{
  "type": "Domain",
  "indicator": "artsselection.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/artsselection.com",
    "alexa": "http://www.alexa.com/siteinfo/artsselection.com",
    "indicator": "artsselection.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4273131033,
      "indicator": "artsselection.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 7,
      "pulses": [
        {
          "id": "6a1ab6efb8f3c8da4f6b358c",
          "name": "GREYVIBE Threat Actor: TTPs, Malware, and Infrastructure Analysis.",
          "description": "GREYVIBE is a cyber threat actor identified by WithSecure, primarily targeting Ukraine and entities related to Ukraine since August 2025. The group's activities show significant overlaps in their attack infrastructure and operational methodologies, which indicate a persistent campaign aligned with Russian state interests, especially in the context of the Russia-Ukraine war. GREYVIBE's operations have been characterized by the use of various attack vectors, including spear-phishing emails, fake captcha pages, and fraudulent websites impersonating Ukrainian organizations. These methods have facilitated the distribution of malware, predominantly custom-developed variants like PhantomRelay, FallSpy, and LegionRelay.",
          "modified": "2026-05-30T10:12:00.827000",
          "created": "2026-05-30T10:07:43.020000",
          "tags": [
            "research",
            "whitepaper",
            "mohammad kazem hassan nejad",
            "2026",
            "powershell",
            "fallspy",
            "legionrelay",
            "lookvalps",
            "lookvaljs",
            "javascript",
            "daylight",
            "teasoup",
            "android spyware",
            "august",
            "telegram",
            "dronelink",
            "princessclub",
            "phantomrelayv1",
            "greyvibe",
            "domain name",
            "phantommail",
            "sha256",
            "domain",
            "development",
            "phantomclick",
            "club site",
            "teams",
            "kongtuke",
            "april",
            "nsis",
            "service",
            "impacket"
          ],
          "references": [
            "https://labs.withsecure.com/publications/greyvibe"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "LegionRelay",
              "display_name": "LegionRelay",
              "target": null
            },
            {
              "id": "DroneLink",
              "display_name": "DroneLink",
              "target": null
            },
            {
              "id": "PrincessClub",
              "display_name": "PrincessClub",
              "target": null
            },
            {
              "id": "PhantomRelayV1",
              "display_name": "PhantomRelayV1",
              "target": null
            },
            {
              "id": "LOOKVALJS",
              "display_name": "LOOKVALJS",
              "target": null
            },
            {
              "id": "GREYVIBE",
              "display_name": "GREYVIBE",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1021.001",
              "name": "Remote Desktop Protocol",
              "display_name": "T1021.001 - Remote Desktop Protocol"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1059.003",
              "name": "Windows Command Shell",
              "display_name": "T1059.003 - Windows Command Shell"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            }
          ],
          "industries": [
            "Military",
            "Government",
            "Energy"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 55,
            "FileHash-MD5": 14,
            "FileHash-SHA1": 13,
            "FileHash-SHA256": 67,
            "IPv4": 9,
            "URL": 3,
            "hostname": 4
          },
          "indicator_count": 165,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 542,
          "modified_text": "18 hours ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69c29e15bfd8b89822bc6e0a",
          "name": "Payload_Delivery | Mar 25, 2026 | Part 1/2",
          "description": "Payload_Delivery indicators. Date: Mar 25, 2026. Part 1/2. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-03-24T14:22:13.135000",
          "created": "2026-03-24T14:22:13.135000",
          "tags": [
            "payload_delivery"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1220,
            "URL": 297,
            "domain": 226,
            "FileHash-MD5": 6,
            "FileHash-SHA256": 172
          },
          "indicator_count": 1921,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "67 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69c14a170e4aa1f21092ba06",
          "name": "Payload_Delivery | Mar 24, 2026 | Part 1/2",
          "description": "Payload_Delivery indicators. Date: Mar 24, 2026. Part 1/2. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-03-23T14:11:35.782000",
          "created": "2026-03-23T14:11:35.782000",
          "tags": [
            "payload_delivery"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1186,
            "URL": 277,
            "domain": 286,
            "FileHash-SHA256": 177
          },
          "indicator_count": 1926,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "68 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69bff73cca0135cb4158456b",
          "name": "Payload_Delivery | Mar 23, 2026 | Part 1/3",
          "description": "Payload_Delivery indicators. Date: Mar 23, 2026. Part 1/3. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-03-22T14:05:48.988000",
          "created": "2026-03-22T14:05:48.988000",
          "tags": [
            "payload_delivery"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1057,
            "URL": 296,
            "domain": 389,
            "FileHash-SHA256": 182
          },
          "indicator_count": 1924,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "69 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69bea6b498b1d711eef94e6a",
          "name": "Payload_Delivery | Mar 22, 2026 | Part 1/3",
          "description": "Payload_Delivery indicators. Date: Mar 22, 2026. Part 1/3. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-03-21T14:09:56.929000",
          "created": "2026-03-21T14:09:56.929000",
          "tags": [
            "payload_delivery"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 582,
            "domain": 329,
            "hostname": 829,
            "FileHash-SHA256": 185
          },
          "indicator_count": 1925,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "70 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69bd55bf66046b9eb8b55982",
          "name": "Payload_Delivery | Mar 21, 2026 | Part 1/2",
          "description": "Payload_Delivery indicators. Date: Mar 21, 2026. Part 1/2. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-03-20T14:12:14.712000",
          "created": "2026-03-20T14:12:14.712000",
          "tags": [
            "payload_delivery"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 711,
            "domain": 336,
            "hostname": 891,
            "FileHash-SHA256": 46,
            "FileHash-MD5": 10
          },
          "indicator_count": 1994,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "71 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69bc04a5fa5176d8ed9ddee9",
          "name": "Payload_Delivery | Mar 20, 2026 | Part 1/2",
          "description": "Payload_Delivery indicators. Date: Mar 20, 2026. Part 1/2. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-03-19T14:13:57.970000",
          "created": "2026-03-19T14:13:57.970000",
          "tags": [
            "payload_delivery"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 702,
            "URL": 745,
            "domain": 493,
            "FileHash-SHA256": 44,
            "FileHash-MD5": 10
          },
          "indicator_count": 1994,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "72 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://ltna.com.au/cyber",
        "https://labs.withsecure.com/publications/greyvibe"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Dronelink",
            "Phantomrelayv1",
            "Greyvibe",
            "Lookvaljs",
            "Legionrelay",
            "Princessclub"
          ],
          "industries": [
            "Energy",
            "Military",
            "Government"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 7,
  "pulses": [
    {
      "id": "6a1ab6efb8f3c8da4f6b358c",
      "name": "GREYVIBE Threat Actor: TTPs, Malware, and Infrastructure Analysis.",
      "description": "GREYVIBE is a cyber threat actor identified by WithSecure, primarily targeting Ukraine and entities related to Ukraine since August 2025. The group's activities show significant overlaps in their attack infrastructure and operational methodologies, which indicate a persistent campaign aligned with Russian state interests, especially in the context of the Russia-Ukraine war. GREYVIBE's operations have been characterized by the use of various attack vectors, including spear-phishing emails, fake captcha pages, and fraudulent websites impersonating Ukrainian organizations. These methods have facilitated the distribution of malware, predominantly custom-developed variants like PhantomRelay, FallSpy, and LegionRelay.",
      "modified": "2026-05-30T10:12:00.827000",
      "created": "2026-05-30T10:07:43.020000",
      "tags": [
        "research",
        "whitepaper",
        "mohammad kazem hassan nejad",
        "2026",
        "powershell",
        "fallspy",
        "legionrelay",
        "lookvalps",
        "lookvaljs",
        "javascript",
        "daylight",
        "teasoup",
        "android spyware",
        "august",
        "telegram",
        "dronelink",
        "princessclub",
        "phantomrelayv1",
        "greyvibe",
        "domain name",
        "phantommail",
        "sha256",
        "domain",
        "development",
        "phantomclick",
        "club site",
        "teams",
        "kongtuke",
        "april",
        "nsis",
        "service",
        "impacket"
      ],
      "references": [
        "https://labs.withsecure.com/publications/greyvibe"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "LegionRelay",
          "display_name": "LegionRelay",
          "target": null
        },
        {
          "id": "DroneLink",
          "display_name": "DroneLink",
          "target": null
        },
        {
          "id": "PrincessClub",
          "display_name": "PrincessClub",
          "target": null
        },
        {
          "id": "PhantomRelayV1",
          "display_name": "PhantomRelayV1",
          "target": null
        },
        {
          "id": "LOOKVALJS",
          "display_name": "LOOKVALJS",
          "target": null
        },
        {
          "id": "GREYVIBE",
          "display_name": "GREYVIBE",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1021.001",
          "name": "Remote Desktop Protocol",
          "display_name": "T1021.001 - Remote Desktop Protocol"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1059.003",
          "name": "Windows Command Shell",
          "display_name": "T1059.003 - Windows Command Shell"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        }
      ],
      "industries": [
        "Military",
        "Government",
        "Energy"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 55,
        "FileHash-MD5": 14,
        "FileHash-SHA1": 13,
        "FileHash-SHA256": 67,
        "IPv4": 9,
        "URL": 3,
        "hostname": 4
      },
      "indicator_count": 165,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 542,
      "modified_text": "18 hours ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69c29e15bfd8b89822bc6e0a",
      "name": "Payload_Delivery | Mar 25, 2026 | Part 1/2",
      "description": "Payload_Delivery indicators. Date: Mar 25, 2026. Part 1/2. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-03-24T14:22:13.135000",
      "created": "2026-03-24T14:22:13.135000",
      "tags": [
        "payload_delivery"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1220,
        "URL": 297,
        "domain": 226,
        "FileHash-MD5": 6,
        "FileHash-SHA256": 172
      },
      "indicator_count": 1921,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "67 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69c14a170e4aa1f21092ba06",
      "name": "Payload_Delivery | Mar 24, 2026 | Part 1/2",
      "description": "Payload_Delivery indicators. Date: Mar 24, 2026. Part 1/2. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-03-23T14:11:35.782000",
      "created": "2026-03-23T14:11:35.782000",
      "tags": [
        "payload_delivery"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1186,
        "URL": 277,
        "domain": 286,
        "FileHash-SHA256": 177
      },
      "indicator_count": 1926,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "68 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69bff73cca0135cb4158456b",
      "name": "Payload_Delivery | Mar 23, 2026 | Part 1/3",
      "description": "Payload_Delivery indicators. Date: Mar 23, 2026. Part 1/3. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-03-22T14:05:48.988000",
      "created": "2026-03-22T14:05:48.988000",
      "tags": [
        "payload_delivery"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1057,
        "URL": 296,
        "domain": 389,
        "FileHash-SHA256": 182
      },
      "indicator_count": 1924,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "69 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69bea6b498b1d711eef94e6a",
      "name": "Payload_Delivery | Mar 22, 2026 | Part 1/3",
      "description": "Payload_Delivery indicators. Date: Mar 22, 2026. Part 1/3. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-03-21T14:09:56.929000",
      "created": "2026-03-21T14:09:56.929000",
      "tags": [
        "payload_delivery"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 582,
        "domain": 329,
        "hostname": 829,
        "FileHash-SHA256": 185
      },
      "indicator_count": 1925,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "70 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69bd55bf66046b9eb8b55982",
      "name": "Payload_Delivery | Mar 21, 2026 | Part 1/2",
      "description": "Payload_Delivery indicators. Date: Mar 21, 2026. Part 1/2. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-03-20T14:12:14.712000",
      "created": "2026-03-20T14:12:14.712000",
      "tags": [
        "payload_delivery"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 711,
        "domain": 336,
        "hostname": 891,
        "FileHash-SHA256": 46,
        "FileHash-MD5": 10
      },
      "indicator_count": 1994,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "71 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69bc04a5fa5176d8ed9ddee9",
      "name": "Payload_Delivery | Mar 20, 2026 | Part 1/2",
      "description": "Payload_Delivery indicators. Date: Mar 20, 2026. Part 1/2. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-03-19T14:13:57.970000",
      "created": "2026-03-19T14:13:57.970000",
      "tags": [
        "payload_delivery"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 702,
        "URL": 745,
        "domain": 493,
        "FileHash-SHA256": 44,
        "FileHash-MD5": 10
      },
      "indicator_count": 1994,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "72 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "artsselection.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "artsselection.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780200724.2763946
}