{
  "type": "Domain",
  "indicator": "chamran.ir",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/chamran.ir",
    "alexa": "http://www.alexa.com/siteinfo/chamran.ir",
    "indicator": "chamran.ir",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3901793848,
      "indicator": "chamran.ir",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6679f2e1113c862f469713bc",
          "name": "AS31549 Aria Shatel Company Ltd",
          "description": "",
          "modified": "2025-02-19T02:39:01.166000",
          "created": "2024-06-24T22:27:45.124000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Iran, Islamic Republic of"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2,
            "domain": 2841,
            "hostname": 2145
          },
          "indicator_count": 4988,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 185,
          "modified_text": "469 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6663311a8c529069bb34a06f",
          "name": "Injection | Win.Worm.Mydoom | Ransomware | Android Device attack",
          "description": "Android device, remotely modified, hidden users, 'zombie' device, targeting, framing, unknown admin.",
          "modified": "2024-07-07T15:00:25.739000",
          "created": "2024-06-07T16:11:06.485000",
          "tags": [
            "november",
            "threat roundup",
            "axelo",
            "atkafij0",
            "referrer",
            "historical ssl",
            "dynamicloader",
            "write c",
            "yara rule",
            "delete c",
            "ms windows",
            "medium",
            "yara detections",
            "show",
            "search",
            "united",
            "write",
            "copy",
            "create c",
            "read c",
            "flashpix",
            "high",
            "template",
            "persistence",
            "execution",
            "next",
            "unknown",
            "shared address",
            "html info",
            "title rfc",
            "ipv4 prefix",
            "space meta",
            "tags",
            "prefix",
            "space",
            "script tags",
            "anchor hrefs",
            "sha256",
            "vhash",
            "ssdeep",
            "html internet",
            "magic html",
            "ascii text",
            "magika html",
            "file size",
            "internet",
            "iana",
            "city",
            "los angeles",
            "orgabusephone",
            "orgid",
            "iana ref",
            "net192",
            "net1920000",
            "iana special",
            "detections type",
            "name",
            "win32 exe",
            "runresdll",
            "android",
            "trojan",
            "files",
            "installer",
            "10357",
            "javascript",
            "malibot",
            "pe32",
            "intel",
            "linux x8664",
            "khtml",
            "win32",
            "process32nextw",
            "discovery",
            "discovery t1057",
            "t1057",
            "t1045",
            "memcommit",
            "regopenkeyexw",
            "regsetvalueexa",
            "writeconsolea",
            "minute tr",
            "highest f",
            "regdword",
            "del f",
            "start",
            "memreserve",
            "dock"
          ],
          "references": [
            "http://tools.ietf.org/html/rfc6598 | Found in android device| Block: 100:116.200.0/? [Special Use /Non - IANA]",
            "AV Detection: Win.Downloader.68062-1 | Yara Detections: MS_Visual_Basic_6_0 ,  Cabinet_Archive",
            "High Priority Alerts: dead_host network_icmp dumped_buffer2 nolookup_communication modifies_certificates",
            "Alerts: dumped_buffer network_http allocates_rwx antisandbox_sleep antivm_disk_size exe_appdata antivm_network_adapters privilege_luid_check",
            "Alerts: antivm_queries_computername checks_debugger recon_fingerprint antivm_memory_available",
            "Image: https://otx.alienvault.com/otxapi/indicators/file/screenshot/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811",
            "https://otx.alienvault.com/indicator/file/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811 [Win.Downloader.68062-1]",
            "https://otx.alienvault.com/indicator/file/0000374bffccbcd54ea9a1c51514b671a8caf732ef3bef2cc8cccd4bf01665cf [Win.Worm.Mydoom-5]",
            "Yara Detections: Nrv2x , upx_3 ,  UPX_OEP_place , UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser , UPX",
            "High Priority Alerts: procmem_yara network_bind persistence_autorun",
            "Alerts: dynamic_function_loading powershell_download reads_self suspicious_tld dead_connect",
            "buildbot.tools.ietf.org [Win32:Malware-gen]",
            "Yara Detections: MS_Visual_Cpp_2008 | High Priority Alerts:  dead_host network_icmp",
            "Priority Alerts: dumped_buffer network_http suspicious_tld allocates_rwx creates_exe exe_appdata antivm_network_adapters pe_features",
            "Yara: Detections Skype User-Agent detected, LZMA"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Win.Downloader.68062-1",
              "display_name": "Win.Downloader.68062-1",
              "target": null
            },
            {
              "id": "Win.Worm.Mydoom-5",
              "display_name": "Win.Worm.Mydoom-5",
              "target": null
            },
            {
              "id": "Win32:Trojan-gen",
              "display_name": "Win32:Trojan-gen",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Hera.A!bit",
              "display_name": "Backdoor:Win32/Hera.A!bit",
              "target": "/malware/Backdoor:Win32/Hera.A!bit"
            }
          ],
          "attack_ids": [
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 350,
            "FileHash-SHA1": 318,
            "FileHash-SHA256": 1929,
            "URL": 1885,
            "hostname": 1600,
            "domain": 1380,
            "email": 7,
            "SSLCertFingerprint": 40
          },
          "indicator_count": 7509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 233,
          "modified_text": "695 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Priority Alerts: dumped_buffer network_http suspicious_tld allocates_rwx creates_exe exe_appdata antivm_network_adapters pe_features",
        "High Priority Alerts: dead_host network_icmp dumped_buffer2 nolookup_communication modifies_certificates",
        "Yara Detections: MS_Visual_Cpp_2008 | High Priority Alerts:  dead_host network_icmp",
        "High Priority Alerts: procmem_yara network_bind persistence_autorun",
        "AV Detection: Win.Downloader.68062-1 | Yara Detections: MS_Visual_Basic_6_0 ,  Cabinet_Archive",
        "https://otx.alienvault.com/indicator/file/0000374bffccbcd54ea9a1c51514b671a8caf732ef3bef2cc8cccd4bf01665cf [Win.Worm.Mydoom-5]",
        "buildbot.tools.ietf.org [Win32:Malware-gen]",
        "Yara Detections: Nrv2x , upx_3 ,  UPX_OEP_place , UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser , UPX",
        "http://tools.ietf.org/html/rfc6598 | Found in android device| Block: 100:116.200.0/? [Special Use /Non - IANA]",
        "Alerts: antivm_queries_computername checks_debugger recon_fingerprint antivm_memory_available",
        "Alerts: dumped_buffer network_http allocates_rwx antisandbox_sleep antivm_disk_size exe_appdata antivm_network_adapters privilege_luid_check",
        "Image: https://otx.alienvault.com/otxapi/indicators/file/screenshot/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811",
        "https://otx.alienvault.com/indicator/file/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811 [Win.Downloader.68062-1]",
        "Yara: Detections Skype User-Agent detected, LZMA",
        "Alerts: dynamic_function_loading powershell_download reads_self suspicious_tld dead_connect"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Backdoor:win32/hera.a!bit",
            "Win.downloader.68062-1",
            "Win.worm.mydoom-5",
            "Win32:trojan-gen"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6679f2e1113c862f469713bc",
      "name": "AS31549 Aria Shatel Company Ltd",
      "description": "",
      "modified": "2025-02-19T02:39:01.166000",
      "created": "2024-06-24T22:27:45.124000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Iran, Islamic Republic of"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2,
        "domain": 2841,
        "hostname": 2145
      },
      "indicator_count": 4988,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 185,
      "modified_text": "469 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6663311a8c529069bb34a06f",
      "name": "Injection | Win.Worm.Mydoom | Ransomware | Android Device attack",
      "description": "Android device, remotely modified, hidden users, 'zombie' device, targeting, framing, unknown admin.",
      "modified": "2024-07-07T15:00:25.739000",
      "created": "2024-06-07T16:11:06.485000",
      "tags": [
        "november",
        "threat roundup",
        "axelo",
        "atkafij0",
        "referrer",
        "historical ssl",
        "dynamicloader",
        "write c",
        "yara rule",
        "delete c",
        "ms windows",
        "medium",
        "yara detections",
        "show",
        "search",
        "united",
        "write",
        "copy",
        "create c",
        "read c",
        "flashpix",
        "high",
        "template",
        "persistence",
        "execution",
        "next",
        "unknown",
        "shared address",
        "html info",
        "title rfc",
        "ipv4 prefix",
        "space meta",
        "tags",
        "prefix",
        "space",
        "script tags",
        "anchor hrefs",
        "sha256",
        "vhash",
        "ssdeep",
        "html internet",
        "magic html",
        "ascii text",
        "magika html",
        "file size",
        "internet",
        "iana",
        "city",
        "los angeles",
        "orgabusephone",
        "orgid",
        "iana ref",
        "net192",
        "net1920000",
        "iana special",
        "detections type",
        "name",
        "win32 exe",
        "runresdll",
        "android",
        "trojan",
        "files",
        "installer",
        "10357",
        "javascript",
        "malibot",
        "pe32",
        "intel",
        "linux x8664",
        "khtml",
        "win32",
        "process32nextw",
        "discovery",
        "discovery t1057",
        "t1057",
        "t1045",
        "memcommit",
        "regopenkeyexw",
        "regsetvalueexa",
        "writeconsolea",
        "minute tr",
        "highest f",
        "regdword",
        "del f",
        "start",
        "memreserve",
        "dock"
      ],
      "references": [
        "http://tools.ietf.org/html/rfc6598 | Found in android device| Block: 100:116.200.0/? [Special Use /Non - IANA]",
        "AV Detection: Win.Downloader.68062-1 | Yara Detections: MS_Visual_Basic_6_0 ,  Cabinet_Archive",
        "High Priority Alerts: dead_host network_icmp dumped_buffer2 nolookup_communication modifies_certificates",
        "Alerts: dumped_buffer network_http allocates_rwx antisandbox_sleep antivm_disk_size exe_appdata antivm_network_adapters privilege_luid_check",
        "Alerts: antivm_queries_computername checks_debugger recon_fingerprint antivm_memory_available",
        "Image: https://otx.alienvault.com/otxapi/indicators/file/screenshot/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811",
        "https://otx.alienvault.com/indicator/file/a674df2469cb894b79343bdedfb2068c124746003678826f9281f69887200811 [Win.Downloader.68062-1]",
        "https://otx.alienvault.com/indicator/file/0000374bffccbcd54ea9a1c51514b671a8caf732ef3bef2cc8cccd4bf01665cf [Win.Worm.Mydoom-5]",
        "Yara Detections: Nrv2x , upx_3 ,  UPX_OEP_place , UPX290LZMAMarkusOberhumerLaszloMolnarJohnReiser , UPX",
        "High Priority Alerts: procmem_yara network_bind persistence_autorun",
        "Alerts: dynamic_function_loading powershell_download reads_self suspicious_tld dead_connect",
        "buildbot.tools.ietf.org [Win32:Malware-gen]",
        "Yara Detections: MS_Visual_Cpp_2008 | High Priority Alerts:  dead_host network_icmp",
        "Priority Alerts: dumped_buffer network_http suspicious_tld allocates_rwx creates_exe exe_appdata antivm_network_adapters pe_features",
        "Yara: Detections Skype User-Agent detected, LZMA"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Win.Downloader.68062-1",
          "display_name": "Win.Downloader.68062-1",
          "target": null
        },
        {
          "id": "Win.Worm.Mydoom-5",
          "display_name": "Win.Worm.Mydoom-5",
          "target": null
        },
        {
          "id": "Win32:Trojan-gen",
          "display_name": "Win32:Trojan-gen",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Hera.A!bit",
          "display_name": "Backdoor:Win32/Hera.A!bit",
          "target": "/malware/Backdoor:Win32/Hera.A!bit"
        }
      ],
      "attack_ids": [
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 350,
        "FileHash-SHA1": 318,
        "FileHash-SHA256": 1929,
        "URL": 1885,
        "hostname": 1600,
        "domain": 1380,
        "email": 7,
        "SSLCertFingerprint": 40
      },
      "indicator_count": 7509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 233,
      "modified_text": "695 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "chamran.ir",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "chamran.ir",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780470167.3760831
}