{"id":3894,"date":"2021-11-29T09:40:49","date_gmt":"2021-11-29T04:10:49","guid":{"rendered":"https:\/\/xiarch.com\/blog\/?p=3894"},"modified":"2021-11-29T09:40:51","modified_gmt":"2021-11-29T04:10:51","slug":"discord-malware-operation-targets-crypto-and-nft-associations","status":"publish","type":"post","link":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/","title":{"rendered":"Discord Malware Operation Targets Crypto and NFT Associations"},"content":{"rendered":"\n<p><p style=\"text-align: justify;\">An advanced malware operation on Discord utilizes the Babadeda crypter to hide malware that targets the crypto, NFT, and DeFi communities. Babadeda is a crypter used to encrypt and obfuscate malicious payloads in what appear to be harmless application installers or programs. Starting in May 2021, threat actors have been distributing remote access trojans obfuscated by Babadeda as a legitimate app on crypto-themed Discord channels.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Due to its complex obfuscation, it has a very low AV detection rate, and according to researchers at Morphisec, its infection rates are picking up speed.<\/p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What is <strong>Phishing on Discord<\/strong>?<\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">The delivery chain begins on public Discord channels enjoying large viewership from a crypto-focused audience, such as new NFT drops or cryptocurrency discussions. The threat actors post on these channels or send private messages to prospective victims, inviting them to download a game or an app.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">In some cases, the actors impersonate existing blockchain software projects like the \u201cMines of Dalarna\u201d game.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image1-1.jpg\" alt=\"Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image1\" class=\"wp-image-3897\" width=\"697\" height=\"436\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image1-1.jpg 949w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image1-1-300x188.jpg 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image1-1-768x482.jpg 768w\" sizes=\"(max-width: 697px) 100vw, 697px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">If the user is tricked and clicks on the provided URL, they will end up on a decoy site that uses a cybersquatter domain that is easy to pass as the real one. These domains use a valid LetsEncrypt certificate and support an HTTPS connection, making it even harder for careless users to spot the fraud.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Various decoy sites utilized in this operation are given below:<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image2-2.jpg\" alt=\"Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image2\" class=\"wp-image-3898\" width=\"406\" height=\"438\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image2-2.jpg 690w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image2-2-278x300.jpg 278w\" sizes=\"(max-width: 406px) 100vw, 406px\" \/><\/figure><\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What is the Babadeda deception?<\/strong><\/h2>\n\n\n\n<p><p style=\"text-align: justify;\">The malware is downloaded upon clicking the &#8220;Play Now&#8221; or &#8220;Download app&#8221; buttons on the above sites, hiding in the form of DLLs and EXE files inside an archive that appears like any ordinary app folder at first glance.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">If the user attempts to execute the installer, they will receive a fake error message to deceive the victim into thinking that nothing happened. In the background, though, the execution of the malware continues, reading the steps from an XML file to execute new threads and load the DLL that will implement persistence.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">This persistence is done through a new startup folder item and the writing of a new registry Run key, both starting crypter&#8217;s primary executable.<\/p><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img decoding=\"async\" loading=\"lazy\" src=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image3-1-1024x687.jpg\" alt=\"Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image3\" class=\"wp-image-3899\" width=\"470\" height=\"315\" srcset=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image3-1-1024x687.jpg 1024w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image3-1-300x201.jpg 300w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image3-1-768x516.jpg 768w, https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-image3-1.jpg 1211w\" sizes=\"(max-width: 470px) 100vw, 470px\" \/><\/figure><\/div>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;The executable .text section\u2019s characteristics are configured to RWE (Read-Write-Execute) &#8212; that way the actor doesn&#8217;t need to use VirtualAlloc or VirtualProtect in order to copy the shellcode and transfer the execution.&#8221; &#8211; Morphisec<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">&#8220;This helps with evasion since those functions are highly monitored by security solutions. Once the shellcode is copied to the executable, the DLL calls to the shellcode\u2019s entry point (shellcode_address).&#8221;<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Babadeda has been used in past malware campaigns distributing info-stealers, RATs, and even the LockBit ransomware, but in this specific campaign, Morphisec witnessed the dropping of Remcos and BitRAT.<\/p><\/p>\n\n\n\n<p><p style=\"text-align: justify;\">Remcos is widely-abused foreign monitoring software that allows attackers to take authority of the infected machine and steal account credentials, browser cookies, drop more payloads, etc. In this case, because the attack targets members of the crypto community, it is expected that they are after their wallets, cryptocurrency funds, and NFT assets.<\/p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An advanced malware operation on Discord utilizes the Babadeda crypter to hide malware that targets the crypto, NFT, and DeFi communities. Babadeda is a crypter used to encrypt and obfuscate malicious payloads in what appear to be harmless application installers or programs. Starting in May 2021, threat actors have been distributing remote access trojans obfuscated [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3896,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[6],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.11 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Discord Malware Operation Targets Crypto and NFT Associations - Xiarch Bharat Pvt Ltd<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Discord Malware Operation Targets Crypto and NFT Associations - Xiarch Bharat Pvt Ltd\" \/>\n<meta property=\"og:description\" content=\"An advanced malware operation on Discord utilizes the Babadeda crypter to hide malware that targets the crypto, NFT, and DeFi communities. Babadeda is a crypter used to encrypt and obfuscate malicious payloads in what appear to be harmless application installers or programs. Starting in May 2021, threat actors have been distributing remote access trojans obfuscated [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/\" \/>\n<meta property=\"og:site_name\" content=\"Xiarch Bharat Pvt Ltd\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/xiarch\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-11-29T04:10:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-11-29T04:10:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-featured-image-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"525\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Xiarch Security\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@xiarch\" \/>\n<meta name=\"twitter:site\" content=\"@xiarch\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Xiarch Security\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/\"},\"author\":{\"name\":\"Xiarch Security\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\"},\"headline\":\"Discord Malware Operation Targets Crypto and NFT Associations\",\"datePublished\":\"2021-11-29T04:10:49+00:00\",\"dateModified\":\"2021-11-29T04:10:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/\"},\"wordCount\":500,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"articleSection\":[\"Vulnerabilities\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/\",\"url\":\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/\",\"name\":\"Discord Malware Operation Targets Crypto and NFT Associations - Xiarch Bharat Pvt Ltd\",\"isPartOf\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#website\"},\"datePublished\":\"2021-11-29T04:10:49+00:00\",\"dateModified\":\"2021-11-29T04:10:51+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/xiarch.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Discord Malware Operation Targets Crypto and NFT Associations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/xiarch.com\/blog\/#website\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"name\":\"Xiarch Bharat Pvt Ltd\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/xiarch.com\/blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/xiarch.com\/blog\/#organization\",\"name\":\"Xiarch\",\"url\":\"https:\/\/xiarch.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"contentUrl\":\"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png\",\"width\":300,\"height\":300,\"caption\":\"Xiarch\"},\"image\":{\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/xiarch\/\",\"https:\/\/twitter.com\/xiarch\",\"https:\/\/www.linkedin.com\/company\/xiarch\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c\",\"name\":\"Xiarch Security\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g\",\"caption\":\"Xiarch Security\"},\"sameAs\":[\"https:\/\/xiarch.com\/blog\/\"],\"url\":\"https:\/\/xiarch.com\/blog\/author\/vector\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Discord Malware Operation Targets Crypto and NFT Associations - Xiarch Bharat Pvt Ltd","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/","og_locale":"en_US","og_type":"article","og_title":"Discord Malware Operation Targets Crypto and NFT Associations - Xiarch Bharat Pvt Ltd","og_description":"An advanced malware operation on Discord utilizes the Babadeda crypter to hide malware that targets the crypto, NFT, and DeFi communities. Babadeda is a crypter used to encrypt and obfuscate malicious payloads in what appear to be harmless application installers or programs. Starting in May 2021, threat actors have been distributing remote access trojans obfuscated [&hellip;]","og_url":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/","og_site_name":"Xiarch Bharat Pvt Ltd","article_publisher":"https:\/\/www.facebook.com\/xiarch\/","article_published_time":"2021-11-29T04:10:49+00:00","article_modified_time":"2021-11-29T04:10:51+00:00","og_image":[{"width":1000,"height":525,"url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/11\/Discord-Malware-Operation-Targets-Crypto-and-NFT-Communities-featured-image-1.jpg","type":"image\/jpeg"}],"author":"Xiarch Security","twitter_card":"summary_large_image","twitter_creator":"@xiarch","twitter_site":"@xiarch","twitter_misc":{"Written by":"Xiarch Security","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/#article","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/"},"author":{"name":"Xiarch Security","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c"},"headline":"Discord Malware Operation Targets Crypto and NFT Associations","datePublished":"2021-11-29T04:10:49+00:00","dateModified":"2021-11-29T04:10:51+00:00","mainEntityOfPage":{"@id":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/"},"wordCount":500,"commentCount":0,"publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"articleSection":["Vulnerabilities"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/","url":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/","name":"Discord Malware Operation Targets Crypto and NFT Associations - Xiarch Bharat Pvt Ltd","isPartOf":{"@id":"https:\/\/xiarch.com\/blog\/#website"},"datePublished":"2021-11-29T04:10:49+00:00","dateModified":"2021-11-29T04:10:51+00:00","breadcrumb":{"@id":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/xiarch.com\/blog\/discord-malware-operation-targets-crypto-and-nft-associations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/xiarch.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Discord Malware Operation Targets Crypto and NFT Associations"}]},{"@type":"WebSite","@id":"https:\/\/xiarch.com\/blog\/#website","url":"https:\/\/xiarch.com\/blog\/","name":"Xiarch Bharat Pvt Ltd","description":"","publisher":{"@id":"https:\/\/xiarch.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/xiarch.com\/blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/xiarch.com\/blog\/#organization","name":"Xiarch","url":"https:\/\/xiarch.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","contentUrl":"https:\/\/xiarch.com\/blog\/wp-content\/uploads\/2021\/06\/xi-logo-002.png","width":300,"height":300,"caption":"Xiarch"},"image":{"@id":"https:\/\/xiarch.com\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/xiarch\/","https:\/\/twitter.com\/xiarch","https:\/\/www.linkedin.com\/company\/xiarch"]},{"@type":"Person","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/655d814a04eacce56942270cfdc5c59c","name":"Xiarch Security","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/xiarch.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d33699ed91b76568586dc1ae278ea568?s=96&d=mm&r=g","caption":"Xiarch Security"},"sameAs":["https:\/\/xiarch.com\/blog\/"],"url":"https:\/\/xiarch.com\/blog\/author\/vector\/"}]}},"_links":{"self":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3894"}],"collection":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/comments?post=3894"}],"version-history":[{"count":1,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3894\/revisions"}],"predecessor-version":[{"id":3900,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/posts\/3894\/revisions\/3900"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media\/3896"}],"wp:attachment":[{"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/media?parent=3894"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/categories?post=3894"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xiarch.com\/blog\/wp-json\/wp\/v2\/tags?post=3894"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}