{
  "type": "Domain",
  "indicator": "cheffsys.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/cheffsys.com",
    "alexa": "http://www.alexa.com/siteinfo/cheffsys.com",
    "indicator": "cheffsys.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3492303991,
      "indicator": "cheffsys.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 12,
      "pulses": [
        {
          "id": "5fa1ee5c64dc0e2060647954",
          "name": "Malware - Malware Domain Feed V2 - November 03 2020",
          "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
          "modified": "2026-05-31T01:17:54.397000",
          "created": "2020-11-03T23:57:16.317000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 130482,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "otxrobottwo_testing",
            "id": "83138",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45551,
            "domain": 66446
          },
          "indicator_count": 111997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 971,
          "modified_text": "6 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b5461ad2cb2f9e8d342d",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:06.188000",
          "created": "2024-02-06T22:40:06.188000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "844 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b543bc2adfd3eca5ff2b",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:03.501000",
          "created": "2024-02-06T22:40:03.501000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "844 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65c2b5405e6e9e23324e6d8e",
          "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
          "description": "",
          "modified": "2024-02-06T22:40:00.906000",
          "created": "2024-02-06T22:40:00.906000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "5fa1ee5c64dc0e2060647954",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 45530,
            "domain": 66406
          },
          "indicator_count": 111936,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "844 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6372032fca2a16fe4ff0f171",
          "name": "Threat Intel Report - W47-2022.pdf",
          "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
          "modified": "2022-12-14T08:00:12.567000",
          "created": "2022-11-14T08:58:23.798000",
          "tags": [],
          "references": [
            "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_ Real-time",
            "https://www.dnsbl.info/",
            "https://www.spamhaus.org/xbl/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "aa00643640@techmahindra.com",
            "id": "156540",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 79,
            "hostname": 59,
            "FileHash-MD5": 16,
            "FileHash-SHA1": 38,
            "FileHash-SHA256": 26,
            "CVE": 3,
            "URL": 135
          },
          "indicator_count": 356,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 106,
          "modified_text": "1263 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "636ce56b5861d61a50c11523",
          "name": "Threat Spotlight: Cyber Criminal Adoption of IPFS for Phishing, Malware Campaigns",
          "description": "New technologies like the InterPlanetary File System (IPFS) are being used by cybercriminals to host malicious content, including malware and phishing kit, according to Cisco Talos Intelligence.",
          "modified": "2022-12-10T11:02:24.049000",
          "created": "2022-11-10T11:50:03.310000",
          "tags": [
            "grabber",
            "securex",
            "top story",
            "threat spotlight",
            "threats",
            "ipfs",
            "ipfs network",
            "ipfs gateway",
            "python",
            "system",
            "appliance",
            "talos",
            "web3 technology",
            "web3",
            "pe32 executable",
            "discord",
            "swift",
            "powershell"
          ],
          "references": [
            "https://blog.talosintelligence.com/ipfs-abuse/",
            "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_URLs.txt",
            "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_domains.txt",
            "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_ips.txt",
            "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_emails.txt",
            "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_hashes.txt",
            "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_parents.txt",
            "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/ipfs-abuse.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Grabber",
              "display_name": "Grabber",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 28,
            "URL": 70,
            "domain": 66,
            "FileHash-SHA256": 2427,
            "FileHash-MD5": 302,
            "FileHash-SHA1": 302
          },
          "indicator_count": 3195,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 864,
          "modified_text": "1267 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62cbdddd1fc2e2956bfacda5",
          "name": "vvvvv",
          "description": "The internet is full of people, but not everyone wants to see it, so here's a look at some of the more eye-catching snippets from the past few days:..com.",
          "modified": "2022-08-10T00:00:07.214000",
          "created": "2022-07-11T08:22:53.511000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "leiwen15",
            "id": "157128",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_157128/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3662,
            "URL": 250,
            "domain": 1592,
            "FileHash-MD5": 4,
            "email": 2
          },
          "indicator_count": 5510,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 41,
          "modified_text": "1390 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62cbdde0447b9617f24a8901",
          "name": "vvvvv",
          "description": "The internet is full of people, but not everyone wants to see it, so here's a look at some of the more eye-catching snippets from the past few days:..com.",
          "modified": "2022-08-10T00:00:07.214000",
          "created": "2022-07-11T08:22:56.693000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "leiwen15",
            "id": "157128",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_157128/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3662,
            "URL": 250,
            "domain": 1592,
            "FileHash-MD5": 4,
            "email": 2
          },
          "indicator_count": 5510,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 41,
          "modified_text": "1390 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62cbddf0c4709eb7b4d0fb94",
          "name": "data of hhh",
          "description": "The internet is full of people, but not everyone wants to see it, so here's a look at some of the more eye-catching snippets from the past few days:..com.",
          "modified": "2022-08-10T00:00:07.214000",
          "created": "2022-07-11T08:23:12.624000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "leiwen15",
            "id": "157128",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_157128/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3662,
            "URL": 250,
            "domain": 1592,
            "FileHash-MD5": 4,
            "email": 2
          },
          "indicator_count": 5510,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "1390 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62c7fb0f8ab654b1c8ebb621",
          "name": "jintingtingtesttest",
          "description": "A look back at some of the most eye-catching stories of recent weeks, as compiled by the BBC News website, with the help of a handful of key characters:..com.-",
          "modified": "2022-08-07T00:05:43.824000",
          "created": "2022-07-08T09:38:23.587000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "jtt12345",
            "id": "194112",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 4268,
            "URL": 101,
            "FileHash-MD5": 13,
            "FileHash-SHA256": 1,
            "domain": 283
          },
          "indicator_count": 4666,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "1393 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62c7fb0ff1ead7d85fad5e43",
          "name": "jintingtingtesttest",
          "description": "A look back at some of the most eye-catching stories of recent weeks, as compiled by the BBC News website, with the help of a handful of key characters:..com.-",
          "modified": "2022-08-07T00:05:43.824000",
          "created": "2022-07-08T09:38:23.273000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "jtt12345",
            "id": "194112",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 4268,
            "URL": 101,
            "FileHash-MD5": 13,
            "FileHash-SHA256": 1,
            "domain": 283
          },
          "indicator_count": 4666,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "1393 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62c7fb128e18ef22262d95d0",
          "name": "jintingtingtesttest",
          "description": "A look back at some of the most eye-catching stories of recent weeks, as compiled by the BBC News website, with the help of a handful of key characters:..com.-",
          "modified": "2022-08-07T00:05:43.824000",
          "created": "2022-07-08T09:38:26.026000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "jtt12345",
            "id": "194112",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 4268,
            "URL": 101,
            "FileHash-MD5": 13,
            "FileHash-SHA256": 1,
            "domain": 283
          },
          "indicator_count": 4666,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 30,
          "modified_text": "1393 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_parents.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/ipfs-abuse.txt",
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_ Real-time",
        "https://www.spamhaus.org/xbl/",
        "https://www.dnsbl.info/",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_domains.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_ips.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_emails.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_hashes.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_URLs.txt",
        "https://blog.talosintelligence.com/ipfs-abuse/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Grabber"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 12,
  "pulses": [
    {
      "id": "5fa1ee5c64dc0e2060647954",
      "name": "Malware - Malware Domain Feed V2 - November 03 2020",
      "description": "Command and Control domains for Malware. These domains are extracted from a number of sources, and are suspicious.",
      "modified": "2026-05-31T01:17:54.397000",
      "created": "2020-11-03T23:57:16.317000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 130482,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "otxrobottwo_testing",
        "id": "83138",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45551,
        "domain": 66446
      },
      "indicator_count": 111997,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 971,
      "modified_text": "6 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c2b5461ad2cb2f9e8d342d",
      "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
      "description": "",
      "modified": "2024-02-06T22:40:06.188000",
      "created": "2024-02-06T22:40:06.188000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "5fa1ee5c64dc0e2060647954",
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45530,
        "domain": 66406
      },
      "indicator_count": 111936,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "844 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c2b543bc2adfd3eca5ff2b",
      "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
      "description": "",
      "modified": "2024-02-06T22:40:03.501000",
      "created": "2024-02-06T22:40:03.501000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "5fa1ee5c64dc0e2060647954",
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45530,
        "domain": 66406
      },
      "indicator_count": 111936,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "844 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65c2b5405e6e9e23324e6d8e",
      "name": "Malware - Malware Domain Feed V2 - 11.93.2020  [Pulse by otxrobottwo_testing]",
      "description": "",
      "modified": "2024-02-06T22:40:00.906000",
      "created": "2024-02-06T22:40:00.906000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "5fa1ee5c64dc0e2060647954",
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 45530,
        "domain": 66406
      },
      "indicator_count": 111936,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "844 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6372032fca2a16fe4ff0f171",
      "name": "Threat Intel Report - W47-2022.pdf",
      "description": "This is a cyber-advisory document, presenting the compiled cyber threat intelligence sourced from various channels and tools.\nThese are weekly base recommendations to all IT Administrators and CISOs to take corrective actions to upgrade their security infrastructure against newly identified threats and attacks in this week.\nSecurity is a continuous process, and it has to be reviewed and audited on a continuous manner through manual or automated tools.\nThese details may be used as an additional layer to verify the current security posture of an organization against latest cyber trends.",
      "modified": "2022-12-14T08:00:12.567000",
      "created": "2022-11-14T08:58:23.798000",
      "tags": [],
      "references": [
        "https://myip.ms/browse/blacklist/Blacklist_IP_Blacklist_IP_Addresses_Live_Database_ Real-time",
        "https://www.dnsbl.info/",
        "https://www.spamhaus.org/xbl/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "aa00643640@techmahindra.com",
        "id": "156540",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 79,
        "hostname": 59,
        "FileHash-MD5": 16,
        "FileHash-SHA1": 38,
        "FileHash-SHA256": 26,
        "CVE": 3,
        "URL": 135
      },
      "indicator_count": 356,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 106,
      "modified_text": "1263 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "636ce56b5861d61a50c11523",
      "name": "Threat Spotlight: Cyber Criminal Adoption of IPFS for Phishing, Malware Campaigns",
      "description": "New technologies like the InterPlanetary File System (IPFS) are being used by cybercriminals to host malicious content, including malware and phishing kit, according to Cisco Talos Intelligence.",
      "modified": "2022-12-10T11:02:24.049000",
      "created": "2022-11-10T11:50:03.310000",
      "tags": [
        "grabber",
        "securex",
        "top story",
        "threat spotlight",
        "threats",
        "ipfs",
        "ipfs network",
        "ipfs gateway",
        "python",
        "system",
        "appliance",
        "talos",
        "web3 technology",
        "web3",
        "pe32 executable",
        "discord",
        "swift",
        "powershell"
      ],
      "references": [
        "https://blog.talosintelligence.com/ipfs-abuse/",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_URLs.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_domains.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_contacted_ips.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_emails.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_hashes.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/Emotet_parents.txt",
        "https://raw.githubusercontent.com/Cisco-Talos/IOCs/main/2022/11/ipfs-abuse.txt"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Grabber",
          "display_name": "Grabber",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1127",
          "name": "Trusted Developer Utilities Proxy Execution",
          "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "display_name": "T1490 - Inhibit System Recovery"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 28,
        "URL": 70,
        "domain": 66,
        "FileHash-SHA256": 2427,
        "FileHash-MD5": 302,
        "FileHash-SHA1": 302
      },
      "indicator_count": 3195,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 864,
      "modified_text": "1267 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62cbdddd1fc2e2956bfacda5",
      "name": "vvvvv",
      "description": "The internet is full of people, but not everyone wants to see it, so here's a look at some of the more eye-catching snippets from the past few days:..com.",
      "modified": "2022-08-10T00:00:07.214000",
      "created": "2022-07-11T08:22:53.511000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "leiwen15",
        "id": "157128",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_157128/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3662,
        "URL": 250,
        "domain": 1592,
        "FileHash-MD5": 4,
        "email": 2
      },
      "indicator_count": 5510,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 41,
      "modified_text": "1390 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62cbdde0447b9617f24a8901",
      "name": "vvvvv",
      "description": "The internet is full of people, but not everyone wants to see it, so here's a look at some of the more eye-catching snippets from the past few days:..com.",
      "modified": "2022-08-10T00:00:07.214000",
      "created": "2022-07-11T08:22:56.693000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "leiwen15",
        "id": "157128",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_157128/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3662,
        "URL": 250,
        "domain": 1592,
        "FileHash-MD5": 4,
        "email": 2
      },
      "indicator_count": 5510,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 41,
      "modified_text": "1390 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62cbddf0c4709eb7b4d0fb94",
      "name": "data of hhh",
      "description": "The internet is full of people, but not everyone wants to see it, so here's a look at some of the more eye-catching snippets from the past few days:..com.",
      "modified": "2022-08-10T00:00:07.214000",
      "created": "2022-07-11T08:23:12.624000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "leiwen15",
        "id": "157128",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_157128/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3662,
        "URL": 250,
        "domain": 1592,
        "FileHash-MD5": 4,
        "email": 2
      },
      "indicator_count": 5510,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "1390 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62c7fb0f8ab654b1c8ebb621",
      "name": "jintingtingtesttest",
      "description": "A look back at some of the most eye-catching stories of recent weeks, as compiled by the BBC News website, with the help of a handful of key characters:..com.-",
      "modified": "2022-08-07T00:05:43.824000",
      "created": "2022-07-08T09:38:23.587000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "jtt12345",
        "id": "194112",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 4268,
        "URL": 101,
        "FileHash-MD5": 13,
        "FileHash-SHA256": 1,
        "domain": 283
      },
      "indicator_count": 4666,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 30,
      "modified_text": "1393 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "cheffsys.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "cheffsys.com",
    "found": true,
    "verdict": "malicious",
    "url_count": 2,
    "online_count": 0,
    "blacklists": {
      "spamhaus_dbl": "not listed",
      "surbl": "not listed"
    },
    "urls": [
      {
        "url": "https://cheffsys.com/css/5JqXCHJmidSY/",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2022-11-07",
        "tags": [
          "dll",
          "emotet",
          "epoch5",
          "heodo"
        ]
      },
      {
        "url": "https://cheffsys.com/AZOTEA/QpZ/",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2022-06-22",
        "tags": [
          "dll",
          "emotet",
          "epoch5",
          "heodo"
        ]
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780212392.3639703
}