{
  "type": "Domain",
  "indicator": "stg.lsmartv.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/stg.lsmartv.com",
    "alexa": "http://www.alexa.com/siteinfo/stg.lsmartv.com",
    "indicator": "stg.lsmartv.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {},
    "pulse_info": {
      "count": 0,
      "pulses": [],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 1,
  "pulses": [
    {
      "id": "69e9d8ba4c0b0df25b764711",
      "name": "Malicious Campaign Deploying AdaptixC2 Beacon and VS Code via Trojanized SumatraPDF",
      "description": "On March 12, 2026, a sophisticated attack campaign was identified targeting Chinese-speaking individuals using military-themed document lures distributed through a malicious ZIP archive. The operation employed a trojanized SumatraPDF binary as the initial vector to deploy an AdaptixC2 Beacon and Visual Studio Code on victim systems. The shellcode loader demonstrated significant similarities to the TOSHIS loader previously linked to TAOTH campaigns. Attackers established a custom AdaptixC2 Beacon listener utilizing GitHub for command-and-control infrastructure. The staging server infrastructure additionally hosted CobaltStrike Beacon and EntryShell backdoor, both previously associated with this threat group. The campaign infrastructure included multiple compromised domains and IP addresses for malware distribution and C2 communications.",
      "author_name": "AlienVault",
      "modified": "2026-05-23T08:20:01.501000",
      "created": "2026-04-23T08:30:50.632000",
      "revision": 2,
      "tlp": "white",
      "public": 1,
      "adversary": "Tropic Trooper",
      "indicators": [
        {
          "id": 4324125661,
          "indicator": "2d7cc3646c287d6355def362916c6d26",
          "type": "FileHash-MD5",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125662,
          "indicator": "3238d2f6b9ea9825eb61ae5e80e7365c",
          "type": "FileHash-MD5",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125663,
          "indicator": "67fcf5c21474d314aa0b27b0ce8befb2",
          "type": "FileHash-MD5",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125664,
          "indicator": "71fa755b6ba012e1713c9101c7329f8d",
          "type": "FileHash-MD5",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125665,
          "indicator": "89daa54fada8798c5f4e21738c8ea0b4",
          "type": "FileHash-MD5",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125666,
          "indicator": "9a69b717ec4e8a35ae595aa6762d3c27",
          "type": "FileHash-MD5",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125667,
          "indicator": "c620b4671a5715eec0e9f3b93e6532ba",
          "type": "FileHash-MD5",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125668,
          "indicator": "e2dc48ef24da000b8fc1354fa31ca9ae",
          "type": "FileHash-MD5",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125669,
          "indicator": "19e3c4df728e3e657cb9496cd4aaf69648470b63",
          "type": "FileHash-SHA1",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125670,
          "indicator": "2c65433696037f4ce0f8c9a1d78bdd6835c1b94d",
          "type": "FileHash-SHA1",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125671,
          "indicator": "343be0f2077901ea5b5b9fb97d97892ac1a907e6",
          "type": "FileHash-SHA1",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125672,
          "indicator": "401cc16d79d94c32da3f66df21d66ffd71603c14",
          "type": "FileHash-SHA1",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125673,
          "indicator": "6c68dc2e33780e07596c3c06aa819ea460b3d125",
          "type": "FileHash-SHA1",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125674,
          "indicator": "adb47733c224fc8c0f7edc61becb578e560435ab",
          "type": "FileHash-SHA1",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125675,
          "indicator": "bd618c9e1e10891fe666839650fa406833d70afd",
          "type": "FileHash-SHA1",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125676,
          "indicator": "c2051635ccfdc0b48c260e7ceeee3f96bf026fea",
          "type": "FileHash-SHA1",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125677,
          "indicator": "3936f522f187f8f67dda3dc88abfd170f6ba873af81fc31bbf1fdbcad1b2a7fb",
          "type": "FileHash-SHA256",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125678,
          "indicator": "3c29c72a59133dd9eb23953211129fd8275a11b91a3b8dddb3c6e502b6b63edb",
          "type": "FileHash-SHA256",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125679,
          "indicator": "47c7ce0e3816647b23bb180725c7233e505f61c35e7776d47fd448009e887857",
          "type": "FileHash-SHA256",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125680,
          "indicator": "6eaea92394e115cd6d5bab9ae1c6d088806229aae320e6c519c2d2210dbc94fe",
          "type": "FileHash-SHA256",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125681,
          "indicator": "7a95ce0b5f201d9880a6844a1db69aac7d1a0bf1c88f85989264caf6c82c6001",
          "type": "FileHash-SHA256",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125682,
          "indicator": "a4f2131eb497afe5f78d8d6e534df2b8d75c5b9b565c3ec17a323afe5355da26",
          "type": "FileHash-SHA256",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125683,
          "indicator": "aeec65bac035789073b567753284b64ce0b95bbae62cf79e1479714238af0eb7",
          "type": "FileHash-SHA256",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125684,
          "indicator": "b92a3a1cf5786b6e08643483387b77640cd44f84df1169dd00efde7af46b5714",
          "type": "FileHash-SHA256",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125687,
          "indicator": "https://47.76.236.58:4430/Divide/developement/GIZWQVCLF",
          "type": "URL",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125688,
          "indicator": "https://47.76.236.58:4430/Originate/contacts/CX4YJ5JI7RZ",
          "type": "URL",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125689,
          "indicator": "https://stg.lsmartv.com:8443/Divide/developement/GIZWQVCLF",
          "type": "URL",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125690,
          "indicator": "https://stg.lsmartv.com:8443/Originate/contacts/CX4YJ5JI7RZ",
          "type": "URL",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        },
        {
          "id": 4324125691,
          "indicator": "stg.lsmartv.com",
          "type": "hostname",
          "created": "2026-04-23T08:30:51",
          "content": "",
          "title": "",
          "description": "",
          "expiration": null,
          "is_active": 1,
          "role": null
        }
      ],
      "tags": [
        "sumatrapdf",
        "cobaltstrike",
        "adaptixc2 beacon",
        "entryshell",
        "toshis",
        "tropic trooper",
        "chinese targets",
        "cobaltstrike beacon",
        "toshis loader",
        "adaptixc2",
        "github c2"
      ],
      "targeted_countries": [],
      "malware_families": [
        "AdaptixC2 Beacon",
        "CobaltStrike Beacon",
        "EntryShell",
        "TOSHIS"
      ],
      "attack_ids": [
        "T1036.005",
        "T1204.002",
        "T1566.001",
        "T1082",
        "T1140",
        "T1055",
        "T1218",
        "T1059",
        "T1083",
        "T1102",
        "T1547.001",
        "T1027",
        "T1573",
        "T1070.004",
        "T1027.002",
        "T1071.001",
        "T1105"
      ],
      "references": [],
      "industries": [],
      "extract_source": [],
      "more_indicators": false,
      "indicator_count": 31
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "stg.lsmartv.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "stg.lsmartv.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780177597.369623
}