{
  "type": "IPv4",
  "indicator": "110.36.2.23",
  "general": {
    "whois": "http://whois.domaintools.com/110.36.2.23",
    "reputation": 0,
    "indicator": "110.36.2.23",
    "type": "IPv4",
    "type_title": "IPv4",
    "base_indicator": {
      "id": 4245286764,
      "indicator": "110.36.2.23",
      "type": "IPv4",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 23,
      "pulses": [
        {
          "id": "6a1a3b20659841db54164270",
          "name": "URLHaus data - 29-05-2026 (Part 1)",
          "description": "",
          "modified": "2026-05-30T01:19:28.174000",
          "created": "2026-05-30T01:19:28.174000",
          "tags": [
            "54e64e",
            "dropped-by-amadey",
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "arm",
            "mirai",
            "ClearFake",
            "gafgyt",
            "83-142-209-67",
            "sh",
            "ua-wget",
            "46-151-182-31",
            "connectwise",
            "exe",
            "46-151-182-242",
            "DDoSAgent",
            "supershell",
            "supershell-c2",
            "c2-monitor-auto",
            "9d2ca3",
            "rustystealer",
            "14-128-50-87",
            "dropped-by-Phorpiex",
            "BlackMatter",
            "176-65-139-77",
            "176-65-139-68",
            "62-60-130-237",
            "38-47-108-62",
            "31-56-209-72",
            "GhostPulse",
            "opendir",
            "msi",
            "rmm",
            "screenconnect",
            "ACRStealer",
            "LummaStealer",
            "RemusStealer",
            "wraith",
            "discord",
            "keylogger",
            "MacOS Stealer",
            "206-237-30-225",
            "154-89-148-115",
            "macho",
            "x86",
            "64-bit",
            "x86-64"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 257,
            "IPv4": 102,
            "hostname": 34,
            "domain": 2
          },
          "indicator_count": 395,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "22 hours ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f01341e9a1d5da90605291",
          "name": "Malware Filter - Botnet List - 27-04-2026 (Part 1)",
          "description": "",
          "modified": "2026-05-28T01:00:50.636000",
          "created": "2026-04-28T01:54:09.392000",
          "tags": [],
          "references": [
            "https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {},
          "indicator_count": 0,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1623,
          "modified_text": "2 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69eec8d1c4c8f9c722f89acf",
          "name": "URLHaus data - 26-04-2026 (Part 4)",
          "description": "",
          "modified": "2026-05-27T02:18:45.246000",
          "created": "2026-04-27T02:24:17.454000",
          "tags": [
            "ClearFake",
            "AdaptixC2",
            "exe",
            "opendir",
            "elf",
            "ua-wget",
            "32-bit",
            "mips",
            "Mozi",
            "sh",
            "mirai",
            "arm",
            "zip",
            "84-54-33-214",
            "84-54-33-77",
            "connectwise",
            "84-54-33-71",
            "84-54-33-157",
            "194-163-151-12",
            "45-88-186-69",
            "ladvix",
            "botnetdomain",
            "vmi3229260-contaboserver-net",
            "luxzzc2servers-my-id",
            "45-88-186-209",
            "45-92-1-43",
            "45-80-158-96",
            "45-138-16-51",
            "203-159-90-245",
            "45-154-98-122",
            "203-159-90-22",
            "193-26-115-225",
            "45-138-16-223",
            "124-198-131-61",
            "185-241-208-194",
            "x86",
            "m68k",
            "sparc",
            "SuperH",
            "PowerPC",
            "msi",
            "rmm",
            "screenconnect",
            "pw-LUMEN",
            "gitlab",
            "SantaStealer",
            "Vidar",
            "adeladel32951",
            "github",
            "EvelynStealer",
            "script",
            "193-26-115-162",
            "192-159-99-32",
            "192-159-99-209",
            "192-159-99-152-8080",
            "124-198-132-54",
            "124-198-132-14",
            "124-198-132-37",
            "45-156-87-140",
            "gafgyt",
            "124-198-131-54",
            "happytugsbakery-com",
            "204-76-203-195",
            "192-109-200-9",
            "204-76-203-248",
            "192-109-200-12",
            "192-109-200-131",
            "176-65-148-160",
            "176-65-132-197",
            "176-65-132-139",
            "194-26-192-44",
            "176-65-148-212",
            "beautiful-roentgen-176-65-139-130-plesk-page",
            "www-176-65-139-130-plesk-page",
            "91-92-242-236",
            "Amadey",
            "gamecheap-store",
            "156-229-165-225",
            "earnify",
            "maskify",
            "proxy-sdk",
            "176-65-139-141",
            "176-65-139-46",
            "176-65-139-47",
            "rustystealer"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 153,
            "hostname": 60
          },
          "indicator_count": 213,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "3 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69eec8d01c819eba42f63c29",
          "name": "URLHaus data - 26-04-2026 (Part 3)",
          "description": "",
          "modified": "2026-05-27T02:18:45.246000",
          "created": "2026-04-27T02:24:16.773000",
          "tags": [
            "ClearFake",
            "AdaptixC2",
            "exe",
            "opendir",
            "elf",
            "ua-wget",
            "32-bit",
            "mips",
            "Mozi",
            "sh",
            "mirai",
            "arm",
            "zip",
            "84-54-33-214",
            "84-54-33-77",
            "connectwise",
            "84-54-33-71",
            "84-54-33-157",
            "194-163-151-12",
            "45-88-186-69",
            "ladvix",
            "botnetdomain",
            "vmi3229260-contaboserver-net",
            "luxzzc2servers-my-id",
            "45-88-186-209",
            "45-92-1-43",
            "45-80-158-96",
            "45-138-16-51",
            "203-159-90-245",
            "45-154-98-122",
            "203-159-90-22",
            "193-26-115-225",
            "45-138-16-223",
            "124-198-131-61",
            "185-241-208-194",
            "x86",
            "m68k",
            "sparc",
            "SuperH",
            "PowerPC",
            "msi",
            "rmm",
            "screenconnect",
            "pw-LUMEN",
            "gitlab",
            "SantaStealer",
            "Vidar",
            "adeladel32951",
            "github",
            "EvelynStealer",
            "script",
            "193-26-115-162",
            "192-159-99-32",
            "192-159-99-209",
            "192-159-99-152-8080",
            "124-198-132-54",
            "124-198-132-14",
            "124-198-132-37",
            "45-156-87-140",
            "gafgyt",
            "124-198-131-54",
            "happytugsbakery-com",
            "204-76-203-195",
            "192-109-200-9",
            "204-76-203-248",
            "192-109-200-12",
            "192-109-200-131",
            "176-65-148-160",
            "176-65-132-197",
            "176-65-132-139",
            "194-26-192-44",
            "176-65-148-212",
            "beautiful-roentgen-176-65-139-130-plesk-page",
            "www-176-65-139-130-plesk-page",
            "91-92-242-236",
            "Amadey",
            "gamecheap-store",
            "156-229-165-225",
            "earnify",
            "maskify",
            "proxy-sdk",
            "176-65-139-141",
            "176-65-139-46",
            "176-65-139-47",
            "rustystealer"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 250,
            "hostname": 40,
            "domain": 1
          },
          "indicator_count": 291,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "3 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69ecae6a156da44db667be66",
          "name": "imvfeoirewIVONVCIDJCJCW",
          "description": "",
          "modified": "2026-05-25T12:11:06.214000",
          "created": "2026-04-25T12:07:06.437000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "MohammedRizwan2001",
            "id": "361933",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 508,
            "FileHash-MD5": 100,
            "FileHash-SHA1": 100,
            "FileHash-SHA256": 187,
            "domain": 17,
            "hostname": 159
          },
          "indicator_count": 1071,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 21,
          "modified_text": "5 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69ec18b7ea98d416d8bf38e9",
          "name": "URLHaus data - 24-04-2026 (Part 3)",
          "description": "",
          "modified": "2026-05-25T01:40:06.925000",
          "created": "2026-04-25T01:28:23.961000",
          "tags": [
            "ClearFake",
            "elf",
            "mips",
            "mirai",
            "ua-wget",
            "32-bit",
            "Mozi",
            "m68k",
            "arm",
            "PowerPC",
            "SuperH",
            "x86",
            "SmartLoader",
            "zip",
            "script",
            "opendir",
            "pw-4496",
            "rar",
            "pw-9931",
            "pw-DR67KVLD",
            "Vidar",
            "SantaStealer",
            "exe",
            "sh",
            "beacon",
            "PrivateLoader",
            "RedLine",
            "stealer",
            "ascii",
            "PureHVNC",
            "PureRAT",
            "rat",
            "vbs",
            "gafgyt",
            "PhantomStealer",
            "js",
            "176-65-139-146",
            "176-65-139-131",
            "176-65-139-152",
            "176-65-139-115",
            "176-65-139-47",
            "176-65-139-50",
            "176-65-139-141",
            "45-131-108-107",
            "91-92-243-181",
            "connectwise",
            "178-16-53-72",
            "178-16-54-33",
            "158-94-210-6",
            "178-16-55-93",
            "178-16-55-86",
            "178-16-54-224",
            "91-92-242-236",
            "tinynuke",
            "honeypot",
            "Xorddos"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 226,
            "hostname": 94,
            "domain": 1
          },
          "indicator_count": 321,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "5 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69eac9ec2d31146043bc2021",
          "name": "URLHaus data - 23-04-2026 (Part 2)",
          "description": "",
          "modified": "2026-05-24T01:27:05.528000",
          "created": "2026-04-24T01:39:56.794000",
          "tags": [
            "ClearFake",
            "32-bit",
            "arm",
            "elf",
            "Mozi",
            "mips",
            "CoinMiner",
            "ua-wget",
            "sh",
            "mirai",
            "PowerPC",
            "x86",
            "SuperH",
            "135e7b",
            "connectwise",
            "dropped-by-amadey",
            "Amadey",
            "cred64.dll",
            "plugin",
            "cred.dll",
            "gafgyt",
            "158-94-210-65-6275",
            "opendir",
            "plugins-costs-nyc-boulevard-trycloudflare-com",
            "xworm",
            "rat",
            "RemcosRAT",
            "zip",
            "ladvix",
            "c2",
            "dropper",
            "github",
            "malware",
            "spyware",
            "exe",
            "ChromElevator",
            "MassLogger",
            "script"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 250,
            "hostname": 51
          },
          "indicator_count": 301,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1623,
          "modified_text": "6 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "6a0e5ac9323cbdcd9cff7cbe",
          "name": "URLHaus data - 20-05-2026 (Part 3)",
          "description": "",
          "modified": "2026-05-21T01:07:21.475000",
          "created": "2026-05-21T01:07:21.475000",
          "tags": [
            "ClearFake",
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "arm",
            "mirai",
            "54e64e",
            "dropped-by-amadey",
            "sh",
            "ua-wget",
            "xml",
            "104-236-37-21",
            "hajime",
            "backdoor",
            "sshdkit",
            "exe",
            "opendir",
            "meterpreter",
            "ocx",
            "WsgiDAV",
            "DDoSAgent",
            "botnetdomain",
            "gafgyt",
            "ua-mshta",
            "VantaRAT",
            "jar",
            "WeedHack",
            "SilentNet",
            "104-131-37-178",
            "ascii",
            "powershell",
            "ps1",
            "rustystealer",
            "194-58-47-204",
            "31-42-176-91",
            "connectwise",
            "PureHVNC",
            "PureRAT",
            "rat",
            "vbs",
            "c2-monitor-auto",
            "script",
            "ClickFix",
            "ua-powershell",
            "finger",
            "9d2ca3",
            "android"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 111,
            "URL": 251,
            "hostname": 15,
            "domain": 30
          },
          "indicator_count": 407,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "9 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e42fe3e325b1e6e95567b3",
          "name": "URLHaus data - 18-04-2026 (Part 2)",
          "description": "",
          "modified": "2026-05-19T01:05:19.771000",
          "created": "2026-04-19T01:29:07.307000",
          "tags": [
            "ClearFake",
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "64-bit",
            "x86-64",
            "arm",
            "mirai",
            "hajime",
            "opendir",
            "ua-wget",
            "sh",
            "gafgyt",
            "NetSupport",
            "ascii",
            "powershell",
            "ps1",
            "ua-ps",
            "PureHVNC",
            "PureRAT",
            "rat",
            "zip",
            "x86-32",
            "nc",
            "85-11-167-21",
            "x86",
            "SuperH",
            "sparc",
            "PowerPC",
            "arc",
            "m68k"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 252,
            "hostname": 51,
            "domain": 4
          },
          "indicator_count": 307,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "11 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "6a0a6bd8197cd2d0d353fa5d",
          "name": "URLHaus data - 17-05-2026 (Part 2)",
          "description": "",
          "modified": "2026-05-18T01:31:04.127000",
          "created": "2026-05-18T01:31:04.127000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "ClearFake",
            "arm",
            "mirai",
            "ua-wget",
            "sh",
            "unknown",
            "opendir",
            "gafgyt",
            "hajime",
            "github",
            "c2-monitor-auto",
            "dropped-by-amadey",
            "DDoSAgent",
            "CoinMiner",
            "redtail",
            "x86",
            "exe",
            "stealer",
            "pw-GGWP",
            "54e64e",
            "armv7l",
            "ddos",
            "nova",
            "armv4l",
            "PowerPC",
            "armv5",
            "armv5l",
            "armv6",
            "armv6l",
            "x86_64",
            "i686",
            "mipsel",
            "Boatnet",
            "apk",
            "mamont",
            "i586",
            "sh4",
            "botnet",
            "load",
            "x64",
            "SalatStealer",
            "trojan",
            "dropper",
            "macOS",
            "shell"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 258,
            "IPv4": 77,
            "domain": 25,
            "hostname": 6
          },
          "indicator_count": 366,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "12 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0a6bd72d90c32f34b15c24",
          "name": "URLHaus data - 17-05-2026 (Part 1)",
          "description": "",
          "modified": "2026-05-18T01:31:03.403000",
          "created": "2026-05-18T01:31:03.403000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "ClearFake",
            "arm",
            "mirai",
            "ua-wget",
            "sh",
            "unknown",
            "opendir",
            "gafgyt",
            "hajime",
            "github",
            "c2-monitor-auto",
            "dropped-by-amadey",
            "DDoSAgent",
            "CoinMiner",
            "redtail",
            "x86",
            "exe",
            "stealer",
            "pw-GGWP",
            "54e64e",
            "armv7l",
            "ddos",
            "nova",
            "armv4l",
            "PowerPC",
            "armv5",
            "armv5l",
            "armv6",
            "armv6l",
            "x86_64",
            "i686",
            "mipsel",
            "Boatnet",
            "apk",
            "mamont",
            "i586",
            "sh4",
            "botnet",
            "load",
            "x64",
            "SalatStealer",
            "trojan",
            "dropper",
            "macOS",
            "shell"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 265,
            "IPv4": 70,
            "domain": 31,
            "hostname": 6
          },
          "indicator_count": 372,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "12 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a091955143b263bc4dd11c9",
          "name": "URLHaus data - 16-05-2026 (Part 3)",
          "description": "",
          "modified": "2026-05-17T01:26:44.990000",
          "created": "2026-05-17T01:26:44.990000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "ua-wget",
            "ClearFake",
            "arm",
            "mirai",
            "ClickFix",
            "exe",
            "msi",
            "CoinMiner",
            "d52f85",
            "dropped-by-amadey",
            "lnk",
            "opendir",
            "WsgiDAV",
            "Cobalt strike",
            "shellcode",
            "meterpreter",
            "xworm",
            "sh",
            "MetaStealer",
            "VenomLNK",
            "ChromElevator",
            "botnetdomain",
            "Encoded",
            "github",
            "gitlab",
            "stealer",
            "vbs",
            "gafgyt",
            "DDoSAgent",
            "HeliBot",
            "27-124-17-179",
            "27-124-17-217",
            "176-65-139-26",
            "31-56-209-125",
            "85-11-167-89",
            "64-89-163-196",
            "ladvix",
            "176-65-132-159",
            "176-65-139-174",
            "45-82-254-62-9999",
            "cdn-assets-xyz",
            "134-122-189-74-8080",
            "134-122-189-98-8080",
            "134-122-189-79-8080",
            "107-182-128-74",
            "python",
            "107-182-128-79",
            "107-182-128-67",
            "107-182-128-214",
            "107-182-128-70",
            "107-182-128-87",
            "107-182-128-69",
            "107-182-128-220",
            "107-182-128-217",
            "107-182-128-221",
            "107-182-128-215",
            "107-182-128-222",
            "107-182-128-75",
            "107-182-128-211",
            "9d2ca3",
            "45-198-224-38",
            "23-148-146-29",
            "connectwise",
            "178-16-53-143-8080",
            "45-89-53-89",
            "45-15-126-107",
            "54e64e"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 96,
            "URL": 254,
            "domain": 22,
            "hostname": 4
          },
          "indicator_count": 376,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "13 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a03bf4773b48c0ba5708a9c",
          "name": "hjkhhkjhjhkhkj",
          "description": "The following is the full text of the text-based code that has been used to identify and identify people using the word \"deepseek\" as a means of identifying and identifying them from the public.",
          "modified": "2026-05-13T00:01:11.186000",
          "created": "2026-05-13T00:01:11.186000",
          "tags": [
            "indicator name",
            "ydznvjljcz6f7",
            "kpuspriyonews"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "MohammedRizwan2001",
            "id": "361933",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 153,
            "FileHash-MD5": 186,
            "FileHash-SHA1": 85,
            "FileHash-SHA256": 81,
            "IPv4": 657,
            "domain": 211,
            "hostname": 561
          },
          "indicator_count": 1934,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 20,
          "modified_text": "18 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a027e8f1599c14b9b95eaed",
          "name": "URLHaus data - 11-05-2026 (Part 3)",
          "description": "",
          "modified": "2026-05-12T01:12:47.145000",
          "created": "2026-05-12T01:12:47.145000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "arm",
            "mirai",
            "opendir",
            "ua-wget",
            "PowerPC",
            "x86",
            "sparc",
            "m68k",
            "SuperH",
            "arc",
            "sh",
            "powershell",
            "botnetdomain",
            "176-65-139-167",
            "176-65-139-112",
            "176-65-139-152",
            "176-65-139-79",
            "gafgyt",
            "176-65-139-102",
            "ClearFake",
            "45.141.148.126",
            "mutex-nu9dEg9kHbubEzR1",
            "xworm",
            "194-156-79-120",
            "exe"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 245,
            "IPv4": 15
          },
          "indicator_count": 260,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1623,
          "modified_text": "18 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a026d1302c9455055c93776",
          "name": "hdsaljlkdldjlksjalkjlksdajlkdas",
          "description": "",
          "modified": "2026-05-11T23:58:11.141000",
          "created": "2026-05-11T23:58:11.141000",
          "tags": [
            "kpuspriyonews"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "MohammedRizwan2001",
            "id": "361933",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 953,
            "FileHash-MD5": 151,
            "FileHash-SHA1": 50,
            "FileHash-SHA256": 54,
            "IPv4": 858,
            "domain": 214,
            "hostname": 559
          },
          "indicator_count": 2839,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 20,
          "modified_text": "19 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fd84d2656fe3bd9f747899",
          "name": "URLHaus data - 07-05-2026 (Part 1)",
          "description": "",
          "modified": "2026-05-08T06:38:10.297000",
          "created": "2026-05-08T06:38:10.297000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "ClearFake",
            "SnappyClient",
            "arm",
            "mirai",
            "ua-wget",
            "45-156-87-157",
            "254fce8d9c8b6dea2b15bd016dae84bb3b3ec8ef9972f1bffdfabd3af004",
            "remcos",
            "791651d9ca0de1f77082de5a724fd0054b3daa5ff160a6eaf6e69a192588",
            "f3f3ff3f0964ca6e8c550940145fae49e6b4135523e309400513d8cbb969",
            "11ed7be675889b8d19b2e8f44bb33d6733a9de2e092102b1e8c1f28469d6",
            "RemcosRAT",
            "8eca755b90ce60a452f0c94a522b120601a8c2baddf939531f72db0f93a9",
            "df3d5ee897b28da580030a4776d2aec2d4d9b05667c6e1995fef8c41a5cd",
            "huge-file",
            "lnk",
            "140-233-190-47",
            "sh",
            "94-156-152-18",
            "opendir"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 257,
            "IPv4": 88,
            "hostname": 98,
            "domain": 3
          },
          "indicator_count": 446,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1623,
          "modified_text": "22 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fabfcb8d7b1cfb2fb6e05a",
          "name": "URLHaus data - 05-05-2026 (Part 1)",
          "description": "",
          "modified": "2026-05-06T04:12:59.304000",
          "created": "2026-05-06T04:12:59.304000",
          "tags": [
            "ClearFake",
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "ua-wget",
            "mirai",
            "sh",
            "arm",
            "opendir",
            "xml",
            "SuperH",
            "x86",
            "m68k",
            "PowerPC",
            "sparc",
            "x86-32",
            "209-99-186-71",
            "209-99-190-249-8080",
            "209-99-190-249-3000",
            "DDoSAgent",
            "83-147-18-16-8001",
            "rustystealer",
            "185-242-3-121",
            "31-57-216-218-8000",
            "Cobalt strike",
            "185-177-239-181",
            "SalatStealer",
            "193-233-113-59-8085",
            "SantaStealer",
            "130-94-41-210-8080",
            "meterpreter",
            "46-151-182-85",
            "46-151-182-23",
            "83-142-209-150",
            "njRAT",
            "77-221-136-59",
            "dropped-by-Stealc",
            "neverhigh",
            "rev-base64-loader",
            "apk",
            "mamont",
            "NetSupport",
            "msi",
            "CoinMiner",
            "exe",
            "AdamantLocker",
            "ascii",
            "ClickFix",
            "PureClaw",
            "PureHVNC",
            "c2-monitor-auto",
            "dropped-by-amadey"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 253,
            "hostname": 111,
            "IPv4": 57
          },
          "indicator_count": 421,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "24 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f409eb2515545cb09c7a3b",
          "name": "URLHaus data - 30-04-2026 (Part 1)",
          "description": "",
          "modified": "2026-05-01T02:03:23.387000",
          "created": "2026-05-01T02:03:23.387000",
          "tags": [
            "ClearFake",
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "arm",
            "mirai",
            "ua-wget",
            "sh",
            "x86",
            "54e64e",
            "dropped-by-amadey",
            "176-65-139-69",
            "176-65-139-80",
            "d52f85",
            "ClickFix",
            "95-181-173-225",
            "Rhadamanthys",
            "dropped-by-Phorpiex",
            "phorpiex",
            "hajime",
            "45-154-98-107",
            "169-40-135-103",
            "connectwise",
            "exe",
            "151-243-109-141-8888",
            "31-57-97-20",
            "Smoke Loader",
            "31-59-104-25",
            "CoinMiner",
            "redtail",
            "103-83-87-122",
            "103-83-86-91"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 254,
            "hostname": 78,
            "IPv4": 79,
            "domain": 1
          },
          "indicator_count": 412,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "29 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b78dfd573f2d35af2e17e5",
          "name": "URLHaus data - 15-03-2026 (Part 1)",
          "description": "",
          "modified": "2026-04-15T04:08:56.830000",
          "created": "2026-03-16T04:58:37.470000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "ua-wget",
            "mirai",
            "ACRStealer",
            "ClearFake",
            "arm",
            "gafgyt",
            "sh",
            "dropped-by-amadey",
            "fbf543",
            "c2-monitor-auto",
            "Stealc",
            "opendir",
            "x86",
            "script",
            "CoinMiner",
            "hajime",
            "Vidar",
            "rustystealer",
            "SilverFox",
            "ClickFix",
            "ErrTraffic",
            "NetSupport",
            "powershell",
            "boxter",
            "hta",
            "phishing",
            "zip",
            "pw-2026",
            "pw-ryos",
            "SmartLoader"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 258,
            "hostname": 119
          },
          "indicator_count": 377,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "45 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69b3feaad8ebe8ae1b654034",
          "name": "Honeypot Data - March 2026 - Cowrie",
          "description": "Data collected from honeypots in Louisiana. Just a fun project I tinker with.. data submitted with some gnarly python scripts for automation.",
          "modified": "2026-04-12T15:03:58.178000",
          "created": "2026-03-13T12:10:18.128000",
          "tags": [
            "malicious",
            "sftp",
            "LAMP",
            "cowrie",
            "ssh",
            "honeytrap"
          ],
          "references": [
            "https://github.com/telekom-security/tpotce"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ladarrellmiller",
            "id": "111524",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 49
          },
          "indicator_count": 49,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 429,
          "modified_text": "48 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69b267bb5f41d88da916193c",
          "name": "URLHaus data - 11-03-2026 (Part 2)",
          "description": "",
          "modified": "2026-04-11T07:34:42.144000",
          "created": "2026-03-12T07:14:03.468000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "dropped-by-amadey",
            "fbf543",
            "arm",
            "mirai",
            "ClearFake",
            "Vidar",
            "ua-wget",
            "c2-monitor-auto",
            "xworm",
            "64-bit",
            "x86-64",
            "sh",
            "ACRStealer",
            "ClickFix",
            "macOS",
            "ascii",
            "opendir",
            "powershell",
            "ps1",
            "ua-ps",
            "VIPKeylogger",
            "AgentTesla",
            "PhantomStealer",
            "Encoded",
            "rev-base64-loader",
            "ValleyRAT",
            "AsyncRAT",
            "rat",
            "exe",
            "bash",
            "geofenced",
            "USA",
            "xml"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 239,
            "hostname": 70,
            "domain": 5
          },
          "indicator_count": 314,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "49 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69b267b9fab177a841b2acd2",
          "name": "URLHaus data - 11-03-2026 (Part 1)",
          "description": "",
          "modified": "2026-04-11T07:34:42.144000",
          "created": "2026-03-12T07:14:01.774000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "dropped-by-amadey",
            "fbf543",
            "arm",
            "mirai",
            "ClearFake",
            "Vidar",
            "ua-wget",
            "c2-monitor-auto",
            "xworm",
            "64-bit",
            "x86-64",
            "sh",
            "ACRStealer",
            "ClickFix",
            "macOS",
            "ascii",
            "opendir",
            "powershell",
            "ps1",
            "ua-ps",
            "VIPKeylogger",
            "AgentTesla",
            "PhantomStealer",
            "Encoded",
            "rev-base64-loader",
            "ValleyRAT",
            "AsyncRAT",
            "rat",
            "exe",
            "bash",
            "geofenced",
            "USA",
            "xml"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 251,
            "hostname": 65,
            "domain": 7
          },
          "indicator_count": 323,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "49 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        },
        {
          "id": "69aba9eb044ee6eee8cbb7da",
          "name": "URLHaus data - 06-03-2026 (Part 3)",
          "description": "",
          "modified": "2026-04-06T04:01:24.170000",
          "created": "2026-03-07T04:30:35.497000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "ClearFake",
            "EternalRocks",
            "arm",
            "mirai",
            "dropped-by-amadey",
            "fbf543",
            "geofenced",
            "opendir",
            "sh",
            "ua-wget",
            "USA",
            "xml",
            "c2-monitor-auto",
            "DarkVisionRAT",
            "botnetdomain",
            "censys",
            "py",
            "c",
            "gafgyt",
            "SalatStealer",
            "CoinMiner",
            "connectwise",
            "DDoSAgent",
            "exe",
            "img",
            "njRAT",
            "vbs",
            "Kaiji",
            "xmrig",
            "NirCmd",
            "Vidar",
            "rustystealer",
            "Fuery",
            "ascii",
            "Encoded",
            "rev-base64-loader",
            "Amadey",
            "macOS",
            "skimmer",
            "payload",
            "stealer",
            "AmateraStealer",
            "redtail"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 250,
            "hostname": 57,
            "domain": 6
          },
          "indicator_count": 313,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "54 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "IPv4",
          "related_indicator_is_active": 0
        }
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/",
        "https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt",
        "https://github.com/telekom-security/tpotce"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": [],
    "validation": [],
    "asn": "AS38264 national wimax/ims environment",
    "city_data": true,
    "city": null,
    "region": null,
    "continent_code": "AS",
    "country_code3": "PAK",
    "country_code2": "PK",
    "subdivision": null,
    "latitude": 30.0,
    "postal_code": null,
    "longitude": 70.0,
    "accuracy_radius": 50,
    "country_code": "PK",
    "country_name": "Pakistan",
    "dma_code": 0,
    "charset": 0,
    "area_code": 0,
    "flag_url": "/assets/images/flags/pk.png",
    "flag_title": "Pakistan",
    "sections": [
      "general",
      "geo",
      "reputation",
      "url_list",
      "passive_dns",
      "malware",
      "nids_list",
      "http_scans"
    ]
  },
  "geo": {
    "asn": "AS38264 national wimax/ims environment",
    "city_data": true,
    "city": null,
    "region": null,
    "continent_code": "AS",
    "country_code3": "PAK",
    "country_code2": "PK",
    "subdivision": null,
    "latitude": 30.0,
    "postal_code": null,
    "longitude": 70.0,
    "accuracy_radius": 50,
    "country_code": "PK",
    "country_name": "Pakistan",
    "dma_code": 0,
    "charset": 0,
    "area_code": 0,
    "flag_url": "/assets/images/flags/pk.png",
    "flag_title": "Pakistan"
  },
  "geo_ipapicom": {
    "country": "Pakistan",
    "country_code": "PK",
    "region": "Punjab",
    "city": "Keshupur",
    "zip": "",
    "latitude": 32.26,
    "longitude": 72.5,
    "timezone": "Asia/Karachi",
    "isp": "Wateen Telecom Limited",
    "org": "Wateen Telecom Limited",
    "asn": "AS38264 National WiMAX/IMS environment",
    "asn_name": "WATEEN-IMS-PK-AS-AP",
    "is_proxy": false,
    "is_hosting": false,
    "source": "ip-api.com"
  },
  "pulse_count": 23,
  "pulses": [
    {
      "id": "6a1a3b20659841db54164270",
      "name": "URLHaus data - 29-05-2026 (Part 1)",
      "description": "",
      "modified": "2026-05-30T01:19:28.174000",
      "created": "2026-05-30T01:19:28.174000",
      "tags": [
        "54e64e",
        "dropped-by-amadey",
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "arm",
        "mirai",
        "ClearFake",
        "gafgyt",
        "83-142-209-67",
        "sh",
        "ua-wget",
        "46-151-182-31",
        "connectwise",
        "exe",
        "46-151-182-242",
        "DDoSAgent",
        "supershell",
        "supershell-c2",
        "c2-monitor-auto",
        "9d2ca3",
        "rustystealer",
        "14-128-50-87",
        "dropped-by-Phorpiex",
        "BlackMatter",
        "176-65-139-77",
        "176-65-139-68",
        "62-60-130-237",
        "38-47-108-62",
        "31-56-209-72",
        "GhostPulse",
        "opendir",
        "msi",
        "rmm",
        "screenconnect",
        "ACRStealer",
        "LummaStealer",
        "RemusStealer",
        "wraith",
        "discord",
        "keylogger",
        "MacOS Stealer",
        "206-237-30-225",
        "154-89-148-115",
        "macho",
        "x86",
        "64-bit",
        "x86-64"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 257,
        "IPv4": 102,
        "hostname": 34,
        "domain": 2
      },
      "indicator_count": 395,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "22 hours ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f01341e9a1d5da90605291",
      "name": "Malware Filter - Botnet List - 27-04-2026 (Part 1)",
      "description": "",
      "modified": "2026-05-28T01:00:50.636000",
      "created": "2026-04-28T01:54:09.392000",
      "tags": [],
      "references": [
        "https://malware-filter.gitlab.io/malware-filter/botnet-filter.txt"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {},
      "indicator_count": 0,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1623,
      "modified_text": "2 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 0
    },
    {
      "id": "69eec8d1c4c8f9c722f89acf",
      "name": "URLHaus data - 26-04-2026 (Part 4)",
      "description": "",
      "modified": "2026-05-27T02:18:45.246000",
      "created": "2026-04-27T02:24:17.454000",
      "tags": [
        "ClearFake",
        "AdaptixC2",
        "exe",
        "opendir",
        "elf",
        "ua-wget",
        "32-bit",
        "mips",
        "Mozi",
        "sh",
        "mirai",
        "arm",
        "zip",
        "84-54-33-214",
        "84-54-33-77",
        "connectwise",
        "84-54-33-71",
        "84-54-33-157",
        "194-163-151-12",
        "45-88-186-69",
        "ladvix",
        "botnetdomain",
        "vmi3229260-contaboserver-net",
        "luxzzc2servers-my-id",
        "45-88-186-209",
        "45-92-1-43",
        "45-80-158-96",
        "45-138-16-51",
        "203-159-90-245",
        "45-154-98-122",
        "203-159-90-22",
        "193-26-115-225",
        "45-138-16-223",
        "124-198-131-61",
        "185-241-208-194",
        "x86",
        "m68k",
        "sparc",
        "SuperH",
        "PowerPC",
        "msi",
        "rmm",
        "screenconnect",
        "pw-LUMEN",
        "gitlab",
        "SantaStealer",
        "Vidar",
        "adeladel32951",
        "github",
        "EvelynStealer",
        "script",
        "193-26-115-162",
        "192-159-99-32",
        "192-159-99-209",
        "192-159-99-152-8080",
        "124-198-132-54",
        "124-198-132-14",
        "124-198-132-37",
        "45-156-87-140",
        "gafgyt",
        "124-198-131-54",
        "happytugsbakery-com",
        "204-76-203-195",
        "192-109-200-9",
        "204-76-203-248",
        "192-109-200-12",
        "192-109-200-131",
        "176-65-148-160",
        "176-65-132-197",
        "176-65-132-139",
        "194-26-192-44",
        "176-65-148-212",
        "beautiful-roentgen-176-65-139-130-plesk-page",
        "www-176-65-139-130-plesk-page",
        "91-92-242-236",
        "Amadey",
        "gamecheap-store",
        "156-229-165-225",
        "earnify",
        "maskify",
        "proxy-sdk",
        "176-65-139-141",
        "176-65-139-46",
        "176-65-139-47",
        "rustystealer"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 153,
        "hostname": 60
      },
      "indicator_count": 213,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1621,
      "modified_text": "3 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 0
    },
    {
      "id": "69eec8d01c819eba42f63c29",
      "name": "URLHaus data - 26-04-2026 (Part 3)",
      "description": "",
      "modified": "2026-05-27T02:18:45.246000",
      "created": "2026-04-27T02:24:16.773000",
      "tags": [
        "ClearFake",
        "AdaptixC2",
        "exe",
        "opendir",
        "elf",
        "ua-wget",
        "32-bit",
        "mips",
        "Mozi",
        "sh",
        "mirai",
        "arm",
        "zip",
        "84-54-33-214",
        "84-54-33-77",
        "connectwise",
        "84-54-33-71",
        "84-54-33-157",
        "194-163-151-12",
        "45-88-186-69",
        "ladvix",
        "botnetdomain",
        "vmi3229260-contaboserver-net",
        "luxzzc2servers-my-id",
        "45-88-186-209",
        "45-92-1-43",
        "45-80-158-96",
        "45-138-16-51",
        "203-159-90-245",
        "45-154-98-122",
        "203-159-90-22",
        "193-26-115-225",
        "45-138-16-223",
        "124-198-131-61",
        "185-241-208-194",
        "x86",
        "m68k",
        "sparc",
        "SuperH",
        "PowerPC",
        "msi",
        "rmm",
        "screenconnect",
        "pw-LUMEN",
        "gitlab",
        "SantaStealer",
        "Vidar",
        "adeladel32951",
        "github",
        "EvelynStealer",
        "script",
        "193-26-115-162",
        "192-159-99-32",
        "192-159-99-209",
        "192-159-99-152-8080",
        "124-198-132-54",
        "124-198-132-14",
        "124-198-132-37",
        "45-156-87-140",
        "gafgyt",
        "124-198-131-54",
        "happytugsbakery-com",
        "204-76-203-195",
        "192-109-200-9",
        "204-76-203-248",
        "192-109-200-12",
        "192-109-200-131",
        "176-65-148-160",
        "176-65-132-197",
        "176-65-132-139",
        "194-26-192-44",
        "176-65-148-212",
        "beautiful-roentgen-176-65-139-130-plesk-page",
        "www-176-65-139-130-plesk-page",
        "91-92-242-236",
        "Amadey",
        "gamecheap-store",
        "156-229-165-225",
        "earnify",
        "maskify",
        "proxy-sdk",
        "176-65-139-141",
        "176-65-139-46",
        "176-65-139-47",
        "rustystealer"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 250,
        "hostname": 40,
        "domain": 1
      },
      "indicator_count": 291,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1621,
      "modified_text": "3 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 0
    },
    {
      "id": "69ecae6a156da44db667be66",
      "name": "imvfeoirewIVONVCIDJCJCW",
      "description": "",
      "modified": "2026-05-25T12:11:06.214000",
      "created": "2026-04-25T12:07:06.437000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "MohammedRizwan2001",
        "id": "361933",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 508,
        "FileHash-MD5": 100,
        "FileHash-SHA1": 100,
        "FileHash-SHA256": 187,
        "domain": 17,
        "hostname": 159
      },
      "indicator_count": 1071,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 21,
      "modified_text": "5 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 0
    },
    {
      "id": "69ec18b7ea98d416d8bf38e9",
      "name": "URLHaus data - 24-04-2026 (Part 3)",
      "description": "",
      "modified": "2026-05-25T01:40:06.925000",
      "created": "2026-04-25T01:28:23.961000",
      "tags": [
        "ClearFake",
        "elf",
        "mips",
        "mirai",
        "ua-wget",
        "32-bit",
        "Mozi",
        "m68k",
        "arm",
        "PowerPC",
        "SuperH",
        "x86",
        "SmartLoader",
        "zip",
        "script",
        "opendir",
        "pw-4496",
        "rar",
        "pw-9931",
        "pw-DR67KVLD",
        "Vidar",
        "SantaStealer",
        "exe",
        "sh",
        "beacon",
        "PrivateLoader",
        "RedLine",
        "stealer",
        "ascii",
        "PureHVNC",
        "PureRAT",
        "rat",
        "vbs",
        "gafgyt",
        "PhantomStealer",
        "js",
        "176-65-139-146",
        "176-65-139-131",
        "176-65-139-152",
        "176-65-139-115",
        "176-65-139-47",
        "176-65-139-50",
        "176-65-139-141",
        "45-131-108-107",
        "91-92-243-181",
        "connectwise",
        "178-16-53-72",
        "178-16-54-33",
        "158-94-210-6",
        "178-16-55-93",
        "178-16-55-86",
        "178-16-54-224",
        "91-92-242-236",
        "tinynuke",
        "honeypot",
        "Xorddos"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 226,
        "hostname": 94,
        "domain": 1
      },
      "indicator_count": 321,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "5 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 0
    },
    {
      "id": "69eac9ec2d31146043bc2021",
      "name": "URLHaus data - 23-04-2026 (Part 2)",
      "description": "",
      "modified": "2026-05-24T01:27:05.528000",
      "created": "2026-04-24T01:39:56.794000",
      "tags": [
        "ClearFake",
        "32-bit",
        "arm",
        "elf",
        "Mozi",
        "mips",
        "CoinMiner",
        "ua-wget",
        "sh",
        "mirai",
        "PowerPC",
        "x86",
        "SuperH",
        "135e7b",
        "connectwise",
        "dropped-by-amadey",
        "Amadey",
        "cred64.dll",
        "plugin",
        "cred.dll",
        "gafgyt",
        "158-94-210-65-6275",
        "opendir",
        "plugins-costs-nyc-boulevard-trycloudflare-com",
        "xworm",
        "rat",
        "RemcosRAT",
        "zip",
        "ladvix",
        "c2",
        "dropper",
        "github",
        "malware",
        "spyware",
        "exe",
        "ChromElevator",
        "MassLogger",
        "script"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 250,
        "hostname": 51
      },
      "indicator_count": 301,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1623,
      "modified_text": "6 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 0
    },
    {
      "id": "6a0e5ac9323cbdcd9cff7cbe",
      "name": "URLHaus data - 20-05-2026 (Part 3)",
      "description": "",
      "modified": "2026-05-21T01:07:21.475000",
      "created": "2026-05-21T01:07:21.475000",
      "tags": [
        "ClearFake",
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "arm",
        "mirai",
        "54e64e",
        "dropped-by-amadey",
        "sh",
        "ua-wget",
        "xml",
        "104-236-37-21",
        "hajime",
        "backdoor",
        "sshdkit",
        "exe",
        "opendir",
        "meterpreter",
        "ocx",
        "WsgiDAV",
        "DDoSAgent",
        "botnetdomain",
        "gafgyt",
        "ua-mshta",
        "VantaRAT",
        "jar",
        "WeedHack",
        "SilentNet",
        "104-131-37-178",
        "ascii",
        "powershell",
        "ps1",
        "rustystealer",
        "194-58-47-204",
        "31-42-176-91",
        "connectwise",
        "PureHVNC",
        "PureRAT",
        "rat",
        "vbs",
        "c2-monitor-auto",
        "script",
        "ClickFix",
        "ua-powershell",
        "finger",
        "9d2ca3",
        "android"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 111,
        "URL": 251,
        "hostname": 15,
        "domain": 30
      },
      "indicator_count": 407,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "9 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 1
    },
    {
      "id": "69e42fe3e325b1e6e95567b3",
      "name": "URLHaus data - 18-04-2026 (Part 2)",
      "description": "",
      "modified": "2026-05-19T01:05:19.771000",
      "created": "2026-04-19T01:29:07.307000",
      "tags": [
        "ClearFake",
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "64-bit",
        "x86-64",
        "arm",
        "mirai",
        "hajime",
        "opendir",
        "ua-wget",
        "sh",
        "gafgyt",
        "NetSupport",
        "ascii",
        "powershell",
        "ps1",
        "ua-ps",
        "PureHVNC",
        "PureRAT",
        "rat",
        "zip",
        "x86-32",
        "nc",
        "85-11-167-21",
        "x86",
        "SuperH",
        "sparc",
        "PowerPC",
        "arc",
        "m68k"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 252,
        "hostname": 51,
        "domain": 4
      },
      "indicator_count": 307,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1621,
      "modified_text": "11 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 0
    },
    {
      "id": "6a0a6bd8197cd2d0d353fa5d",
      "name": "URLHaus data - 17-05-2026 (Part 2)",
      "description": "",
      "modified": "2026-05-18T01:31:04.127000",
      "created": "2026-05-18T01:31:04.127000",
      "tags": [
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "ClearFake",
        "arm",
        "mirai",
        "ua-wget",
        "sh",
        "unknown",
        "opendir",
        "gafgyt",
        "hajime",
        "github",
        "c2-monitor-auto",
        "dropped-by-amadey",
        "DDoSAgent",
        "CoinMiner",
        "redtail",
        "x86",
        "exe",
        "stealer",
        "pw-GGWP",
        "54e64e",
        "armv7l",
        "ddos",
        "nova",
        "armv4l",
        "PowerPC",
        "armv5",
        "armv5l",
        "armv6",
        "armv6l",
        "x86_64",
        "i686",
        "mipsel",
        "Boatnet",
        "apk",
        "mamont",
        "i586",
        "sh4",
        "botnet",
        "load",
        "x64",
        "SalatStealer",
        "trojan",
        "dropper",
        "macOS",
        "shell"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 258,
        "IPv4": 77,
        "domain": 25,
        "hostname": 6
      },
      "indicator_count": 366,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "12 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "IPv4",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "110.36.2.23",
    "type": "IPv4"
  },
  "abuseipdb": {
    "indicator": "110.36.2.23",
    "abuse_score": 90,
    "verdict": "malicious",
    "total_reports": 90,
    "distinct_users": 36,
    "last_reported": "2026-05-30T18:30:32+00:00",
    "country_code": "PK",
    "country_name": "Pakistan",
    "isp": "National Wimax/IMS environment",
    "domain": "wateen.com",
    "is_tor": false,
    "is_public": true,
    "is_whitelisted": false,
    "usage_type": "Fixed Line ISP",
    "recent_reports": [
      {
        "date": "2026-05-30",
        "categories": [
          "Port Scan"
        ],
        "comment": "2026-05-30 17:48:24 UTC Unauthorized activity to TCP port 23. Telnet",
        "reporter": "US"
      },
      {
        "date": "2026-05-28",
        "categories": [
          "Hacking",
          "IoT Targeted"
        ],
        "comment": "Honeypot detection: Mozi IoT botnet payload delivery / infection attempt on port 8080. Severity: CRITICAL. Aaran.cloud",
        "reporter": "GB"
      },
      {
        "date": "2026-05-28",
        "categories": [
          "IoT Targeted",
          "Brute-Force"
        ],
        "comment": "Honeypot detection: Telnet / IoT device brute-force or exploitation attempt on port 23. Severity: MEDIUM. Aaran.cloud",
        "reporter": "GB"
      },
      {
        "date": "2026-05-28",
        "categories": [
          "Port Scan",
          "Hacking"
        ],
        "comment": "Port Scan on Honeypot | Ports: 8080/HTTP-proxy(2x) | Proto: TCP(2) | Flags: all SYN | TTL: 50 | Len: 60B(2x) | Win: 1440",
        "reporter": "DE"
      },
      {
        "date": "2026-05-26",
        "categories": [
          "Port Scan"
        ],
        "comment": "Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)",
        "reporter": "AT"
      }
    ],
    "error": null
  },
  "urlhaus": {
    "indicator": "110.36.2.23",
    "found": true,
    "verdict": "malicious",
    "url_count": 25,
    "online_count": 0,
    "blacklists": {
      "spamhaus_dbl": "not listed",
      "surbl": "not listed"
    },
    "urls": [
      {
        "url": "http://110.36.2.23:55973/i",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-29",
        "tags": [
          "32-bit",
          "elf",
          "mips",
          "Mozi"
        ]
      },
      {
        "url": "http://110.36.2.23:55973/bin.sh",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-29",
        "tags": [
          "32-bit",
          "elf",
          "mips",
          "Mozi"
        ]
      },
      {
        "url": "http://110.36.2.23:41597/i",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-20",
        "tags": [
          "32-bit",
          "elf",
          "mips",
          "Mozi"
        ]
      },
      {
        "url": "http://110.36.2.23:41597/bin.sh",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-20",
        "tags": [
          "32-bit",
          "elf",
          "mips",
          "Mozi"
        ]
      },
      {
        "url": "http://110.36.2.23:41430/bin.sh",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-17",
        "tags": [
          "32-bit",
          "elf",
          "mips",
          "Mozi"
        ]
      },
      {
        "url": "http://110.36.2.23:41430/i",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-17",
        "tags": [
          "32-bit",
          "elf",
          "mips",
          "Mozi"
        ]
      },
      {
        "url": "http://110.36.2.23:45976/i",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-16",
        "tags": []
      },
      {
        "url": "http://110.36.2.23:43265/i",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-11",
        "tags": [
          "32-bit",
          "elf",
          "mips",
          "Mozi"
        ]
      },
      {
        "url": "http://110.36.2.23:43265/bin.sh",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-11",
        "tags": [
          "32-bit",
          "elf",
          "mips",
          "Mozi"
        ]
      },
      {
        "url": "http://110.36.2.23:56368/i",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-05-07",
        "tags": []
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780186175.2634075
}