﻿{"id":2516,"date":"2018-05-29T12:18:37","date_gmt":"2018-05-29T05:18:37","guid":{"rendered":"https:\/\/humanit.asia\/?p=2516"},"modified":"2019-07-11T14:41:18","modified_gmt":"2019-07-11T07:41:18","slug":"ta18-149a","status":"publish","type":"post","link":"https:\/\/old.humanit.asia\/th\/ta18-149a\/","title":{"rendered":"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm"},"content":{"rendered":"<div>Original release date: May 29, 2018<\/p>\n<h3>Systems Affected<\/h3>\n<p>Network systems<\/p>\n<h3>Overview<\/h3>\n<p>This joint Technical Alert (TA) is the result of analytic efforts between the Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI). Working with U.S. government partners, DHS and FBI identified Internet Protocol (IP) addresses and other indicators of compromise (IOCs) associated with two families of malware used by the North Korean government:<\/p>\n<ul>\n<li>a remote access tool (RAT), commonly known as Joanap; and<\/li>\n<li>a Server Message Block (SMB) worm, commonly known as Brambul.<\/li>\n<\/ul>\n<p>The U.S. Government refers to malicious cyber activity by the North Korean government as HIDDEN COBRA. For more information on HIDDEN COBRA activity, visit <a href=\"https:\/\/www.us-cert.gov\/hiddencobra\">https:\/\/www.us-cert.gov\/hiddencobra<\/a>.<\/p>\n<p>FBI has high confidence that HIDDEN COBRA actors are using the IP addresses\u2014listed in this report\u2019s IOC files\u2014to maintain a presence on victims\u2019 networks and enable network exploitation. DHS and FBI are distributing these IP addresses and other IOCs to enable network defense and reduce exposure to any North Korean government malicious cyber activity.<\/p>\n<p>This alert also includes suggested response actions to the IOCs provided, recommended mitigation techniques, and information on how to report incidents. If users or administrators detect activity associated with these malware families, they should immediately flag it, report it to the DHS National Cybersecurity and Communications Integration Center (NCCIC) or the FBI Cyber Watch (CyWatch), and give it the highest priority for enhanced mitigation.<\/p>\n<p>See the following links for a downloadable copy of IOCs:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.us-cert.gov\/sites\/default\/files\/publications\/TA18-149A.CSV\">IOCs<\/a> (.csv)<\/li>\n<li><a href=\"https:\/\/www.us-cert.gov\/sites\/default\/files\/publications\/TA18-149A.stix.xml\">IOCs<\/a> (.stix)<\/li>\n<\/ul>\n<p>NCCIC conducted analysis on four malware samples and produced a Malware Analysis Report (MAR). MAR-10135536.3 \u2013 RAT\/Worm examines the tactics, techniques, and procedures observed in the malware. Visit <a href=\"https:\/\/www.us-cert.gov\/ncas\/analysis-reports\/AR18-149A\">MAR-10135536.3 \u2013 HIDDEN COBRA RAT\/Worm<\/a> for the report and associated IOCs.<\/p>\n<h3>Description<\/h3>\n<p>According to reporting of trusted third parties, HIDDEN COBRA actors have likely been using both Joanap and Brambul malware since at least 2009 to target multiple victims globally and in the United States\u2014including the media, aerospace, financial, and critical infrastructure sectors. Users and administrators should review the information related to Joanap and Brambul from the Operation Blockbuster Destructive Malware Report <a href=\"https:\/\/www.operationblockbuster.com\/wp-content\/uploads\/2016\/02\/Operation-Blockbuster-Destructive-Malware-Report.pdf\">[1]<\/a> in conjunction with the IP addresses listed in the .csv and .stix files provided within this alert. Like many of the families of malware used by HIDDEN COBRA actors, Joanap, Brambul, and other previously reported custom malware tools, may be found on compromised network nodes. Each malware tool has different purposes and functionalities.<\/p>\n<p>Joanap malware is a fully functional RAT that is able to receive multiple commands, which can be issued by HIDDEN COBRA actors remotely from a command and control server. Joanap typically infects a system as a file dropped by other HIDDEN COBRA malware, which users unknowingly downloaded either when they visit sites compromised by HIDDEN COBRA actors, or when they open malicious email attachments.<\/p>\n<p>During analysis of the infrastructure used by Joanap malware, the U.S. Government identified 87 compromised network nodes. The countries in which the infected IP addresses are registered are as follows:<\/p>\n<table align=\"center\" cellpadding=\"1\" cellspacing=\"1\" class=\"noborder\" style=\"width: 420px; height: 112px;\">\n<thead>\n<tr>\n<td scope=\"col\" style=\"text-align: left;\" width=\"140px\">\n<ul>\n<li>Argentina<\/li>\n<li>Belgium<\/li>\n<li>Brazil<\/li>\n<li>Cambodia<\/li>\n<li>China<\/li>\n<li>Colombia<\/li>\n<\/ul>\n<\/td>\n<td scope=\"col\" style=\"text-align: left;\" width=\"140px\">\n<ul>\n<li>Egypt<\/li>\n<li>India<\/li>\n<li>Iran<\/li>\n<li>Jordan<\/li>\n<li>Pakistan<\/li>\n<li>Saudi Arabia<\/li>\n<\/ul>\n<\/td>\n<td scope=\"col\" style=\"text-align: left;\" width=\"140px\">\n<ul>\n<li>Spain<\/li>\n<li>Sri Lanka<\/li>\n<li>Sweden<\/li>\n<li>Taiwan<\/li>\n<li>Tunisia<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/thead>\n<\/table>\n<p>Malware often infects servers and systems without the knowledge of system users and owners. If the malware can establish persistence, it could move laterally through a victim\u2019s network and any connected networks to infect nodes beyond those identified in this alert.<\/p>\n<p>Brambul malware is a brute-force authentication worm that spreads through SMB shares. SMBs enable shared access to files between users on a network. Brambul malware typically spreads by using a list of hard-coded login credentials to launch a brute-force password attack against an SMB protocol for access to a victim\u2019s networks.<\/p>\n<p><strong>Technical Details<\/strong><\/p>\n<p><strong>Joanap<\/strong><\/p>\n<p>Joanap is a two-stage malware used to establish peer-to-peer communications and to manage botnets designed to enable other operations. Joanap malware provides HIDDEN COBRA actors with the ability to exfiltrate data, drop and run secondary payloads, and initialize proxy communications on a compromised Windows device. Other notable functions include<\/p>\n<ul>\n<li>file management,<\/li>\n<li>process management,<\/li>\n<li>creation and deletion of directories, and<\/li>\n<li>node management.<\/li>\n<\/ul>\n<p>Analysis indicates the malware encodes data using Rivest Cipher 4 encryption to protect its communication with HIDDEN COBRA actors. Once installed, the malware creates a log entry within the Windows System Directory in a file named mssscardprv.ax. HIDDEN COBRA actors use this file to capture and store victims\u2019 information such as the host IP address, host name, and the current system time.<\/p>\n<p><strong>Brambul<\/strong><\/p>\n<p>Brambul malware is a malicious Windows 32-bit SMB worm that functions as a service dynamic link library file or a portable executable file often dropped and installed onto victims\u2019 networks by dropper malware. When executed, the malware attempts to establish contact with victim systems and IP addresses on victims\u2019 local subnets. If successful, the application attempts to gain unauthorized access via the SMB protocol (ports 139 and 445) by launching brute-force password attacks using a list of embedded passwords. Additionally, the malware generates random IP addresses for further attacks.<\/p>\n<p>Analysts suspect the malware targets insecure or unsecured user accounts and spreads through poorly secured network shares. Once the malware establishes unauthorized access on the victim\u2019s systems, it communicates information about victim\u2019s systems to HIDDEN COBRA actors using malicious email addresses. This information includes the IP address and host name\u2014as well as the username and password\u2014of each victim\u2019s system. HIDDEN COBRA actors can use this information to remotely access a compromised system via the SMB protocol.<\/p>\n<p>Analysis of a newer variant of Brambul malware identified the following built-in functions for remote operations:<\/p>\n<ul>\n<li>harvesting system information,<\/li>\n<li>accepting command-line arguments,<\/li>\n<li>generating and executing a suicide script,<\/li>\n<li>propagating across the network using SMB,<\/li>\n<li>brute forcing SMB login credentials, and<\/li>\n<li>generating Simple Mail Transport Protocol email messages containing target host system information.<\/li>\n<\/ul>\n<p><strong>Detection and Response<\/strong><\/p>\n<p>This alert\u2019s IOC files provide HIDDEN COBRA IOCs related to Joanap and Brambul. DHS and FBI recommend that network administrators review the information provided, identify whether any of the provided IP addresses fall within their organizations\u2019 allocated IP address space, and\u2014if found\u2014take necessary measures to remove the malware.<\/p>\n<p>When reviewing network perimeter logs for the IP addresses, organizations may find instances of these IP addresses attempting to connect to their systems. Upon reviewing the traffic from these IP addresses, system owners may find some traffic relates to malicious activity and some traffic relates to legitimate activity.<\/p>\n<h3>Impact<\/h3>\n<p>A successful network intrusion can have severe impacts, particularly if the compromise becomes public. Possible impacts include<\/p>\n<ul>\n<li>temporary or permanent loss of sensitive or proprietary information,<\/li>\n<li>disruption to regular operations,<\/li>\n<li>financial losses incurred to restore systems and files, and<\/li>\n<li>potential harm to an organization\u2019s reputation.<\/li>\n<\/ul>\n<h3>Solution<\/h3>\n<p><strong><em>Mitigation Strategies<\/em><\/strong><\/p>\n<p>DHS recommends that users and administrators use the following best practices as preventive measures to protect their computer networks:<\/p>\n<ul>\n<li>Keep operating systems and software up-to-date with the latest patches. Most attacks target vulnerable applications and operating systems. Patching with the latest updates greatly reduces the number of exploitable entry points available to an attacker.<\/li>\n<li>Maintain up-to-date antivirus software, and scan all software downloaded from the internet before executing.<\/li>\n<li>Restrict users\u2019 abilities (permissions) to install and run unwanted software applications, and apply the principle of least privilege to all systems and services. Restricting these privileges may prevent malware from running or limit its capability to spread through the network.<\/li>\n<li>Scan for and remove suspicious email attachments. If a user opens a malicious attachment and enables macros, embedded code will execute the malware on the machine. Enterprises and organizations should consider blocking email messages from suspicious sources that contain attachments. For information on safely handling email attachments, see <a href=\"https:\/\/www.us-cert.gov\/ncas\/tips\/ST04-010\">Using Caution with Email Attachments<\/a>. Follow safe practices when browsing the web. See <a href=\"https:\/\/www.us-cert.gov\/ncas\/tips\/ST04-003\">Good Security Habits<\/a>&nbsp;and <a href=\"https:\/\/www.us-cert.gov\/ncas\/tips\/ST06-008\">Safeguarding Your Data<\/a>&nbsp;for additional details.<\/li>\n<li>Disable Microsoft\u2019s File and Printer Sharing service, if not required by the user\u2019s organization. If this service is required, use strong passwords or Active Directory authentication. See <a href=\"https:\/\/www.us-cert.gov\/ncas\/tips\/ST04-002\">Choosing and Protecting Passwords<\/a> for more information on creating strong passwords.<\/li>\n<li>Enable a personal firewall on organization workstations and configure it to deny unsolicited connection requests.<\/li>\n<\/ul>\n<p><strong><em>Response to Unauthorized Network Access<\/em><\/strong><\/p>\n<p><strong>Contact DHS or your local FBI office immediately.<\/strong> To report an intrusion and request resources for incident response or technical assistance, contact DHS NCCIC (<a href=\"https:\/\/www.us-cert.govmailto:NCCICCustomerService@hq.dhs.gov\/\">NCCICCustomerService@hq.dhs.gov<\/a> or 888-282-0870), FBI through a local field office, or FBI\u2019s Cyber Division (<a href=\"https:\/\/www.us-cert.govmailto:CyWatch@fbi.gov\/\">CyWatch@fbi.gov<\/a> or 855-292-3937).<\/p>\n<h3>References<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.operationblockbuster.com\/wp-content\/uploads\/2016\/02\/Operation-Blockbuster-Destructive-Malware-Report.pdf\">[1] Novetta\u2019s Destructive Malware Report<\/a><\/li>\n<\/ul>\n<h3>Revision History<\/h3>\n<ul>\n<li>May 29, 2018: Initial version<\/li>\n<\/ul>\n<hr>\n<p>This product is provided subject to this <a href=\"http:\/\/www.us-cert.gov\/privacy\/notification\">Notification<\/a> and this <a href=\"http:\/\/www.us-cert.gov\/privacy\/\">Privacy &amp; Use<\/a> policy.<\/p>\n<\/div>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener noreferrer\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Original release date: May 29, 2018 Systems Affected Ne [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[106],"tags":[],"class_list":["post-2516","post","type-post","status-publish","format-standard","hentry","category-alerts-th"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm - humanit managed services<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/old.humanit.asia\/ta18-149a\/\" \/>\n<meta property=\"og:locale\" content=\"th_TH\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm - humanit managed services\" \/>\n<meta property=\"og:description\" content=\"Original release date: May 29, 2018 Systems Affected Ne [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/old.humanit.asia\/ta18-149a\/\" \/>\n<meta property=\"og:site_name\" content=\"humanit managed services\" \/>\n<meta property=\"article:published_time\" content=\"2018-05-29T05:18:37+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2019-07-11T07:41:18+00:00\" \/>\n<meta name=\"author\" content=\"Admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 \u0e19\u0e32\u0e17\u0e35\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-149a\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-149a\\\/\"},\"author\":{\"name\":\"Admin\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"headline\":\"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm\",\"datePublished\":\"2018-05-29T05:18:37+00:00\",\"dateModified\":\"2019-07-11T07:41:18+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-149a\\\/\"},\"wordCount\":1441,\"articleSection\":[\"Alerts\"],\"inLanguage\":\"th\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-149a\\\/\",\"url\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-149a\\\/\",\"name\":\"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm - humanit managed services\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\"},\"datePublished\":\"2018-05-29T05:18:37+00:00\",\"dateModified\":\"2019-07-11T07:41:18+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-149a\\\/#breadcrumb\"},\"inLanguage\":\"th\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/old.humanit.asia\\\/ta18-149a\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/old.humanit.asia\\\/ta18-149a\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/old.humanit.asia\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#website\",\"url\":\"https:\\\/\\\/old.old.humanit.asia\\\/\",\"name\":\"humanit managed services\",\"description\":\"making technology easy\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/old.old.humanit.asia\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"th\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/old.old.humanit.asia\\\/#\\\/schema\\\/person\\\/e7a3d665ee9cc6526fb6fdc92f4eb09c\",\"name\":\"Admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"th\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g\",\"caption\":\"Admin\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm - humanit managed services","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/old.humanit.asia\/ta18-149a\/","og_locale":"th_TH","og_type":"article","og_title":"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm - humanit managed services","og_description":"Original release date: May 29, 2018 Systems Affected Ne [&hellip;]","og_url":"https:\/\/old.humanit.asia\/ta18-149a\/","og_site_name":"humanit managed services","article_published_time":"2018-05-29T05:18:37+00:00","article_modified_time":"2019-07-11T07:41:18+00:00","author":"Admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Admin","Est. reading time":"7 \u0e19\u0e32\u0e17\u0e35"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/old.humanit.asia\/ta18-149a\/#article","isPartOf":{"@id":"https:\/\/old.humanit.asia\/ta18-149a\/"},"author":{"name":"Admin","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"headline":"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm","datePublished":"2018-05-29T05:18:37+00:00","dateModified":"2019-07-11T07:41:18+00:00","mainEntityOfPage":{"@id":"https:\/\/old.humanit.asia\/ta18-149a\/"},"wordCount":1441,"articleSection":["Alerts"],"inLanguage":"th"},{"@type":"WebPage","@id":"https:\/\/old.humanit.asia\/ta18-149a\/","url":"https:\/\/old.humanit.asia\/ta18-149a\/","name":"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm - humanit managed services","isPartOf":{"@id":"https:\/\/old.old.humanit.asia\/#website"},"datePublished":"2018-05-29T05:18:37+00:00","dateModified":"2019-07-11T07:41:18+00:00","author":{"@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c"},"breadcrumb":{"@id":"https:\/\/old.humanit.asia\/ta18-149a\/#breadcrumb"},"inLanguage":"th","potentialAction":[{"@type":"ReadAction","target":["https:\/\/old.humanit.asia\/ta18-149a\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/old.humanit.asia\/ta18-149a\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/old.humanit.asia\/"},{"@type":"ListItem","position":2,"name":"TA18-149A: HIDDEN COBRA \u2013 Joanap Backdoor Trojan and Brambul Server Message Block Worm"}]},{"@type":"WebSite","@id":"https:\/\/old.old.humanit.asia\/#website","url":"https:\/\/old.old.humanit.asia\/","name":"humanit managed services","description":"making technology easy","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/old.old.humanit.asia\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"th"},{"@type":"Person","@id":"https:\/\/old.old.humanit.asia\/#\/schema\/person\/e7a3d665ee9cc6526fb6fdc92f4eb09c","name":"Admin","image":{"@type":"ImageObject","inLanguage":"th","@id":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2d8f90c345033af4c0eb51ef25202eced8799a4331f9c232149e984d2570105b?s=96&d=mm&r=g","caption":"Admin"}}]}},"_links":{"self":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/comments?post=2516"}],"version-history":[{"count":1,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2516\/revisions"}],"predecessor-version":[{"id":2517,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/posts\/2516\/revisions\/2517"}],"wp:attachment":[{"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/media?parent=2516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/categories?post=2516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/old.humanit.asia\/th\/wp-json\/wp\/v2\/tags?post=2516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}