{
  "type": "Domain",
  "indicator": "tunneldrive.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/tunneldrive.com",
    "alexa": "http://www.alexa.com/siteinfo/tunneldrive.com",
    "indicator": "tunneldrive.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3398191988,
      "indicator": "tunneldrive.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 13,
      "pulses": [
        {
          "id": "642ede8fc5b3e870156bb050",
          "name": "CryptoClippy Speaks Portuguese",
          "description": "Unit 42 recently discovered a malware campaign targeting Portuguese speakers, which aims to redirect cryptocurrency away from legitimate users\u2019 wallets and into wallets controlled by threat actors instead. To do this, the campaign uses a type of malware known as a cryptocurrency clipper, which monitors the victim\u2019s clipboard for signs that a cryptocurrency wallet address is being copied.",
          "modified": "2023-04-06T15:00:29.864000",
          "created": "2023-04-06T15:00:29.864000",
          "tags": [
            "CryptoClippy",
            "Malvertising"
          ],
          "references": [
            "https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "CryptoClippy",
              "display_name": "CryptoClippy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 381,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 16,
            "domain": 6
          },
          "indicator_count": 26,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386594,
          "modified_text": "1151 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "659c73db79d680af1c1c8f69",
          "name": "Data Center [Pulse curated by StreamMiningEx]",
          "description": "",
          "modified": "2024-01-08T22:14:51.330000",
          "created": "2024-01-08T22:14:51.330000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6570a01137b1bcae30a77dfa",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-MD5": 255,
            "FileHash-SHA256": 1129,
            "hostname": 1306,
            "domain": 14829,
            "FileHash-SHA1": 45,
            "URL": 9697,
            "email": 5,
            "CIDR": 3
          },
          "indicator_count": 27271,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "874 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65539ae80b7b6e0d9c669216",
          "name": "Test Pulse",
          "description": "",
          "modified": "2023-12-16T16:02:10.435000",
          "created": "2023-11-14T16:06:00.013000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "gzerphPer",
            "id": "197016",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 3,
            "URL": 189,
            "FileHash-MD5": 442,
            "FileHash-SHA1": 395,
            "FileHash-SHA256": 659,
            "email": 1,
            "hostname": 298,
            "domain": 515,
            "FilePath": 12
          },
          "indicator_count": 2514,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1,
          "modified_text": "897 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a746daf9bcde6a5a80e9",
          "name": "SSDEEP",
          "description": "",
          "modified": "2023-12-06T16:54:27.604000",
          "created": "2023-12-06T16:54:27.604000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-MD5": 255,
            "FileHash-SHA256": 1129,
            "hostname": 1306,
            "domain": 14829,
            "FileHash-SHA1": 45,
            "URL": 9697,
            "email": 5,
            "CIDR": 3
          },
          "indicator_count": 27271,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 112,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a01137b1bcae30a77dfa",
          "name": "Data Center",
          "description": "",
          "modified": "2023-12-06T16:23:45.285000",
          "created": "2023-12-06T16:23:45.285000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-MD5": 255,
            "FileHash-SHA256": 1129,
            "hostname": 1306,
            "domain": 14829,
            "FileHash-SHA1": 45,
            "URL": 9697,
            "email": 5,
            "CIDR": 3
          },
          "indicator_count": 27271,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1fa4726c7449f379d172",
          "name": "SSDEEP",
          "description": "",
          "modified": "2023-10-30T03:14:44.205000",
          "created": "2023-10-30T03:14:44.205000",
          "tags": [
            "united",
            "as13335",
            "unknown",
            "search",
            "aaaa",
            "link",
            "accept encoding",
            "entries",
            "creation date",
            "record value",
            "date",
            "body",
            "cookie",
            "domain related",
            "showing",
            "maxage0",
            "colocation data",
            "maxage2592000",
            "acceptencoding",
            "centers",
            "powered shells",
            "sabey",
            "submission",
            "buildtosuit",
            "details links",
            "community",
            "join",
            "vt community",
            "api key",
            "virtual address",
            "virtual size",
            "raw size",
            "entropy",
            "sections",
            "functionality",
            "file type",
            "chi2",
            "contained",
            "us entropy",
            "ascii text",
            "rtmanifest",
            "rticon",
            "neutral",
            "sha256",
            "type rticon",
            "vhash",
            "imphash",
            "ssdeep",
            "win32 exe",
            "magic pe32",
            "ms windows",
            "intel",
            "trid generic",
            "cil executable",
            "mono"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65136e65a6a0e9d07117995a",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 284,
            "URL": 37584,
            "domain": 58771,
            "email": 23,
            "hostname": 4995,
            "FileHash-SHA256": 3633,
            "FileHash-SHA1": 57,
            "CIDR": 14,
            "CVE": 4
          },
          "indicator_count": 105365,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "944 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65136e65a6a0e9d07117995a",
          "name": "SSDEEP",
          "description": "",
          "modified": "2023-09-26T23:51:01.817000",
          "created": "2023-09-26T23:51:01.817000",
          "tags": [
            "united",
            "as13335",
            "unknown",
            "search",
            "aaaa",
            "link",
            "accept encoding",
            "entries",
            "creation date",
            "record value",
            "date",
            "body",
            "cookie",
            "domain related",
            "showing",
            "maxage0",
            "colocation data",
            "maxage2592000",
            "acceptencoding",
            "centers",
            "powered shells",
            "sabey",
            "submission",
            "buildtosuit",
            "details links",
            "community",
            "join",
            "vt community",
            "api key",
            "virtual address",
            "virtual size",
            "raw size",
            "entropy",
            "sections",
            "functionality",
            "file type",
            "chi2",
            "contained",
            "us entropy",
            "ascii text",
            "rtmanifest",
            "rticon",
            "neutral",
            "sha256",
            "type rticon",
            "vhash",
            "imphash",
            "ssdeep",
            "win32 exe",
            "magic pe32",
            "ms windows",
            "intel",
            "trid generic",
            "cil executable",
            "mono"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "64de492643ea275c2b0e2eb9",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 284,
            "URL": 37584,
            "domain": 58771,
            "email": 23,
            "hostname": 4995,
            "FileHash-SHA256": 3633,
            "FileHash-SHA1": 57,
            "CIDR": 14,
            "CVE": 4
          },
          "indicator_count": 105365,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 233,
          "modified_text": "978 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64de492643ea275c2b0e2eb9",
          "name": "Data Center",
          "description": "Tags:\ncve-2014-3931\nwise\ncve-2007-0943\ncve-2017-11882\nbobsoft\nbase64-embedded\ncve-2004-0566\ncve-2005-0233\ncontains-embedded-js\ncontains-elf\ncve-1999-0016\ncve-2017-1188\nattachment\ncve-2018-0802\nthemida\ncontains-pe\ncve-2018-0798\nupx\ncve-2016-0101",
          "modified": "2023-09-16T17:02:31.206000",
          "created": "2023-08-17T16:21:58.779000",
          "tags": [
            "united",
            "as13335",
            "unknown",
            "search",
            "aaaa",
            "link",
            "accept encoding",
            "entries",
            "creation date",
            "record value",
            "date",
            "body",
            "cookie",
            "domain related",
            "showing",
            "maxage0",
            "colocation data",
            "maxage2592000",
            "acceptencoding",
            "centers",
            "powered shells",
            "sabey",
            "submission",
            "buildtosuit",
            "details links",
            "community",
            "join",
            "vt community",
            "api key",
            "virtual address",
            "virtual size",
            "raw size",
            "entropy",
            "sections",
            "functionality",
            "file type",
            "chi2",
            "contained",
            "us entropy",
            "ascii text",
            "rtmanifest",
            "rticon",
            "neutral",
            "sha256",
            "type rticon",
            "vhash",
            "imphash",
            "ssdeep",
            "win32 exe",
            "magic pe32",
            "ms windows",
            "intel",
            "trid generic",
            "cil executable",
            "mono"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 284,
            "URL": 37584,
            "domain": 58771,
            "email": 23,
            "hostname": 4995,
            "FileHash-SHA256": 3633,
            "FileHash-SHA1": 57,
            "CIDR": 14,
            "CVE": 4
          },
          "indicator_count": 105365,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "988 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "642e8db62d651d47f1c69ec0",
          "name": "CryptoClippy Speaks Portuguese",
          "description": "A malware campaign targeting Portuguese speakers aims to steal cryptocurrency from legitimate users' wallets, according to Palo Alto Networks Unit 42 Managed Threat Hunting, which has recently discovered a new variant of the malware.",
          "modified": "2023-05-06T00:04:41.929000",
          "created": "2023-04-06T09:15:34.176000",
          "tags": [
            "cryptocurrency",
            "cryptoclippy",
            "figure",
            "exe file",
            "unit",
            "whatsapp web",
            "lnk file",
            "ethereum",
            "ethereum wallet",
            "palo alto",
            "stage",
            "powershell",
            "virustotal",
            "generator",
            "alliance",
            "smokeloader",
            "miner"
          ],
          "references": [
            "https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/"
          ],
          "public": 1,
          "adversary": "Cryptocurrency",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "CryptoClippy",
              "display_name": "CryptoClippy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            }
          ],
          "industries": [
            "Manufacturing"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3,
            "BitcoinAddress": 7,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 17,
            "domain": 6
          },
          "indicator_count": 37,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1122 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6430a56346b46e2ab89c9b0d",
          "name": "CryptoClippy: New Clipper Malware Targeting Portuguese Cryptocurrency Users",
          "description": "",
          "modified": "2023-04-07T23:21:07.297000",
          "created": "2023-04-07T23:21:07.297000",
          "tags": [
            "OSINT",
            "Cryptocurrency",
            "Clipper",
            "CryptoClippy",
            "T1129",
            "T1055",
            "T1036",
            "T1082",
            "T1027",
            "T1129"
          ],
          "references": [
            "https://community.riskiq.com/article/4d9d67c4"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 6,
            "FileHash-SHA256": 15
          },
          "indicator_count": 21,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "1150 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "642f381b5171ad6bb41717cc",
          "name": "New CryptoClippy Malware",
          "description": "",
          "modified": "2023-04-06T21:22:35.135000",
          "created": "2023-04-06T21:22:35.135000",
          "tags": [
            "public",
            "infrastructure"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 2,
            "domain": 6
          },
          "indicator_count": 12,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 499,
          "modified_text": "1151 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "642ee8462162bd8cd2d164e8",
          "name": "CryptoClippy: New Clipper Malware Targeting Portuguese Cryptocurrency Users",
          "description": "Portuguese users are being targeted by a new malware codenamed CryptoClippy that's capable of stealing cryptocurrency as part of a malvertising campaign.\n\nThe activity leverages SEO poisoning techniques to entice users searching for \"WhatsApp web\" to rogue domains hosting the malware, Palo Alto Networks Unit 42 said in a new report published today.\n\nCryptoClippy, a C-based executable, is a type of cryware known as clipper malware that monitors a victim's clipboard for content matching cryptocurrency addresses and substituting them with a wallet address under the threat actor's control.",
          "modified": "2023-04-06T15:41:58.210000",
          "created": "2023-04-06T15:41:58.210000",
          "tags": [
            "cryptocurrency",
            "cryptoclippy",
            "figure",
            "exe file",
            "unit",
            "whatsapp web",
            "lnk file",
            "ethereum",
            "ethereum wallet",
            "palo alto",
            "stage",
            "powershell",
            "virustotal",
            "generator",
            "alliance",
            "smokeloader",
            "miner"
          ],
          "references": [
            "https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/",
            "https://thehackernews.com/2023/04/cryptoclippy-new-clipper-malware.html"
          ],
          "public": 1,
          "adversary": "Cryptocurrency",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "CryptoClippy",
              "display_name": "CryptoClippy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            }
          ],
          "industries": [
            "Manufacturing"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 307,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dekaRituraj",
            "id": "99856",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_99856/resized/80/avatar_0e93d502b7.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "BitcoinAddress": 7,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 17,
            "domain": 6
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 433,
          "modified_text": "1151 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "622eba32db188ff0c42a97ce",
          "name": "NewDom-6-20220314",
          "description": "ICANN-Dom",
          "modified": "2022-04-28T00:00:15.198000",
          "created": "2022-03-14T03:44:50.454000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ZENDataGELowC",
            "id": "152785",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {},
          "indicator_count": 0,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 202,
          "modified_text": "1495 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 0
        }
      ],
      "references": [
        "https://community.riskiq.com/article/4d9d67c4",
        "https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/",
        "https://thehackernews.com/2023/04/cryptoclippy-new-clipper-malware.html"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [
            "Cryptoclippy"
          ],
          "industries": []
        },
        "other": {
          "adversary": [
            "Cryptocurrency"
          ],
          "malware_families": [
            "Cryptoclippy"
          ],
          "industries": [
            "Manufacturing"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 13,
  "pulses": [
    {
      "id": "642ede8fc5b3e870156bb050",
      "name": "CryptoClippy Speaks Portuguese",
      "description": "Unit 42 recently discovered a malware campaign targeting Portuguese speakers, which aims to redirect cryptocurrency away from legitimate users\u2019 wallets and into wallets controlled by threat actors instead. To do this, the campaign uses a type of malware known as a cryptocurrency clipper, which monitors the victim\u2019s clipboard for signs that a cryptocurrency wallet address is being copied.",
      "modified": "2023-04-06T15:00:29.864000",
      "created": "2023-04-06T15:00:29.864000",
      "tags": [
        "CryptoClippy",
        "Malvertising"
      ],
      "references": [
        "https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "CryptoClippy",
          "display_name": "CryptoClippy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1104",
          "name": "Multi-Stage Channels",
          "display_name": "T1104 - Multi-Stage Channels"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1127",
          "name": "Trusted Developer Utilities Proxy Execution",
          "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 381,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 16,
        "domain": 6
      },
      "indicator_count": 26,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386594,
      "modified_text": "1151 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "659c73db79d680af1c1c8f69",
      "name": "Data Center [Pulse curated by StreamMiningEx]",
      "description": "",
      "modified": "2024-01-08T22:14:51.330000",
      "created": "2024-01-08T22:14:51.330000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6570a01137b1bcae30a77dfa",
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 2,
        "FileHash-MD5": 255,
        "FileHash-SHA256": 1129,
        "hostname": 1306,
        "domain": 14829,
        "FileHash-SHA1": 45,
        "URL": 9697,
        "email": 5,
        "CIDR": 3
      },
      "indicator_count": 27271,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "874 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65539ae80b7b6e0d9c669216",
      "name": "Test Pulse",
      "description": "",
      "modified": "2023-12-16T16:02:10.435000",
      "created": "2023-11-14T16:06:00.013000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "gzerphPer",
        "id": "197016",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 3,
        "URL": 189,
        "FileHash-MD5": 442,
        "FileHash-SHA1": 395,
        "FileHash-SHA256": 659,
        "email": 1,
        "hostname": 298,
        "domain": 515,
        "FilePath": 12
      },
      "indicator_count": 2514,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1,
      "modified_text": "897 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a746daf9bcde6a5a80e9",
      "name": "SSDEEP",
      "description": "",
      "modified": "2023-12-06T16:54:27.604000",
      "created": "2023-12-06T16:54:27.604000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 2,
        "FileHash-MD5": 255,
        "FileHash-SHA256": 1129,
        "hostname": 1306,
        "domain": 14829,
        "FileHash-SHA1": 45,
        "URL": 9697,
        "email": 5,
        "CIDR": 3
      },
      "indicator_count": 27271,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 112,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a01137b1bcae30a77dfa",
      "name": "Data Center",
      "description": "",
      "modified": "2023-12-06T16:23:45.285000",
      "created": "2023-12-06T16:23:45.285000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 2,
        "FileHash-MD5": 255,
        "FileHash-SHA256": 1129,
        "hostname": 1306,
        "domain": 14829,
        "FileHash-SHA1": 45,
        "URL": 9697,
        "email": 5,
        "CIDR": 3
      },
      "indicator_count": 27271,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f1fa4726c7449f379d172",
      "name": "SSDEEP",
      "description": "",
      "modified": "2023-10-30T03:14:44.205000",
      "created": "2023-10-30T03:14:44.205000",
      "tags": [
        "united",
        "as13335",
        "unknown",
        "search",
        "aaaa",
        "link",
        "accept encoding",
        "entries",
        "creation date",
        "record value",
        "date",
        "body",
        "cookie",
        "domain related",
        "showing",
        "maxage0",
        "colocation data",
        "maxage2592000",
        "acceptencoding",
        "centers",
        "powered shells",
        "sabey",
        "submission",
        "buildtosuit",
        "details links",
        "community",
        "join",
        "vt community",
        "api key",
        "virtual address",
        "virtual size",
        "raw size",
        "entropy",
        "sections",
        "functionality",
        "file type",
        "chi2",
        "contained",
        "us entropy",
        "ascii text",
        "rtmanifest",
        "rticon",
        "neutral",
        "sha256",
        "type rticon",
        "vhash",
        "imphash",
        "ssdeep",
        "win32 exe",
        "magic pe32",
        "ms windows",
        "intel",
        "trid generic",
        "cil executable",
        "mono"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65136e65a6a0e9d07117995a",
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 284,
        "URL": 37584,
        "domain": 58771,
        "email": 23,
        "hostname": 4995,
        "FileHash-SHA256": 3633,
        "FileHash-SHA1": 57,
        "CIDR": 14,
        "CVE": 4
      },
      "indicator_count": 105365,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "944 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65136e65a6a0e9d07117995a",
      "name": "SSDEEP",
      "description": "",
      "modified": "2023-09-26T23:51:01.817000",
      "created": "2023-09-26T23:51:01.817000",
      "tags": [
        "united",
        "as13335",
        "unknown",
        "search",
        "aaaa",
        "link",
        "accept encoding",
        "entries",
        "creation date",
        "record value",
        "date",
        "body",
        "cookie",
        "domain related",
        "showing",
        "maxage0",
        "colocation data",
        "maxage2592000",
        "acceptencoding",
        "centers",
        "powered shells",
        "sabey",
        "submission",
        "buildtosuit",
        "details links",
        "community",
        "join",
        "vt community",
        "api key",
        "virtual address",
        "virtual size",
        "raw size",
        "entropy",
        "sections",
        "functionality",
        "file type",
        "chi2",
        "contained",
        "us entropy",
        "ascii text",
        "rtmanifest",
        "rticon",
        "neutral",
        "sha256",
        "type rticon",
        "vhash",
        "imphash",
        "ssdeep",
        "win32 exe",
        "magic pe32",
        "ms windows",
        "intel",
        "trid generic",
        "cil executable",
        "mono"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "64de492643ea275c2b0e2eb9",
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 284,
        "URL": 37584,
        "domain": 58771,
        "email": 23,
        "hostname": 4995,
        "FileHash-SHA256": 3633,
        "FileHash-SHA1": 57,
        "CIDR": 14,
        "CVE": 4
      },
      "indicator_count": 105365,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 233,
      "modified_text": "978 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "64de492643ea275c2b0e2eb9",
      "name": "Data Center",
      "description": "Tags:\ncve-2014-3931\nwise\ncve-2007-0943\ncve-2017-11882\nbobsoft\nbase64-embedded\ncve-2004-0566\ncve-2005-0233\ncontains-embedded-js\ncontains-elf\ncve-1999-0016\ncve-2017-1188\nattachment\ncve-2018-0802\nthemida\ncontains-pe\ncve-2018-0798\nupx\ncve-2016-0101",
      "modified": "2023-09-16T17:02:31.206000",
      "created": "2023-08-17T16:21:58.779000",
      "tags": [
        "united",
        "as13335",
        "unknown",
        "search",
        "aaaa",
        "link",
        "accept encoding",
        "entries",
        "creation date",
        "record value",
        "date",
        "body",
        "cookie",
        "domain related",
        "showing",
        "maxage0",
        "colocation data",
        "maxage2592000",
        "acceptencoding",
        "centers",
        "powered shells",
        "sabey",
        "submission",
        "buildtosuit",
        "details links",
        "community",
        "join",
        "vt community",
        "api key",
        "virtual address",
        "virtual size",
        "raw size",
        "entropy",
        "sections",
        "functionality",
        "file type",
        "chi2",
        "contained",
        "us entropy",
        "ascii text",
        "rtmanifest",
        "rticon",
        "neutral",
        "sha256",
        "type rticon",
        "vhash",
        "imphash",
        "ssdeep",
        "win32 exe",
        "magic pe32",
        "ms windows",
        "intel",
        "trid generic",
        "cil executable",
        "mono"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 284,
        "URL": 37584,
        "domain": 58771,
        "email": 23,
        "hostname": 4995,
        "FileHash-SHA256": 3633,
        "FileHash-SHA1": 57,
        "CIDR": 14,
        "CVE": 4
      },
      "indicator_count": 105365,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 225,
      "modified_text": "988 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "642e8db62d651d47f1c69ec0",
      "name": "CryptoClippy Speaks Portuguese",
      "description": "A malware campaign targeting Portuguese speakers aims to steal cryptocurrency from legitimate users' wallets, according to Palo Alto Networks Unit 42 Managed Threat Hunting, which has recently discovered a new variant of the malware.",
      "modified": "2023-05-06T00:04:41.929000",
      "created": "2023-04-06T09:15:34.176000",
      "tags": [
        "cryptocurrency",
        "cryptoclippy",
        "figure",
        "exe file",
        "unit",
        "whatsapp web",
        "lnk file",
        "ethereum",
        "ethereum wallet",
        "palo alto",
        "stage",
        "powershell",
        "virustotal",
        "generator",
        "alliance",
        "smokeloader",
        "miner"
      ],
      "references": [
        "https://unit42.paloaltonetworks.com/crypto-clipper-targets-portuguese-speakers/"
      ],
      "public": 1,
      "adversary": "Cryptocurrency",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "CryptoClippy",
          "display_name": "CryptoClippy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1104",
          "name": "Multi-Stage Channels",
          "display_name": "T1104 - Multi-Stage Channels"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1127",
          "name": "Trusted Developer Utilities Proxy Execution",
          "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        }
      ],
      "industries": [
        "Manufacturing"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3,
        "BitcoinAddress": 7,
        "FileHash-MD5": 3,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 17,
        "domain": 6
      },
      "indicator_count": 37,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "1122 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6430a56346b46e2ab89c9b0d",
      "name": "CryptoClippy: New Clipper Malware Targeting Portuguese Cryptocurrency Users",
      "description": "",
      "modified": "2023-04-07T23:21:07.297000",
      "created": "2023-04-07T23:21:07.297000",
      "tags": [
        "OSINT",
        "Cryptocurrency",
        "Clipper",
        "CryptoClippy",
        "T1129",
        "T1055",
        "T1036",
        "T1082",
        "T1027",
        "T1129"
      ],
      "references": [
        "https://community.riskiq.com/article/4d9d67c4"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 6,
        "FileHash-SHA256": 15
      },
      "indicator_count": 21,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1621,
      "modified_text": "1150 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "tunneldrive.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "tunneldrive.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780274360.8360646
}