{
  "type": "Domain",
  "indicator": "ashoo.buzz",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/ashoo.buzz",
    "alexa": "http://www.alexa.com/siteinfo/ashoo.buzz",
    "indicator": "ashoo.buzz",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4333499908,
      "indicator": "ashoo.buzz",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "69f32d843b6570c22f6059eb",
          "name": "EbeeApril2026 Pt8",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2026-05-30T10:03:42.474000",
          "created": "2026-04-30T10:23:00.416000",
          "tags": [
            "filehashsha256",
            "filehashmd5",
            "filehashsha1",
            "yara",
            "filepath",
            "cve20221388 url",
            "cve20151770 cve",
            "client"
          ],
          "references": [
            "IOCs.2026.csv"
          ],
          "public": 1,
          "adversary": "Trigona, SHub Stealer v2.0, Malicious Compiled HTML Help File, Vidar",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 95,
            "FileHash-MD5": 163,
            "FileHash-SHA1": 147,
            "FileHash-SHA256": 290,
            "CIDR": 1,
            "CVE": 12,
            "SSLCertFingerprint": 1,
            "domain": 90,
            "email": 2,
            "hostname": 116
          },
          "indicator_count": 917,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 40,
          "modified_text": "12 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f0ec61cd5de4a604aba1f8",
          "name": "Phishing / Brand Impersonation: tut[.]ashoo[.]buzz - Fake copy of legitimate Ashoo platform",
          "description": "The domain tut[.]ashoo[.]buzz operates as a fraudulent impersonation site that copies and misuses the brand, name, and visual elements of the legitimate adult platform Ashoo. The site blocks direct access and only opens when the browser\u2019s Referer header shows it was reached via Google or Yandex search results.",
          "modified": "2026-05-28T17:28:45.507000",
          "created": "2026-04-28T17:20:28.367000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Russian Federation"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "litreevtech",
            "id": "381501",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1,
            "domain": 1
          },
          "indicator_count": 2,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 13,
          "modified_text": "2 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "IOCs.2026.csv"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "Trigona, SHub Stealer v2.0, Malicious Compiled HTML Help File, Vidar"
          ],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "69f32d843b6570c22f6059eb",
      "name": "EbeeApril2026 Pt8",
      "description": "Multiple APT/threat actors, Malware and Campaigns",
      "modified": "2026-05-30T10:03:42.474000",
      "created": "2026-04-30T10:23:00.416000",
      "tags": [
        "filehashsha256",
        "filehashmd5",
        "filehashsha1",
        "yara",
        "filepath",
        "cve20221388 url",
        "cve20151770 cve",
        "client"
      ],
      "references": [
        "IOCs.2026.csv"
      ],
      "public": 1,
      "adversary": "Trigona, SHub Stealer v2.0, Malicious Compiled HTML Help File, Vidar",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 95,
        "FileHash-MD5": 163,
        "FileHash-SHA1": 147,
        "FileHash-SHA256": 290,
        "CIDR": 1,
        "CVE": 12,
        "SSLCertFingerprint": 1,
        "domain": 90,
        "email": 2,
        "hostname": 116
      },
      "indicator_count": 917,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 40,
      "modified_text": "12 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f0ec61cd5de4a604aba1f8",
      "name": "Phishing / Brand Impersonation: tut[.]ashoo[.]buzz - Fake copy of legitimate Ashoo platform",
      "description": "The domain tut[.]ashoo[.]buzz operates as a fraudulent impersonation site that copies and misuses the brand, name, and visual elements of the legitimate adult platform Ashoo. The site blocks direct access and only opens when the browser\u2019s Referer header shows it was reached via Google or Yandex search results.",
      "modified": "2026-05-28T17:28:45.507000",
      "created": "2026-04-28T17:20:28.367000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Russian Federation"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "litreevtech",
        "id": "381501",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1,
        "domain": 1
      },
      "indicator_count": 2,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 13,
      "modified_text": "2 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "ashoo.buzz",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "ashoo.buzz",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780180539.264258
}