{"id":28061,"date":"2024-07-10T20:40:11","date_gmt":"2024-07-11T03:40:11","guid":{"rendered":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/"},"modified":"2024-07-10T20:40:11","modified_gmt":"2024-07-11T03:40:11","slug":"vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting","status":"publish","type":"post","link":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/","title":{"rendered":"ViperSoftX malware covertly runs PowerShell using AutoIT scripting"},"content":{"rendered":"<div>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"ViperSoftX malware covertly runs PowerShell using AutoIT scripting\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/07\/10\/vipersoftx.jpg\" width=\"1600\"><\/p>\n<p>The latest variants of the ViperSoftX recordsdata-stealing malware exhaust the customary language runtime (CLR) to load and blueprint PowerShell commands interior AutoIt scripts to evade detection.<\/p>\n<p>CLR is a key component of Microsoft&rsquo;s .NET Framework, serving because the execution engine and runtime environment for .NET applications.<\/p>\n<p>ViperSoftX makes exhaust of CLR to load code interior AutoIt, a scripting language for automating Residence windows duties which shall be on the total trusted by safety alternate strategies.<\/p>\n<p>To boot, researchers realized that the developer of the malware integrated modified offensive scripts in the latest versions to enlarge sophistication.<\/p>\n<h2>Infection chain<\/h2>\n<p>ViperSoftX has been spherical since no longer no longer as much as 2020 and it&#8217;s in the period in-between dispensed on torrent sites as ebooks that bring malicious RAR archives with&nbsp;a decoy PDF or e book file, a shortcut (.LNK) file, and PowerShell and AutoIT scripts disguised as JPG portray recordsdata.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Data in the RAR archive\" height=\"404\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2024\/Cybersecurity\/09\/files.jpg\" width=\"900\"><figcaption><strong>Data in the RAR archive<\/strong><br \/><em>Provide: Trellix<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Malware researchers at cybersecurity firm Trellix mumble that the infection begins when victims blueprint the .LNK file. At some level of the direction of, it loads the PowerShell script that hides interior easy spaces commands which shall be routinely accomplished in the List Rapid.<\/p>\n<p>The PS script strikes to the %APPDATA%MicrosoftResidence windows list two recordsdata (<em>zz1Cover2.jpg<\/em> and <em>zz1Cover3.jpg<\/em>). One among them&nbsp;is the executable for AutoIt and renamed<em>AutoIt3.exe.<\/em><\/p>\n<p>To withhold persistence, the identical script&nbsp;configures the Assignment Scheduler to race AutoIt3.exe every five minutes after the person logs in.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Scheduled duties added by ViperSoftX\" height=\"180\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2024\/Cybersecurity\/09\/task.jpg\" width=\"624\"><figcaption><strong>Scheduled duties added by ViperSoftX<\/strong><br \/><em>Provide: Trellix<\/em><\/figcaption><\/figure>\n<\/div>\n<h2>Stealthy operation<\/h2>\n<p>By using CLR to load&nbsp;and blueprint&nbsp;PowerShell commands in the midst of the AutoIt environment, ViperSoftX seeks to blend into legit activities on the scheme and evade detection.<\/p>\n<p>Right here is doable because no topic AutoIT no longer supporting&nbsp;.NET CLR natively, customers can relate capabilities that enable invoking&nbsp;PowerShell commands circuitously.<\/p>\n<p>ViperSoftX makes exhaust of heavy Base64 obfuscation and AES encryption to conceal the commands in the PowerShell scripts taken from the portray decoy recordsdata.<\/p>\n<p>The malware also strategies a characteristic to switch the memory of the Antimalware Scan Interface (AMSI) characteristic (&lsquo;AmsiScanBuffer&rsquo;) to bypass safety assessments on the scripts.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"ViperSoftX assault trudge\" height=\"536\" width=\"1200\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2024\/Cybersecurity\/09\/attack-flow.jpg\" previous-src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2024\/Cybersecurity\/09\/attack-flow.jpg\"><figcaption><strong>ViperSoftX assault trudge<\/strong><br \/><em>Provide: Trellix<\/em><\/figcaption><\/figure>\n<\/div>\n<p>For&nbsp;network communication, ViperSoftX makes exhaust of&nbsp;mistaken hostnames love &lsquo;safety-microsoft.com. To care for beneath the radar, scheme recordsdata is encoded in the Base64&nbsp;format and the details is delivered by a POST&nbsp;demand with a command measurement of &ldquo;0.&rdquo; In doing so, the threat actor again tries to withhold a long way from consideration because of the the dearth of body command.<\/p>\n<p>The goal of ViperSoftX is to clutch the following data from compromised systems:<\/p>\n<ul>\n<li>Machine and hardware critical capabilities<\/li>\n<li>Cryptocurrency wallet data from browser extensions love MetaMask, Ronin Wallet, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/vipersoftx-info-stealing-malware-now-targets-password-managers\/\" target=\"_blank\" rel=\"noopener\">and heaps of others<\/a><\/li>\n<li>Clipboard contents<\/li>\n<\/ul>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"ViperSoftX checking the browser extensions\" height=\"600\" width=\"739\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2024\/Cybersecurity\/09\/extensions.jpg\" previous-src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2024\/Cybersecurity\/09\/extensions.jpg\"><figcaption><strong>ViperSoftX checking the browser extensions<\/strong><br \/><em>Provide: Trellix<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Trellix says that ViperSoftX has refined its evasion ways and has change into an even bigger threat. By integrating CLR to blueprint PowerShell interior AutoIt, the malware manages to race malicious capabilities while evading safety mechanisms that on the total find standalone PowerShell exercise.<\/p>\n<p>The researchers describe the malware as a trendy and agile standard threat that would possibly maybe also be thwarted with &#8220;a comprehensive defense technique that encompasses detection, prevention, and response capabilities.&#8221;<\/p>\n<hr>\n<p><a href=\"https:\/\/try.flare.io\/bleeping-computer\/\" target=\"_blank\" rel=\"nofollow noopener\"><img decoding=\"async\" width=\"1832px\" height=\"400px\" src=\"https:\/\/www.bleepstatic.com\/c\/f\/flare\/flare-400.jpg\" previous-src=\"https:\/\/www.bleepstatic.com\/c\/f\/flare\/flare-400.jpg\"><\/a><\/p>\n<\/div>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The latest variants of the ViperSoftX recordsdata-stealing malware exhaust the customary language runtime (CLR) to&#8230;<\/p>\n","protected":false},"author":1,"featured_media":28062,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3103,3102],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>ViperSoftX malware covertly runs PowerShell using AutoIT scripting - CBS26 Arizona<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"ViperSoftX malware covertly runs PowerShell using AutoIT scripting - CBS26 Arizona\" \/>\n<meta property=\"og:description\" content=\"The latest variants of the ViperSoftX recordsdata-stealing malware exhaust the customary language runtime (CLR) to...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/\" \/>\n<meta property=\"og:site_name\" content=\"CBS26 Arizona\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/CBSNews\/\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-11T03:40:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/07\/10\/vipersoftx.jpg\" \/>\n<meta name=\"author\" content=\"cbs26.com\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@CBSNews\" \/>\n<meta name=\"twitter:site\" content=\"@CBSNews\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"cbs26.com\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/\"},\"author\":{\"name\":\"cbs26.com\",\"@id\":\"https:\/\/cbs26.com\/#\/schema\/person\/6f199387dd167b788a14f8b99f8ff352\"},\"headline\":\"ViperSoftX malware covertly runs PowerShell using AutoIT scripting\",\"datePublished\":\"2024-07-11T03:40:11+00:00\",\"dateModified\":\"2024-07-11T03:40:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/\"},\"wordCount\":576,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/cbs26.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cbs26.com\/wp-content\/uploads\/2024\/07\/28061-vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting.jpg\",\"articleSection\":[\"malware\",\"ViperSoftX\"],\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/\",\"url\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/\",\"name\":\"ViperSoftX malware covertly runs PowerShell using AutoIT scripting - CBS26 Arizona\",\"isPartOf\":{\"@id\":\"https:\/\/cbs26.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/cbs26.com\/wp-content\/uploads\/2024\/07\/28061-vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting.jpg\",\"datePublished\":\"2024-07-11T03:40:11+00:00\",\"dateModified\":\"2024-07-11T03:40:11+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#primaryimage\",\"url\":\"https:\/\/cbs26.com\/wp-content\/uploads\/2024\/07\/28061-vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting.jpg\",\"contentUrl\":\"https:\/\/cbs26.com\/wp-content\/uploads\/2024\/07\/28061-vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting.jpg\",\"width\":1280,\"height\":720,\"caption\":\"ViperSoftX malware covertly runs PowerShell using AutoIT scripting\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/cbs26.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"ViperSoftX malware covertly runs PowerShell using AutoIT scripting\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/cbs26.com\/#website\",\"url\":\"https:\/\/cbs26.com\/\",\"name\":\"CBS26 Arizona\",\"description\":\"The Spirit of Arizona\",\"publisher\":{\"@id\":\"https:\/\/cbs26.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/cbs26.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/cbs26.com\/#organization\",\"name\":\"CBS26 Arizona\",\"url\":\"https:\/\/cbs26.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/cbs26.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/cbs26.com\/wp-content\/uploads\/2023\/12\/cbs26.fw_-1-e1703104627272.png\",\"contentUrl\":\"https:\/\/cbs26.com\/wp-content\/uploads\/2023\/12\/cbs26.fw_-1-e1703104627272.png\",\"width\":296,\"height\":96,\"caption\":\"CBS26 Arizona\"},\"image\":{\"@id\":\"https:\/\/cbs26.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/CBSNews\/\",\"https:\/\/x.com\/CBSNews\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/cbs26.com\/#\/schema\/person\/6f199387dd167b788a14f8b99f8ff352\",\"name\":\"cbs26.com\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/cbs26.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e5c693e6a74bdbc1461a75db724fe465?s=96&d=mm&r=r\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e5c693e6a74bdbc1461a75db724fe465?s=96&d=mm&r=r\",\"caption\":\"cbs26.com\"},\"sameAs\":[\"http:\/\/cbs26.com\"],\"url\":\"https:\/\/cbs26.com\/index.php\/author\/cbs26-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"ViperSoftX malware covertly runs PowerShell using AutoIT scripting - CBS26 Arizona","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/","og_locale":"en_GB","og_type":"article","og_title":"ViperSoftX malware covertly runs PowerShell using AutoIT scripting - CBS26 Arizona","og_description":"The latest variants of the ViperSoftX recordsdata-stealing malware exhaust the customary language runtime (CLR) to...","og_url":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/","og_site_name":"CBS26 Arizona","article_publisher":"https:\/\/www.facebook.com\/CBSNews\/","article_published_time":"2024-07-11T03:40:11+00:00","og_image":[{"url":"https:\/\/www.bleepstatic.com\/content\/hl-images\/2024\/07\/10\/vipersoftx.jpg"}],"author":"cbs26.com","twitter_card":"summary_large_image","twitter_creator":"@CBSNews","twitter_site":"@CBSNews","twitter_misc":{"Written by":"cbs26.com","Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#article","isPartOf":{"@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/"},"author":{"name":"cbs26.com","@id":"https:\/\/cbs26.com\/#\/schema\/person\/6f199387dd167b788a14f8b99f8ff352"},"headline":"ViperSoftX malware covertly runs PowerShell using AutoIT scripting","datePublished":"2024-07-11T03:40:11+00:00","dateModified":"2024-07-11T03:40:11+00:00","mainEntityOfPage":{"@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/"},"wordCount":576,"commentCount":0,"publisher":{"@id":"https:\/\/cbs26.com\/#organization"},"image":{"@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#primaryimage"},"thumbnailUrl":"https:\/\/cbs26.com\/wp-content\/uploads\/2024\/07\/28061-vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting.jpg","articleSection":["malware","ViperSoftX"],"inLanguage":"en-GB","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/","url":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/","name":"ViperSoftX malware covertly runs PowerShell using AutoIT scripting - CBS26 Arizona","isPartOf":{"@id":"https:\/\/cbs26.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#primaryimage"},"image":{"@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#primaryimage"},"thumbnailUrl":"https:\/\/cbs26.com\/wp-content\/uploads\/2024\/07\/28061-vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting.jpg","datePublished":"2024-07-11T03:40:11+00:00","dateModified":"2024-07-11T03:40:11+00:00","breadcrumb":{"@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#primaryimage","url":"https:\/\/cbs26.com\/wp-content\/uploads\/2024\/07\/28061-vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting.jpg","contentUrl":"https:\/\/cbs26.com\/wp-content\/uploads\/2024\/07\/28061-vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting.jpg","width":1280,"height":720,"caption":"ViperSoftX malware covertly runs PowerShell using AutoIT scripting"},{"@type":"BreadcrumbList","@id":"https:\/\/cbs26.com\/index.php\/2024\/07\/10\/vipersoftx-malware-covertly-runs-powershell-using-autoit-scripting\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cbs26.com\/"},{"@type":"ListItem","position":2,"name":"ViperSoftX malware covertly runs PowerShell using AutoIT scripting"}]},{"@type":"WebSite","@id":"https:\/\/cbs26.com\/#website","url":"https:\/\/cbs26.com\/","name":"CBS26 Arizona","description":"The Spirit of Arizona","publisher":{"@id":"https:\/\/cbs26.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cbs26.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/cbs26.com\/#organization","name":"CBS26 Arizona","url":"https:\/\/cbs26.com\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/cbs26.com\/#\/schema\/logo\/image\/","url":"https:\/\/cbs26.com\/wp-content\/uploads\/2023\/12\/cbs26.fw_-1-e1703104627272.png","contentUrl":"https:\/\/cbs26.com\/wp-content\/uploads\/2023\/12\/cbs26.fw_-1-e1703104627272.png","width":296,"height":96,"caption":"CBS26 Arizona"},"image":{"@id":"https:\/\/cbs26.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/CBSNews\/","https:\/\/x.com\/CBSNews"]},{"@type":"Person","@id":"https:\/\/cbs26.com\/#\/schema\/person\/6f199387dd167b788a14f8b99f8ff352","name":"cbs26.com","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/cbs26.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e5c693e6a74bdbc1461a75db724fe465?s=96&d=mm&r=r","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e5c693e6a74bdbc1461a75db724fe465?s=96&d=mm&r=r","caption":"cbs26.com"},"sameAs":["http:\/\/cbs26.com"],"url":"https:\/\/cbs26.com\/index.php\/author\/cbs26-com\/"}]}},"_links":{"self":[{"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/posts\/28061"}],"collection":[{"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/comments?post=28061"}],"version-history":[{"count":0,"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/posts\/28061\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/media\/28062"}],"wp:attachment":[{"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/media?parent=28061"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/categories?post=28061"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cbs26.com\/index.php\/wp-json\/wp\/v2\/tags?post=28061"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}