{"id":26147,"date":"2026-09-21T13:06:28","date_gmt":"2026-09-21T21:06:28","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/analysis-of-ongoing-ousaban-attacks-targeting-the-iberian-peninsula-3\/"},"modified":"2026-09-21T13:06:28","modified_gmt":"2026-09-21T21:06:28","slug":"analysis-of-ongoing-ousaban-attacks-targeting-the-iberian-peninsula-3","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/analysis-of-ongoing-ousaban-attacks-targeting-the-iberian-peninsula-3\/","title":{"rendered":"Analysis of Ongoing Ousaban Attacks Targeting the Iberian Peninsula"},"content":{"rendered":"<div class=\"Table-Content aem-GridColumn aem-GridColumn--default--12\">\n<div class=\"blog-toc\">\n<div class=\"b3-blog-list__row\">\n<div class=\"b3-blog-list__column-left table-content-wrapper automatic\">\n<ul class=\"table-of-content\">\n<li class=\"header\"><img decoding=\"async\" alt=\"\" class=\"toc-icon\" src=\"\/content\/dam\/fortinet\/images\/toc-icon.jpg\"\/>Article Contents<\/li>\n<\/ul>\n<\/div>\n<div class=\"aem-GridColumn aem-GridColumn--default--8 b3-blog-list__column-right scrolling-content automatic\">\n<div class=\"b15-blog-meta__container text-container\">\n<span>By <\/span><br \/>\n<span class=\"b15-blog-meta__author\"><br \/>\n<a href=\"\/blog\/search?author=Rachael+Liao\">Rachael Liao<\/a><br \/>\n<\/span><br \/>\n<span class=\"b15-blog-meta__\"><br \/>\n<\/span><br \/>\n<span class=\"b15-blog-meta__date\"> | July 01, 2026<\/span>\n<\/div>\n<div class=\"C875-Disclaimer\">\n<\/div>\n<div class=\"raw-import\">\n<div class=\"text-container\"><\/div>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p style=\"\tmargin-left: 80.0px;\n\"><b>Affected Platforms: <\/b>Microsoft Windows<br \/>\n<b>Impacted Users: <\/b>Microsoft Windows<br \/>\n<b>Impact: <\/b>The stolen information can be used for future attacks<br \/>\n<b>Severity Level: <\/b>High<\/p>\n<p>In May 2026, FortiGuard Labs identified an attack targeting users in Spain and Portugal involving the banking Trojan Ousaban. This malware has been active in Brazil and is spread through an MSI downloader. The malicious payload involves a DLL file that is run via DLL side-loading or process injection.<\/p>\n<p>In this campaign, the threat actor primarily targets users in Spain and Portugal. Figure 1 shows how the attack unfolds. The phishing PDF tricks victims into visiting a malicious webpage that scans the user&#8217;s environment. If they are in Spain or Portugal, the webpage downloads a VBS file to kickstart the next part of the attack. The final payload is an EXE file that is dropped onto the victim\u2019s computer and executed by the VBS script.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 1: Attack flow<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>PDF<\/h2>\n<p>As shown in Figure 2, the phishing PDF is disguised as a corrupted file and contains a deceptive message box that prompts the victim to update it. The <b>Atualizar<\/b> button, which translates to &#8220;Update&#8221; in English, links to a malicious webpage. The PDF also includes JavaScript code that displays an error message and then accesses the same webpage. This JavaScript code is hex-escaped to evade detection.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 2: Screenshot of the phishing PDF<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p class=\"cq-text-placeholder-ipe\" data-emptytext=\"Text\">\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 3: The JavaScript code included in the PDF file<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>HTML<\/h2>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 4: The malicious webpage<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>The second phase of the attack involves a webpage that masquerades as a legitimate source of tax documents and system installers. A previous version of the webpage used detailed code for enforcing access controls. The webpage checks IP and device data to block unauthorized users and ensure that files are downloaded only by the intended recipients. It verifies language, time zone, and IP details to limit access to users in Spain and Portugal. To prevent bypassing this geo-restriction, the code also blocks IP addresses linked to VPNs by looking for keywords such as <b>&#8216;vpn<\/b>&#8216; in the organization info.<\/p>\n<p>Additionally, it evaluates user behavior and device characteristics, such as screen resolution, browser rendering, and font enumeration, to identify and block automated tools, such as sandboxes and crawlers, that tend to have limited browser capabilities.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 5: Part of the anti-analysis code<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>It has a 50% chance of showing an error message and a 50% chance of downloading the fake file<b> <\/b>if the user doesn\u2019t pass the environment check.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 6: Malware behavior when the environment check fails<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>In this new version, anti-analysis code is not used. Environmental information is sent to the threat actor, and a PDF containing a Spanish message that translates to &#8220;Access denied. Service not available from your country&#8221; is downloaded from the webpage if access does not originate from Spain or Portugal. By performing the environment check on the server side, the threat actor obscures specific indicators, making it harder for analysts to identify the criteria used in the check.<\/p>\n<h2>VBS<\/h2>\n<p>If the user environment passes the server-side check, a VBS file is downloaded. The VBS file contains numerous benign function calls. The malicious code downloads a steganographic image that resembles a PDF icon. It extracts a ZIP file from the image and retrieves the Ousaban payload. The image and ZIP archive are dropped into the Temp folder, and the payload is dropped to C:\\SysMain_5874288. After execution, the ZIP file, image file, and VBS file are deleted to minimize the footprint.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 7: A ZIP file is appended to the image file<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>Ousaban<\/h2>\n<p>Once executed, Ousaban creates a registry value named<b> Financeiro<\/b> (meaning Finance in English) in the CurrentVersion\\Run registry key to ensure persistence, and creates an empty file named <b>maisum.dat<\/b>, using its creation time as the installation timestamp. It then decrypts bank-related strings, which are subsequently used to check if the victim accesses a particular bank service. The list of banks is provided below:<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 8: Bank list<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>The strings are encrypted with a custom algorithm widely used by Latin American banking Trojans, including Casbaneiro.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 9: Example of decryption<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>The first byte of the encrypted data is a random value generated during encryption and is used as the base offset. Encryption begins with the second byte. The second byte is XORed with the corresponding key character, and subtracting the base offset from the result yields the decrypted value. The second byte then becomes the new base offset, and the process continues with the next byte. If the XOR result of the current byte and the corresponding key byte is smaller than the current base offset, it adds 0xFF to the difference between the XOR result and the current base offset.<\/p>\n<p>Including a random value ensures that identical plaintexts produce different ciphertexts, thereby increasing the complexity of analysis. For example, the screenshot below shows a Heartbeat packet: all data from the server is encrypted <b>#ON-LINE#,<\/b> and the client responses <b>are #StrPingOK#<\/b>, yet all encrypted data are different strings.\u00a0<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 10: Heartbeat packet<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Previous variants stored configurations remotely. In this attack, Ousaban decrypts a Pastebin link that points to configuration data containing a private IP address.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 11: The configuration data containing a private IP address<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>Ousaban does not use the Pastebin post to retrieve the actual IP address. Instead, it resolves the C2 IP address by looking up a hostname that changes daily when it detects the victim accessing specific banking services via a web browser. The hostnames belong to a DDNS-managed domain. The subdomains consist of a hard-coded string &#8220;aki&#8221; and the first eight characters of an MD5 hash. The MD5 hash is generated from a string that combines a hard-coded string &#8220;a9f8b7c6e5d4f3a2b1c8d7e6f5g4h3i2j1k9l8m7n6o5p4q&#8221; and the current date. To obtain the current date, Ousaban intentionally accesses the Google Automated Queries page and extracts the date from the page.<\/p>\n<p>If the hostname is resolvable, Ousaban establishes a connection to the C2 server. Below is the basic command list:<\/p>\n<p>\u00a0<\/p>\n<table border=\"0\" cellpadding=\"0\" cellspacing=\"0\" class=\"details-tbl\" width=\"100%\">\n<tbody>\n<tr class=\"gray\">\n<td width=\"20%\"><b>#Convite#<\/b><\/td>\n<td width=\"80%\">Collect user information<\/td>\n<\/tr>\n<tr>\n<td><b>#Handle#<\/b><\/td>\n<td>Assign a victim ID<\/td>\n<\/tr>\n<tr class=\"gray\">\n<td><b>#ON-LINE#<\/b><\/td>\n<td>Heartbeat<\/td>\n<\/tr>\n<tr>\n<td><b>#xyScree#<\/b><\/td>\n<td>Get screen resolution<\/td>\n<\/tr>\n<tr class=\"gray\">\n<td><b>#Iniciar#<\/b><\/td>\n<td>Start screenshot capture and remote control capability<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Most of the traffic between the server and Ousaban is encrypted using the previously described algorithm. Some messages consist of a command followed by its argument. For example, the following is the response when Ousaban receives the <b>#Convite# <\/b>command. The command and its arguments are separated by <b>&lt;#&gt;<\/b>.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n-->\n<\/div>\n<div class=\"cmp cmp-text\">\n<p><b>#Iniciar#<\/b> starts screenshot capture and initializes various functions for further actions, such as controlling the mouse and keyboard, performing clipboard injection, implementing a keylogger, and creating a more realistic scenario to deceive the victim. The following is an example of the fake message generated in response to the C2 server&#8217;s command.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 12: An example of a fake message used to deceive the victim<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>Pastebin<\/h2>\n<p>The Pastebin post containing a private IP address appears to be a decoy designed to divert attention from the actual method used to retrieve the C2 IP address. However, it still provides useful threat-hunting context because Ousaban variants used in late 2025 also accessed the post. Below is the attack flow:<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 13: Attack flow of the attack that occurred in late 2025<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<p>There are two types of initial attack vectors. One uses a ClickFix technique to trick the victim into executing malicious code. The code downloads a VBS file, which then retrieves an MSI installer. The other uses a PDF file that directs the victim to a phishing webpage, where the MSI installer is delivered. The MSI installer contains a Rust-based downloader that downloads and executes the Ousaban payload.<\/p>\n<\/div>\n<div class=\"cmp cmp-image\">\n<p><!--\n\n<div class=\"enlarge-btn\" data-sly-test=\"\">\n\n<div class=\"gg-maximize-alt\"><\/div>\n\n \n\n<div>Click to Enlarge<\/div>\n\n<\/div>\n\n--><br \/>\n<span class=\"cmp-image--title\">Figure 14: The PDF file used in late 2025<\/span>\n<\/div>\n<div class=\"cmp cmp-text\">\n<h2>Conclusion<\/h2>\n<p>The threat actor constantly advances and refines their malware delivery methods. In this campaign, they use various techniques to restrict access to the malware, such as geofencing and environmental checks, to limit exposure to the target audience. Apart from the distribution method, Ousaban depends on daily-changing domains to access the C2 IP and employs a traditional C2 setup as a decoy. Additionally, its encryption algorithm has been in use for a long time and remains effective at avoiding detection by security systems.\u00a0<\/p>\n<p>This malware employs numerous advanced distribution and evasion methods. FortiGuard will continue to monitor these attack campaigns and provide appropriate protections as needed.<\/p>\n<h2>Fortinet Protections<\/h2>\n<p>The malware described in this report is detected and blocked by <a aria-label=\"FortiGuard Antivirus\" href=\"\/support\/support-services\/fortiguard-security-subscriptions\/antivirus\" title=\"FortiGuard Antivirus\">FortiGuard Antivirus<\/a> as:<\/p>\n<p style=\"\tmargin-left: 40.0px;\n\">W32\/Ousaban.EY!tr.spy<br \/>\nVBS\/Agent.TPX!tr.dldr<br \/>\nPDF\/Agent.STG!tr<\/p>\n<p>FortiGate, FortiMail, FortiClient, and FortiEDR support the FortiGuard AntiVirus service. The FortiGuard AntiVirus engine is part of each of these solutions. As a result, customers who have these products with up-to-date protections are protected.<\/p>\n<p>FortiMail recognizes the phishing email as \u201cvirus detected.\u201d In addition, real-time anti-phishing provided by FortiSandbox embedded in Fortinet\u2019s FortiMail, web filtering, and antivirus solutions provides advanced protection against both known and unknown phishing attempts.<\/p>\n<p>The FortiGuard CDR (Content Disarm and Reconstruction) service, which runs on both FortiGate and FortiMail, can disarm the malicious macros in the document.<\/p>\n<p>We also suggest that organizations complete Fortinet\u2019s free <a aria-label=\"NSE training\" href=\"\/nse-training\" title=\"NSE training\">NSE training<\/a> module, <a aria-label=\"FCF Fortinet Certified Fundamentals\" href=\"https:\/\/training.fortinet.com\/local\/staticpage\/view.php?page=fcf_cybersecurity\" rel=\"noopener noreferrer\" target=\"_blank\" title=\"FCF Fortinet Certified Fundamentals\">FCF Fortinet Certified Fundamentals<\/a>. This module is designed to help end users learn how to identify and protect themselves from phishing attacks.<\/p>\n<p><a aria-label=\"FortiGuard IP Reputation\" href=\"\/support\/support-services\/fortiguard-security-subscriptions\/ipreputation-antibot\" title=\"FortiGuard IP Reputation\">FortiGuard IP Reputation<\/a> and <a aria-label=\"Anti-Botnet Security Service\" href=\"\/support\/support-services\/fortiguard-security-subscriptions\/ipreputation-antibot\" title=\"Anti-Botnet Security Service\">Anti-Botnet Security Service<\/a> proactively block these attacks by aggregating malicious source IP data from the Fortinet distributed network of threat sensors, CERTs, MITRE, cooperative competitors, and other global sources that collaborate to provide up-to-date threat intelligence about hostile sources.<\/p>\n<p>If you believe this or any other cybersecurity threat has impacted your organization, please contact our <a aria-label=\"Global FortiGuard Incident Response Team\" href=\"\/corporate\/about-us\/contact-us\/experienced-a-breach\" title=\"Global FortiGuard Incident Response Team\">Global FortiGuard Incident Response Team<\/a>.<\/p>\n<h2>IOCs<\/h2>\n<h3>Domains<\/h3>\n<p>faturanova[.]xyz<br \/>\nfacture-in[.]pages[.]dev<br \/>\nfacture-arsys[.]duckdns[.]org<br \/>\nfaturanova[.]duckdns[.]org<br \/>\ncontrolfacturas[.]site<\/p>\n<h3>IPs<\/h3>\n<p>213[.]159[.]64[.]191<br \/>\n162[.]33[.]179[.]46<br \/>\n91[.]92[.]240[.]140<br \/>\n78[.]40[.]209[.]32<\/p>\n<h3>PDFs<\/h3>\n<p>6bc2e11b0917f47d0557288c4f0cb20bd7589185943b989a969fdc6d3704ee73<br \/>\n540ee1936e61d2344b5ebc93485589a351ec2f113a9b4940ae16f3baa4807392<br \/>\ne2f0c2d4c1552cd81fa012043e4a5ac832582b639b7b6b7eccc0c4802d7a8ad8<br \/>\n9d07a83cf89685651ea8992047ae694c24f6ddef193044357debd15ce07a64fe<br \/>\n4c9fdc2823da505ef339d43c6ad38499b7e3447736733e42b5ab6b1afcfd42aa<br \/>\n5e06af187b45476ade0d953e834fced6197d0a33ac60c2575877660e26ab15e8<\/p>\n<h3>HTML<\/h3>\n<p>65c1a998bac48e02b52b1c850cd500e9fb87521e21755c3a4a491243f5f9a700<br \/>\n9e81ade09cc18f0fc09d73e72d2e0bffad02f52fdcc26553e473cee8cabc1567<br \/>\n1e77992666acbbfa0d01fcefa9cc8fbdac291e0681b35745be27c6dfb159a375<br \/>\nfadbb8061715128bebecf7bc59132b6bb04fe8cc39b965aa5b8722dffe28d7e7<\/p>\n<h3>VBS<\/h3>\n<p>5a2ed557c357ba8f96f2d55a8a00695987806b5df766cd1dfdab0cbed111774a<br \/>\n19ac18a50abb48dc0ea9524850acfaec49359e6b3bcc67c6193c2d56da812c71<br \/>\n48723a33bab89f174750576f9a62da35b3b9e5ac31a5a8f1ce9859a1b35bf8b8<\/p>\n<h3>MSI<\/h3>\n<p>21b24f7ee1f6bdbbb670f0394d66009ee0daa8ced57048298da715e88f7a7cdd<br \/>\nd4eb4ff02df659fdeec17d36b77084627469623bb3c7d16383d257404b52d1c3<\/p>\n<h3>EXEs<\/h3>\n<p>ffb9eb47cc0cb2f43e04a10dc84df13d04bca1ebacbe47fad0b669728de2f59c<br \/>\n18fd38988d58dd930f5992d448cc09a9400c1eafba76b820b9a83239ac48cf4e<br \/>\n4ca2c863d740bb7022776dccabd8ae34bb9998768928042d76ebcf08984eefcb<br \/>\n5837e47198a20877e1b04b270c36d9194206ee38d4f32fe3151b3c3b396c4f0d<br \/>\ne6e78eb2e9bd41a4bc62f7ad54d095ea9813864bebe37172ae30a1afa631fe14<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Affected Platforms: Microsoft Windows<br \/>\nImpacted Users: Microsoft Windows<br \/>\nImpact: The stolen information can be used for future attacks<br \/>\nSeverity Level: High<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10424,10378,32774],"tags":[],"class_list":["post-26147","post","type-post","status-publish","format-standard","hentry","category-fortinet","category-security","category-threats"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26147","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26147"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26147\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26147"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26147"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26147"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}