{
  "type": "Domain",
  "indicator": "airchecklab.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/airchecklab.com",
    "alexa": "http://www.alexa.com/siteinfo/airchecklab.com",
    "indicator": "airchecklab.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3782397842,
      "indicator": "airchecklab.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 10,
      "pulses": [
        {
          "id": "69a02837827feb0b78fa3ad2",
          "name": "The Belasco Chain",
          "description": "The adversary delivers a masterclass in \"Regular Belasco\" stagecraft, utilizing authentic Adobe PIDs to construct a \"living library\" of legitimacy where mundane metadata like SOPHIA.json acts as Gatsby\u2019s \"real but uncut\" volumes to mask a hollowed-out interior. This is a triumph of performative evasion; while researchers marvel at the realism of the set-dressing, MSI50B8.tmp and MSI4F2F.tmp wait in the wings of the Windows\\Installer directory, invisible to the human eye and using NGEN hijacking to bake illicit scripts directly into the OS framework. By employing Cryptnet certificates as \"stage lighting\" to mask C2 handshakes, the malware doesn't just attend the system\u2019s party\u2014it rewrites the invitation to own the house. Unlike the tragic end at West Egg, this Belasco chain is a play that refuses to end; it simply resets the stage, ensuring the performance continues as long as the \"green light\" of the C2 remains active.",
          "modified": "2026-06-02T10:34:57.454000",
          "created": "2026-02-26T11:02:15.932000",
          "tags": [
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "file type",
            "sha1",
            "sha256",
            "crc32",
            "filenames c"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2813,
            "FileHash-SHA1": 2576,
            "FileHash-SHA256": 8145,
            "domain": 1903,
            "hostname": 1502,
            "URL": 1359,
            "email": 46,
            "CVE": 54,
            "CIDR": 3,
            "YARA": 7,
            "JA3": 1,
            "IPv4": 2
          },
          "indicator_count": 18411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 76,
          "modified_text": "7 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d3532c76eb3bf5edd9609b",
          "name": "clone credit octoseek-Dark Power - Pegasus | https://lawlink.com/ CREATED 2 YEARS AGO MODIFIED 2 YEARS AGO by OctoSeek",
          "description": "",
          "modified": "2026-04-06T06:31:08.181000",
          "created": "2026-04-06T06:31:08.181000",
          "tags": [
            "no expiration",
            "filehashmd5",
            "iocs",
            "next",
            "scan endpoints",
            "all octoseek",
            "create new",
            "pulse use",
            "pdf report",
            "pcap",
            "filehashsha1",
            "filehashsha256",
            "ipv4",
            "expiration",
            "url http",
            "url https",
            "hostname",
            "domain",
            "domain xn",
            "orgid1054",
            "ruen",
            "multiru",
            "multi",
            "fh no",
            "f no",
            "m892175",
            "n1822",
            "contact",
            "contacted",
            "ciphersuite",
            "backdoor",
            "generic malware",
            "mydoom",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "1b@ssl.com",
            "apple",
            "all octoseek",
            "aaaa",
            "access",
            "alerts",
            "analyze",
            "antivirus",
            "apple as714",
            "apple as8075",
            "bootstrap@4.6.2",
            "body",
            "cellebrite",
            "cobalt strike",
            "command and control",
            "content type",
            "core",
            "create c",
            "cyber threat",
            "dark power",
            "privilege",
            "abuse",
            "legal",
            "privilege abuse",
            "preemptive policing",
            "ransomware",
            "dns",
            "worm",
            "network",
            "rat",
            "bat",
            "colorado",
            "douglas county",
            "pd",
            "racism",
            "sexism",
            "cover up",
            "malicious",
            "jeffrey reimer dpt",
            "default",
            "defender",
            "delete c",
            "dnssec",
            "document file",
            "dynamic",
            "dynamicloader",
            "emotet",
            "execution",
            "expiration",
            "date",
            "factory",
            "february",
            "filehash",
            "formbook",
            "hacktool",
            "framing",
            "harstel",
            "florence, co",
            "sherida",
            "spyeye",
            "castle pines",
            "tools",
            "defense",
            "medical malpractice fraud",
            "scheme",
            "tsara brashears",
            "targeting",
            "swatting",
            "high",
            "hostname",
            "hostnames",
            "malicious prosecution",
            "apb",
            "installer",
            "intel",
            "iocs",
            "ios",
            "lawlink@2x.svg",
            "local",
            "local",
            "lockbit",
            "lumma stealer",
            "corruption",
            "state actors",
            "untitled states",
            "installer",
            "intel",
            "makop",
            "malware",
            "silencing",
            "ms windows",
            "human rights",
            "civil rights",
            "retaliation",
            "name servers",
            "next",
            "passive dns",
            "paste",
            "collect contacts",
            "password",
            "unlock phone",
            "ios",
            "apple gateway",
            "android overlay",
            "interfacing",
            "pe32",
            "pegasus",
            "phishing",
            "protect",
            "pulse",
            "pulses",
            "qakbot",
            "quasar",
            "ransomexx",
            "read c",
            "record value",
            "regdword",
            "regsetvalueexa",
            "relacionada",
            "sample",
            "samples",
            "scan endpoints",
            "search",
            "servers",
            "shared",
            "show",
            "ssl certificate",
            "status",
            "stealer",
            "survivor",
            "t1063",
            "targets sa",
            "url",
            "xport",
            "write c",
            "write",
            "win32",
            "whois record",
            "threat",
            "threat analyzer",
            "tlsv1",
            "tracking",
            "united",
            "unknown",
            "urls",
            "urls https",
            "ursnif",
            "v2 document",
            "vanilla-lazyload@12.0.0",
            "vista event"
          ],
          "references": [
            "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
            "cbi.com",
            "deviceinbox.com",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
            "support.apple.com [nefarious]",
            "caselaw.lawlink.com",
            "http://mail.thyrsus.com/ [phishing]",
            "ppa.launchpad.net [Apple open use]",
            "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
            "1click-uninstaller.informer.com [Apple - access PE]",
            "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:PowerShell/DynamicLoader",
              "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/FormBook",
              "display_name": "ALF:Trojan:Win32/FormBook",
              "target": null
            },
            {
              "id": "Worm:Win32/Bloored.E",
              "display_name": "Worm:Win32/Bloored.E",
              "target": "/malware/Worm:Win32/Bloored.E"
            },
            {
              "id": "Makop",
              "display_name": "Makop",
              "target": null
            },
            {
              "id": "RansomEXX (ELF)",
              "display_name": "RansomEXX (ELF)",
              "target": null
            },
            {
              "id": "Ransom:Win32/Makop",
              "display_name": "Ransom:Win32/Makop",
              "target": "/malware/Ransom:Win32/Makop"
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "PWS:Win32/XPort",
              "display_name": "PWS:Win32/XPort",
              "target": "/malware/PWS:Win32/XPort"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "Pegasus",
              "display_name": "Pegasus",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1562.003",
              "name": "Impair Command History Logging",
              "display_name": "T1562.003 - Impair Command History Logging"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1505.001",
              "name": "SQL Stored Procedures",
              "display_name": "T1505.001 - SQL Stored Procedures"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65bbb998c3b7662e5059b6c2",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1353,
            "URL": 5046,
            "FileHash-MD5": 5182,
            "FileHash-SHA1": 2869,
            "FileHash-SHA256": 4063,
            "hostname": 2471,
            "email": 28,
            "CVE": 2,
            "SSLCertFingerprint": 5
          },
          "indicator_count": 21019,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "57 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69d3532a6537880f6e2c68dc",
          "name": "clone credit octoseek-Dark Power - Pegasus | https://lawlink.com/ CREATED 2 YEARS AGO MODIFIED 2 YEARS AGO by OctoSeek",
          "description": "",
          "modified": "2026-04-06T06:31:06.730000",
          "created": "2026-04-06T06:31:06.730000",
          "tags": [
            "no expiration",
            "filehashmd5",
            "iocs",
            "next",
            "scan endpoints",
            "all octoseek",
            "create new",
            "pulse use",
            "pdf report",
            "pcap",
            "filehashsha1",
            "filehashsha256",
            "ipv4",
            "expiration",
            "url http",
            "url https",
            "hostname",
            "domain",
            "domain xn",
            "orgid1054",
            "ruen",
            "multiru",
            "multi",
            "fh no",
            "f no",
            "m892175",
            "n1822",
            "contact",
            "contacted",
            "ciphersuite",
            "backdoor",
            "generic malware",
            "mydoom",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "1b@ssl.com",
            "apple",
            "all octoseek",
            "aaaa",
            "access",
            "alerts",
            "analyze",
            "antivirus",
            "apple as714",
            "apple as8075",
            "bootstrap@4.6.2",
            "body",
            "cellebrite",
            "cobalt strike",
            "command and control",
            "content type",
            "core",
            "create c",
            "cyber threat",
            "dark power",
            "privilege",
            "abuse",
            "legal",
            "privilege abuse",
            "preemptive policing",
            "ransomware",
            "dns",
            "worm",
            "network",
            "rat",
            "bat",
            "colorado",
            "douglas county",
            "pd",
            "racism",
            "sexism",
            "cover up",
            "malicious",
            "jeffrey reimer dpt",
            "default",
            "defender",
            "delete c",
            "dnssec",
            "document file",
            "dynamic",
            "dynamicloader",
            "emotet",
            "execution",
            "expiration",
            "date",
            "factory",
            "february",
            "filehash",
            "formbook",
            "hacktool",
            "framing",
            "harstel",
            "florence, co",
            "sherida",
            "spyeye",
            "castle pines",
            "tools",
            "defense",
            "medical malpractice fraud",
            "scheme",
            "tsara brashears",
            "targeting",
            "swatting",
            "high",
            "hostname",
            "hostnames",
            "malicious prosecution",
            "apb",
            "installer",
            "intel",
            "iocs",
            "ios",
            "lawlink@2x.svg",
            "local",
            "local",
            "lockbit",
            "lumma stealer",
            "corruption",
            "state actors",
            "untitled states",
            "installer",
            "intel",
            "makop",
            "malware",
            "silencing",
            "ms windows",
            "human rights",
            "civil rights",
            "retaliation",
            "name servers",
            "next",
            "passive dns",
            "paste",
            "collect contacts",
            "password",
            "unlock phone",
            "ios",
            "apple gateway",
            "android overlay",
            "interfacing",
            "pe32",
            "pegasus",
            "phishing",
            "protect",
            "pulse",
            "pulses",
            "qakbot",
            "quasar",
            "ransomexx",
            "read c",
            "record value",
            "regdword",
            "regsetvalueexa",
            "relacionada",
            "sample",
            "samples",
            "scan endpoints",
            "search",
            "servers",
            "shared",
            "show",
            "ssl certificate",
            "status",
            "stealer",
            "survivor",
            "t1063",
            "targets sa",
            "url",
            "xport",
            "write c",
            "write",
            "win32",
            "whois record",
            "threat",
            "threat analyzer",
            "tlsv1",
            "tracking",
            "united",
            "unknown",
            "urls",
            "urls https",
            "ursnif",
            "v2 document",
            "vanilla-lazyload@12.0.0",
            "vista event"
          ],
          "references": [
            "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
            "cbi.com",
            "deviceinbox.com",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
            "support.apple.com [nefarious]",
            "caselaw.lawlink.com",
            "http://mail.thyrsus.com/ [phishing]",
            "ppa.launchpad.net [Apple open use]",
            "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
            "1click-uninstaller.informer.com [Apple - access PE]",
            "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:PowerShell/DynamicLoader",
              "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/FormBook",
              "display_name": "ALF:Trojan:Win32/FormBook",
              "target": null
            },
            {
              "id": "Worm:Win32/Bloored.E",
              "display_name": "Worm:Win32/Bloored.E",
              "target": "/malware/Worm:Win32/Bloored.E"
            },
            {
              "id": "Makop",
              "display_name": "Makop",
              "target": null
            },
            {
              "id": "RansomEXX (ELF)",
              "display_name": "RansomEXX (ELF)",
              "target": null
            },
            {
              "id": "Ransom:Win32/Makop",
              "display_name": "Ransom:Win32/Makop",
              "target": "/malware/Ransom:Win32/Makop"
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "PWS:Win32/XPort",
              "display_name": "PWS:Win32/XPort",
              "target": "/malware/PWS:Win32/XPort"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "Pegasus",
              "display_name": "Pegasus",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1562.003",
              "name": "Impair Command History Logging",
              "display_name": "T1562.003 - Impair Command History Logging"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1505.001",
              "name": "SQL Stored Procedures",
              "display_name": "T1505.001 - SQL Stored Procedures"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65bbb998c3b7662e5059b6c2",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1353,
            "URL": 5046,
            "FileHash-MD5": 5182,
            "FileHash-SHA1": 2869,
            "FileHash-SHA256": 4063,
            "hostname": 2471,
            "email": 28,
            "CVE": 2,
            "SSLCertFingerprint": 5
          },
          "indicator_count": 21019,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "57 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65bbb9815816db0de034f3a3",
          "name": "Dark Power - Pegasus |  https://lawlink.com/",
          "description": "Dark Power ransomware first emerged in early 2023. The group engages in multi-extortion, threatening to release victim data for various reasons. Dark Power encrypts the victim's files and requests a ransom payment in exchange for the decryption key. Dark Power's ransom note is distinct from other ransomware campaigns.\n\nPrivilege and other abusive practices considering individuals targeted.",
          "modified": "2024-03-02T13:01:40.418000",
          "created": "2024-02-01T15:32:17.285000",
          "tags": [
            "no expiration",
            "filehashmd5",
            "iocs",
            "next",
            "scan endpoints",
            "all octoseek",
            "create new",
            "pulse use",
            "pdf report",
            "pcap",
            "filehashsha1",
            "filehashsha256",
            "ipv4",
            "expiration",
            "url http",
            "url https",
            "hostname",
            "domain",
            "domain xn",
            "orgid1054",
            "ruen",
            "multiru",
            "multi",
            "fh no",
            "f no",
            "m892175",
            "n1822",
            "contact",
            "contacted",
            "ciphersuite",
            "backdoor",
            "generic malware",
            "mydoom",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "1b@ssl.com",
            "apple",
            "all octoseek",
            "aaaa",
            "access",
            "alerts",
            "analyze",
            "antivirus",
            "apple as714",
            "apple as8075",
            "bootstrap@4.6.2",
            "body",
            "cellebrite",
            "cobalt strike",
            "command and control",
            "content type",
            "core",
            "create c",
            "cyber threat",
            "dark power",
            "privilege",
            "abuse",
            "legal",
            "privilege abuse",
            "preemptive policing",
            "ransomware",
            "dns",
            "worm",
            "network",
            "rat",
            "bat",
            "colorado",
            "douglas county",
            "pd",
            "racism",
            "sexism",
            "cover up",
            "malicious",
            "jeffrey reimer dpt",
            "default",
            "defender",
            "delete c",
            "dnssec",
            "document file",
            "dynamic",
            "dynamicloader",
            "emotet",
            "execution",
            "expiration",
            "date",
            "factory",
            "february",
            "filehash",
            "formbook",
            "hacktool",
            "framing",
            "harstel",
            "florence, co",
            "sherida",
            "spyeye",
            "castle pines",
            "tools",
            "defense",
            "medical malpractice fraud",
            "scheme",
            "tsara brashears",
            "targeting",
            "swatting",
            "high",
            "hostname",
            "hostnames",
            "malicious prosecution",
            "apb",
            "installer",
            "intel",
            "iocs",
            "ios",
            "lawlink@2x.svg",
            "local",
            "local",
            "lockbit",
            "lumma stealer",
            "corruption",
            "state actors",
            "untitled states",
            "installer",
            "intel",
            "makop",
            "malware",
            "silencing",
            "ms windows",
            "human rights",
            "civil rights",
            "retaliation",
            "name servers",
            "next",
            "passive dns",
            "paste",
            "collect contacts",
            "password",
            "unlock phone",
            "ios",
            "apple gateway",
            "android overlay",
            "interfacing",
            "pe32",
            "pegasus",
            "phishing",
            "protect",
            "pulse",
            "pulses",
            "qakbot",
            "quasar",
            "ransomexx",
            "read c",
            "record value",
            "regdword",
            "regsetvalueexa",
            "relacionada",
            "sample",
            "samples",
            "scan endpoints",
            "search",
            "servers",
            "shared",
            "show",
            "ssl certificate",
            "status",
            "stealer",
            "survivor",
            "t1063",
            "targets sa",
            "url",
            "xport",
            "write c",
            "write",
            "win32",
            "whois record",
            "threat",
            "threat analyzer",
            "tlsv1",
            "tracking",
            "united",
            "unknown",
            "urls",
            "urls https",
            "ursnif",
            "v2 document",
            "vanilla-lazyload@12.0.0",
            "vista event"
          ],
          "references": [
            "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
            "cbi.com",
            "deviceinbox.com",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
            "support.apple.com [nefarious]",
            "caselaw.lawlink.com",
            "http://mail.thyrsus.com/ [phishing]",
            "ppa.launchpad.net [Apple open use]",
            "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
            "1click-uninstaller.informer.com [Apple - access PE]",
            "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:PowerShell/DynamicLoader",
              "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/FormBook",
              "display_name": "ALF:Trojan:Win32/FormBook",
              "target": null
            },
            {
              "id": "Worm:Win32/Bloored.E",
              "display_name": "Worm:Win32/Bloored.E",
              "target": "/malware/Worm:Win32/Bloored.E"
            },
            {
              "id": "Makop",
              "display_name": "Makop",
              "target": null
            },
            {
              "id": "RansomEXX (ELF)",
              "display_name": "RansomEXX (ELF)",
              "target": null
            },
            {
              "id": "Ransom:Win32/Makop",
              "display_name": "Ransom:Win32/Makop",
              "target": "/malware/Ransom:Win32/Makop"
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "PWS:Win32/XPort",
              "display_name": "PWS:Win32/XPort",
              "target": "/malware/PWS:Win32/XPort"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "Pegasus",
              "display_name": "Pegasus",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1562.003",
              "name": "Impair Command History Logging",
              "display_name": "T1562.003 - Impair Command History Logging"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1505.001",
              "name": "SQL Stored Procedures",
              "display_name": "T1505.001 - SQL Stored Procedures"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1353,
            "URL": 5046,
            "FileHash-MD5": 5182,
            "FileHash-SHA1": 2869,
            "FileHash-SHA256": 4063,
            "hostname": 2471,
            "email": 28,
            "CVE": 2,
            "SSLCertFingerprint": 5
          },
          "indicator_count": 21019,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "822 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65bbb98c440c1c45ec12ccdc",
          "name": "Dark Power - Pegasus |  https://lawlink.com/",
          "description": "Dark Power ransomware first emerged in early 2023. The group engages in multi-extortion, threatening to release victim data for various reasons. Dark Power encrypts the victim's files and requests a ransom payment in exchange for the decryption key. Dark Power's ransom note is distinct from other ransomware campaigns.\n\nPrivilege and other abusive practices considering individuals targeted.",
          "modified": "2024-03-02T13:01:40.418000",
          "created": "2024-02-01T15:32:28.063000",
          "tags": [
            "no expiration",
            "filehashmd5",
            "iocs",
            "next",
            "scan endpoints",
            "all octoseek",
            "create new",
            "pulse use",
            "pdf report",
            "pcap",
            "filehashsha1",
            "filehashsha256",
            "ipv4",
            "expiration",
            "url http",
            "url https",
            "hostname",
            "domain",
            "domain xn",
            "orgid1054",
            "ruen",
            "multiru",
            "multi",
            "fh no",
            "f no",
            "m892175",
            "n1822",
            "contact",
            "contacted",
            "ciphersuite",
            "backdoor",
            "generic malware",
            "mydoom",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "1b@ssl.com",
            "apple",
            "all octoseek",
            "aaaa",
            "access",
            "alerts",
            "analyze",
            "antivirus",
            "apple as714",
            "apple as8075",
            "bootstrap@4.6.2",
            "body",
            "cellebrite",
            "cobalt strike",
            "command and control",
            "content type",
            "core",
            "create c",
            "cyber threat",
            "dark power",
            "privilege",
            "abuse",
            "legal",
            "privilege abuse",
            "preemptive policing",
            "ransomware",
            "dns",
            "worm",
            "network",
            "rat",
            "bat",
            "colorado",
            "douglas county",
            "pd",
            "racism",
            "sexism",
            "cover up",
            "malicious",
            "jeffrey reimer dpt",
            "default",
            "defender",
            "delete c",
            "dnssec",
            "document file",
            "dynamic",
            "dynamicloader",
            "emotet",
            "execution",
            "expiration",
            "date",
            "factory",
            "february",
            "filehash",
            "formbook",
            "hacktool",
            "framing",
            "harstel",
            "florence, co",
            "sherida",
            "spyeye",
            "castle pines",
            "tools",
            "defense",
            "medical malpractice fraud",
            "scheme",
            "tsara brashears",
            "targeting",
            "swatting",
            "high",
            "hostname",
            "hostnames",
            "malicious prosecution",
            "apb",
            "installer",
            "intel",
            "iocs",
            "ios",
            "lawlink@2x.svg",
            "local",
            "local",
            "lockbit",
            "lumma stealer",
            "corruption",
            "state actors",
            "untitled states",
            "installer",
            "intel",
            "makop",
            "malware",
            "silencing",
            "ms windows",
            "human rights",
            "civil rights",
            "retaliation",
            "name servers",
            "next",
            "passive dns",
            "paste",
            "collect contacts",
            "password",
            "unlock phone",
            "ios",
            "apple gateway",
            "android overlay",
            "interfacing",
            "pe32",
            "pegasus",
            "phishing",
            "protect",
            "pulse",
            "pulses",
            "qakbot",
            "quasar",
            "ransomexx",
            "read c",
            "record value",
            "regdword",
            "regsetvalueexa",
            "relacionada",
            "sample",
            "samples",
            "scan endpoints",
            "search",
            "servers",
            "shared",
            "show",
            "ssl certificate",
            "status",
            "stealer",
            "survivor",
            "t1063",
            "targets sa",
            "url",
            "xport",
            "write c",
            "write",
            "win32",
            "whois record",
            "threat",
            "threat analyzer",
            "tlsv1",
            "tracking",
            "united",
            "unknown",
            "urls",
            "urls https",
            "ursnif",
            "v2 document",
            "vanilla-lazyload@12.0.0",
            "vista event"
          ],
          "references": [
            "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
            "cbi.com",
            "deviceinbox.com",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
            "support.apple.com [nefarious]",
            "caselaw.lawlink.com",
            "http://mail.thyrsus.com/ [phishing]",
            "ppa.launchpad.net [Apple open use]",
            "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
            "1click-uninstaller.informer.com [Apple - access PE]",
            "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:PowerShell/DynamicLoader",
              "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/FormBook",
              "display_name": "ALF:Trojan:Win32/FormBook",
              "target": null
            },
            {
              "id": "Worm:Win32/Bloored.E",
              "display_name": "Worm:Win32/Bloored.E",
              "target": "/malware/Worm:Win32/Bloored.E"
            },
            {
              "id": "Makop",
              "display_name": "Makop",
              "target": null
            },
            {
              "id": "RansomEXX (ELF)",
              "display_name": "RansomEXX (ELF)",
              "target": null
            },
            {
              "id": "Ransom:Win32/Makop",
              "display_name": "Ransom:Win32/Makop",
              "target": "/malware/Ransom:Win32/Makop"
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "PWS:Win32/XPort",
              "display_name": "PWS:Win32/XPort",
              "target": "/malware/PWS:Win32/XPort"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "Pegasus",
              "display_name": "Pegasus",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1562.003",
              "name": "Impair Command History Logging",
              "display_name": "T1562.003 - Impair Command History Logging"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1505.001",
              "name": "SQL Stored Procedures",
              "display_name": "T1505.001 - SQL Stored Procedures"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1353,
            "URL": 5046,
            "FileHash-MD5": 5182,
            "FileHash-SHA1": 2869,
            "FileHash-SHA256": 4063,
            "hostname": 2471,
            "email": 28,
            "CVE": 2,
            "SSLCertFingerprint": 5
          },
          "indicator_count": 21019,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "822 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65bbb98d9818cca8f130c195",
          "name": "Dark Power - Pegasus |  https://lawlink.com/",
          "description": "Dark Power ransomware first emerged in early 2023. The group engages in multi-extortion, threatening to release victim data for various reasons. Dark Power encrypts the victim's files and requests a ransom payment in exchange for the decryption key. Dark Power's ransom note is distinct from other ransomware campaigns.\n\nPrivilege and other abusive practices considering individuals targeted.",
          "modified": "2024-03-02T13:01:40.418000",
          "created": "2024-02-01T15:32:29.619000",
          "tags": [
            "no expiration",
            "filehashmd5",
            "iocs",
            "next",
            "scan endpoints",
            "all octoseek",
            "create new",
            "pulse use",
            "pdf report",
            "pcap",
            "filehashsha1",
            "filehashsha256",
            "ipv4",
            "expiration",
            "url http",
            "url https",
            "hostname",
            "domain",
            "domain xn",
            "orgid1054",
            "ruen",
            "multiru",
            "multi",
            "fh no",
            "f no",
            "m892175",
            "n1822",
            "contact",
            "contacted",
            "ciphersuite",
            "backdoor",
            "generic malware",
            "mydoom",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "1b@ssl.com",
            "apple",
            "all octoseek",
            "aaaa",
            "access",
            "alerts",
            "analyze",
            "antivirus",
            "apple as714",
            "apple as8075",
            "bootstrap@4.6.2",
            "body",
            "cellebrite",
            "cobalt strike",
            "command and control",
            "content type",
            "core",
            "create c",
            "cyber threat",
            "dark power",
            "privilege",
            "abuse",
            "legal",
            "privilege abuse",
            "preemptive policing",
            "ransomware",
            "dns",
            "worm",
            "network",
            "rat",
            "bat",
            "colorado",
            "douglas county",
            "pd",
            "racism",
            "sexism",
            "cover up",
            "malicious",
            "jeffrey reimer dpt",
            "default",
            "defender",
            "delete c",
            "dnssec",
            "document file",
            "dynamic",
            "dynamicloader",
            "emotet",
            "execution",
            "expiration",
            "date",
            "factory",
            "february",
            "filehash",
            "formbook",
            "hacktool",
            "framing",
            "harstel",
            "florence, co",
            "sherida",
            "spyeye",
            "castle pines",
            "tools",
            "defense",
            "medical malpractice fraud",
            "scheme",
            "tsara brashears",
            "targeting",
            "swatting",
            "high",
            "hostname",
            "hostnames",
            "malicious prosecution",
            "apb",
            "installer",
            "intel",
            "iocs",
            "ios",
            "lawlink@2x.svg",
            "local",
            "local",
            "lockbit",
            "lumma stealer",
            "corruption",
            "state actors",
            "untitled states",
            "installer",
            "intel",
            "makop",
            "malware",
            "silencing",
            "ms windows",
            "human rights",
            "civil rights",
            "retaliation",
            "name servers",
            "next",
            "passive dns",
            "paste",
            "collect contacts",
            "password",
            "unlock phone",
            "ios",
            "apple gateway",
            "android overlay",
            "interfacing",
            "pe32",
            "pegasus",
            "phishing",
            "protect",
            "pulse",
            "pulses",
            "qakbot",
            "quasar",
            "ransomexx",
            "read c",
            "record value",
            "regdword",
            "regsetvalueexa",
            "relacionada",
            "sample",
            "samples",
            "scan endpoints",
            "search",
            "servers",
            "shared",
            "show",
            "ssl certificate",
            "status",
            "stealer",
            "survivor",
            "t1063",
            "targets sa",
            "url",
            "xport",
            "write c",
            "write",
            "win32",
            "whois record",
            "threat",
            "threat analyzer",
            "tlsv1",
            "tracking",
            "united",
            "unknown",
            "urls",
            "urls https",
            "ursnif",
            "v2 document",
            "vanilla-lazyload@12.0.0",
            "vista event"
          ],
          "references": [
            "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
            "cbi.com",
            "deviceinbox.com",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
            "support.apple.com [nefarious]",
            "caselaw.lawlink.com",
            "http://mail.thyrsus.com/ [phishing]",
            "ppa.launchpad.net [Apple open use]",
            "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
            "1click-uninstaller.informer.com [Apple - access PE]",
            "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:PowerShell/DynamicLoader",
              "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/FormBook",
              "display_name": "ALF:Trojan:Win32/FormBook",
              "target": null
            },
            {
              "id": "Worm:Win32/Bloored.E",
              "display_name": "Worm:Win32/Bloored.E",
              "target": "/malware/Worm:Win32/Bloored.E"
            },
            {
              "id": "Makop",
              "display_name": "Makop",
              "target": null
            },
            {
              "id": "RansomEXX (ELF)",
              "display_name": "RansomEXX (ELF)",
              "target": null
            },
            {
              "id": "Ransom:Win32/Makop",
              "display_name": "Ransom:Win32/Makop",
              "target": "/malware/Ransom:Win32/Makop"
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "PWS:Win32/XPort",
              "display_name": "PWS:Win32/XPort",
              "target": "/malware/PWS:Win32/XPort"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "Pegasus",
              "display_name": "Pegasus",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1562.003",
              "name": "Impair Command History Logging",
              "display_name": "T1562.003 - Impair Command History Logging"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1505.001",
              "name": "SQL Stored Procedures",
              "display_name": "T1505.001 - SQL Stored Procedures"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1353,
            "URL": 5046,
            "FileHash-MD5": 5182,
            "FileHash-SHA1": 2869,
            "FileHash-SHA256": 4063,
            "hostname": 2471,
            "email": 28,
            "CVE": 2,
            "SSLCertFingerprint": 5
          },
          "indicator_count": 21019,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "822 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65bbb998c3b7662e5059b6c2",
          "name": "Dark Power - Pegasus |  https://lawlink.com/",
          "description": "Dark Power ransomware first emerged in early 2023. The group engages in multi-extortion, threatening to release victim data for various reasons. Dark Power encrypts the victim's files and requests a ransom payment in exchange for the decryption key. Dark Power's ransom note is distinct from other ransomware campaigns.\n\nPrivilege and other abusive practices considering individuals targeted.",
          "modified": "2024-03-02T13:01:40.418000",
          "created": "2024-02-01T15:32:40.759000",
          "tags": [
            "no expiration",
            "filehashmd5",
            "iocs",
            "next",
            "scan endpoints",
            "all octoseek",
            "create new",
            "pulse use",
            "pdf report",
            "pcap",
            "filehashsha1",
            "filehashsha256",
            "ipv4",
            "expiration",
            "url http",
            "url https",
            "hostname",
            "domain",
            "domain xn",
            "orgid1054",
            "ruen",
            "multiru",
            "multi",
            "fh no",
            "f no",
            "m892175",
            "n1822",
            "contact",
            "contacted",
            "ciphersuite",
            "backdoor",
            "generic malware",
            "mydoom",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "1b@ssl.com",
            "apple",
            "all octoseek",
            "aaaa",
            "access",
            "alerts",
            "analyze",
            "antivirus",
            "apple as714",
            "apple as8075",
            "bootstrap@4.6.2",
            "body",
            "cellebrite",
            "cobalt strike",
            "command and control",
            "content type",
            "core",
            "create c",
            "cyber threat",
            "dark power",
            "privilege",
            "abuse",
            "legal",
            "privilege abuse",
            "preemptive policing",
            "ransomware",
            "dns",
            "worm",
            "network",
            "rat",
            "bat",
            "colorado",
            "douglas county",
            "pd",
            "racism",
            "sexism",
            "cover up",
            "malicious",
            "jeffrey reimer dpt",
            "default",
            "defender",
            "delete c",
            "dnssec",
            "document file",
            "dynamic",
            "dynamicloader",
            "emotet",
            "execution",
            "expiration",
            "date",
            "factory",
            "february",
            "filehash",
            "formbook",
            "hacktool",
            "framing",
            "harstel",
            "florence, co",
            "sherida",
            "spyeye",
            "castle pines",
            "tools",
            "defense",
            "medical malpractice fraud",
            "scheme",
            "tsara brashears",
            "targeting",
            "swatting",
            "high",
            "hostname",
            "hostnames",
            "malicious prosecution",
            "apb",
            "installer",
            "intel",
            "iocs",
            "ios",
            "lawlink@2x.svg",
            "local",
            "local",
            "lockbit",
            "lumma stealer",
            "corruption",
            "state actors",
            "untitled states",
            "installer",
            "intel",
            "makop",
            "malware",
            "silencing",
            "ms windows",
            "human rights",
            "civil rights",
            "retaliation",
            "name servers",
            "next",
            "passive dns",
            "paste",
            "collect contacts",
            "password",
            "unlock phone",
            "ios",
            "apple gateway",
            "android overlay",
            "interfacing",
            "pe32",
            "pegasus",
            "phishing",
            "protect",
            "pulse",
            "pulses",
            "qakbot",
            "quasar",
            "ransomexx",
            "read c",
            "record value",
            "regdword",
            "regsetvalueexa",
            "relacionada",
            "sample",
            "samples",
            "scan endpoints",
            "search",
            "servers",
            "shared",
            "show",
            "ssl certificate",
            "status",
            "stealer",
            "survivor",
            "t1063",
            "targets sa",
            "url",
            "xport",
            "write c",
            "write",
            "win32",
            "whois record",
            "threat",
            "threat analyzer",
            "tlsv1",
            "tracking",
            "united",
            "unknown",
            "urls",
            "urls https",
            "ursnif",
            "v2 document",
            "vanilla-lazyload@12.0.0",
            "vista event"
          ],
          "references": [
            "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
            "cbi.com",
            "deviceinbox.com",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
            "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
            "support.apple.com [nefarious]",
            "caselaw.lawlink.com",
            "http://mail.thyrsus.com/ [phishing]",
            "ppa.launchpad.net [Apple open use]",
            "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
            "1click-uninstaller.informer.com [Apple - access PE]",
            "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:PowerShell/DynamicLoader",
              "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/FormBook",
              "display_name": "ALF:Trojan:Win32/FormBook",
              "target": null
            },
            {
              "id": "Worm:Win32/Bloored.E",
              "display_name": "Worm:Win32/Bloored.E",
              "target": "/malware/Worm:Win32/Bloored.E"
            },
            {
              "id": "Makop",
              "display_name": "Makop",
              "target": null
            },
            {
              "id": "RansomEXX (ELF)",
              "display_name": "RansomEXX (ELF)",
              "target": null
            },
            {
              "id": "Ransom:Win32/Makop",
              "display_name": "Ransom:Win32/Makop",
              "target": "/malware/Ransom:Win32/Makop"
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "PWS:Win32/XPort",
              "display_name": "PWS:Win32/XPort",
              "target": "/malware/PWS:Win32/XPort"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "Pegasus",
              "display_name": "Pegasus",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1562.003",
              "name": "Impair Command History Logging",
              "display_name": "T1562.003 - Impair Command History Logging"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1505.001",
              "name": "SQL Stored Procedures",
              "display_name": "T1505.001 - SQL Stored Procedures"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1353,
            "URL": 5046,
            "FileHash-MD5": 5182,
            "FileHash-SHA1": 2869,
            "FileHash-SHA256": 4063,
            "hostname": 2471,
            "email": 28,
            "CVE": 2,
            "SSLCertFingerprint": 5
          },
          "indicator_count": 21019,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "822 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6552d60aae6e1b3c22455088",
          "name": "Hive 0065",
          "description": "Hive 0065\nURL: https://applemusic-spotlight.myunidays.com/US/en-US?\n\nHive 0065\nHostname: applemusic-spotlight.myunidays.com",
          "modified": "2023-12-13T16:00:45.799000",
          "created": "2023-11-14T02:06:02.329000",
          "tags": [
            "united",
            "as8075",
            "creation date",
            "unknown",
            "search",
            "entries",
            "asnone country",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "related domains",
            "show",
            "domain related",
            "xbox",
            "whois record",
            "contacted",
            "whois whois",
            "ssl certificate",
            "communicating",
            "referrer",
            "execution",
            "historical ssl",
            "bundled",
            "family",
            "lolkek",
            "formbook",
            "skynet",
            "lockbit",
            "ursnif",
            "attack",
            "core"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 4276,
            "email": 3,
            "hostname": 2288,
            "FileHash-MD5": 51,
            "FileHash-SHA1": 49,
            "FileHash-SHA256": 2756,
            "URL": 8696,
            "CVE": 1
          },
          "indicator_count": 18120,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "902 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6552d6f5f56d2e9cd9e18a30",
          "name": "Lolkek \u2022 FormBook \u2022 Lokbit \u2022 Skynet",
          "description": "Hive 0065\nURL: https://applemusic-spotlight.myunidays.com/US/en-US?\n\nHive 0065\nHostname: applemusic-spotlight.myunidays.com",
          "modified": "2023-12-13T16:00:45.799000",
          "created": "2023-11-14T02:09:57.370000",
          "tags": [
            "united",
            "as8075",
            "creation date",
            "unknown",
            "search",
            "entries",
            "asnone country",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "related domains",
            "show",
            "domain related",
            "xbox",
            "whois record",
            "contacted",
            "whois whois",
            "ssl certificate",
            "communicating",
            "referrer",
            "execution",
            "historical ssl",
            "bundled",
            "family",
            "lolkek",
            "formbook",
            "skynet",
            "lockbit",
            "ursnif",
            "attack",
            "core"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 4276,
            "email": 3,
            "hostname": 2288,
            "FileHash-MD5": 51,
            "FileHash-SHA1": 49,
            "FileHash-SHA256": 2756,
            "URL": 8696,
            "CVE": 1
          },
          "indicator_count": 18120,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "902 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65568b00198f82af2e88d463",
          "name": "Lolkek \u2022 FormBook \u2022 Lokbit \u2022 Skynet",
          "description": "",
          "modified": "2023-12-13T16:00:45.799000",
          "created": "2023-11-16T21:34:56.016000",
          "tags": [
            "united",
            "as8075",
            "creation date",
            "unknown",
            "search",
            "entries",
            "asnone country",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "related domains",
            "show",
            "domain related",
            "xbox",
            "whois record",
            "contacted",
            "whois whois",
            "ssl certificate",
            "communicating",
            "referrer",
            "execution",
            "historical ssl",
            "bundled",
            "family",
            "lolkek",
            "formbook",
            "skynet",
            "lockbit",
            "ursnif",
            "attack",
            "core"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6552d6f5f56d2e9cd9e18a30",
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 4276,
            "email": 3,
            "hostname": 2288,
            "FileHash-MD5": 51,
            "FileHash-SHA1": 49,
            "FileHash-SHA256": 2756,
            "URL": 8696,
            "CVE": 1
          },
          "indicator_count": 18120,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 231,
          "modified_text": "902 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "cbi.com",
        "1click-uninstaller.informer.com [Apple - access PE]",
        "ppa.launchpad.net [Apple open use]",
        "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
        "support.apple.com [nefarious]",
        "caselaw.lawlink.com",
        "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
        "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S",
        "deviceinbox.com",
        "http://mail.thyrsus.com/ [phishing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Pegasus",
            "Worm:win32/bloored.e",
            "Hacktool",
            "Dark power",
            "Ransomexx (elf)",
            "Emotet",
            "Qakbot",
            "Pws:win32/xport",
            "Quasar rat",
            "Formbook",
            "Lumma stealer",
            "Alf:trojan:powershell/dynamicloader",
            "Lockbit",
            "Cobalt strike",
            "Makop",
            "Alf:trojan:win32/formbook",
            "Ransom:win32/makop"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 10,
  "pulses": [
    {
      "id": "69a02837827feb0b78fa3ad2",
      "name": "The Belasco Chain",
      "description": "The adversary delivers a masterclass in \"Regular Belasco\" stagecraft, utilizing authentic Adobe PIDs to construct a \"living library\" of legitimacy where mundane metadata like SOPHIA.json acts as Gatsby\u2019s \"real but uncut\" volumes to mask a hollowed-out interior. This is a triumph of performative evasion; while researchers marvel at the realism of the set-dressing, MSI50B8.tmp and MSI4F2F.tmp wait in the wings of the Windows\\Installer directory, invisible to the human eye and using NGEN hijacking to bake illicit scripts directly into the OS framework. By employing Cryptnet certificates as \"stage lighting\" to mask C2 handshakes, the malware doesn't just attend the system\u2019s party\u2014it rewrites the invitation to own the house. Unlike the tragic end at West Egg, this Belasco chain is a play that refuses to end; it simply resets the stage, ensuring the performance continues as long as the \"green light\" of the C2 remains active.",
      "modified": "2026-06-02T10:34:57.454000",
      "created": "2026-02-26T11:02:15.932000",
      "tags": [
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "file type",
        "sha1",
        "sha256",
        "crc32",
        "filenames c"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2813,
        "FileHash-SHA1": 2576,
        "FileHash-SHA256": 8145,
        "domain": 1903,
        "hostname": 1502,
        "URL": 1359,
        "email": 46,
        "CVE": 54,
        "CIDR": 3,
        "YARA": 7,
        "JA3": 1,
        "IPv4": 2
      },
      "indicator_count": 18411,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 76,
      "modified_text": "7 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d3532c76eb3bf5edd9609b",
      "name": "clone credit octoseek-Dark Power - Pegasus | https://lawlink.com/ CREATED 2 YEARS AGO MODIFIED 2 YEARS AGO by OctoSeek",
      "description": "",
      "modified": "2026-04-06T06:31:08.181000",
      "created": "2026-04-06T06:31:08.181000",
      "tags": [
        "no expiration",
        "filehashmd5",
        "iocs",
        "next",
        "scan endpoints",
        "all octoseek",
        "create new",
        "pulse use",
        "pdf report",
        "pcap",
        "filehashsha1",
        "filehashsha256",
        "ipv4",
        "expiration",
        "url http",
        "url https",
        "hostname",
        "domain",
        "domain xn",
        "orgid1054",
        "ruen",
        "multiru",
        "multi",
        "fh no",
        "f no",
        "m892175",
        "n1822",
        "contact",
        "contacted",
        "ciphersuite",
        "backdoor",
        "generic malware",
        "mydoom",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "1b@ssl.com",
        "apple",
        "all octoseek",
        "aaaa",
        "access",
        "alerts",
        "analyze",
        "antivirus",
        "apple as714",
        "apple as8075",
        "bootstrap@4.6.2",
        "body",
        "cellebrite",
        "cobalt strike",
        "command and control",
        "content type",
        "core",
        "create c",
        "cyber threat",
        "dark power",
        "privilege",
        "abuse",
        "legal",
        "privilege abuse",
        "preemptive policing",
        "ransomware",
        "dns",
        "worm",
        "network",
        "rat",
        "bat",
        "colorado",
        "douglas county",
        "pd",
        "racism",
        "sexism",
        "cover up",
        "malicious",
        "jeffrey reimer dpt",
        "default",
        "defender",
        "delete c",
        "dnssec",
        "document file",
        "dynamic",
        "dynamicloader",
        "emotet",
        "execution",
        "expiration",
        "date",
        "factory",
        "february",
        "filehash",
        "formbook",
        "hacktool",
        "framing",
        "harstel",
        "florence, co",
        "sherida",
        "spyeye",
        "castle pines",
        "tools",
        "defense",
        "medical malpractice fraud",
        "scheme",
        "tsara brashears",
        "targeting",
        "swatting",
        "high",
        "hostname",
        "hostnames",
        "malicious prosecution",
        "apb",
        "installer",
        "intel",
        "iocs",
        "ios",
        "lawlink@2x.svg",
        "local",
        "local",
        "lockbit",
        "lumma stealer",
        "corruption",
        "state actors",
        "untitled states",
        "installer",
        "intel",
        "makop",
        "malware",
        "silencing",
        "ms windows",
        "human rights",
        "civil rights",
        "retaliation",
        "name servers",
        "next",
        "passive dns",
        "paste",
        "collect contacts",
        "password",
        "unlock phone",
        "ios",
        "apple gateway",
        "android overlay",
        "interfacing",
        "pe32",
        "pegasus",
        "phishing",
        "protect",
        "pulse",
        "pulses",
        "qakbot",
        "quasar",
        "ransomexx",
        "read c",
        "record value",
        "regdword",
        "regsetvalueexa",
        "relacionada",
        "sample",
        "samples",
        "scan endpoints",
        "search",
        "servers",
        "shared",
        "show",
        "ssl certificate",
        "status",
        "stealer",
        "survivor",
        "t1063",
        "targets sa",
        "url",
        "xport",
        "write c",
        "write",
        "win32",
        "whois record",
        "threat",
        "threat analyzer",
        "tlsv1",
        "tracking",
        "united",
        "unknown",
        "urls",
        "urls https",
        "ursnif",
        "v2 document",
        "vanilla-lazyload@12.0.0",
        "vista event"
      ],
      "references": [
        "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
        "cbi.com",
        "deviceinbox.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
        "support.apple.com [nefarious]",
        "caselaw.lawlink.com",
        "http://mail.thyrsus.com/ [phishing]",
        "ppa.launchpad.net [Apple open use]",
        "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
        "1click-uninstaller.informer.com [Apple - access PE]",
        "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:PowerShell/DynamicLoader",
          "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/FormBook",
          "display_name": "ALF:Trojan:Win32/FormBook",
          "target": null
        },
        {
          "id": "Worm:Win32/Bloored.E",
          "display_name": "Worm:Win32/Bloored.E",
          "target": "/malware/Worm:Win32/Bloored.E"
        },
        {
          "id": "Makop",
          "display_name": "Makop",
          "target": null
        },
        {
          "id": "RansomEXX (ELF)",
          "display_name": "RansomEXX (ELF)",
          "target": null
        },
        {
          "id": "Ransom:Win32/Makop",
          "display_name": "Ransom:Win32/Makop",
          "target": "/malware/Ransom:Win32/Makop"
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "PWS:Win32/XPort",
          "display_name": "PWS:Win32/XPort",
          "target": "/malware/PWS:Win32/XPort"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Dark Power",
          "display_name": "Dark Power",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "Pegasus",
          "display_name": "Pegasus",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1562.003",
          "name": "Impair Command History Logging",
          "display_name": "T1562.003 - Impair Command History Logging"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1505.001",
          "name": "SQL Stored Procedures",
          "display_name": "T1505.001 - SQL Stored Procedures"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65bbb998c3b7662e5059b6c2",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1353,
        "URL": 5046,
        "FileHash-MD5": 5182,
        "FileHash-SHA1": 2869,
        "FileHash-SHA256": 4063,
        "hostname": 2471,
        "email": 28,
        "CVE": 2,
        "SSLCertFingerprint": 5
      },
      "indicator_count": 21019,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "57 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69d3532a6537880f6e2c68dc",
      "name": "clone credit octoseek-Dark Power - Pegasus | https://lawlink.com/ CREATED 2 YEARS AGO MODIFIED 2 YEARS AGO by OctoSeek",
      "description": "",
      "modified": "2026-04-06T06:31:06.730000",
      "created": "2026-04-06T06:31:06.730000",
      "tags": [
        "no expiration",
        "filehashmd5",
        "iocs",
        "next",
        "scan endpoints",
        "all octoseek",
        "create new",
        "pulse use",
        "pdf report",
        "pcap",
        "filehashsha1",
        "filehashsha256",
        "ipv4",
        "expiration",
        "url http",
        "url https",
        "hostname",
        "domain",
        "domain xn",
        "orgid1054",
        "ruen",
        "multiru",
        "multi",
        "fh no",
        "f no",
        "m892175",
        "n1822",
        "contact",
        "contacted",
        "ciphersuite",
        "backdoor",
        "generic malware",
        "mydoom",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "1b@ssl.com",
        "apple",
        "all octoseek",
        "aaaa",
        "access",
        "alerts",
        "analyze",
        "antivirus",
        "apple as714",
        "apple as8075",
        "bootstrap@4.6.2",
        "body",
        "cellebrite",
        "cobalt strike",
        "command and control",
        "content type",
        "core",
        "create c",
        "cyber threat",
        "dark power",
        "privilege",
        "abuse",
        "legal",
        "privilege abuse",
        "preemptive policing",
        "ransomware",
        "dns",
        "worm",
        "network",
        "rat",
        "bat",
        "colorado",
        "douglas county",
        "pd",
        "racism",
        "sexism",
        "cover up",
        "malicious",
        "jeffrey reimer dpt",
        "default",
        "defender",
        "delete c",
        "dnssec",
        "document file",
        "dynamic",
        "dynamicloader",
        "emotet",
        "execution",
        "expiration",
        "date",
        "factory",
        "february",
        "filehash",
        "formbook",
        "hacktool",
        "framing",
        "harstel",
        "florence, co",
        "sherida",
        "spyeye",
        "castle pines",
        "tools",
        "defense",
        "medical malpractice fraud",
        "scheme",
        "tsara brashears",
        "targeting",
        "swatting",
        "high",
        "hostname",
        "hostnames",
        "malicious prosecution",
        "apb",
        "installer",
        "intel",
        "iocs",
        "ios",
        "lawlink@2x.svg",
        "local",
        "local",
        "lockbit",
        "lumma stealer",
        "corruption",
        "state actors",
        "untitled states",
        "installer",
        "intel",
        "makop",
        "malware",
        "silencing",
        "ms windows",
        "human rights",
        "civil rights",
        "retaliation",
        "name servers",
        "next",
        "passive dns",
        "paste",
        "collect contacts",
        "password",
        "unlock phone",
        "ios",
        "apple gateway",
        "android overlay",
        "interfacing",
        "pe32",
        "pegasus",
        "phishing",
        "protect",
        "pulse",
        "pulses",
        "qakbot",
        "quasar",
        "ransomexx",
        "read c",
        "record value",
        "regdword",
        "regsetvalueexa",
        "relacionada",
        "sample",
        "samples",
        "scan endpoints",
        "search",
        "servers",
        "shared",
        "show",
        "ssl certificate",
        "status",
        "stealer",
        "survivor",
        "t1063",
        "targets sa",
        "url",
        "xport",
        "write c",
        "write",
        "win32",
        "whois record",
        "threat",
        "threat analyzer",
        "tlsv1",
        "tracking",
        "united",
        "unknown",
        "urls",
        "urls https",
        "ursnif",
        "v2 document",
        "vanilla-lazyload@12.0.0",
        "vista event"
      ],
      "references": [
        "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
        "cbi.com",
        "deviceinbox.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
        "support.apple.com [nefarious]",
        "caselaw.lawlink.com",
        "http://mail.thyrsus.com/ [phishing]",
        "ppa.launchpad.net [Apple open use]",
        "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
        "1click-uninstaller.informer.com [Apple - access PE]",
        "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:PowerShell/DynamicLoader",
          "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/FormBook",
          "display_name": "ALF:Trojan:Win32/FormBook",
          "target": null
        },
        {
          "id": "Worm:Win32/Bloored.E",
          "display_name": "Worm:Win32/Bloored.E",
          "target": "/malware/Worm:Win32/Bloored.E"
        },
        {
          "id": "Makop",
          "display_name": "Makop",
          "target": null
        },
        {
          "id": "RansomEXX (ELF)",
          "display_name": "RansomEXX (ELF)",
          "target": null
        },
        {
          "id": "Ransom:Win32/Makop",
          "display_name": "Ransom:Win32/Makop",
          "target": "/malware/Ransom:Win32/Makop"
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "PWS:Win32/XPort",
          "display_name": "PWS:Win32/XPort",
          "target": "/malware/PWS:Win32/XPort"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Dark Power",
          "display_name": "Dark Power",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "Pegasus",
          "display_name": "Pegasus",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1562.003",
          "name": "Impair Command History Logging",
          "display_name": "T1562.003 - Impair Command History Logging"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1505.001",
          "name": "SQL Stored Procedures",
          "display_name": "T1505.001 - SQL Stored Procedures"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65bbb998c3b7662e5059b6c2",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1353,
        "URL": 5046,
        "FileHash-MD5": 5182,
        "FileHash-SHA1": 2869,
        "FileHash-SHA256": 4063,
        "hostname": 2471,
        "email": 28,
        "CVE": 2,
        "SSLCertFingerprint": 5
      },
      "indicator_count": 21019,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "57 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65bbb9815816db0de034f3a3",
      "name": "Dark Power - Pegasus |  https://lawlink.com/",
      "description": "Dark Power ransomware first emerged in early 2023. The group engages in multi-extortion, threatening to release victim data for various reasons. Dark Power encrypts the victim's files and requests a ransom payment in exchange for the decryption key. Dark Power's ransom note is distinct from other ransomware campaigns.\n\nPrivilege and other abusive practices considering individuals targeted.",
      "modified": "2024-03-02T13:01:40.418000",
      "created": "2024-02-01T15:32:17.285000",
      "tags": [
        "no expiration",
        "filehashmd5",
        "iocs",
        "next",
        "scan endpoints",
        "all octoseek",
        "create new",
        "pulse use",
        "pdf report",
        "pcap",
        "filehashsha1",
        "filehashsha256",
        "ipv4",
        "expiration",
        "url http",
        "url https",
        "hostname",
        "domain",
        "domain xn",
        "orgid1054",
        "ruen",
        "multiru",
        "multi",
        "fh no",
        "f no",
        "m892175",
        "n1822",
        "contact",
        "contacted",
        "ciphersuite",
        "backdoor",
        "generic malware",
        "mydoom",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "1b@ssl.com",
        "apple",
        "all octoseek",
        "aaaa",
        "access",
        "alerts",
        "analyze",
        "antivirus",
        "apple as714",
        "apple as8075",
        "bootstrap@4.6.2",
        "body",
        "cellebrite",
        "cobalt strike",
        "command and control",
        "content type",
        "core",
        "create c",
        "cyber threat",
        "dark power",
        "privilege",
        "abuse",
        "legal",
        "privilege abuse",
        "preemptive policing",
        "ransomware",
        "dns",
        "worm",
        "network",
        "rat",
        "bat",
        "colorado",
        "douglas county",
        "pd",
        "racism",
        "sexism",
        "cover up",
        "malicious",
        "jeffrey reimer dpt",
        "default",
        "defender",
        "delete c",
        "dnssec",
        "document file",
        "dynamic",
        "dynamicloader",
        "emotet",
        "execution",
        "expiration",
        "date",
        "factory",
        "february",
        "filehash",
        "formbook",
        "hacktool",
        "framing",
        "harstel",
        "florence, co",
        "sherida",
        "spyeye",
        "castle pines",
        "tools",
        "defense",
        "medical malpractice fraud",
        "scheme",
        "tsara brashears",
        "targeting",
        "swatting",
        "high",
        "hostname",
        "hostnames",
        "malicious prosecution",
        "apb",
        "installer",
        "intel",
        "iocs",
        "ios",
        "lawlink@2x.svg",
        "local",
        "local",
        "lockbit",
        "lumma stealer",
        "corruption",
        "state actors",
        "untitled states",
        "installer",
        "intel",
        "makop",
        "malware",
        "silencing",
        "ms windows",
        "human rights",
        "civil rights",
        "retaliation",
        "name servers",
        "next",
        "passive dns",
        "paste",
        "collect contacts",
        "password",
        "unlock phone",
        "ios",
        "apple gateway",
        "android overlay",
        "interfacing",
        "pe32",
        "pegasus",
        "phishing",
        "protect",
        "pulse",
        "pulses",
        "qakbot",
        "quasar",
        "ransomexx",
        "read c",
        "record value",
        "regdword",
        "regsetvalueexa",
        "relacionada",
        "sample",
        "samples",
        "scan endpoints",
        "search",
        "servers",
        "shared",
        "show",
        "ssl certificate",
        "status",
        "stealer",
        "survivor",
        "t1063",
        "targets sa",
        "url",
        "xport",
        "write c",
        "write",
        "win32",
        "whois record",
        "threat",
        "threat analyzer",
        "tlsv1",
        "tracking",
        "united",
        "unknown",
        "urls",
        "urls https",
        "ursnif",
        "v2 document",
        "vanilla-lazyload@12.0.0",
        "vista event"
      ],
      "references": [
        "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
        "cbi.com",
        "deviceinbox.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
        "support.apple.com [nefarious]",
        "caselaw.lawlink.com",
        "http://mail.thyrsus.com/ [phishing]",
        "ppa.launchpad.net [Apple open use]",
        "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
        "1click-uninstaller.informer.com [Apple - access PE]",
        "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:PowerShell/DynamicLoader",
          "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/FormBook",
          "display_name": "ALF:Trojan:Win32/FormBook",
          "target": null
        },
        {
          "id": "Worm:Win32/Bloored.E",
          "display_name": "Worm:Win32/Bloored.E",
          "target": "/malware/Worm:Win32/Bloored.E"
        },
        {
          "id": "Makop",
          "display_name": "Makop",
          "target": null
        },
        {
          "id": "RansomEXX (ELF)",
          "display_name": "RansomEXX (ELF)",
          "target": null
        },
        {
          "id": "Ransom:Win32/Makop",
          "display_name": "Ransom:Win32/Makop",
          "target": "/malware/Ransom:Win32/Makop"
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "PWS:Win32/XPort",
          "display_name": "PWS:Win32/XPort",
          "target": "/malware/PWS:Win32/XPort"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Dark Power",
          "display_name": "Dark Power",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "Pegasus",
          "display_name": "Pegasus",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1562.003",
          "name": "Impair Command History Logging",
          "display_name": "T1562.003 - Impair Command History Logging"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1505.001",
          "name": "SQL Stored Procedures",
          "display_name": "T1505.001 - SQL Stored Procedures"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1353,
        "URL": 5046,
        "FileHash-MD5": 5182,
        "FileHash-SHA1": 2869,
        "FileHash-SHA256": 4063,
        "hostname": 2471,
        "email": 28,
        "CVE": 2,
        "SSLCertFingerprint": 5
      },
      "indicator_count": 21019,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "822 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65bbb98c440c1c45ec12ccdc",
      "name": "Dark Power - Pegasus |  https://lawlink.com/",
      "description": "Dark Power ransomware first emerged in early 2023. The group engages in multi-extortion, threatening to release victim data for various reasons. Dark Power encrypts the victim's files and requests a ransom payment in exchange for the decryption key. Dark Power's ransom note is distinct from other ransomware campaigns.\n\nPrivilege and other abusive practices considering individuals targeted.",
      "modified": "2024-03-02T13:01:40.418000",
      "created": "2024-02-01T15:32:28.063000",
      "tags": [
        "no expiration",
        "filehashmd5",
        "iocs",
        "next",
        "scan endpoints",
        "all octoseek",
        "create new",
        "pulse use",
        "pdf report",
        "pcap",
        "filehashsha1",
        "filehashsha256",
        "ipv4",
        "expiration",
        "url http",
        "url https",
        "hostname",
        "domain",
        "domain xn",
        "orgid1054",
        "ruen",
        "multiru",
        "multi",
        "fh no",
        "f no",
        "m892175",
        "n1822",
        "contact",
        "contacted",
        "ciphersuite",
        "backdoor",
        "generic malware",
        "mydoom",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "1b@ssl.com",
        "apple",
        "all octoseek",
        "aaaa",
        "access",
        "alerts",
        "analyze",
        "antivirus",
        "apple as714",
        "apple as8075",
        "bootstrap@4.6.2",
        "body",
        "cellebrite",
        "cobalt strike",
        "command and control",
        "content type",
        "core",
        "create c",
        "cyber threat",
        "dark power",
        "privilege",
        "abuse",
        "legal",
        "privilege abuse",
        "preemptive policing",
        "ransomware",
        "dns",
        "worm",
        "network",
        "rat",
        "bat",
        "colorado",
        "douglas county",
        "pd",
        "racism",
        "sexism",
        "cover up",
        "malicious",
        "jeffrey reimer dpt",
        "default",
        "defender",
        "delete c",
        "dnssec",
        "document file",
        "dynamic",
        "dynamicloader",
        "emotet",
        "execution",
        "expiration",
        "date",
        "factory",
        "february",
        "filehash",
        "formbook",
        "hacktool",
        "framing",
        "harstel",
        "florence, co",
        "sherida",
        "spyeye",
        "castle pines",
        "tools",
        "defense",
        "medical malpractice fraud",
        "scheme",
        "tsara brashears",
        "targeting",
        "swatting",
        "high",
        "hostname",
        "hostnames",
        "malicious prosecution",
        "apb",
        "installer",
        "intel",
        "iocs",
        "ios",
        "lawlink@2x.svg",
        "local",
        "local",
        "lockbit",
        "lumma stealer",
        "corruption",
        "state actors",
        "untitled states",
        "installer",
        "intel",
        "makop",
        "malware",
        "silencing",
        "ms windows",
        "human rights",
        "civil rights",
        "retaliation",
        "name servers",
        "next",
        "passive dns",
        "paste",
        "collect contacts",
        "password",
        "unlock phone",
        "ios",
        "apple gateway",
        "android overlay",
        "interfacing",
        "pe32",
        "pegasus",
        "phishing",
        "protect",
        "pulse",
        "pulses",
        "qakbot",
        "quasar",
        "ransomexx",
        "read c",
        "record value",
        "regdword",
        "regsetvalueexa",
        "relacionada",
        "sample",
        "samples",
        "scan endpoints",
        "search",
        "servers",
        "shared",
        "show",
        "ssl certificate",
        "status",
        "stealer",
        "survivor",
        "t1063",
        "targets sa",
        "url",
        "xport",
        "write c",
        "write",
        "win32",
        "whois record",
        "threat",
        "threat analyzer",
        "tlsv1",
        "tracking",
        "united",
        "unknown",
        "urls",
        "urls https",
        "ursnif",
        "v2 document",
        "vanilla-lazyload@12.0.0",
        "vista event"
      ],
      "references": [
        "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
        "cbi.com",
        "deviceinbox.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
        "support.apple.com [nefarious]",
        "caselaw.lawlink.com",
        "http://mail.thyrsus.com/ [phishing]",
        "ppa.launchpad.net [Apple open use]",
        "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
        "1click-uninstaller.informer.com [Apple - access PE]",
        "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:PowerShell/DynamicLoader",
          "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/FormBook",
          "display_name": "ALF:Trojan:Win32/FormBook",
          "target": null
        },
        {
          "id": "Worm:Win32/Bloored.E",
          "display_name": "Worm:Win32/Bloored.E",
          "target": "/malware/Worm:Win32/Bloored.E"
        },
        {
          "id": "Makop",
          "display_name": "Makop",
          "target": null
        },
        {
          "id": "RansomEXX (ELF)",
          "display_name": "RansomEXX (ELF)",
          "target": null
        },
        {
          "id": "Ransom:Win32/Makop",
          "display_name": "Ransom:Win32/Makop",
          "target": "/malware/Ransom:Win32/Makop"
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "PWS:Win32/XPort",
          "display_name": "PWS:Win32/XPort",
          "target": "/malware/PWS:Win32/XPort"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Dark Power",
          "display_name": "Dark Power",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "Pegasus",
          "display_name": "Pegasus",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1562.003",
          "name": "Impair Command History Logging",
          "display_name": "T1562.003 - Impair Command History Logging"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1505.001",
          "name": "SQL Stored Procedures",
          "display_name": "T1505.001 - SQL Stored Procedures"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1353,
        "URL": 5046,
        "FileHash-MD5": 5182,
        "FileHash-SHA1": 2869,
        "FileHash-SHA256": 4063,
        "hostname": 2471,
        "email": 28,
        "CVE": 2,
        "SSLCertFingerprint": 5
      },
      "indicator_count": 21019,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "822 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65bbb98d9818cca8f130c195",
      "name": "Dark Power - Pegasus |  https://lawlink.com/",
      "description": "Dark Power ransomware first emerged in early 2023. The group engages in multi-extortion, threatening to release victim data for various reasons. Dark Power encrypts the victim's files and requests a ransom payment in exchange for the decryption key. Dark Power's ransom note is distinct from other ransomware campaigns.\n\nPrivilege and other abusive practices considering individuals targeted.",
      "modified": "2024-03-02T13:01:40.418000",
      "created": "2024-02-01T15:32:29.619000",
      "tags": [
        "no expiration",
        "filehashmd5",
        "iocs",
        "next",
        "scan endpoints",
        "all octoseek",
        "create new",
        "pulse use",
        "pdf report",
        "pcap",
        "filehashsha1",
        "filehashsha256",
        "ipv4",
        "expiration",
        "url http",
        "url https",
        "hostname",
        "domain",
        "domain xn",
        "orgid1054",
        "ruen",
        "multiru",
        "multi",
        "fh no",
        "f no",
        "m892175",
        "n1822",
        "contact",
        "contacted",
        "ciphersuite",
        "backdoor",
        "generic malware",
        "mydoom",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "1b@ssl.com",
        "apple",
        "all octoseek",
        "aaaa",
        "access",
        "alerts",
        "analyze",
        "antivirus",
        "apple as714",
        "apple as8075",
        "bootstrap@4.6.2",
        "body",
        "cellebrite",
        "cobalt strike",
        "command and control",
        "content type",
        "core",
        "create c",
        "cyber threat",
        "dark power",
        "privilege",
        "abuse",
        "legal",
        "privilege abuse",
        "preemptive policing",
        "ransomware",
        "dns",
        "worm",
        "network",
        "rat",
        "bat",
        "colorado",
        "douglas county",
        "pd",
        "racism",
        "sexism",
        "cover up",
        "malicious",
        "jeffrey reimer dpt",
        "default",
        "defender",
        "delete c",
        "dnssec",
        "document file",
        "dynamic",
        "dynamicloader",
        "emotet",
        "execution",
        "expiration",
        "date",
        "factory",
        "february",
        "filehash",
        "formbook",
        "hacktool",
        "framing",
        "harstel",
        "florence, co",
        "sherida",
        "spyeye",
        "castle pines",
        "tools",
        "defense",
        "medical malpractice fraud",
        "scheme",
        "tsara brashears",
        "targeting",
        "swatting",
        "high",
        "hostname",
        "hostnames",
        "malicious prosecution",
        "apb",
        "installer",
        "intel",
        "iocs",
        "ios",
        "lawlink@2x.svg",
        "local",
        "local",
        "lockbit",
        "lumma stealer",
        "corruption",
        "state actors",
        "untitled states",
        "installer",
        "intel",
        "makop",
        "malware",
        "silencing",
        "ms windows",
        "human rights",
        "civil rights",
        "retaliation",
        "name servers",
        "next",
        "passive dns",
        "paste",
        "collect contacts",
        "password",
        "unlock phone",
        "ios",
        "apple gateway",
        "android overlay",
        "interfacing",
        "pe32",
        "pegasus",
        "phishing",
        "protect",
        "pulse",
        "pulses",
        "qakbot",
        "quasar",
        "ransomexx",
        "read c",
        "record value",
        "regdword",
        "regsetvalueexa",
        "relacionada",
        "sample",
        "samples",
        "scan endpoints",
        "search",
        "servers",
        "shared",
        "show",
        "ssl certificate",
        "status",
        "stealer",
        "survivor",
        "t1063",
        "targets sa",
        "url",
        "xport",
        "write c",
        "write",
        "win32",
        "whois record",
        "threat",
        "threat analyzer",
        "tlsv1",
        "tracking",
        "united",
        "unknown",
        "urls",
        "urls https",
        "ursnif",
        "v2 document",
        "vanilla-lazyload@12.0.0",
        "vista event"
      ],
      "references": [
        "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
        "cbi.com",
        "deviceinbox.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
        "support.apple.com [nefarious]",
        "caselaw.lawlink.com",
        "http://mail.thyrsus.com/ [phishing]",
        "ppa.launchpad.net [Apple open use]",
        "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
        "1click-uninstaller.informer.com [Apple - access PE]",
        "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:PowerShell/DynamicLoader",
          "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/FormBook",
          "display_name": "ALF:Trojan:Win32/FormBook",
          "target": null
        },
        {
          "id": "Worm:Win32/Bloored.E",
          "display_name": "Worm:Win32/Bloored.E",
          "target": "/malware/Worm:Win32/Bloored.E"
        },
        {
          "id": "Makop",
          "display_name": "Makop",
          "target": null
        },
        {
          "id": "RansomEXX (ELF)",
          "display_name": "RansomEXX (ELF)",
          "target": null
        },
        {
          "id": "Ransom:Win32/Makop",
          "display_name": "Ransom:Win32/Makop",
          "target": "/malware/Ransom:Win32/Makop"
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "PWS:Win32/XPort",
          "display_name": "PWS:Win32/XPort",
          "target": "/malware/PWS:Win32/XPort"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Dark Power",
          "display_name": "Dark Power",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "Pegasus",
          "display_name": "Pegasus",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1562.003",
          "name": "Impair Command History Logging",
          "display_name": "T1562.003 - Impair Command History Logging"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1505.001",
          "name": "SQL Stored Procedures",
          "display_name": "T1505.001 - SQL Stored Procedures"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1353,
        "URL": 5046,
        "FileHash-MD5": 5182,
        "FileHash-SHA1": 2869,
        "FileHash-SHA256": 4063,
        "hostname": 2471,
        "email": 28,
        "CVE": 2,
        "SSLCertFingerprint": 5
      },
      "indicator_count": 21019,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "822 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65bbb998c3b7662e5059b6c2",
      "name": "Dark Power - Pegasus |  https://lawlink.com/",
      "description": "Dark Power ransomware first emerged in early 2023. The group engages in multi-extortion, threatening to release victim data for various reasons. Dark Power encrypts the victim's files and requests a ransom payment in exchange for the decryption key. Dark Power's ransom note is distinct from other ransomware campaigns.\n\nPrivilege and other abusive practices considering individuals targeted.",
      "modified": "2024-03-02T13:01:40.418000",
      "created": "2024-02-01T15:32:40.759000",
      "tags": [
        "no expiration",
        "filehashmd5",
        "iocs",
        "next",
        "scan endpoints",
        "all octoseek",
        "create new",
        "pulse use",
        "pdf report",
        "pcap",
        "filehashsha1",
        "filehashsha256",
        "ipv4",
        "expiration",
        "url http",
        "url https",
        "hostname",
        "domain",
        "domain xn",
        "orgid1054",
        "ruen",
        "multiru",
        "multi",
        "fh no",
        "f no",
        "m892175",
        "n1822",
        "contact",
        "contacted",
        "ciphersuite",
        "backdoor",
        "generic malware",
        "mydoom",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "1b@ssl.com",
        "apple",
        "all octoseek",
        "aaaa",
        "access",
        "alerts",
        "analyze",
        "antivirus",
        "apple as714",
        "apple as8075",
        "bootstrap@4.6.2",
        "body",
        "cellebrite",
        "cobalt strike",
        "command and control",
        "content type",
        "core",
        "create c",
        "cyber threat",
        "dark power",
        "privilege",
        "abuse",
        "legal",
        "privilege abuse",
        "preemptive policing",
        "ransomware",
        "dns",
        "worm",
        "network",
        "rat",
        "bat",
        "colorado",
        "douglas county",
        "pd",
        "racism",
        "sexism",
        "cover up",
        "malicious",
        "jeffrey reimer dpt",
        "default",
        "defender",
        "delete c",
        "dnssec",
        "document file",
        "dynamic",
        "dynamicloader",
        "emotet",
        "execution",
        "expiration",
        "date",
        "factory",
        "february",
        "filehash",
        "formbook",
        "hacktool",
        "framing",
        "harstel",
        "florence, co",
        "sherida",
        "spyeye",
        "castle pines",
        "tools",
        "defense",
        "medical malpractice fraud",
        "scheme",
        "tsara brashears",
        "targeting",
        "swatting",
        "high",
        "hostname",
        "hostnames",
        "malicious prosecution",
        "apb",
        "installer",
        "intel",
        "iocs",
        "ios",
        "lawlink@2x.svg",
        "local",
        "local",
        "lockbit",
        "lumma stealer",
        "corruption",
        "state actors",
        "untitled states",
        "installer",
        "intel",
        "makop",
        "malware",
        "silencing",
        "ms windows",
        "human rights",
        "civil rights",
        "retaliation",
        "name servers",
        "next",
        "passive dns",
        "paste",
        "collect contacts",
        "password",
        "unlock phone",
        "ios",
        "apple gateway",
        "android overlay",
        "interfacing",
        "pe32",
        "pegasus",
        "phishing",
        "protect",
        "pulse",
        "pulses",
        "qakbot",
        "quasar",
        "ransomexx",
        "read c",
        "record value",
        "regdword",
        "regsetvalueexa",
        "relacionada",
        "sample",
        "samples",
        "scan endpoints",
        "search",
        "servers",
        "shared",
        "show",
        "ssl certificate",
        "status",
        "stealer",
        "survivor",
        "t1063",
        "targets sa",
        "url",
        "xport",
        "write c",
        "write",
        "win32",
        "whois record",
        "threat",
        "threat analyzer",
        "tlsv1",
        "tracking",
        "united",
        "unknown",
        "urls",
        "urls https",
        "ursnif",
        "v2 document",
        "vanilla-lazyload@12.0.0",
        "vista event"
      ],
      "references": [
        "https://lawlink.com/documents/10935/blackbag-technologies-announces-new-release-of-blacklight-forensic-software",
        "cbi.com",
        "deviceinbox.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [iOS unlocker password cracker]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing, apple data collecting, malvertizing]",
        "http://api.steampowered.com/http:/api.steampowered.com/ISteamUser/GetPlayerSummaries/v2/?key=C48A57D233D635FB8F3F10A436ECC1C6&steamids=76561198381531427 [Apple ' Get Player Summary]",
        "support.apple.com [nefarious]",
        "caselaw.lawlink.com",
        "http://mail.thyrsus.com/ [phishing]",
        "ppa.launchpad.net [Apple open use]",
        "http://www.apple.com/certificateauthority/AppleApplicationIntegrationCA5G1.cer [Apple Ubuntu access]",
        "1click-uninstaller.informer.com [Apple - access PE]",
        "http://findbetterresults.com/Merino_Wool_Sweater.cfm?domain=forever-maroc.info&fp=8hY5xppsJcgtsARaT7WA9YWFkv73AgUQdyA1jnNh+yA3h9O8vZwUKqaru+BK8mHlpfLdKQ3uyLeEMmr67cTpI5enUnehh8e08wXWZNWzuUuirPDdezatbM1egtU/y9NvL+vDq1mMMFh/mM2oY2OTk3Q55I/HPDvMg9G5tDB7B2NI1ORnlbH9It49w5nNtE8GPJO62ZrvE7op4RE1uejyAg==&yep=tn+cv4IO28h1WrEcdzQlEs/jm101ce3N5Yd+dISS3zi1qqYLL/bRey5jbLHFBau3HlE+l5mG3OfHGMjIhgUcSjmzkFmO8xF5WIF5bJ3TAo5F28EHKI1Zq/4skZteAEAU5z84hISeRSzcOq5BOh6KqXkJ975lpWA3dnOl6D4sRQWtda/GdACNYKHuxXk56T3vAIxgvjIsOYAJmKp5S"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:PowerShell/DynamicLoader",
          "display_name": "ALF:Trojan:PowerShell/DynamicLoader",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/FormBook",
          "display_name": "ALF:Trojan:Win32/FormBook",
          "target": null
        },
        {
          "id": "Worm:Win32/Bloored.E",
          "display_name": "Worm:Win32/Bloored.E",
          "target": "/malware/Worm:Win32/Bloored.E"
        },
        {
          "id": "Makop",
          "display_name": "Makop",
          "target": null
        },
        {
          "id": "RansomEXX (ELF)",
          "display_name": "RansomEXX (ELF)",
          "target": null
        },
        {
          "id": "Ransom:Win32/Makop",
          "display_name": "Ransom:Win32/Makop",
          "target": "/malware/Ransom:Win32/Makop"
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "PWS:Win32/XPort",
          "display_name": "PWS:Win32/XPort",
          "target": "/malware/PWS:Win32/XPort"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Dark Power",
          "display_name": "Dark Power",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "Pegasus",
          "display_name": "Pegasus",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1562.003",
          "name": "Impair Command History Logging",
          "display_name": "T1562.003 - Impair Command History Logging"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1505.001",
          "name": "SQL Stored Procedures",
          "display_name": "T1505.001 - SQL Stored Procedures"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1353,
        "URL": 5046,
        "FileHash-MD5": 5182,
        "FileHash-SHA1": 2869,
        "FileHash-SHA256": 4063,
        "hostname": 2471,
        "email": 28,
        "CVE": 2,
        "SSLCertFingerprint": 5
      },
      "indicator_count": 21019,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "822 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6552d60aae6e1b3c22455088",
      "name": "Hive 0065",
      "description": "Hive 0065\nURL: https://applemusic-spotlight.myunidays.com/US/en-US?\n\nHive 0065\nHostname: applemusic-spotlight.myunidays.com",
      "modified": "2023-12-13T16:00:45.799000",
      "created": "2023-11-14T02:06:02.329000",
      "tags": [
        "united",
        "as8075",
        "creation date",
        "unknown",
        "search",
        "entries",
        "asnone country",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "related domains",
        "show",
        "domain related",
        "xbox",
        "whois record",
        "contacted",
        "whois whois",
        "ssl certificate",
        "communicating",
        "referrer",
        "execution",
        "historical ssl",
        "bundled",
        "family",
        "lolkek",
        "formbook",
        "skynet",
        "lockbit",
        "ursnif",
        "attack",
        "core"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 4276,
        "email": 3,
        "hostname": 2288,
        "FileHash-MD5": 51,
        "FileHash-SHA1": 49,
        "FileHash-SHA256": 2756,
        "URL": 8696,
        "CVE": 1
      },
      "indicator_count": 18120,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "902 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6552d6f5f56d2e9cd9e18a30",
      "name": "Lolkek \u2022 FormBook \u2022 Lokbit \u2022 Skynet",
      "description": "Hive 0065\nURL: https://applemusic-spotlight.myunidays.com/US/en-US?\n\nHive 0065\nHostname: applemusic-spotlight.myunidays.com",
      "modified": "2023-12-13T16:00:45.799000",
      "created": "2023-11-14T02:09:57.370000",
      "tags": [
        "united",
        "as8075",
        "creation date",
        "unknown",
        "search",
        "entries",
        "asnone country",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "related domains",
        "show",
        "domain related",
        "xbox",
        "whois record",
        "contacted",
        "whois whois",
        "ssl certificate",
        "communicating",
        "referrer",
        "execution",
        "historical ssl",
        "bundled",
        "family",
        "lolkek",
        "formbook",
        "skynet",
        "lockbit",
        "ursnif",
        "attack",
        "core"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 4276,
        "email": 3,
        "hostname": 2288,
        "FileHash-MD5": 51,
        "FileHash-SHA1": 49,
        "FileHash-SHA256": 2756,
        "URL": 8696,
        "CVE": 1
      },
      "indicator_count": 18120,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 225,
      "modified_text": "902 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65568b00198f82af2e88d463",
      "name": "Lolkek \u2022 FormBook \u2022 Lokbit \u2022 Skynet",
      "description": "",
      "modified": "2023-12-13T16:00:45.799000",
      "created": "2023-11-16T21:34:56.016000",
      "tags": [
        "united",
        "as8075",
        "creation date",
        "unknown",
        "search",
        "entries",
        "asnone country",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "related domains",
        "show",
        "domain related",
        "xbox",
        "whois record",
        "contacted",
        "whois whois",
        "ssl certificate",
        "communicating",
        "referrer",
        "execution",
        "historical ssl",
        "bundled",
        "family",
        "lolkek",
        "formbook",
        "skynet",
        "lockbit",
        "ursnif",
        "attack",
        "core"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6552d6f5f56d2e9cd9e18a30",
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 4276,
        "email": 3,
        "hostname": 2288,
        "FileHash-MD5": 51,
        "FileHash-SHA1": 49,
        "FileHash-SHA256": 2756,
        "URL": 8696,
        "CVE": 1
      },
      "indicator_count": 18120,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 231,
      "modified_text": "902 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "airchecklab.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "airchecklab.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780424194.6694736
}