{"id":5113,"date":"2020-04-22T12:26:04","date_gmt":"2020-04-22T19:26:04","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=5113"},"modified":"2024-04-26T13:21:26","modified_gmt":"2024-04-26T20:21:26","slug":"spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/","title":{"rendered":"Spoofed Healthcare Malspam Campaign Delivers Hancitor Infostealer"},"content":{"rendered":"<p>On 14 April, security researcher JTHL (@JayTHL), reported a Humana Insurance\/COVID-19-themed malicious spam (malspam) campaign delivering Hancitor malware, also known as Chanitor, via an embedded macro in a Microsoft Excel (XLS) file.<sup>1<\/sup><\/p>\n<p>Hancitor is a trojan downloader that lures victims into downloading malicious Microsoft Office files that introduce additional malware to a victim\u2019s machine. The stage-two payloads are designed to steal personally identifiable information (PII) such as device credentials or banking information. Once Hancitor infects a victim&#8217;s device, it receives instructions through communication with its command and control (C2) server to download additional malware, such as the Gozi, Pony, or Evil Pony information stealers (infostealers).<\/p>\n<p>The messages in this campaign impersonate the healthcare provider Humana with subject lines such as &#8220;The above is a safe message coming from Humana. #&lt;digits&gt;.\u201d The bodies of the emails prompt the user to click a &#8220;See Details&#8221; button for information on a fraudulent invoice for a COVID-19 protection plan.<\/p>\n<p>Malspam subject lines:<\/p>\n<ul>\n<li>The above is a secure e-mail from Humana. #141241276<\/li>\n<li>The above is a safe message coming from Humana. #1446999<\/li>\n<li>This is a secure message coming from Humana. #1224<\/li>\n<\/ul>\n<p>Infoblox\u2019s full report on this instance of the malware will be available soon on our <a href=\"https:\/\/insights.infoblox.com\/threat-intelligence-reports\">Threat Intelligence Reports<\/a> page.<\/p>\n<p><strong>Endnotes<\/strong><\/p>\n<ol>\n<li><a href=\"https:\/\/twitter.com\/JayTHL\/status\/1250274763479506945\">https:\/\/twitter.com\/JayTHL\/status\/1250274763479506945<\/a><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>On 14 April, security researcher JTHL (@JayTHL), reported a Humana Insurance\/COVID-19-themed malicious spam (malspam) campaign delivering Hancitor malware, also known as Chanitor, via an embedded macro in a Microsoft Excel (XLS) file.1 Hancitor is a trojan downloader that lures victims into downloading malicious Microsoft Office files that introduce additional malware to a victim\u2019s machine. The [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":2809,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[254],"tags":[346,15,40,260],"class_list":{"0":"post-5113","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threat-intelligence","8":"tag-healthcare","9":"tag-security","10":"tag-threat-intelligence","11":"tag-trojan","12":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Spoofed Humana Healthcare Malspam Campaign Delivers Hancitor Infostealer<\/title>\n<meta name=\"description\" content=\"On 14 April, security researcher JTHL (@JayTHL), reported a Humana Insurance\/COVID-19-themed malicious spam (malspam) campaign delivering Hancitor malware, also known as Chanitor, via an embedded macro in a Microsoft Excel (XLS) file.1Hancitor is a trojan downloader that lures victims into downloading malicious Microsoft Office files that introduce additional malware to a victim\u2019s machine.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Spoofed Healthcare Malspam Campaign Delivers Hancitor Infostealer\" \/>\n<meta property=\"og:description\" content=\"On 14 April, security researcher JTHL (@JayTHL), reported a Humana Insurance\/COVID-19-themed malicious spam (malspam) campaign delivering Hancitor malware, also known as Chanitor, via an embedded macro in a Microsoft Excel (XLS) file.1Hancitor is a trojan downloader that lures victims into downloading malicious Microsoft Office files that introduce additional malware to a victim\u2019s machine.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2020-04-22T19:26:04+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-26T20:21:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Avoiding-VDI-Voodoo.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"660\" \/>\n\t<meta property=\"og:image:height\" content=\"454\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"Spoofed Healthcare Malspam Campaign Delivers Hancitor Infostealer\",\"datePublished\":\"2020-04-22T19:26:04+00:00\",\"dateModified\":\"2024-04-26T20:21:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/\"},\"wordCount\":221,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Avoiding-VDI-Voodoo.jpg\",\"keywords\":[\"Healthcare\",\"Security\",\"Threat Intelligence\",\"Trojan\"],\"articleSection\":[\"Infoblox Threat Intel\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/\",\"name\":\"Spoofed Humana Healthcare Malspam Campaign Delivers Hancitor Infostealer\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Avoiding-VDI-Voodoo.jpg\",\"datePublished\":\"2020-04-22T19:26:04+00:00\",\"dateModified\":\"2024-04-26T20:21:26+00:00\",\"description\":\"On 14 April, security researcher JTHL (@JayTHL), reported a Humana Insurance\\\/COVID-19-themed malicious spam (malspam) campaign delivering Hancitor malware, also known as Chanitor, via an embedded macro in a Microsoft Excel (XLS) file.1Hancitor is a trojan downloader that lures victims into downloading malicious Microsoft Office files that introduce additional malware to a victim\u2019s machine.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Avoiding-VDI-Voodoo.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Avoiding-VDI-Voodoo.jpg\",\"width\":660,\"height\":454,\"caption\":\"Avoiding VDI Voodoo\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Spoofed Healthcare Malspam Campaign Delivers Hancitor Infostealer\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Spoofed Humana Healthcare Malspam Campaign Delivers Hancitor Infostealer","description":"On 14 April, security researcher JTHL (@JayTHL), reported a Humana Insurance\/COVID-19-themed malicious spam (malspam) campaign delivering Hancitor malware, also known as Chanitor, via an embedded macro in a Microsoft Excel (XLS) file.1Hancitor is a trojan downloader that lures victims into downloading malicious Microsoft Office files that introduce additional malware to a victim\u2019s machine.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/","og_locale":"en_US","og_type":"article","og_title":"Spoofed Healthcare Malspam Campaign Delivers Hancitor Infostealer","og_description":"On 14 April, security researcher JTHL (@JayTHL), reported a Humana Insurance\/COVID-19-themed malicious spam (malspam) campaign delivering Hancitor malware, also known as Chanitor, via an embedded macro in a Microsoft Excel (XLS) file.1Hancitor is a trojan downloader that lures victims into downloading malicious Microsoft Office files that introduce additional malware to a victim\u2019s machine.","og_url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/","og_site_name":"Infoblox Blog","article_published_time":"2020-04-22T19:26:04+00:00","article_modified_time":"2024-04-26T20:21:26+00:00","og_image":[{"width":660,"height":454,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Avoiding-VDI-Voodoo.jpg","type":"image\/jpeg"}],"author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"Spoofed Healthcare Malspam Campaign Delivers Hancitor Infostealer","datePublished":"2020-04-22T19:26:04+00:00","dateModified":"2024-04-26T20:21:26+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/"},"wordCount":221,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Avoiding-VDI-Voodoo.jpg","keywords":["Healthcare","Security","Threat Intelligence","Trojan"],"articleSection":["Infoblox Threat Intel"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/","url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/","name":"Spoofed Humana Healthcare Malspam Campaign Delivers Hancitor Infostealer","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Avoiding-VDI-Voodoo.jpg","datePublished":"2020-04-22T19:26:04+00:00","dateModified":"2024-04-26T20:21:26+00:00","description":"On 14 April, security researcher JTHL (@JayTHL), reported a Humana Insurance\/COVID-19-themed malicious spam (malspam) campaign delivering Hancitor malware, also known as Chanitor, via an embedded macro in a Microsoft Excel (XLS) file.1Hancitor is a trojan downloader that lures victims into downloading malicious Microsoft Office files that introduce additional malware to a victim\u2019s machine.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Avoiding-VDI-Voodoo.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Avoiding-VDI-Voodoo.jpg","width":660,"height":454,"caption":"Avoiding VDI Voodoo"},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/spoofed-humana-healthcare-malspam-campaign-delivers-hancitor-infostealer\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"Spoofed Healthcare Malspam Campaign Delivers Hancitor Infostealer"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/5113","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=5113"}],"version-history":[{"count":4,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/5113\/revisions"}],"predecessor-version":[{"id":5117,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/5113\/revisions\/5117"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/2809"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=5113"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=5113"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=5113"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}