{
  "type": "Domain",
  "indicator": "smallcloud.ga",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/smallcloud.ga",
    "alexa": "http://www.alexa.com/siteinfo/smallcloud.ga",
    "indicator": "smallcloud.ga",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 208968217,
      "indicator": "smallcloud.ga",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 9,
      "pulses": [
        {
          "id": "5b680d1afd6a3e5318179326",
          "name": "Turla Actors using Copied Cars.com Content",
          "description": "Starting in November of 2017, Turla actors appeared to start using website content copied from &quot;cars.com&quot; on their command and control channels.",
          "modified": "2018-08-06T08:55:54.534000",
          "created": "2018-08-06T08:55:54.534000",
          "tags": [
            "turla",
            "snake",
            "russia"
          ],
          "references": [
            "https://twitter.com/9bplus/status/1024714362244739073?s=21"
          ],
          "public": 1,
          "adversary": "Turla",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 44,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 5,
            "hostname": 264,
            "domain": 26
          },
          "indicator_count": 295,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386537,
          "modified_text": "2854 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5a55526949cace1e7e249928",
          "name": "Diplomats in Eastern Europe bitten by a Turla mosquito",
          "description": "Turla is one of the longest-known state-sponsored cyberespionage groups, with well-known victims\nsuch as the US Department of Defense in 2008. The group owns a large toolset that is generally\ndivided into several categories: the most advanced malware is only deployed on machines that are\nthe most interesting to the attackers. Their espionage platform is mainly used against Windows\nmachines, but also against macOS and Linux machines with various backdoors and a rootkit.\nFor years, Turla has relied, among other impersonations, on fake Flash installers to compromise\nvictims. This kind of attack vector does not require highly sophisticated exploits but rather depends\non tricking the user into installing the fake program.",
          "modified": "2018-01-09T23:38:17.150000",
          "created": "2018-01-09T23:38:17.150000",
          "tags": [
            "turla",
            "snake",
            "russia"
          ],
          "references": [
            "https://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf"
          ],
          "public": 1,
          "adversary": "Turla Group",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 85,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2,
            "hostname": 11,
            "domain": 3,
            "FileHash-SHA256": 14,
            "FileHash-MD5": 14,
            "FileHash-SHA1": 14
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386557,
          "modified_text": "3063 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5fa1ee5c64dc0e2060647954",
          "name": "Malware - Malware Domain Feed V2 - November 03 2020",
          "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
          "modified": "2026-05-31T01:17:54.397000",
          "created": "2020-11-03T23:57:16.317000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 130478,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "otxrobottwo_testing",
            "id": "83138",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45551,
            "domain": 66446
          },
          "indicator_count": 111997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 971,
          "modified_text": "5 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6645e430dd6a9505cb9cd9ca",
          "name": "To the Moon and back(doors): Lunar landing in diplomatic missions",
          "description": "ESET Research has identified two backdoors used by the infamous Russian-aligned cyberespionage group, Turla, to compromise European diplomatic institutions in the Middle East and other parts of the world.",
          "modified": "2024-06-15T10:04:30.773000",
          "created": "2024-05-16T10:47:12.433000",
          "tags": [
            "lunarweb",
            "lunarmail",
            "strong",
            "c server",
            "eset research",
            "turla",
            "stage",
            "outlook",
            "aes256",
            "http",
            "powershell",
            "persistence",
            "win64",
            "format",
            "first",
            "tips",
            "snake",
            "defense",
            "smskey",
            "stages",
            "loader",
            "lightneuron",
            "execution",
            "ebury",
            "webglobe",
            "lunarloader",
            "gazer loader",
            "welivesecurity",
            "crypto",
            "compromise",
            "ltmanager",
            "carbon",
            "gazer",
            "mosquito",
            "armenia",
            "star",
            "dllinjector",
            "dropper",
            "comrat",
            "crutch",
            "footer"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/",
            "https://github.com/eset/malware-ioc/tree/master/turla#to-the-moon-and-backdoors-lunar-landing-in-diplomatic-missionsindicators-of-compromise"
          ],
          "public": 1,
          "adversary": "Turla",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Turla",
              "display_name": "Turla",
              "target": null
            },
            {
              "id": "Webglobe",
              "display_name": "Webglobe",
              "target": null
            },
            {
              "id": "LunarLoader",
              "display_name": "LunarLoader",
              "target": null
            },
            {
              "id": "LunarWeb",
              "display_name": "LunarWeb",
              "target": null
            },
            {
              "id": "LunarMail",
              "display_name": "LunarMail",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1020",
              "name": "Automated Exfiltration",
              "display_name": "T1020 - Automated Exfiltration"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1030",
              "name": "Data Transfer Size Limits",
              "display_name": "T1030 - Data Transfer Size Limits"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1137",
              "name": "Office Application Startup",
              "display_name": "T1137 - Office Application Startup"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1586",
              "name": "Compromise Accounts",
              "display_name": "T1586 - Compromise Accounts"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1591",
              "name": "Gather Victim Org Information",
              "display_name": "T1591 - Gather Victim Org Information"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Diplomatic",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "bluenumberone",
            "id": "246058",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 27,
            "URL": 25,
            "FileHash-MD5": 59,
            "FileHash-SHA1": 128,
            "FileHash-SHA256": 59,
            "domain": 47,
            "email": 2
          },
          "indicator_count": 347,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 72,
          "modified_text": "714 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b5461ad2cb2f9e8d342d",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:06.188000",
          "created": "2024-02-06T22:40:06.188000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "844 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b543bc2adfd3eca5ff2b",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:03.501000",
          "created": "2024-02-06T22:40:03.501000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "844 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b5405e6e9e23324e6d8e",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:00.906000",
          "created": "2024-02-06T22:40:00.906000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "844 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707dfb9f84eebbe3bdfe59",
          "name": "Pegasus and Friends  2 - all touch by Pegasus or Variant in some way or another",
          "description": "",
          "modified": "2023-12-06T13:58:18.607000",
          "created": "2023-12-06T13:58:18.607000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1207,
            "domain": 312,
            "hostname": 1198,
            "URL": 3217,
            "FileHash-MD5": 3
          },
          "indicator_count": 5937,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "620844f08a0cd181e13a81c0",
          "name": "Pegasus and Friends  2 - all touch by Pegasus or Variant in some way or another",
          "description": "",
          "modified": "2022-03-15T00:00:20.682000",
          "created": "2022-02-12T23:38:24.616000",
          "tags": [
            "whois record",
            "ssl certificate",
            "whois whois",
            "whois",
            "pegasus",
            "spyware"
          ],
          "references": [
            "https://pastebn.com/Q9qWTKsM",
            "https://pastebn.com/Q9qWTKsM/",
            "Graph by nilaymistry30",
            "https://www.virustotal.com/graph/g1143d9441bce4ab3b427b7bace69140516650b053aa4470584248657edc53ef3"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3217,
            "hostname": 1198,
            "domain": 312,
            "FileHash-SHA256": 1207,
            "FileHash-MD5": 3
          },
          "indicator_count": 5937,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 403,
          "modified_text": "1538 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://pastebn.com/Q9qWTKsM",
        "https://pastebn.com/Q9qWTKsM/",
        "https://www.virustotal.com/graph/g1143d9441bce4ab3b427b7bace69140516650b053aa4470584248657edc53ef3",
        "https://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf",
        "https://twitter.com/9bplus/status/1024714362244739073?s=21",
        "Graph by nilaymistry30",
        "https://github.com/eset/malware-ioc/tree/master/turla#to-the-moon-and-backdoors-lunar-landing-in-diplomatic-missionsindicators-of-compromise",
        "https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "Turla",
            "Turla Group"
          ],
          "malware_families": [],
          "industries": [
            "Government"
          ]
        },
        "other": {
          "adversary": [
            "Turla"
          ],
          "malware_families": [
            "Webglobe",
            "Turla",
            "Lunarweb",
            "Lunarmail",
            "Lunarloader"
          ],
          "industries": [
            "Government",
            "Diplomatic"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 9,
  "pulses": [
    {
      "id": "5b680d1afd6a3e5318179326",
      "name": "Turla Actors using Copied Cars.com Content",
      "description": "Starting in November of 2017, Turla actors appeared to start using website content copied from &quot;cars.com&quot; on their command and control channels.",
      "modified": "2018-08-06T08:55:54.534000",
      "created": "2018-08-06T08:55:54.534000",
      "tags": [
        "turla",
        "snake",
        "russia"
      ],
      "references": [
        "https://twitter.com/9bplus/status/1024714362244739073?s=21"
      ],
      "public": 1,
      "adversary": "Turla",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 44,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 5,
        "hostname": 264,
        "domain": 26
      },
      "indicator_count": 295,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386537,
      "modified_text": "2854 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5a55526949cace1e7e249928",
      "name": "Diplomats in Eastern Europe bitten by a Turla mosquito",
      "description": "Turla is one of the longest-known state-sponsored cyberespionage groups, with well-known victims\nsuch as the US Department of Defense in 2008. The group owns a large toolset that is generally\ndivided into several categories: the most advanced malware is only deployed on machines that are\nthe most interesting to the attackers. Their espionage platform is mainly used against Windows\nmachines, but also against macOS and Linux machines with various backdoors and a rootkit.\nFor years, Turla has relied, among other impersonations, on fake Flash installers to compromise\nvictims. This kind of attack vector does not require highly sophisticated exploits but rather depends\non tricking the user into installing the fake program.",
      "modified": "2018-01-09T23:38:17.150000",
      "created": "2018-01-09T23:38:17.150000",
      "tags": [
        "turla",
        "snake",
        "russia"
      ],
      "references": [
        "https://www.welivesecurity.com/wp-content/uploads/2018/01/ESET_Turla_Mosquito.pdf"
      ],
      "public": 1,
      "adversary": "Turla Group",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Government"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 85,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2,
        "hostname": 11,
        "domain": 3,
        "FileHash-SHA256": 14,
        "FileHash-MD5": 14,
        "FileHash-SHA1": 14
      },
      "indicator_count": 58,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386557,
      "modified_text": "3063 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5fa1ee5c64dc0e2060647954",
      "name": "Malware - Malware Domain Feed V2 - November 03 2020",
      "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
      "modified": "2026-05-31T01:17:54.397000",
      "created": "2020-11-03T23:57:16.317000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 130478,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "otxrobottwo_testing",
        "id": "83138",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45551,
        "domain": 66446
      },
      "indicator_count": 111997,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 971,
      "modified_text": "5 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6645e430dd6a9505cb9cd9ca",
      "name": "To the Moon and back(doors): Lunar landing in diplomatic missions",
      "description": "ESET Research has identified two backdoors used by the infamous Russian-aligned cyberespionage group, Turla, to compromise European diplomatic institutions in the Middle East and other parts of the world.",
      "modified": "2024-06-15T10:04:30.773000",
      "created": "2024-05-16T10:47:12.433000",
      "tags": [
        "lunarweb",
        "lunarmail",
        "strong",
        "c server",
        "eset research",
        "turla",
        "stage",
        "outlook",
        "aes256",
        "http",
        "powershell",
        "persistence",
        "win64",
        "format",
        "first",
        "tips",
        "snake",
        "defense",
        "smskey",
        "stages",
        "loader",
        "lightneuron",
        "execution",
        "ebury",
        "webglobe",
        "lunarloader",
        "gazer loader",
        "welivesecurity",
        "crypto",
        "compromise",
        "ltmanager",
        "carbon",
        "gazer",
        "mosquito",
        "armenia",
        "star",
        "dllinjector",
        "dropper",
        "comrat",
        "crutch",
        "footer"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/",
        "https://github.com/eset/malware-ioc/tree/master/turla#to-the-moon-and-backdoors-lunar-landing-in-diplomatic-missionsindicators-of-compromise"
      ],
      "public": 1,
      "adversary": "Turla",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Turla",
          "display_name": "Turla",
          "target": null
        },
        {
          "id": "Webglobe",
          "display_name": "Webglobe",
          "target": null
        },
        {
          "id": "LunarLoader",
          "display_name": "LunarLoader",
          "target": null
        },
        {
          "id": "LunarWeb",
          "display_name": "LunarWeb",
          "target": null
        },
        {
          "id": "LunarMail",
          "display_name": "LunarMail",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1020",
          "name": "Automated Exfiltration",
          "display_name": "T1020 - Automated Exfiltration"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1030",
          "name": "Data Transfer Size Limits",
          "display_name": "T1030 - Data Transfer Size Limits"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1137",
          "name": "Office Application Startup",
          "display_name": "T1137 - Office Application Startup"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1586",
          "name": "Compromise Accounts",
          "display_name": "T1586 - Compromise Accounts"
        },
        {
          "id": "T1587",
          "name": "Develop Capabilities",
          "display_name": "T1587 - Develop Capabilities"
        },
        {
          "id": "T1591",
          "name": "Gather Victim Org Information",
          "display_name": "T1591 - Gather Victim Org Information"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [
        "Diplomatic",
        "Government"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "bluenumberone",
        "id": "246058",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 27,
        "URL": 25,
        "FileHash-MD5": 59,
        "FileHash-SHA1": 128,
        "FileHash-SHA256": 59,
        "domain": 47,
        "email": 2
      },
      "indicator_count": 347,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 72,
      "modified_text": "714 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c2b5461ad2cb2f9e8d342d",
      "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
      "description": "",
      "modified": "2024-02-06T22:40:06.188000",
      "created": "2024-02-06T22:40:06.188000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "5fa1ee5c64dc0e2060647954",
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45530,
        "domain": 66406
      },
      "indicator_count": 111936,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "844 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c2b543bc2adfd3eca5ff2b",
      "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
      "description": "",
      "modified": "2024-02-06T22:40:03.501000",
      "created": "2024-02-06T22:40:03.501000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "5fa1ee5c64dc0e2060647954",
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45530,
        "domain": 66406
      },
      "indicator_count": 111936,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "844 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c2b5405e6e9e23324e6d8e",
      "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
      "description": "",
      "modified": "2024-02-06T22:40:00.906000",
      "created": "2024-02-06T22:40:00.906000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "5fa1ee5c64dc0e2060647954",
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45530,
        "domain": 66406
      },
      "indicator_count": 111936,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "844 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707dfb9f84eebbe3bdfe59",
      "name": "Pegasus and Friends  2 - all touch by Pegasus or Variant in some way or another",
      "description": "",
      "modified": "2023-12-06T13:58:18.607000",
      "created": "2023-12-06T13:58:18.607000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1207,
        "domain": 312,
        "hostname": 1198,
        "URL": 3217,
        "FileHash-MD5": 3
      },
      "indicator_count": 5937,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "620844f08a0cd181e13a81c0",
      "name": "Pegasus and Friends  2 - all touch by Pegasus or Variant in some way or another",
      "description": "",
      "modified": "2022-03-15T00:00:20.682000",
      "created": "2022-02-12T23:38:24.616000",
      "tags": [
        "whois record",
        "ssl certificate",
        "whois whois",
        "whois",
        "pegasus",
        "spyware"
      ],
      "references": [
        "https://pastebn.com/Q9qWTKsM",
        "https://pastebn.com/Q9qWTKsM/",
        "Graph by nilaymistry30",
        "https://www.virustotal.com/graph/g1143d9441bce4ab3b427b7bace69140516650b053aa4470584248657edc53ef3"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3217,
        "hostname": 1198,
        "domain": 312,
        "FileHash-SHA256": 1207,
        "FileHash-MD5": 3
      },
      "indicator_count": 5937,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 403,
      "modified_text": "1538 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "smallcloud.ga",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "smallcloud.ga",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780210967.433482
}