{
  "type": "Domain",
  "indicator": "amxrtb.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/amxrtb.com",
    "alexa": "http://www.alexa.com/siteinfo/amxrtb.com",
    "indicator": "amxrtb.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3234660783,
      "indicator": "amxrtb.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "68596260a9ca6c4cc92ca068",
          "name": "Delete service | Affects Threat Research Platforms",
          "description": "Delete service attacking threat researchers platforms. Deletes , blocks, scrambles , attaches to accounts like an overlord monitoring and deletion of Io\u2019s across various platforms. \n\nIDS Rules: PROTOCOL-ICMP PATH MTU denial of service attempt\n\u2022 PROTOCOL-ICMP Destination Unreachable Fragmentation Needed and DF bit was set\n\u2022 Matches rule PROTOCOL-ICMP Echo Reply\nInteresting: TLS: SNI: slscr.update.microsoft.com\nSNI: nexusrules.officeapps.live.com\nSNI: login.live.com\nSNI: client.wns.windows.com",
          "modified": "2025-08-20T04:13:22.641000",
          "created": "2025-06-23T14:19:12.328000",
          "tags": [
            "ta0004 defense",
            "evasion ta0005",
            "command",
            "control ta0011",
            "oc0006",
            "get http",
            "resolved ips",
            "dns resolutions",
            "request",
            "response",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "ip address",
            "country name",
            "cname",
            "port",
            "accept",
            "gmt ifnonematch",
            "url data",
            "icmp",
            "mutexes nothing",
            "data",
            "datacrashpad",
            "edge",
            "created",
            "nothing",
            "html internet",
            "html document",
            "ascii text",
            "gtmkvjvztk dl"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 2401,
            "URL": 5856,
            "FileHash-SHA256": 3473,
            "domain": 2188,
            "FileHash-MD5": 123,
            "FileHash-SHA1": 120,
            "CVE": 2
          },
          "indicator_count": 14163,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 145,
          "modified_text": "287 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68435ff63dc5b9f2bcb15849",
          "name": "https://prebid.a-mo.net/a/c - unknown | malicious content delivery via parked domains | comes and goes",
          "description": "Unknown \n#netify #parked #parkingcrews # \nAdaptMX\nAmazon-02",
          "modified": "2025-07-06T21:04:43.991000",
          "created": "2025-06-06T21:39:02.641000",
          "tags": [
            "v3 serial",
            "number",
            "issuer",
            "cus cnamazon",
            "m02 oamazon",
            "validity",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "x509v3 subject",
            "algorithm",
            "cus oamazon",
            "cnamazon rsa",
            "m03 validity",
            "thumbprint",
            "registrant",
            "record type",
            "ttl value",
            "ip address",
            "as autonomous",
            "system",
            "amazon02",
            "amazonaes",
            "value",
            "asn16509",
            "united",
            "frankfurt",
            "main",
            "germany",
            "screenshot",
            "cisco umbrella",
            "rank",
            "cisco",
            "umbrella rank",
            "resource path",
            "size",
            "type mimetype",
            "primary request",
            "b document",
            "b image",
            "general full",
            "url https",
            "protocol h2",
            "security tls",
            "france",
            "asn60558",
            "reverse dns",
            "software",
            "resource",
            "http",
            "phoenix nap",
            "verified",
            "ecdsa",
            "europeparis",
            "aes128gcm",
            "linux x8664",
            "khtml",
            "gecko",
            "encrypt",
            "amazon rsa",
            "november",
            "size xfer"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 6,
            "FileHash-MD5": 46,
            "FileHash-SHA1": 40,
            "FileHash-SHA256": 1228,
            "URL": 32,
            "hostname": 38,
            "CIDR": 3
          },
          "indicator_count": 1393,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 141,
          "modified_text": "331 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c371e524237b2402a4f6ec",
          "name": "UAlberta (TLD) Compromised",
          "description": "This pulse takes a peak at findings from threatcrowd re: domain of ualberta[.]ca\n-Reported, they will not be fixing anything (likely for a while)\n-Adding this (along with other findings across pulses, collections, etc.), the simple act of visiting this domain is likely to have negative effects on your devices/networks/etc.\n-There is a significant uptick of malicious activity occuring on campus that is going un-addressed\n-The institution is focusing on it's 'SHAPE' program (i.e. getting rid of anyone helpful) in lieu of their efforts to increase student enrollment numbers (slashed & cut IT, no Cybersecurity folks, admin turning the other way). --Staff that have been helpful are all worried about job security (have some help, but they are limited).",
          "modified": "2024-09-18T16:00:13.177000",
          "created": "2024-08-19T16:25:09.228000",
          "tags": [
            "breach",
            "malware",
            "classc",
            "date domain",
            "date ip",
            "address",
            "backdoor",
            "trojan",
            "win32kelihos",
            "malfakeavuf",
            "md5 av",
            "drop",
            "jm3tfliszza",
            "malkelihosa",
            "b3rpr6cpopk",
            "virtool",
            "kryptik"
          ],
          "references": [
            "http://ci-www.threatcrowd.org/domain.php?domain=ualberta.ca",
            "https://viz.greynoise.io/analysis/f973ae84-85c7-4bb5-a6b0-615a422f3b84",
            "https://www.urlvoid.com/scan/ualberta.ca/",
            "https://viz.greynoise.io/query/AS16509",
            "https://otx.alienvault.com/pulse/6647908c09468f42bc1249f1",
            "https://viz.greynoise.io/query/AS3359",
            "https://www.criminalip.io/asset/search?query=ualberta.ca"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [
            {
              "id": "Kryptik",
              "display_name": "Kryptik",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Education",
            "Healthcare",
            "Government",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 164,
            "hostname": 320,
            "FileHash-MD5": 11,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 53,
            "URL": 113,
            "email": 1
          },
          "indicator_count": 663,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 132,
          "modified_text": "623 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708191cdba4e9f07ba1f93",
          "name": "mail.ru:%22,",
          "description": "",
          "modified": "2023-12-06T14:13:36.976000",
          "created": "2023-12-06T14:13:36.976000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 2753,
            "hostname": 1341,
            "domain": 447,
            "URL": 3301,
            "CIDR": 65,
            "FileHash-MD5": 112,
            "FileHash-SHA1": 2
          },
          "indicator_count": 8021,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "622ce493722da2314c26a477",
          "name": "mail.ru:%22,",
          "description": "",
          "modified": "2022-04-11T00:04:29.819000",
          "created": "2022-03-12T18:21:07.131000",
          "tags": [],
          "references": [
            "mail.ru:%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3301,
            "hostname": 1341,
            "domain": 447,
            "FileHash-SHA256": 2753,
            "CIDR": 65,
            "FileHash-MD5": 112,
            "FileHash-SHA1": 2
          },
          "indicator_count": 8021,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1514 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.urlvoid.com/scan/ualberta.ca/",
        "https://viz.greynoise.io/query/AS3359",
        "mail.ru:%22,.pdf",
        "https://otx.alienvault.com/pulse/6647908c09468f42bc1249f1",
        "https://viz.greynoise.io/query/AS16509",
        "https://viz.greynoise.io/analysis/f973ae84-85c7-4bb5-a6b0-615a422f3b84",
        "http://ci-www.threatcrowd.org/domain.php?domain=ualberta.ca",
        "https://www.criminalip.io/asset/search?query=ualberta.ca"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Kryptik"
          ],
          "industries": [
            "Technology",
            "Government",
            "Education",
            "Healthcare"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "68596260a9ca6c4cc92ca068",
      "name": "Delete service | Affects Threat Research Platforms",
      "description": "Delete service attacking threat researchers platforms. Deletes , blocks, scrambles , attaches to accounts like an overlord monitoring and deletion of Io\u2019s across various platforms. \n\nIDS Rules: PROTOCOL-ICMP PATH MTU denial of service attempt\n\u2022 PROTOCOL-ICMP Destination Unreachable Fragmentation Needed and DF bit was set\n\u2022 Matches rule PROTOCOL-ICMP Echo Reply\nInteresting: TLS: SNI: slscr.update.microsoft.com\nSNI: nexusrules.officeapps.live.com\nSNI: login.live.com\nSNI: client.wns.windows.com",
      "modified": "2025-08-20T04:13:22.641000",
      "created": "2025-06-23T14:19:12.328000",
      "tags": [
        "ta0004 defense",
        "evasion ta0005",
        "command",
        "control ta0011",
        "oc0006",
        "get http",
        "resolved ips",
        "dns resolutions",
        "request",
        "response",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "ip address",
        "country name",
        "cname",
        "port",
        "accept",
        "gmt ifnonematch",
        "url data",
        "icmp",
        "mutexes nothing",
        "data",
        "datacrashpad",
        "edge",
        "created",
        "nothing",
        "html internet",
        "html document",
        "ascii text",
        "gtmkvjvztk dl"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 2401,
        "URL": 5856,
        "FileHash-SHA256": 3473,
        "domain": 2188,
        "FileHash-MD5": 123,
        "FileHash-SHA1": 120,
        "CVE": 2
      },
      "indicator_count": 14163,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 145,
      "modified_text": "287 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68435ff63dc5b9f2bcb15849",
      "name": "https://prebid.a-mo.net/a/c - unknown | malicious content delivery via parked domains | comes and goes",
      "description": "Unknown \n#netify #parked #parkingcrews # \nAdaptMX\nAmazon-02",
      "modified": "2025-07-06T21:04:43.991000",
      "created": "2025-06-06T21:39:02.641000",
      "tags": [
        "v3 serial",
        "number",
        "issuer",
        "cus cnamazon",
        "m02 oamazon",
        "validity",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "x509v3 subject",
        "algorithm",
        "cus oamazon",
        "cnamazon rsa",
        "m03 validity",
        "thumbprint",
        "registrant",
        "record type",
        "ttl value",
        "ip address",
        "as autonomous",
        "system",
        "amazon02",
        "amazonaes",
        "value",
        "asn16509",
        "united",
        "frankfurt",
        "main",
        "germany",
        "screenshot",
        "cisco umbrella",
        "rank",
        "cisco",
        "umbrella rank",
        "resource path",
        "size",
        "type mimetype",
        "primary request",
        "b document",
        "b image",
        "general full",
        "url https",
        "protocol h2",
        "security tls",
        "france",
        "asn60558",
        "reverse dns",
        "software",
        "resource",
        "http",
        "phoenix nap",
        "verified",
        "ecdsa",
        "europeparis",
        "aes128gcm",
        "linux x8664",
        "khtml",
        "gecko",
        "encrypt",
        "amazon rsa",
        "november",
        "size xfer"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 6,
        "FileHash-MD5": 46,
        "FileHash-SHA1": 40,
        "FileHash-SHA256": 1228,
        "URL": 32,
        "hostname": 38,
        "CIDR": 3
      },
      "indicator_count": 1393,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 141,
      "modified_text": "331 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66c371e524237b2402a4f6ec",
      "name": "UAlberta (TLD) Compromised",
      "description": "This pulse takes a peak at findings from threatcrowd re: domain of ualberta[.]ca\n-Reported, they will not be fixing anything (likely for a while)\n-Adding this (along with other findings across pulses, collections, etc.), the simple act of visiting this domain is likely to have negative effects on your devices/networks/etc.\n-There is a significant uptick of malicious activity occuring on campus that is going un-addressed\n-The institution is focusing on it's 'SHAPE' program (i.e. getting rid of anyone helpful) in lieu of their efforts to increase student enrollment numbers (slashed & cut IT, no Cybersecurity folks, admin turning the other way). --Staff that have been helpful are all worried about job security (have some help, but they are limited).",
      "modified": "2024-09-18T16:00:13.177000",
      "created": "2024-08-19T16:25:09.228000",
      "tags": [
        "breach",
        "malware",
        "classc",
        "date domain",
        "date ip",
        "address",
        "backdoor",
        "trojan",
        "win32kelihos",
        "malfakeavuf",
        "md5 av",
        "drop",
        "jm3tfliszza",
        "malkelihosa",
        "b3rpr6cpopk",
        "virtool",
        "kryptik"
      ],
      "references": [
        "http://ci-www.threatcrowd.org/domain.php?domain=ualberta.ca",
        "https://viz.greynoise.io/analysis/f973ae84-85c7-4bb5-a6b0-615a422f3b84",
        "https://www.urlvoid.com/scan/ualberta.ca/",
        "https://viz.greynoise.io/query/AS16509",
        "https://otx.alienvault.com/pulse/6647908c09468f42bc1249f1",
        "https://viz.greynoise.io/query/AS3359",
        "https://www.criminalip.io/asset/search?query=ualberta.ca"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [
        {
          "id": "Kryptik",
          "display_name": "Kryptik",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Education",
        "Healthcare",
        "Government",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 164,
        "hostname": 320,
        "FileHash-MD5": 11,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 53,
        "URL": 113,
        "email": 1
      },
      "indicator_count": 663,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 132,
      "modified_text": "623 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708191cdba4e9f07ba1f93",
      "name": "mail.ru:%22,",
      "description": "",
      "modified": "2023-12-06T14:13:36.976000",
      "created": "2023-12-06T14:13:36.976000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 2753,
        "hostname": 1341,
        "domain": 447,
        "URL": 3301,
        "CIDR": 65,
        "FileHash-MD5": 112,
        "FileHash-SHA1": 2
      },
      "indicator_count": 8021,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "622ce493722da2314c26a477",
      "name": "mail.ru:%22,",
      "description": "",
      "modified": "2022-04-11T00:04:29.819000",
      "created": "2022-03-12T18:21:07.131000",
      "tags": [],
      "references": [
        "mail.ru:%22,.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3301,
        "hostname": 1341,
        "domain": 447,
        "FileHash-SHA256": 2753,
        "CIDR": 65,
        "FileHash-MD5": 112,
        "FileHash-SHA1": 2
      },
      "indicator_count": 8021,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 406,
      "modified_text": "1514 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "amxrtb.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "amxrtb.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780508366.7761211
}