{
  "type": "Domain",
  "indicator": "a.ws",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/a.ws",
    "alexa": "http://www.alexa.com/siteinfo/a.ws",
    "indicator": "a.ws",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2922295878,
      "indicator": "a.ws",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 8,
      "pulses": [
        {
          "id": "67709b347e368914cb5d1fa2",
          "name": "ld869rwRuHeO9Tw.exe   1d773d866966940f042d442b9e0cec638e733a83f7137cbdd4e70d4cb9803ada",
          "description": "https://www.hybrid-analysis.com/sample/1d773d866966940f042d442b9e0cec638e733a83f7137cbdd4e70d4cb9803ada/677086f7a2798798250fafcd\nLastcode analysis wedi cyhoeddi i'wadu cyffredinol, \u00c2\u00a31.5m, \u00e2\u201a\u00ac2.4m.",
          "modified": "2025-05-14T21:11:16.436000",
          "created": "2024-12-29T00:43:32.094000",
          "tags": [
            "sha256 file",
            "type type",
            "language chi2",
            "image english",
            "us 1",
            "1 upx1",
            "monitoruj",
            "rozszerzenia",
            "kali linux",
            "live boot",
            "apple m1",
            "kolekcja dvd",
            "sound pool",
            "hashdb narodowa",
            "oprogramowania",
            "nsrl",
            "programfiles",
            "kopiuj md5",
            "kopiuj sha1",
            "skopiuj sha256",
            "sha1",
            "sha256",
            "runtime process",
            "description zip",
            "type",
            "size",
            "error",
            "null",
            "install",
            "bitcoin",
            "python",
            "calendar",
            "xorist",
            "path",
            "refresh",
            "body",
            "span",
            "green",
            "win32",
            "designer",
            "filler",
            "tools",
            "black",
            "wallpaper",
            "zapis",
            "pulpit",
            "autoit",
            "bill",
            "light",
            "stars",
            "look",
            "verify",
            "restart",
            "desktop"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 491,
            "FileHash-MD5": 452,
            "FileHash-SHA1": 458,
            "BitcoinAddress": 1,
            "URL": 39,
            "domain": 66,
            "hostname": 18
          },
          "indicator_count": 1525,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 124,
          "modified_text": "383 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708eedef45abdffcb1a9ae",
          "name": "tracking more than space junk",
          "description": "",
          "modified": "2023-12-06T15:10:37.631000",
          "created": "2023-12-06T15:10:37.631000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 371,
            "domain": 139,
            "URL": 1034,
            "FileHash-SHA256": 113,
            "FileHash-MD5": 1
          },
          "indicator_count": 1658,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708bf87a08635a650eeb9b",
          "name": "ctgserver.net",
          "description": "",
          "modified": "2023-12-06T14:58:00.096000",
          "created": "2023-12-06T14:58:00.096000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1286,
            "domain": 560,
            "hostname": 1602,
            "URL": 7975,
            "FileHash-MD5": 85,
            "FileHash-SHA1": 1
          },
          "indicator_count": 11509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708befc4f4c7e2be4370d9",
          "name": "ctgserver.net",
          "description": "",
          "modified": "2023-12-06T14:57:51.922000",
          "created": "2023-12-06T14:57:51.922000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1286,
            "domain": 560,
            "hostname": 1602,
            "URL": 7975,
            "FileHash-MD5": 85,
            "FileHash-SHA1": 1
          },
          "indicator_count": 11509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "628e4ddc014aff9f1d08aa71",
          "name": "tracking more than space junk",
          "description": "var Cc,Dc andEc, all of whom have the same name, can now be identified by their own code, if they want to use it, as a symbol or symbol.",
          "modified": "2022-05-25T15:40:12.368000",
          "created": "2022-05-25T15:40:12.368000",
          "tags": [
            "padre medium",
            "your angel",
            "discover",
            "angel",
            "get your",
            "c0c0ff",
            "gray",
            "e0e0e0",
            "f0f0f0",
            "verdana",
            "cccccc",
            "white",
            "ffffcc",
            "cc55ff",
            "ffffc0",
            "date",
            "error",
            "function",
            "typeof t",
            "array",
            "regexp",
            "twitter",
            "copyright",
            "msie",
            "1011",
            "false",
            "experiment",
            "blank",
            "this",
            "dispatcher",
            "button",
            "string",
            "twitter follow",
            "twitter tweet",
            "dnull",
            "msies",
            "number",
            "twopi",
            "typeof b",
            "pseudo",
            "child",
            "sufeffxa0",
            "class",
            "attr",
            "null",
            "void",
            "typeerror",
            "symbol",
            "array int8array",
            "argument",
            "rafunction",
            "iframe",
            "edge",
            "sxa0",
            "qafunction",
            "trident",
            "android"
          ],
          "references": [
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
            "https://apis.google.com/js/plusone.js",
            "https://code.jquery.com/jquery-1.12.0.min.js",
            "https://www.heavens-above.com/scripts/standard.min.js",
            "https://impl.onscroll.com/vet-takeover/2017/02/1487848477922.js",
            "https://impl.onscroll.com/engaged-refresh/2016/12/1481103489249.js",
            "https://platform.twitter.com/js/button.e878ad6ba18f0bdda53d6861059b0edd.js",
            "https://platform.twitter.com/widgets.js",
            "https://tags.onscroll.com/608ff96c-526d-43c0-92d3-5faa546bc80e/tag.min.js",
            "https://www.heavens-above.com/css/ha.css",
            "https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-5668297076217155&output=html&h=90&twa=1&slotname=5479771053&adk=1840069807&adf=1414646361&pi=t.ma~as.5479771053&w=396&fwrn=4&fwrnh=100&lmt=1653492727&format=396x90&url=https%3A%2F%2Fwww.heavens-above.com%2F&fwr=0&rh=90&rw=396&wgl=1&dt=1653492727387&bpp=10&bdt=19&idt=116&shv=r20220523&mjsv=m202205230101&ptt=5&saldr=sa&abxe=1&cookie=ID%3D3d7fd49730f9716e-226e20b4a7d200c9%3AT%3D1653492408%3ART%3D1653492408%3AS%3DALNI_MY5x7-J93w8BBEbj3tqtpARwaFfjA&gpi",
            "https://www.google.com/recaptcha/api2/aframe"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1034,
            "hostname": 371,
            "FileHash-SHA256": 113,
            "domain": 139,
            "FileHash-MD5": 1
          },
          "indicator_count": 1658,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "1468 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625eff927c93e3e5cd50e191",
          "name": "ctgserver.net",
          "description": "var d=b.dir,e=c&&\"parentNode\"===d,f=x, f=w, b.b, and d(b) for the first time.",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T18:29:38.810000",
          "tags": [
            "0x1d3c",
            "function",
            "json",
            "date",
            "0x3abb84",
            "0x400e43",
            "0x4e2be0",
            "0x27ecdf",
            "this",
            "0x217f25",
            "webview",
            "array",
            "typeof e",
            "regexp",
            "null",
            "object",
            "string",
            "post",
            "typeof r",
            "error",
            "android",
            "void",
            "math",
            "k3wc3w",
            "o4wo4w",
            "b0z1",
            "a4r1",
            "b2bbbb",
            "o5r1",
            "image",
            "typeof s",
            "typeof console",
            "contenttype",
            "number",
            "60number",
            "new date",
            "close",
            "sector",
            "typeof symbol",
            "crispclient",
            "crisp im",
            "typeof b",
            "width",
            "pseudo",
            "child",
            "sufeffxa0",
            "class",
            "accept"
          ],
          "references": [
            "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
            "https://client.crisp.chat/l.js",
            "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
            "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
            "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
            "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
            "http://push.zhanzhang.baidu.com/push.js",
            "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
            "http://static.geetest.com/static/js/geetest.6.0.9.js",
            "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
            "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
            "https://sofire.bdstatic.com/js/dfxaf.js",
            "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
            "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
            "xfe-URL-Zhuzi.me-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7975,
            "FileHash-SHA256": 1286,
            "hostname": 1602,
            "domain": 560,
            "FileHash-MD5": 85,
            "FileHash-SHA1": 1
          },
          "indicator_count": 11509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1475 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625effa1c4edcef37385c4eb",
          "name": "ctgserver.net",
          "description": "var d=b.dir,e=c&&\"parentNode\"===d,f=x, f=w, b.b, and d(b) for the first time.",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T18:29:53.960000",
          "tags": [
            "0x1d3c",
            "function",
            "json",
            "date",
            "0x3abb84",
            "0x400e43",
            "0x4e2be0",
            "0x27ecdf",
            "this",
            "0x217f25",
            "webview",
            "array",
            "typeof e",
            "regexp",
            "null",
            "object",
            "string",
            "post",
            "typeof r",
            "error",
            "android",
            "void",
            "math",
            "k3wc3w",
            "o4wo4w",
            "b0z1",
            "a4r1",
            "b2bbbb",
            "o5r1",
            "image",
            "typeof s",
            "typeof console",
            "contenttype",
            "number",
            "60number",
            "new date",
            "close",
            "sector",
            "typeof symbol",
            "crispclient",
            "crisp im",
            "typeof b",
            "width",
            "pseudo",
            "child",
            "sufeffxa0",
            "class",
            "accept"
          ],
          "references": [
            "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
            "https://client.crisp.chat/l.js",
            "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
            "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
            "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
            "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
            "http://push.zhanzhang.baidu.com/push.js",
            "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
            "http://static.geetest.com/static/js/geetest.6.0.9.js",
            "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
            "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
            "https://sofire.bdstatic.com/js/dfxaf.js",
            "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
            "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
            "xfe-URL-Zhuzi.me-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7975,
            "FileHash-SHA256": 1286,
            "hostname": 1602,
            "domain": 560,
            "FileHash-MD5": 85,
            "FileHash-SHA1": 1
          },
          "indicator_count": 11509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1475 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f05c71e903844d907b1ae",
          "name": "Russian Malware Strain",
          "description": "The full text of the new Dictionary of Human Rights, compiled by the Office of National Statistics (ONS), has been published on the internet, with the help of a few words: \"Glasgow\".",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T18:56:07.131000",
          "tags": [
            "bapunycode",
            "s700",
            "array",
            "topmailru",
            "error",
            "tmrtmr",
            "rbclickid",
            "tmrdebug1",
            "tadaeaxbyb",
            "bbdaea",
            "cbdaea",
            "uadaea",
            "ver1",
            "typemini",
            "verb0",
            "youtube",
            "content",
            "smartbanner",
            "null",
            "text",
            "smart banner",
            "copyright",
            "android",
            "windows store",
            "title",
            "price",
            "click",
            "date",
            "twitter",
            "string",
            "regexp",
            "number",
            "typeerror",
            "symbol",
            "array int8array",
            "argument",
            "rafunction",
            "iframe",
            "please",
            "image",
            "v[1]-1:k+=",
            "dpjquery",
            "document",
            "function",
            "this",
            "left",
            "bottom",
            "html",
            "nulle",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "attr",
            "class",
            "invalid json",
            "domparser",
            "edge",
            "sxa0",
            "qafunction",
            "trident",
            "ondomready",
            "make sure",
            "gc",
            "65535",
            "boolean",
            "counter",
            "segoe ui",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "form",
            "impact",
            "light",
            "bad idp",
            "cvtx",
            "bad event",
            "typeof b",
            "closure library",
            "f1518500249",
            "f1859775393",
            "body"
          ],
          "references": [
            "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
            "xfe-URL-Xelent.ru-stix2-2.1-export.json",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
            "http://mc.yandex.ru/metrika/watch.js",
            "http://metrika.installtraffic.com/js/watch.js",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
            "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
            "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
            "http://loviotvet.ru/lib/project/common.js",
            "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
            "https://apis.google.com/js/plusone.js",
            "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
            "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
            "https://top-fwz1.mail.ru/js/code.js",
            "https://bitrix.info/ba.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "V[1]-1:k+=",
              "display_name": "V[1]-1:k+=",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1987,
            "hostname": 733,
            "FileHash-SHA256": 294,
            "domain": 354
          },
          "indicator_count": 3368,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1475 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://top-fwz1.mail.ru/js/code.js",
        "https://apis.google.com/js/plusone.js",
        "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
        "xfe-URL-Zhuzi.me-stix2-2.1-export.json",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
        "http://metrika.installtraffic.com/js/watch.js",
        "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
        "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
        "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
        "https://tags.onscroll.com/608ff96c-526d-43c0-92d3-5faa546bc80e/tag.min.js",
        "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
        "https://bitrix.info/ba.js",
        "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
        "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
        "http://push.zhanzhang.baidu.com/push.js",
        "https://sofire.bdstatic.com/js/dfxaf.js",
        "http://mc.yandex.ru/metrika/watch.js",
        "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
        "https://www.google.com/recaptcha/api2/aframe",
        "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
        "https://impl.onscroll.com/engaged-refresh/2016/12/1481103489249.js",
        "xfe-URL-Xelent.ru-stix2-2.1-export.json",
        "https://platform.twitter.com/js/button.e878ad6ba18f0bdda53d6861059b0edd.js",
        "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
        "https://impl.onscroll.com/vet-takeover/2017/02/1487848477922.js",
        "https://client.crisp.chat/l.js",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
        "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
        "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
        "https://www.heavens-above.com/scripts/standard.min.js",
        "https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-5668297076217155&output=html&h=90&twa=1&slotname=5479771053&adk=1840069807&adf=1414646361&pi=t.ma~as.5479771053&w=396&fwrn=4&fwrnh=100&lmt=1653492727&format=396x90&url=https%3A%2F%2Fwww.heavens-above.com%2F&fwr=0&rh=90&rw=396&wgl=1&dt=1653492727387&bpp=10&bdt=19&idt=116&shv=r20220523&mjsv=m202205230101&ptt=5&saldr=sa&abxe=1&cookie=ID%3D3d7fd49730f9716e-226e20b4a7d200c9%3AT%3D1653492408%3ART%3D1653492408%3AS%3DALNI_MY5x7-J93w8BBEbj3tqtpARwaFfjA&gpi",
        "http://loviotvet.ru/lib/project/common.js",
        "https://www.heavens-above.com/css/ha.css",
        "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
        "http://static.geetest.com/static/js/geetest.6.0.9.js",
        "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
        "https://platform.twitter.com/widgets.js",
        "https://code.jquery.com/jquery-1.12.0.min.js"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Gc",
            "V[1]-1:k+="
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 8,
  "pulses": [
    {
      "id": "67709b347e368914cb5d1fa2",
      "name": "ld869rwRuHeO9Tw.exe   1d773d866966940f042d442b9e0cec638e733a83f7137cbdd4e70d4cb9803ada",
      "description": "https://www.hybrid-analysis.com/sample/1d773d866966940f042d442b9e0cec638e733a83f7137cbdd4e70d4cb9803ada/677086f7a2798798250fafcd\nLastcode analysis wedi cyhoeddi i'wadu cyffredinol, \u00c2\u00a31.5m, \u00e2\u201a\u00ac2.4m.",
      "modified": "2025-05-14T21:11:16.436000",
      "created": "2024-12-29T00:43:32.094000",
      "tags": [
        "sha256 file",
        "type type",
        "language chi2",
        "image english",
        "us 1",
        "1 upx1",
        "monitoruj",
        "rozszerzenia",
        "kali linux",
        "live boot",
        "apple m1",
        "kolekcja dvd",
        "sound pool",
        "hashdb narodowa",
        "oprogramowania",
        "nsrl",
        "programfiles",
        "kopiuj md5",
        "kopiuj sha1",
        "skopiuj sha256",
        "sha1",
        "sha256",
        "runtime process",
        "description zip",
        "type",
        "size",
        "error",
        "null",
        "install",
        "bitcoin",
        "python",
        "calendar",
        "xorist",
        "path",
        "refresh",
        "body",
        "span",
        "green",
        "win32",
        "designer",
        "filler",
        "tools",
        "black",
        "wallpaper",
        "zapis",
        "pulpit",
        "autoit",
        "bill",
        "light",
        "stars",
        "look",
        "verify",
        "restart",
        "desktop"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 491,
        "FileHash-MD5": 452,
        "FileHash-SHA1": 458,
        "BitcoinAddress": 1,
        "URL": 39,
        "domain": 66,
        "hostname": 18
      },
      "indicator_count": 1525,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 124,
      "modified_text": "383 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708eedef45abdffcb1a9ae",
      "name": "tracking more than space junk",
      "description": "",
      "modified": "2023-12-06T15:10:37.631000",
      "created": "2023-12-06T15:10:37.631000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 371,
        "domain": 139,
        "URL": 1034,
        "FileHash-SHA256": 113,
        "FileHash-MD5": 1
      },
      "indicator_count": 1658,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708bf87a08635a650eeb9b",
      "name": "ctgserver.net",
      "description": "",
      "modified": "2023-12-06T14:58:00.096000",
      "created": "2023-12-06T14:58:00.096000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1286,
        "domain": 560,
        "hostname": 1602,
        "URL": 7975,
        "FileHash-MD5": 85,
        "FileHash-SHA1": 1
      },
      "indicator_count": 11509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708befc4f4c7e2be4370d9",
      "name": "ctgserver.net",
      "description": "",
      "modified": "2023-12-06T14:57:51.922000",
      "created": "2023-12-06T14:57:51.922000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1286,
        "domain": 560,
        "hostname": 1602,
        "URL": 7975,
        "FileHash-MD5": 85,
        "FileHash-SHA1": 1
      },
      "indicator_count": 11509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "628e4ddc014aff9f1d08aa71",
      "name": "tracking more than space junk",
      "description": "var Cc,Dc andEc, all of whom have the same name, can now be identified by their own code, if they want to use it, as a symbol or symbol.",
      "modified": "2022-05-25T15:40:12.368000",
      "created": "2022-05-25T15:40:12.368000",
      "tags": [
        "padre medium",
        "your angel",
        "discover",
        "angel",
        "get your",
        "c0c0ff",
        "gray",
        "e0e0e0",
        "f0f0f0",
        "verdana",
        "cccccc",
        "white",
        "ffffcc",
        "cc55ff",
        "ffffc0",
        "date",
        "error",
        "function",
        "typeof t",
        "array",
        "regexp",
        "twitter",
        "copyright",
        "msie",
        "1011",
        "false",
        "experiment",
        "blank",
        "this",
        "dispatcher",
        "button",
        "string",
        "twitter follow",
        "twitter tweet",
        "dnull",
        "msies",
        "number",
        "twopi",
        "typeof b",
        "pseudo",
        "child",
        "sufeffxa0",
        "class",
        "attr",
        "null",
        "void",
        "typeerror",
        "symbol",
        "array int8array",
        "argument",
        "rafunction",
        "iframe",
        "edge",
        "sxa0",
        "qafunction",
        "trident",
        "android"
      ],
      "references": [
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
        "https://apis.google.com/js/plusone.js",
        "https://code.jquery.com/jquery-1.12.0.min.js",
        "https://www.heavens-above.com/scripts/standard.min.js",
        "https://impl.onscroll.com/vet-takeover/2017/02/1487848477922.js",
        "https://impl.onscroll.com/engaged-refresh/2016/12/1481103489249.js",
        "https://platform.twitter.com/js/button.e878ad6ba18f0bdda53d6861059b0edd.js",
        "https://platform.twitter.com/widgets.js",
        "https://tags.onscroll.com/608ff96c-526d-43c0-92d3-5faa546bc80e/tag.min.js",
        "https://www.heavens-above.com/css/ha.css",
        "https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-5668297076217155&output=html&h=90&twa=1&slotname=5479771053&adk=1840069807&adf=1414646361&pi=t.ma~as.5479771053&w=396&fwrn=4&fwrnh=100&lmt=1653492727&format=396x90&url=https%3A%2F%2Fwww.heavens-above.com%2F&fwr=0&rh=90&rw=396&wgl=1&dt=1653492727387&bpp=10&bdt=19&idt=116&shv=r20220523&mjsv=m202205230101&ptt=5&saldr=sa&abxe=1&cookie=ID%3D3d7fd49730f9716e-226e20b4a7d200c9%3AT%3D1653492408%3ART%3D1653492408%3AS%3DALNI_MY5x7-J93w8BBEbj3tqtpARwaFfjA&gpi",
        "https://www.google.com/recaptcha/api2/aframe"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1034,
        "hostname": 371,
        "FileHash-SHA256": 113,
        "domain": 139,
        "FileHash-MD5": 1
      },
      "indicator_count": 1658,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "1468 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "625eff927c93e3e5cd50e191",
      "name": "ctgserver.net",
      "description": "var d=b.dir,e=c&&\"parentNode\"===d,f=x, f=w, b.b, and d(b) for the first time.",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T18:29:38.810000",
      "tags": [
        "0x1d3c",
        "function",
        "json",
        "date",
        "0x3abb84",
        "0x400e43",
        "0x4e2be0",
        "0x27ecdf",
        "this",
        "0x217f25",
        "webview",
        "array",
        "typeof e",
        "regexp",
        "null",
        "object",
        "string",
        "post",
        "typeof r",
        "error",
        "android",
        "void",
        "math",
        "k3wc3w",
        "o4wo4w",
        "b0z1",
        "a4r1",
        "b2bbbb",
        "o5r1",
        "image",
        "typeof s",
        "typeof console",
        "contenttype",
        "number",
        "60number",
        "new date",
        "close",
        "sector",
        "typeof symbol",
        "crispclient",
        "crisp im",
        "typeof b",
        "width",
        "pseudo",
        "child",
        "sufeffxa0",
        "class",
        "accept"
      ],
      "references": [
        "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
        "https://client.crisp.chat/l.js",
        "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
        "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
        "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
        "http://push.zhanzhang.baidu.com/push.js",
        "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
        "http://static.geetest.com/static/js/geetest.6.0.9.js",
        "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
        "https://sofire.bdstatic.com/js/dfxaf.js",
        "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
        "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
        "xfe-URL-Zhuzi.me-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 7975,
        "FileHash-SHA256": 1286,
        "hostname": 1602,
        "domain": 560,
        "FileHash-MD5": 85,
        "FileHash-SHA1": 1
      },
      "indicator_count": 11509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1475 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "625effa1c4edcef37385c4eb",
      "name": "ctgserver.net",
      "description": "var d=b.dir,e=c&&\"parentNode\"===d,f=x, f=w, b.b, and d(b) for the first time.",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T18:29:53.960000",
      "tags": [
        "0x1d3c",
        "function",
        "json",
        "date",
        "0x3abb84",
        "0x400e43",
        "0x4e2be0",
        "0x27ecdf",
        "this",
        "0x217f25",
        "webview",
        "array",
        "typeof e",
        "regexp",
        "null",
        "object",
        "string",
        "post",
        "typeof r",
        "error",
        "android",
        "void",
        "math",
        "k3wc3w",
        "o4wo4w",
        "b0z1",
        "a4r1",
        "b2bbbb",
        "o5r1",
        "image",
        "typeof s",
        "typeof console",
        "contenttype",
        "number",
        "60number",
        "new date",
        "close",
        "sector",
        "typeof symbol",
        "crispclient",
        "crisp im",
        "typeof b",
        "width",
        "pseudo",
        "child",
        "sufeffxa0",
        "class",
        "accept"
      ],
      "references": [
        "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
        "https://client.crisp.chat/l.js",
        "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
        "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
        "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
        "http://push.zhanzhang.baidu.com/push.js",
        "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
        "http://static.geetest.com/static/js/geetest.6.0.9.js",
        "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
        "https://sofire.bdstatic.com/js/dfxaf.js",
        "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
        "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
        "xfe-URL-Zhuzi.me-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 7975,
        "FileHash-SHA256": 1286,
        "hostname": 1602,
        "domain": 560,
        "FileHash-MD5": 85,
        "FileHash-SHA1": 1
      },
      "indicator_count": 11509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1475 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "625f05c71e903844d907b1ae",
      "name": "Russian Malware Strain",
      "description": "The full text of the new Dictionary of Human Rights, compiled by the Office of National Statistics (ONS), has been published on the internet, with the help of a few words: \"Glasgow\".",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T18:56:07.131000",
      "tags": [
        "bapunycode",
        "s700",
        "array",
        "topmailru",
        "error",
        "tmrtmr",
        "rbclickid",
        "tmrdebug1",
        "tadaeaxbyb",
        "bbdaea",
        "cbdaea",
        "uadaea",
        "ver1",
        "typemini",
        "verb0",
        "youtube",
        "content",
        "smartbanner",
        "null",
        "text",
        "smart banner",
        "copyright",
        "android",
        "windows store",
        "title",
        "price",
        "click",
        "date",
        "twitter",
        "string",
        "regexp",
        "number",
        "typeerror",
        "symbol",
        "array int8array",
        "argument",
        "rafunction",
        "iframe",
        "please",
        "image",
        "v[1]-1:k+=",
        "dpjquery",
        "document",
        "function",
        "this",
        "left",
        "bottom",
        "html",
        "nulle",
        "next",
        "february",
        "april",
        "june",
        "august",
        "atom",
        "cookie",
        "back",
        "bounce",
        "attr",
        "class",
        "invalid json",
        "domparser",
        "edge",
        "sxa0",
        "qafunction",
        "trident",
        "ondomready",
        "make sure",
        "gc",
        "65535",
        "boolean",
        "counter",
        "segoe ui",
        "lucida",
        "ecommerce",
        "ext link",
        "comic",
        "form",
        "impact",
        "light",
        "bad idp",
        "cvtx",
        "bad event",
        "typeof b",
        "closure library",
        "f1518500249",
        "f1859775393",
        "body"
      ],
      "references": [
        "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
        "xfe-URL-Xelent.ru-stix2-2.1-export.json",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
        "http://mc.yandex.ru/metrika/watch.js",
        "http://metrika.installtraffic.com/js/watch.js",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
        "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
        "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
        "http://loviotvet.ru/lib/project/common.js",
        "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
        "https://apis.google.com/js/plusone.js",
        "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
        "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
        "https://top-fwz1.mail.ru/js/code.js",
        "https://bitrix.info/ba.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "V[1]-1:k+=",
          "display_name": "V[1]-1:k+=",
          "target": null
        },
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1987,
        "hostname": 733,
        "FileHash-SHA256": 294,
        "domain": 354
      },
      "indicator_count": 3368,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1475 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "a.ws",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "a.ws",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780399415.7643087
}