{
  "type": "Domain",
  "indicator": "bignight.net",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/bignight.net",
    "alexa": "http://www.alexa.com/siteinfo/bignight.net",
    "indicator": "bignight.net",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3781111763,
      "indicator": "bignight.net",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 8,
      "pulses": [
        {
          "id": "687059a339b3b2a79765dbec",
          "name": "inverte",
          "description": "",
          "modified": "2026-02-01T17:53:50.806000",
          "created": "2025-07-11T00:24:03.079000",
          "tags": [],
          "references": [
            "https://github.com/Abjuri5t/SarlackLab/raw/refs/heads/main/IOCs.csv"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 10129,
            "URL": 14767,
            "domain": 3421,
            "hostname": 7022,
            "CVE": 7
          },
          "indicator_count": 35346,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "118 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "682554f8cb8dd6dce4b839a7",
          "name": "Remcos extra",
          "description": "",
          "modified": "2025-12-25T20:49:21.712000",
          "created": "2025-05-15T02:44:08.231000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1206,
            "domain": 296,
            "hostname": 1036,
            "URL": 1854,
            "CVE": 2
          },
          "indicator_count": 4394,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 182,
          "modified_text": "156 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6775b17c488523ee9d290afd",
          "name": "agressive extra",
          "description": "",
          "modified": "2025-03-17T22:57:49.933000",
          "created": "2025-01-01T21:19:56.847000",
          "tags": [],
          "references": [
            "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 35208,
            "URL": 79504,
            "domain": 19527,
            "hostname": 28058,
            "CVE": 9
          },
          "indicator_count": 162306,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 205,
          "modified_text": "439 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66bb43ce0b5a9b42a54a3498",
          "name": "Threat Intel Report - W31-2024",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2024-09-12T11:00:55.410000",
          "created": "2024-08-13T11:30:22.195000",
          "tags": [
            "mozi",
            "mozi link",
            "week",
            "windows",
            "microsoft",
            "penterac2",
            "russia",
            "germany",
            "cvss",
            "cvss base",
            "spynote",
            "mexico",
            "agent tesla",
            "remcos",
            "snakekeylogger",
            "coinminer",
            "panama",
            "indonesia",
            "asyncrat",
            "panda",
            "android"
          ],
          "references": [
            "https://any.run/malware-trends/",
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 62,
            "hostname": 87,
            "URL": 136,
            "FileHash-MD5": 53,
            "FileHash-SHA1": 53,
            "FileHash-SHA256": 112
          },
          "indicator_count": 503,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 106,
          "modified_text": "626 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66bb43d21b05a860a29b73c0",
          "name": "Threat Intel Report - W31-2024",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2024-09-12T11:00:55.410000",
          "created": "2024-08-13T11:30:26.211000",
          "tags": [
            "mozi",
            "mozi link",
            "week",
            "windows",
            "microsoft",
            "penterac2",
            "russia",
            "germany",
            "cvss",
            "cvss base",
            "spynote",
            "mexico",
            "agent tesla",
            "remcos",
            "snakekeylogger",
            "coinminer",
            "panama",
            "indonesia",
            "asyncrat",
            "panda",
            "android"
          ],
          "references": [
            "https://any.run/malware-trends/",
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 62,
            "hostname": 87,
            "URL": 136,
            "FileHash-MD5": 53,
            "FileHash-SHA1": 53,
            "FileHash-SHA256": 112
          },
          "indicator_count": 503,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 106,
          "modified_text": "626 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66bb43d21eaad50b74da3b82",
          "name": "Threat Intel Report - W31-2024",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2024-09-12T11:00:55.410000",
          "created": "2024-08-13T11:30:26.108000",
          "tags": [
            "mozi",
            "mozi link",
            "week",
            "windows",
            "microsoft",
            "penterac2",
            "russia",
            "germany",
            "cvss",
            "cvss base",
            "spynote",
            "mexico",
            "agent tesla",
            "remcos",
            "snakekeylogger",
            "coinminer",
            "panama",
            "indonesia",
            "asyncrat",
            "panda",
            "android"
          ],
          "references": [
            "https://any.run/malware-trends/",
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 62,
            "hostname": 87,
            "URL": 136,
            "FileHash-MD5": 53,
            "FileHash-SHA1": 53,
            "FileHash-SHA256": 112
          },
          "indicator_count": 503,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 106,
          "modified_text": "626 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6662e7f76f953ff0241a9fd5",
          "name": "Threat Intel Report - W22-2024",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2024-07-07T10:01:50.774000",
          "created": "2024-06-07T10:59:03.288000",
          "tags": [
            "urls https",
            "urls http",
            "sha values",
            "malware url",
            "ip address",
            "blacklist host",
            "domains"
          ],
          "references": [
            "https://any.run/malware-trends/",
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 88,
            "FileHash-MD5": 56,
            "FileHash-SHA1": 56,
            "FileHash-SHA256": 119,
            "URL": 88,
            "domain": 9
          },
          "indicator_count": 416,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 106,
          "modified_text": "693 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66433f6f5494b3625cdc22dc",
          "name": "Threat Intel Report - W17-2024",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2024-06-13T10:01:32.838000",
          "created": "2024-05-14T10:39:42.604000",
          "tags": [
            "mozi",
            "mozi link",
            "stealc",
            "guloader link",
            "bulgaria",
            "canada",
            "urls https",
            "germany",
            "sha values",
            "file name"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse.php?search=.exe",
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 89,
            "FileHash-MD5": 62,
            "FileHash-SHA1": 62,
            "FileHash-SHA256": 119,
            "URL": 167,
            "domain": 26
          },
          "indicator_count": 525,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 106,
          "modified_text": "717 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://github.com/Abjuri5t/SarlackLab/raw/refs/heads/main/IOCs.csv",
        "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time",
        "https://urlhaus.abuse.ch/browse.php?search=.exe",
        "https://any.run/malware-trends/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 8,
  "pulses": [
    {
      "id": "687059a339b3b2a79765dbec",
      "name": "inverte",
      "description": "",
      "modified": "2026-02-01T17:53:50.806000",
      "created": "2025-07-11T00:24:03.079000",
      "tags": [],
      "references": [
        "https://github.com/Abjuri5t/SarlackLab/raw/refs/heads/main/IOCs.csv"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 10129,
        "URL": 14767,
        "domain": 3421,
        "hostname": 7022,
        "CVE": 7
      },
      "indicator_count": 35346,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "118 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "682554f8cb8dd6dce4b839a7",
      "name": "Remcos extra",
      "description": "",
      "modified": "2025-12-25T20:49:21.712000",
      "created": "2025-05-15T02:44:08.231000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1206,
        "domain": 296,
        "hostname": 1036,
        "URL": 1854,
        "CVE": 2
      },
      "indicator_count": 4394,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 182,
      "modified_text": "156 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6775b17c488523ee9d290afd",
      "name": "agressive extra",
      "description": "",
      "modified": "2025-03-17T22:57:49.933000",
      "created": "2025-01-01T21:19:56.847000",
      "tags": [],
      "references": [
        "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 35208,
        "URL": 79504,
        "domain": 19527,
        "hostname": 28058,
        "CVE": 9
      },
      "indicator_count": 162306,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 205,
      "modified_text": "439 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66bb43ce0b5a9b42a54a3498",
      "name": "Threat Intel Report - W31-2024",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2024-09-12T11:00:55.410000",
      "created": "2024-08-13T11:30:22.195000",
      "tags": [
        "mozi",
        "mozi link",
        "week",
        "windows",
        "microsoft",
        "penterac2",
        "russia",
        "germany",
        "cvss",
        "cvss base",
        "spynote",
        "mexico",
        "agent tesla",
        "remcos",
        "snakekeylogger",
        "coinminer",
        "panama",
        "indonesia",
        "asyncrat",
        "panda",
        "android"
      ],
      "references": [
        "https://any.run/malware-trends/",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 62,
        "hostname": 87,
        "URL": 136,
        "FileHash-MD5": 53,
        "FileHash-SHA1": 53,
        "FileHash-SHA256": 112
      },
      "indicator_count": 503,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 106,
      "modified_text": "626 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66bb43d21b05a860a29b73c0",
      "name": "Threat Intel Report - W31-2024",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2024-09-12T11:00:55.410000",
      "created": "2024-08-13T11:30:26.211000",
      "tags": [
        "mozi",
        "mozi link",
        "week",
        "windows",
        "microsoft",
        "penterac2",
        "russia",
        "germany",
        "cvss",
        "cvss base",
        "spynote",
        "mexico",
        "agent tesla",
        "remcos",
        "snakekeylogger",
        "coinminer",
        "panama",
        "indonesia",
        "asyncrat",
        "panda",
        "android"
      ],
      "references": [
        "https://any.run/malware-trends/",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 62,
        "hostname": 87,
        "URL": 136,
        "FileHash-MD5": 53,
        "FileHash-SHA1": 53,
        "FileHash-SHA256": 112
      },
      "indicator_count": 503,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 106,
      "modified_text": "626 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66bb43d21eaad50b74da3b82",
      "name": "Threat Intel Report - W31-2024",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2024-09-12T11:00:55.410000",
      "created": "2024-08-13T11:30:26.108000",
      "tags": [
        "mozi",
        "mozi link",
        "week",
        "windows",
        "microsoft",
        "penterac2",
        "russia",
        "germany",
        "cvss",
        "cvss base",
        "spynote",
        "mexico",
        "agent tesla",
        "remcos",
        "snakekeylogger",
        "coinminer",
        "panama",
        "indonesia",
        "asyncrat",
        "panda",
        "android"
      ],
      "references": [
        "https://any.run/malware-trends/",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 62,
        "hostname": 87,
        "URL": 136,
        "FileHash-MD5": 53,
        "FileHash-SHA1": 53,
        "FileHash-SHA256": 112
      },
      "indicator_count": 503,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 106,
      "modified_text": "626 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6662e7f76f953ff0241a9fd5",
      "name": "Threat Intel Report - W22-2024",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2024-07-07T10:01:50.774000",
      "created": "2024-06-07T10:59:03.288000",
      "tags": [
        "urls https",
        "urls http",
        "sha values",
        "malware url",
        "ip address",
        "blacklist host",
        "domains"
      ],
      "references": [
        "https://any.run/malware-trends/",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 88,
        "FileHash-MD5": 56,
        "FileHash-SHA1": 56,
        "FileHash-SHA256": 119,
        "URL": 88,
        "domain": 9
      },
      "indicator_count": 416,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 106,
      "modified_text": "693 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66433f6f5494b3625cdc22dc",
      "name": "Threat Intel Report - W17-2024",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools. \n\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week. \n\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools. \n\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2024-06-13T10:01:32.838000",
      "created": "2024-05-14T10:39:42.604000",
      "tags": [
        "mozi",
        "mozi link",
        "stealc",
        "guloader link",
        "bulgaria",
        "canada",
        "urls https",
        "germany",
        "sha values",
        "file name"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse.php?search=.exe",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_Real-time"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 89,
        "FileHash-MD5": 62,
        "FileHash-SHA1": 62,
        "FileHash-SHA256": 119,
        "URL": 167,
        "domain": 26
      },
      "indicator_count": 525,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 106,
      "modified_text": "717 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "bignight.net",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "bignight.net",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780237600.2871013
}