{
  "type": "Domain",
  "indicator": "cicispro.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/cicispro.com",
    "alexa": "http://www.alexa.com/siteinfo/cicispro.com",
    "indicator": "cicispro.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3882993608,
      "indicator": "cicispro.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "69efd4fac1df453ecabdac37",
          "name": "CAPTCHA Check",
          "description": "[\"http://172.31.30.27:\n\nThe ip address http://172.31.30.27 is registered by the Internet Assigned Numbers Authority (IANA) as a part of private network 172.31.30.0/24. IP addresses in the private space are not assigned to any specific organization and anybody may use these IP addresses without the consent of a regional Internet registry as described in RFC 1918, unlike public IP addresses.\"]\nOf note, Client does not use a router.",
          "modified": "2026-05-27T22:00:37.280000",
          "created": "2026-04-27T21:28:26.469000",
          "tags": [
            "captcha check",
            "iana",
            "docker",
            "proxy",
            "https://www.proxydocker.com/es/routerpassword/172.31.30.27"
          ],
          "references": [
            "https://www.proxydocker.com/es/routerpassword/172.31.30.27"
          ],
          "public": 1,
          "adversary": "[Unnamed group]",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CIDR": 16,
            "domain": 229,
            "hostname": 472,
            "URL": 233,
            "email": 70,
            "FileHash-SHA256": 27,
            "FileHash-SHA1": 10,
            "URI": 2,
            "FileHash-MD5": 8
          },
          "indicator_count": 1067,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "4 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "695555b664c8998371393b8f",
          "name": "\u200emyMetro App - App Store \u2022 Access Attack via  iOS App",
          "description": "Apple iOS attack. Drive by compromise. Device fully compromised. Service provider incorrect. Device user  does not use MetroPCS as Cellular carrier. \n\n#cyberwarfare #pegasus #endgame #apple #earsinthecornfield #compromised_device #zombie",
          "modified": "2026-01-30T16:01:37.437000",
          "created": "2025-12-31T16:56:22.577000",
          "tags": [
            "espaol",
            "metro pcs",
            "metro",
            "english",
            "data",
            "privacy",
            "learn",
            "requires",
            "strong",
            "see all",
            "bernie",
            "mint",
            "never",
            "example",
            "click",
            "indonesia",
            "\u2019m",
            "win32mydoom dec",
            "united",
            "trojan",
            "name servers",
            "servers",
            "expiration date",
            "backdoor",
            "found",
            "passive dns",
            "gmt connection",
            "control",
            "content type",
            "twitter",
            "title",
            "aaaa",
            "ember cli",
            "ember view",
            "certificate",
            "win32",
            "invalid url",
            "body html",
            "head title",
            "title head",
            "body h1",
            "reference",
            "urls",
            "akamai",
            "unknown ns",
            "domain",
            "search",
            "ipv4",
            "files",
            "reverse dns",
            "location united",
            "america flag",
            "america asn",
            "dynamicloader",
            "port",
            "high",
            "medium",
            "windows",
            "displayname",
            "write",
            "destination",
            "tofsee",
            "stream",
            "malware",
            "hostile",
            "read c",
            "show",
            "rgba",
            "unicode",
            "whitelisted",
            "memcommit",
            "delete",
            "execution",
            "dock",
            "persistence",
            "msie",
            "chrome",
            "ip address",
            "otx telemetry",
            "unknown soa",
            "gmt content",
            "for privacy",
            "moved",
            "record value",
            "ubuntu date",
            "encrypt",
            "a domains",
            "welcome",
            "type",
            "content length",
            "ipv4 add",
            "url analysis",
            "accept",
            "overview domain",
            "files ip",
            "address",
            "location france",
            "asn as16276",
            "tags none",
            "indicator facts",
            "historical otx",
            "france unknown",
            "ovhcloud meta",
            "domain add",
            "present dec",
            "status",
            "service",
            "win32cutwail",
            "setcookie",
            "gmt server",
            "refloadapihash",
            "virtool",
            "present nov",
            "present oct",
            "all ipv4",
            "hostname",
            "present jul",
            "saudi arabia",
            "present mar",
            "present jun",
            "present feb",
            "entries",
            "france asn",
            "asn as16509",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "contacted hosts",
            "pattern match",
            "ascii text",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "sha1",
            "hybrid",
            "local",
            "path",
            "strings",
            "delete c",
            "okrndate",
            "grum",
            "powershell",
            "pegasus",
            "unknown",
            "crlf line",
            "ff d5",
            "unicode text",
            "utf8",
            "ee fc",
            "yara rule",
            "f0 ff",
            "ff bb",
            "push",
            "autorun",
            "suspicious",
            "pulse pulses",
            "date",
            "music",
            "apple",
            "apple id",
            "show process",
            "flag",
            "markmonitor",
            "name tactics",
            "informative",
            "command",
            "adversaries",
            "spawns",
            "access att",
            "t1566 phishing",
            "zerobits",
            "allocationtype",
            "protect",
            "programfiles",
            "processhandle",
            "commitsize",
            "viewsize",
            "regionsize",
            "handles modules",
            "files amsi",
            "filehandle",
            "path filehandle",
            "porthandle",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "href",
            "null",
            "refresh",
            "body",
            "span",
            "general",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "html",
            "x22scriptx22",
            "binary file",
            "t1189",
            "cyberwarfare",
            "brian sabey",
            "never say anything",
            "christopher ahmann",
            "colorado state",
            "quasi",
            "zombie device",
            "present may",
            "emails",
            "exif standard",
            "tiff image",
            "windows nt",
            "wow64",
            "slcc2",
            "media center",
            "jpeg image",
            "copy",
            "next",
            "pecompact",
            "february",
            "packer",
            "delphi",
            "code",
            "tlsv1",
            "ogoogle trust",
            "xserver",
            "lowfi",
            "creation date",
            "domain name",
            "showing",
            "ids detections",
            "yara detections",
            "worm",
            "arial",
            "present aug",
            "meta",
            "dns domain",
            "site",
            "free dns",
            "msil",
            "dnssec",
            "penetration",
            "injections",
            "dead host"
          ],
          "references": [
            "https://apps.apple.com/app/",
            "metropcs.com/account/sign-in.html",
            "smtp.google.com \u2022 www.google.com/images/errors/robot.png",
            "https://www.endgamesystems.com/ \u2022 https://www.endgames.com/",
            "https://freedns.afraid.org/images/exclamation",
            "xred.mooo.com \u2022 mooo.com \u2022 afraid.org",
            "admin@bigtits.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "\u2019m",
              "display_name": "\u2019m",
              "target": null
            },
            {
              "id": "Win.Malware.Jaik-9968280-0",
              "display_name": "Win.Malware.Jaik-9968280-0",
              "target": null
            },
            {
              "id": "Worm:Win32/Mydoom",
              "display_name": "Worm:Win32/Mydoom",
              "target": "/malware/Worm:Win32/Mydoom"
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "Win.Trojan.Installcore-877",
              "display_name": "Win.Trojan.Installcore-877",
              "target": null
            },
            {
              "id": "Win.Downloader.Small",
              "display_name": "Win.Downloader.Small",
              "target": null
            },
            {
              "id": "Win.Trojan.Barys-10005825-0",
              "display_name": "Win.Trojan.Barys-10005825-0",
              "target": null
            },
            {
              "id": "Tibs",
              "display_name": "Tibs",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Cutwail",
              "display_name": "TrojanDownloader:Win32/Cutwail",
              "target": "/malware/TrojanDownloader:Win32/Cutwail"
            },
            {
              "id": "Worm:Win32/Autorun",
              "display_name": "Worm:Win32/Autorun",
              "target": "/malware/Worm:Win32/Autorun"
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "ALF:JASYP:PUA:Win32/4Shared",
              "display_name": "ALF:JASYP:PUA:Win32/4Shared",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1418",
              "name": "Application Discovery",
              "display_name": "T1418 - Application Discovery"
            },
            {
              "id": "T1444",
              "name": "Masquerade as Legitimate Application",
              "display_name": "T1444 - Masquerade as Legitimate Application"
            },
            {
              "id": "T1456",
              "name": "Drive-by Compromise",
              "display_name": "T1456 - Drive-by Compromise"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1557",
              "name": "Man-in-the-Middle",
              "display_name": "T1557 - Man-in-the-Middle"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1589",
              "name": "Gather Victim Identity Information",
              "display_name": "T1589 - Gather Victim Identity Information"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1592",
              "name": "Gather Victim Host Information",
              "display_name": "T1592 - Gather Victim Host Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1147",
              "name": "Hidden Users",
              "display_name": "T1147 - Hidden Users"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1195.001",
              "name": "Compromise Software Dependencies and Development Tools",
              "display_name": "T1195.001 - Compromise Software Dependencies and Development Tools"
            },
            {
              "id": "T1577",
              "name": "Compromise Application Executable",
              "display_name": "T1577 - Compromise Application Executable"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1086",
              "name": "PowerShell",
              "display_name": "T1086 - PowerShell"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1863,
            "URL": 4952,
            "FileHash-SHA256": 1990,
            "FileHash-MD5": 981,
            "FileHash-SHA1": 791,
            "email": 26,
            "domain": 1277,
            "SSLCertFingerprint": 24
          },
          "indicator_count": 11904,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 147,
          "modified_text": "121 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "688ae705371a43d76d8f6e69",
          "name": "Trojan:Win32/Comisproc",
          "description": "Trojan:Win32/Comisproc!gmb\n[https://www.smsrl.it/en/foundry-toolings/prototypes/sand-casting/]\nFrom  previous Hostile Denver community\u2019s pulse \u2018Vashti\u2019 public.Hi!\nI am Vashti. Named after a Queen  married to a perverted King who after weeks of rimless and gluttony asked his wife the Queen to reveal herself to the men in his \u2018freak off\u2019 like a true lady she refused and was dethroned. Not a Queens obligation to  this. She stood for her rights. He later married a child named Queen Esther.\n#Vashti_said_tell_your_ cat_i_said_hi #foundry  #hitmen #comispro #denver #uptown #levelblue",
          "modified": "2025-08-30T03:00:57.020000",
          "created": "2025-07-31T03:46:13.849000",
          "tags": [
            "italy unknown",
            "unknown ns",
            "united",
            "moved",
            "ip address",
            "creation date",
            "encrypt",
            "search",
            "record value",
            "entries",
            "body",
            "date",
            "passive dns",
            "urls",
            "url add",
            "pulse pulses",
            "http",
            "hostname",
            "files domain",
            "files related",
            "pulses none",
            "related tags",
            "a domains",
            "present jul",
            "showing",
            "domains",
            "domain add",
            "meta",
            "encrypt free",
            "research group",
            "isrg",
            "next http",
            "scans show",
            "extraction",
            "data upload",
            "extra",
            "source ur",
            "include data",
            "type",
            "extra data",
            "msie",
            "windows nt",
            "win64",
            "slcc2",
            "media center",
            "tlsv1",
            "show",
            "unknown",
            "trojan",
            "copy",
            "write",
            "malware",
            "hostile",
            "present may",
            "checked url",
            "hostname server",
            "response ip",
            "address google",
            "safe browsing",
            "present jun",
            "next associated",
            "medium",
            "high",
            "a file",
            "ms defender",
            "files matching",
            "number",
            "sample analysis",
            "hide samples",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "defense evasion",
            "command",
            "mitre att",
            "ck techniques",
            "ascii text",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "size",
            "sha1",
            "sha256",
            "pattern match",
            "jfif",
            "exif standard",
            "core",
            "hybrid",
            "general",
            "local",
            "path",
            "click",
            "strings",
            "format"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1088,
            "hostname": 407,
            "domain": 621,
            "FileHash-SHA1": 156,
            "FileHash-SHA256": 1498,
            "email": 2,
            "FileHash-MD5": 204,
            "SSLCertFingerprint": 11
          },
          "indicator_count": 3987,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "metropcs.com/account/sign-in.html",
        "admin@bigtits.com",
        "https://www.endgamesystems.com/ \u2022 https://www.endgames.com/",
        "https://apps.apple.com/app/",
        "xred.mooo.com \u2022 mooo.com \u2022 afraid.org",
        "https://freedns.afraid.org/images/exclamation",
        "https://www.proxydocker.com/es/routerpassword/172.31.30.27",
        "smtp.google.com \u2022 www.google.com/images/errors/robot.png"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "[Unnamed group]"
          ],
          "malware_families": [
            "Tofsee",
            "Tibs",
            "Alf:jasyp:pua:win32/4shared",
            "Win.trojan.installcore-877",
            "Win.downloader.small",
            "Emotet",
            "\u2019m",
            "Win.trojan.barys-10005825-0",
            "Worm:win32/autorun",
            "Trojandownloader:win32/cutwail",
            "Worm:win32/mydoom",
            "Win.malware.jaik-9968280-0"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "69efd4fac1df453ecabdac37",
      "name": "CAPTCHA Check",
      "description": "[\"http://172.31.30.27:\n\nThe ip address http://172.31.30.27 is registered by the Internet Assigned Numbers Authority (IANA) as a part of private network 172.31.30.0/24. IP addresses in the private space are not assigned to any specific organization and anybody may use these IP addresses without the consent of a regional Internet registry as described in RFC 1918, unlike public IP addresses.\"]\nOf note, Client does not use a router.",
      "modified": "2026-05-27T22:00:37.280000",
      "created": "2026-04-27T21:28:26.469000",
      "tags": [
        "captcha check",
        "iana",
        "docker",
        "proxy",
        "https://www.proxydocker.com/es/routerpassword/172.31.30.27"
      ],
      "references": [
        "https://www.proxydocker.com/es/routerpassword/172.31.30.27"
      ],
      "public": 1,
      "adversary": "[Unnamed group]",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CIDR": 16,
        "domain": 229,
        "hostname": 472,
        "URL": 233,
        "email": 70,
        "FileHash-SHA256": 27,
        "FileHash-SHA1": 10,
        "URI": 2,
        "FileHash-MD5": 8
      },
      "indicator_count": 1067,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "4 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "695555b664c8998371393b8f",
      "name": "\u200emyMetro App - App Store \u2022 Access Attack via  iOS App",
      "description": "Apple iOS attack. Drive by compromise. Device fully compromised. Service provider incorrect. Device user  does not use MetroPCS as Cellular carrier. \n\n#cyberwarfare #pegasus #endgame #apple #earsinthecornfield #compromised_device #zombie",
      "modified": "2026-01-30T16:01:37.437000",
      "created": "2025-12-31T16:56:22.577000",
      "tags": [
        "espaol",
        "metro pcs",
        "metro",
        "english",
        "data",
        "privacy",
        "learn",
        "requires",
        "strong",
        "see all",
        "bernie",
        "mint",
        "never",
        "example",
        "click",
        "indonesia",
        "\u2019m",
        "win32mydoom dec",
        "united",
        "trojan",
        "name servers",
        "servers",
        "expiration date",
        "backdoor",
        "found",
        "passive dns",
        "gmt connection",
        "control",
        "content type",
        "twitter",
        "title",
        "aaaa",
        "ember cli",
        "ember view",
        "certificate",
        "win32",
        "invalid url",
        "body html",
        "head title",
        "title head",
        "body h1",
        "reference",
        "urls",
        "akamai",
        "unknown ns",
        "domain",
        "search",
        "ipv4",
        "files",
        "reverse dns",
        "location united",
        "america flag",
        "america asn",
        "dynamicloader",
        "port",
        "high",
        "medium",
        "windows",
        "displayname",
        "write",
        "destination",
        "tofsee",
        "stream",
        "malware",
        "hostile",
        "read c",
        "show",
        "rgba",
        "unicode",
        "whitelisted",
        "memcommit",
        "delete",
        "execution",
        "dock",
        "persistence",
        "msie",
        "chrome",
        "ip address",
        "otx telemetry",
        "unknown soa",
        "gmt content",
        "for privacy",
        "moved",
        "record value",
        "ubuntu date",
        "encrypt",
        "a domains",
        "welcome",
        "type",
        "content length",
        "ipv4 add",
        "url analysis",
        "accept",
        "overview domain",
        "files ip",
        "address",
        "location france",
        "asn as16276",
        "tags none",
        "indicator facts",
        "historical otx",
        "france unknown",
        "ovhcloud meta",
        "domain add",
        "present dec",
        "status",
        "service",
        "win32cutwail",
        "setcookie",
        "gmt server",
        "refloadapihash",
        "virtool",
        "present nov",
        "present oct",
        "all ipv4",
        "hostname",
        "present jul",
        "saudi arabia",
        "present mar",
        "present jun",
        "present feb",
        "entries",
        "france asn",
        "asn as16509",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "contacted hosts",
        "pattern match",
        "ascii text",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "sha1",
        "hybrid",
        "local",
        "path",
        "strings",
        "delete c",
        "okrndate",
        "grum",
        "powershell",
        "pegasus",
        "unknown",
        "crlf line",
        "ff d5",
        "unicode text",
        "utf8",
        "ee fc",
        "yara rule",
        "f0 ff",
        "ff bb",
        "push",
        "autorun",
        "suspicious",
        "pulse pulses",
        "date",
        "music",
        "apple",
        "apple id",
        "show process",
        "flag",
        "markmonitor",
        "name tactics",
        "informative",
        "command",
        "adversaries",
        "spawns",
        "access att",
        "t1566 phishing",
        "zerobits",
        "allocationtype",
        "protect",
        "programfiles",
        "processhandle",
        "commitsize",
        "viewsize",
        "regionsize",
        "handles modules",
        "files amsi",
        "filehandle",
        "path filehandle",
        "porthandle",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "href",
        "null",
        "refresh",
        "body",
        "span",
        "general",
        "error",
        "tools",
        "look",
        "verify",
        "restart",
        "html",
        "x22scriptx22",
        "binary file",
        "t1189",
        "cyberwarfare",
        "brian sabey",
        "never say anything",
        "christopher ahmann",
        "colorado state",
        "quasi",
        "zombie device",
        "present may",
        "emails",
        "exif standard",
        "tiff image",
        "windows nt",
        "wow64",
        "slcc2",
        "media center",
        "jpeg image",
        "copy",
        "next",
        "pecompact",
        "february",
        "packer",
        "delphi",
        "code",
        "tlsv1",
        "ogoogle trust",
        "xserver",
        "lowfi",
        "creation date",
        "domain name",
        "showing",
        "ids detections",
        "yara detections",
        "worm",
        "arial",
        "present aug",
        "meta",
        "dns domain",
        "site",
        "free dns",
        "msil",
        "dnssec",
        "penetration",
        "injections",
        "dead host"
      ],
      "references": [
        "https://apps.apple.com/app/",
        "metropcs.com/account/sign-in.html",
        "smtp.google.com \u2022 www.google.com/images/errors/robot.png",
        "https://www.endgamesystems.com/ \u2022 https://www.endgames.com/",
        "https://freedns.afraid.org/images/exclamation",
        "xred.mooo.com \u2022 mooo.com \u2022 afraid.org",
        "admin@bigtits.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "\u2019m",
          "display_name": "\u2019m",
          "target": null
        },
        {
          "id": "Win.Malware.Jaik-9968280-0",
          "display_name": "Win.Malware.Jaik-9968280-0",
          "target": null
        },
        {
          "id": "Worm:Win32/Mydoom",
          "display_name": "Worm:Win32/Mydoom",
          "target": "/malware/Worm:Win32/Mydoom"
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "Win.Trojan.Installcore-877",
          "display_name": "Win.Trojan.Installcore-877",
          "target": null
        },
        {
          "id": "Win.Downloader.Small",
          "display_name": "Win.Downloader.Small",
          "target": null
        },
        {
          "id": "Win.Trojan.Barys-10005825-0",
          "display_name": "Win.Trojan.Barys-10005825-0",
          "target": null
        },
        {
          "id": "Tibs",
          "display_name": "Tibs",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Cutwail",
          "display_name": "TrojanDownloader:Win32/Cutwail",
          "target": "/malware/TrojanDownloader:Win32/Cutwail"
        },
        {
          "id": "Worm:Win32/Autorun",
          "display_name": "Worm:Win32/Autorun",
          "target": "/malware/Worm:Win32/Autorun"
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "ALF:JASYP:PUA:Win32/4Shared",
          "display_name": "ALF:JASYP:PUA:Win32/4Shared",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1418",
          "name": "Application Discovery",
          "display_name": "T1418 - Application Discovery"
        },
        {
          "id": "T1444",
          "name": "Masquerade as Legitimate Application",
          "display_name": "T1444 - Masquerade as Legitimate Application"
        },
        {
          "id": "T1456",
          "name": "Drive-by Compromise",
          "display_name": "T1456 - Drive-by Compromise"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1069.002",
          "name": "Domain Groups",
          "display_name": "T1069.002 - Domain Groups"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1557",
          "name": "Man-in-the-Middle",
          "display_name": "T1557 - Man-in-the-Middle"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1589",
          "name": "Gather Victim Identity Information",
          "display_name": "T1589 - Gather Victim Identity Information"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1592",
          "name": "Gather Victim Host Information",
          "display_name": "T1592 - Gather Victim Host Information"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1147",
          "name": "Hidden Users",
          "display_name": "T1147 - Hidden Users"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1195.001",
          "name": "Compromise Software Dependencies and Development Tools",
          "display_name": "T1195.001 - Compromise Software Dependencies and Development Tools"
        },
        {
          "id": "T1577",
          "name": "Compromise Application Executable",
          "display_name": "T1577 - Compromise Application Executable"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1086",
          "name": "PowerShell",
          "display_name": "T1086 - PowerShell"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1863,
        "URL": 4952,
        "FileHash-SHA256": 1990,
        "FileHash-MD5": 981,
        "FileHash-SHA1": 791,
        "email": 26,
        "domain": 1277,
        "SSLCertFingerprint": 24
      },
      "indicator_count": 11904,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 147,
      "modified_text": "121 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "688ae705371a43d76d8f6e69",
      "name": "Trojan:Win32/Comisproc",
      "description": "Trojan:Win32/Comisproc!gmb\n[https://www.smsrl.it/en/foundry-toolings/prototypes/sand-casting/]\nFrom  previous Hostile Denver community\u2019s pulse \u2018Vashti\u2019 public.Hi!\nI am Vashti. Named after a Queen  married to a perverted King who after weeks of rimless and gluttony asked his wife the Queen to reveal herself to the men in his \u2018freak off\u2019 like a true lady she refused and was dethroned. Not a Queens obligation to  this. She stood for her rights. He later married a child named Queen Esther.\n#Vashti_said_tell_your_ cat_i_said_hi #foundry  #hitmen #comispro #denver #uptown #levelblue",
      "modified": "2025-08-30T03:00:57.020000",
      "created": "2025-07-31T03:46:13.849000",
      "tags": [
        "italy unknown",
        "unknown ns",
        "united",
        "moved",
        "ip address",
        "creation date",
        "encrypt",
        "search",
        "record value",
        "entries",
        "body",
        "date",
        "passive dns",
        "urls",
        "url add",
        "pulse pulses",
        "http",
        "hostname",
        "files domain",
        "files related",
        "pulses none",
        "related tags",
        "a domains",
        "present jul",
        "showing",
        "domains",
        "domain add",
        "meta",
        "encrypt free",
        "research group",
        "isrg",
        "next http",
        "scans show",
        "extraction",
        "data upload",
        "extra",
        "source ur",
        "include data",
        "type",
        "extra data",
        "msie",
        "windows nt",
        "win64",
        "slcc2",
        "media center",
        "tlsv1",
        "show",
        "unknown",
        "trojan",
        "copy",
        "write",
        "malware",
        "hostile",
        "present may",
        "checked url",
        "hostname server",
        "response ip",
        "address google",
        "safe browsing",
        "present jun",
        "next associated",
        "medium",
        "high",
        "a file",
        "ms defender",
        "files matching",
        "number",
        "sample analysis",
        "hide samples",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "defense evasion",
        "command",
        "mitre att",
        "ck techniques",
        "ascii text",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "size",
        "sha1",
        "sha256",
        "pattern match",
        "jfif",
        "exif standard",
        "core",
        "hybrid",
        "general",
        "local",
        "path",
        "click",
        "strings",
        "format"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1088,
        "hostname": 407,
        "domain": 621,
        "FileHash-SHA1": 156,
        "FileHash-SHA256": 1498,
        "email": 2,
        "FileHash-MD5": 204,
        "SSLCertFingerprint": 11
      },
      "indicator_count": 3987,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "274 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "cicispro.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "cicispro.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780274276.3168821
}