "Astral Stealer Strikes Again Stealing More Than Just Your Cookies",
            "The New Ransomware Menace Vgod Gains Momentum",
            "Microsoft Advertisers Phished via Malicious Google Ads",
            "LegionLoader Malware Expands Global Reach",
            "NEW.txt",
            "From Stealers to Ransomware PureCrypter Delivers It All",
            "New Phishing Campaign Abuses Webflow, SEO, and Fake CAPTCHAs",
            "FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux",
            "LockBit Ransomware Attack Leveraging Cobalt Strike",
            "Rspack_Compromised_Packages",
            "SmokeLoader",
            "Sock5Systemz-PROXY-AM",
            "solana-backdoor",
            "U.S. Organization in China Targeted by Attackers",
            "UAC-0185 attacks warned by CERT-UA",
            "BellaCpp",
            "bootkitty(logofail)",
            "Visual Studio Code Remote tunnels",
            "Cloud Atlas seen using a new tool in its attacks",
            "Christmas-Themed LNK Files Used for Malware Delivery",
            "DarkGate",
            "MirrorFace Campain",
            "horns-hooves",
            "Developers Targeted by New \u2018OtterCookie\u2019 Malware with Fake Job Offers",
            "NetSupport RAT and BurnsRAT",
            "Cybercriminals Leverage Fake CAPTCHAs for Malware Delivery",
            "MUT-1244-GitHub",
            "Phobos ransomware",
            "Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data",
            "PUMAKIT",
            "OtterCookie used by Contagious Interview",
            "Ransomware-Lockbit3-IOCs.csv"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mekotio Banking",
              "display_name": "Mekotio Banking",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "MSI",
              "display_name": "MSI",
              "target": null
            },
            {
              "id": "InvisibleFerret",
              "display_name": "InvisibleFerret",
              "target": null
            },
            {
              "id": "Vant",
              "display_name": "Vant",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 84,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Badderawy",
            "id": "310597",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 950,
            "FileHash-SHA1": 847,
            "FileHash-SHA256": 1060,
            "hostname": 1158,
            "domain": 867,
            "URL": 813,
            "email": 77,
            "CIDR": 2,
            "CVE": 9
          },
          "indicator_count": 5783,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 27,
          "modified_text": "427 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ba1f6c72cd82b53124639d",
          "name": "Mallox ranomware affiliate leverages PureCrypter in MS-SQL exploitation campaigns",
          "description": "A security honeypot was targeted by an attack leveraging brute-force tactics, which led to the release of the PureCrypter ransomware, according to research by Sekoia Research, a security firm.",
          "modified": "2025-03-24T19:03:26.922000",
          "created": "2025-02-22T19:03:08.348000",
          "tags": [
            "mallox",
            "purecrypter",
            "sekoia",
            "maestro",
            "mssql",
            "april",
            "as208091",
            "mssql server",
            "mallox raas",
            "focus",
            "june",
            "shell",
            "unsafe",
            "powershell",
            "prior",
            "targetcompany",
            "team",
            "ramp",
            "twitter",
            "ransom",
            "ukraine",
            "stop",
            "service",
            "shutdown",
            "restart",
            "bitcoin",
            "community",
            "sign",
            "find",
            "search",
            "strong",
            "code issues",
            "pull",
            "breadcrumbs",
            "iocs",
            "star",
            "copy",
            "footer",
            "clr sqlshell",
            "trigona",
            "sqlshell",
            "xollam"
          ],
          "references": [
            "https://blog.sekoia.io/mallox-ransomware-affiliate-leverages-purecrypter-in-microsoft-sql-exploitation-campaigns/",
            "https://github.com/SEKOIA-IO/Community/blob/main/IOCs/mallox/mallox_purecrypter_iocs_20240513.csv"
          ],
          "public": 1,
          "adversary": "Mallox",
          "targeted_countries": [
            "United States of America",
            "United Kingdom of Great Britain and Northern Ireland",
            "Canada",
            "Australia",
            "Germany",
            "Kazakhstan",
            "Russian Federation",
            "Qatar",
            "Ukraine"
          ],
          "malware_families": [
            {
              "id": "CLR SqlShell",
              "display_name": "CLR SqlShell",
              "target": null
            },
            {
              "id": "Trigona",
              "display_name": "Trigona",
              "target": null
            },
            {
              "id": "SqlShell",
              "display_name": "SqlShell",
              "target": null
            },
            {
              "id": "Xollam",
              "display_name": "Xollam",
              "target": null
            },
            {
              "id": "Mallox",
              "display_name": "Mallox",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1559",
              "name": "Inter-Process Communication",
              "display_name": "T1559 - Inter-Process Communication"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [
            "Manufacturing",
            "Retail",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Armature_TIP",
            "id": "308911",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_308911/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "URL": 17,
            "domain": 2,
            "hostname": 2,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 6
          },
          "indicator_count": 40,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "432 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67733b72d522398f5ea0a12d",
          "name": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar",
          "description": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar con Intereses en la Administraci\u00f3n P\u00fablica de la Rep\u00fablica Dominicana, Diciembre 2024",
          "modified": "2025-01-30T00:00:18.927000",
          "created": "2024-12-31T00:31:46.858000",
          "tags": [
            "cve201711882",
            "cve20201472"
          ],
          "references": [],
          "public": 1,
          "adversary": "El Machete, TAG-100, Mirage, Unamed_Grooup",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2631,
            "FileHash-SHA1": 2168,
            "FileHash-SHA256": 3401,
            "CVE": 25,
            "domain": 977,
            "hostname": 1226
          },
          "indicator_count": 10428,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6773390f17d71879c414676a",
          "name": "El Machete",
          "description": "El Machete es un grupo de ciberespionaje activo desde al menos 2014, enfocado en atacar principalmente a naciones de habla hispana. Este grupo es conocido por su sofisticada malware y t\u00e1cticas de exfiltraci\u00f3n de datos, con un enfoque en objetivos de alto perfil, como agencias gubernamentales y organizaciones estrat\u00e9gicas.",
          "modified": "2025-01-30T00:00:18.927000",
          "created": "2024-12-31T00:21:35.813000",
          "tags": [
            "cve201711882",
            "cve20201472",
            "El Machete"
          ],
          "references": [],
          "public": 1,
          "adversary": "El Machete",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 473,
            "FileHash-SHA1": 471,
            "FileHash-SHA256": 500,
            "CVE": 9,
            "domain": 60,
            "hostname": 18
          },
          "indicator_count": 1531,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 60,
          "modified_text": "486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "675f6ca99ae8870748878e05",
          "name": "Declawing PUMAKIT \u2014 Elastic Security Labs",
          "description": "A sophisticated Linux rootkit, known as PUMAKIT, has been uncovered during an analysis of samples uploaded to VirusTotal in 2024, but how does it hide its presence and maintain persistence and control?",
          "modified": "2025-01-14T23:05:01.296000",
          "created": "2024-12-15T23:56:25.146000",
          "tags": [
            "lkm rootkit",
            "pumakit",
            "puma",
            "kitsune",
            "linux kernel",
            "virustotal",
            "cron binary",
            "cron",
            "payload",
            "elf file",
            "target",
            "february",
            "error",
            "rootkit",
            "huinder"
          ],
          "references": [
            "https://www.elastic.co/security-labs/declawing-pumakit"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Huinder",
              "display_name": "Huinder",
              "target": null
            },
            {
              "id": "PUMAKIT",
              "display_name": "PUMAKIT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ChrisTan0",
            "id": "262536",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 5,
            "FileHash-SHA1": 5,
            "FileHash-SHA256": 9,
            "YARA": 1,
            "domain": 3,
            "hostname": 4
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 42,
          "modified_text": "501 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "675c09a9fd112575fd3a7507",
          "name": "New stealthy Pumakit Linux rootkit malware spotted in the wild",
          "description": "A sophisticated Linux rootkit that uses advanced stealth mechanisms to evade detection and maintain persistence and control has been uncovered by researchers at the University of California, San Francisco, and the US National Security Agency (NSA).",
          "modified": "2025-01-12T10:03:17.920000",
          "created": "2024-12-13T10:17:13.931000",
          "tags": [
            "lkm rootkit",
            "pumakit",
            "puma",
            "kitsune",
            "linux kernel",
            "virustotal",
            "cron binary",
            "cron",
            "payload",
            "elf file",
            "target",
            "february",
            "error",
            "rootkit",
            "huinder"
          ],
          "references": [
            "https://www.elastic.co/security-labs/declawing-pumakit"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Huinder",
              "display_name": "Huinder",
              "target": null
            },
            {
              "id": "PUMAKIT",
              "display_name": "PUMAKIT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 5,
            "FileHash-SHA1": 5,
            "FileHash-SHA256": 9,
            "YARA": 1,
            "domain": 3,
            "hostname": 4
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "503 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6715faf117a025d608cdd04b",
          "name": "Unmasking Lumma Stealer : Analyzing Deceptive Tactics with Fake CAPTCHA | Qualys Security Blog",
          "description": "The Lumma Stealer malware is a deceptive and persistent threat that uses a variety of tactics, including fake CAPTCHA pages, which trick users into executing the payload, according to Qualys.",
          "modified": "2024-11-20T00:00:14.174000",
          "created": "2024-10-21T06:55:45.872000",
          "tags": [
            "lumma stealer",
            "figure",
            "command",
            "qualys edr",
            "powershell",
            "ps script",
            "c2 server",
            "threat",
            "cdns",
            "captcha",
            "verify",
            "malware",
            "stealer",
            "lumma"
          ],
          "references": [
            "https://blog.qualys.com/vulnerabilities-threat-research/2024/10/20/unmasking-lumma-stealer-analyzing-deceptive-tactics-with-fake-captcha"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lumma",
              "display_name": "Lumma",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1217",
              "name": "Browser Bookmark Discovery",
              "display_name": "T1217 - Browser Bookmark Discovery"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 11,
            "FileHash-MD5": 12,
            "FileHash-SHA1": 12,
            "FileHash-SHA256": 14,
            "hostname": 1
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 864,
          "modified_text": "557 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6710059101b736e38b9cd2b0",
          "name": "Black Basta",
          "description": "Black Basta is a financially motivated ransomware group that began operations in 2022. It targets organizations across various sectors, including manufacturing, healthcare, and finance, using a double extortion method. The group encrypts victims' systems and threatens to leak stolen data unless a ransom is paid. Their ransomware spreads via phishing campaigns, exploiting vulnerabilities in systems. Black Basta is known for collaborating with other cybercriminals, which enhances the impact and sophistication of their attacks.",
          "modified": "2024-11-15T17:03:59.652000",
          "created": "2024-10-16T18:27:29.179000",
          "tags": [
            "strong",
            "black basta",
            "cisa",
            "powershell",
            "ransomware",
            "cobalt strike",
            "phishing",
            "mimikatz",
            "qakbot",
            "psexec",
            "bits",
            "webdav",
            "winscp",
            "conti",
            "anydesk",
            "quick assist",
            "netsupport",
            "windows",
            "blackbasta",
            "batloader",
            "rclone",
            "vmware esxi",
            "netcat",
            "qbot",
            "emotet",
            "trickbot",
            "pinkslipbot",
            "team",
            "C++",
            "Linux",
            "ChaCha20",
            "RSA-4096",
            "ConnectWise",
            "ZeroLogon",
            "NoPac",
            "PrintNightmare",
            "CVE-2024-1709",
            "CVE-2024-26169",
            "CVE-2020-1472",
            "CVE-2021-42278",
            "CVE-2021-42287",
            "CVE-2021-34527",
            "BITSAdmin",
            "Cobalt Strike",
            "Netcat",
            "ScreenConnect",
            "NetSupport Manager",
            "SystemBC",
            "Qakbot",
            "WMI",
            "RClone",
            "SoftPerfect",
            "BackStab",
            "EvilProxy",
            "Splashtop",
            "WinSCP",
            "C2",
            "CVE-2022-30190",
            "Storm-1811",
            "spear phishing",
            "Coroxy",
            "cobeacon",
            "RaaS",
            "aa24-131a",
            "wandering spider",
            "Conti",
            "wizard spider",
            "BGH"
          ],
          "references": [
            "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a",
            "https://blog.qualys.com/vulnerabilities-threat-research/2024/09/19/black-basta-ransomware-what-you-need-to-know",
            "https://www.rapid7.com/blog/post/2024/05/10/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators/",
            "https://darktrace.com/blog/black-basta-old-dogs-with-new-tricks",
            "https://www.fortinet.com/blog/threat-research/ransomware-roundup-black-basta",
            "https://www.cybereason.com/blog/threat-alert-aggressive-qakbot-campaign-and-the-black-basta-ransomware-group-targeting-u.s.-companies",
            "https://www.cve.org/CVERecord?id=CVE-2020-1472",
            "https://www.cve.org/CVERecord?id=CVE-2021-34527",
            "https://www.cve.org/CVERecord?id=CVE-2021-42278",
            "https://www.cve.org/CVERecord?id=CVE-2021-42287",
            "https://www.cve.org/CVERecord?id=CVE-2024-1709",
            "https://www.cve.org/CVERecord?id=CVE-2024-26169",
            "https://www.cve.org/CVERecord?id=CVE-2022-30190",
            "https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/",
            "https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/",
            "https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbasta"
          ],
          "public": 1,
          "adversary": "Black Basta",
          "targeted_countries": [
            "United States of America",
            "Germany",
            "Canada",
            "Australia",
            "New Zealand",
            "Japan",
            "France",
            "United Kingdom of Great Britain and Northern Ireland",
            "Italy",
            "Switzerland"
          ],
          "malware_families": [
            {
              "id": "Conti",
              "display_name": "Conti",
              "target": null
            },
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Black Basta",
              "display_name": "Black Basta",
              "target": null
            },
            {
              "id": "Primary NetSupport",
              "display_name": "Primary NetSupport",
              "target": null
            },
            {
              "id": "NetSupport",
              "display_name": "NetSupport",
              "target": null
            },
            {
              "id": "Basta Linux",
              "display_name": "Basta Linux",
              "target": null
            },
            {
              "id": "Widespread QBot",
              "display_name": "Widespread QBot",
              "target": null
            },
            {
              "id": "Qbot",
              "display_name": "Qbot",
              "target": null
            },
            {
              "id": "TrojanDownloader:O97M/Qakbot",
              "display_name": "TrojanDownloader:O97M/Qakbot",
              "target": "/malware/TrojanDownloader:O97M/Qakbot"
            },
            {
              "id": "Trojan:Win32/QBot",
              "display_name": "Trojan:Win32/QBot",
              "target": "/malware/Trojan:Win32/QBot"
            },
            {
              "id": "Trojan:Win32/Qakbot",
              "display_name": "Trojan:Win32/Qakbot",
              "target": "/malware/Trojan:Win32/Qakbot"
            },
            {
              "id": "TrojanSpy:Win32/Qakbot",
              "display_name": "TrojanSpy:Win32/Qakbot",
              "target": "/malware/TrojanSpy:Win32/Qakbot"
            },
            {
              "id": "Behavior:Win32/Qakbot",
              "display_name": "Behavior:Win32/Qakbot",
              "target": "/malware/Behavior:Win32/Qakbot"
            },
            {
              "id": "Behavior:Win32/Basta",
              "display_name": "Behavior:Win32/Basta",
              "target": "/malware/Behavior:Win32/Basta"
            },
            {
              "id": "Ransom:Win32/Basta",
              "display_name": "Ransom:Win32/Basta",
              "target": "/malware/Ransom:Win32/Basta"
            },
            {
              "id": "Trojan:Win32/Basta",
              "display_name": "Trojan:Win32/Basta",
              "target": "/malware/Trojan:Win32/Basta"
            },
            {
              "id": "Behavior:Win32/CobaltStrike",
              "display_name": "Behavior:Win32/CobaltStrike",
              "target": "/malware/Behavior:Win32/CobaltStrike"
            },
            {
              "id": "Backdoor:Win64/CobaltStrike",
              "display_name": "Backdoor:Win64/CobaltStrike",
              "target": "/malware/Backdoor:Win64/CobaltStrike"
            },
            {
              "id": "HackTool:Win64/CobaltStrike",
              "display_name": "HackTool:Win64/CobaltStrike",
              "target": "/malware/HackTool:Win64/CobaltStrike"
            },
            {
              "id": "TrojanDropper:PowerShell/Cobacis",
              "display_name": "TrojanDropper:PowerShell/Cobacis",
              "target": "/malware/TrojanDropper:PowerShell/Cobacis"
            },
            {
              "id": "Trojan:Win64/TurtleLoader.CS",
              "display_name": "Trojan:Win64/TurtleLoader.CS",
              "target": "/malware/Trojan:Win64/TurtleLoader.CS"
            },
            {
              "id": "Exploit:Win32/ShellCode.BN",
              "display_name": "Exploit:Win32/ShellCode.BN",
              "target": "/malware/Exploit:Win32/ShellCode.BN"
            },
            {
              "id": "Behavior:Win32/SystemBC",
              "display_name": "Behavior:Win32/SystemBC",
              "target": "/malware/Behavior:Win32/SystemBC"
            },
            {
              "id": "Trojan: Win32/SystemBC",
              "display_name": "Trojan: Win32/SystemBC",
              "target": "/malware/Trojan: Win32/SystemBC"
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1531",
              "name": "Account Access Removal",
              "display_name": "T1531 - Account Access Removal"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1550",
              "name": "Use Alternate Authentication Material",
              "display_name": "T1550 - Use Alternate Authentication Material"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1570",
              "name": "Lateral Tool Transfer",
              "display_name": "T1570 - Lateral Tool Transfer"
            },
            {
              "id": "T1572",
              "name": "Protocol Tunneling",
              "display_name": "T1572 - Protocol Tunneling"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1185",
              "name": "Man in the Browser",
              "display_name": "T1185 - Man in the Browser"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1187",
              "name": "Forced Authentication",
              "display_name": "T1187 - Forced Authentication"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1195",
              "name": "Supply Chain Compromise",
              "display_name": "T1195 - Supply Chain Compromise"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            }
          ],
          "industries": [
            "Critical Infrastructure",
            "Healthcare",
            "Manufacturing",
            "Construction",
            "Retail",
            "Legal",
            "Finance",
            "Technology",
            "Emergency Services",
            "Media",
            "Transportation"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 52,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "v0od0o.exe",
            "id": "273579",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 111,
            "FileHash-SHA1": 110,
            "FileHash-SHA256": 148,
            "CVE": 7,
            "domain": 113,
            "hostname": 62,
            "URL": 4
          },
          "indicator_count": 555,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 27,
          "modified_text": "561 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67289a00f153559e9a657bc3",
          "name": "Lumma Stealer Uses Fake CAPTCHA Pages to Spread Malware",
          "description": "Researchers have found that Lumma Stealer, a malware offered through a Malware-as-a-Service (MaaS) model, has significantly advanced its deceptive methods. In a recent campaign, Lumma Stealer was observed using fake CAPTCHA pages to lure users into executing a persistent payload. This attack employs multi-stage fileless techniques, making it both elusive and long-lasting.",
          "modified": "2024-11-04T09:55:12.970000",
          "created": "2024-11-04T09:55:12.970000",
          "tags": [
            "lumma stealer",
            "figure",
            "command",
            "qualys edr",
            "powershell",
            "ps script",
            "c2 server",
            "threat",
            "cdns",
            "captcha",
            "verify",
            "malware",
            "stealer",
            "lumma"
          ],
          "references": [
            "https://blog.qualys.com/vulnerabilities-threat-research/2024/10/20/unmasking-lumma-stealer-analyzing-deceptive-tactics-with-fake-captcha"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lumma",
              "display_name": "Lumma",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1217",
              "name": "Browser Bookmark Discovery",
              "display_name": "T1217 - Browser Bookmark Discovery"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Superpro",
            "id": "61676",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 11,
            "FileHash-MD5": 13,
            "FileHash-SHA1": 13,
            "FileHash-SHA256": 14,
            "hostname": 1
          },
          "indicator_count": 52,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 215,
          "modified_text": "572 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "672025a446db1f324cbda420",
          "name": "Katz and Mouse Game:  MaaS Infostealers Adapt to Patched Chrome Defenses \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2024-10-29T00:00:36.726000",
          "created": "2024-10-29T00:00:36.726000",
          "tags": [
            "chrome",
            "stealc",
            "lumma",
            "google",
            "september",
            "chromekatz",
            "google chrome",
            "chrome process",
            "windows",
            "july",
            "team",
            "vidar",
            "metastealer",
            "legacy"
          ],
          "references": [
            "https://www.elastic.co/security-labs/katz-and-mouse-game"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ChrisTan0",
            "id": "262536",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 2,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 5,
            "YARA": 1,
            "domain": 4
          },
          "indicator_count": 15,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 42,
          "modified_text": "579 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66f130c6547f970c56c9ebb7",
          "name": "Twelve: from initial compromise to ransomware and wipers | Securelist",
          "description": "The Kaspersky security company has identified the Russian cyberattack group Twelve, which was formed in April 2023 and is believed to be active and capable of carrying out a number of high-profile attacks.",
          "modified": "2024-10-23T09:07:52.333000",
          "created": "2024-09-23T09:11:34.960000",
          "tags": [
            "crimeware",
            "hacktivists",
            "lockbit",
            "malware",
            "malware descriptions",
            "ransomware",
            "shamoon",
            "targeted attacks",
            "trojan",
            "ttps",
            "twelve",
            "wiper",
            "redacted",
            "domain",
            "user",
            "powershell",
            "processname",
            "logtime",
            "taskcachetasks",
            "unified kill",
            "permissions",
            "cobalt strike",
            "bloodhound",
            "powerview",
            "psexec",
            "june",
            "april",
            "shadow",
            "comet",
            "darkstar",
            "crackmapexec",
            "facefish",
            "pass",
            "xenarmor",
            "sandbox",
            "execution",
            "encrypt",
            "stop",
            "verify",
            "chaos"
          ],
          "references": [
            "https://securelist.com/twelve-group-unified-kill-chain/113877/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Wiper",
              "display_name": "Wiper",
              "target": null
            },
            {
              "id": "wiper",
              "display_name": "wiper",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1123",
              "name": "Audio Capture",
              "display_name": "T1123 - Audio Capture"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            }
          ],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 48,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7,
            "CVE": 2,
            "FileHash-MD5": 23,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 4,
            "domain": 3
          },
          "indicator_count": 43,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "584 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66ed8192d7bf1059b4a11ce0",
          "name": "Twelve: from initial compromise to ransomware and wipers | Securelist",
          "description": "The Kaspersky security company has identified the Russian cyberattack group Twelve, which was formed in April 2023 and is believed to be active and capable of carrying out a number of high-profile attacks.",
          "modified": "2024-10-20T14:03:33.411000",
          "created": "2024-09-20T14:07:14.598000",
          "tags": [
            "crimeware",
            "hacktivists",
            "lockbit",
            "malware",
            "malware descriptions",
            "ransomware",
            "shamoon",
            "targeted attacks",
            "trojan",
            "ttps",
            "twelve",
            "wiper",
            "redacted",
            "domain",
            "user",
            "powershell",
            "processname",
            "logtime",
            "taskcachetasks",
            "unified kill",
            "permissions",
            "cobalt strike",
            "bloodhound",
            "powerview",
            "psexec",
            "june",
            "april",
            "shadow",
            "comet",
            "darkstar",
            "crackmapexec",
            "facefish",
            "pass",
            "xenarmor",
            "sandbox",
            "execution",
            "encrypt",
            "stop",
            "verify",
            "chaos"
          ],
          "references": [
            "https://securelist.com/twelve-group-unified-kill-chain/113877/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Wiper",
              "display_name": "Wiper",
              "target": null
            },
            {
              "id": "wiper",
              "display_name": "wiper",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1123",
              "name": "Audio Capture",
              "display_name": "T1123 - Audio Capture"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            }
          ],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ghitansilviu@gmail.com",
            "id": "177478",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1,
            "CVE": 2,
            "FileHash-MD5": 23,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 4,
            "domain": 3
          },
          "indicator_count": 37,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 49,
          "modified_text": "587 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66fe40c0778b4a8b4e728607",
          "name": "Threat Brief: Understanding Akira Ransomware | Qualys Security Blog",
          "description": "",
          "modified": "2024-10-03T06:59:12.683000",
          "created": "2024-10-03T06:59:12.683000",
          "tags": [
            "akira",
            "conti",
            "qualys",
            "march",
            "raas",
            "win32shadowcopy",
            "apis",
            "t1490",
            "remote access",
            "overview akira",
            "ransomware",
            "service",
            "blackbyte"
          ],
          "references": [
            "https://blog.qualys.com/vulnerabilities-threat-research/2024/10/02/threat-brief-understanding-akira-ransomware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1020",
              "name": "Automated Exfiltration",
              "display_name": "T1020 - Automated Exfiltration"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1078",
              "name": "Valid Accounts",
              "display_name": "T1078 - Valid Accounts"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1219",
              "name": "Remote Access Software",
              "display_name": "T1219 - Remote Access Software"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 38,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 4,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 3,
            "domain": 1,
            "hostname": 2
          },
          "indicator_count": 19,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "605 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66ed3d4f6c14a7f20638ec81",
          "name": "Black Basta Ransomware: What You Need to Know | Qualys Security Blog",
          "description": "Black Basta is a ransomware-as-a-service group operating as a service and is known to exploit vulnerabilities and vulnerabilities to gain access to critical systems and data, according to Qualys.",
          "modified": "2024-09-20T09:15:59.733000",
          "created": "2024-09-20T09:15:59.733000",
          "tags": [
            "black basta",
            "appdata",
            "qualys edr",
            "qakbot",
            "cobalt strike",
            "response",
            "xxxxxx",
            "ransom note",
            "mitre att",
            "overview black",
            "april",
            "defender",
            "systembc",
            "mimikatz",
            "winscp",
            "mega",
            "ransomware",
            "powershell",
            "boom",
            "fin7",
            "conti"
          ],
          "references": [
            "https://blog.qualys.com/vulnerabilities-threat-research/2024/09/19/black-basta-ransomware-what-you-need-to-know"
          ],
          "public": 1,
          "adversary": "FIN7",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Conti",
              "display_name": "Conti",
              "target": null
            },
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Black Basta",
              "display_name": "Black Basta",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            }
          ],
          "industries": [
            "Critical Infrastructure"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 59,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 81,
            "CVE": 6,
            "domain": 25
          },
          "indicator_count": 230,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 865,
          "modified_text": "617 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66b203e853f07eb549a1ca86",
          "name": "Dismantling Smart App Control \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2024-08-06T11:07:20.063000",
          "created": "2024-08-06T11:07:20.063000",
          "tags": [
            "smartscreen",
            "smart app",
            "control",
            "motw",
            "mark",
            "microsoft",
            "lnk file",
            "windows smart",
            "app control",
            "windows",
            "virustotal",
            "malware",
            "solarmarker",
            "shellcode",
            "powershell"
          ],
          "references": [
            "https://www.elastic.co/security-labs/dismantling-smart-app-control"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 2,
            "domain": 3,
            "hostname": 4
          },
          "indicator_count": 11,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "662 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6661758de424abc2e27f2492",
          "name": "Mallox ranomware affiliate leverages PureCrypter in MS-SQL exploitation campaigns",
          "description": "",
          "modified": "2024-07-06T08:03:26.984000",
          "created": "2024-06-06T08:38:37.663000",
          "tags": [
            "mallox",
            "purecrypter",
            "sekoia",
            "maestro",
            "mssql",
            "april",
            "as208091",
            "mssql server",
            "mallox raas",
            "focus",
            "june",
            "shell",
            "powershell",
            "prior",
            "team",
            "twitter",
            "ransom",
            "ukraine",
            "stop",
            "service",
            "shutdown",
            "restart",
            "bitcoin"
          ],
          "references": [
            "https://blog.sekoia.io/mallox-ransomware-affiliate-leverages-purecrypter-in-microsoft-sql-exploitation-campaigns/#h-focus-vampire."
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "URL": 3,
            "domain": 2,
            "hostname": 2
          },
          "indicator_count": 8,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "693 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "667a92f2267424e1b819a68a",
          "name": "GrimResource - Microsoft Management Console for initial access and evasion \u2014 Elastic Security Labs",
          "description": "A novel, in-the-wild code execution technique leveraging Microsoft Management Console files (MSC) has been identified by Elastic Security researchers and was first spotted in the wild in June 2016 and is currently being investigated by VirusTotal.",
          "modified": "2024-06-25T09:50:42.069000",
          "created": "2024-06-25T09:50:42.069000",
          "tags": [
            "msc file",
            "vbscript",
            "mmc console",
            "grimresource",
            "console",
            "pastaloader",
            "execution",
            "windows script",
            "rwx memory",
            "jscript",
            "june",
            "virustotal",
            "cobalt strike"
          ],
          "references": [
            "https://www.elastic.co/security-labs/grimresource"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "bluenumberone",
            "id": "246058",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 3,
            "domain": 2,
            "hostname": 3
          },
          "indicator_count": 8,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "704 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6652a8a4277f631ec23d5552",
          "name": "Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID \u2014 Elastic Security Labs",
          "description": "A potential replacement for ICEDID has been identified as LATRODECTUS, a malware loader that has emerged in recent financially-motivated campaigns, according to Proofpoint and Team Cymru.",
          "modified": "2024-06-25T03:01:55.092000",
          "created": "2024-05-26T03:12:36.666000",
          "tags": [
            "latrodectus",
            "icedid",
            "below",
            "c2 server",
            "windows",
            "icedid payload",
            "windows server",
            "elastic defend",
            "walmart",
            "pikabot",
            "error",
            "download",
            "execution",
            "python",
            "webdav",
            "iceid",
            "sonicwall",
            "labs threat",
            "remcosrat",
            "cyclethe sample",
            "pe file",
            "easy",
            "thread local",
            "storage",
            "windows user",
            "access control",
            "team",
            "jar file",
            "forcepoint",
            "autoit script",
            "autoit",
            "java",
            "zip file",
            "darkgate",
            "pdf format",
            "pdf file",
            "java archive",
            "powershell"
          ],
          "references": [
            "https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus",
            "https://blog.sonicwall.com/en-us/2024/05/remcos-is-pairing-with-privateloader-to-extend-its-capabilities/",
            "https://www.forcepoint.com/blog/x-labs/phishing-script-inside-darkgate-campaign"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ICEID",
              "display_name": "ICEID",
              "target": null
            },
            {
              "id": "ICEDID",
              "display_name": "ICEDID",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 44,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "text_account",
            "id": "221593",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CIDR": 15,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "URL": 13,
            "YARA": 1,
            "domain": 18,
            "hostname": 3
          },
          "indicator_count": 55,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 51,
          "modified_text": "705 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "664b219dfbbf02ccbd6937d2",
          "name": "Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2024-06-19T10:00:57.752000",
          "created": "2024-05-20T10:10:37.329000",
          "tags": [
            "latrodectus",
            "icedid",
            "below",
            "c2 server",
            "windows",
            "icedid payload",
            "windows server",
            "elastic defend",
            "walmart",
            "pikabot",
            "error",
            "download",
            "execution",
            "python",
            "webdav"
          ],
          "references": [
            "https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "bluenumberone",
            "id": "246058",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CIDR": 15,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "URL": 3,
            "YARA": 1,
            "domain": 6,
            "hostname": 2
          },
          "indicator_count": 30,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "710 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "664b9d93d13872a5da90e45a",
          "name": "Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2024-05-20T18:59:31.296000",
          "created": "2024-05-20T18:59:31.296000",
          "tags": [
            "latrodectus",
            "icedid",
            "below",
            "c2 server",
            "windows",
            "icedid payload",
            "windows server",
            "elastic defend",
            "walmart",
            "pikabot",
            "error",
            "download",
            "execution",
            "python",
            "webdav"
          ],
          "references": [
            "https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AustinBH",
            "id": "147442",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 1,
            "URL": 3,
            "YARA": 1,
            "domain": 6,
            "hostname": 2
          },
          "indicator_count": 15,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "740 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6545ee0e27e6274f9e66b973",
          "name": "Elastic catches DPRK passing out KANDYKORN \u2014 Elastic Security Labs",
          "description": "A novel intrusion targeting blockchain engineers of a crypto exchange platform was carried out by the Democratic Republic of Korea (D DPRK), according to Elastic Security Labs, who identified the North Korean state as the Lazarus Group.",
          "modified": "2023-12-04T07:05:12.406000",
          "created": "2023-11-04T07:09:02.366000",
          "tags": [
            "sugarloader",
            "command",
            "kandykorn",
            "lazarus group",
            "discord",
            "eql query",
            "dprk",
            "c2 server",
            "google drive",
            "ref7001",
            "python",
            "virustotal",
            "dropper",
            "loader",
            "swift",
            "kill",
            "model",
            "malware",
            "lazarus",
            "macos",
            "findertools"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "SUGARLOADER",
              "display_name": "SUGARLOADER",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1008",
              "name": "Fallback Channels",
              "display_name": "T1008 - Fallback Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 3,
            "URL": 2,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 18,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "909 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6545ee2587c61e9e6e119c43",
          "name": "Elastic catches DPRK passing out KANDYKORN \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2023-12-04T07:05:12.406000",
          "created": "2023-11-04T07:09:25.543000",
          "tags": [
            "sugarloader",
            "command",
            "kandykorn",
            "lazarus group",
            "discord",
            "eql query",
            "dprk",
            "c2 server",
            "google drive",
            "ref7001",
            "python",
            "virustotal",
            "dropper",
            "loader",
            "swift",
            "kill",
            "model",
            "malware",
            "lazarus",
            "macos",
            "findertools"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "SUGARLOADER",
              "display_name": "SUGARLOADER",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1008",
              "name": "Fallback Channels",
              "display_name": "T1008 - Fallback Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6545ee0e27e6274f9e66b973",
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 3,
            "URL": 2,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 18,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 276,
          "modified_text": "909 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65607608c2de990f5f2065e4",
          "name": "Elastic catches DPRK passing out KANDYKORN \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2023-12-04T07:05:12.406000",
          "created": "2023-11-24T10:08:08.673000",
          "tags": [
            "sugarloader",
            "command",
            "kandykorn",
            "lazarus group",
            "discord",
            "eql query",
            "dprk",
            "c2 server",
            "google drive",
            "ref7001",
            "python",
            "virustotal",
            "dropper",
            "loader",
            "swift",
            "kill",
            "model",
            "malware",
            "lazarus",
            "macos",
            "findertools"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "SUGARLOADER",
              "display_name": "SUGARLOADER",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1008",
              "name": "Fallback Channels",
              "display_name": "T1008 - Fallback Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6545ee2587c61e9e6e119c43",
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "santravault1",
            "id": "217419",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_217419/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 3,
            "URL": 2,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 18,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 75,
          "modified_text": "909 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65424d2787b756c2301208df",
          "name": "Elastic catches DPRK passing out KANDYKORN \u2014 Elastic Security Labs",
          "description": "A novel intrusion targeting blockchain engineers of a crypto exchange platform was carried out by the Democratic Republic of Korea (D DPRK), according to Elastic Security Labs, who identified the North Korean state as the Lazarus Group.",
          "modified": "2023-12-01T13:00:03.967000",
          "created": "2023-11-01T13:05:43.927000",
          "tags": [
            "sugarloader",
            "command",
            "kandykorn",
            "lazarus group",
            "discord",
            "eql query",
            "dprk",
            "c2 server",
            "google drive",
            "ref7001",
            "python",
            "virustotal",
            "dropper",
            "loader",
            "write",
            "june",
            "jokerspy",
            "swift",
            "kill",
            "april",
            "model",
            "malware",
            "lazarus",
            "macos",
            "findertools"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "macOS",
              "display_name": "macOS",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "SUGARLOADER",
              "display_name": "SUGARLOADER",
              "target": null
            },
            {
              "id": "FinderTools",
              "display_name": "FinderTools",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1008",
              "name": "Fallback Channels",
              "display_name": "T1008 - Fallback Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 3,
            "URL": 3,
            "domain": 4,
            "hostname": 9
          },
          "indicator_count": 20,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 864,
          "modified_text": "911 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "652e382249b6450188a20316",
          "name": "New BLISTER Malware Involved in Network Infiltration",
          "description": "",
          "modified": "2023-11-16T07:01:26.974000",
          "created": "2023-10-17T07:30:42.274000",
          "tags": [
            "blister",
            "blister loader",
            "security labs",
            "labs",
            "elastic",
            "new development",
            "palo alto",
            "mythic",
            "vlc dll",
            "different",
            "august",
            "virustotal",
            "june",
            "test",
            "trojan",
            "persistence",
            "blister malware",
            "strong",
            "security",
            "startup folder",
            "execution",
            "binary proxy",
            "malware",
            "cobaltstrike",
            "bitrat",
            "urls",
            "please",
            "javascript",
            "group",
            "push",
            "team",
            "red dev",
            "bitrat malware",
            "xmm0",
            "pla unit",
            "maria bitrat",
            "nanocore rat",
            "ave maria",
            "jackal",
            "nodestealer",
            "bomb",
            "discord",
            "purecrypter",
            "quasar rat",
            "avemariarat",
            "hido",
            "powershell",
            "melissa",
            "netwire rc",
            "oilrig",
            "mask",
            "bluenoroff",
            "panda",
            "back",
            "xworm",
            "xavier",
            "adobot",
            "orcus rat",
            "pandora rat",
            "raccoon",
            "vlad",
            "bill",
            "tinynuke",
            "remcos",
            "cobalt strike",
            "zloader",
            "agent tesla",
            "ficker stealer",
            "avemaria",
            "download",
            "stealth mango",
            "ixeshe",
            "aluminum",
            "msupdater",
            "nettraveler",
            "keyboy",
            "sednit",
            "sofacy",
            "oceanlotus",
            "holmium",
            "scarcruft",
            "venus",
            "sykipot",
            "leviathan",
            "amoeba",
            "hoodoo",
            "dragon",
            "star",
            "matanbuchus",
            "comnie",
            "termite",
            "emdivi",
            "greenbug",
            "careto",
            "cobalt",
            "cyber",
            "icefog",
            "trident",
            "dnspionage",
            "darkhotel",
            "luder",
            "nemim",
            "tapaoux",
            "pioneer",
            "havex",
            "machete",
            "evilnum",
            "carbanak",
            "gcman",
            "ghostnet",
            "bitter",
            "infy",
            "karakurt",
            "kinsing",
            "mercury",
            "naikon",
            "nitro",
            "strongpity",
            "powerpool",
            "indra",
            "sauron",
            "sidewinder",
            "redalpha",
            "mantis",
            "rocke",
            "mimic",
            "silence",
            "guardian",
            "teamspy",
            "teamtnt",
            "teamxrat",
            "turla",
            "snake",
            "wraith",
            "pfinet",
            "krypton",
            "zoopark",
            "sha256 trend",
            "micro detection",
            "script c",
            "unique string",
            "windows",
            "lnk file",
            "windows native",
            "payload",
            "launchcolorcpl",
            "amadey",
            "clipbanker",
            "launch",
            "apache"
          ],
          "references": [
            "September 06th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3180 - New BLISTER Malware Involved in Network Infiltration.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 74,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 57,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 61,
            "domain": 10,
            "hostname": 6,
            "YARA": 3,
            "URL": 3
          },
          "indicator_count": 199,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 500,
          "modified_text": "927 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64a2b6a638a683d6da50262c",
          "name": "New 'RustBucket' Malware Variant Targeting macOS Users",
          "description": "Researchers have pulled back the curtain on an updated version of an Apple macOS malware called RustBucket that comes with improved capabilities to establish persistence and avoid detection by security software.\n\n\"This variant of RustBucket, a malware family that targets macOS systems, adds persistence capabilities not previously observed,\" Elastic Security Labs researchers said in a report published this week, adding it's \"leveraging a dynamic network infrastructure methodology for command-and-control.\"\n\nRustBucket is the work of a North Korean threat actor known as BlueNoroff, which is part of a larger intrusion set tracked under the name Lazarus Group, an elite hacking unit supervised by the Reconnaissance General Bureau (RGB), the country's primary intelligence agency.",
          "modified": "2023-08-02T11:00:08.290000",
          "created": "2023-07-03T11:53:10.113000",
          "tags": [
            "stage",
            "http response",
            "firefox",
            "method",
            "allowed",
            "ref9135",
            "c2 domain",
            "found",
            "c2 server",
            "internet",
            "lazarus",
            "security research",
            "dprk",
            "rustbucket"
          ],
          "references": [
            "https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket",
            "https://thehackernews.com/2023/07/beware-new-rustbucket-malware-variant.html"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Security Research",
              "display_name": "Security Research",
              "target": null
            },
            {
              "id": "REF9135",
              "display_name": "REF9135",
              "target": null
            },
            {
              "id": "DPRK",
              "display_name": "DPRK",
              "target": null
            },
            {
              "id": "RUSTBUCKET",
              "display_name": "RUSTBUCKET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Cryptocurrency"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 312,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dekaRituraj",
            "id": "99856",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_99856/resized/80/avatar_0e93d502b7.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 9,
            "YARA": 1,
            "domain": 5,
            "hostname": 4
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 434,
          "modified_text": "1032 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64a297645ecb370a4c5fe113",
          "name": "Beware: New 'RustBucket' Malware Variant Targeting macOS Users",
          "description": "Here is a full list of highlights from the latest security research on Elastic, the search and discovery platform for the Elastic Stack, which is available on the web, mobile, iPlayer and app.",
          "modified": "2023-08-02T09:04:51.419000",
          "created": "2023-07-03T09:39:48.754000",
          "tags": [
            "stage",
            "http response",
            "firefox",
            "method",
            "allowed",
            "ref9135",
            "c2 domain",
            "found",
            "c2 server",
            "internet",
            "lazarus",
            "security research",
            "dprk",
            "rustbucket"
          ],
          "references": [
            "https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Security Research",
              "display_name": "Security Research",
              "target": null
            },
            {
              "id": "REF9135",
              "display_name": "REF9135",
              "target": null
            },
            {
              "id": "DPRK",
              "display_name": "DPRK",
              "target": null
            },
            {
              "id": "RUSTBUCKET",
              "display_name": "RUSTBUCKET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Cryptocurrency"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "parvesh4399",
            "id": "224939",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 9,
            "YARA": 1,
            "domain": 5,
            "hostname": 4
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 55,
          "modified_text": "1032 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64a3aae5c97ae614933e01bd",
          "name": "The DPRK strikes using a new variant of RUSTBUCKET | Elastic",
          "description": "",
          "modified": "2023-08-02T03:05:34.536000",
          "created": "2023-07-04T05:15:17.694000",
          "tags": [
            "ref9135",
            "c2 domain",
            "c2 server",
            "lazarus",
            "dprk",
            "rustbucket"
          ],
          "references": [
            "https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "RUSTBUCKET",
              "display_name": "RUSTBUCKET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Cryptocurrency"
          ],
          "TLP": "white",
          "cloned_from": "64a3aab6d8fc995e6f411255",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 9,
            "URL": 2,
            "YARA": 1,
            "domain": 5,
            "hostname": 4
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 276,
          "modified_text": "1033 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64a3aab6d8fc995e6f411255",
          "name": "The DPRK strikes using a new variant of RUSTBUCKET | Elastic",
          "description": "",
          "modified": "2023-08-02T03:05:34.536000",
          "created": "2023-07-04T05:14:30.984000",
          "tags": [
            "ref9135",
            "c2 domain",
            "c2 server",
            "lazarus",
            "dprk",
            "rustbucket"
          ],
          "references": [
            "https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "RUSTBUCKET",
              "display_name": "RUSTBUCKET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Cryptocurrency"
          ],
          "TLP": "white",
          "cloned_from": "64a23f37094d507e996725d7",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 9,
            "URL": 2,
            "YARA": 1,
            "domain": 5,
            "hostname": 4
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "1033 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64a23f37094d507e996725d7",
          "name": "The DPRK strikes using a new variant of RUSTBUCKET | Elastic",
          "description": "The Elastic Security Labs team has detected a new variant of the RUSTBUCKET malware, a family that has been previously attributed to the BlueNorOff group by Jamf Threat Labs in April 2023. This variant of RUSTBUCKET, a malware family that targets macOS systems, adds persistence capabilities not previously observed and, at the time of reporting, is undetected by VirusTotal signature engines. \n\nThe research into REF9135 used host, binary, and network analysis to identify and attribute intrusions observed by this research team, and other intelligence groups, with high confidence to the Lazarus Group; a cybercrime and espionage organization operated by the Democratic People\u2019s Republic of North Korea (DPRK).",
          "modified": "2023-08-02T03:05:34.536000",
          "created": "2023-07-03T03:23:35.187000",
          "tags": [
            "ref9135",
            "c2 domain",
            "c2 server",
            "lazarus",
            "dprk",
            "rustbucket"
          ],
          "references": [
            "https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "RUSTBUCKET",
              "display_name": "RUSTBUCKET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            }
          ],
          "industries": [
            "Cryptocurrency"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "goatluxy",
            "id": "207695",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 9,
            "URL": 2,
            "YARA": 1,
            "domain": 5,
            "hostname": 4
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 72,
          "modified_text": "1033 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64520cce3fe76f7af80a6cda",
          "name": "Elastic Security Labs discovers the LOBSHOT malware | Elastic",
          "description": "",
          "modified": "2023-05-03T07:27:10.400000",
          "created": "2023-05-03T07:27:10.400000",
          "tags": [
            "lobshot",
            "security labs",
            "google ads",
            "hidden virtual",
            "yara signature"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6450b06a0dd67d58d571eaf8",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1,
            "IPv4": 1,
            "URL": 1,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 9,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "1124 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6450b06a0dd67d58d571eaf8",
          "name": "Elastic Security Labs discovers the LOBSHOT malware | Elastic",
          "description": "",
          "modified": "2023-05-02T06:40:42.269000",
          "created": "2023-05-02T06:40:42.269000",
          "tags": [
            "lobshot",
            "security labs",
            "google ads",
            "hidden virtual",
            "yara signature"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1,
            "IPv4": 1,
            "URL": 1,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 9,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1125 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "642c0676f0f3f58f0e7cf551",
          "name": "3CXDesktopApp Backdoored in a Suspected Lazarus Campaign | Qualys Security Blog",
          "description": "North Korean state-sponsored group Lazarus has been identified as the perpetrator of a supply chain attack on a popular VOIP desktop client by 3CX, according to security firm Qualys.",
          "modified": "2023-04-04T11:13:57.970000",
          "created": "2023-04-04T11:13:57.970000",
          "tags": [
            "fig.1",
            "table.4 info",
            "voip desktop",
            "edge",
            "firefox",
            "threat research",
            "windows",
            "chrome",
            "github",
            "detection",
            "protection",
            "analysis",
            "android",
            "malware",
            "dani"
          ],
          "references": [
            "https://blog.qualys.com/vulnerabilities-threat-research/2023/04/03/3cxdesktopapp-backdoored-in-a-suspected-lazarus-campaign#iocs"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Table.4 Info",
              "display_name": "Table.4 Info",
              "target": null
            },
            {
              "id": "Fig.1",
              "display_name": "Fig.1",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1195",
              "name": "Supply Chain Compromise",
              "display_name": "T1195 - Supply Chain Compromise"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 10,
            "FileHash-SHA1": 11,
            "FileHash-SHA256": 27,
            "domain": 22
          },
          "indicator_count": 70,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "1152 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63bfd1749cbf9b14577833ce",
          "name": "Gootkit: the cautious Trojan | Securelist",
          "description": "Gootkit is a complex multi-stage banking malware that is capable of stealing data from web users, taking screenshots and performing man-in-the-browser attacks, but can be stopped if the loader is encrypted.",
          "modified": "2023-01-12T09:23:00.638000",
          "created": "2023-01-12T09:23:00.638000",
          "tags": [
            "spelevo",
            "domains",
            "roadsweep",
            "janicab",
            "financial malware",
            "malware descriptions",
            "malware technologies",
            "trojan banker",
            "gootkit",
            "crc32",
            "vmware",
            "main body",
            "gootkit loader",
            "firefox",
            "section1",
            "inf file",
            "systemroot",
            "c server",
            "sandbox",
            "win64",
            "loader"
          ],
          "references": [
            "https://securelist.com/gootkit-the-cautious-trojan/102731/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Italy",
            "Germany"
          ],
          "malware_families": [
            {
              "id": "Janicab",
              "display_name": "Janicab",
              "target": null
            },
            {
              "id": "ROADSWEEP",
              "display_name": "ROADSWEEP",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "Spelevo",
              "display_name": "Spelevo",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1080",
              "name": "Taint Shared Content",
              "display_name": "T1080 - Taint Shared Content"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            }
          ],
          "industries": [
            "Legal",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-MD5": 5,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 2,
            "domain": 6
          },
          "indicator_count": 18,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1234 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "ASAuthorizationProviderExtensionAuthorizationResult.h",
        "AppleUSBDescriptorParsing.h",
        "GKTurnBasedMatchmakerViewController.h",
        "https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbasta",
        "GCButtonElement.h",
        "GKSessionError.h",
        "ASCredentialRequest.h",
        "ASAuthorizationWebBrowserPublicKeyCredentialManager.h",
        "audit_ioctl.h",
        "lz4.h",
        "MapKit.tbd",
        "stdatomic.h",
        "WolfsBane Backdoor",
        "https://www.truesec.com/hub/blog/malicious-axios-packages-npm-in-supply-chain-compromise",
        "GCProductCategories.h",
        "GKMatchmakerViewController.h",
        "AppSandbox.tbd",
        "GCGamepad.h",
        "vForce.h",
        "GKGameSessionError.h",
        "ASCOSEConstants.h",
        "MultipeerConnectivity.h",
        "locate_plugin.h",
        "https://www.cve.org/CVERecord?id=CVE-2024-1709",
        "perlsdio.h",
        "IOUSBHost.h",
        "static_if.h",
        "perly.h",
        "unicode_constants.h",
        "North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks",
        "GKGameSessionSharingViewController.h",
        "parser.h",
        "SwiftUI.swiftoverlay",
        "GCKeyboard.h",
        "machine_remote_time.h",
        "pycore_condvar.h",
        "GCSyntheticDeviceKeys.h",
        "nostdio.h",
        "https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust",
        "WKWebsiteDataRecord.h",
        "SecTopRAT",
        "IOUSBHostControllerInterface.h",
        "arm64e-apple-macos.swiftinterface",
        "_mcontext.h",
        "MultipeerConnectivity.tbd",
        "libperl.tbd",
        "in_stat.h",
        "perl_langinfo.h",
        "https://blog.sonicwall.com/en-us/2024/05/remcos-is-pairing-with-privateloader-to-extend-its-capabilities/",
        "GCControllerTouchpad.h",
        "ELDORADO RANSOMWARE",
        "ASPublicKeyCredentialClientData.h",
        "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/#h-iocs-and-technical-details",
        "unixish.h",
        "Bluetooth.h",
        "encode.h",
        "WKPDFConfiguration.h",
        "RansomHub Affiliate leverages Python-based backdoor",
        "OtterCookie used by Contagious Interview",
        "ASAccountAuthenticationModificationUpgradePasswordToStrongPasswordRequest.h",
        "warnings.h",
        "IOBluetoothObjectPushUIController.h",
        "GCPhysicalInputElement.h",
        "pmap.h",
        "sv.h",
        "ASPasswordCredential.h",
        "Unveiling Silent Lynx APT Targeting Entities Across Kyrgyzstan & Neighbouring Nations",
        "GKVoiceChat.h",
        "OBEXBluetooth.h",
        "dosish.h",
        "WKContentRuleList.h",
        "Rat Race_ ValleyRAT Malware Targets Organizations with New Delivery Techniques",
        "overload.h",
        "Python NodeStealer",
        "https://github.com/SEKOIA-IO/Community/blob/main/IOCs/mallox/mallox_purecrypter_iocs_20240513.csv",
        "ptrauth.h",
        "ASWebAuthenticationSessionWebBrowserSessionManager.h",
        "GKMatch.h",
        "WKUserScript.h",
        "OSvKernDSPLib.h",
        "lz4_assembly_select.h",
        "regcomp.h",
        "IntentsUI.apinotes",
        "tcp_timer.h",
        "FatalRAT",
        "ASAuthorizationSecurityKeyPublicKeyCredentialAssertion.h",
        "GKLeaderboardSet.h",
        "gv.h",
        "sysctl.h",
        "kpi_ipfilter.h",
        "MintsLoader_Stealc",
        "cv.h",
        "ASExtensionErrors.h",
        "https://blog.qualys.com/vulnerabilities-threat-research/2024/10/20/unmasking-lumma-stealer-analyzing-deceptive-tactics-with-fake-captcha",
        "Phobos ransomware",
        "OSAtomic.h",
        "config.h",
        "MUT-1244-GitHub",
        "in_pcb.h",
        "https://www.derp.ca/research/axios-npm-supply-chain-rat/",
        "GKPeerPickerController.h",
        "vm_compressor_algorithms.h",
        "mg.h",
        "IOUSBHostDevice.h",
        "HawkEye Malware",
        "horns-hooves",
        "perldtrace.h",
        "vm_fault.h",
        "UNDTypes.h",
        "Stealers on the Rise",
        "AFKMemoryDescriptorOptions.h",
        "INImage+IntentsUI.h",
        "WebKit.apinotes",
        "play ransomware",
        "reentr.h",
        "scope.h",
        "WKPreviewActionItem.h",
        "OSReturn.h",
        "GKChallengesViewController.h",
        "WKWebView.h",
        "WebKit.h",
        "Snake Keylogger",
        "https://www.elastic.co/guide/en/security/current/windows-defender-exclusions-added-via-powershell.html",
        "WKOpenPanelParameters.h",
        "ASCredentialIdentity.h",
        "MirrorFace Campain",
        "GCLinearInput.h",
        "ASAccountAuthenticationModificationExtensionContext.h",
        "GCRacingWheel.h",
        "ASPasswordCredentialIdentity.h",
        "GKChallenge.h",
        "GKEventListener.h",
        "python-3.9-embed.pc",
        "Microsoft Advertisers Phished via Malicious Google Ads",
        "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware",
        "cop.h",
        "GKDialogController.h",
        "https://blog.sekoia.io/phishing-campaigns-i-paid-twice-targeting-booking-com-hotels-and-customers/",
        "WKURLSchemeTask.h",
        "GCColor.h",
        "ASAuthorizationWebBrowserPlatformPublicKeyCredentialProvider.h",
        "RustyStealer and New Ymir Ransomware",
        "Threat Surge as Lumma Stealer Expands Its Reach",
        "GCKeyboardInput.h",
        "vecLibTypes.h",
        "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialRegistrationRequest.h",
        "IOUSBHostControllerInterfaceHelpers.h",
        "UAC-0185 attacks warned by CERT-UA",
        "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-131a",
        "_endian.h",
        "ASAuthorizationPublicKeyCredentialLargeBlobAssertionOutput.h",
        "ASAuthorizationPublicKeyCredentialAssertionRequest.h",
        "x86_64-apple-macos.swiftinterface",
        "ASAuthorizationCustomMethod.h",
        "hv.h",
        "WebDriver.tbd",
        "Fake game sites lead to information stealers",
        "MEKOTIO BANKING TROJAN",
        "GCPhysicalInputSource.h",
        "embed.h",
        "IOUSBHostDefinitions.h",
        "IOUSBHost.tbd",
        "in_var.h",
        "FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and Linux",
        "Demodex rootkit",
        "ASAuthorizationAppleIDCredential.h",
        "ASAuthorizationWebBrowserPlatformPublicKeyCredential.h",
        "Sliver Implant Targets German Entities with DLL Sideloading and Proxying Techniques",
        "IOBluetoothTypes.h",
        "MCError.h",
        "time64.h",
        "GCMouse.h",
        "GCDeviceBattery.h",
        "IOPCIDevice.iig",
        "preauth_plugin.h",
        "GKGameCenterViewController.h",
        "https://blog.sekoia.io/mallox-ransomware-affiliate-leverages-purecrypter-in-microsoft-sql-exploitation-campaigns/",
        "ip_icmp.h",
        "https://hunt.io/blog/axios-supply-chain-attack-ta444-bluenoroff",
        "zconf.h",
        "ASAuthorizationPlatformPublicKeyCredentialAssertion.h",
        "XSUB.h",
        "GKLocalPlayer.h",
        "in_private.h",
        "time64_config.h",
        "arm_features.inc",
        "WKWebViewConfiguration.h",
        "CredentialsCache2.h",
        "vDSP.h",
        "ipc_types.h",
        "BrazenBamboo",
        "clickfix-tactic",
        "IOUSBHostCIControllerStateMachine.h",
        "https://darktrace.com/blog/black-basta-old-dogs-with-new-tricks",
        "IOUSBHostInterface.h",
        "config.xml",
        "ASPasskeyAssertionCredential.h",
        "ip6.h",
        "KerberosLogin.h",
        "GCDeviceCursor.h",
        "IOBluetooth.tbd",
        "IOBluetoothUI.tbd",
        "WKScriptMessageHandler.h",
        "tcp_private.h",
        "version.h",
        "op.h",
        "https://www.elastic.co/security-labs/spring-cleaning-with-latrodectus",
        "OSByteOrder.h",
        "INUIAddVoiceShortcutViewController.h",
        "GCDirectionPadElement.h",
        "cpu_capabilities_public.h",
        "BugSleep Malware",
        "GCDevicePhysicalInputState.h",
        "fakesdio.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialRegistration.h",
        "canvas.html",
        "invlist_inline.h",
        "intrpvar.h",
        "IOBluetoothPasskeyDisplay.h",
        "perl_siphash.h",
        "hv_func.h",
        "vfs_support.h",
        "GKSession.h",
        "perlio.h",
        "New Malware Campaign Abusing RDPWrapper and Tailscale to Target Cryptocurrency Users",
        "sel.h",
        "GCMouseInput.h",
        "Developers Targeted by New \u2018OtterCookie\u2019 Malware with Fake Job Offers",
        "GKCloudPlayer.h",
        "GKVoiceChatService.h",
        "Cybercriminals Leverage Fake CAPTCHAs for Malware Delivery",
        "BellaCpp",
        "igmp.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialDescriptor.h",
        "MCAdvertiserAssistant.h",
        "WKSecurityOrigin.h",
        "op_reg_common.h",
        "OBEX.h",
        "romcom-exploits-firefox-and-windows",
        "ASAccountAuthenticationModificationReplacePasswordWithSignInWithAppleRequest.h",
        "stdbool.h",
        "GCMicroGamepadSnapshot.h",
        "SteelFox Trojan",
        "tcpip.h",
        "alc.h",
        "vm_map.h",
        "WKDownloadDelegate.h",
        "Bitter APT",
        "APT36",
        "ASPasskeyRegistrationCredential.h",
        "AuthenticationServicesCore.tbd",
        "oalStaticBufferExtension.h",
        "PUMAKIT",
        "GCControllerButtonInput.h",
        "The Return of PlugX Malware with Fresh Tricks",
        "perl.h",
        "Suspicious Domains Exploiting the Recent CrowdStrike Outage!",
        "GCSwitchPositionInput.h",
        "GCTouchedStateInput.h",
        "GCTypes.h",
        "MCNearbyServiceAdvertiser.h",
        "GKError.h",
        "pp.h",
        "Rspack_Compromised_Packages",
        "bootkitty(logofail)",
        "OSBase.h",
        "UNDTypes.defs",
        "GCKeyNames.h",
        "https://securelist.com/gootkit-the-cautious-trojan/102731/",
        "pp_proto.h",
        "Fake CAPTCHA Campaign That Spreads LUMMA Info Stealer",
        "BluetoothAssignedNumbers.h",
        "rpcv2.h",
        "nfsproto.h",
        "perlvars.h",
        "NSAttributedString.h",
        "GCDualShockGamepad.h",
        "signal.h",
        "ASAuthorizationError.h",
        "AirPlayReceiver.tbd",
        "table.h",
        "machine_cpuid.h",
        "CredentialsCache.h",
        "IOBluetoothPairingController.h",
        "WKContentWorld.h",
        "plugin.js",
        "ip.h",
        "capture_resize.js",
        "WKProcessPool.h",
        "ASAuthorizationOpenIDRequest.h",
        "ASWebAuthenticationSession.h",
        "MALLOX RANSOMWARE",
        "https://www.cve.org/CVERecord?id=CVE-2020-1472",
        "WKNavigation.h",
        "GKGameSessionEventListener.h",
        "Iranian Hackers Use GitHub and Phishing to Evade Detection in SnailResin Attack",
        "September 06th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3180 - New BLISTER Malware Involved in Network Infiltration.pdf",
        "WKHTTPCookieStore.h",
        "vm_dyld_pager.h",
        "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialProvider.h",
        "ASWebAuthenticationSessionWebBrowserSessionHandling.h",
        "pio.h",
        "GCExtendedGamepadSnapshot.h",
        "GCPressedStateInput.h",
        "utf8.h",
        "WKUserContentController.h",
        "WKURLSchemeHandler.h",
        "GCKeyCodes.h",
        "ASWebAuthenticationSessionRequest.h",
        "GCSwitchElement.h",
        "pad.h",
        "perliol.h",
        "ASPasskeyCredentialIdentity.h",
        "GKDefines.h",
        "OSMalloc.h",
        "GKFriendRequestComposeViewController.h",
        "ASAuthorizationAppleIDButton.h",
        "util.h",
        "Christmas-Themed LNK Files Used for Malware Delivery",
        "IOBluetoothUIUserLib.h",
        "NetSupport RAT and BurnsRAT",
        "ipc_pthread_priority_types.h",
        "xdr_subs.h",
        "ASAuthorization.h",
        "ASAuthorizationPublicKeyCredentialDescriptor.h",
        "https://www.cve.org/CVERecord?id=CVE-2021-42287",
        "https://www.elastic.co/security-labs/declawing-pumakit",
        "https://www.rapid7.com/blog/post/2024/05/10/ongoing-social-engineering-campaign-linked-to-black-basta-ransomware-operators/",
        "keywords.h",
        "iperlsys.h",
        "WKNavigationResponse.h",
        "NEW.txt",
        "ip_var.h",
        "WebGPU.tbd",
        "mg_data.h",
        "ASEProcessing.tbd",
        "inline.h",
        "WKError.h",
        "GKAchievement.h",
        "ASAuthorizationPublicKeyCredentialRegistration.h",
        "al.h",
        "IOUSBHostIOSource.h",
        "ASCredentialServiceIdentifier.h",
        "GKLeaderboardScore.h",
        "REF5961 Group Deploys EAGERBEE Backdoor Against Critical Sectors",
        "Ransomware-Lockbit3-IOCs.csv",
        "APT-K-47",
        "solana-backdoor",
        "vm_pageout.h",
        "Gh0stGambit",
        "tree.h",
        "Hundreds of fake Reddit sites push Lumma Stealer malware",
        "GKSavedGame.h",
        "ASAuthorizationPasswordProvider.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialRegistrationRequest.h",
        "https://www.forcepoint.com/blog/x-labs/phishing-script-inside-darkgate-campaign",
        "ASCredentialIdentityStoreState.h",
        "UAC-0194\u2019s Exploitation of CVE-2024-43451 in Ukraine for Phishing",
        "From Stealers to Ransomware PureCrypter Delivers It All",
        "zlib.h",
        "IOUSBHostCIDeviceStateMachine.h",
        "Admin.tbd",
        "ASAuthorizationPublicKeyCredentialLargeBlobRegistrationOutput.h",
        "EXTERN.h",
        "sbox32_hash.h",
        "vm_far.h",
        "thread.h",
        "ACR Stealer",
        "GCDevicePhysicalInputStateDiff.h",
        "Cloud Atlas seen using a new tool in its attacks",
        "WKContentRuleListStore.h",
        "https://www.crowdstrike.com/en-us/blog/stardust-chollima-likely-compromises-axios-npm-package/",
        "WKWebpagePreferences.h",
        "GKSavedGameListener.h",
        "GCDualSenseAdaptiveTrigger.h",
        "GameKit.h",
        "Glove-Stealer",
        "WKWebsiteDataStore.h",
        "IOUSBHostCIPortStateMachine.h",
        "ASAuthorizationRequest.h",
        "CloudScout_ Evasive Panda scouting cloud services",
        "Winos4.0 RAT",
        "OpenAL.tbd",
        "SystemBC RAT Poses New Risks to Linux System",
        "https://www.microsoft.com/en-us/security/blog/2024/05/15/threat-actors-misusing-quick-assist-in-social-engineering-attacks-leading-to-ransomware/",
        "vBasicOps.h",
        "string.h",
        "GCControllerInput.h",
        "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialAssertionRequest.h",
        "WKNavigationAction.h",
        "Shadowroot Ransomware",
        "ASAccountAuthenticationModificationController.h",
        "icmp_var.h",
        "_types.h",
        "ASAuthorizationWebBrowserExternallyAuthenticatableRequest.h",
        "av.h",
        "Python Malware in Zebo-0.1.0 and Cometlogger-0.1 Found Stealing User Data",
        "WKWindowFeatures.h",
        "crc.h",
        "ASPublicKeyCredential.h",
        "GKGameSession.h",
        "in_systm.h",
        "udp_var.h",
        "oalMacOSX_OALExtensions.h",
        "WebKit.tbd",
        "Chinese State-Sponsored RedDelta Targeted Taiwan, Mongolia, and Southeast Asia with Adapted PlugX Infection Chain",
        "GCMicroGamepad.h",
        "udp.h",
        "ASPasskeyCredentialRequest.h",
        "GCExtern.h",
        "Kerberos.h",
        "gssapi_generic.h",
        "opcode.h",
        "tcp_fsm.h",
        "GCSteeringWheelElement.h",
        "GameController.tbd",
        "uudmap.h",
        "GameKit.apinotes",
        "https://www.elastic.co/security-labs/grimresource",
        "ASAuthorizationPlatformPublicKeyCredentialProvider.h",
        "WKPreviewActionItemIdentifiers.h",
        "Salt Typhoon  Target U.S. Telecom Networks",
        "uconfig.h",
        "ASAuthorizationPlatformPublicKeyCredentialRegistration.h",
        "GKChallengeEventHandler.h",
        "IOUSBHostCIEndpointStateMachine.h",
        "GCEventViewController.h",
        "GCAxis2DInput.h",
        "pal_routines.h",
        "git_version.h",
        "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/",
        "embedvar.h",
        "https://www.elastic.co/security-labs/DPRK-strikes-using-a-new-variant-of-rustbucket",
        "IOBluetoothDeviceSelectorController.h",
        "vmparam.h",
        "stddef.h",
        "GCControllerElement.h",
        "Weaponized Software Targeting Chinese Organizations",
        "GCDirectionalGamepad.h",
        "vm_memtag.h",
        "ASCredentialProviderExtensionContext.h",
        "krb5.h",
        "GCExtendedGamepad.h",
        "ASAccountAuthenticationModificationRequest.h",
        "ASAuthorizationPublicKeyCredentialParameters.h",
        "ASAuthorizationProviderExtensionAuthorizationRequest.h",
        "regexp.h",
        "IOBluetoothUI.h",
        "The New Ransomware Menace Vgod Gains Momentum",
        "WKFoundation.h",
        "PyPI-AIOCPA",
        "Sock5Systemz-PROXY-AM",
        "GCAxisElement.h",
        "https://blog.nviso.eu/2026/04/03/the-axios-npm-supply-chain-incident-fake-dependency-real-backdoor/",
        "tcp_seq.h",
        "AsyncRAT Reloaded",
        "monotonic.h",
        "reg_help.h",
        "ASAuthorizationWebBrowserPlatformPublicKeyCredentialAssertionRequest.h",
        "WKFindConfiguration.h",
        "types.h",
        "ASWebAuthenticationSessionCallback.h",
        "SpyGlace",
        "IOBluetooth.h",
        "MultipeerConnectivity.apinotes",
        "cpuid_internal.h",
        "machine_machdep.h",
        "The great Google Ads heist_ criminals ransack advertiser accounts via fake Google ads",
        "icmp6.h",
        "https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections",
        "ASAuthorizationPublicKeyCredentialLargeBlobRegistrationInput.h",
        "zaphod32_hash.h",
        "LDAP.tbd",
        "The BadPilot campaign_ Seashell Blizzard subgroup conducts multiyear global access operation",
        "New Phishing Campaign Abuses Webflow, SEO, and Fake CAPTCHAs",
        "ASAuthorizationProvider.h",
        "IOPCIDevice.h",
        "malloc_ctl.h",
        "WKBackForwardListItem.h",
        "https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan",
        "Chrome Extensions Hijacked, 2.6 Million Users Impacted",
        "module.modulemap",
        "https://www.todyl.com/blog/threat-advisory-lightperlgirl-malware",
        "in_arp.h",
        "krpc.h",
        "WKUIDelegate.h",
        "IOBluetoothUtilities.h",
        "ASAuthorizationSingleSignOnRequest.h",
        "GKAccessPoint.h",
        "_OSByteOrder.h",
        "OSKextLib.h",
        "GCMotion.h",
        "https://blog.talosintelligence.com/axois-npm-supply-chain-incident/",
        "form.h",
        "https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/",
        "OSDebug.h",
        "TAG-100",
        "feature.h",
        "WKFindResult.h",
        "WKFrameInfo.h",
        "Astral Stealer Strikes Again Stealing More Than Just Your Cookies",
        "GKLeaderboardEntry.h",
        "Block.h",
        "ASAccountAuthenticationModificationViewController.h",
        "ASFoundation.h",
        "https://thehackernews.com/2023/07/beware-new-rustbucket-malware-variant.html",
        "ASAuthorizationAppleIDProvider.h",
        "uuid.h",
        "GKPlayer.h",
        "PXA Stealer",
        "Advanced Evasion Techniques Used by NonEuclid RAT",
        "GCDualSenseGamepad.h",
        "GKLeaderboardViewController.h",
        "IOUSBHostObject.h",
        "utfebcdic.h",
        "_param.h",
        "ASAuthorizationSingleSignOnProvider.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialProvider.h",
        "ASPasskeyCredentialRequestParameters.h",
        "GKPublicProtocols.h",
        "UNDRequest.defs",
        "IOUSBHostControllerInterfaceDefinitions.h",
        "lz4_constants.h",
        "copyio.h",
        "kdp_en_debugger.h",
        "profile.h",
        "Akira Ransomware",
        "DarkGate",
        "tcp.h",
        "Silent Skimmer Gets Loud (Again)",
        "GCControllerAxisInput.h",
        "Evasive Panda Uses MACMA and MgBot Malware to Target US and Taiwan",
        "perlapi.h",
        "apfs_boot_mount.tbd",
        "IOUSBHostPipe.h",
        "MCBrowserViewController.h",
        "limits.h",
        "bootp.h",
        "popen_spawn_win32.py",
        "stdint.h",
        "ebcdic_tables.h",
        "hv_macro.h",
        "ASAuthorizationAppleIDRequest.h",
        "memory_types.h",
        "gssapi.h",
        "https://www.cve.org/CVERecord?id=CVE-2024-26169",
        "_limits.h",
        "ASAuthorizationPublicKeyCredentialLargeBlobAssertionInput.h",
        "WKSnapshotConfiguration.h",
        "ASAuthorizationPublicKeyCredentialAssertion.h",
        "Helldown Ransomware",
        "capture_0.bundle.js",
        "GCGamepadSnapshot.h",
        "locks.h",
        "machine_kpc.h",
        "vm_options.h",
        "metaconfig.h",
        "GKNotificationBanner.h",
        "param.h",
        "InvisibleFerret Malware Leveraging Python for Targeted Attacks",
        "Phishing Campaigns Fuel Compiled AutoIt Malware Distribution",
        "LockBit Ransomware Attack Leveraging Cobalt Strike",
        "Fake Discount Sites Exploit Black Friday",
        "WKNavigationDelegate.h",
        "https://www.cve.org/CVERecord?id=CVE-2021-42278",
        "trap.h",
        "macOS Users Targeted by the New Variant of Banshee Infostealer",
        "INUIEditVoiceShortcutViewController.h",
        "U.S. Organization in China Targeted by Attackers",
        "kdp_callout.h",
        "opnames.h",
        "GameController.h",
        "ASAuthorizationPublicKeyCredentialRegistrationRequest.h",
        "mg_raw.h",
        "GCControllerDirectionPad.h",
        "WKPreferences.h",
        "INUIAddVoiceShortcutButton.h",
        "WKDataDetectorTypes.h",
        "io.h",
        "GKMatchmaker.h",
        "patchlevel.h",
        "North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware",
        "GCAxisInput.h",
        "Bumblebee Malware",
        "bitcount.h",
        "GCPhysicalInputProfile.h",
        "https://securelist.com/twelve-group-unified-kill-chain/113877/",
        "GKLeaderboard.h",
        "WKContextMenuElementInfo.h",
        "regnodes.h",
        "https://blog.qualys.com/vulnerabilities-threat-research/2023/04/03/3cxdesktopapp-backdoored-in-a-suspected-lazarus-campaign#iocs",
        "MCNearbyServiceBrowser.h",
        "nfs.h",
        "handy.h",
        "libkern.h",
        "perl_inc_macro.h",
        "vm_shared_region.h",
        "SmokeLoader",
        "FERRET Malware Targets macOS in Sophisticated North Korean Attacks",
        "igmp_var.h",
        "tcp_var.h",
        "l1_char_class_tab.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialAssertionRequest.h",
        "mg_vtable.h",
        "AdID.tbd",
        "Espionage Campaign Targeting South Asian Entities",
        "ASAuthorizationPlatformPublicKeyCredentialDescriptor.h",
        "https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn",
        "babbleloader",
        "https://socradar.io/blog/axios-npm-supply-chain-attack-2026-ciso-guide/",
        "GKAchievementDescription.h",
        "Rockstar-Phishing",
        "GCRelativeInput.h",
        "New Star Blizzard spear-phishing campaign targets WhatsApp accounts",
        "desc.h",
        "ASAuthorizationWebBrowserPlatformPublicKeyCredentialRegistrationRequest.h",
        "AuthenticationServices.apinotes",
        "https://blog.qualys.com/vulnerabilities-threat-research/2024/09/19/black-basta-ransomware-what-you-need-to-know",
        "byte_order.h",
        "ASAuthorizationPasswordRequest.h",
        "vecLib.h",
        "python-3.9.pc",
        "IOUSBHostStream.h",
        "NOOPDOOR Malware",
        "ASAuthorizationPublicKeyCredentialConstants.h",
        "gssapi_krb5.h",
        "https://blog.sekoia.io/mallox-ransomware-affiliate-leverages-purecrypter-in-microsoft-sql-exploitation-campaigns/#h-focus-vampire.",
        "ASAuthorizationPlatformPublicKeyCredentialAssertionRequest.h",
        "GCRacingWheelInput.h",
        "GCDevice.h",
        "https://www.cve.org/CVERecord?id=CVE-2022-30190",
        "WebKitLegacy.h",
        "ASAuthorizationCredential.h",
        "GCController.h",
        "atomic.h",
        "python3-embed.pc",
        "atm_types.h",
        "https://www.fortinet.com/blog/threat-research/ransomware-roundup-black-basta",
        "AFKUser.tbd",
        "Visual Studio Code Remote tunnels",
        "Remcos RAT",
        "HotPage.exe (malware)",
        "GKAchievementViewController.h",
        "vutil.h",
        "IOPCIFamilyDefinitions.h",
        "ASSettingsHelper.h",
        "if_ether.h",
        "vm_kern.h",
        "AuthenticationServices.h",
        "https://www.zscaler.com/blogs/security-research/supply-chain-attacks-surge-march-2026",
        "GKScore.h",
        "GKTurnBasedMatch.h",
        "KUNCUserNotifications.h",
        "WKPreviewElementInfo.h",
        "OSTypes.h",
        "ASAuthorizationPlatformPublicKeyCredentialRegistrationRequest.h",
        "MCPeerID.h",
        "tss.h",
        "WKScriptMessage.h",
        "WezRat Malware",
        "PCIDriverKit.h",
        "https://www.elastic.co/security-labs/dismantling-smart-app-control",
        "ASPasswordCredentialRequest.h",
        "Avast-Anti-Root-KIt",
        "mydtrace.h",
        "cpu.h",
        "https://blog.qualys.com/vulnerabilities-threat-research/2024/10/02/threat-brief-understanding-akira-ransomware",
        "INTERN.h",
        "GCGearShifterElement.h",
        "https://www.cve.org/CVERecord?id=CVE-2021-34527",
        "UNDReply.defs",
        "ASCredentialIdentityStore.h",
        "GCXboxGamepad.h",
        "com_err.h",
        "OpenAL.h",
        "LegionLoader Malware Expands Global Reach",
        "https://www.cybereason.com/blog/threat-alert-aggressive-qakbot-campaign-and-the-black-basta-ransomware-group-targeting-u.s.-companies",
        "MCSession.h",
        "TargetConditionals.h",
        "GamaCopy APT Group Mimicking GamaRedon",
        "IOBluetoothServiceBrowserController.h",
        "GKBasePlayer.h",
        "GCInputNames.h",
        "IOBluetoothUserLib.h",
        "WKBackForwardList.h",
        "IntentsUI.h",
        "Qilin Ransomware",
        "GCDeviceHaptics.h",
        "WKDownload.h",
        "machine_routines.h",
        "asm_help.h",
        "Bootkitty",
        "cpuid.h",
        "WKScriptMessageHandlerWithReply.h",
        "https://socket.dev/blog/axios-npm-package-compromised",
        "endian.h",
        "stdarg.h",
        "ASCredentialProviderViewController.h",
        "ASAuthorizationSingleSignOnCredential.h",
        "The Growing Risk of Sneaky 2FA for Microsoft and Gmail Accounts",
        "GKPublicConstants.h",
        "math.h",
        "GCDeviceLight.h",
        "ASAuthorizationController.h",
        "python3.pc",
        "https://www.elastic.co/security-labs/katz-and-mouse-game",
        "arch.h",
        "GCDevicePhysicalInput.h"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "Lazarus"
          ],
          "malware_families": [
            "Ld.py",
            "Golangghost",
            "Plain-crypto-js",
            "Wt.exe",
            "Com.apple.act.mond",
            "Frostyferret"
          ],
          "industries": [
            "Finance",
            "Technology"
          ]
        },
        "other": {
          "adversary": [
            "El Machete, TAG-100, Mirage, Unamed_Grooup",
            "Mallox",
            "Black Basta",
            "El Machete",
            "FIN7",
            "Threat",
            "Lazarus",
            "Turla Group, FIN7, APT34, APT28, DragonForce Malaysia Hacker Group, Indonesia Islamic Warriors Counc"
          ],
          "malware_families": [
            "Qbot",
            "Vant",
            "Backdoor:win64/cobaltstrike",
            "Sugarloader",
            "Ransom:win32/basta",
            "Findertools",
            "Behavior:win32/qakbot",
            "Trojan:win64/turtleloader.cs",
            "Conti",
            "Netsupport",
            "Security research",
            "Internet",
            "Trojanspy",
            "Black basta",
            "Wiper",
            "Xollam",
            "Trojandownloader:o97m/qakbot",
            "Basta linux",
            "Cobalt strike",
            "Widespread qbot",
            "Trojanspy:win32/qakbot",
            "Huinder",
            "Behavior:win32/systembc",
            "Trojan: win32/systembc",
            "Janicab",
            "Osreturn",
            "Invisibleferret",
            "Fig.1",
            "Spelevo",
            "Table.4 info",
            "Mallox",
            "Primary netsupport",
            "Icedid",
            "Sqlshell",
            "Trojandropper:powershell/cobacis",
            "Iceid",
            "Roadsweep",
            "Mekotio banking",
            "Ref9135",
            "Clr sqlshell",
            "Rustbucket",
            "Osatomic",
            "Hacktool:win64/cobaltstrike",
            "Behavior:win32/cobaltstrike",
            "Domains",
            "Purerat",
            "Ver",
            "Lightperlgirl",
            "Lumma",
            "Msi",
            "Trojan:win32/basta",
            "Exploit:win32/shellcode.bn",
            "Macos",
            "Trigona",
            "Trojan:win32/qbot",
            "Behavior:win32/basta",
            "Lazarus",
            "Pumakit",
            "Qakbot",
            "Dprk",
            "Trojan:win32/qakbot"
          ],
          "industries": [
            "Media",
            "Emergency services",
            "Transportation",
            "Finance",
            "Manufacturing",
            "Cryptocurrency",
            "Hotel",
            "Banking",
            "Legal",
            "Technology",
            "Construction",
            "Hospitality",
            "Government",
            "Critical infrastructure",
            "Retail",
            "Healthcare"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 46,
  "pulses": [
    {
      "id": "69d4e63921cbadb426b7cd2a",
      "name": "Detections for the Axios supply chain compromise",
      "description": "A supply chain attack targeting Axios npm package versions 1.14.1 and 0.30.4 introduced a malicious transitive dependency (plain-crypto-js@4.2.1) that executed during installation. The attack deploys cross-platform payloads across Linux, Windows, and macOS through a consistent pattern: Node.js spawns OS-native shells to retrieve and execute remote payloads in detached or hidden contexts. Linux victims receive a Python-based RAT, Windows systems get a PowerShell backdoor with registry persistence, and macOS hosts are compromised with a Mach-O binary backdoor. All variants beacon to the same C2 infrastructure, performing host fingerprinting, process enumeration, filesystem reconnaissance, and arbitrary code execution. The malicious activity is reliably detected through behavioral signatures focusing on unusual Node.js process ancestry and remote payload retrieval rather than static indicators.",
      "modified": "2026-05-07T11:10:38.058000",
      "created": "2026-04-07T11:10:49.715000",
      "tags": [
        "supply chain attack",
        "post-install execution",
        "axios"
      ],
      "references": [
        "https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "plain-crypto-js",
          "display_name": "plain-crypto-js",
          "target": null
        },
        {
          "id": "ld.py",
          "display_name": "ld.py",
          "target": null
        },
        {
          "id": "wt.exe",
          "display_name": "wt.exe",
          "target": null
        },
        {
          "id": "com.apple.act.mond",
          "display_name": "com.apple.act.mond",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1132.001",
          "name": "Standard Encoding",
          "display_name": "T1132.001 - Standard Encoding"
        },
        {
          "id": "T1036.005",
          "name": "Match Legitimate Name or Location",
          "display_name": "T1036.005 - Match Legitimate Name or Location"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1059.004",
          "name": "Unix Shell",
          "display_name": "T1059.004 - Unix Shell"
        },
        {
          "id": "T1055.012",
          "name": "Process Hollowing",
          "display_name": "T1055.012 - Process Hollowing"
        },
        {
          "id": "T1195.002",
          "name": "Compromise Software Supply Chain",
          "display_name": "T1195.002 - Compromise Software Supply Chain"
        },
        {
          "id": "T1027.003",
          "name": "Steganography",
          "display_name": "T1027.003 - Steganography"
        },
        {
          "id": "T1518.001",
          "name": "Security Software Discovery",
          "display_name": "T1518.001 - Security Software Discovery"
        },
        {
          "id": "T1543.001",
          "name": "Launch Agent",
          "display_name": "T1543.001 - Launch Agent"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1124",
          "name": "System Time Discovery",
          "display_name": "T1124 - System Time Discovery"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6,
        "FileHash-SHA256": 7,
        "URL": 1,
        "domain": 2,
        "hostname": 1
      },
      "indicator_count": 23,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386492,
      "modified_text": "23 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67ebff51da5765b1e4d9509e",
      "name": "From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic",
      "description": "Lazarus, a North Korean state-sponsored threat actor, has launched a new campaign called ClickFake Interview targeting cryptocurrency job seekers. This campaign, an evolution of the previously documented Contagious Interview, uses fake job interview websites to deploy the GolangGhost backdoor on Windows and macOS systems. The infection chain leverages the ClickFix tactic, downloading and executing malicious payloads during the interview process. The campaign primarily targets centralized finance (CeFi) entities, aligning with Lazarus' focus on cryptocurrency-related targets. Notable changes include targeting non-technical roles and using ReactJS-based websites for the fake interviews. The malware provides remote control and data theft capabilities, including browser information exfiltration.",
      "modified": "2025-05-01T14:02:57.427000",
      "created": "2025-04-01T14:59:29.783000",
      "tags": [
        "clickfix",
        "north korea",
        "golangghost",
        "cryptocurrency",
        "frostyferret",
        "backdoor",
        "job interviews",
        "cefi"
      ],
      "references": [
        "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "GolangGhost",
          "display_name": "GolangGhost",
          "target": null
        },
        {
          "id": "FrostyFerret",
          "display_name": "FrostyFerret",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        }
      ],
      "industries": [
        "Finance",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 58,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 7,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 12,
        "URL": 7,
        "YARA": 9,
        "domain": 40,
        "hostname": 24
      },
      "indicator_count": 100,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386492,
      "modified_text": "394 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ce83659fb527eb96c998a2",
      "name": "Malicious Axios Packages Published to npm in New Supply Chain Compromise",
      "description": "A recent supply chain compromise has been identified affecting the widely utilized JavaScript HTTP client axios, wherein malicious versions of the package were published to npm using compromised maintainer credentials. The exploitation involves the deployment of a Remote Access Trojan (RAT) through a fabricated dependency labeled plain-crypto-js@4.2.1. Notably, this dependency is not directly imported by axios, functioning instead as a dropper that executes a postinstall script upon installation.",
      "modified": "2026-05-04T15:01:49.491000",
      "created": "2026-04-02T14:55:33.872000",
      "tags": [
        "truesec",
        "post body",
        "temp",
        "cicd",
        "rotate npm",
        "monitor",
        "npm supplychain",
        "risk detection",
        "urls",
        "network",
        "remote access"
      ],
      "references": [
        "https://www.truesec.com/hub/blog/malicious-axios-packages-npm-in-supply-chain-compromise",
        "https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan",
        "https://www.derp.ca/research/axios-npm-supply-chain-rat/",
        "https://socket.dev/blog/axios-npm-package-compromised",
        "https://socradar.io/blog/axios-npm-supply-chain-attack-2026-ciso-guide/",
        "https://www.malwarebytes.com/blog/news/2026/03/axios-supply-chain-attack-chops-away-at-npm-trust",
        "https://www.elastic.co/security-labs/axios-supply-chain-compromise-detections",
        "https://www.crowdstrike.com/en-us/blog/stardust-chollima-likely-compromises-axios-npm-package/",
        "https://blog.nviso.eu/2026/04/03/the-axios-npm-supply-chain-incident-fake-dependency-real-backdoor/",
        "https://hunt.io/blog/axios-supply-chain-attack-ta444-bluenoroff",
        "https://www.zscaler.com/blogs/security-research/supply-chain-attacks-surge-march-2026",
        "https://blog.talosintelligence.com/axois-npm-supply-chain-incident/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1070.004",
          "name": "File Deletion",
          "display_name": "T1070.004 - File Deletion"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1195.001",
          "name": "Compromise Software Dependencies and Development Tools",
          "display_name": "T1195.001 - Compromise Software Dependencies and Development Tools"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 58,
        "FileHash-SHA1": 62,
        "FileHash-SHA256": 60,
        "URL": 28,
        "domain": 19,
        "email": 5,
        "hostname": 10,
        "CIDR": 2,
        "CVE": 2
      },
      "indicator_count": 246,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 544,
      "modified_text": "26 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69665d5c109a09813bce8749",
      "name": "Booking.com Phishing Campaign Targeting Hotels and Customers - Sekoia.io Blog",
      "description": "A new report from cybersecurity firm Sekoia.io examines a sophisticated phishing campaign targeting Booking.com and its customers around the world, as well as the impact of infostealing malware.",
      "modified": "2026-02-12T14:01:38.116000",
      "created": "2026-01-13T14:57:32.880000",
      "tags": [
        "purerat",
        "clickfix",
        "booking",
        "powershell",
        "zip archive",
        "run registry",
        "october",
        "sekoia soc",
        "ip address",
        "c2 server",
        "facebook",
        "malicious",
        "april",
        "date",
        "refresh",
        "quirkyloader",
        "purecrypter",
        "twitter",
        "cluster",
        "clearfake",
        "malware",
        "threat"
      ],
      "references": [
        "https://blog.sekoia.io/phishing-campaigns-i-paid-twice-targeting-booking-com-hotels-and-customers/"
      ],
      "public": 1,
      "adversary": "Threat",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "PureRAT",
          "display_name": "PureRAT",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1078",
          "name": "Valid Accounts",
          "display_name": "T1078 - Valid Accounts"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [
        "Hospitality",
        "Hotel",
        "Banking"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 5,
        "FileHash-SHA1": 4,
        "FileHash-SHA256": 4,
        "URL": 28,
        "domain": 70,
        "hostname": 2
      },
      "indicator_count": 113,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "107 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "685504a184b712521ffeb975",
      "name": "Threat Advisory: LightPerlGirl Malware",
      "description": "The malware campaign centered around a threat actor utilizing a fake CAPTCHA popup dubbed ClickFix, which deceives users into executing malicious PowerShell commands. This initial compromise occurs when a user visits a compromised WordPress site that serves a JavaScript payload, mimicking a legitimate security check. The malicious dialog prompts the user to engage with a PowerShell command, which is obfuscated to evade detection. This command reaches out to a command-and-control (C2) server at cmbkz8kz1000108k2carjewzf.info and initiates a multi-stage infection process.",
      "modified": "2025-07-20T06:03:58.975000",
      "created": "2025-06-20T06:50:09.809000",
      "tags": [
        "todyl",
        "strong",
        "powershell",
        "c2 server",
        "urex",
        "exwpl",
        "helpio",
        "lightperlgirl",
        "runas",
        "ascii",
        "execution",
        "next",
        "info",
        "attack",
        "defender",
        "path",
        "main",
        "never",
        "hunt",
        "contact"
      ],
      "references": [
        "https://www.todyl.com/blog/threat-advisory-lightperlgirl-malware"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "LightPerlGirl",
          "display_name": "LightPerlGirl",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1059.003",
          "name": "Windows Command Shell",
          "display_name": "T1059.003 - Windows Command Shell"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1218.012",
          "name": "Verclsid",
          "display_name": "T1218.012 - Verclsid"
        },
        {
          "id": "T1547.001",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1547.001 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1548.002",
          "name": "Bypass User Account Control",
          "display_name": "T1548.002 - Bypass User Account Control"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CIDR": 3,
        "URL": 25,
        "domain": 3,
        "hostname": 8
      },
      "indicator_count": 39,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 539,
      "modified_text": "315 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "684124ef2e8badb3e5395e43",
      "name": "Windows Defender Exclusions Added via PowerShell | Detection Rules Overview",
      "description": "The full text of this year's EU Referendum, which will take place on 26 November, has been published.. and it will not appear on BBC Radio 5 live or on iPlayer.",
      "modified": "2025-06-05T05:02:39.006000",
      "created": "2025-06-05T05:02:39.006000",
      "tags": [
        "logstash",
        "create",
        "kubernetes",
        "kibana",
        "elastic agent",
        "system",
        "google cloud",
        "filebeat",
        "elasticsearch",
        "agent",
        "error",
        "span",
        "project",
        "general",
        "powershell",
        "upgrade",
        "apache",
        "cloud",
        "curator",
        "icmp",
        "service",
        "monitoring",
        "install",
        "prometheus",
        "watcher",
        "date",
        "rest",
        "scroll",
        "hosts",
        "collector",
        "local",
        "benchmark",
        "graphite",
        "legacy",
        "tips",
        "codec",
        "defender",
        "spaces",
        "korean",
        "frozen",
        "score",
        "observer",
        "multi",
        "matrix",
        "trickbot",
        "virustotal",
        "false",
        "stop",
        "stack",
        "ms windows",
        "intel",
        "pe32",
        "pe32 executable"
      ],
      "references": [
        "https://www.elastic.co/guide/en/security/current/windows-defender-exclusions-added-via-powershell.html"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 4,
        "hostname": 17,
        "URL": 29,
        "FileHash-SHA256": 161,
        "FileHash-MD5": 107,
        "FileHash-SHA1": 105
      },
      "indicator_count": 423,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "360 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67f861c5c9347add1cf1889f",
      "name": "Lazarus ClickFake Interview Campaign: From Contagious to ClickFix Malware Tactics",
      "description": "In March 2025, cybersecurity analysts observed that the North Korean state-sponsored group Lazarus initiated a sub-campaign named \"ClickFake Interview,\" evolving from their earlier \"Contagious Interview\" operations. This campaign involves contacting individuals via social media, inviting them to fake job interviews on counterfeit cryptocurrency-related websites. During these interviews, users encounter fabricated technical issues prompting them to download malicious software, which subsequently installs backdoors on both Windows and macOS systems. This strategy allows Lazarus to gain unauthorized access to victims' devices, posing significant security risks. \ue200cite\ue202turn0search0\ue201\ue206",
      "modified": "2025-05-11T00:01:34.348000",
      "created": "2025-04-11T00:26:45.507000",
      "tags": [
        "lazarus",
        "windows",
        "golangghost",
        "cefi",
        "sekoia",
        "frostyferret",
        "clickfix tactic",
        "temp",
        "march",
        "dprk",
        "invisibleferret",
        "terminal",
        "macos",
        "sharpknot",
        "manuscrypt",
        "bluenoroff",
        "february",
        "beavertail",
        "path",
        "kraken",
        "robinhood"
      ],
      "references": [
        "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/#h-iocs-and-technical-details"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Armature_TIP",
        "id": "308911",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_308911/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 7,
        "FileHash-MD5": 10,
        "FileHash-SHA1": 4,
        "FileHash-SHA256": 14,
        "YARA": 9,
        "domain": 40,
        "hostname": 25
      },
      "indicator_count": 109,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 43,
      "modified_text": "385 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67f33233092ab19b74879403",
      "name": "MacOS M2 Chip Infiltration: Game Center & XBOX Pod Game & Chat Server",
      "description": "pulse explores a variety of files, objects, and functions that could be associated with different system components, libraries, and protocols. It highlights a wide range of potential vulnerabilities that may exist in software related to system functions, APIs, data handling, and device interactions, including issues in devices like game controllers, HID devices, and platform-specific services (such as Apple and Android). The pulse references several components across different platforms (macOS, iOS, ARM architectures, and others), with a focus on low-level code, encryption libraries, system utilities, and network protocols like TCP, IP, and Bluetooth. The identified vulnerabilities could involve buffer overflows, deprecated functions, improper memory handling, and potential exploit vectors related to system security, performance, and integrity.",
      "modified": "2025-05-07T02:03:20.735000",
      "created": "2025-04-07T02:02:27.322000",
      "tags": [
        "helper macro",
        "param",
        "param inccache",
        "kerberos",
        "ccache",
        "api function",
        "ccapi",
        "api version",
        "param ioccache",
        "ccacheserver",
        "win32",
        "null",
        "code",
        "win64",
        "error",
        "union",
        "ccapideprecated",
        "ccacheapi",
        "ccapiv2h",
        "apple",
        "export",
        "united",
        "ccache api",
        "cplusplus",
        "x8664",
        "typedef",
        "patheq",
        "none",
        "popen",
        "terminate",
        "false",
        "winenv",
        "winexe",
        "frozen",
        "winservice",
        "python",
        "posixthreads",
        "pyhavecondvar",
        "ntthreads",
        "vista",
        "pyemulatedwincv",
        "ntddivista",
        "semaphore",
        "pycondt",
        "win7",
        "pybuildcore",
        "fall",
        "copyright",
        "technology",
        "all rights",
        "reserved",
        "america",
        "government",
        "within that",
        "klprincipal",
        "klloginoptions",
        "inpassword",
        "klboolean",
        "klindex inindex",
        "login",
        "klstatus",
        "kerberos login",
        "inst",
        "regexp",
        "typeof e",
        "function",
        "typeof t",
        "typeof o",
        "width",
        "typeof",
        "pseudo",
        "body",
        "sticky",
        "date",
        "class",
        "this",
        "void",
        "accept",
        "span",
        "krb5callconv",
        "apoptsreserved",
        "tktflgreserved",
        "kdcoptreserved",
        "krb5data",
        "eblock",
        "krb5address",
        "krb5keyblock",
        "service",
        "realm",
        "format",
        "general",
        "internal",
        "entropy",
        "mask",
        "mcpeerid",
        "mcsession",
        "property",
        "protocol",
        "create",
        "nsuinteger",
        "notifies",
        "mcsession api",
        "interface",
        "bonjour",
        "ascii lowercase",
        "abc company",
        "section",
        "bonjour txt",
        "mcextern",
        "attribute",
        "mcextern extern",
        "mcexternweak",
        "nsenum",
        "nsinteger",
        "mcerrorcode",
        "mcerrorunknown",
        "mcerrortimedout",
        "bonjour apis",
        "stop",
        "peer",
        "example",
        "tags",
        "session",
        "nsprogress",
        "nserror",
        "nsstring",
        "nsurl",
        "nsarray",
        "note",
        "ui element",
        "utf8 encoding",
        "nscopying",
        "nsdictionary",
        "webpackrequire",
        "webpackexports",
        "object",
        "adobe systems",
        "adobe",
        "incorporated",
        "dissemination",
        "touchmove",
        "window",
        "launch",
        "close",
        "core",
        "webview",
        "nwebpackrequire",
        "arraybuffer",
        "name",
        "typedarray",
        "prototype",
        "string",
        "number",
        "nvar",
        "meta",
        "infinity",
        "generator",
        "zero",
        "epsilon",
        "observer",
        "android",
        "freeze",
        "trim",
        "canvas",
        "simple",
        "bind",
        "fast",
        "next",
        "patch",
        "rest",
        "middle",
        "find",
        "enumerate",
        "facebook",
        "executor",
        "apiunavailable",
        "gamecontroller",
        "gcbuttoninput",
        "gcswitchinput",
        "nsobject",
        "apiavailable",
        "hid device",
        "cfstr",
        "iohiddeviceref",
        "boolean value",
        "c iohidmanager",
        "iohidmanager",
        "c iohiddevice",
        "issequential",
        "bool sequential",
        "bool canwrap",
        "nsset",
        "nsunavailable",
        "gcswitchelement",
        "bool",
        "share button",
        "xbox controller",
        "xbox elite",
        "xbox series",
        "gcxboxgamepad",
        "gcpoint2",
        "gcpoint2make",
        "gcpoint2 p",
        "cfinline bool",
        "gcpoint2equal",
        "gcpoint2 point1",
        "gcpoint2 point2",
        "gcrelativeinput",
        "isanalog",
        "bool analog",
        "hasinclude",
        "gcaxis2dinput",
        "gcpoint2 value",
        "gcaxiselement",
        "certain",
        "gcaxisinput",
        "gcbuttonelement",
        "gccontroller",
        "nsnotification",
        "chhapticengine",
        "gcmicrogamepad",
        "input",
        "menu button",
        "gcdevicelight",
        "gccolor",
        "x axis",
        "xvalue",
        "developers",
        "functionality",
        "options button",
        "sf symbols",
        "elements",
        "gcdevice",
        "gctouchstate",
        "gctouchstateup",
        "apideprecated",
        "gckeyboard",
        "gcmouse",
        "nsswiftname",
        "gcdevicebattery",
        "battery level",
        "direction pad",
        "directionapad",
        "thumbstick",
        "gcdevicecursor",
        "a controller",
        "gccolor color",
        "gcinputbuttona",
        "gcinputbuttonb",
        "button b",
        "check",
        "a element",
        "c nil",
        "nsenumerator",
        "siri remote",
        "equivalent",
        "down",
        "left",
        "right",
        "kindof",
        "handle button",
        "c device",
        "immediate input",
        "dualsense",
        "positional",
        "sony dualsense",
        "gcmotion",
        "dualshock",
        "uievent",
        "controllers",
        "uikit user",
        "uiview",
        "method",
        "nsdata",
        "axes",
        "nsdata source",
        "return",
        "nullable",
        "nsdata object",
        "button",
        "shoulder",
        "extended",
        "gamepad profile",
        "nsdata api",
        "gcgamepad",
        "sizeof",
        "standard",
        "gckeyboardinput",
        "keyboard",
        "nsstring const",
        "controller",
        "back buttons",
        "game controller",
        "back",
        "keypad",
        "delete",
        "insert",
        "home",
        "right arrow",
        "left arrow",
        "down arrow",
        "up arrow",
        "korean",
        "backspace",
        "alongside",
        "gckeyuparrow",
        "gckeycode const",
        "lang1",
        "gclinearinput",
        "gcquaternion",
        "gcacceleration",
        "y axis",
        "z axis",
        "gcmouse mouse",
        "gcmouse class",
        "mice",
        "gcmouseinput",
        "mouse profile",
        "scroll",
        "nsdata instance",
        "a alias",
        "press",
        "micro profile",
        "siri remotes",
        "b button",
        "a gcinput",
        "button a",
        "nsoptions",
        "examining",
        "c sfsymbolsname",
        "apple tv",
        "remote",
        "control center",
        "a set",
        "game",
        "gcracingwheel",
        "gcbundlewithpid",
        "gcinputbuttonx",
        "gcinputbuttony",
        "gcinputshifter",
        "gckeya",
        "gckeyb",
        "gckeybackslash",
        "rawvalue",
        "apple swift",
        "o librarylevel",
        "swift import",
        "element",
        "indices",
        "iterator",
        "subsequence",
        "kerberoscomerr",
        "const",
        "permission",
        "mit software",
        "suitability",
        "athena",
        "openvision",
        "gssdllimp",
        "gssapigenerich",
        "this software",
        "purpose",
        "disclaims all",
        "warranties with",
        "regard to",
        "constraint",
        "kerberosprofile",
        "krb5profileh",
        "const names",
        "newvalue",
        "1429577728l",
        "gnuc",
        "mach",
        "omuint32",
        "gssapikrb5h",
        "form",
        "uid form",
        "client function",
        "asrep",
        "including",
        "preauth",
        "db entry",
        "free",
        "pointer",
        "rock",
        "neither",
        "direct",
        "damage",
        "minorstatus",
        "gssbuffert",
        "gssctxidt",
        "gssoid",
        "gssnamet",
        "gsscredidt",
        "gssoidset",
        "gssapi",
        "first",
        "alcapi",
        "alcapientry",
        "alcboolean",
        "targetosmac",
        "alcdevice",
        "alcenum param",
        "alalch",
        "alcchar",
        "alcsizei",
        "capture",
        "but not",
        "limited",
        "openal cross",
        "apple computer",
        "redistribution",
        "is provided",
        "type",
        "alvoid",
        "alint",
        "openal",
        "aluint sid",
        "alenum",
        "alint value",
        "aluint property",
        "alvoid nonnull",
        "alfloat",
        "write",
        "openalopenalh",
        "umbrella header",
        "alenum param",
        "alapi",
        "aluint bid",
        "alsizei",
        "alfloat value",
        "alapientry",
        "aluint",
        "verify",
        "play",
        "speed",
        "bits",
        "albuffer3i",
        "albufferdata",
        "albufferf",
        "albufferfv",
        "albufferi",
        "albufferiv",
        "aldistancemodel",
        "aldopplerfactor",
        "algetbooleanv",
        "algetbuffer3f",
        "iousbhostdevice",
        "iousbhostobject",
        "iousbhostpipe",
        "iousbhoststream",
        "iousbhost",
        "brief",
        "usb host",
        "bool yes",
        "bool no",
        "advance",
        "iousbhostfamily",
        "kernel",
        "ioreturn status",
        "nsnumber",
        "ioreturn error",
        "usb device",
        "select",
        "commands",
        "enqueue",
        "nsmutabledata",
        "field",
        "enum",
        "options",
        "retrieve",
        "iosource",
        "current address",
        "bos descriptor",
        "extract",
        "a descriptor",
        "license",
        "io request",
        "abort",
        "discussion",
        "stream",
        "please",
        "swift api",
        "iousbbitrange",
        "iousbbitrange64",
        "iousbbit",
        "client",
        "usb controller",
        "usb descriptor",
        "unknown",
        "critical",
        "refer",
        "link",
        "send",
        "same",
        "common ui",
        "bluetooth",
        "service browser",
        "option",
        "1001",
        "cfstringref",
        "deprecated",
        "macos",
        "returns",
        "abstract",
        "nswindow",
        "creates",
        "mac os",
        "uuids",
        "uuid",
        "sdp service",
        "nsimage",
        "nsview",
        "mpasskeystring",
        "nsmutablearray",
        "uuid array",
        "ioreturn",
        "runmodal",
        "group",
        "command",
        "byte",
        "masks",
        "pduid",
        "l2cap",
        "range",
        "opcode",
        "packet",
        "major",
        "local",
        "profiles",
        "iobluetooth",
        "framework",
        "support",
        "host controller",
        "rfcomm",
        "minor class",
        "pseudoclass",
        "specific device",
        "headset",
        "peripheral",
        "desktop",
        "glasses",
        "device reset",
        "no hci",
        "hci controller",
        "returns number",
        "variable number",
        "packdata",
        "cstring",
        "pass",
        "path",
        "deprecated in",
        "obex session",
        "obexsessionref",
        "rfcomm channel",
        "obex",
        "does not",
        "l2cap channel",
        "inrefcon",
        "device",
        "length",
        "obex spec",
        "error code",
        "make",
        "headerid",
        "april",
        "alarm",
        "avrcplog",
        "audiolog",
        "bccmd16touint16",
        "bccmd16touint8",
        "bccmd32touint32",
        "hfplog",
        "obexcreatevcard",
        "obexsessionget",
        "uint16tobccmd16",
        "intents",
        "created",
        "andrea gottardo",
        "inimage",
        "intentsui",
        "project version",
        "inshortcut",
        "ibdesignable",
        "invoiceshortcut",
        "nsbundle",
        "siri",
        "beralloct",
        "berbvarrayadd",
        "berbvarrayfree",
        "berbvdup",
        "berbvecadd",
        "berbvecfree",
        "berbvfree",
        "berdump",
        "berdup",
        "berdupbv",
        "ldap",
        "vdspinput1",
        "vectorsize",
        "iirchannel",
        "osvkerndsplib",
        "pragmaonce",
        "paul chang",
        "fri mar",
        "original code",
        "apple operating",
        "modifications",
        "apple public",
        "source license",
        "version",
        "lframesize",
        "i386",
        "picify",
        "callmcount",
        "nonlazystub",
        "align",
        "roundtostack",
        "leaf",
        "import",
        "carnegie mellon",
        "carnegie",
        "inline void",
        "software",
        "school",
        "august",
        "xnuarchi386selh",
        "next computer",
        "mike demoney",
        "bruce martin",
        "state segment",
        "nxswappedfloat",
        "osswapint32",
        "inline float",
        "inline double",
        "osswapint64",
        "armlimitsh",
        "arm64",
        "useclangtypes",
        "bsdarmtypesh",
        "int8t",
        "gnuc typedef",
        "uint8t",
        "ansi c",
        "ansi",
        "use wchart",
        "armmcontexth",
        "mcontextt",
        "armparamh",
        "round",
        "darwinsizet",
        "darwinalign",
        "uint32t",
        "darwinalign32",
        "warranties",
        "a particular",
        "university",
        "armarch6zk",
        "armarch6k",
        "armarch4t",
        "armarch4",
        "http",
        "capbitnb",
        "legacy",
        "armfeatureflag",
        "california",
        "notice",
        "berkeley",
        "limited to",
        "define",
        "useclanglimits",
        "lp64",
        "ansisource",
        "darwincsource",
        "longmin",
        "ulongmax",
        "parameter",
        "vmmemcoherent",
        "vmmemearlyack",
        "vmmeminner",
        "vmmemrt",
        "vmmemguarded",
        "armmemorytypesh",
        "armpalroutinesh",
        "read",
        "struct",
        "booleant",
        "cluster",
        "devbsize",
        "mclbytes",
        "unix system",
        "laboratories",
        "devbshift",
        "thumb",
        "armv5",
        "armv7",
        "cache",
        "neon",
        "swift",
        "bsdarmprofileh",
        "xxx todo",
        "block",
        "mcount",
        "mcountinit",
        "mcountenter",
        "splhigh",
        "armthreadh",
        "armtraph",
        "dflssiz",
        "targetososx",
        "maxssiz",
        "rliminfinity",
        "maxcsiz",
        "bsdarmvmparamh",
        "dfldsiz",
        "maxdsiz",
        "xxx stack",
        "armsignal",
        "int64t",
        "armmachtypesh",
        "int32t",
        "methods",
        "thread",
        "hasapplepac",
        "atmatmtypesh",
        "libkernlocksh",
        "fortifysource",
        "libkerncopyioh",
        "sizedby",
        "darwinosinline",
        "stdcversion",
        "osswapint16",
        "libkerncrch",
        "blockexport",
        "vaargs",
        "blockrelease",
        "blockh",
        "collection",
        "blockcopy",
        "ososbaseh",
        "base",
        "byteoffset",
        "host endianess",
        "generic host",
        "generic",
        "osmalloc",
        "osmalloctag tag",
        "osmalloctag",
        "pci device",
        "uint32",
        "uint32 mask",
        "safecastptr",
        "sint32",
        "osaddatomic64",
        "uint8",
        "libkern c",
        "internal error",
        "core osreturn",
        "libkern",
        "values",
        "pragmamark",
        "kexts",
        "kext",
        "c string",
        "grab",
        "osostypesh",
        "boolean",
        "unsignedwide",
        "uint32 hi",
        "buildtime value",
        "libkernversionh",
        "versionmajor",
        "versionminor",
        "versionvariant",
        "versionrevision",
        "ostype",
        "osrelease",
        "libkernsysctlh",
        "instructions",
        "data cache",
        "future",
        "rbleft",
        "rbright",
        "rbgetparent",
        "splayright",
        "splayleft",
        "rbsetcolor",
        "rbblack",
        "rbgetcolor",
        "comp",
        "main",
        "stdc",
        "msdos",
        "windows",
        "sys16bit",
        "zlibdll",
        "zextern",
        "zconfh",
        "model",
        "zextern int",
        "zstreamerror",
        "znull",
        "zbuferror",
        "zmemerror",
        "zstreamend",
        "zdataerror",
        "zfinish",
        "enough",
        "possible",
        "trailer",
        "compiler",
        "countedby",
        "sparta",
        "osatomic",
        "ipcipctypesh",
        "ipcobjectnull",
        "ipcobjectdead",
        "osreturn",
        "nfskrpch",
        "xdrbuf",
        "xdrbuf xbp",
        "xbptr",
        "xbleft",
        "tlen",
        "lval",
        "xbcleanup",
        "xbtype",
        "xbflags",
        "nfsargsversion",
        "file",
        "packed",
        "nfshz",
        "mount",
        "term",
        "restrict",
        "stats",
        "nfsbitmapset",
        "nfsver3",
        "nfsxunsigned",
        "attr",
        "nfsprogram",
        "nfssmallfh",
        "which",
        "from",
        "mark",
        "obsolete",
        "ip address",
        "iaddrt",
        "netinetbootph",
        "nvmaxtext",
        "magic",
        "etheraddrlen",
        "target",
        "byteorder",
        "bigendian",
        "littleendian",
        "dest",
        "igmp",
        "ushort",
        "inpcbptr",
        "inpcblistentry",
        "ipsec",
        "pcbs",
        "cookie",
        "netinetinstath",
        "minimal",
        "result",
        "arp packet",
        "icmpparamprob",
        "icmpredirect",
        "address",
        "ditto",
        "ip filter",
        "ipv4",
        "ip packet",
        "inject",
        "wifi",
        "server",
        "tcpmaxnotifyack",
        "wired",
        "ecn setup",
        "notify",
        "slow",
        "definitions",
        "tcptmax",
        "retransmit",
        "mptcp",
        "tcpsclosewait",
        "tcpsestablished",
        "tcpstimewait",
        "tcpseq",
        "timer drift",
        "sack",
        "char",
        "icmp",
        "synack",
        "tcpoptnop",
        "syndata",
        "ver",
        "internet",
        "iopcidevice",
        "constant",
        "perst",
        "localonly",
        "iooptionbits",
        "optional access",
        "ioservice",
        "open",
        "pcidriverkith",
        "osmetaclassbase",
        "iorpc rpc",
        "auditpipeiobase",
        "auditsdeviobase",
        "ioctls",
        "data",
        "the software",
        "stdargh",
        "hasincludenext",
        "eli friedman",
        "as is",
        "hack",
        "atomic",
        "atomicseqcst",
        "clangstdatomich",
        "stdchosted",
        "stdboolh",
        "needwintt",
        "stddefh",
        "hasbuiltin",
        "const src",
        "xnumembersize",
        "const dst",
        "wcharmax",
        "wcharmin",
        "limits",
        "kernelstdinth",
        "lp64 typedef",
        "intmaxc",
        "uintmaxc",
        "ptrauth",
        "olddata",
        "value",
        "declkey",
        "abi pointer",
        "c function",
        "float16",
        "fltevalmethod",
        "legacy bsd",
        "c standard",
        "sincospi",
        "cosp",
        "x8664monotonich",
        "staticifentry",
        "hasmte",
        "vmmemorytypesh",
        "vmwimgdefault",
        "wimg",
        "extvectortype",
        "utilfunction",
        "aligned",
        "srcptr",
        "vmpmaph",
        "vmdyldpagerh",
        "vmvmfaulth",
        "vmvmmaph",
        "development",
        "debug",
        "vmvmoptionsh",
        "vmvmpageouth",
        "kasantbi",
        "machvmmemtagh",
        "given",
        "vmmemtagptrsize",
        "vmmemtagtagsize",
        "copy",
        "vmsharedregionh",
        "vfsvfssupporth",
        "veclib",
        "master",
        "world wide",
        "various",
        "veclibtypes",
        "carbonlib",
        "availability",
        "carbon",
        "noncarbon cfm",
        "vbasicops",
        "shift",
        "vforceh",
        "vdsplength n",
        "realp",
        "nonnull",
        "vector",
        "dspsplitcomplex",
        "ieee",
        "dspcomplex",
        "uuiduuidh",
        "uuiddefine",
        "public",
        "uuid library",
        "kernelserver",
        "simpleroutine",
        "undkey",
        "execution",
        "strings array",
        "user",
        "title string",
        "info",
        "1024",
        "xmldatat",
        "undreplyref",
        "kernsuccess",
        "osaction",
        "targetosiphone",
        "istargetvendor",
        "targetcpux8664",
        "targetosunix",
        "targetcpuppc",
        "targetcpuppc64",
        "targetcpux86",
        "targetrtmaccfm",
        "bridge",
        "svflags",
        "svpavreal",
        "svpavreify",
        "xpvav",
        "svany",
        "avfillp",
        "for apidoc",
        "mutableav",
        "avrealoff",
        "pltopenv",
        "stmtstart",
        "stmtend",
        "copfile",
        "plcurstackinfo",
        "copfilegv",
        "cophinthashget",
        "loop",
        "stack",
        "beware",
        "orig",
        "loops",
        "this file",
        "the build",
        "plbitcount",
        "u8 value",
        "cvflags",
        "xpvcv",
        "mutableptr",
        "perlcore",
        "cvgv",
        "cvfile",
        "cvfmethod",
        "cvflvalue",
        "cvfconst",
        "anon",
        "doinit extconst",
        "ebcdic",
        "extconst u8",
        "index",
        "ascii platform",
        "confusingly",
        "u8 pla2e",
        "pla2e",
        "u8 ple2a",
        "guard",
        "declspec",
        "extconst",
        "ext externc",
        "init",
        "larry wall",
        "gnu general",
        "readme file",
        "multiplicity",
        "plsawampersand",
        "do not",
        "perliogetc",
        "perlioputc",
        "perliostdoutf",
        "perlio",
        "perlfeatureh",
        "featuresubbit",
        "featuremyrefbit",
        "featurefcbit",
        "featureisabit",
        "featuresaybit",
        "featurestatebit",
        "featuretrybit",
        "hintfeaturemask",
        "ffspace",
        "process",
        "ffdecimal",
        "ffend",
        "gvgp",
        "gvflags",
        "gvnamehek",
        "svtype",
        "gvegv",
        "gvstash",
        "gvxpvgv",
        "svtpvgv",
        "svtpvlv",
        "super",
        "edit directly",
        "djgpp",
        "bitbucket",
        "perlsysinitbody",
        "perlioinit",
        "perlsystermbody",
        "w macros",
        "wexitstatus",
        "shpath",
        "mkdir",
        "rotl64",
        "rotl32",
        "rotate x",
        "rotr32",
        "can64bithash",
        "rotr64",
        "ivsize",
        "u8to16le",
        "rotluv",
        "rotruv",
        "sbox32maxlen",
        "plhashstate",
        "perlhash",
        "perl",
        "usehashseed",
        "perlseenhvfunch",
        "perlhashseed",
        "siphash24",
        "siphash13",
        "seed",
        "c program",
        "c type",
        "c compiler",
        "gcc attribute",
        "longsize",
        "c preprocessor",
        "install",
        "kill",
        "cont",
        "thus",
        "ext declspec",
        "dext",
        "for apidocitem",
        "utf8",
        "ascii",
        "fitsin8bits",
        "nativetolatin1",
        "strwithlen",
        "u8 end",
        "test",
        "poison",
        "february",
        "cray",
        "prior",
        "behaviour",
        "except",
        "alpha",
        "perlvar",
        "perlvari",
        "perlvara",
        "padoffset",
        "true",
        "pmop",
        "hooks",
        "hook",
        "sv invlist",
        "perlinregcompc",
        "svcur",
        "perlinopc",
        "tointernalsize",
        "svtinvlist",
        "invlistlen",
        "strlen",
        "hvaux",
        "heklen",
        "svook",
        "hekutf8",
        "hekkey",
        "hekflags",
        "mutablehv",
        "hvnameheknn",
        "gosh",
        "leave",
        "iperlsock",
        "plsock",
        "iperlstdio",
        "plstdio",
        "iperlproc",
        "plproc",
        "iperllio",
        "pllio",
        "perlimplicitsys",
        "plink",
        "keypackage",
        "keyend",
        "keysub",
        "keydump",
        "keylog",
        "keysend",
        "keystate",
        "perlioclose",
        "perlmemcollxfrm",
        "nativetoneed",
        "plclocaleobj",
        "plno",
        "plwarnall",
        "plwarnnone",
        "plyes",
        "plzero",
        "plc9utf8dfatab",
        "nomathoms",
        "perlintokec",
        "perlinutf8c",
        "perlinsvc",
        "perlinregexecc",
        "debugging",
        "perlinlocalec",
        "pfinet",
        "snoop",
        "ccprint",
        "ccgraph",
        "cccharnamecont",
        "ccascii",
        "ccwordchar",
        "ccalphanumeric",
        "ccidfirst",
        "ccquotemeta",
        "ccalpha",
        "cccased",
        "ordinal",
        "magicvtablemax",
        "extra",
        "regex match",
        "env hash",
        "isa array",
        "debugger",
        "sig hash",
        "available",
        "shadow",
        "array length",
        "magic mg",
        "sv sv",
        "mgftainteddir",
        "hefsvkey",
        "mutablesv",
        "ssizet",
        "mgvtbl entry",
        "mgfbytes",
        "perlmagicsv 0",
        "special",
        "perlmagicarylen",
        "perlmagicrhash",
        "extra data",
        "perlmagicpos",
        "perlmagicsymtab",
        "provides",
        "dtrace probes",
        "stdioh",
        "stdioincluded",
        "sfioversion",
        "rxfpmfcharset",
        "rxfpmfmultiline",
        "rxfpmffold",
        "rxfpmfextended",
        "rxfpmfnocapture",
        "rxfpmfkeepcopy",
        "flags",
        "rxfpmfstrict",
        "ocshift",
        "plop",
        "perlbitfield16",
        "baseop op",
        "useithreads",
        "pmfonce",
        "padop",
        "perlcknull",
        "perlckfun",
        "opparg1mask",
        "opparg4mask",
        "opparg2mask",
        "perlckftst",
        "perlppftrowned",
        "perlckbitop",
        "perlckcmp",
        "perlcklfun",
        "dump",
        "chroot",
        "syscall",
        "flip",
        "undef",
        "crypt",
        "push",
        "stub",
        "trans",
        "predec",
        "flop",
        "prtf",
        "shutdown",
        "perlcontext cx",
        "perlmemlog",
        "c pointer",
        "cxtype",
        "logic",
        "toavamg",
        "tohvamg",
        "opftrread",
        "oplt",
        "opincmp",
        "opbitand",
        "opsbitor",
        "opsend",
        "opgetpeername",
        "opfteexec",
        "opftbinary",
        "opclose",
        "plparser",
        "yylex",
        "lexshared",
        "position",
        "repl",
        "memsize",
        "malloct",
        "perlmallocctlh",
        "uv nfree",
        "uv ntotal",
        "iv topbucket",
        "iv totalsbrk",
        "iv minbucket",
        "level",
        "plcomppad",
        "plcurpad",
        "uvxf",
        "ptr2uv",
        "avarray",
        "padnameflags",
        "plcopseqmax",
        "padlistarray",
        "c array",
        "padnametype",
        "incpushperl5lib",
        "appllibexp",
        "privlibexp",
        "defineincmacros",
        "perlfsversion",
        "perl5lib",
        "sitearchexp",
        "perllanginfoh",
        "hasnllanginfo",
        "ilanginfo",
        "codeset",
        "codeset 1",
        "dtfmt",
        "dtfmt 2",
        "dfmt",
        "dfmt 3",
        "sipround",
        "u8to64le",
        "fallthrough",
        "uint64c",
        "perlsiphashfnc",
        "siprounds",
        "strlen inlen",
        "sipfinalrounds",
        "could",
        "configure",
        "plout",
        "mine001",
        "argv",
        "plin",
        "localpatchcount",
        "perlapih",
        "xs code",
        "portingglossary",
        "first version",
        "brand",
        "symbols",
        "haswcrtomb",
        "perlionotstdio",
        "perlcallconv",
        "perlio f",
        "perlioh",
        "usestdio",
        "case",
        "bufsiz",
        "sizet",
        "perlstability",
        "perltypedefs",
        "perldtracehin",
        "perlloadedfile",
        "perlloadingfile",
        "perlopentry",
        "perlphasechange",
        "perlsubentry",
        "perlsubreturn",
        "generated",
        "perlcallconv iv",
        "sizet count",
        "sv arg",
        "mode",
        "perliofuncs tab",
        "stdchar",
        "perliolistt",
        "sv args",
        "mutex",
        "perlinterpreter",
        "sigsize",
        "perlioisstdio",
        "perlcallconv op",
        "perldokv",
        "perlppaassign",
        "perlppabs",
        "perlppaccept",
        "perlppadd",
        "perlppaeach",
        "perlppaelem",
        "public license",
        "free software",
        "foundation",
        "yydebug",
        "bison",
        "bareword",
        "funcmeth",
        "arrow",
        "targ",
        "pushs",
        "tops",
        "does",
        "xsub",
        "pops",
        "xpushs",
        "erange",
        "perlreentrapi",
        "perlreentrapi0",
        "hostentsize",
        "getgrentrproto",
        "getpwentrproto",
        "getnetentrproto",
        "grentbuffer",
        "grentsize",
        "hostenterrno",
        "redebugflag",
        "debugvtest",
        "debugr",
        "u16 nextoff",
        "argset",
        "u8 type",
        "nextoff",
        "strings",
        "problem",
        "june",
        "invert",
        "perlfpclass",
        "longdoublekind",
        "plstatusvalue",
        "pldebug",
        "numclasses",
        "locale",
        "grok",
        "pragma",
        "dword",
        "attack",
        "little",
        "lynx",
        "done",
        "reany",
        "rxpextflags",
        "rxextflags",
        "checkpoint cp",
        "rxftaintedseen",
        "rxfcopydone",
        "plsavestackix",
        "plsavestack",
        "plsavestackmax",
        "ssmaxpush",
        "enter",
        "debugscope",
        "state",
        "u32 state",
        "debugsbox32hash",
        "sbox32warn5",
        "line",
        "mutexunlock",
        "mutexinit",
        "noop",
        "mutexlock",
        "condinit",
        "detach",
        "panic",
        "usetm64",
        "should",
        "bsd extension",
        "configuration",
        "time64debug",
        "int64t nv",
        "gnu extension",
        "perltime64h",
        "time64t",
        "int64t int64",
        "int64 time64t",
        "i32 year",
        "tm64",
        "hastmtmgmtoff",
        "decide",
        "svpvx",
        "svgmagic",
        "bonk",
        "anything",
        "turn",
        "crash",
        "fstat",
        "perlmicro",
        "hasioctl",
        "hasutime",
        "hasgroup",
        "haspasswd",
        "usemybinmode",
        "idirent",
        "likely",
        "generated code",
        "utfebcdic",
        "unicode",
        "step",
        "ufeff",
        "u00a0",
        "u00df",
        "u00b5",
        "ufffd",
        "u017f",
        "u0300",
        "unlikely",
        "nativeutf8toi8",
        "utf8skip",
        "nativetouni",
        "lazy",
        "extrasize",
        "regnodemax",
        "exact",
        "match",
        "whilem",
        "anyof",
        "curly",
        "trie",
        "curlym",
        "eval",
        "star",
        "perlutilh",
        "hsmapiverlen",
        "hsxsverlenmax",
        "hskeyp",
        "tools",
        "sv vs",
        "perlversionlt",
        "svpvxnolenconst",
        "perlckwarner",
        "u32 err",
        "scroakxsusage",
        "pluumap",
        "warnings",
        "categories",
        "plcurcop",
        "perlckwarn",
        "perlckwarnd",
        "perlwarnisset",
        "perlwarnoff",
        "perlwarnbit",
        "xsversion",
        "xsreturn",
        "perlxshandshake",
        "plstackbase",
        "hskey",
        "zaphod32mix",
        "u8to32le",
        "zaphod32warn4",
        "zaphod32warn3",
        "zaphod32warn6",
        "perlform",
        "i8tonativeutf8",
        "warnutf8",
        "myshift",
        "c extension",
        "libs",
        "cflags",
        "afkuserlog",
        "kafkeventcancel",
        "kafkeventerror",
        "adamsbagmanager",
        "adjinglerequest",
        "isinternalbuild",
        "kickmcxdforuid",
        "loadappkit",
        "ardconfig",
        "authenticator",
        "dsauthenticator",
        "dsnode",
        "dsrecord",
        "hostconfig",
        "addtofront",
        "calcslope",
        "copyarray",
        "createcachenode",
        "defaultebecurve",
        "deletecache",
        "disablehcucache",
        "dumpcache",
        "dumpoutputhcu",
        "enablet1sim",
        "ascagent",
        "ascagentproxy",
        "asdevice",
        "ddrangecompare",
        "wdosloglauncher",
        "wdoslogprotocol",
        "findchar",
        "ddasllogger",
        "ddfilelogger",
        "ddlog",
        "ddlogfileinfo",
        "ddlogmessage",
        "ddloggernode",
        "mkurlparser",
        "mkerrordomain",
        "mkintegerhash",
        "mklonghash",
        "mkmaprectinset",
        "mkmaprectnull",
        "mkmaprectoffset",
        "mkmaprectworld",
        "mkmapsizeworld",
        "kextensionnonui",
        "wkarraycreate",
        "wkbooleancreate",
        "wkcontextcreate",
        "wkdatacreate",
        "wkdatagettypeid",
        "wkdoublecreate",
        "wkframecopyurl",
        "wkgettypeid",
        "wkimagecreate",
        "wkpagecandelete",
        "webkit",
        "methodkind",
        "wkerrordomain",
        "by apple",
        "document",
        "a block",
        "wkcontentworld",
        "wkwebview",
        "javascript",
        "wkerrorcode",
        "wkerrorunknown",
        "nsswiftasync",
        "wkswiftasync",
        "wkcookiepolicy",
        "nshttpcookie",
        "whether",
        "wknavigation",
        "wkdownload",
        "decides",
        "mime type",
        "wkscriptmessage",
        "wkframeinfo",
        "information",
        "url scheme",
        "wkcontentmode",
        "wkuserscript",
        "wkextern",
        "media",
        "promise",
        "fulfill",
        "cgfloat",
        "targetoswatch",
        "sign",
        "password",
        "provider",
        "uicontrol",
        "nscontrol",
        "opaque user",
        "apple id",
        "nsstring user",
        "asuseragerange",
        "initiate",
        "asauthorization",
        "confirms",
        "apple upgrade",
        "nserrorenum",
        "operation",
        "relying party",
        "targetosvision",
        "a byte",
        "nsdata userid",
        "relying",
        "a string",
        "asapiavailable",
        "http response",
        "authorization",
        "oauth",
        "saml",
        "nsdata readdata",
        "bool didwrite",
        "a cose",
        "nsstring name",
        "bool appid",
        "targetosxr",
        "a state",
        "a json",
        "web token",
        "private seckeys",
        "nsstring appid",
        "mdm profile",
        "nsurl url",
        "returns yes",
        "lacontext",
        "asswiftsendable",
        "keychain",
        "cose algorithm",
        "ecdsa",
        "sha256",
        "cose curve",
        "p256",
        "nsinteger rank",
        "enables",
        "bool success",
        "remove",
        "call",
        "complete",
        "prepare",
        "attempt",
        "list",
        "nsextension",
        "settings",
        "initializes",
        "a key",
        "extensions",
        "hash",
        "json",
        "initialize",
        "nsstring origin",
        "settings app",
        "urls",
        "https urls",
        "safari",
        "cancel",
        "nsuuid uuid",
        "asextern extern",
        "asextern",
        "nsswiftsendable",
        "uiwindow",
        "propertykind",
        "gkplayer",
        "n tags",
        "gkerrordomain",
        "gamecenter",
        "targetosios",
        "targetostv",
        "nsavailable",
        "gkachievement",
        "local player",
        "view",
        "present",
        "optional",
        "gkbaseplayer",
        "game center",
        "uiimage",
        "app store",
        "gkchallenge",
        "gklocalplayer",
        "nsdeprecated",
        "a singleton",
        "gkcloudplayer",
        "returns nil",
        "nsdeprecatedmac",
        "internal2",
        "internal3",
        "internal4",
        "gkscore",
        "gkextern",
        "gkextern extern",
        "gkexternweak",
        "gkerrorcode",
        "gkerrorunknown",
        "gkerrorunderage",
        "friendplayer",
        "standard view",
        "nsresponder",
        "parentwindow",
        "ibaction",
        "gkgamesession",
        "apis",
        "gkplayer player",
        "nsinteger score",
        "nsdate date",
        "gkleaderboard",
        "connect",
        "nsinteger value",
        "load",
        "gktransporttype",
        "nsstring title",
        "loads array",
        "localized",
        "gkmatch",
        "gkmatchrequest",
        "gkinvite",
        "gksession",
        "gksession api",
        "gamekit",
        "asynchronously",
        "welcome",
        "nstimeinterval",
        "delegate",
        "delivery",
        "gksenddatamode",
        "gksessionmode",
        "gkphotosize",
        "callbacks",
        "gkmatchdelegate",
        "gksavedgame",
        "default value",
        "gksessionerror",
        "gkvoicechat",
        "participant",
        "voice chat",
        "clienta"
      ],
      "references": [
        "CredentialsCache.h",
        "CredentialsCache2.h",
        "config.xml",
        "popen_spawn_win32.py",
        "pycore_condvar.h",
        "Kerberos.h",
        "KerberosLogin.h",
        "plugin.js",
        "krb5.h",
        "MultipeerConnectivity.tbd",
        "MCBrowserViewController.h",
        "MCNearbyServiceAdvertiser.h",
        "MCError.h",
        "MCAdvertiserAssistant.h",
        "MCNearbyServiceBrowser.h",
        "MultipeerConnectivity.apinotes",
        "MultipeerConnectivity.h",
        "MCSession.h",
        "MCPeerID.h",
        "canvas.html",
        "capture_0.bundle.js",
        "capture_resize.js",
        "GCRacingWheelInput.h",
        "GCSyntheticDeviceKeys.h",
        "GCSwitchPositionInput.h",
        "GCSteeringWheelElement.h",
        "GCSwitchElement.h",
        "GCTouchedStateInput.h",
        "GCXboxGamepad.h",
        "GCTypes.h",
        "GCRelativeInput.h",
        "GameController.h",
        "GCAxis2DInput.h",
        "GCAxisElement.h",
        "GCAxisInput.h",
        "GCButtonElement.h",
        "GCController.h",
        "GCColor.h",
        "GCControllerAxisInput.h",
        "GCControllerDirectionPad.h",
        "GCControllerInput.h",
        "GCControllerElement.h",
        "GCControllerTouchpad.h",
        "GCDevice.h",
        "GCDeviceBattery.h",
        "GCDeviceCursor.h",
        "GCDeviceHaptics.h",
        "GCDeviceLight.h",
        "GCDevicePhysicalInputState.h",
        "GCDevicePhysicalInputStateDiff.h",
        "GCDirectionalGamepad.h",
        "GCDirectionPadElement.h",
        "GCDevicePhysicalInput.h",
        "GCDualSenseAdaptiveTrigger.h",
        "GCDualSenseGamepad.h",
        "GCDualShockGamepad.h",
        "GCEventViewController.h",
        "GCExtendedGamepadSnapshot.h",
        "GCExtern.h",
        "GCExtendedGamepad.h",
        "GCGamepadSnapshot.h",
        "GCGearShifterElement.h",
        "GCGamepad.h",
        "GCKeyboard.h",
        "GCInputNames.h",
        "GCControllerButtonInput.h",
        "GCKeyNames.h",
        "GCKeyboardInput.h",
        "GCKeyCodes.h",
        "GCLinearInput.h",
        "GCMotion.h",
        "GCMouse.h",
        "GCMouseInput.h",
        "GCMicroGamepadSnapshot.h",
        "GCPhysicalInputElement.h",
        "GCMicroGamepad.h",
        "GCPhysicalInputProfile.h",
        "GCPhysicalInputSource.h",
        "GCPressedStateInput.h",
        "GCProductCategories.h",
        "GCRacingWheel.h",
        "GameController.tbd",
        "arm64e-apple-macos.swiftinterface",
        "x86_64-apple-macos.swiftinterface",
        "module.modulemap",
        "com_err.h",
        "gssapi_generic.h",
        "locate_plugin.h",
        "profile.h",
        "gssapi_krb5.h",
        "preauth_plugin.h",
        "gssapi.h",
        "alc.h",
        "oalStaticBufferExtension.h",
        "oalMacOSX_OALExtensions.h",
        "OpenAL.h",
        "al.h",
        "OpenAL.tbd",
        "IOUSBHost.tbd",
        "IOUSBHostCIEndpointStateMachine.h",
        "IOUSBHostCIControllerStateMachine.h",
        "IOUSBHost.h",
        "IOUSBHostCIPortStateMachine.h",
        "IOUSBHostCIDeviceStateMachine.h",
        "IOUSBHostControllerInterfaceHelpers.h",
        "IOUSBHostDevice.h",
        "IOUSBHostControllerInterface.h",
        "IOUSBHostDefinitions.h",
        "IOUSBHostInterface.h",
        "IOUSBHostIOSource.h",
        "AppleUSBDescriptorParsing.h",
        "IOUSBHostStream.h",
        "IOUSBHostObject.h",
        "IOUSBHostControllerInterfaceDefinitions.h",
        "IOUSBHostPipe.h",
        "IOBluetoothUIUserLib.h",
        "IOBluetoothUI.h",
        "IOBluetoothObjectPushUIController.h",
        "IOBluetoothDeviceSelectorController.h",
        "IOBluetoothPasskeyDisplay.h",
        "IOBluetoothPairingController.h",
        "IOBluetoothServiceBrowserController.h",
        "IOBluetoothUI.tbd",
        "Bluetooth.h",
        "IOBluetooth.h",
        "BluetoothAssignedNumbers.h",
        "IOBluetoothTypes.h",
        "IOBluetoothUtilities.h",
        "OBEXBluetooth.h",
        "IOBluetoothUserLib.h",
        "OBEX.h",
        "IOBluetooth.tbd",
        "INImage+IntentsUI.h",
        "IntentsUI.h",
        "INUIAddVoiceShortcutButton.h",
        "IntentsUI.apinotes",
        "INUIEditVoiceShortcutViewController.h",
        "INUIAddVoiceShortcutViewController.h",
        "LDAP.tbd",
        "OSvKernDSPLib.h",
        "cpu.h",
        "asm_help.h",
        "desc.h",
        "pio.h",
        "io.h",
        "sel.h",
        "reg_help.h",
        "tss.h",
        "table.h",
        "byte_order.h",
        "_limits.h",
        "_types.h",
        "_mcontext.h",
        "_param.h",
        "_endian.h",
        "arch.h",
        "cpuid_internal.h",
        "cpu_capabilities_public.h",
        "arm_features.inc",
        "endian.h",
        "locks.h",
        "limits.h",
        "atomic.h",
        "machine_cpuid.h",
        "memory_types.h",
        "pal_routines.h",
        "machine_routines.h",
        "param.h",
        "cpuid.h",
        "thread.h",
        "trap.h",
        "vmparam.h",
        "signal.h",
        "types.h",
        "AFKMemoryDescriptorOptions.h",
        "machine_machdep.h",
        "atm_types.h",
        "copyio.h",
        "_OSByteOrder.h",
        "crc.h",
        "Block.h",
        "OSBase.h",
        "OSByteOrder.h",
        "OSDebug.h",
        "OSMalloc.h",
        "OSAtomic.h",
        "OSReturn.h",
        "OSKextLib.h",
        "OSTypes.h",
        "version.h",
        "sysctl.h",
        "tree.h",
        "zconf.h",
        "zlib.h",
        "libkern.h",
        "kdp_callout.h",
        "kdp_en_debugger.h",
        "ipc_types.h",
        "krpc.h",
        "rpcv2.h",
        "xdr_subs.h",
        "nfs.h",
        "nfsproto.h",
        "bootp.h",
        "if_ether.h",
        "icmp6.h",
        "icmp_var.h",
        "igmp_var.h",
        "igmp.h",
        "in_pcb.h",
        "in_stat.h",
        "in_private.h",
        "in_arp.h",
        "in_var.h",
        "in_systm.h",
        "ip_var.h",
        "ip_icmp.h",
        "kpi_ipfilter.h",
        "ip6.h",
        "tcp_private.h",
        "ip.h",
        "tcp_timer.h",
        "tcp_fsm.h",
        "udp_var.h",
        "tcp_seq.h",
        "tcpip.h",
        "udp.h",
        "tcp_var.h",
        "tcp.h",
        "IOPCIFamilyDefinitions.h",
        "IOPCIDevice.iig",
        "PCIDriverKit.h",
        "IOPCIDevice.h",
        "audit_ioctl.h",
        "stdarg.h",
        "stdatomic.h",
        "stdbool.h",
        "stddef.h",
        "string.h",
        "stdint.h",
        "ptrauth.h",
        "math.h",
        "monotonic.h",
        "static_if.h",
        "machine_kpc.h",
        "machine_remote_time.h",
        "ipc_pthread_priority_types.h",
        "lz4_assembly_select.h",
        "vm_compressor_algorithms.h",
        "lz4.h",
        "pmap.h",
        "vm_dyld_pager.h",
        "vm_far.h",
        "vm_fault.h",
        "vm_map.h",
        "lz4_constants.h",
        "vm_options.h",
        "vm_pageout.h",
        "vm_memtag.h",
        "vm_shared_region.h",
        "vm_kern.h",
        "vfs_support.h",
        "vecLib.h",
        "vecLibTypes.h",
        "vBasicOps.h",
        "vForce.h",
        "vDSP.h",
        "uuid.h",
        "UNDReply.defs",
        "UNDRequest.defs",
        "KUNCUserNotifications.h",
        "UNDTypes.defs",
        "UNDTypes.h",
        "TargetConditionals.h",
        "apfs_boot_mount.tbd",
        "av.h",
        "cop.h",
        "bitcount.h",
        "cv.h",
        "ebcdic_tables.h",
        "EXTERN.h",
        "embedvar.h",
        "fakesdio.h",
        "feature.h",
        "form.h",
        "gv.h",
        "git_version.h",
        "dosish.h",
        "hv_macro.h",
        "hv_func.h",
        "config.h",
        "INTERN.h",
        "handy.h",
        "intrpvar.h",
        "invlist_inline.h",
        "hv.h",
        "iperlsys.h",
        "keywords.h",
        "libperl.tbd",
        "embed.h",
        "l1_char_class_tab.h",
        "mg_data.h",
        "mg_raw.h",
        "mg.h",
        "mg_vtable.h",
        "mydtrace.h",
        "nostdio.h",
        "op_reg_common.h",
        "op.h",
        "opcode.h",
        "inline.h",
        "overload.h",
        "opnames.h",
        "parser.h",
        "malloc_ctl.h",
        "pad.h",
        "perl_inc_macro.h",
        "perl_langinfo.h",
        "perl_siphash.h",
        "patchlevel.h",
        "perlapi.h",
        "metaconfig.h",
        "perlio.h",
        "perldtrace.h",
        "perliol.h",
        "perlvars.h",
        "perlsdio.h",
        "pp_proto.h",
        "perly.h",
        "pp.h",
        "reentr.h",
        "regcomp.h",
        "perl.h",
        "regexp.h",
        "scope.h",
        "sbox32_hash.h",
        "time64_config.h",
        "time64.h",
        "sv.h",
        "unixish.h",
        "uconfig.h",
        "utfebcdic.h",
        "unicode_constants.h",
        "utf8.h",
        "regnodes.h",
        "util.h",
        "vutil.h",
        "uudmap.h",
        "warnings.h",
        "XSUB.h",
        "zaphod32_hash.h",
        "encode.h",
        "python-3.9.pc",
        "python-3.9-embed.pc",
        "python3-embed.pc",
        "python3.pc",
        "AFKUser.tbd",
        "AdID.tbd",
        "Admin.tbd",
        "AirPlayReceiver.tbd",
        "AppSandbox.tbd",
        "ASEProcessing.tbd",
        "AuthenticationServicesCore.tbd",
        "WebGPU.tbd",
        "WebDriver.tbd",
        "MapKit.tbd",
        "SwiftUI.swiftoverlay",
        "WebKit.tbd",
        "WebKit.apinotes",
        "WKBackForwardList.h",
        "NSAttributedString.h",
        "WebKit.h",
        "WKBackForwardListItem.h",
        "WKContentRuleList.h",
        "WKContentRuleListStore.h",
        "WKContextMenuElementInfo.h",
        "WKDataDetectorTypes.h",
        "WKContentWorld.h",
        "WKError.h",
        "WKFoundation.h",
        "WKFindResult.h",
        "WKHTTPCookieStore.h",
        "WKFrameInfo.h",
        "WKNavigation.h",
        "WKFindConfiguration.h",
        "WKNavigationDelegate.h",
        "WKNavigationResponse.h",
        "WKOpenPanelParameters.h",
        "WebKitLegacy.h",
        "WKPreviewActionItem.h",
        "WKNavigationAction.h",
        "WKPreferences.h",
        "WKPreviewActionItemIdentifiers.h",
        "WKPreviewElementInfo.h",
        "WKProcessPool.h",
        "WKDownload.h",
        "WKPDFConfiguration.h",
        "WKScriptMessage.h",
        "WKSecurityOrigin.h",
        "WKScriptMessageHandler.h",
        "WKSnapshotConfiguration.h",
        "WKUIDelegate.h",
        "WKURLSchemeTask.h",
        "WKWebpagePreferences.h",
        "WKUserContentController.h",
        "WKWebsiteDataStore.h",
        "WKWebsiteDataRecord.h",
        "WKUserScript.h",
        "WKURLSchemeHandler.h",
        "WKWebViewConfiguration.h",
        "WKWebView.h",
        "WKScriptMessageHandlerWithReply.h",
        "WKWindowFeatures.h",
        "WKDownloadDelegate.h",
        "ASAccountAuthenticationModificationController.h",
        "ASAccountAuthenticationModificationViewController.h",
        "ASAuthorization.h",
        "ASAuthorizationAppleIDButton.h",
        "ASAccountAuthenticationModificationRequest.h",
        "ASAuthorizationAppleIDProvider.h",
        "ASAuthorizationAppleIDRequest.h",
        "ASAuthorizationAppleIDCredential.h",
        "ASAuthorizationController.h",
        "ASAuthorizationCredential.h",
        "ASAccountAuthenticationModificationExtensionContext.h",
        "ASAuthorizationError.h",
        "ASAuthorizationCustomMethod.h",
        "ASAuthorizationPasswordRequest.h",
        "ASAuthorizationOpenIDRequest.h",
        "ASAuthorizationPlatformPublicKeyCredentialDescriptor.h",
        "ASAuthorizationPlatformPublicKeyCredentialProvider.h",
        "ASAccountAuthenticationModificationReplacePasswordWithSignInWithAppleRequest.h",
        "ASAccountAuthenticationModificationUpgradePasswordToStrongPasswordRequest.h",
        "ASAuthorizationPlatformPublicKeyCredentialRegistrationRequest.h",
        "ASAuthorizationPlatformPublicKeyCredentialRegistration.h",
        "ASAuthorizationProvider.h",
        "ASAuthorizationPlatformPublicKeyCredentialAssertion.h",
        "ASAuthorizationPublicKeyCredentialAssertion.h",
        "ASAuthorizationPublicKeyCredentialAssertionRequest.h",
        "ASAuthorizationPublicKeyCredentialConstants.h",
        "ASAuthorizationProviderExtensionAuthorizationResult.h",
        "ASAuthorizationPublicKeyCredentialDescriptor.h",
        "ASAuthorizationPublicKeyCredentialLargeBlobAssertionOutput.h",
        "ASAuthorizationPasswordProvider.h",
        "ASAuthorizationPublicKeyCredentialLargeBlobRegistrationInput.h",
        "ASAuthorizationPublicKeyCredentialParameters.h",
        "ASAuthorizationPublicKeyCredentialLargeBlobRegistrationOutput.h",
        "ASAuthorizationPublicKeyCredentialRegistration.h",
        "ASAuthorizationPublicKeyCredentialRegistrationRequest.h",
        "ASAuthorizationPublicKeyCredentialLargeBlobAssertionInput.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialAssertion.h",
        "ASAuthorizationRequest.h",
        "ASAuthorizationPlatformPublicKeyCredentialAssertionRequest.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialProvider.h",
        "ASAuthorizationSingleSignOnCredential.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialDescriptor.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialAssertionRequest.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialRegistration.h",
        "ASAuthorizationSingleSignOnProvider.h",
        "ASAuthorizationWebBrowserExternallyAuthenticatableRequest.h",
        "ASAuthorizationWebBrowserPlatformPublicKeyCredentialAssertionRequest.h",
        "ASAuthorizationWebBrowserPlatformPublicKeyCredentialRegistrationRequest.h",
        "ASAuthorizationWebBrowserPublicKeyCredentialManager.h",
        "ASAuthorizationWebBrowserPlatformPublicKeyCredential.h",
        "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialAssertionRequest.h",
        "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialRegistrationRequest.h",
        "ASCOSEConstants.h",
        "ASCredentialIdentity.h",
        "ASAuthorizationSingleSignOnRequest.h",
        "ASCredentialIdentityStore.h",
        "ASAuthorizationWebBrowserSecurityKeyPublicKeyCredentialProvider.h",
        "ASCredentialProviderExtensionContext.h",
        "ASCredentialProviderViewController.h",
        "ASAuthorizationSecurityKeyPublicKeyCredentialRegistrationRequest.h",
        "ASCredentialServiceIdentifier.h",
        "ASExtensionErrors.h",
        "ASAuthorizationProviderExtensionAuthorizationRequest.h",
        "ASCredentialRequest.h",
        "ASAuthorizationWebBrowserPlatformPublicKeyCredentialProvider.h",
        "ASPasskeyAssertionCredential.h",
        "ASPasskeyCredentialRequest.h",
        "ASPasskeyCredentialRequestParameters.h",
        "ASCredentialIdentityStoreState.h",
        "ASPasskeyRegistrationCredential.h",
        "ASPasswordCredential.h",
        "ASPublicKeyCredential.h",
        "ASPasskeyCredentialIdentity.h",
        "ASPublicKeyCredentialClientData.h",
        "ASSettingsHelper.h",
        "ASWebAuthenticationSessionCallback.h",
        "ASWebAuthenticationSession.h",
        "ASWebAuthenticationSessionRequest.h",
        "ASWebAuthenticationSessionWebBrowserSessionManager.h",
        "AuthenticationServices.h",
        "ASFoundation.h",
        "AuthenticationServices.apinotes",
        "ASWebAuthenticationSessionWebBrowserSessionHandling.h",
        "ASPasswordCredentialIdentity.h",
        "ASPasswordCredentialRequest.h",
        "GameKit.apinotes",
        "GKAccessPoint.h",
        "GameKit.h",
        "GKAchievement.h",
        "GKAchievementViewController.h",
        "GKBasePlayer.h",
        "GKAchievementDescription.h",
        "GKChallengeEventHandler.h",
        "GKCloudPlayer.h",
        "GKChallengesViewController.h",
        "GKChallenge.h",
        "GKDefines.h",
        "GKError.h",
        "GKEventListener.h",
        "GKFriendRequestComposeViewController.h",
        "GKDialogController.h",
        "GKGameSessionEventListener.h",
        "GKGameSessionError.h",
        "GKGameCenterViewController.h",
        "GKGameSessionSharingViewController.h",
        "GKLeaderboardEntry.h",
        "GKLeaderboard.h",
        "GKLeaderboardScore.h",
        "GKGameSession.h",
        "GKLeaderboardSet.h",
        "GKLocalPlayer.h",
        "GKLeaderboardViewController.h",
        "GKMatch.h",
        "GKMatchmaker.h",
        "GKMatchmakerViewController.h",
        "GKPeerPickerController.h",
        "GKNotificationBanner.h",
        "GKPublicConstants.h",
        "GKPlayer.h",
        "GKPublicProtocols.h",
        "GKSavedGameListener.h",
        "GKScore.h",
        "GKSessionError.h",
        "GKVoiceChat.h",
        "GKTurnBasedMatchmakerViewController.h",
        "GKSession.h",
        "GKTurnBasedMatch.h",
        "GKSavedGame.h",
        "GKVoiceChatService.h"
      ],
      "public": 1,
      "adversary": "Turla Group, FIN7, APT34, APT28, DragonForce Malaysia Hacker Group, Indonesia Islamic Warriors Counc",
      "targeted_countries": [
        "United States of America",
        "India",
        "Australia"
      ],
      "malware_families": [
        {
          "id": "OSAtomic",
          "display_name": "OSAtomic",
          "target": null
        },
        {
          "id": "OSReturn",
          "display_name": "OSReturn",
          "target": null
        },
        {
          "id": "Ver",
          "display_name": "Ver",
          "target": null
        },
        {
          "id": "Internet",
          "display_name": "Internet",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1123",
          "name": "Audio Capture",
          "display_name": "T1123 - Audio Capture"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 39,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ilyailya",
        "id": "298851",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1968,
        "domain": 526,
        "FileHash-SHA256": 207,
        "hostname": 972,
        "email": 55,
        "FileHash-SHA1": 9,
        "FileHash-MD5": 4,
        "CVE": 2,
        "CIDR": 10
      },
      "indicator_count": 3753,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 35,
      "modified_text": "389 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67eed1bef3ff35a5814d2d81",
      "name": "New GolangGhost Malware Linked to Lazarus Group\u2019s Cyber Campaign",
      "description": "North Korean hackers linked to the Lazarus Group are targeting job seekers in the cryptocurrency sector with a new social engineering tactic called ClickFix, deploying a previously unseen Go-based backdoor named GolangGhost on Windows and macOS systems. Researchers said the campaign, now tracked as ClickFake Interview, impersonates major crypto firms like Coinbase, Kraken, and Binance to lure victims.",
      "modified": "2025-05-03T18:03:35.754000",
      "created": "2025-04-03T18:21:50.101000",
      "tags": [
        "lazarus",
        "windows",
        "golangghost",
        "cefi",
        "sekoia",
        "frostyferret",
        "clickfix tactic",
        "temp",
        "march",
        "dprk",
        "invisibleferret",
        "terminal",
        "macos",
        "sharpknot",
        "manuscrypt",
        "bluenoroff",
        "february",
        "beavertail",
        "path",
        "kraken",
        "robinhood"
      ],
      "references": [
        "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Superpro",
        "id": "61676",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 10,
        "FileHash-SHA1": 3,
        "FileHash-SHA256": 14,
        "URL": 7,
        "YARA": 9,
        "domain": 40,
        "hostname": 25
      },
      "indicator_count": 108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 214,
      "modified_text": "392 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67ee8daa5adeb254fb7d484e",
      "name": "From Contagious to ClickFake Interview: Lazarus leveraging the ClickFix tactic - Sekoia.io Blog",
      "description": "In March 2025, Bybit, an UAE-based crypto exchange platform, was targeted by Lazarus, a state-sponsored intrusion set attributed to the Democratic People\u2019s Republic of Korea (DPRK), leading to the theft of $1.5 billion, which represents a record-breaking crypto heist in history.",
      "modified": "2025-05-03T13:01:09.343000",
      "created": "2025-04-03T13:31:22.404000",
      "tags": [
        "lazarus",
        "windows",
        "golangghost",
        "cefi",
        "sekoia",
        "frostyferret",
        "clickfix tactic",
        "temp",
        "march",
        "dprk",
        "invisibleferret",
        "terminal",
        "macos",
        "sharpknot",
        "manuscrypt",
        "bluenoroff",
        "february",
        "beavertail",
        "path",
        "kraken",
        "robinhood"
      ],
      "references": [
        "https://blog.sekoia.io/clickfake-interview-campaign-by-lazarus/#h-iocs-and-technical-details"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 10,
        "FileHash-SHA1": 3,
        "FileHash-SHA256": 14,
        "URL": 7,
        "YARA": 9,
        "domain": 40,
        "hostname": 25
      },
      "indicator_count": 108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "392 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "process.name",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "process.name",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780213107.6704655
}