{
  "type": "Domain",
  "indicator": "turnscor.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/turnscor.com",
    "alexa": "http://www.alexa.com/siteinfo/turnscor.com",
    "indicator": "turnscor.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2750839838,
      "indicator": "turnscor.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 27,
      "pulses": [
        {
          "id": "68b9d266a57b122998115dc6",
          "name": "Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms",
          "description": "North Korean threat actors associated with the Contagious Interview campaign cluster are actively monitoring cyber threat intelligence platforms to detect infrastructure exposure and scout for new assets. They operate in coordinated teams, likely using Slack for real-time collaboration, and leverage multiple intelligence sources including Validin, VirusTotal, and Maltrail. Despite being aware of their infrastructure's detectability, they make only limited changes to reduce detection risk, focusing instead on rapidly deploying new infrastructure to sustain operations. The actors' effectiveness is evident in their engagement of over 230 victims between January and March 2025, primarily targeting individuals in the cryptocurrency industry. Their activities involve sophisticated social engineering tactics, including the ClickFix technique, to trick targets into executing malware.",
          "modified": "2025-10-04T17:00:59.344000",
          "created": "2025-09-04T17:54:46.837000",
          "tags": [
            "cyber espionage",
            "social engineering",
            "north korea",
            "job seeker targeting",
            "clickfix",
            "lazarus",
            "infrastructure monitoring",
            "cryptocurrency",
            "contagiousdrop"
          ],
          "references": [
            "https://www.sentinelone.com/labs/contagious-interview-threat-actors-scout-cyber-intel-platforms-reveal-plans-and-ops"
          ],
          "public": 1,
          "adversary": "Contagious Interview",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1589",
              "name": "Gather Victim Identity Information",
              "display_name": "T1589 - Gather Victim Identity Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1586",
              "name": "Compromise Accounts",
              "display_name": "T1586 - Compromise Accounts"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1585",
              "name": "Establish Accounts",
              "display_name": "T1585 - Establish Accounts"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            }
          ],
          "industries": [
            "Finance",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 44164,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 116,
            "FileHash-SHA1": 99,
            "FileHash-SHA256": 246,
            "CVE": 1,
            "domain": 2140,
            "hostname": 1231
          },
          "indicator_count": 3833,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 387149,
          "modified_text": "242 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6516dc1c66c2a9a03166669f",
          "name": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
          "description": "The fake recruiter contacted the victim via LinkedIn Messaging, a feature within the LinkedIn professional social networking platform, and sent two coding challenges required as part of a hiring process, which the victim downloaded and executed on a company device. The first challenge is a very basic project that displays the text \u201cHello, World!\u201d, the second one prints a Fibonacci sequence \u2013 a series of numbers in which each number is the sum of the two preceding ones. ESET Research was able to reconstruct the initial access steps and analyze the toolset used by Lazarus thanks to cooperation with the affected aerospace company.",
          "modified": "2023-10-29T14:01:08.677000",
          "created": "2023-09-29T14:15:55.789000",
          "tags": [
            "LinkedIn",
            "Lazarus",
            "cyberespionage",
            "NickelLoader",
            "RAT",
            "LightlessCan",
            "miniBlindingCan"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Spain"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1585",
              "name": "Establish Accounts",
              "display_name": "T1585 - Establish Accounts"
            },
            {
              "id": "T1593",
              "name": "Search Open Websites/Domains",
              "display_name": "T1593 - Search Open Websites/Domains"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 418,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 13,
            "domain": 5,
            "hostname": 5
          },
          "indicator_count": 23,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 387150,
          "modified_text": "948 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f46a108000bd36fe90d5be",
          "name": "APT29",
          "description": "In the latest episode of the LNK forensic analysis series, we look at how a malicious file was linked to a Chinese-speaking threat actor, who then modified the file to target a powershell program.",
          "modified": "2026-05-31T06:03:25.904000",
          "created": "2026-05-01T08:53:34.200000",
          "tags": [
            "sha1",
            "ipv4",
            "sha256",
            "n cobalt",
            "n https",
            "strong",
            "rararchive",
            "backdoor",
            "n c2",
            "cobalt strike",
            "guloader",
            "cobaltstrike",
            "cobalt",
            "downloader",
            "april",
            "icedid",
            "dropper",
            "june",
            "trickbot",
            "donut",
            "fast",
            "payload",
            "unknown",
            "delphi",
            "noname",
            "anydesk",
            "blister",
            "quasar",
            "winnti",
            "somnia",
            "qakbot",
            "gogo",
            "netwire",
            "chrysalis",
            "download",
            "exploit",
            "netspy",
            "loader",
            "ursnif",
            "themida",
            "vidar",
            "doublezero",
            "voldemort",
            "next",
            "meterpreter",
            "tencent",
            "plugx",
            "shadow",
            "batloader",
            "redline stealer",
            "havoc",
            "resident",
            "decoy",
            "dump",
            "shellcode",
            "infostealer",
            "appe",
            "bumblebee",
            "emotet",
            "syscall",
            "acidrain",
            "credomap",
            "cozyduke",
            "ukraine",
            "daveshell",
            "cont",
            "refer",
            "fail",
            "first",
            "snake",
            "mega",
            "onlin",
            "grayrabbit",
            "open",
            "power",
            "august",
            "test",
            "path",
            "mimikatz",
            "nbtscan",
            "impacket",
            "comment",
            "install",
            "redline",
            "comet",
            "autoit",
            "wiper",
            "endurance",
            "sharphound",
            "psexec",
            "malicious",
            "service",
            "wind",
            "installer",
            "info",
            "confi",
            "remcosrat",
            "hermeticwiper",
            "isaacwiper",
            "graphsteel",
            "caddywiper",
            "grimplant",
            "industroyer2",
            "defense",
            "energy",
            "telecom",
            "media",
            "grapeloader",
            "wineloader",
            "envyscout",
            "sunburst",
            "panda",
            "metasploit",
            "sparkrat",
            "zbot",
            "darkgate",
            "finspy",
            "rhadamanthys",
            "warmcookie",
            "trojanspy",
            "diceloader",
            "asyncrat",
            "esxiargs",
            "webshell",
            "cerber",
            "azorult",
            "lokibot",
            "blackcat",
            "poortry",
            "cuba",
            "malcat",
            "ctrlt",
            "transform",
            "bazaar",
            "virustotal",
            "window",
            "pdf document",
            "iit app",
            "tools",
            "lucky",
            "injector",
            "handleref",
            "temp",
            "conti",
            "groupexchange",
            "group400",
            "grouprevil",
            "revilconti",
            "providerpath",
            "regexpandsz",
            "minidump",
            "groupuchebkac",
            "malware",
            "bypass",
            "adfind",
            "threat",
            "command",
            "procdump",
            "seatbelt",
            "below",
            "anydesk remote",
            "lsass",
            "powershell",
            "cookie",
            "android",
            "null",
            "sliver",
            "initial access",
            "code",
            "defender",
            "defense evasion",
            "enterprise",
            "powerview",
            "pipes",
            "cloud",
            "date",
            "poison",
            "advantage",
            "mind",
            "designer",
            "shell",
            "projector libra",
            "bazarloader",
            "figure",
            "file size",
            "transferxl",
            "palo alto",
            "iso image",
            "windows",
            "wildfire",
            "february",
            "alliance",
            "bazarbackdoor",
            "bokbot",
            "diavol",
            "shown",
            "hook",
            "threat spotlight",
            "manjusaka",
            "c2 server",
            "appliance",
            "cisco talos",
            "golang",
            "haixi mongol",
            "prefecture",
            "talos",
            "rust",
            "agent",
            "win64",
            "hello",
            "xor algorithms",
            "z85 ascii85",
            "base85",
            "ascii85",
            "compile",
            "z85 https",
            "threat analysis",
            "primary threat",
            "elf",
            "strike payload",
            "uri http",
            "post body",
            "lockbit",
            "sentinellabs",
            "c curl",
            "ip address",
            "lockbit black",
            "cyber threats",
            "investigations",
            "research",
            "expert perspective",
            "articles",
            "news",
            "reports",
            "learn",
            "trend vision",
            "vision one",
            "gootkit",
            "trend micro",
            "amsi telemetry",
            "micro",
            "gootkit loader",
            "security",
            "stop",
            "find",
            "life",
            "operations",
            "protect",
            "small",
            "carriers",
            "voice",
            "attack",
            "suncrypt",
            "revil",
            "sodinokibi",
            "kronos",
            "korean",
            "createobject",
            "javascript",
            "ascii value",
            "opens",
            "urls",
            "color1",
            "python script",
            "gootloader",
            "twitter",
            "python",
            "unc1151",
            "microbackdoor",
            "beacon",
            "base64",
            "github",
            "run registry",
            "putty",
            "persistence",
            "discord",
            "blackenergy",
            "state",
            "uac0056",
            "detection",
            "threatdown",
            "cybercrime has",
            "machinescale",
            "response",
            "nebula",
            "indirizzo",
            "il file",
            "questo cert",
            "italia",
            "il messaggio",
            "allegato",
            "covid19",
            "file pdf",
            "html",
            "serbia",
            "stata",
            "file location",
            "https traffic",
            "thursday",
            "windows host",
            "wireshark",
            "emotet run",
            "pakistan",
            "ttps",
            "shadowpad",
            "plugx backdoor",
            "kaspersky ics",
            "afghanistan",
            "malaysia",
            "march",
            "cert",
            "ntlm",
            "winrar",
            "assembly",
            "china chopper",
            "microsoft",
            "fancybear",
            "cozybear",
            "december",
            "strontium",
            "ransomhub",
            "matrix",
            "raspberry robin",
            "sofacy",
            "beatdrop",
            "quietexit",
            "cyclops",
            "knight",
            "bank",
            "facebook",
            "beer",
            "worm",
            "threat advisory",
            "ransomware",
            "threats",
            "securex",
            "avos",
            "unified access",
            "gateways",
            "avoslocker",
            "cisco secure",
            "vmware horizon",
            "darkcomet",
            "apt29",
            "nobelium",
            "stellarparticle",
            "shadow chaser",
            "file type",
            "sha256 hash",
            "html file",
            "pe32",
            "intel",
            "matanbuchus",
            "confluence",
            "data center",
            "server",
            "waf rule",
            "confluence data",
            "shut",
            "jars",
            "cvss",
            "update",
            "centerall",
            "mustang panda",
            "vietnam",
            "analyze",
            "dll file",
            "summary",
            "vincss",
            "vietnamese",
            "english",
            "unc2165",
            "evil corp",
            "fakeupdates",
            "dridex",
            "hades",
            "colorfake",
            "bitpaymer",
            "doppelpaymer",
            "wastedlocker",
            "megasync",
            "trojan",
            "payloadbin",
            "macaw",
            "cuba ransomware",
            "tor directory",
            "bughatch",
            "iis worker",
            "mare",
            "team",
            "zenpak",
            "impact",
            "mosquito",
            "exfiltration",
            "execution",
            "masquerading",
            "netsupport rat",
            "select",
            "script",
            "hash",
            "press enter",
            "http",
            "activexobject",
            "lnk file",
            "socgholish",
            "servhelper",
            "fakeupdate",
            "model",
            "socgholish netsupport",
            "netsupport",
            "ta551",
            "ryuk",
            "threat actor",
            "hta file",
            "trickbot c2",
            "sonatype",
            "drops cobalt",
            "strike",
            "pymafka",
            "open source",
            "contact us",
            "macos",
            "nexus",
            "demo",
            "protected",
            "friday",
            "gold blackburn",
            "ahnlab",
            "was1",
            "was2",
            "dc server",
            "coinminer",
            "ntlm hash",
            "january",
            "ad group",
            "darkside",
            "miner",
            "win32.bitcoinminer",
            "win32.agent",
            "frp",
            "transferxl url",
            "iso file",
            "bumblebee c2",
            "file name",
            "exotic lily",
            "transferxl urls",
            "function",
            "dropbox",
            "c2 dropbox",
            "c2clientmain",
            "filename",
            "av evasion",
            "syswhispers2",
            "dropbox loader",
            "stream",
            "mark",
            "back",
            "pcap",
            "ta578",
            "contact forms",
            "images evidence",
            "windows service",
            "main entry",
            "a service",
            "service main",
            "entry point",
            "windows context",
            "administrator",
            "concept",
            "https",
            "lazagne",
            "setmppreference",
            "use ie",
            "msie",
            "windows nt",
            "bloodhound",
            "wmiexec",
            "covenant",
            "empire",
            "poshc2",
            "organization",
            "cleanup",
            "winscp",
            "dword",
            "netscan",
            "http c2",
            "base64url",
            "c2 traffic",
            "netbios",
            "teamserver",
            "mask",
            "legezo",
            "windows event",
            "denis legezo",
            "september",
            "silent break",
            "windows system",
            "rc4 encryption",
            "sysdig",
            "plugx implant",
            "myanmar",
            "russia",
            "hong kong",
            "reddelta",
            "belarus",
            "digital certificates",
            "fileless malware",
            "malware descriptions",
            "malware technologies",
            "rat trojan",
            "targeted attacks",
            "silentbreak",
            "throwback",
            "linode",
            "slingshot",
            "inject",
            "patch",
            "magic",
            "mozilla",
            "false",
            "\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3",
            "\u30de\u30af\u30cb\u30ab\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9",
            "word",
            "stager",
            "url https",
            "windows10",
            "dll sideloading",
            "ida pro",
            "darkhotel",
            "oceanlotus",
            "mandiant",
            "boommic",
            "group policy",
            "smb beacon",
            "trello",
            "kerberos",
            "pass",
            "vaporrage",
            "platform sha256",
            "urls http",
            "unc2452",
            "opsec",
            "scale",
            "apt29 activity",
            "apt29 conduct",
            "global func",
            "vmware xfer",
            "edrepp",
            "vmware command",
            "dfir team",
            "abcd",
            "stealbit",
            "stdout",
            "hooks",
            "logic",
            "dfir report",
            "icedid malware",
            "icedid payload",
            "pty ltd",
            "goodware",
            "string",
            "desktop",
            "morphisec",
            "vmware identity",
            "morphisec labs",
            "core impact",
            "vmware",
            "workspace one",
            "access",
            "cve202222957",
            "cve202222958",
            "fortune",
            "jssloader",
            "stark",
            "moving",
            "please",
            "virtualbox",
            "registry",
            "windows logon",
            "hive",
            "varonis",
            "ai security",
            "proxyshell",
            "detect",
            "data risk",
            "google cloud",
            "trust",
            "varonis threat",
            "contact",
            "qbot",
            "void",
            "police",
            "pysa",
            "chisel",
            "files",
            "where",
            "pysa ransomware",
            "redacted",
            "force",
            "getchilditem",
            "aes key",
            "szdrf",
            "mespinoza",
            "target",
            "winapi",
            "edr hooks",
            "winapi call",
            "endpoint",
            "tracing",
            "api call",
            "direct system",
            "phase",
            "import",
            "outflank",
            "dll payload",
            "bumblebee dll",
            "programdata",
            "orion",
            "strings",
            "example",
            "zloader",
            "eset research",
            "atera agent",
            "eset",
            "aitb",
            "eset security",
            "tips",
            "silent",
            "night",
            "botnet",
            "teamviewer",
            "atera",
            "capture",
            "grantedaccess",
            "computer",
            "lsass memory",
            "targetimage",
            "sourceimage",
            "simulate",
            "atomic",
            "karakurt",
            "view",
            "hacking team",
            "sign",
            "contributors",
            "from karakurt",
            "appearance",
            "manage",
            "write",
            "star",
            "stars",
            "ruby",
            "footer",
            "birdwatch",
            "fin7",
            "easylook",
            "unc3381",
            "powerplant",
            "crowview",
            "boatlaunch",
            "stoneboat",
            "fowlgaze",
            "uuid variant",
            "hell",
            "ipfuscation",
            "james haughom",
            "ipfuscated",
            "gate variant",
            "gate",
            "rubeus",
            "wow64",
            "cp1250",
            "uuids",
            "touch",
            "blob",
            "hwinithlw",
            "sphw",
            "shathak",
            "conti affiliate",
            "valentine",
            "favorite",
            "rats",
            "ragnarlocker",
            "hellokitty",
            "squirrelwaffle",
            "uris",
            "http get",
            "post",
            "http post",
            "c2 profile",
            "accept",
            "vnc activity",
            "ms windows",
            "go downloader",
            "unc2589",
            "ta471",
            "sentinelone",
            "module stomp",
            "return address",
            "cobalt strikes",
            "rtlallocateheap",
            "use section",
            "dlls",
            "first detection",
            "apt41",
            "dustpan",
            "cve202144207",
            "cve202144228",
            "log4shell",
            "vmprotect",
            "deadeye",
            "keyplug",
            "filler",
            "confuserex",
            "badpotato",
            "task manager",
            "lsass process",
            "cisa",
            "bazar",
            "hancitor",
            "splashtop",
            "kportscan",
            "story",
            "emotet payload",
            "excel",
            "appdatalocal",
            "november",
            "emotet campaign",
            "vba macro",
            "cybercrime",
            "cybersecurity architect",
            "threat research",
            "jarm signature",
            "sha2",
            "jarm",
            "salesforce",
            "epoch",
            "emotet core",
            "epochs",
            "conti group",
            "emotet epoch",
            "trickbot group",
            "prior",
            "threat response",
            "unit",
            "socs",
            "hunters",
            "cyber",
            "mssql",
            "mssql server",
            "lemon duck",
            "asec analysis",
            "account",
            "kingminer",
            "vollgar",
            "mssql process",
            "cve20201472",
            "reg add",
            "regdword",
            "makes",
            "et exploit",
            "core",
            "possible",
            "comspec",
            "tracker",
            "userdomain",
            "appdata",
            "hide",
            "vbscript",
            "exclusionpath",
            "userpcname",
            "ipcount",
            "gozi",
            "cybereason",
            "exchange",
            "datoploader",
            "cybereason xdr",
            "report",
            "phishing",
            "pinkslipbot",
            "theft",
            "beyond",
            "never",
            "malwarebazaar",
            "strike activity",
            "filejust",
            "file contentsi",
            "vscode",
            "sublime editor",
            "windows exe",
            "utf8",
            "turla",
            "root",
            "msoffice",
            "nativezone",
            "kazuar",
            "bluenoroff",
            "customerloader",
            "muddywater",
            "chat",
            "overwatch",
            "aquatic panda",
            "log4j",
            "linux",
            "apache tomcat",
            "crowdstrike",
            "github project",
            "click",
            "fishmaster",
            "yanluowang",
            "thieflock",
            "scanner",
            "canthroid",
            "grabff",
            "symantec",
            "connectwise",
            "screenconnect",
            "fivehands",
            "browserpassview",
            "rundll32",
            "sharefinder",
            "wmic",
            "ping",
            "rollcoast",
            "south africa",
            "unc2190",
            "july",
            "tycoon",
            "unc2190 beacon",
            "latin",
            "arcane",
            "sabbath",
            "slovak",
            "slovakia",
            "albanian",
            "albania",
            "swedish",
            "turkish",
            "indonesia",
            "estonia",
            "armenia",
            "c2 data",
            "cyberchef",
            "javascript code",
            "rsa key",
            "remove",
            "get request",
            "xor key",
            "exploits & vulnerabilities",
            "managed xdr",
            "one marketplace",
            "lockfile",
            "attack overview",
            "stage",
            "conti gang",
            "datop",
            "handover",
            "kazakhstan",
            "os version",
            "winrm",
            "protocol",
            "enterpssession",
            "psrp",
            "windows remote",
            "source process",
            "stack",
            "rita",
            "threat feed",
            "myrtus",
            "harvester",
            "c activity",
            "artefactsfolder",
            "identity",
            "infectionid",
            "october",
            "main",
            "ad environment",
            "bazar c2",
            "networks",
            "d3desdecrypt",
            "nim malware",
            "jason",
            "part",
            "reaves6 min",
            "nimrodnimza",
            "rustybuer",
            "nimgrabber",
            "caesar",
            "file encryption",
            "nimrev",
            "discovery",
            "data",
            "mitre att",
            "powersploit",
            "leverage",
            "beaconloader",
            "doorme backdoor",
            "issuer cus",
            "apt group",
            "chamelgang",
            "doorme",
            "mcafee",
            "timestomp",
            "copy",
            "oilrig",
            "error",
            "body",
            "eternalblue",
            "zip file",
            "enable",
            "content",
            "vbs script",
            "word document",
            "maldoc",
            "form",
            "win api",
            "bazarloader dll",
            "intro conti",
            "coveware",
            "raas",
            "ransom",
            "ryuk ransomware",
            "cve202140444",
            "multiple",
            "north america",
            "europe",
            "asia",
            "html object",
            "mshtml engine",
            "sidewalk",
            "crosswalk",
            "c server",
            "sparklinggoblin",
            "google docs",
            "winnti group",
            "format",
            "darkshell",
            "motnug",
            "threat-intelligence",
            "apt",
            "nsa",
            "def con",
            "iso filesystem",
            "iocs",
            "recon village",
            "leviathan",
            "encrypt",
            "prophet spider",
            "oracle weblogic",
            "exception",
            "weblogic access",
            "class",
            "linux system",
            "egregor",
            "mountlocker",
            "radar",
            "front",
            "gotroj",
            "encoder",
            "stealer",
            "soar",
            "speed",
            "prophet",
            "classloader",
            "reconnaissance",
            "tech",
            "recon",
            "et cnc",
            "feodo tracker",
            "cnc server",
            "trigger",
            "alive",
            "spawn",
            "method",
            "http method",
            "jitter",
            "port",
            "beacon type",
            "later",
            "close",
            "browser",
            "chinese-speaking cybercrime",
            "google chrome",
            "microsoft word",
            "spear phishing",
            "luminousmoth",
            "honeymyte",
            "assistant",
            "username",
            "motc",
            "ministry",
            "local",
            "xll file",
            "docusign",
            "hancitor dll",
            "hancitor exe",
            "ficker stealer",
            "api hashing",
            "api hash",
            "monpass",
            "avast",
            "monpass client",
            "monpass web",
            "mongolia",
            "jan rubn",
            "discovered",
            "initial contact",
            "final",
            "watermark",
            "chanitor",
            "pony",
            "vawtrak",
            "uwaga",
            "falcon complete",
            "falcon",
            "wizard spider",
            "lime",
            "easy",
            "flex",
            "yahxz",
            "efno",
            "unc2465",
            "ngrok",
            "ultravnc",
            "methodology",
            "ngrok tunnel",
            "smokedham",
            "guard",
            "dllstageless",
            "submission",
            "size",
            "noblebaron",
            "itw name",
            "scout",
            "elite",
            "containedwithin",
            "withheld",
            "relatedto",
            "strike beacon",
            "matches no",
            "privacy",
            "description",
            "entropy",
            "restrict",
            "host ip",
            "owner",
            "igos",
            "germany",
            "file",
            "type",
            "artemis",
            "rozena",
            "razy",
            "khalesi",
            "\u30c7\u30b8\u30bf\u30eb\u7f72\u540d",
            "cobalt strike loader",
            "\u6a19\u7684\u578b\u653b\u6483",
            "strike loader",
            "iocindicator",
            "microsoft docs",
            "2 cobalt",
            "3 sigcheck",
            "1 microsoftdll",
            "powershell rat",
            "macro",
            "progression",
            "hackerman",
            "robinhood",
            "scan behavioral",
            "unusual port",
            "potential scan",
            "campo loader",
            "dfdownloader",
            "japan",
            "post method",
            "openfield",
            "blacktds",
            "public",
            "behaviour",
            "variant",
            "malicious file",
            "transfer",
            "control",
            "feature",
            "fireeye",
            "plink",
            "campo",
            "bazarcall",
            "xyzcampobb hxxp",
            "ioc510",
            "urlcampo",
            "20214",
            "headlines",
            "tlds",
            "duck",
            "beapy",
            "prometei",
            "umbrella",
            "wdigest",
            "iceid",
            "networkminer",
            "caploader",
            "network forensics",
            "ja3",
            "x.509",
            "sslbl",
            "1768.py",
            "didier stevens",
            "8da75e1f974d1011c91ed3110a4ded38",
            "e9b5e549363fa9fcb362b606b75d131dec6c020e",
            "0314b8cd45b636f38d07032dc8ed463295710460ea7a4e214c1de7b0e817aab6",
            "banusdona.top",
            "172.67.188.12",
            "f98711dfeeab9c8b4975b2f9a88d8fea",
            "c2bdc885083696b877ab6f0e05a9d968fd7cc2bb",
            "213e9c8bf7f6d0113193f785cb407f0e8900ba75b9131475796445c11f3ff37c",
            "momenturede.fun",
            "104.236.115.181",
            "96a535122aba4240e2c6370d0c9a09d3",
            "485ba347cf898e34a7455e0fd36b0bcf8b03ffd8",
            "11965662e146d97d3fa3288e119aefb2",
            "b63d7ad26df026f6cca07eae14bb10a0ddb77f41",
            "d45b3f9d93171c29a51f9c8011cd61aa44fcb474d59a0b68181bb690dbbf2ef5",
            "vaccnavalcod.website",
            "mazzappa.fun",
            "ameripermanentno.website",
            "odichaly.space",
            "83.97.20.176",
            "452e969c51882628dac65e38aff0f8e5ebee6e6b",
            "lesti.net",
            "185.141.26.140",
            "449c1967d1708d7056053bedb9e45781",
            "1ab39f1c8fb3f2af47b877cafda4ee09374d7bd3",
            "c7da494880130cdb52bd75dae1556a78f2298a8cc9a2e75ece8a57ca290880d3",
            "45.147.229.157",
            "1580103814",
            "luckymouse",
            "emissary panda",
            "apt 27",
            "apt27",
            "a0e9f5d64349fb13191bc781f81f42e1",
            "3b5074b1b5d032e5620f69f9f700ff0e",
            "erik hjelmvik",
            "monday",
            "openssl",
            "michael",
            "bazaloader",
            "anchor",
            "alex",
            "header",
            "getoperandvalue",
            "win32",
            "build",
            "trickbot crews",
            "cs loader",
            "trickbots cs",
            "trickbots crew",
            "google drive",
            "hancitor c2",
            "icmp",
            "dcdomainname",
            "dclocal",
            "base",
            "cnbuiltin",
            "cnusers",
            "security groups",
            "bitcoin",
            "sage",
            "svchost",
            "bits",
            "beacon dll",
            "started service",
            "beacon payload",
            "process hacker",
            "sleepex",
            "identifies",
            "crph",
            "smadavprotect32",
            "cec list",
            "meeting",
            "dll library",
            "ta800",
            "nim programming",
            "nimzaloader",
            "doesn",
            "json object",
            "c url",
            "trustinfo",
            "displayname",
            "dpiaware",
            "anchordns",
            "enjoy",
            "nimrod",
            "gecko",
            "khtml",
            "offensivenim",
            "sharpkatz",
            "crypter",
            "done",
            "sprite spider",
            "carbon spider",
            "esxi",
            "spider",
            "defray777",
            "pyxie",
            "hypervisor",
            "defray",
            "ransomexx",
            "sekur",
            "anunak",
            "harpy",
            "griffon",
            "unc2198",
            "maze",
            "maze ransomware",
            "file transfer",
            "mouseisland",
            "koadic",
            "photoloader",
            "ocean lotus",
            "mac os",
            "kerrdown",
            "human",
            "kerrdown sample",
            "macho",
            "tcp port",
            "systembc",
            "http traffic",
            "hatching triage",
            "directory",
            "endpoint1",
            "ryuk threat",
            "raindrop",
            "teardrop",
            "decrypt",
            "raindrop loader",
            "name file",
            "pl shellcode",
            "funnyswitch",
            "chm file",
            "config",
            "frombase64",
            "azaz09",
            "nltest",
            "regwrite",
            "exitendifif",
            "sleep",
            "regsz",
            "stwashington",
            "lredmond",
            "dircreate",
            "protection",
            "defenderspynet",
            "john",
            "doublepulsar",
            "amadey",
            "zeppelin",
            "apt & targeted attacks",
            "earth wendigo",
            "service worker",
            "xss attack",
            "domain",
            "learn more",
            "ck technique",
            "techniques",
            "emerging threat",
            "solarwinds",
            "breach",
            "dora",
            "pioneer",
            "solarstorm",
            "cortex xdr",
            "iot security",
            "atom",
            "supernova",
            "yara",
            "snort",
            "gap analysis",
            "keefarce",
            "safetykatz",
            "gadgettojscript",
            "sharpzerologon",
            "tuesday",
            "qakbot binary",
            "qakbot malspam",
            "qakbot malware",
            "windows binary",
            "malspam",
            "egregor payload",
            "threat alert",
            "sekhmet",
            "platform",
            "monitoring",
            "chacha",
            "notpetya",
            "bad rabbit",
            "internet",
            "tls server",
            "tls client",
            "server hello",
            "ja3s",
            "hello packet",
            "apache",
            "random",
            "vatet",
            "localappdata",
            "epochtime",
            "rapid7",
            "cash",
            "logmein",
            "swift",
            "radmin",
            "bazar loader",
            "highest",
            "certificate",
            "issuer org",
            "over",
            "ryuk domain",
            "infrastructure",
            "namecheap",
            "ryuk host",
            "monovm",
            "olol",
            "gnu c",
            "o2 o2",
            "marchx8664 g",
            "g o2",
            "sttx",
            "ltexas",
            "ooffice",
            "name",
            "basecamp",
            "userinit",
            "hack",
            "snow",
            "apt19",
            "yara rule",
            "chimera",
            "pe header",
            "vhash",
            "lpwstr lpbuffer",
            "startw",
            "request",
            "netwalker",
            "neshta",
            "mailto",
            "thor",
            "xmrig",
            "teamt5",
            "threatsonar anti-ransomware",
            "threatsonar",
            "threatvision",
            "cyber espionage",
            "ransom virus",
            "tt",
            "cyber threat hunters",
            "cyber espionage solutions",
            "threat analysis service",
            "incident response",
            "investigation services",
            "threat intelligence",
            "md5 hash",
            "softether",
            "domain teamt5",
            "teamt5 teamt5",
            "plead",
            "pastebin",
            "travelex",
            "pos software",
            "gandcrab",
            "rat",
            "indigodrop",
            "msf shellcode",
            "msf downloader",
            "urlshxxp",
            "stages",
            "threatlabz",
            "india-china",
            "zscaler cloud",
            "dkmc framework",
            "gif header",
            "dkmc",
            "sandbox report",
            "publickey",
            "sandbox",
            "ntds",
            "beacon version",
            "console",
            "file creation",
            "file deletion",
            "rename",
            "or filefullname",
            "coronavirus",
            "tvrat",
            "gozi malware",
            "js file",
            "wscript",
            "msbuild",
            "msbuild project",
            "silent trinity",
            "threat grid",
            "lolbins",
            "cisco threat",
            "msbuild process",
            "naga",
            "trinity",
            "dos header",
            "sfx code",
            "sfx file",
            "export function",
            "mz header",
            "open process",
            "set current",
            "create",
            "apt2019",
            "2019 payload",
            "lnklnklnklnk",
            "1 docvbavbavba",
            "dllentry rat",
            "operation pawn",
            "storm",
            "midst intrusion",
            "pawn storm",
            "xtunnel",
            "hidedrv",
            "aurora",
            "blackshades",
            "conficker",
            "chapro",
            "dark comet",
            "dexter",
            "duqu",
            "gauss",
            "bridge",
            "hikit",
            "makadocs",
            "medre",
            "morto",
            "narilam",
            "onionduke",
            "rustock",
            "dorkbot",
            "spyeye",
            "stabuniq",
            "stuxnet",
            "tinba",
            "vobfus",
            "zeroaccess",
            "zeus",
            "zusy",
            "committee",
            "dnc network",
            "trump",
            "dnc hack",
            "donald trump",
            "neither",
            "general",
            "hill",
            "magazine",
            "mexico",
            "winids",
            "foozer",
            "downrage",
            "hydra",
            "remcom",
            "inc\\.",
            "bear",
            "wirelurker",
            "generic.933739",
            "python code",
            "zxkbdklakv",
            "seaduke",
            "cookie value",
            "bookmark server",
            "p4bnzr0",
            "duke"
          ],
          "references": [
            "https://malcat.fr/blog/lnk-forensic-and-config-extraction-of-a-cobalt-strike-beacon/",
            "https://mp.weixin.qq.com/s/cGS8FocPnUdBconLbbaG-g",
            "https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/",
            "https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra/",
            "https://blog.talosintelligence.com/manjusaka-offensive-framework/",
            "https://cocomelonc.github.io/malware/2022/07/30/malware-av-evasion-8.html",
            "https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/",
            "https://www.trendmicro.com/en_us/research/22/g/gootkit-loaders-updated-tactics-and-fileless-delivery-of-cobalt-strike.html",
            "https://blog.nviso.eu/2022/07/20/analysis-of-a-trojanized-jquery-script-gootloader-unleashed/",
            "https://cloud.google.com/blog/topics/threat-intelligence/spear-phish-ukrainian-entities/",
            "https://www.threatdown.com/blog/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign/",
            "https://cert.gov.ua/article/703548",
            "https://cert-agid.gov.it/news/il-malware-envyscout-apt29-e-stato-veicolato-anche-in-italia/",
            "https://isc.sans.edu/diary/Emotet%20infection%20with%20Cobalt%20Strike/28824",
            "https://cert.gov.ua/article/619229",
            "https://ics-cert.kaspersky.com/publications/reports/2022/06/27/attacks-on-industrial-control-systems-using-shadowpad/",
            "https://blog.bushidotoken.net/2022/06/overview-of-russian-gru-and-svr.html",
            "https://blog.talosintelligence.com/avoslocker-new-arsenal/",
            "https://isc.sans.edu/diary/rss/28752",
            "https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html",
            "https://kienmanowar.wordpress.com/2022/06/04/quicknote-cobaltstrike-smb-beacon-analysis-2/",
            "https://cloud.google.com/blog/topics/threat-intelligence/unc2165-shifts-to-evade-sanctions",
            "https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis",
            "https://medium.com/walmartglobaltech/socgholish-campaigns-and-initial-access-kit-4c4283fea8ee",
            "https://thehackernews.com/2022/05/malware-analysis-trickbot.html",
            "https://www.sonatype.com/blog/new-pymafka-malicious-package-drops-cobalt-strike-on-macos-windows-linux",
            "https://asec.ahnlab.com/en/34549/",
            "https://isc.sans.edu/diary/Bumblebee+Malware+from+TransferXL+URLs/28664",
            "https://raw.githubusercontent.com/Dump-GUY/Malware-analysis-and-Reverse-engineering/refs/heads/main/APT29_C2-Client_Dropbox_Loader/APT29-DropboxLoader_analysis.md",
            "https://redcanary.com/wp-content/uploads/2022/05/Gootloader.pdf",
            "https://i.blackhat.com/Asia-22/Thursday-Materials/AS-22-LeonSilvia-NextGenPlugXShadowPad.pdf",
            "https://isc.sans.edu/diary/28636",
            "https://cocomelonc.github.io/tutorial/2022/05/09/malware-pers-4.html",
            "https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/",
            "https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encoding-decoding/",
            "https://thehackernews.com/2022/05/this-new-fileless-malware-hides.html",
            "https://blog.talosintelligence.com/mustang-panda-targets-europe/",
            "https://securelist.com/a-new-secret-stash-for-fileless-malware/106393/",
            "https://security.macnica.co.jp/blog/2022/05/iso.html",
            "https://cloud.google.com/blog/topics/threat-intelligence/tracking-apt29-phishing-campaigns/",
            "https://documents.trendmicro.com/assets/txt/earth-berberoka-windows-iocs-2.txt",
            "https://cert.ssi.gouv.fr/uploads/20220427_NP_TLPWHITE_ANSSI_FIN7.pdf",
            "https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29/",
            "https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/",
            "https://thedfirreport.com/2022/04/25/quantum-ransomware/",
            "https://www.morphisec.com/blog/vmware-identity-manager-attack-backdoor/",
            "https://cocomelonc.github.io/tutorial/2022/04/20/malware-pers-1.html",
            "https://www.varonis.com/blog/hive-ransomware-analysis",
            "https://www.sentinelone.com/blog/from-the-front-lines-peering-into-a-pysa-ransomware-attack/",
            "https://vanmieghem.io/blueprint-for-evading-edr-in-2022/",
            "https://www.cynet.com/blog/orion-threat-alert-flight-of-the-bumblebee/",
            "https://www.welivesecurity.com/2022/04/13/eset-takes-part-global-operation-disrupt-zloader-botnets/",
            "https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html",
            "https://github.com/infinitumitlabs/Karakurt-Hacking-Team-CTI",
            "https://cloud.google.com/blog/topics/threat-intelligence/evolution-of-fin7/",
            "https://www.sentinelone.com/blog/hive-ransomware-deploys-novel-ipfuscation-technique/",
            "https://medium.com/walmartglobaltech/cobaltstrike-uuid-stager-ca7e82f7bb64",
            "https://resource.redcanary.com/rs/003-YRU-314/images/2022_ThreatDetectionReport_RedCanary.pdf",
            "https://www.esentire.com/blog/conti-affiliate-exposed-new-domain-names-ip-addresses-and-email-addresses-uncovered-by-esentire",
            "https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2-profile/",
            "https://isc.sans.edu/diary/Qakbot+infection+with+Cobalt+Strike+and+VNC+activity/28448",
            "https://www.sentinelone.com/blog/threat-actor-uac-0056-targeting-ukraine-with-fake-translation-software/",
            "https://www.arashparsa.com/catching-a-malware-with-no-name/",
            "https://cert.gov.ua/article/37704",
            "https://cloud.google.com/blog/topics/threat-intelligence/apt41-us-state-governments/",
            "https://thedfirreport.com/2022/03/07/2021-year-in-review/",
            "https://www.cynet.com/security-foundations/attack-techniques/new-wave-of-emotet-when-project-x-turns-into-y/",
            "https://www.fortinet.com/blog/threat-research/nobelium-returns-to-the-political-world-stage",
            "https://cyber.wtf/2022/03/23/what-the-packer/",
            "https://www.esentire.com/blog/icedid-to-cobalt-strike-in-under-20-minutes",
            "https://asec.ahnlab.com/en/31811/",
            "https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/",
            "https://medium.com/walmartglobaltech/signed-dll-campaigns-as-a-service-7760ac676489",
            "https://www.cybereason.com/blog/research/threat-analysis-report-datoploader-exploits-proxyshell-to-deliver-qbot-and-cobalt-strike",
            "https://forensicitguy.github.io/inspecting-powershell-cobalt-strike-beacon/",
            "https://blog.sekoia.io/nobeliums-envyscout-infection-chain-goes-in-the-registry-targeting-embassies/",
            "https://www.crowdstrike.com/en-us/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/",
            "https://www.security.com/threat-intelligence/yanluowang-ransomware-attacks-continue",
            "https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/",
            "https://cloud.google.com/blog/topics/threat-intelligence/sabbath-ransomware-affiliate/",
            "https://blog.nviso.eu/2021/11/17/cobalt-strike-decrypting-obfuscated-traffic-part-4/",
            "https://www.trendmicro.com/en_gb/research/21/k/analyzing-proxyshell-related-incidents-via-trend-micro-managed-x.html",
            "https://www.truesec.com/hub/blog/proxyshell-qbot-and-conti-ransomware-combined-in-a-series-of-cyber-attacks",
            "https://www.threatdown.com/blog/a-multi-stage-powershell-based-attack-targets-kazakhstan/",
            "https://www.unh4ck.com/detection-engineering-and-threat-hunting/lateral-movement/detecting-conti-cobaltstrike-lateral-movement-techniques-part-1",
            "https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-009.pdf",
            "https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/",
            "https://www.security.com/threat-intelligence/harvester-new-apt-attacks-asia",
            "https://unit42.paloaltonetworks.com/bazarloader-network-reconnaissance/",
            "https://medium.com/walmartglobaltech/investigation-into-the-state-of-nim-malware-part-2-a28bffffa671",
            "https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/",
            "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/new-apt-group-chamelgang/#id3",
            "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/new-apt-group-chamelgang/",
            "https://www.cynet.com/security-foundations/attack-techniques/understanding-squirrelwaffle/",
            "https://thedfirreport.com/2021/09/13/bazarloader-to-conti-ransomware-in-32-hours/",
            "https://blog.gigamon.com/2021/09/10/rendering-threats-a-network-perspective/",
            "https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/i/ssl-tls-technical-brief/ssl-tls-technical-brief.pdf",
            "https://documents.trendmicro.com/assets/white_papers/wp-earth-baku-an-apt-group-targeting-indo-pacific-countries.pdf",
            "https://www.welivesecurity.com/2021/08/24/sidewalk-may-be-as-dangerous-as-crosswalk/",
            "https://istrosec.com/blog/apt-sk-cobalt/",
            "https://www.crowdstrike.com/en-us/blog/prophet-spider-exploits-oracle-weblogic-to-facilitate-ransomware-activity/",
            "https://thedfirreport.com/2021/08/01/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike/",
            "https://thedfirreport.com/2021/07/19/icedid-and-cobalt-strike-vs-antivirus/",
            "https://securelist.com/apt-luminousmoth/103332/",
            "https://isc.sans.edu/diary/rss/27618",
            "https://www.gendigital.com/blog/insights/research/decoding-cobalt-strike-understanding-payloads",
            "https://www.gendigital.com/blog/insights/research/backdoored-client-from-mongolian-ca-monpass",
            "https://thedfirreport.com/2021/06/28/hancitor-continues-to-push-cobalt-strike/",
            "https://www.crowdstrike.com/en-us/blog/how-falcon-complete-disrupts-ecrime-operators-wizard-spider/",
            "https://thedfirreport.com/2021/06/20/from-word-to-lateral-movement-in-1-hour/",
            "https://cloud.google.com/blog/topics/threat-intelligence/darkside-affiliate-supply-chain-software-compromise",
            "https://www.sentinelone.com/labs/noblebaron-new-poisoned-installers-could-be-used-in-supply-chain-attacks/",
            "https://www.cisa.gov/news-events/analysis-reports/ar21-148a",
            "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-148a",
            "https://www.lac.co.jp/lacwatch/report/20210521_002618.html",
            "https://www.ncsc.gov.ie/pdfs/HSE_Conti_140521_UPDATE.pdf",
            "https://www.guidepointsecurity.com/blog/from-zloader-to-darkside-a-ransomware-story/",
            "https://thedfirreport.com/2021/05/12/conti-ransomware/",
            "https://mal-eats.net/en/2021/05/11/campo_new_attack_campaign_targeting_japan/",
            "https://cloud.google.com/blog/topics/threat-intelligence/shining-a-light-on-darkside-ransomware-operations/",
            "https://mal-eats.net/2021/05/10/campo_new_attack_campaign_targeting_japan/",
            "https://blog.talosintelligence.com/lemon-duck-spreads-wings/",
            "https://thedfirreport.com/2021/05/02/trickbot-brief-creds-and-beacons/",
            "https://www.netresec.com/?page=Blog&month=2021-04&post=Analysing-a-malware-PCAP-with-IcedID-and-Cobalt-Strike-traff",
            "https://isc.sans.edu/diary/27308",
            "https://medium.com/walmartglobaltech/trickbot-crews-new-cobaltstrike-loader-32c72b78e81c",
            "https://unit42.paloaltonetworks.com/hancitor-infections-cobalt-strike/",
            "https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/",
            "https://www.elastic.co/blog/detecting-cobalt-strike-with-memory-signatures",
            "https://www.qurium.org/alerts/targeted-malware-against-crph/",
            "https://www.proofpoint.com/us/blog/threat-insight/nimzaloader-ta800s-new-initial-access-malware",
            "https://thedfirreport.com/2021/03/08/bazar-drops-the-anchor/",
            "https://medium.com/walmartglobaltech/investigation-into-the-state-of-nim-malware-14cc543af811",
            "https://www.crowdstrike.com/en-us/blog/carbon-spider-sprite-spider-target-esxi-servers-with-ransomware/?utm_campaign=blog&utm_medium=soc&utm_source=twtr&utm_content=sprout",
            "https://cloud.google.com/blog/topics/threat-intelligence/melting-unc2198-icedid-to-ransomware-operations/",
            "https://raw.githubusercontent.com/AmnestyTech/investigations/refs/heads/master/2021-02-24_vietnam/README.md",
            "https://isc.sans.edu/diary/Excel+spreadsheets+push+SystemBC+malware/27060",
            "https://thedfirreport.com/2021/01/31/bazar-no-ryuk/",
            "https://www.security.com/threat-intelligence/solarwinds-raindrop-malware",
            "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/",
            "https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/",
            "https://medium.com/walmartglobaltech/man1-moskal-hancitor-and-a-side-of-ransomware-d77b4d991618",
            "https://www.trendmicro.com/en_us/research/21/a/earth-wendigo-injects-javascript-backdoor-to-service-worker-for-.html",
            "https://www.picussecurity.com/resource/blog/ttps-used-in-the-solarwinds-breach",
            "https://unit42.paloaltonetworks.com/fireeye-solarstorm-sunburst/",
            "https://unit42.paloaltonetworks.com/fireeye-red-team-tool-breach/",
            "https://isc.sans.edu/diary/rss/26862",
            "https://i.blackhat.com/eu-20/Wednesday/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations-wp.pdf",
            "https://i.blackhat.com/eu-20/Wednesday/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations.pdf",
            "https://www.cybereason.com/blog/cybereason-vs-egregor-ransomware",
            "https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a/",
            "https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/5/",
            "https://thedfirreport.com/2020/11/05/ryuk-speed-run-2-hours-to-ransom/",
            "https://raw.githubusercontent.com/ThreatConnect-Inc/research-team/refs/heads/master/IOCs/WizardSpider-UNC1878-Ryuk.csv",
            "https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/",
            "https://cloud.google.com/blog/topics/threat-intelligence/kegtap-and-singlemalt-with-a-ransomware-chaser/",
            "https://raw.githubusercontent.com/StrangerealIntel/CyberThreatIntel/refs/heads/master/China/APT/Chimera/Analysis.md",
            "https://thedfirreport.com/2020/10/08/ryuks-return/",
            "https://thedfirreport.com/2020/08/31/netwalker-ransomware-in-1-hour/",
            "https://teamt5.org/tw/posts/mjib-holds-briefing-on-chinese-hackers-attacks-on-taiwanese-government-agencies/",
            "https://i.blackhat.com/USA-20/Thursday/us-20-Chen-Operation-Chimera-APT-Operation-Targets-Semiconductor-Vendors.pdf",
            "https://www.security.com/threat-intelligence/sodinokibi-ransomware-cobalt-strike-pos",
            "https://blog.talosintelligence.com/indigodrop-maldocs-cobalt-strike/",
            "https://www.zscaler.com/blogs/security-research/targeted-attack-leverages-india-china-border-dispute-lure-victims",
            "https://www.sentinelone.com/labs/the-anatomy-of-an-apt-attack-and-cobaltstrike-beacons-encoded-configuration/",
            "https://thedfirreport.com/2020/04/24/ursnif-via-lolbins/",
            "https://blog.talosintelligence.com/building-bypass-with-msbuild/",
            "https://tccontre.blogspot.com/2019/11/cobaltstrike-beacondll-your-not.html",
            "https://web-assets.esetstatic.com/wls/2019/10/ESET_Operation_Ghost_Dukes.pdf",
            "https://mp.weixin.qq.com/s/xPsEXp2J5IE7wNSMEVC24A",
            "https://contagiodump.blogspot.com/2017/02/russian-apt-apt28-collection-of-samples.html",
            "https://www.cisa.gov/sites/default/files/publications/AR-17-20045_Enhanced_Analysis_of_GRIZZLY_STEPPE_Activity.pdf",
            "https://www.crowdstrike.com/en-us/blog/bears-midst-intrusion-democratic-national-committee/",
            "https://blog-assets.f-secure.com/wp-content/uploads/2020/03/18122307/F-Secure_Dukes_Whitepaper.pdf",
            "https://contagiodump.blogspot.com/2014/11/onionduke-samples.html",
            "https://unit42.paloaltonetworks.com/unit-42-technical-analysis-seaduke/"
          ],
          "public": 1,
          "adversary": "Threat",
          "targeted_countries": [
            "Czechia",
            "Ukraine",
            "Russian Federation",
            "Poland",
            "Belarus",
            "Lithuania",
            "Latvia",
            "Germany",
            "Pakistan",
            "Afghanistan",
            "Malaysia",
            "Greece",
            "Italy",
            "T\u00fcrkiye",
            "Portugal",
            "Brazil",
            "China",
            "Japan",
            "Korea, Republic of",
            "United States of America",
            "Mexico",
            "New Zealand",
            "Canada",
            "Georgia",
            "Iran, Islamic Republic of"
          ],
          "malware_families": [
            {
              "id": "HandleRef",
              "display_name": "HandleRef",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Threat",
              "display_name": "Threat",
              "target": null
            },
            {
              "id": "Primary Threat",
              "display_name": "Primary Threat",
              "target": null
            },
            {
              "id": "BazarLoader",
              "display_name": "BazarLoader",
              "target": null
            },
            {
              "id": "Bumblebee",
              "display_name": "Bumblebee",
              "target": null
            },
            {
              "id": "ELF",
              "display_name": "ELF",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Kronos",
              "display_name": "Kronos",
              "target": null
            },
            {
              "id": "BEACON",
              "display_name": "BEACON",
              "target": null
            },
            {
              "id": "MICROBACKDOOR",
              "display_name": "MICROBACKDOOR",
              "target": null
            },
            {
              "id": "GRIMPLANT",
              "display_name": "GRIMPLANT",
              "target": null
            },
            {
              "id": "GRAPHSTEEL",
              "display_name": "GRAPHSTEEL",
              "target": null
            },
            {
              "id": "Shadowpad",
              "display_name": "Shadowpad",
              "target": null
            },
            {
              "id": "PlugX",
              "display_name": "PlugX",
              "target": null
            },
            {
              "id": "ShadowPad",
              "display_name": "ShadowPad",
              "target": null
            },
            {
              "id": "Threat Analysis",
              "display_name": "Threat Analysis",
              "target": null
            },
            {
              "id": "CredoMap",
              "display_name": "CredoMap",
              "target": null
            },
            {
              "id": "StellarParticle",
              "display_name": "StellarParticle",
              "target": null
            },
            {
              "id": "CozyBear",
              "display_name": "CozyBear",
              "target": null
            },
            {
              "id": "Shadow Chaser",
              "display_name": "Shadow Chaser",
              "target": null
            },
            {
              "id": "Raspberry Robin",
              "display_name": "Raspberry Robin",
              "target": null
            },
            {
              "id": "RansomHub",
              "display_name": "RansomHub",
              "target": null
            },
            {
              "id": "Cyclops",
              "display_name": "Cyclops",
              "target": null
            },
            {
              "id": "FancyBear",
              "display_name": "FancyBear",
              "target": null
            },
            {
              "id": "APT29",
              "display_name": "APT29",
              "target": null
            },
            {
              "id": "AvosLocker",
              "display_name": "AvosLocker",
              "target": null
            },
            {
              "id": "Matanbuchus",
              "display_name": "Matanbuchus",
              "target": null
            },
            {
              "id": "HADES",
              "display_name": "HADES",
              "target": null
            },
            {
              "id": "SocGholish NetSupport",
              "display_name": "SocGholish NetSupport",
              "target": null
            },
            {
              "id": "SocGholish",
              "display_name": "SocGholish",
              "target": null
            },
            {
              "id": "NetSupport",
              "display_name": "NetSupport",
              "target": null
            },
            {
              "id": "Gold Blackburn",
              "display_name": "Gold Blackburn",
              "target": null
            },
            {
              "id": "Conti",
              "display_name": "Conti",
              "target": null
            },
            {
              "id": "Ryuk",
              "display_name": "Ryuk",
              "target": null
            },
            {
              "id": "Trickbot",
              "display_name": "Trickbot",
              "target": null
            },
            {
              "id": "Darkside",
              "display_name": "Darkside",
              "target": null
            },
            {
              "id": "Win32.BitCoinMiner",
              "display_name": "Win32.BitCoinMiner",
              "target": null
            },
            {
              "id": "Win32.Agent",
              "display_name": "Win32.Agent",
              "target": null
            },
            {
              "id": "NbtScan",
              "display_name": "NbtScan",
              "target": null
            },
            {
              "id": "Frp",
              "display_name": "Frp",
              "target": null
            },
            {
              "id": "Pcap",
              "display_name": "Pcap",
              "target": null
            },
            {
              "id": "BeaconLoader",
              "display_name": "BeaconLoader",
              "target": null
            },
            {
              "id": "DoorMe",
              "display_name": "DoorMe",
              "target": null
            },
            {
              "id": "Win API",
              "display_name": "Win API",
              "target": null
            },
            {
              "id": "Generic.933739",
              "display_name": "Generic.933739",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Gas",
            "Government",
            "Defense",
            "Media",
            "Telecommunications",
            "Logistics",
            "Industrial",
            "Manufacturing",
            "Transport",
            "Transportation",
            "Diplomatic",
            "Foreign Affairs",
            "Academics",
            "Banking",
            "Aviation",
            "Political",
            "Energy",
            "Military",
            "Financial",
            "Legal",
            "Pharmaceutical",
            "Technology",
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "kikinumpav",
            "id": "385742",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3082,
            "FileHash-SHA1": 2478,
            "FileHash-SHA256": 4182,
            "URL": 3155,
            "CVE": 190,
            "SSLCertFingerprint": 41,
            "domain": 2991,
            "email": 58,
            "hostname": 2130,
            "YARA": 95
          },
          "indicator_count": 18402,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 16,
          "modified_text": "3 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "660566db15f516334e28c875",
          "name": "Saiba mais sobre o Lazarus Group, grupo de amea\u00e7a que visa o Brasil",
          "description": "",
          "modified": "2024-04-27T12:04:00.761000",
          "created": "2024-03-28T12:47:23.957000",
          "tags": [
            "ciberseguran\u00e7a",
            "lazarus group",
            "empresa segura",
            "ambiente da empresa",
            "principais amea\u00e7as",
            "seguran\u00e7a digital",
            "o grupo",
            "indicadores",
            "conhecido",
            "lazarus",
            "para",
            "iocs",
            "isso",
            "isso pode",
            "explorao",
            "modo",
            "manuscrypt",
            "fallchill",
            "wannacry",
            "rats",
            "malware",
            "destover",
            "powershell",
            "heimdall",
            "policy",
            "internet site",
            "the internet",
            "site",
            "organization",
            "internet",
            "personal data",
            "cookie policy",
            "socradar",
            "cookie usage",
            "date",
            "https"
          ],
          "references": [
            "https://www.ish.com.br/blog/principais-ameacas-que-visam-o-brasil-lazarus-group/",
            "https://socradar.io/apt-group-lazarus-exploits-high-severity-flaw-in-dell-driver/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Netherlands",
            "Belgium"
          ],
          "malware_families": [
            {
              "id": "Manuscrypt",
              "display_name": "Manuscrypt",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "Heimdall",
              "display_name": "Heimdall",
              "target": null
            },
            {
              "id": "HTTPS",
              "display_name": "HTTPS",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1098",
              "name": "Account Manipulation",
              "display_name": "T1098 - Account Manipulation"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1557",
              "name": "Man-in-the-Middle",
              "display_name": "T1557 - Man-in-the-Middle"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            },
            {
              "id": "T1495",
              "name": "Firmware Corruption",
              "display_name": "T1495 - Firmware Corruption"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            }
          ],
          "industries": [
            "Aerospace",
            "Political"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "john_zno",
            "id": "211870",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA1": 20,
            "FileHash-SHA256": 7,
            "URL": 3,
            "domain": 2,
            "hostname": 2
          },
          "indicator_count": 41,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 32,
          "modified_text": "767 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "651a72358fd4b4a6a3e838f9",
          "name": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
          "description": "ESET Research has uncovered the tools deployed by the so-called Lazarus cybercriminal group to gain access to the systems of aerospace companies in Spain and the United States, as well as other high-profile incidents such as WannaCry.",
          "modified": "2023-11-01T07:03:22.463000",
          "created": "2023-10-02T07:33:09.938000",
          "tags": [
            "lightlesscan",
            "strong",
            "lazarus",
            "figure",
            "eset research",
            "mimic",
            "c server",
            "online",
            "windows prompt",
            "nickelloader",
            "blindingcan",
            "meta",
            "rats",
            "april",
            "hello",
            "wannacry",
            "august",
            "malware",
            "vmprotect",
            "june",
            "podcast",
            "tips",
            "facebook",
            "wannacryptor",
            "mini",
            "download",
            "first",
            "phishing",
            "service",
            "execution",
            "persistence",
            "manipulation",
            "team",
            "oilrig",
            "winordll64",
            "hidden cobra",
            "upload",
            "linux",
            "ku",
            "kw",
            "kt",
            "https",
            "miniblindingcan"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 36,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 11,
            "FileHash-SHA1": 13,
            "domain": 5,
            "hostname": 5
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 864,
          "modified_text": "945 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "651a4aaebb26e186d506fb1b",
          "name": "Lazarus hackers breach aerospace firm with new LightlessCan malware",
          "description": "",
          "modified": "2023-11-01T04:01:38.337000",
          "created": "2023-10-02T04:44:30.214000",
          "tags": [],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 11,
            "FileHash-SHA1": 13,
            "domain": 5,
            "hostname": 5
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 501,
          "modified_text": "945 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6519cdc8cea6cf8431b15da8",
          "name": "ACTIVIDAD MALICIOSA | Relacionada con Ataque de Lazarus a la Agencia Aeroespacial 01-10-2023",
          "description": "Hemos descrito un nuevo ataque de Lazarus que se origin\u00f3 en LinkedIn, donde reclutadores falsos se acercaban a sus v\u00edctimas potenciales, que utilizaban computadoras corporativas para fines personales. Aunque la conciencia p\u00fablica sobre este tipo de ataques deber\u00eda ser alta, las tasas de \u00e9xito de estas campa\u00f1as a\u00fan no han bajado a cero.",
          "modified": "2023-10-31T19:02:38.816000",
          "created": "2023-10-01T19:51:36.036000",
          "tags": [
            "entity"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/gc9d8101923d24588b6c83b20613a1bf0bb3b5b0a38654f7a8cc81f1d16e0be9d?theme=light",
            "https://otx.alienvault.com/pulse/6516dc1c66c2a9a03166669f",
            "https://alertas-y-seguridad.jimdosite.com/repositorio-ioc/"
          ],
          "public": 1,
          "adversary": "Lazarus Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Trojan:Win32/Lazarus",
              "display_name": "Trojan:Win32/Lazarus",
              "target": "/malware/Trojan:Win32/Lazarus"
            },
            {
              "id": "Trojan:Win64/Lazarus",
              "display_name": "Trojan:Win64/Lazarus",
              "target": "/malware/Trojan:Win64/Lazarus"
            },
            {
              "id": "LightlessCan",
              "display_name": "LightlessCan",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "esoporteingenieria2020",
            "id": "121604",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 13,
            "domain": 5,
            "hostname": 4
          },
          "indicator_count": 22,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 268,
          "modified_text": "945 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6516f22aadc43e7b516394d5",
          "name": "Lazarus hackers breach aerospace firm with new LightlessCan malware",
          "description": "The North Korean 'Lazarus' hacking group targeted employees of an aerospace company located in Spain with fake job opportunities to hack into the corporate network using a previously unknown 'LightlessCan' backdoor.\n\nThe hackers utilized their ongoing \"Operation Dreamjob\" campaign, which entails approaching a target over LinkedIn and engaging in a fake employee recruitment process that, at some point, required the victim to download a file. The employee did so on a company's computer, allowing the North Korean hackers to breach the corporate network to conduct cyber espionage.",
          "modified": "2023-10-29T15:00:40.733000",
          "created": "2023-09-29T15:50:02.853000",
          "tags": [
            "lightlesscan",
            "strong",
            "lazarus",
            "figure",
            "eset research",
            "mimic",
            "c server",
            "online",
            "windows prompt",
            "nickelloader",
            "blindingcan",
            "meta",
            "rats",
            "april",
            "hello",
            "wannacry",
            "august",
            "malware",
            "vmprotect",
            "june",
            "podcast",
            "tips",
            "facebook",
            "wannacryptor",
            "mini",
            "download",
            "first",
            "phishing",
            "service",
            "execution",
            "persistence",
            "manipulation",
            "team",
            "oilrig",
            "winordll64",
            "hidden cobra",
            "upload",
            "linux",
            "ku",
            "kw",
            "kt",
            "https",
            "miniblindingcan"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/",
            "https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Korea, Democratic People's Republic of",
            "Netherlands",
            "Belgium"
          ],
          "malware_families": [
            {
              "id": "KU",
              "display_name": "KU",
              "target": null
            },
            {
              "id": "KW",
              "display_name": "KW",
              "target": null
            },
            {
              "id": "KT",
              "display_name": "KT",
              "target": null
            },
            {
              "id": "HTTPS",
              "display_name": "HTTPS",
              "target": null
            },
            {
              "id": "NickelLoader",
              "display_name": "NickelLoader",
              "target": null
            },
            {
              "id": "BlindingCan",
              "display_name": "BlindingCan",
              "target": null
            },
            {
              "id": "miniBlindingCan",
              "display_name": "miniBlindingCan",
              "target": null
            },
            {
              "id": "LightlessCan",
              "display_name": "LightlessCan",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [
            "Aerospace",
            "Defense"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 328,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dekaRituraj",
            "id": "99856",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_99856/resized/80/avatar_0e93d502b7.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 13,
            "URL": 11,
            "domain": 5,
            "hostname": 5
          },
          "indicator_count": 34,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 434,
          "modified_text": "948 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "651a6bf5c2ef0eb8b7bda145",
          "name": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
          "description": "",
          "modified": "2023-10-29T14:01:08.677000",
          "created": "2023-10-02T07:06:29.568000",
          "tags": [
            "LinkedIn",
            "Lazarus",
            "cyberespionage",
            "NickelLoader",
            "RAT",
            "LightlessCan",
            "miniBlindingCan"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Spain"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1585",
              "name": "Establish Accounts",
              "display_name": "T1585 - Establish Accounts"
            },
            {
              "id": "T1593",
              "name": "Search Open Websites/Domains",
              "display_name": "T1593 - Search Open Websites/Domains"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": "651a5c71689f50987b56be3f",
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 13,
            "domain": 5,
            "hostname": 5
          },
          "indicator_count": 23,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 278,
          "modified_text": "948 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "651a5c71689f50987b56be3f",
          "name": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
          "description": "",
          "modified": "2023-10-29T14:01:08.677000",
          "created": "2023-10-02T06:00:17.772000",
          "tags": [
            "LinkedIn",
            "Lazarus",
            "cyberespionage",
            "NickelLoader",
            "RAT",
            "LightlessCan",
            "miniBlindingCan"
          ],
          "references": [
            "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Spain"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1585",
              "name": "Establish Accounts",
              "display_name": "T1585 - Establish Accounts"
            },
            {
              "id": "T1593",
              "name": "Search Open Websites/Domains",
              "display_name": "T1593 - Search Open Websites/Domains"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": "6516dc1c66c2a9a03166669f",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 13,
            "domain": 5,
            "hostname": 5
          },
          "indicator_count": 23,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 187,
          "modified_text": "948 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "650ab3794fd273ef3e8dc012",
          "name": "ZINC weaponizing open-source software | Microsoft Security Blog",
          "description": "",
          "modified": "2023-10-20T06:03:55.728000",
          "created": "2023-09-20T08:55:21.336000",
          "tags": [
            "zinc",
            "putty",
            "microsoft",
            "sumatra pdf",
            "kitty",
            "dll search",
            "tightvnc viewer",
            "linkedin",
            "whatsapp",
            "reader",
            "zetanile",
            "june",
            "pass",
            "defender",
            "rats",
            "foggybrass",
            "twitter",
            "april",
            "defense",
            "blindingcan",
            "themida",
            "vmprotect",
            "daily",
            "win64",
            "look"
          ],
          "references": [
            "https://www.microsoft.com/en-us/security/blog/2022/09/29/zinc-weaponizing-open-source-software/?ranMID=46137&ranEAID=je6NUbpObpQ&ranSiteID=je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A&epi=je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A&irgwc=1&OCID=AIDcmm549zy227_aff_7792_1243925&tduid=%28ir__1jzmmrmv2skfd09mw9hoedxrnv2xbzpdmhhcftum00%29%287792%29%281243925%29%28je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A%29%28%29&irclickid=_1jzmmrmv2skfd09mw9hoedxrnv2xbzpdmhhcftum00"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "650a956c513e8e0927aaae4d",
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 8,
            "URL": 6,
            "domain": 4,
            "hostname": 3
          },
          "indicator_count": 40,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 279,
          "modified_text": "957 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "650a956c513e8e0927aaae4d",
          "name": "ZINC weaponizing open-source software | Microsoft Security Blog",
          "description": "",
          "modified": "2023-10-20T06:03:55.728000",
          "created": "2023-09-20T06:47:08.384000",
          "tags": [
            "zinc",
            "putty",
            "microsoft",
            "sumatra pdf",
            "kitty",
            "dll search",
            "tightvnc viewer",
            "linkedin",
            "whatsapp",
            "reader",
            "zetanile",
            "june",
            "pass",
            "defender",
            "rats",
            "foggybrass",
            "twitter",
            "april",
            "defense",
            "blindingcan",
            "themida",
            "vmprotect",
            "daily",
            "win64",
            "look"
          ],
          "references": [
            "https://www.microsoft.com/en-us/security/blog/2022/09/29/zinc-weaponizing-open-source-software/?ranMID=46137&ranEAID=je6NUbpObpQ&ranSiteID=je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A&epi=je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A&irgwc=1&OCID=AIDcmm549zy227_aff_7792_1243925&tduid=%28ir__1jzmmrmv2skfd09mw9hoedxrnv2xbzpdmhhcftum00%29%287792%29%281243925%29%28je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A%29%28%29&irclickid=_1jzmmrmv2skfd09mw9hoedxrnv2xbzpdmhhcftum00"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 8,
            "URL": 6,
            "domain": 4,
            "hostname": 3
          },
          "indicator_count": 40,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 188,
          "modified_text": "957 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64886ada7313b886df588f8f",
          "name": "domains",
          "description": "domains",
          "modified": "2023-06-13T13:10:50.659000",
          "created": "2023-06-13T13:10:50.659000",
          "tags": [
            "domain"
          ],
          "references": [
            "entities (48).csv"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ASQ505sa",
            "id": "217420",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 23,
            "domain": 91
          },
          "indicator_count": 114,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 35,
          "modified_text": "1086 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6425d837bf1d51febcb347de",
          "name": "Amazon&#8209;themed campaigns of Lazarus in the Netherlands and Belgium | WeLiveSecurity",
          "description": "ESET researchers have uncovered and analyzed a set of malicious tools used by the infamous Lazarus APT group in attacks against targets in the autumn of 2021, the first recorded abuse of a vulnerability in Windows.",
          "modified": "2023-04-29T18:02:26.111000",
          "created": "2023-03-30T18:43:03.014000",
          "tags": [
            "lazarus",
            "hidden cobra",
            "toy guys",
            "blindingcan",
            "jd",
            "http",
            "figure",
            "c server",
            "belgium",
            "netherlands",
            "eset",
            "line",
            "eset research",
            "june",
            "malware",
            "august",
            "february",
            "execution",
            "wannacryptor",
            "wannacry",
            "polish",
            "themida",
            "vmprotect",
            "team",
            "dream",
            "trojan",
            "podcast",
            "love"
          ],
          "references": [
            "https://www.welivesecurity.com/2022/09/30/amazon-themed-campaigns-lazarus-netherlands-belgium/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Belgium",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "JD",
              "display_name": "JD",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "BLINDINGCAN",
              "display_name": "BLINDINGCAN",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            }
          ],
          "industries": [
            "Defense",
            "Media",
            "Political",
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Gargomel",
            "id": "17466",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 2,
            "URL": 5,
            "domain": 5,
            "hostname": 2
          },
          "indicator_count": 33,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 151,
          "modified_text": "1130 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633c4dab74f79dc94181d0a1",
          "name": "ZINC weaponizing open-source software - Microsoft Security Blog",
          "description": "",
          "modified": "2022-11-03T15:00:10.128000",
          "created": "2022-10-04T15:13:47.919000",
          "tags": [
            "zinc",
            "putty",
            "microsoft",
            "sumatra pdf",
            "kitty",
            "dll search",
            "tightvnc viewer",
            "linkedin",
            "whatsapp",
            "reader",
            "zetanile",
            "defender",
            "june",
            "pass",
            "rats",
            "foggybrass",
            "twitter",
            "april",
            "blindingcan",
            "themida",
            "vmprotect",
            "daily",
            "win64",
            "look"
          ],
          "references": [
            "https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/"
          ],
          "public": 1,
          "adversary": "Zinc",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fuchs-aaron",
            "id": "171510",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 8,
            "URL": 6,
            "domain": 4,
            "hostname": 3
          },
          "indicator_count": 29,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 52,
          "modified_text": "1308 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633be76cc2c20669ed41b649",
          "name": "Amazon\u2011themed campaigns of Lazarus in the Netherlands and Belgium",
          "description": "",
          "modified": "2022-11-03T05:04:20.106000",
          "created": "2022-10-04T07:57:32.195000",
          "tags": [
            "lazarus",
            "hidden cobra",
            "malware",
            "execution",
            "wannacryptor",
            "trojan"
          ],
          "references": [
            "https://www.welivesecurity.com/2022/09/30/amazon-themed-campaigns-lazarus-netherlands-belgium/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Belgium",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "BLINDINGCAN",
              "display_name": "BLINDINGCAN",
              "target": null
            },
            {
              "id": "",
              "display_name": "",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            }
          ],
          "industries": [
            "Defense",
            "Media",
            "Political",
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": "633bc6f99d1ce0b01b699389",
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 2,
            "URL": 5,
            "domain": 5,
            "hostname": 2
          },
          "indicator_count": 33,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "1308 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633bc6f99d1ce0b01b699389",
          "name": "Amazon\u2011themed campaigns of Lazarus in the Netherlands and Belgium",
          "description": "ESET researchers have uncovered and analyzed a set of malicious tools used by the infamous Lazarus APT group in attacks against targets in the autumn of 2021, the first recorded abuse of a vulnerability in Windows.",
          "modified": "2022-11-03T05:04:20.106000",
          "created": "2022-10-04T05:39:05.449000",
          "tags": [
            "lazarus",
            "hidden cobra",
            "malware",
            "execution",
            "wannacryptor",
            "trojan"
          ],
          "references": [
            "https://www.welivesecurity.com/2022/09/30/amazon-themed-campaigns-lazarus-netherlands-belgium/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Belgium",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "BLINDINGCAN",
              "display_name": "BLINDINGCAN",
              "target": null
            },
            {
              "id": "",
              "display_name": "",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            }
          ],
          "industries": [
            "Defense",
            "Media",
            "Political",
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 2,
            "URL": 5,
            "domain": 5,
            "hostname": 2
          },
          "indicator_count": 33,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "1308 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633b1b17afbf935db3bd9c46",
          "name": "Amazon&#8209;themed campaigns of Lazarus in the Netherlands and Belgium | WeLiveSecurity",
          "description": "ESET researchers have uncovered and analyzed a set of tools used by the infamous Lazarus APT group in attacks against targets in the Netherlands and Belgium in 2021, the first recorded abuse of a vulnerability in Windows.",
          "modified": "2022-11-02T17:00:58.786000",
          "created": "2022-10-03T17:25:43.725000",
          "tags": [
            "lazarus",
            "hidden cobra",
            "toy guys",
            "blindingcan",
            "jd",
            "http",
            "figure",
            "c server",
            "belgium",
            "netherlands",
            "eset",
            "line",
            "eset research",
            "june",
            "malware",
            "august",
            "february",
            "execution",
            "wannacryptor",
            "wannacry",
            "polish",
            "themida",
            "vmprotect",
            "team",
            "dream",
            "trojan",
            "podcast"
          ],
          "references": [
            "https://www.welivesecurity.com/2022/09/30/amazon-themed-campaigns-lazarus-netherlands-belgium/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Belgium",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "JD",
              "display_name": "JD",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "BLINDINGCAN",
              "display_name": "BLINDINGCAN",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            }
          ],
          "industries": [
            "Defense",
            "Media",
            "Political",
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Cyber74Team",
            "id": "202637",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_202637/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 2,
            "URL": 5,
            "domain": 5,
            "hostname": 2
          },
          "indicator_count": 33,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 164,
          "modified_text": "1309 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633adb404f623511269ff590",
          "name": "Lazarus hackers abuse Dell driver bug",
          "description": "",
          "modified": "2022-11-02T12:00:03.754000",
          "created": "2022-10-03T12:53:20.945000",
          "tags": [],
          "references": [
            "October  03rd, 2022 - CryptoGen Cyber Threat Intelligence - Lazarus hackers abuse Dell driver bug .pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 1,
            "URL": 3,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 23,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 501,
          "modified_text": "1309 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633ad56b7c190989f85338dd",
          "name": "Hackers Exploiting Dell Driver Vulnerability to Deploy Rootkit on Targeted Computers",
          "description": "Lazurus Group targeting Dell Drivers to deploy rootkits via, phishing campaigns surround linkedIn message and phishing emails",
          "modified": "2022-11-02T11:01:50.038000",
          "created": "2022-10-03T12:28:27.571000",
          "tags": [
            "lazarus",
            "blindingcan",
            "lazarus http",
            "http",
            "c server",
            "execution",
            "startup folder",
            "themida",
            "vmprotect",
            "phishing"
          ],
          "references": [
            "https://www.welivesecurity.com/2022/09/30/amazon-themed-campaigns-lazarus-netherlands-belgium/",
            "https://thehackernews.com/2022/10/hackers-exploiting-dell-driver.html"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "BLINDINGCAN",
              "display_name": "BLINDINGCAN",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "BITSecurity",
            "id": "103352",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_103352/resized/80/avatar_1540652530.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 14,
            "FileHash-SHA256": 1,
            "URL": 3,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 22,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 242,
          "modified_text": "1309 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633ab01ce4f4ec2b536d321d",
          "name": "Amazon-themed campaigns of Lazarus in the Netherlands and Belgium | WeLiveSecurity",
          "description": "ESET researchers have uncovered and analyzed a set of tools used by the infamous Lazarus APT group in attacks against targets in the Netherlands and Belgium in 2021, the first recorded abuse of a vulnerability in Windows.",
          "modified": "2022-11-02T09:03:30.652000",
          "created": "2022-10-03T09:49:16.939000",
          "tags": [
            "lazarus",
            "hidden cobra",
            "toy guys",
            "blindingcan",
            "jd",
            "http",
            "figure",
            "c server",
            "belgium",
            "netherlands",
            "eset",
            "line",
            "eset research",
            "june",
            "malware",
            "august",
            "february",
            "execution",
            "wannacryptor",
            "wannacry",
            "polish",
            "themida",
            "vmprotect",
            "team",
            "dream",
            "trojan",
            "podcast"
          ],
          "references": [
            "https://www.welivesecurity.com/2022/09/30/amazon-themed-campaigns-lazarus-netherlands-belgium/"
          ],
          "public": 1,
          "adversary": "Lazarus",
          "targeted_countries": [
            "Belgium",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "JD",
              "display_name": "JD",
              "target": null
            },
            {
              "id": "Lazarus",
              "display_name": "Lazarus",
              "target": null
            },
            {
              "id": "BLINDINGCAN",
              "display_name": "BLINDINGCAN",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1104",
              "name": "Multi-Stage Channels",
              "display_name": "T1104 - Multi-Stage Channels"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            }
          ],
          "industries": [
            "Defense",
            "Media",
            "Political",
            "Aerospace"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 15,
            "FileHash-SHA256": 2,
            "URL": 5,
            "domain": 5,
            "hostname": 2
          },
          "indicator_count": 33,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1309 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633aae3ecadfce7eb1127cf9",
          "name": "ZINC weaponizing open-source software - Microsoft Security Blog",
          "description": "",
          "modified": "2022-11-02T09:03:30.652000",
          "created": "2022-10-03T09:41:18.024000",
          "tags": [
            "zinc",
            "putty",
            "microsoft",
            "sumatra pdf",
            "kitty",
            "dll search",
            "tightvnc viewer",
            "linkedin",
            "whatsapp",
            "reader",
            "zetanile",
            "defender",
            "june",
            "pass",
            "rats",
            "foggybrass",
            "twitter",
            "april",
            "blindingcan",
            "themida",
            "vmprotect",
            "daily",
            "win64",
            "look"
          ],
          "references": [
            "https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 8,
            "URL": 6,
            "domain": 4,
            "hostname": 3
          },
          "indicator_count": 29,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 865,
          "modified_text": "1309 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6335fd9e40732f30979d4487",
          "name": "ZINC weaponizing open-source software - Microsoft Security Blog",
          "description": "",
          "modified": "2022-10-29T18:03:45.010000",
          "created": "2022-09-29T20:18:38.019000",
          "tags": [
            "zinc",
            "putty",
            "microsoft",
            "sumatra pdf",
            "kitty",
            "dll search",
            "tightvnc viewer",
            "linkedin",
            "whatsapp",
            "reader",
            "zetanile",
            "defender",
            "june",
            "pass",
            "rats",
            "foggybrass",
            "twitter",
            "april",
            "blindingcan",
            "themida",
            "vmprotect",
            "daily",
            "win64",
            "look"
          ],
          "references": [
            "https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Cyber74Team",
            "id": "202637",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_202637/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 8,
            "URL": 6,
            "domain": 4,
            "hostname": 3
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 165,
          "modified_text": "1312 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6335d48bcfdda8c36f81d647",
          "name": "ZINC weaponizing open-source software - Microsoft Security Blog",
          "description": "",
          "modified": "2022-10-29T17:01:35.315000",
          "created": "2022-09-29T17:23:23.827000",
          "tags": [
            "zinc",
            "putty",
            "microsoft",
            "sumatra pdf",
            "kitty",
            "dll search",
            "tightvnc viewer",
            "linkedin",
            "whatsapp",
            "reader",
            "zetanile",
            "defender",
            "june",
            "pass",
            "rats",
            "foggybrass",
            "twitter",
            "april",
            "blindingcan",
            "themida",
            "vmprotect",
            "daily",
            "win64",
            "look"
          ],
          "references": [
            "https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "VertekLabs",
            "id": "168455",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_168455/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 8,
            "URL": 6,
            "domain": 4,
            "hostname": 3
          },
          "indicator_count": 27,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 562,
          "modified_text": "1313 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63251cc98a620fb45f9e48ef",
          "name": "ACTIVIDAD MALICIOSA | UNC4034 APT Y SU ACTIVIDAD",
          "description": "Los m\u00e9todos utilizados por UNC4034 en este compromiso, as\u00ed como los m\u00e9todos utilizados en las innumerables intrusiones investigadas por Mandiant, se utilizan para desarrollar y refinar continuamente las hip\u00f3tesis de b\u00fasqueda de amenazas dentro de Managed Defense. Proporcionan conclusiones muy precisas y pr\u00e1cticas que se basan en los m\u00e9todos de trabajo en evoluci\u00f3n de los actores de amenazas.",
          "modified": "2022-10-17T00:13:10.423000",
          "created": "2022-09-17T01:03:05.756000",
          "tags": [
            "t1021",
            "t1102",
            "servicio web",
            "t1187",
            "t1530",
            "datos",
            "t1560",
            "archivar datos",
            "t1027",
            "informacin",
            "url https",
            "rutas"
          ],
          "references": [
            "https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing",
            "https://www.alertasyseguridad.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1187",
              "name": "Forced Authentication",
              "display_name": "T1187 - Forced Authentication"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "esoporteingenieria2020",
            "id": "121604",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 6,
            "URL": 3,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 12,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 267,
          "modified_text": "1325 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "632445d91ab5b89337e31c5e",
          "name": "It's Time to PuTTY! DPRK Job Opportunity Phishing via WhatsApp | Mandiant",
          "description": "Find out more about Mandiant, the world's leading cyber security provider, at www.mandiant.co.uk.com and on-demand and free access to the company's services.",
          "modified": "2022-10-16T09:13:23.140000",
          "created": "2022-09-16T09:46:01.481000",
          "tags": [
            "apt29",
            "cuteloop",
            "airdry.v2",
            "airdry",
            "mandiant",
            "figure",
            "unc4034",
            "managed defense",
            "putty",
            "airdry backdoor",
            "http",
            "c2 server",
            "defense",
            "virustotal",
            "themida",
            "blindingcan"
          ],
          "references": [
            "https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "AIRDRY",
              "display_name": "AIRDRY",
              "target": null
            },
            {
              "id": "AIRDRY.V2",
              "display_name": "AIRDRY.V2",
              "target": null
            },
            {
              "id": "CUTELOOP",
              "display_name": "CUTELOOP",
              "target": null
            },
            {
              "id": "APT29",
              "display_name": "APT29",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1187",
              "name": "Forced Authentication",
              "display_name": "T1187 - Forced Authentication"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA256": 6,
            "URL": 3,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 19,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "1326 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "633fdf55a293e5c5ee21916f",
          "name": "APT Group Lazarus Exploits High Severity Flaw in Dell Driver",
          "description": "",
          "modified": "2022-10-07T08:12:05.004000",
          "created": "2022-10-07T08:12:05.004000",
          "tags": [
            "eset",
            "lazarus group",
            "cve202121551",
            "fudmodule",
            "logon autostart",
            "execution",
            "bring",
            "driver",
            "byovd",
            "dell firmware",
            "august",
            "blindingcan"
          ],
          "references": [
            "https://socradar.io/apt-group-lazarus-exploits-high-severity-flaw-in-dell-driver/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1587",
              "name": "Develop Capabilities",
              "display_name": "T1587 - Develop Capabilities"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fontwang1234",
            "id": "196068",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 13,
            "URL": 3,
            "domain": 2,
            "hostname": 1
          },
          "indicator_count": 19,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 50,
          "modified_text": "1335 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://unit42.paloaltonetworks.com/fireeye-solarstorm-sunburst/",
        "https://isc.sans.edu/diary/Qakbot+infection+with+Cobalt+Strike+and+VNC+activity/28448",
        "https://thedfirreport.com/2021/07/19/icedid-and-cobalt-strike-vs-antivirus/",
        "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-148a",
        "https://thedfirreport.com/2020/10/08/ryuks-return/",
        "https://www.cynet.com/security-foundations/attack-techniques/new-wave-of-emotet-when-project-x-turns-into-y/",
        "https://medium.com/walmartglobaltech/man1-moskal-hancitor-and-a-side-of-ransomware-d77b4d991618",
        "https://vanmieghem.io/blueprint-for-evading-edr-in-2022/",
        "https://www.sentinelone.com/labs/noblebaron-new-poisoned-installers-could-be-used-in-supply-chain-attacks/",
        "https://thedfirreport.com/2020/08/31/netwalker-ransomware-in-1-hour/",
        "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/",
        "https://blog.talosintelligence.com/building-bypass-with-msbuild/",
        "https://thedfirreport.com/2022/04/25/quantum-ransomware/",
        "https://blog.nviso.eu/2021/11/17/cobalt-strike-decrypting-obfuscated-traffic-part-4/",
        "https://medium.com/walmartglobaltech/trickbot-crews-new-cobaltstrike-loader-32c72b78e81c",
        "https://documents.trendmicro.com/assets/white_papers/wp-earth-baku-an-apt-group-targeting-indo-pacific-countries.pdf",
        "https://cloud.google.com/blog/topics/threat-intelligence/sabbath-ransomware-affiliate/",
        "https://alertas-y-seguridad.jimdosite.com/repositorio-ioc/",
        "https://thedfirreport.com/2021/09/13/bazarloader-to-conti-ransomware-in-32-hours/",
        "https://mal-eats.net/en/2021/05/11/campo_new_attack_campaign_targeting_japan/",
        "https://ics-cert.kaspersky.com/publications/reports/2022/06/27/attacks-on-industrial-control-systems-using-shadowpad/",
        "https://cloud.google.com/blog/topics/threat-intelligence/tracking-apt29-phishing-campaigns/",
        "https://mp.weixin.qq.com/s/cGS8FocPnUdBconLbbaG-g",
        "https://www.cybereason.com/blog/research/threat-analysis-report-datoploader-exploits-proxyshell-to-deliver-qbot-and-cobalt-strike",
        "https://cocomelonc.github.io/malware/2022/07/30/malware-av-evasion-8.html",
        "https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html",
        "https://raw.githubusercontent.com/StrangerealIntel/CyberThreatIntel/refs/heads/master/China/APT/Chimera/Analysis.md",
        "https://thehackernews.com/2022/05/this-new-fileless-malware-hides.html",
        "https://isc.sans.edu/diary/rss/26862",
        "https://blog-assets.f-secure.com/wp-content/uploads/2020/03/18122307/F-Secure_Dukes_Whitepaper.pdf",
        "https://www.guidepointsecurity.com/blog/from-zloader-to-darkside-a-ransomware-story/",
        "https://blog.nviso.eu/2022/07/20/analysis-of-a-trojanized-jquery-script-gootloader-unleashed/",
        "https://thedfirreport.com/2022/03/07/2021-year-in-review/",
        "https://www.virustotal.com/graph/embed/gc9d8101923d24588b6c83b20613a1bf0bb3b5b0a38654f7a8cc81f1d16e0be9d?theme=light",
        "https://blog.sekoia.io/nobeliums-envyscout-infection-chain-goes-in-the-registry-targeting-embassies/",
        "https://www.crowdstrike.com/en-us/blog/carbon-spider-sprite-spider-target-esxi-servers-with-ransomware/?utm_campaign=blog&utm_medium=soc&utm_source=twtr&utm_content=sprout",
        "https://www.sentinelone.com/blog/hive-ransomware-deploys-novel-ipfuscation-technique/",
        "https://isc.sans.edu/diary/27308",
        "https://www.trendmicro.com/en_us/research/21/a/earth-wendigo-injects-javascript-backdoor-to-service-worker-for-.html",
        "https://github.com/infinitumitlabs/Karakurt-Hacking-Team-CTI",
        "https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/",
        "https://teamt5.org/tw/posts/mjib-holds-briefing-on-chinese-hackers-attacks-on-taiwanese-government-agencies/",
        "https://www.sentinelone.com/blog/threat-actor-uac-0056-targeting-ukraine-with-fake-translation-software/",
        "https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/",
        "https://www.security.com/threat-intelligence/yanluowang-ransomware-attacks-continue",
        "https://isc.sans.edu/diary/Bumblebee+Malware+from+TransferXL+URLs/28664",
        "October  03rd, 2022 - CryptoGen Cyber Threat Intelligence - Lazarus hackers abuse Dell driver bug .pdf",
        "https://malcat.fr/blog/lnk-forensic-and-config-extraction-of-a-cobalt-strike-beacon/",
        "https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/",
        "https://cert.gov.ua/article/619229",
        "https://thedfirreport.com/2021/06/28/hancitor-continues-to-push-cobalt-strike/",
        "https://cloud.google.com/blog/topics/threat-intelligence/evolution-of-fin7/",
        "https://www.sonatype.com/blog/new-pymafka-malicious-package-drops-cobalt-strike-on-macos-windows-linux",
        "https://blog.talosintelligence.com/avoslocker-new-arsenal/",
        "https://www.welivesecurity.com/2022/09/30/amazon-themed-campaigns-lazarus-netherlands-belgium/",
        "https://securelist.com/apt-luminousmoth/103332/",
        "https://thehackernews.com/2022/10/hackers-exploiting-dell-driver.html",
        "https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/",
        "https://www.alertasyseguridad.com/",
        "https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html",
        "https://contagiodump.blogspot.com/2017/02/russian-apt-apt28-collection-of-samples.html",
        "https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2-profile/",
        "https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra/",
        "https://medium.com/walmartglobaltech/investigation-into-the-state-of-nim-malware-part-2-a28bffffa671",
        "https://cloud.google.com/blog/topics/threat-intelligence/melting-unc2198-icedid-to-ransomware-operations/",
        "https://cloud.google.com/blog/topics/threat-intelligence/apt41-us-state-governments/",
        "https://kienmanowar.wordpress.com/2022/06/04/quicknote-cobaltstrike-smb-beacon-analysis-2/",
        "https://security.macnica.co.jp/blog/2022/05/iso.html",
        "https://www.proofpoint.com/us/blog/threat-insight/nimzaloader-ta800s-new-initial-access-malware",
        "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/",
        "https://isc.sans.edu/diary/Emotet%20infection%20with%20Cobalt%20Strike/28824",
        "https://mp.weixin.qq.com/s/xPsEXp2J5IE7wNSMEVC24A",
        "https://unit42.paloaltonetworks.com/fireeye-red-team-tool-breach/",
        "https://resource.redcanary.com/rs/003-YRU-314/images/2022_ThreatDetectionReport_RedCanary.pdf",
        "https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/",
        "https://www.esentire.com/blog/conti-affiliate-exposed-new-domain-names-ip-addresses-and-email-addresses-uncovered-by-esentire",
        "https://www.welivesecurity.com/2022/04/13/eset-takes-part-global-operation-disrupt-zloader-botnets/",
        "https://www.welivesecurity.com/2021/08/24/sidewalk-may-be-as-dangerous-as-crosswalk/",
        "https://www.microsoft.com/en-us/security/blog/2022/09/29/zinc-weaponizing-open-source-software/?ranMID=46137&ranEAID=je6NUbpObpQ&ranSiteID=je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A&epi=je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A&irgwc=1&OCID=AIDcmm549zy227_aff_7792_1243925&tduid=%28ir__1jzmmrmv2skfd09mw9hoedxrnv2xbzpdmhhcftum00%29%287792%29%281243925%29%28je6NUbpObpQ-c.Fjj4H8riK2h6MbDyvZ3A%29%28%29&irclickid=_1jzmmrmv2skfd09mw9hoedxrnv2xbzpdmhhcftum00",
        "https://i.blackhat.com/Asia-22/Thursday-Materials/AS-22-LeonSilvia-NextGenPlugXShadowPad.pdf",
        "https://medium.com/walmartglobaltech/investigation-into-the-state-of-nim-malware-14cc543af811",
        "https://cyber.wtf/2022/03/23/what-the-packer/",
        "https://cert.gov.ua/article/37704",
        "https://forensicitguy.github.io/inspecting-powershell-cobalt-strike-beacon/",
        "https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/",
        "https://www.crowdstrike.com/en-us/blog/prophet-spider-exploits-oracle-weblogic-to-facilitate-ransomware-activity/",
        "https://thehackernews.com/2022/05/malware-analysis-trickbot.html",
        "https://blog.gigamon.com/2021/09/10/rendering-threats-a-network-perspective/",
        "https://www.elastic.co/blog/detecting-cobalt-strike-with-memory-signatures",
        "https://www.security.com/threat-intelligence/solarwinds-raindrop-malware",
        "https://www.morphisec.com/blog/vmware-identity-manager-attack-backdoor/",
        "https://blog.talosintelligence.com/manjusaka-offensive-framework/",
        "https://www.sentinelone.com/labs/contagious-interview-threat-actors-scout-cyber-intel-platforms-reveal-plans-and-ops",
        "https://isc.sans.edu/diary/Excel+spreadsheets+push+SystemBC+malware/27060",
        "https://cocomelonc.github.io/tutorial/2022/04/20/malware-pers-1.html",
        "https://cocomelonc.github.io/tutorial/2022/05/09/malware-pers-4.html",
        "https://www.cynet.com/blog/orion-threat-alert-flight-of-the-bumblebee/",
        "https://thedfirreport.com/2021/05/02/trickbot-brief-creds-and-beacons/",
        "https://raw.githubusercontent.com/AmnestyTech/investigations/refs/heads/master/2021-02-24_vietnam/README.md",
        "https://www.sentinelone.com/labs/the-anatomy-of-an-apt-attack-and-cobaltstrike-beacons-encoded-configuration/",
        "https://thedfirreport.com/2021/06/20/from-word-to-lateral-movement-in-1-hour/",
        "https://blog.talosintelligence.com/lemon-duck-spreads-wings/",
        "https://www.crowdstrike.com/en-us/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/",
        "https://isc.sans.edu/diary/rss/28752",
        "https://isc.sans.edu/diary/rss/27618",
        "https://cloud.google.com/blog/topics/threat-intelligence/darkside-affiliate-supply-chain-software-compromise",
        "https://www.ish.com.br/blog/principais-ameacas-que-visam-o-brasil-lazarus-group/",
        "https://raw.githubusercontent.com/ThreatConnect-Inc/research-team/refs/heads/master/IOCs/WizardSpider-UNC1878-Ryuk.csv",
        "https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29/",
        "https://otx.alienvault.com/pulse/6516dc1c66c2a9a03166669f",
        "https://www.gendigital.com/blog/insights/research/backdoored-client-from-mongolian-ca-monpass",
        "https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/",
        "https://cert-agid.gov.it/news/il-malware-envyscout-apt29-e-stato-veicolato-anche-in-italia/",
        "https://unit42.paloaltonetworks.com/bazarloader-network-reconnaissance/",
        "https://www.lac.co.jp/lacwatch/report/20210521_002618.html",
        "https://raw.githubusercontent.com/Dump-GUY/Malware-analysis-and-Reverse-engineering/refs/heads/main/APT29_C2-Client_Dropbox_Loader/APT29-DropboxLoader_analysis.md",
        "https://medium.com/walmartglobaltech/cobaltstrike-uuid-stager-ca7e82f7bb64",
        "https://www.trendmicro.com/en_gb/research/21/k/analyzing-proxyshell-related-incidents-via-trend-micro-managed-x.html",
        "https://isc.sans.edu/diary/28636",
        "https://www.gendigital.com/blog/insights/research/decoding-cobalt-strike-understanding-payloads",
        "https://www.arashparsa.com/catching-a-malware-with-no-name/",
        "https://web-assets.esetstatic.com/wls/2019/10/ESET_Operation_Ghost_Dukes.pdf",
        "https://thedfirreport.com/2020/04/24/ursnif-via-lolbins/",
        "https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-009.pdf",
        "https://mal-eats.net/2021/05/10/campo_new_attack_campaign_targeting_japan/",
        "https://i.blackhat.com/USA-20/Thursday/us-20-Chen-Operation-Chimera-APT-Operation-Targets-Semiconductor-Vendors.pdf",
        "https://www.picussecurity.com/resource/blog/ttps-used-in-the-solarwinds-breach",
        "https://www.threatdown.com/blog/a-multi-stage-powershell-based-attack-targets-kazakhstan/",
        "https://blog.bushidotoken.net/2022/06/overview-of-russian-gru-and-svr.html",
        "https://www.mandiant.com/resources/blog/dprk-whatsapp-phishing",
        "https://securelist.com/a-new-secret-stash-for-fileless-malware/106393/",
        "https://blog.talosintelligence.com/mustang-panda-targets-europe/",
        "https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/",
        "https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/5/",
        "https://www.unh4ck.com/detection-engineering-and-threat-hunting/lateral-movement/detecting-conti-cobaltstrike-lateral-movement-techniques-part-1",
        "https://www.trendmicro.com/en_us/research/22/g/gootkit-loaders-updated-tactics-and-fileless-delivery-of-cobalt-strike.html",
        "https://medium.com/walmartglobaltech/signed-dll-campaigns-as-a-service-7760ac676489",
        "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/new-apt-group-chamelgang/",
        "https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a/",
        "https://cloud.google.com/blog/topics/threat-intelligence/spear-phish-ukrainian-entities/",
        "https://i.blackhat.com/eu-20/Wednesday/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations-wp.pdf",
        "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/new-apt-group-chamelgang/#id3",
        "https://www.crowdstrike.com/en-us/blog/how-falcon-complete-disrupts-ecrime-operators-wizard-spider/",
        "https://www.crowdstrike.com/en-us/blog/bears-midst-intrusion-democratic-national-committee/",
        "https://www.threatdown.com/blog/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign/",
        "https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/",
        "https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/",
        "https://thedfirreport.com/2021/08/01/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike/",
        "https://cert.gov.ua/article/703548",
        "https://www.cisa.gov/news-events/analysis-reports/ar21-148a",
        "https://www.security.com/threat-intelligence/harvester-new-apt-attacks-asia",
        "https://cloud.google.com/blog/topics/threat-intelligence/shining-a-light-on-darkside-ransomware-operations/",
        "entities (48).csv",
        "https://cert.ssi.gouv.fr/uploads/20220427_NP_TLPWHITE_ANSSI_FIN7.pdf",
        "https://www.varonis.com/blog/hive-ransomware-analysis",
        "https://asec.ahnlab.com/en/31811/",
        "https://blog.talosintelligence.com/indigodrop-maldocs-cobalt-strike/",
        "https://www.cynet.com/security-foundations/attack-techniques/understanding-squirrelwaffle/",
        "https://www.truesec.com/hub/blog/proxyshell-qbot-and-conti-ransomware-combined-in-a-series-of-cyber-attacks",
        "https://www.cybereason.com/blog/cybereason-vs-egregor-ransomware",
        "https://www.netresec.com/?page=Blog&month=2021-04&post=Analysing-a-malware-PCAP-with-IcedID-and-Cobalt-Strike-traff",
        "https://thedfirreport.com/2021/01/31/bazar-no-ryuk/",
        "https://cloud.google.com/blog/topics/threat-intelligence/unc2165-shifts-to-evade-sanctions",
        "https://tccontre.blogspot.com/2019/11/cobaltstrike-beacondll-your-not.html",
        "https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/",
        "https://unit42.paloaltonetworks.com/unit-42-technical-analysis-seaduke/",
        "https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis",
        "https://www.ncsc.gov.ie/pdfs/HSE_Conti_140521_UPDATE.pdf",
        "https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/i/ssl-tls-technical-brief/ssl-tls-technical-brief.pdf",
        "https://www.qurium.org/alerts/targeted-malware-against-crph/",
        "https://medium.com/walmartglobaltech/socgholish-campaigns-and-initial-access-kit-4c4283fea8ee",
        "https://www.esentire.com/blog/icedid-to-cobalt-strike-in-under-20-minutes",
        "https://i.blackhat.com/eu-20/Wednesday/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations.pdf",
        "https://cloud.google.com/blog/topics/threat-intelligence/kegtap-and-singlemalt-with-a-ransomware-chaser/",
        "https://www.security.com/threat-intelligence/sodinokibi-ransomware-cobalt-strike-pos",
        "https://asec.ahnlab.com/en/34549/",
        "https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encoding-decoding/",
        "https://unit42.paloaltonetworks.com/hancitor-infections-cobalt-strike/",
        "https://thedfirreport.com/2020/11/05/ryuk-speed-run-2-hours-to-ransom/",
        "https://istrosec.com/blog/apt-sk-cobalt/",
        "https://socradar.io/apt-group-lazarus-exploits-high-severity-flaw-in-dell-driver/",
        "https://www.sentinelone.com/blog/from-the-front-lines-peering-into-a-pysa-ransomware-attack/",
        "https://redcanary.com/wp-content/uploads/2022/05/Gootloader.pdf",
        "https://thedfirreport.com/2021/03/08/bazar-drops-the-anchor/",
        "https://contagiodump.blogspot.com/2014/11/onionduke-samples.html",
        "https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/",
        "https://documents.trendmicro.com/assets/txt/earth-berberoka-windows-iocs-2.txt",
        "https://thedfirreport.com/2021/05/12/conti-ransomware/",
        "https://www.cisa.gov/sites/default/files/publications/AR-17-20045_Enhanced_Analysis_of_GRIZZLY_STEPPE_Activity.pdf",
        "https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/",
        "https://www.fortinet.com/blog/threat-research/nobelium-returns-to-the-political-world-stage",
        "https://www.zscaler.com/blogs/security-research/targeted-attack-leverages-india-china-border-dispute-lure-victims"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "Contagious Interview",
            "Lazarus"
          ],
          "malware_families": [],
          "industries": [
            "Aerospace",
            "Technology",
            "Finance"
          ]
        },
        "other": {
          "adversary": [
            "Threat",
            "Zinc",
            "Lazarus",
            "Lazarus Group"
          ],
          "malware_families": [
            "",
            "Nbtscan",
            "Shadow chaser",
            "Credomap",
            "Lightlesscan",
            "Stellarparticle",
            "Cozybear",
            "Elf",
            "Primary threat",
            "Ransomhub",
            "Cuteloop",
            "Netsupport",
            "Gootloader",
            "Beacon",
            "Hades",
            "Trickbot",
            "Microbackdoor",
            "Wannacry",
            "Frp",
            "Socgholish netsupport",
            "Heimdall",
            "Kw",
            "Apt29",
            "Raspberry robin",
            "Matanbuchus",
            "Conti",
            "Win api",
            "Graphsteel",
            "Trojan:win64/lazarus",
            "Shadowpad",
            "Threat",
            "Cyclops",
            "Kronos",
            "Avoslocker",
            "Trojan:win32/lazarus",
            "Generic.933739",
            "Bazarloader",
            "Grimplant",
            "Beaconloader",
            "Manuscrypt",
            "Pcap",
            "Https",
            "Kt",
            "Nickelloader",
            "Threat analysis",
            "Plugx",
            "Darkside",
            "Jd",
            "Win32.agent",
            "Lazarus",
            "Handleref",
            "Ryuk",
            "Blindingcan",
            "Airdry",
            "Airdry.v2",
            "Cobalt strike",
            "Bumblebee",
            "Gold blackburn",
            "Win32.bitcoinminer",
            "Socgholish",
            "Doorme",
            "Ku",
            "Miniblindingcan",
            "Fancybear"
          ],
          "industries": [
            "Aviation",
            "Media",
            "Government",
            "Pharmaceutical",
            "Political",
            "Foreign affairs",
            "Logistics",
            "Transport",
            "Academics",
            "Diplomatic",
            "Aerospace",
            "Energy",
            "Military",
            "Gas",
            "Technology",
            "Defense",
            "Transportation",
            "Legal",
            "Telecommunications",
            "Banking",
            "Financial",
            "Industrial",
            "Manufacturing"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 27,
  "pulses": [
    {
      "id": "68b9d266a57b122998115dc6",
      "name": "Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms",
      "description": "North Korean threat actors associated with the Contagious Interview campaign cluster are actively monitoring cyber threat intelligence platforms to detect infrastructure exposure and scout for new assets. They operate in coordinated teams, likely using Slack for real-time collaboration, and leverage multiple intelligence sources including Validin, VirusTotal, and Maltrail. Despite being aware of their infrastructure's detectability, they make only limited changes to reduce detection risk, focusing instead on rapidly deploying new infrastructure to sustain operations. The actors' effectiveness is evident in their engagement of over 230 victims between January and March 2025, primarily targeting individuals in the cryptocurrency industry. Their activities involve sophisticated social engineering tactics, including the ClickFix technique, to trick targets into executing malware.",
      "modified": "2025-10-04T17:00:59.344000",
      "created": "2025-09-04T17:54:46.837000",
      "tags": [
        "cyber espionage",
        "social engineering",
        "north korea",
        "job seeker targeting",
        "clickfix",
        "lazarus",
        "infrastructure monitoring",
        "cryptocurrency",
        "contagiousdrop"
      ],
      "references": [
        "https://www.sentinelone.com/labs/contagious-interview-threat-actors-scout-cyber-intel-platforms-reveal-plans-and-ops"
      ],
      "public": 1,
      "adversary": "Contagious Interview",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1589",
          "name": "Gather Victim Identity Information",
          "display_name": "T1589 - Gather Victim Identity Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1586",
          "name": "Compromise Accounts",
          "display_name": "T1586 - Compromise Accounts"
        },
        {
          "id": "T1608",
          "name": "Stage Capabilities",
          "display_name": "T1608 - Stage Capabilities"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1585",
          "name": "Establish Accounts",
          "display_name": "T1585 - Establish Accounts"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        },
        {
          "id": "T1587",
          "name": "Develop Capabilities",
          "display_name": "T1587 - Develop Capabilities"
        }
      ],
      "industries": [
        "Finance",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 44164,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 116,
        "FileHash-SHA1": 99,
        "FileHash-SHA256": 246,
        "CVE": 1,
        "domain": 2140,
        "hostname": 1231
      },
      "indicator_count": 3833,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 387149,
      "modified_text": "242 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6516dc1c66c2a9a03166669f",
      "name": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
      "description": "The fake recruiter contacted the victim via LinkedIn Messaging, a feature within the LinkedIn professional social networking platform, and sent two coding challenges required as part of a hiring process, which the victim downloaded and executed on a company device. The first challenge is a very basic project that displays the text \u201cHello, World!\u201d, the second one prints a Fibonacci sequence \u2013 a series of numbers in which each number is the sum of the two preceding ones. ESET Research was able to reconstruct the initial access steps and analyze the toolset used by Lazarus thanks to cooperation with the affected aerospace company.",
      "modified": "2023-10-29T14:01:08.677000",
      "created": "2023-09-29T14:15:55.789000",
      "tags": [
        "LinkedIn",
        "Lazarus",
        "cyberespionage",
        "NickelLoader",
        "RAT",
        "LightlessCan",
        "miniBlindingCan"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [
        "Spain"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1135",
          "name": "Network Share Discovery",
          "display_name": "T1135 - Network Share Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1585",
          "name": "Establish Accounts",
          "display_name": "T1585 - Establish Accounts"
        },
        {
          "id": "T1593",
          "name": "Search Open Websites/Domains",
          "display_name": "T1593 - Search Open Websites/Domains"
        },
        {
          "id": "T1608",
          "name": "Stage Capabilities",
          "display_name": "T1608 - Stage Capabilities"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1530",
          "name": "Data from Cloud Storage Object",
          "display_name": "T1530 - Data from Cloud Storage Object"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        }
      ],
      "industries": [
        "Aerospace"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 418,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 13,
        "domain": 5,
        "hostname": 5
      },
      "indicator_count": 23,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 387150,
      "modified_text": "948 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f46a108000bd36fe90d5be",
      "name": "APT29",
      "description": "In the latest episode of the LNK forensic analysis series, we look at how a malicious file was linked to a Chinese-speaking threat actor, who then modified the file to target a powershell program.",
      "modified": "2026-05-31T06:03:25.904000",
      "created": "2026-05-01T08:53:34.200000",
      "tags": [
        "sha1",
        "ipv4",
        "sha256",
        "n cobalt",
        "n https",
        "strong",
        "rararchive",
        "backdoor",
        "n c2",
        "cobalt strike",
        "guloader",
        "cobaltstrike",
        "cobalt",
        "downloader",
        "april",
        "icedid",
        "dropper",
        "june",
        "trickbot",
        "donut",
        "fast",
        "payload",
        "unknown",
        "delphi",
        "noname",
        "anydesk",
        "blister",
        "quasar",
        "winnti",
        "somnia",
        "qakbot",
        "gogo",
        "netwire",
        "chrysalis",
        "download",
        "exploit",
        "netspy",
        "loader",
        "ursnif",
        "themida",
        "vidar",
        "doublezero",
        "voldemort",
        "next",
        "meterpreter",
        "tencent",
        "plugx",
        "shadow",
        "batloader",
        "redline stealer",
        "havoc",
        "resident",
        "decoy",
        "dump",
        "shellcode",
        "infostealer",
        "appe",
        "bumblebee",
        "emotet",
        "syscall",
        "acidrain",
        "credomap",
        "cozyduke",
        "ukraine",
        "daveshell",
        "cont",
        "refer",
        "fail",
        "first",
        "snake",
        "mega",
        "onlin",
        "grayrabbit",
        "open",
        "power",
        "august",
        "test",
        "path",
        "mimikatz",
        "nbtscan",
        "impacket",
        "comment",
        "install",
        "redline",
        "comet",
        "autoit",
        "wiper",
        "endurance",
        "sharphound",
        "psexec",
        "malicious",
        "service",
        "wind",
        "installer",
        "info",
        "confi",
        "remcosrat",
        "hermeticwiper",
        "isaacwiper",
        "graphsteel",
        "caddywiper",
        "grimplant",
        "industroyer2",
        "defense",
        "energy",
        "telecom",
        "media",
        "grapeloader",
        "wineloader",
        "envyscout",
        "sunburst",
        "panda",
        "metasploit",
        "sparkrat",
        "zbot",
        "darkgate",
        "finspy",
        "rhadamanthys",
        "warmcookie",
        "trojanspy",
        "diceloader",
        "asyncrat",
        "esxiargs",
        "webshell",
        "cerber",
        "azorult",
        "lokibot",
        "blackcat",
        "poortry",
        "cuba",
        "malcat",
        "ctrlt",
        "transform",
        "bazaar",
        "virustotal",
        "window",
        "pdf document",
        "iit app",
        "tools",
        "lucky",
        "injector",
        "handleref",
        "temp",
        "conti",
        "groupexchange",
        "group400",
        "grouprevil",
        "revilconti",
        "providerpath",
        "regexpandsz",
        "minidump",
        "groupuchebkac",
        "malware",
        "bypass",
        "adfind",
        "threat",
        "command",
        "procdump",
        "seatbelt",
        "below",
        "anydesk remote",
        "lsass",
        "powershell",
        "cookie",
        "android",
        "null",
        "sliver",
        "initial access",
        "code",
        "defender",
        "defense evasion",
        "enterprise",
        "powerview",
        "pipes",
        "cloud",
        "date",
        "poison",
        "advantage",
        "mind",
        "designer",
        "shell",
        "projector libra",
        "bazarloader",
        "figure",
        "file size",
        "transferxl",
        "palo alto",
        "iso image",
        "windows",
        "wildfire",
        "february",
        "alliance",
        "bazarbackdoor",
        "bokbot",
        "diavol",
        "shown",
        "hook",
        "threat spotlight",
        "manjusaka",
        "c2 server",
        "appliance",
        "cisco talos",
        "golang",
        "haixi mongol",
        "prefecture",
        "talos",
        "rust",
        "agent",
        "win64",
        "hello",
        "xor algorithms",
        "z85 ascii85",
        "base85",
        "ascii85",
        "compile",
        "z85 https",
        "threat analysis",
        "primary threat",
        "elf",
        "strike payload",
        "uri http",
        "post body",
        "lockbit",
        "sentinellabs",
        "c curl",
        "ip address",
        "lockbit black",
        "cyber threats",
        "investigations",
        "research",
        "expert perspective",
        "articles",
        "news",
        "reports",
        "learn",
        "trend vision",
        "vision one",
        "gootkit",
        "trend micro",
        "amsi telemetry",
        "micro",
        "gootkit loader",
        "security",
        "stop",
        "find",
        "life",
        "operations",
        "protect",
        "small",
        "carriers",
        "voice",
        "attack",
        "suncrypt",
        "revil",
        "sodinokibi",
        "kronos",
        "korean",
        "createobject",
        "javascript",
        "ascii value",
        "opens",
        "urls",
        "color1",
        "python script",
        "gootloader",
        "twitter",
        "python",
        "unc1151",
        "microbackdoor",
        "beacon",
        "base64",
        "github",
        "run registry",
        "putty",
        "persistence",
        "discord",
        "blackenergy",
        "state",
        "uac0056",
        "detection",
        "threatdown",
        "cybercrime has",
        "machinescale",
        "response",
        "nebula",
        "indirizzo",
        "il file",
        "questo cert",
        "italia",
        "il messaggio",
        "allegato",
        "covid19",
        "file pdf",
        "html",
        "serbia",
        "stata",
        "file location",
        "https traffic",
        "thursday",
        "windows host",
        "wireshark",
        "emotet run",
        "pakistan",
        "ttps",
        "shadowpad",
        "plugx backdoor",
        "kaspersky ics",
        "afghanistan",
        "malaysia",
        "march",
        "cert",
        "ntlm",
        "winrar",
        "assembly",
        "china chopper",
        "microsoft",
        "fancybear",
        "cozybear",
        "december",
        "strontium",
        "ransomhub",
        "matrix",
        "raspberry robin",
        "sofacy",
        "beatdrop",
        "quietexit",
        "cyclops",
        "knight",
        "bank",
        "facebook",
        "beer",
        "worm",
        "threat advisory",
        "ransomware",
        "threats",
        "securex",
        "avos",
        "unified access",
        "gateways",
        "avoslocker",
        "cisco secure",
        "vmware horizon",
        "darkcomet",
        "apt29",
        "nobelium",
        "stellarparticle",
        "shadow chaser",
        "file type",
        "sha256 hash",
        "html file",
        "pe32",
        "intel",
        "matanbuchus",
        "confluence",
        "data center",
        "server",
        "waf rule",
        "confluence data",
        "shut",
        "jars",
        "cvss",
        "update",
        "centerall",
        "mustang panda",
        "vietnam",
        "analyze",
        "dll file",
        "summary",
        "vincss",
        "vietnamese",
        "english",
        "unc2165",
        "evil corp",
        "fakeupdates",
        "dridex",
        "hades",
        "colorfake",
        "bitpaymer",
        "doppelpaymer",
        "wastedlocker",
        "megasync",
        "trojan",
        "payloadbin",
        "macaw",
        "cuba ransomware",
        "tor directory",
        "bughatch",
        "iis worker",
        "mare",
        "team",
        "zenpak",
        "impact",
        "mosquito",
        "exfiltration",
        "execution",
        "masquerading",
        "netsupport rat",
        "select",
        "script",
        "hash",
        "press enter",
        "http",
        "activexobject",
        "lnk file",
        "socgholish",
        "servhelper",
        "fakeupdate",
        "model",
        "socgholish netsupport",
        "netsupport",
        "ta551",
        "ryuk",
        "threat actor",
        "hta file",
        "trickbot c2",
        "sonatype",
        "drops cobalt",
        "strike",
        "pymafka",
        "open source",
        "contact us",
        "macos",
        "nexus",
        "demo",
        "protected",
        "friday",
        "gold blackburn",
        "ahnlab",
        "was1",
        "was2",
        "dc server",
        "coinminer",
        "ntlm hash",
        "january",
        "ad group",
        "darkside",
        "miner",
        "win32.bitcoinminer",
        "win32.agent",
        "frp",
        "transferxl url",
        "iso file",
        "bumblebee c2",
        "file name",
        "exotic lily",
        "transferxl urls",
        "function",
        "dropbox",
        "c2 dropbox",
        "c2clientmain",
        "filename",
        "av evasion",
        "syswhispers2",
        "dropbox loader",
        "stream",
        "mark",
        "back",
        "pcap",
        "ta578",
        "contact forms",
        "images evidence",
        "windows service",
        "main entry",
        "a service",
        "service main",
        "entry point",
        "windows context",
        "administrator",
        "concept",
        "https",
        "lazagne",
        "setmppreference",
        "use ie",
        "msie",
        "windows nt",
        "bloodhound",
        "wmiexec",
        "covenant",
        "empire",
        "poshc2",
        "organization",
        "cleanup",
        "winscp",
        "dword",
        "netscan",
        "http c2",
        "base64url",
        "c2 traffic",
        "netbios",
        "teamserver",
        "mask",
        "legezo",
        "windows event",
        "denis legezo",
        "september",
        "silent break",
        "windows system",
        "rc4 encryption",
        "sysdig",
        "plugx implant",
        "myanmar",
        "russia",
        "hong kong",
        "reddelta",
        "belarus",
        "digital certificates",
        "fileless malware",
        "malware descriptions",
        "malware technologies",
        "rat trojan",
        "targeted attacks",
        "silentbreak",
        "throwback",
        "linode",
        "slingshot",
        "inject",
        "patch",
        "magic",
        "mozilla",
        "false",
        "\u30b5\u30a4\u30d0\u30fc\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3",
        "\u30de\u30af\u30cb\u30ab\u30cd\u30c3\u30c8\u30ef\u30fc\u30af\u30b9",
        "word",
        "stager",
        "url https",
        "windows10",
        "dll sideloading",
        "ida pro",
        "darkhotel",
        "oceanlotus",
        "mandiant",
        "boommic",
        "group policy",
        "smb beacon",
        "trello",
        "kerberos",
        "pass",
        "vaporrage",
        "platform sha256",
        "urls http",
        "unc2452",
        "opsec",
        "scale",
        "apt29 activity",
        "apt29 conduct",
        "global func",
        "vmware xfer",
        "edrepp",
        "vmware command",
        "dfir team",
        "abcd",
        "stealbit",
        "stdout",
        "hooks",
        "logic",
        "dfir report",
        "icedid malware",
        "icedid payload",
        "pty ltd",
        "goodware",
        "string",
        "desktop",
        "morphisec",
        "vmware identity",
        "morphisec labs",
        "core impact",
        "vmware",
        "workspace one",
        "access",
        "cve202222957",
        "cve202222958",
        "fortune",
        "jssloader",
        "stark",
        "moving",
        "please",
        "virtualbox",
        "registry",
        "windows logon",
        "hive",
        "varonis",
        "ai security",
        "proxyshell",
        "detect",
        "data risk",
        "google cloud",
        "trust",
        "varonis threat",
        "contact",
        "qbot",
        "void",
        "police",
        "pysa",
        "chisel",
        "files",
        "where",
        "pysa ransomware",
        "redacted",
        "force",
        "getchilditem",
        "aes key",
        "szdrf",
        "mespinoza",
        "target",
        "winapi",
        "edr hooks",
        "winapi call",
        "endpoint",
        "tracing",
        "api call",
        "direct system",
        "phase",
        "import",
        "outflank",
        "dll payload",
        "bumblebee dll",
        "programdata",
        "orion",
        "strings",
        "example",
        "zloader",
        "eset research",
        "atera agent",
        "eset",
        "aitb",
        "eset security",
        "tips",
        "silent",
        "night",
        "botnet",
        "teamviewer",
        "atera",
        "capture",
        "grantedaccess",
        "computer",
        "lsass memory",
        "targetimage",
        "sourceimage",
        "simulate",
        "atomic",
        "karakurt",
        "view",
        "hacking team",
        "sign",
        "contributors",
        "from karakurt",
        "appearance",
        "manage",
        "write",
        "star",
        "stars",
        "ruby",
        "footer",
        "birdwatch",
        "fin7",
        "easylook",
        "unc3381",
        "powerplant",
        "crowview",
        "boatlaunch",
        "stoneboat",
        "fowlgaze",
        "uuid variant",
        "hell",
        "ipfuscation",
        "james haughom",
        "ipfuscated",
        "gate variant",
        "gate",
        "rubeus",
        "wow64",
        "cp1250",
        "uuids",
        "touch",
        "blob",
        "hwinithlw",
        "sphw",
        "shathak",
        "conti affiliate",
        "valentine",
        "favorite",
        "rats",
        "ragnarlocker",
        "hellokitty",
        "squirrelwaffle",
        "uris",
        "http get",
        "post",
        "http post",
        "c2 profile",
        "accept",
        "vnc activity",
        "ms windows",
        "go downloader",
        "unc2589",
        "ta471",
        "sentinelone",
        "module stomp",
        "return address",
        "cobalt strikes",
        "rtlallocateheap",
        "use section",
        "dlls",
        "first detection",
        "apt41",
        "dustpan",
        "cve202144207",
        "cve202144228",
        "log4shell",
        "vmprotect",
        "deadeye",
        "keyplug",
        "filler",
        "confuserex",
        "badpotato",
        "task manager",
        "lsass process",
        "cisa",
        "bazar",
        "hancitor",
        "splashtop",
        "kportscan",
        "story",
        "emotet payload",
        "excel",
        "appdatalocal",
        "november",
        "emotet campaign",
        "vba macro",
        "cybercrime",
        "cybersecurity architect",
        "threat research",
        "jarm signature",
        "sha2",
        "jarm",
        "salesforce",
        "epoch",
        "emotet core",
        "epochs",
        "conti group",
        "emotet epoch",
        "trickbot group",
        "prior",
        "threat response",
        "unit",
        "socs",
        "hunters",
        "cyber",
        "mssql",
        "mssql server",
        "lemon duck",
        "asec analysis",
        "account",
        "kingminer",
        "vollgar",
        "mssql process",
        "cve20201472",
        "reg add",
        "regdword",
        "makes",
        "et exploit",
        "core",
        "possible",
        "comspec",
        "tracker",
        "userdomain",
        "appdata",
        "hide",
        "vbscript",
        "exclusionpath",
        "userpcname",
        "ipcount",
        "gozi",
        "cybereason",
        "exchange",
        "datoploader",
        "cybereason xdr",
        "report",
        "phishing",
        "pinkslipbot",
        "theft",
        "beyond",
        "never",
        "malwarebazaar",
        "strike activity",
        "filejust",
        "file contentsi",
        "vscode",
        "sublime editor",
        "windows exe",
        "utf8",
        "turla",
        "root",
        "msoffice",
        "nativezone",
        "kazuar",
        "bluenoroff",
        "customerloader",
        "muddywater",
        "chat",
        "overwatch",
        "aquatic panda",
        "log4j",
        "linux",
        "apache tomcat",
        "crowdstrike",
        "github project",
        "click",
        "fishmaster",
        "yanluowang",
        "thieflock",
        "scanner",
        "canthroid",
        "grabff",
        "symantec",
        "connectwise",
        "screenconnect",
        "fivehands",
        "browserpassview",
        "rundll32",
        "sharefinder",
        "wmic",
        "ping",
        "rollcoast",
        "south africa",
        "unc2190",
        "july",
        "tycoon",
        "unc2190 beacon",
        "latin",
        "arcane",
        "sabbath",
        "slovak",
        "slovakia",
        "albanian",
        "albania",
        "swedish",
        "turkish",
        "indonesia",
        "estonia",
        "armenia",
        "c2 data",
        "cyberchef",
        "javascript code",
        "rsa key",
        "remove",
        "get request",
        "xor key",
        "exploits & vulnerabilities",
        "managed xdr",
        "one marketplace",
        "lockfile",
        "attack overview",
        "stage",
        "conti gang",
        "datop",
        "handover",
        "kazakhstan",
        "os version",
        "winrm",
        "protocol",
        "enterpssession",
        "psrp",
        "windows remote",
        "source process",
        "stack",
        "rita",
        "threat feed",
        "myrtus",
        "harvester",
        "c activity",
        "artefactsfolder",
        "identity",
        "infectionid",
        "october",
        "main",
        "ad environment",
        "bazar c2",
        "networks",
        "d3desdecrypt",
        "nim malware",
        "jason",
        "part",
        "reaves6 min",
        "nimrodnimza",
        "rustybuer",
        "nimgrabber",
        "caesar",
        "file encryption",
        "nimrev",
        "discovery",
        "data",
        "mitre att",
        "powersploit",
        "leverage",
        "beaconloader",
        "doorme backdoor",
        "issuer cus",
        "apt group",
        "chamelgang",
        "doorme",
        "mcafee",
        "timestomp",
        "copy",
        "oilrig",
        "error",
        "body",
        "eternalblue",
        "zip file",
        "enable",
        "content",
        "vbs script",
        "word document",
        "maldoc",
        "form",
        "win api",
        "bazarloader dll",
        "intro conti",
        "coveware",
        "raas",
        "ransom",
        "ryuk ransomware",
        "cve202140444",
        "multiple",
        "north america",
        "europe",
        "asia",
        "html object",
        "mshtml engine",
        "sidewalk",
        "crosswalk",
        "c server",
        "sparklinggoblin",
        "google docs",
        "winnti group",
        "format",
        "darkshell",
        "motnug",
        "threat-intelligence",
        "apt",
        "nsa",
        "def con",
        "iso filesystem",
        "iocs",
        "recon village",
        "leviathan",
        "encrypt",
        "prophet spider",
        "oracle weblogic",
        "exception",
        "weblogic access",
        "class",
        "linux system",
        "egregor",
        "mountlocker",
        "radar",
        "front",
        "gotroj",
        "encoder",
        "stealer",
        "soar",
        "speed",
        "prophet",
        "classloader",
        "reconnaissance",
        "tech",
        "recon",
        "et cnc",
        "feodo tracker",
        "cnc server",
        "trigger",
        "alive",
        "spawn",
        "method",
        "http method",
        "jitter",
        "port",
        "beacon type",
        "later",
        "close",
        "browser",
        "chinese-speaking cybercrime",
        "google chrome",
        "microsoft word",
        "spear phishing",
        "luminousmoth",
        "honeymyte",
        "assistant",
        "username",
        "motc",
        "ministry",
        "local",
        "xll file",
        "docusign",
        "hancitor dll",
        "hancitor exe",
        "ficker stealer",
        "api hashing",
        "api hash",
        "monpass",
        "avast",
        "monpass client",
        "monpass web",
        "mongolia",
        "jan rubn",
        "discovered",
        "initial contact",
        "final",
        "watermark",
        "chanitor",
        "pony",
        "vawtrak",
        "uwaga",
        "falcon complete",
        "falcon",
        "wizard spider",
        "lime",
        "easy",
        "flex",
        "yahxz",
        "efno",
        "unc2465",
        "ngrok",
        "ultravnc",
        "methodology",
        "ngrok tunnel",
        "smokedham",
        "guard",
        "dllstageless",
        "submission",
        "size",
        "noblebaron",
        "itw name",
        "scout",
        "elite",
        "containedwithin",
        "withheld",
        "relatedto",
        "strike beacon",
        "matches no",
        "privacy",
        "description",
        "entropy",
        "restrict",
        "host ip",
        "owner",
        "igos",
        "germany",
        "file",
        "type",
        "artemis",
        "rozena",
        "razy",
        "khalesi",
        "\u30c7\u30b8\u30bf\u30eb\u7f72\u540d",
        "cobalt strike loader",
        "\u6a19\u7684\u578b\u653b\u6483",
        "strike loader",
        "iocindicator",
        "microsoft docs",
        "2 cobalt",
        "3 sigcheck",
        "1 microsoftdll",
        "powershell rat",
        "macro",
        "progression",
        "hackerman",
        "robinhood",
        "scan behavioral",
        "unusual port",
        "potential scan",
        "campo loader",
        "dfdownloader",
        "japan",
        "post method",
        "openfield",
        "blacktds",
        "public",
        "behaviour",
        "variant",
        "malicious file",
        "transfer",
        "control",
        "feature",
        "fireeye",
        "plink",
        "campo",
        "bazarcall",
        "xyzcampobb hxxp",
        "ioc510",
        "urlcampo",
        "20214",
        "headlines",
        "tlds",
        "duck",
        "beapy",
        "prometei",
        "umbrella",
        "wdigest",
        "iceid",
        "networkminer",
        "caploader",
        "network forensics",
        "ja3",
        "x.509",
        "sslbl",
        "1768.py",
        "didier stevens",
        "8da75e1f974d1011c91ed3110a4ded38",
        "e9b5e549363fa9fcb362b606b75d131dec6c020e",
        "0314b8cd45b636f38d07032dc8ed463295710460ea7a4e214c1de7b0e817aab6",
        "banusdona.top",
        "172.67.188.12",
        "f98711dfeeab9c8b4975b2f9a88d8fea",
        "c2bdc885083696b877ab6f0e05a9d968fd7cc2bb",
        "213e9c8bf7f6d0113193f785cb407f0e8900ba75b9131475796445c11f3ff37c",
        "momenturede.fun",
        "104.236.115.181",
        "96a535122aba4240e2c6370d0c9a09d3",
        "485ba347cf898e34a7455e0fd36b0bcf8b03ffd8",
        "11965662e146d97d3fa3288e119aefb2",
        "b63d7ad26df026f6cca07eae14bb10a0ddb77f41",
        "d45b3f9d93171c29a51f9c8011cd61aa44fcb474d59a0b68181bb690dbbf2ef5",
        "vaccnavalcod.website",
        "mazzappa.fun",
        "ameripermanentno.website",
        "odichaly.space",
        "83.97.20.176",
        "452e969c51882628dac65e38aff0f8e5ebee6e6b",
        "lesti.net",
        "185.141.26.140",
        "449c1967d1708d7056053bedb9e45781",
        "1ab39f1c8fb3f2af47b877cafda4ee09374d7bd3",
        "c7da494880130cdb52bd75dae1556a78f2298a8cc9a2e75ece8a57ca290880d3",
        "45.147.229.157",
        "1580103814",
        "luckymouse",
        "emissary panda",
        "apt 27",
        "apt27",
        "a0e9f5d64349fb13191bc781f81f42e1",
        "3b5074b1b5d032e5620f69f9f700ff0e",
        "erik hjelmvik",
        "monday",
        "openssl",
        "michael",
        "bazaloader",
        "anchor",
        "alex",
        "header",
        "getoperandvalue",
        "win32",
        "build",
        "trickbot crews",
        "cs loader",
        "trickbots cs",
        "trickbots crew",
        "google drive",
        "hancitor c2",
        "icmp",
        "dcdomainname",
        "dclocal",
        "base",
        "cnbuiltin",
        "cnusers",
        "security groups",
        "bitcoin",
        "sage",
        "svchost",
        "bits",
        "beacon dll",
        "started service",
        "beacon payload",
        "process hacker",
        "sleepex",
        "identifies",
        "crph",
        "smadavprotect32",
        "cec list",
        "meeting",
        "dll library",
        "ta800",
        "nim programming",
        "nimzaloader",
        "doesn",
        "json object",
        "c url",
        "trustinfo",
        "displayname",
        "dpiaware",
        "anchordns",
        "enjoy",
        "nimrod",
        "gecko",
        "khtml",
        "offensivenim",
        "sharpkatz",
        "crypter",
        "done",
        "sprite spider",
        "carbon spider",
        "esxi",
        "spider",
        "defray777",
        "pyxie",
        "hypervisor",
        "defray",
        "ransomexx",
        "sekur",
        "anunak",
        "harpy",
        "griffon",
        "unc2198",
        "maze",
        "maze ransomware",
        "file transfer",
        "mouseisland",
        "koadic",
        "photoloader",
        "ocean lotus",
        "mac os",
        "kerrdown",
        "human",
        "kerrdown sample",
        "macho",
        "tcp port",
        "systembc",
        "http traffic",
        "hatching triage",
        "directory",
        "endpoint1",
        "ryuk threat",
        "raindrop",
        "teardrop",
        "decrypt",
        "raindrop loader",
        "name file",
        "pl shellcode",
        "funnyswitch",
        "chm file",
        "config",
        "frombase64",
        "azaz09",
        "nltest",
        "regwrite",
        "exitendifif",
        "sleep",
        "regsz",
        "stwashington",
        "lredmond",
        "dircreate",
        "protection",
        "defenderspynet",
        "john",
        "doublepulsar",
        "amadey",
        "zeppelin",
        "apt & targeted attacks",
        "earth wendigo",
        "service worker",
        "xss attack",
        "domain",
        "learn more",
        "ck technique",
        "techniques",
        "emerging threat",
        "solarwinds",
        "breach",
        "dora",
        "pioneer",
        "solarstorm",
        "cortex xdr",
        "iot security",
        "atom",
        "supernova",
        "yara",
        "snort",
        "gap analysis",
        "keefarce",
        "safetykatz",
        "gadgettojscript",
        "sharpzerologon",
        "tuesday",
        "qakbot binary",
        "qakbot malspam",
        "qakbot malware",
        "windows binary",
        "malspam",
        "egregor payload",
        "threat alert",
        "sekhmet",
        "platform",
        "monitoring",
        "chacha",
        "notpetya",
        "bad rabbit",
        "internet",
        "tls server",
        "tls client",
        "server hello",
        "ja3s",
        "hello packet",
        "apache",
        "random",
        "vatet",
        "localappdata",
        "epochtime",
        "rapid7",
        "cash",
        "logmein",
        "swift",
        "radmin",
        "bazar loader",
        "highest",
        "certificate",
        "issuer org",
        "over",
        "ryuk domain",
        "infrastructure",
        "namecheap",
        "ryuk host",
        "monovm",
        "olol",
        "gnu c",
        "o2 o2",
        "marchx8664 g",
        "g o2",
        "sttx",
        "ltexas",
        "ooffice",
        "name",
        "basecamp",
        "userinit",
        "hack",
        "snow",
        "apt19",
        "yara rule",
        "chimera",
        "pe header",
        "vhash",
        "lpwstr lpbuffer",
        "startw",
        "request",
        "netwalker",
        "neshta",
        "mailto",
        "thor",
        "xmrig",
        "teamt5",
        "threatsonar anti-ransomware",
        "threatsonar",
        "threatvision",
        "cyber espionage",
        "ransom virus",
        "tt",
        "cyber threat hunters",
        "cyber espionage solutions",
        "threat analysis service",
        "incident response",
        "investigation services",
        "threat intelligence",
        "md5 hash",
        "softether",
        "domain teamt5",
        "teamt5 teamt5",
        "plead",
        "pastebin",
        "travelex",
        "pos software",
        "gandcrab",
        "rat",
        "indigodrop",
        "msf shellcode",
        "msf downloader",
        "urlshxxp",
        "stages",
        "threatlabz",
        "india-china",
        "zscaler cloud",
        "dkmc framework",
        "gif header",
        "dkmc",
        "sandbox report",
        "publickey",
        "sandbox",
        "ntds",
        "beacon version",
        "console",
        "file creation",
        "file deletion",
        "rename",
        "or filefullname",
        "coronavirus",
        "tvrat",
        "gozi malware",
        "js file",
        "wscript",
        "msbuild",
        "msbuild project",
        "silent trinity",
        "threat grid",
        "lolbins",
        "cisco threat",
        "msbuild process",
        "naga",
        "trinity",
        "dos header",
        "sfx code",
        "sfx file",
        "export function",
        "mz header",
        "open process",
        "set current",
        "create",
        "apt2019",
        "2019 payload",
        "lnklnklnklnk",
        "1 docvbavbavba",
        "dllentry rat",
        "operation pawn",
        "storm",
        "midst intrusion",
        "pawn storm",
        "xtunnel",
        "hidedrv",
        "aurora",
        "blackshades",
        "conficker",
        "chapro",
        "dark comet",
        "dexter",
        "duqu",
        "gauss",
        "bridge",
        "hikit",
        "makadocs",
        "medre",
        "morto",
        "narilam",
        "onionduke",
        "rustock",
        "dorkbot",
        "spyeye",
        "stabuniq",
        "stuxnet",
        "tinba",
        "vobfus",
        "zeroaccess",
        "zeus",
        "zusy",
        "committee",
        "dnc network",
        "trump",
        "dnc hack",
        "donald trump",
        "neither",
        "general",
        "hill",
        "magazine",
        "mexico",
        "winids",
        "foozer",
        "downrage",
        "hydra",
        "remcom",
        "inc\\.",
        "bear",
        "wirelurker",
        "generic.933739",
        "python code",
        "zxkbdklakv",
        "seaduke",
        "cookie value",
        "bookmark server",
        "p4bnzr0",
        "duke"
      ],
      "references": [
        "https://malcat.fr/blog/lnk-forensic-and-config-extraction-of-a-cobalt-strike-beacon/",
        "https://mp.weixin.qq.com/s/cGS8FocPnUdBconLbbaG-g",
        "https://thedfirreport.com/2022/08/08/bumblebee-roasts-its-way-to-domain-admin/",
        "https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra/",
        "https://blog.talosintelligence.com/manjusaka-offensive-framework/",
        "https://cocomelonc.github.io/malware/2022/07/30/malware-av-evasion-8.html",
        "https://www.sentinelone.com/blog/living-off-windows-defender-lockbit-ransomware-sideloads-cobalt-strike-through-microsoft-security-tool/",
        "https://www.trendmicro.com/en_us/research/22/g/gootkit-loaders-updated-tactics-and-fileless-delivery-of-cobalt-strike.html",
        "https://blog.nviso.eu/2022/07/20/analysis-of-a-trojanized-jquery-script-gootloader-unleashed/",
        "https://cloud.google.com/blog/topics/threat-intelligence/spear-phish-ukrainian-entities/",
        "https://www.threatdown.com/blog/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign/",
        "https://cert.gov.ua/article/703548",
        "https://cert-agid.gov.it/news/il-malware-envyscout-apt29-e-stato-veicolato-anche-in-italia/",
        "https://isc.sans.edu/diary/Emotet%20infection%20with%20Cobalt%20Strike/28824",
        "https://cert.gov.ua/article/619229",
        "https://ics-cert.kaspersky.com/publications/reports/2022/06/27/attacks-on-industrial-control-systems-using-shadowpad/",
        "https://blog.bushidotoken.net/2022/06/overview-of-russian-gru-and-svr.html",
        "https://blog.talosintelligence.com/avoslocker-new-arsenal/",
        "https://isc.sans.edu/diary/rss/28752",
        "https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html",
        "https://kienmanowar.wordpress.com/2022/06/04/quicknote-cobaltstrike-smb-beacon-analysis-2/",
        "https://cloud.google.com/blog/topics/threat-intelligence/unc2165-shifts-to-evade-sanctions",
        "https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis",
        "https://medium.com/walmartglobaltech/socgholish-campaigns-and-initial-access-kit-4c4283fea8ee",
        "https://thehackernews.com/2022/05/malware-analysis-trickbot.html",
        "https://www.sonatype.com/blog/new-pymafka-malicious-package-drops-cobalt-strike-on-macos-windows-linux",
        "https://asec.ahnlab.com/en/34549/",
        "https://isc.sans.edu/diary/Bumblebee+Malware+from+TransferXL+URLs/28664",
        "https://raw.githubusercontent.com/Dump-GUY/Malware-analysis-and-Reverse-engineering/refs/heads/main/APT29_C2-Client_Dropbox_Loader/APT29-DropboxLoader_analysis.md",
        "https://redcanary.com/wp-content/uploads/2022/05/Gootloader.pdf",
        "https://i.blackhat.com/Asia-22/Thursday-Materials/AS-22-LeonSilvia-NextGenPlugXShadowPad.pdf",
        "https://isc.sans.edu/diary/28636",
        "https://cocomelonc.github.io/tutorial/2022/05/09/malware-pers-4.html",
        "https://thedfirreport.com/2022/05/09/seo-poisoning-a-gootloader-story/",
        "https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encoding-decoding/",
        "https://thehackernews.com/2022/05/this-new-fileless-malware-hides.html",
        "https://blog.talosintelligence.com/mustang-panda-targets-europe/",
        "https://securelist.com/a-new-secret-stash-for-fileless-malware/106393/",
        "https://security.macnica.co.jp/blog/2022/05/iso.html",
        "https://cloud.google.com/blog/topics/threat-intelligence/tracking-apt29-phishing-campaigns/",
        "https://documents.trendmicro.com/assets/txt/earth-berberoka-windows-iocs-2.txt",
        "https://cert.ssi.gouv.fr/uploads/20220427_NP_TLPWHITE_ANSSI_FIN7.pdf",
        "https://cloud.google.com/blog/topics/threat-intelligence/unc2452-merged-into-apt29/",
        "https://www.sentinelone.com/labs/lockbit-ransomware-side-loads-cobalt-strike-beacon-with-legitimate-vmware-utility/",
        "https://thedfirreport.com/2022/04/25/quantum-ransomware/",
        "https://www.morphisec.com/blog/vmware-identity-manager-attack-backdoor/",
        "https://cocomelonc.github.io/tutorial/2022/04/20/malware-pers-1.html",
        "https://www.varonis.com/blog/hive-ransomware-analysis",
        "https://www.sentinelone.com/blog/from-the-front-lines-peering-into-a-pysa-ransomware-attack/",
        "https://vanmieghem.io/blueprint-for-evading-edr-in-2022/",
        "https://www.cynet.com/blog/orion-threat-alert-flight-of-the-bumblebee/",
        "https://www.welivesecurity.com/2022/04/13/eset-takes-part-global-operation-disrupt-zloader-botnets/",
        "https://www.splunk.com/en_us/blog/security/you-bet-your-lsass-hunting-lsass-access.html",
        "https://github.com/infinitumitlabs/Karakurt-Hacking-Team-CTI",
        "https://cloud.google.com/blog/topics/threat-intelligence/evolution-of-fin7/",
        "https://www.sentinelone.com/blog/hive-ransomware-deploys-novel-ipfuscation-technique/",
        "https://medium.com/walmartglobaltech/cobaltstrike-uuid-stager-ca7e82f7bb64",
        "https://resource.redcanary.com/rs/003-YRU-314/images/2022_ThreatDetectionReport_RedCanary.pdf",
        "https://www.esentire.com/blog/conti-affiliate-exposed-new-domain-names-ip-addresses-and-email-addresses-uncovered-by-esentire",
        "https://unit42.paloaltonetworks.com/cobalt-strike-malleable-c2-profile/",
        "https://isc.sans.edu/diary/Qakbot+infection+with+Cobalt+Strike+and+VNC+activity/28448",
        "https://www.sentinelone.com/blog/threat-actor-uac-0056-targeting-ukraine-with-fake-translation-software/",
        "https://www.arashparsa.com/catching-a-malware-with-no-name/",
        "https://cert.gov.ua/article/37704",
        "https://cloud.google.com/blog/topics/threat-intelligence/apt41-us-state-governments/",
        "https://thedfirreport.com/2022/03/07/2021-year-in-review/",
        "https://www.cynet.com/security-foundations/attack-techniques/new-wave-of-emotet-when-project-x-turns-into-y/",
        "https://www.fortinet.com/blog/threat-research/nobelium-returns-to-the-political-world-stage",
        "https://cyber.wtf/2022/03/23/what-the-packer/",
        "https://www.esentire.com/blog/icedid-to-cobalt-strike-in-under-20-minutes",
        "https://asec.ahnlab.com/en/31811/",
        "https://thedfirreport.com/2022/02/21/qbot-and-zerologon-lead-to-full-domain-compromise/",
        "https://medium.com/walmartglobaltech/signed-dll-campaigns-as-a-service-7760ac676489",
        "https://www.cybereason.com/blog/research/threat-analysis-report-datoploader-exploits-proxyshell-to-deliver-qbot-and-cobalt-strike",
        "https://forensicitguy.github.io/inspecting-powershell-cobalt-strike-beacon/",
        "https://blog.sekoia.io/nobeliums-envyscout-infection-chain-goes-in-the-registry-targeting-embassies/",
        "https://www.crowdstrike.com/en-us/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exploit-tools/",
        "https://www.security.com/threat-intelligence/yanluowang-ransomware-attacks-continue",
        "https://thedfirreport.com/2021/11/29/continuing-the-bazar-ransomware-story/",
        "https://cloud.google.com/blog/topics/threat-intelligence/sabbath-ransomware-affiliate/",
        "https://blog.nviso.eu/2021/11/17/cobalt-strike-decrypting-obfuscated-traffic-part-4/",
        "https://www.trendmicro.com/en_gb/research/21/k/analyzing-proxyshell-related-incidents-via-trend-micro-managed-x.html",
        "https://www.truesec.com/hub/blog/proxyshell-qbot-and-conti-ransomware-combined-in-a-series-of-cyber-attacks",
        "https://www.threatdown.com/blog/a-multi-stage-powershell-based-attack-targets-kazakhstan/",
        "https://www.unh4ck.com/detection-engineering-and-threat-hunting/lateral-movement/detecting-conti-cobaltstrike-lateral-movement-techniques-part-1",
        "https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-009.pdf",
        "https://thedfirreport.com/2021/10/18/icedid-to-xinglocker-ransomware-in-24-hours/",
        "https://www.security.com/threat-intelligence/harvester-new-apt-attacks-asia",
        "https://unit42.paloaltonetworks.com/bazarloader-network-reconnaissance/",
        "https://medium.com/walmartglobaltech/investigation-into-the-state-of-nim-malware-part-2-a28bffffa671",
        "https://thedfirreport.com/2021/10/04/bazarloader-and-the-conti-leaks/",
        "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/new-apt-group-chamelgang/#id3",
        "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/new-apt-group-chamelgang/",
        "https://www.cynet.com/security-foundations/attack-techniques/understanding-squirrelwaffle/",
        "https://thedfirreport.com/2021/09/13/bazarloader-to-conti-ransomware-in-32-hours/",
        "https://blog.gigamon.com/2021/09/10/rendering-threats-a-network-perspective/",
        "https://www.trendmicro.com/content/dam/trendmicro/global/en/research/21/i/ssl-tls-technical-brief/ssl-tls-technical-brief.pdf",
        "https://documents.trendmicro.com/assets/white_papers/wp-earth-baku-an-apt-group-targeting-indo-pacific-countries.pdf",
        "https://www.welivesecurity.com/2021/08/24/sidewalk-may-be-as-dangerous-as-crosswalk/",
        "https://istrosec.com/blog/apt-sk-cobalt/",
        "https://www.crowdstrike.com/en-us/blog/prophet-spider-exploits-oracle-weblogic-to-facilitate-ransomware-activity/",
        "https://thedfirreport.com/2021/08/01/bazarcall-to-conti-ransomware-via-trickbot-and-cobalt-strike/",
        "https://thedfirreport.com/2021/07/19/icedid-and-cobalt-strike-vs-antivirus/",
        "https://securelist.com/apt-luminousmoth/103332/",
        "https://isc.sans.edu/diary/rss/27618",
        "https://www.gendigital.com/blog/insights/research/decoding-cobalt-strike-understanding-payloads",
        "https://www.gendigital.com/blog/insights/research/backdoored-client-from-mongolian-ca-monpass",
        "https://thedfirreport.com/2021/06/28/hancitor-continues-to-push-cobalt-strike/",
        "https://www.crowdstrike.com/en-us/blog/how-falcon-complete-disrupts-ecrime-operators-wizard-spider/",
        "https://thedfirreport.com/2021/06/20/from-word-to-lateral-movement-in-1-hour/",
        "https://cloud.google.com/blog/topics/threat-intelligence/darkside-affiliate-supply-chain-software-compromise",
        "https://www.sentinelone.com/labs/noblebaron-new-poisoned-installers-could-be-used-in-supply-chain-attacks/",
        "https://www.cisa.gov/news-events/analysis-reports/ar21-148a",
        "https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-148a",
        "https://www.lac.co.jp/lacwatch/report/20210521_002618.html",
        "https://www.ncsc.gov.ie/pdfs/HSE_Conti_140521_UPDATE.pdf",
        "https://www.guidepointsecurity.com/blog/from-zloader-to-darkside-a-ransomware-story/",
        "https://thedfirreport.com/2021/05/12/conti-ransomware/",
        "https://mal-eats.net/en/2021/05/11/campo_new_attack_campaign_targeting_japan/",
        "https://cloud.google.com/blog/topics/threat-intelligence/shining-a-light-on-darkside-ransomware-operations/",
        "https://mal-eats.net/2021/05/10/campo_new_attack_campaign_targeting_japan/",
        "https://blog.talosintelligence.com/lemon-duck-spreads-wings/",
        "https://thedfirreport.com/2021/05/02/trickbot-brief-creds-and-beacons/",
        "https://www.netresec.com/?page=Blog&month=2021-04&post=Analysing-a-malware-PCAP-with-IcedID-and-Cobalt-Strike-traff",
        "https://isc.sans.edu/diary/27308",
        "https://medium.com/walmartglobaltech/trickbot-crews-new-cobaltstrike-loader-32c72b78e81c",
        "https://unit42.paloaltonetworks.com/hancitor-infections-cobalt-strike/",
        "https://thedfirreport.com/2021/03/29/sodinokibi-aka-revil-ransomware/",
        "https://www.elastic.co/blog/detecting-cobalt-strike-with-memory-signatures",
        "https://www.qurium.org/alerts/targeted-malware-against-crph/",
        "https://www.proofpoint.com/us/blog/threat-insight/nimzaloader-ta800s-new-initial-access-malware",
        "https://thedfirreport.com/2021/03/08/bazar-drops-the-anchor/",
        "https://medium.com/walmartglobaltech/investigation-into-the-state-of-nim-malware-14cc543af811",
        "https://www.crowdstrike.com/en-us/blog/carbon-spider-sprite-spider-target-esxi-servers-with-ransomware/?utm_campaign=blog&utm_medium=soc&utm_source=twtr&utm_content=sprout",
        "https://cloud.google.com/blog/topics/threat-intelligence/melting-unc2198-icedid-to-ransomware-operations/",
        "https://raw.githubusercontent.com/AmnestyTech/investigations/refs/heads/master/2021-02-24_vietnam/README.md",
        "https://isc.sans.edu/diary/Excel+spreadsheets+push+SystemBC+malware/27060",
        "https://thedfirreport.com/2021/01/31/bazar-no-ryuk/",
        "https://www.security.com/threat-intelligence/solarwinds-raindrop-malware",
        "https://global.ptsecurity.com/en/research/pt-esc-threat-intelligence/higaisa-or-winnti-apt-41-backdoors-old-and-new/",
        "https://thedfirreport.com/2021/01/11/trickbot-still-alive-and-well/",
        "https://medium.com/walmartglobaltech/man1-moskal-hancitor-and-a-side-of-ransomware-d77b4d991618",
        "https://www.trendmicro.com/en_us/research/21/a/earth-wendigo-injects-javascript-backdoor-to-service-worker-for-.html",
        "https://www.picussecurity.com/resource/blog/ttps-used-in-the-solarwinds-breach",
        "https://unit42.paloaltonetworks.com/fireeye-solarstorm-sunburst/",
        "https://unit42.paloaltonetworks.com/fireeye-red-team-tool-breach/",
        "https://isc.sans.edu/diary/rss/26862",
        "https://i.blackhat.com/eu-20/Wednesday/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations-wp.pdf",
        "https://i.blackhat.com/eu-20/Wednesday/eu-20-Clarke-Its-Not-FINished-The-Evolving-Maturity-In-Ransomware-Operations.pdf",
        "https://www.cybereason.com/blog/cybereason-vs-egregor-ransomware",
        "https://engineering.salesforce.com/easily-identify-malicious-servers-on-the-internet-with-jarm-e095edac525a/",
        "https://unit42.paloaltonetworks.com/vatet-pyxie-defray777/5/",
        "https://thedfirreport.com/2020/11/05/ryuk-speed-run-2-hours-to-ransom/",
        "https://raw.githubusercontent.com/ThreatConnect-Inc/research-team/refs/heads/master/IOCs/WizardSpider-UNC1878-Ryuk.csv",
        "https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/",
        "https://cloud.google.com/blog/topics/threat-intelligence/kegtap-and-singlemalt-with-a-ransomware-chaser/",
        "https://raw.githubusercontent.com/StrangerealIntel/CyberThreatIntel/refs/heads/master/China/APT/Chimera/Analysis.md",
        "https://thedfirreport.com/2020/10/08/ryuks-return/",
        "https://thedfirreport.com/2020/08/31/netwalker-ransomware-in-1-hour/",
        "https://teamt5.org/tw/posts/mjib-holds-briefing-on-chinese-hackers-attacks-on-taiwanese-government-agencies/",
        "https://i.blackhat.com/USA-20/Thursday/us-20-Chen-Operation-Chimera-APT-Operation-Targets-Semiconductor-Vendors.pdf",
        "https://www.security.com/threat-intelligence/sodinokibi-ransomware-cobalt-strike-pos",
        "https://blog.talosintelligence.com/indigodrop-maldocs-cobalt-strike/",
        "https://www.zscaler.com/blogs/security-research/targeted-attack-leverages-india-china-border-dispute-lure-victims",
        "https://www.sentinelone.com/labs/the-anatomy-of-an-apt-attack-and-cobaltstrike-beacons-encoded-configuration/",
        "https://thedfirreport.com/2020/04/24/ursnif-via-lolbins/",
        "https://blog.talosintelligence.com/building-bypass-with-msbuild/",
        "https://tccontre.blogspot.com/2019/11/cobaltstrike-beacondll-your-not.html",
        "https://web-assets.esetstatic.com/wls/2019/10/ESET_Operation_Ghost_Dukes.pdf",
        "https://mp.weixin.qq.com/s/xPsEXp2J5IE7wNSMEVC24A",
        "https://contagiodump.blogspot.com/2017/02/russian-apt-apt28-collection-of-samples.html",
        "https://www.cisa.gov/sites/default/files/publications/AR-17-20045_Enhanced_Analysis_of_GRIZZLY_STEPPE_Activity.pdf",
        "https://www.crowdstrike.com/en-us/blog/bears-midst-intrusion-democratic-national-committee/",
        "https://blog-assets.f-secure.com/wp-content/uploads/2020/03/18122307/F-Secure_Dukes_Whitepaper.pdf",
        "https://contagiodump.blogspot.com/2014/11/onionduke-samples.html",
        "https://unit42.paloaltonetworks.com/unit-42-technical-analysis-seaduke/"
      ],
      "public": 1,
      "adversary": "Threat",
      "targeted_countries": [
        "Czechia",
        "Ukraine",
        "Russian Federation",
        "Poland",
        "Belarus",
        "Lithuania",
        "Latvia",
        "Germany",
        "Pakistan",
        "Afghanistan",
        "Malaysia",
        "Greece",
        "Italy",
        "T\u00fcrkiye",
        "Portugal",
        "Brazil",
        "China",
        "Japan",
        "Korea, Republic of",
        "United States of America",
        "Mexico",
        "New Zealand",
        "Canada",
        "Georgia",
        "Iran, Islamic Republic of"
      ],
      "malware_families": [
        {
          "id": "HandleRef",
          "display_name": "HandleRef",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Threat",
          "display_name": "Threat",
          "target": null
        },
        {
          "id": "Primary Threat",
          "display_name": "Primary Threat",
          "target": null
        },
        {
          "id": "BazarLoader",
          "display_name": "BazarLoader",
          "target": null
        },
        {
          "id": "Bumblebee",
          "display_name": "Bumblebee",
          "target": null
        },
        {
          "id": "ELF",
          "display_name": "ELF",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Kronos",
          "display_name": "Kronos",
          "target": null
        },
        {
          "id": "BEACON",
          "display_name": "BEACON",
          "target": null
        },
        {
          "id": "MICROBACKDOOR",
          "display_name": "MICROBACKDOOR",
          "target": null
        },
        {
          "id": "GRIMPLANT",
          "display_name": "GRIMPLANT",
          "target": null
        },
        {
          "id": "GRAPHSTEEL",
          "display_name": "GRAPHSTEEL",
          "target": null
        },
        {
          "id": "Shadowpad",
          "display_name": "Shadowpad",
          "target": null
        },
        {
          "id": "PlugX",
          "display_name": "PlugX",
          "target": null
        },
        {
          "id": "ShadowPad",
          "display_name": "ShadowPad",
          "target": null
        },
        {
          "id": "Threat Analysis",
          "display_name": "Threat Analysis",
          "target": null
        },
        {
          "id": "CredoMap",
          "display_name": "CredoMap",
          "target": null
        },
        {
          "id": "StellarParticle",
          "display_name": "StellarParticle",
          "target": null
        },
        {
          "id": "CozyBear",
          "display_name": "CozyBear",
          "target": null
        },
        {
          "id": "Shadow Chaser",
          "display_name": "Shadow Chaser",
          "target": null
        },
        {
          "id": "Raspberry Robin",
          "display_name": "Raspberry Robin",
          "target": null
        },
        {
          "id": "RansomHub",
          "display_name": "RansomHub",
          "target": null
        },
        {
          "id": "Cyclops",
          "display_name": "Cyclops",
          "target": null
        },
        {
          "id": "FancyBear",
          "display_name": "FancyBear",
          "target": null
        },
        {
          "id": "APT29",
          "display_name": "APT29",
          "target": null
        },
        {
          "id": "AvosLocker",
          "display_name": "AvosLocker",
          "target": null
        },
        {
          "id": "Matanbuchus",
          "display_name": "Matanbuchus",
          "target": null
        },
        {
          "id": "HADES",
          "display_name": "HADES",
          "target": null
        },
        {
          "id": "SocGholish NetSupport",
          "display_name": "SocGholish NetSupport",
          "target": null
        },
        {
          "id": "SocGholish",
          "display_name": "SocGholish",
          "target": null
        },
        {
          "id": "NetSupport",
          "display_name": "NetSupport",
          "target": null
        },
        {
          "id": "Gold Blackburn",
          "display_name": "Gold Blackburn",
          "target": null
        },
        {
          "id": "Conti",
          "display_name": "Conti",
          "target": null
        },
        {
          "id": "Ryuk",
          "display_name": "Ryuk",
          "target": null
        },
        {
          "id": "Trickbot",
          "display_name": "Trickbot",
          "target": null
        },
        {
          "id": "Darkside",
          "display_name": "Darkside",
          "target": null
        },
        {
          "id": "Win32.BitCoinMiner",
          "display_name": "Win32.BitCoinMiner",
          "target": null
        },
        {
          "id": "Win32.Agent",
          "display_name": "Win32.Agent",
          "target": null
        },
        {
          "id": "NbtScan",
          "display_name": "NbtScan",
          "target": null
        },
        {
          "id": "Frp",
          "display_name": "Frp",
          "target": null
        },
        {
          "id": "Pcap",
          "display_name": "Pcap",
          "target": null
        },
        {
          "id": "BeaconLoader",
          "display_name": "BeaconLoader",
          "target": null
        },
        {
          "id": "DoorMe",
          "display_name": "DoorMe",
          "target": null
        },
        {
          "id": "Win API",
          "display_name": "Win API",
          "target": null
        },
        {
          "id": "Generic.933739",
          "display_name": "Generic.933739",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Gas",
        "Government",
        "Defense",
        "Media",
        "Telecommunications",
        "Logistics",
        "Industrial",
        "Manufacturing",
        "Transport",
        "Transportation",
        "Diplomatic",
        "Foreign Affairs",
        "Academics",
        "Banking",
        "Aviation",
        "Political",
        "Energy",
        "Military",
        "Financial",
        "Legal",
        "Pharmaceutical",
        "Technology",
        "Aerospace"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "kikinumpav",
        "id": "385742",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3082,
        "FileHash-SHA1": 2478,
        "FileHash-SHA256": 4182,
        "URL": 3155,
        "CVE": 190,
        "SSLCertFingerprint": 41,
        "domain": 2991,
        "email": 58,
        "hostname": 2130,
        "YARA": 95
      },
      "indicator_count": 18402,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 16,
      "modified_text": "3 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "660566db15f516334e28c875",
      "name": "Saiba mais sobre o Lazarus Group, grupo de amea\u00e7a que visa o Brasil",
      "description": "",
      "modified": "2024-04-27T12:04:00.761000",
      "created": "2024-03-28T12:47:23.957000",
      "tags": [
        "ciberseguran\u00e7a",
        "lazarus group",
        "empresa segura",
        "ambiente da empresa",
        "principais amea\u00e7as",
        "seguran\u00e7a digital",
        "o grupo",
        "indicadores",
        "conhecido",
        "lazarus",
        "para",
        "iocs",
        "isso",
        "isso pode",
        "explorao",
        "modo",
        "manuscrypt",
        "fallchill",
        "wannacry",
        "rats",
        "malware",
        "destover",
        "powershell",
        "heimdall",
        "policy",
        "internet site",
        "the internet",
        "site",
        "organization",
        "internet",
        "personal data",
        "cookie policy",
        "socradar",
        "cookie usage",
        "date",
        "https"
      ],
      "references": [
        "https://www.ish.com.br/blog/principais-ameacas-que-visam-o-brasil-lazarus-group/",
        "https://socradar.io/apt-group-lazarus-exploits-high-severity-flaw-in-dell-driver/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [
        "Netherlands",
        "Belgium"
      ],
      "malware_families": [
        {
          "id": "Manuscrypt",
          "display_name": "Manuscrypt",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "Lazarus",
          "display_name": "Lazarus",
          "target": null
        },
        {
          "id": "Heimdall",
          "display_name": "Heimdall",
          "target": null
        },
        {
          "id": "HTTPS",
          "display_name": "HTTPS",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        },
        {
          "id": "T1098",
          "name": "Account Manipulation",
          "display_name": "T1098 - Account Manipulation"
        },
        {
          "id": "T1110",
          "name": "Brute Force",
          "display_name": "T1110 - Brute Force"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1557",
          "name": "Man-in-the-Middle",
          "display_name": "T1557 - Man-in-the-Middle"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1587",
          "name": "Develop Capabilities",
          "display_name": "T1587 - Develop Capabilities"
        },
        {
          "id": "T1495",
          "name": "Firmware Corruption",
          "display_name": "T1495 - Firmware Corruption"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        }
      ],
      "industries": [
        "Aerospace",
        "Political"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "john_zno",
        "id": "211870",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 7,
        "FileHash-SHA1": 20,
        "FileHash-SHA256": 7,
        "URL": 3,
        "domain": 2,
        "hostname": 2
      },
      "indicator_count": 41,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 32,
      "modified_text": "767 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "651a72358fd4b4a6a3e838f9",
      "name": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
      "description": "ESET Research has uncovered the tools deployed by the so-called Lazarus cybercriminal group to gain access to the systems of aerospace companies in Spain and the United States, as well as other high-profile incidents such as WannaCry.",
      "modified": "2023-11-01T07:03:22.463000",
      "created": "2023-10-02T07:33:09.938000",
      "tags": [
        "lightlesscan",
        "strong",
        "lazarus",
        "figure",
        "eset research",
        "mimic",
        "c server",
        "online",
        "windows prompt",
        "nickelloader",
        "blindingcan",
        "meta",
        "rats",
        "april",
        "hello",
        "wannacry",
        "august",
        "malware",
        "vmprotect",
        "june",
        "podcast",
        "tips",
        "facebook",
        "wannacryptor",
        "mini",
        "download",
        "first",
        "phishing",
        "service",
        "execution",
        "persistence",
        "manipulation",
        "team",
        "oilrig",
        "winordll64",
        "hidden cobra",
        "upload",
        "linux",
        "ku",
        "kw",
        "kt",
        "https",
        "miniblindingcan"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 36,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 11,
        "FileHash-SHA1": 13,
        "domain": 5,
        "hostname": 5
      },
      "indicator_count": 34,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 864,
      "modified_text": "945 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "651a4aaebb26e186d506fb1b",
      "name": "Lazarus hackers breach aerospace firm with new LightlessCan malware",
      "description": "",
      "modified": "2023-11-01T04:01:38.337000",
      "created": "2023-10-02T04:44:30.214000",
      "tags": [],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "cryptocti",
        "id": "110256",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 11,
        "FileHash-SHA1": 13,
        "domain": 5,
        "hostname": 5
      },
      "indicator_count": 34,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 501,
      "modified_text": "945 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6519cdc8cea6cf8431b15da8",
      "name": "ACTIVIDAD MALICIOSA | Relacionada con Ataque de Lazarus a la Agencia Aeroespacial 01-10-2023",
      "description": "Hemos descrito un nuevo ataque de Lazarus que se origin\u00f3 en LinkedIn, donde reclutadores falsos se acercaban a sus v\u00edctimas potenciales, que utilizaban computadoras corporativas para fines personales. Aunque la conciencia p\u00fablica sobre este tipo de ataques deber\u00eda ser alta, las tasas de \u00e9xito de estas campa\u00f1as a\u00fan no han bajado a cero.",
      "modified": "2023-10-31T19:02:38.816000",
      "created": "2023-10-01T19:51:36.036000",
      "tags": [
        "entity"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/gc9d8101923d24588b6c83b20613a1bf0bb3b5b0a38654f7a8cc81f1d16e0be9d?theme=light",
        "https://otx.alienvault.com/pulse/6516dc1c66c2a9a03166669f",
        "https://alertas-y-seguridad.jimdosite.com/repositorio-ioc/"
      ],
      "public": 1,
      "adversary": "Lazarus Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Trojan:Win32/Lazarus",
          "display_name": "Trojan:Win32/Lazarus",
          "target": "/malware/Trojan:Win32/Lazarus"
        },
        {
          "id": "Trojan:Win64/Lazarus",
          "display_name": "Trojan:Win64/Lazarus",
          "target": "/malware/Trojan:Win64/Lazarus"
        },
        {
          "id": "LightlessCan",
          "display_name": "LightlessCan",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1135",
          "name": "Network Share Discovery",
          "display_name": "T1135 - Network Share Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "esoporteingenieria2020",
        "id": "121604",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_121604/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 13,
        "domain": 5,
        "hostname": 4
      },
      "indicator_count": 22,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 268,
      "modified_text": "945 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6516f22aadc43e7b516394d5",
      "name": "Lazarus hackers breach aerospace firm with new LightlessCan malware",
      "description": "The North Korean 'Lazarus' hacking group targeted employees of an aerospace company located in Spain with fake job opportunities to hack into the corporate network using a previously unknown 'LightlessCan' backdoor.\n\nThe hackers utilized their ongoing \"Operation Dreamjob\" campaign, which entails approaching a target over LinkedIn and engaging in a fake employee recruitment process that, at some point, required the victim to download a file. The employee did so on a company's computer, allowing the North Korean hackers to breach the corporate network to conduct cyber espionage.",
      "modified": "2023-10-29T15:00:40.733000",
      "created": "2023-09-29T15:50:02.853000",
      "tags": [
        "lightlesscan",
        "strong",
        "lazarus",
        "figure",
        "eset research",
        "mimic",
        "c server",
        "online",
        "windows prompt",
        "nickelloader",
        "blindingcan",
        "meta",
        "rats",
        "april",
        "hello",
        "wannacry",
        "august",
        "malware",
        "vmprotect",
        "june",
        "podcast",
        "tips",
        "facebook",
        "wannacryptor",
        "mini",
        "download",
        "first",
        "phishing",
        "service",
        "execution",
        "persistence",
        "manipulation",
        "team",
        "oilrig",
        "winordll64",
        "hidden cobra",
        "upload",
        "linux",
        "ku",
        "kw",
        "kt",
        "https",
        "miniblindingcan"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/",
        "https://www.bleepingcomputer.com/news/security/lazarus-hackers-breach-aerospace-firm-with-new-lightlesscan-malware/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [
        "Korea, Democratic People's Republic of",
        "Netherlands",
        "Belgium"
      ],
      "malware_families": [
        {
          "id": "KU",
          "display_name": "KU",
          "target": null
        },
        {
          "id": "KW",
          "display_name": "KW",
          "target": null
        },
        {
          "id": "KT",
          "display_name": "KT",
          "target": null
        },
        {
          "id": "HTTPS",
          "display_name": "HTTPS",
          "target": null
        },
        {
          "id": "NickelLoader",
          "display_name": "NickelLoader",
          "target": null
        },
        {
          "id": "BlindingCan",
          "display_name": "BlindingCan",
          "target": null
        },
        {
          "id": "miniBlindingCan",
          "display_name": "miniBlindingCan",
          "target": null
        },
        {
          "id": "LightlessCan",
          "display_name": "LightlessCan",
          "target": null
        },
        {
          "id": "Lazarus",
          "display_name": "Lazarus",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1135",
          "name": "Network Share Discovery",
          "display_name": "T1135 - Network Share Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1530",
          "name": "Data from Cloud Storage Object",
          "display_name": "T1530 - Data from Cloud Storage Object"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        }
      ],
      "industries": [
        "Aerospace",
        "Defense"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 328,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dekaRituraj",
        "id": "99856",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_99856/resized/80/avatar_0e93d502b7.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 13,
        "URL": 11,
        "domain": 5,
        "hostname": 5
      },
      "indicator_count": 34,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 434,
      "modified_text": "948 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "651a6bf5c2ef0eb8b7bda145",
      "name": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
      "description": "",
      "modified": "2023-10-29T14:01:08.677000",
      "created": "2023-10-02T07:06:29.568000",
      "tags": [
        "LinkedIn",
        "Lazarus",
        "cyberespionage",
        "NickelLoader",
        "RAT",
        "LightlessCan",
        "miniBlindingCan"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [
        "Spain"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1135",
          "name": "Network Share Discovery",
          "display_name": "T1135 - Network Share Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1585",
          "name": "Establish Accounts",
          "display_name": "T1585 - Establish Accounts"
        },
        {
          "id": "T1593",
          "name": "Search Open Websites/Domains",
          "display_name": "T1593 - Search Open Websites/Domains"
        },
        {
          "id": "T1608",
          "name": "Stage Capabilities",
          "display_name": "T1608 - Stage Capabilities"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1530",
          "name": "Data from Cloud Storage Object",
          "display_name": "T1530 - Data from Cloud Storage Object"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        }
      ],
      "industries": [
        "Aerospace"
      ],
      "TLP": "white",
      "cloned_from": "651a5c71689f50987b56be3f",
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 13,
        "domain": 5,
        "hostname": 5
      },
      "indicator_count": 23,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 278,
      "modified_text": "948 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "651a5c71689f50987b56be3f",
      "name": "Lazarus luring employees with trojanized coding challenges: The case of a Spanish aerospace company",
      "description": "",
      "modified": "2023-10-29T14:01:08.677000",
      "created": "2023-10-02T06:00:17.772000",
      "tags": [
        "LinkedIn",
        "Lazarus",
        "cyberespionage",
        "NickelLoader",
        "RAT",
        "LightlessCan",
        "miniBlindingCan"
      ],
      "references": [
        "https://www.welivesecurity.com/en/eset-research/lazarus-luring-employees-trojanized-coding-challenges-case-spanish-aerospace-company/"
      ],
      "public": 1,
      "adversary": "Lazarus",
      "targeted_countries": [
        "Spain"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1135",
          "name": "Network Share Discovery",
          "display_name": "T1135 - Network Share Discovery"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1585",
          "name": "Establish Accounts",
          "display_name": "T1585 - Establish Accounts"
        },
        {
          "id": "T1593",
          "name": "Search Open Websites/Domains",
          "display_name": "T1593 - Search Open Websites/Domains"
        },
        {
          "id": "T1608",
          "name": "Stage Capabilities",
          "display_name": "T1608 - Stage Capabilities"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1530",
          "name": "Data from Cloud Storage Object",
          "display_name": "T1530 - Data from Cloud Storage Object"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        }
      ],
      "industries": [
        "Aerospace"
      ],
      "TLP": "white",
      "cloned_from": "6516dc1c66c2a9a03166669f",
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "tr2222200",
        "id": "207905",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 13,
        "domain": 5,
        "hostname": 5
      },
      "indicator_count": 23,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 187,
      "modified_text": "948 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "turnscor.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "turnscor.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780507113.5874956
}