{
  "type": "Domain",
  "indicator": "adpages.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/adpages.com",
    "alexa": "http://www.alexa.com/siteinfo/adpages.com",
    "indicator": "adpages.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4032084152,
      "indicator": "adpages.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "6894f62d1121db26437a3eee",
          "name": "\u201cCAPTCHAgeddon\u201d Unmasking the Viral Evolution of the ClickFix Browser-Based Threat",
          "description": "What began as a niche red-team trick posing as a harmless captcha challenge rapidly mutated into one of today\u2019s most dominant attack methods. Like a real-world virus variant, this new \u201cClickFix\u201d strain quickly outpaced and ultimately wiped out the infamous fake browser update scam that plagued the web just last year. It did so by removing the need for file downloads, using smarter social engineering tactics, and spreading through trusted infrastructure. The result - a wave of infections ranging from mass drive-by attacks to hyper-targeted spear-phishing lures.",
          "modified": "2025-09-06T18:03:44.493000",
          "created": "2025-08-07T18:53:33.547000",
          "tags": [
            "clickfix",
            "google",
            "powershell",
            "clearfake",
            "dbscan",
            "guardio",
            "wordpress",
            "uuids",
            "narrative",
            "evasion",
            "cluster",
            "lumma stealer",
            "stealth",
            "june",
            "chaos",
            "clarity",
            "noise",
            "entropy",
            "shell"
          ],
          "references": [
            "https://guard.io/labs/captchageddon-unmasking-the-viral-evolution-of-the-clickfix-browser-based-threat",
            "https://thehackernews.com/2025/08/clickfix-malware-campaign-exploits.html"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClickFix",
              "display_name": "ClickFix",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AustinBH",
            "id": "147442",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 5,
            "domain": 272,
            "hostname": 39
          },
          "indicator_count": 316,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "268 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "689483159128c89f669e87d6",
          "name": "EbeeAugust2025 Pt1",
          "description": "",
          "modified": "2025-09-06T10:00:39.896000",
          "created": "2025-08-07T10:42:29.730000",
          "tags": [],
          "references": [
            "Aug1.pdf"
          ],
          "public": 1,
          "adversary": "Multiple",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 75,
            "CVE": 1,
            "FileHash-MD5": 111,
            "FileHash-SHA1": 139,
            "FileHash-SHA256": 243,
            "domain": 137,
            "hostname": 43,
            "email": 1
          },
          "indicator_count": 750,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 40,
          "modified_text": "268 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67a1f245f3709030a9f0ccb7",
          "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
          "description": "A report by Insikt Group, based on an analysis of compromised WordPress sites, outlines the threat posed by a network of cybercriminal servers known as TAG-124, which is used to distribute malware.",
          "modified": "2025-03-06T10:04:51.026000",
          "created": "2025-02-04T10:56:05.010000",
          "tags": [
            "tag124",
            "cloudflare",
            "wordpress",
            "insikt group",
            "figure",
            "google chrome",
            "future",
            "urls",
            "ta582",
            "fake google",
            "rhysida",
            "powershell",
            "april",
            "insikt",
            "remcos",
            "interlock"
          ],
          "references": [
            "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
          ],
          "public": 1,
          "adversary": "Insikt",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Insikt",
              "display_name": "Insikt",
              "target": null
            },
            {
              "id": "Rhysida",
              "display_name": "Rhysida",
              "target": null
            },
            {
              "id": "REMCOS",
              "display_name": "REMCOS",
              "target": null
            },
            {
              "id": "Interlock",
              "display_name": "Interlock",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 30,
            "FileHash-SHA1": 30,
            "FileHash-SHA256": 30,
            "URL": 2,
            "domain": 254,
            "hostname": 112
          },
          "indicator_count": 458,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "452 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "679ba047fa5e47a0f6e2c071",
          "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
          "description": "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base\n\nInsikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked by Recorded Future as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, 404TDS, KongTuke, and Chaya_002. TAG-124 comprises a network of compromised WordPress sites, actor-controlled payload servers, a central server, a suspected management server, an additional panel, and other components. The threat actors behind TAG-124 demonstrate high levels of activity, including regularly updating URLs embedded in the compromised WordPress sites, adding servers, refining TDS logic to evade detection, and adapting infection tactics, as demonstrated by their recent implementation of the ClickFix technique.",
          "modified": "2025-03-01T15:01:42.461000",
          "created": "2025-01-30T15:52:39.738000",
          "tags": [
            "fake google",
            "chrome update",
            "matomo instance",
            "remcos rat",
            "c2 ip",
            "address",
            "ta582",
            "hashes"
          ],
          "references": [],
          "public": 1,
          "adversary": "TAG-124",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Rhysida",
              "display_name": "Rhysida",
              "target": null
            },
            {
              "id": "Interlock",
              "display_name": "Interlock",
              "target": null
            },
            {
              "id": "SocGholish",
              "display_name": "SocGholish",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "InformationTechnogyISAC",
            "id": "141282",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 30,
            "domain": 234,
            "hostname": 105
          },
          "indicator_count": 383,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 43,
          "modified_text": "457 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Aug1.pdf",
        "https://guard.io/labs/captchageddon-unmasking-the-viral-evolution-of-the-clickfix-browser-based-threat",
        "https://thehackernews.com/2025/08/clickfix-malware-campaign-exploits.html",
        "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "TAG-124",
            "Insikt",
            "Multiple"
          ],
          "malware_families": [
            "Interlock",
            "Clickfix",
            "Rhysida",
            "Remcos",
            "Insikt",
            "Socgholish"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "6894f62d1121db26437a3eee",
      "name": "\u201cCAPTCHAgeddon\u201d Unmasking the Viral Evolution of the ClickFix Browser-Based Threat",
      "description": "What began as a niche red-team trick posing as a harmless captcha challenge rapidly mutated into one of today\u2019s most dominant attack methods. Like a real-world virus variant, this new \u201cClickFix\u201d strain quickly outpaced and ultimately wiped out the infamous fake browser update scam that plagued the web just last year. It did so by removing the need for file downloads, using smarter social engineering tactics, and spreading through trusted infrastructure. The result - a wave of infections ranging from mass drive-by attacks to hyper-targeted spear-phishing lures.",
      "modified": "2025-09-06T18:03:44.493000",
      "created": "2025-08-07T18:53:33.547000",
      "tags": [
        "clickfix",
        "google",
        "powershell",
        "clearfake",
        "dbscan",
        "guardio",
        "wordpress",
        "uuids",
        "narrative",
        "evasion",
        "cluster",
        "lumma stealer",
        "stealth",
        "june",
        "chaos",
        "clarity",
        "noise",
        "entropy",
        "shell"
      ],
      "references": [
        "https://guard.io/labs/captchageddon-unmasking-the-viral-evolution-of-the-clickfix-browser-based-threat",
        "https://thehackernews.com/2025/08/clickfix-malware-campaign-exploits.html"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClickFix",
          "display_name": "ClickFix",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AustinBH",
        "id": "147442",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 5,
        "domain": 272,
        "hostname": 39
      },
      "indicator_count": 316,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 57,
      "modified_text": "268 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "689483159128c89f669e87d6",
      "name": "EbeeAugust2025 Pt1",
      "description": "",
      "modified": "2025-09-06T10:00:39.896000",
      "created": "2025-08-07T10:42:29.730000",
      "tags": [],
      "references": [
        "Aug1.pdf"
      ],
      "public": 1,
      "adversary": "Multiple",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 75,
        "CVE": 1,
        "FileHash-MD5": 111,
        "FileHash-SHA1": 139,
        "FileHash-SHA256": 243,
        "domain": 137,
        "hostname": 43,
        "email": 1
      },
      "indicator_count": 750,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 40,
      "modified_text": "268 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67a1f245f3709030a9f0ccb7",
      "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
      "description": "A report by Insikt Group, based on an analysis of compromised WordPress sites, outlines the threat posed by a network of cybercriminal servers known as TAG-124, which is used to distribute malware.",
      "modified": "2025-03-06T10:04:51.026000",
      "created": "2025-02-04T10:56:05.010000",
      "tags": [
        "tag124",
        "cloudflare",
        "wordpress",
        "insikt group",
        "figure",
        "google chrome",
        "future",
        "urls",
        "ta582",
        "fake google",
        "rhysida",
        "powershell",
        "april",
        "insikt",
        "remcos",
        "interlock"
      ],
      "references": [
        "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
      ],
      "public": 1,
      "adversary": "Insikt",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Insikt",
          "display_name": "Insikt",
          "target": null
        },
        {
          "id": "Rhysida",
          "display_name": "Rhysida",
          "target": null
        },
        {
          "id": "REMCOS",
          "display_name": "REMCOS",
          "target": null
        },
        {
          "id": "Interlock",
          "display_name": "Interlock",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 30,
        "FileHash-SHA1": 30,
        "FileHash-SHA256": 30,
        "URL": 2,
        "domain": 254,
        "hostname": 112
      },
      "indicator_count": 458,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 863,
      "modified_text": "452 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "679ba047fa5e47a0f6e2c071",
      "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
      "description": "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base\n\nInsikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked by Recorded Future as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, 404TDS, KongTuke, and Chaya_002. TAG-124 comprises a network of compromised WordPress sites, actor-controlled payload servers, a central server, a suspected management server, an additional panel, and other components. The threat actors behind TAG-124 demonstrate high levels of activity, including regularly updating URLs embedded in the compromised WordPress sites, adding servers, refining TDS logic to evade detection, and adapting infection tactics, as demonstrated by their recent implementation of the ClickFix technique.",
      "modified": "2025-03-01T15:01:42.461000",
      "created": "2025-01-30T15:52:39.738000",
      "tags": [
        "fake google",
        "chrome update",
        "matomo instance",
        "remcos rat",
        "c2 ip",
        "address",
        "ta582",
        "hashes"
      ],
      "references": [],
      "public": 1,
      "adversary": "TAG-124",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Rhysida",
          "display_name": "Rhysida",
          "target": null
        },
        {
          "id": "Interlock",
          "display_name": "Interlock",
          "target": null
        },
        {
          "id": "SocGholish",
          "display_name": "SocGholish",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "InformationTechnogyISAC",
        "id": "141282",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 7,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 30,
        "domain": 234,
        "hostname": 105
      },
      "indicator_count": 383,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 43,
      "modified_text": "457 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "adpages.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "adpages.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780347609.9484923
}