{
  "type": "Domain",
  "indicator": "cobaconstruct.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/cobaconstruct.com",
    "alexa": "http://www.alexa.com/siteinfo/cobaconstruct.com",
    "indicator": "cobaconstruct.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4107665158,
      "indicator": "cobaconstruct.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "690af480b45560b4ae78a863",
          "name": "Mirai \u2022 Cycbot - Who is Dennis Schroeder (303) 444-4444 | Social Engineering ~ Legal",
          "description": "Mirai \u2022\nCycBot. Hackers connected\nto targets phone intercepting calls. |\nHi Dennis, how the heck are you? Who are you? We connected targets former phone to a lawyer to become familiar with botnet experience. Time spent speaking to several fraudulent people who pretend to be people they are not. \n\nFrom our side: A factual account was given to a professional sounding female phone actor who answered call without giving name of law firm or her own name / title , listened for some time , few screening questions, no one in \u2018 law firm\u2019 didn\u2019t know statutes of limitations.\n\nSad there was never a way for  target to contact find legitimate legal representation due to being in multiple botnets. \n Very disturbing. \n\n#colorado_government",
          "modified": "2025-12-05T06:05:48.164000",
          "created": "2025-11-05T06:53:52.767000",
          "tags": [
            "url https",
            "url http",
            "related pulses",
            "united",
            "redacted for",
            "meta",
            "accept encoding",
            "moved",
            "ip address",
            "record value",
            "encrypt",
            "backdoor",
            "trojandropper",
            "passive dns",
            "mtb oct",
            "ipv4 add",
            "urls",
            "twitter",
            "trojan",
            "cycbot",
            "dynamicloader",
            "medium",
            "ms windows",
            "write",
            "yara rule",
            "named pipe",
            "pe32",
            "defender",
            "install",
            "smartassembly",
            "malware",
            "local",
            "dns query",
            "xxx adult",
            "site top",
            "level domain",
            "total",
            "whitelisted",
            "yara detections",
            "dyndns domain",
            "filehash",
            "av detections",
            "ids detections",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "acceptencoding",
            "as46606",
            "xserver",
            "killer gecko",
            "host",
            "hello2malware",
            "cnlocalhost",
            "dclocal",
            "guard",
            "url analysis",
            "files",
            "reverse dns",
            "azerbaijan asn",
            "asnone related",
            "destination",
            "port",
            "unknown",
            "et smtp",
            "message",
            "united kingdom",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "found",
            "newremotehost",
            "newexternalport",
            "newprotocol",
            "newinternalport",
            "helloworld",
            "nids",
            "high",
            "ddos",
            "hstr",
            "mtb nov",
            "ransom",
            "msie",
            "chrome",
            "gmt content",
            "hostname add",
            "present jun",
            "germany unknown",
            "domain add",
            "asn as24940",
            "germany asn",
            "domain",
            "files ip",
            "address",
            "less",
            "script urls",
            "dennis schrder",
            "a domains",
            "prox",
            "aaaa",
            "present nov",
            "blog von",
            "apache",
            "dennis schroder",
            "servers",
            "emails",
            "dnssec",
            "as197540",
            "dns resolutions",
            "hostname",
            "verdict",
            "present",
            "directui",
            "element",
            "classinfobase",
            "write c",
            "getclassinfoptr",
            "sgpauiclassinfo",
            "file v2",
            "document",
            "explorer",
            "movie",
            "insert",
            "mitre att",
            "ck matrix",
            "path",
            "hybrid",
            "general",
            "iframe",
            "click",
            "strings",
            "forbidden",
            "default",
            "pdf library",
            "delete c",
            "https domain",
            "tls sni",
            "steals",
            "format",
            "for privacy",
            "name servers",
            "date",
            "japan unknown",
            "entries",
            "next associated",
            "gmt etag",
            "pragma",
            "body",
            "accept",
            "script domains",
            "gmt cache",
            "certificate",
            "alerts",
            "analysis date",
            "file score",
            "present sep",
            "iemobile",
            "ok accept",
            "mirai",
            "cdn.calltrk.com",
            "type indicator"
          ],
          "references": [
            "Redirect from actual firm called - https://coloradoinjurylaw.com/denver-sexual-abuse-lawyer/",
            "leg.colorado.gov \u2022\tmaps.app.goo.gl",
            "https://leg.colorado.gov/bills/hb20 ?",
            "https://mirai-nameko.jp/assets/delighters-js.php",
            "Government porn: https://thehotporn.info/ \u2022 http://live-sex.space/ \u2022 charoenpornintergroup.com",
            "https://fr.bongacams10.com/erikasexy1 \u2022  https://www.bigcitycreations.com/s/stories/a-unisex-guide-to-pairing-colors",
            "colorado.gov"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Germany",
            "Japan",
            "Italy",
            "Aruba",
            "Finland",
            "India",
            "United Kingdom of Great Britain and Northern Ireland",
            "Australia",
            "Hong Kong",
            "Hungary",
            "Switzerland",
            "China",
            "France",
            "T\u00fcrkiye",
            "Canada",
            "Poland"
          ],
          "malware_families": [
            {
              "id": "Cycbot",
              "display_name": "Cycbot",
              "target": null
            },
            {
              "id": "Backdoor:Linux/DemonBot.Aa!MTB",
              "display_name": "Backdoor:Linux/DemonBot.Aa!MTB",
              "target": "/malware/Backdoor:Linux/DemonBot.Aa!MTB"
            },
            {
              "id": "ALF:NID:Susp_NSIS_Stub.A",
              "display_name": "ALF:NID:Susp_NSIS_Stub.A",
              "target": null
            },
            {
              "id": "Trojan:Win32/Predator.PVD!MTB",
              "display_name": "Trojan:Win32/Predator.PVD!MTB",
              "target": "/malware/Trojan:Win32/Predator.PVD!MTB"
            },
            {
              "id": "Trojandropper:Win32/Cutwail.gen!K",
              "display_name": "Trojandropper:Win32/Cutwail.gen!K",
              "target": "/malware/Trojandropper:Win32/Cutwail.gen!K"
            },
            {
              "id": "#Lowfi:SuspiciousSectionName",
              "display_name": "#Lowfi:SuspiciousSectionName",
              "target": null
            },
            {
              "id": "NIDS",
              "display_name": "NIDS",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [
            "Legal",
            "Government",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7782,
            "domain": 5008,
            "hostname": 2287,
            "FileHash-SHA1": 318,
            "email": 7,
            "FileHash-SHA256": 1608,
            "FileHash-MD5": 356,
            "SSLCertFingerprint": 11,
            "CVE": 1
          },
          "indicator_count": 17378,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 141,
          "modified_text": "135 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "690af483e0e2ee05752043cd",
          "name": "Mirai \u2022 Cycbot - Who is Dennis Schroeder (303) 444-4444 | Social Engineering ~ Legal",
          "description": "Mirai \u2022\nCycBot. Hackers connected\nto targets phone intercepting calls. |\nHi Dennis, how the heck are you? Who are you? We connected targets former phone to a lawyer to become familiar with botnet experience. Time spent speaking to several fraudulent people who pretend to be people they are not. \n\nFrom our side: A factual account was given to a professional sounding female phone actor who answered call without giving name of law firm or her own name / title , listened for some time , few screening questions, no one in \u2018 law firm\u2019 didn\u2019t know statutes of limitations.\n\nSad there was never a way for  target to contact find legitimate legal representation due to being in multiple botnets. \n Very disturbing. \n\n#colorado_government",
          "modified": "2025-12-05T06:05:48.164000",
          "created": "2025-11-05T06:53:55.844000",
          "tags": [
            "url https",
            "url http",
            "related pulses",
            "united",
            "redacted for",
            "meta",
            "accept encoding",
            "moved",
            "ip address",
            "record value",
            "encrypt",
            "backdoor",
            "trojandropper",
            "passive dns",
            "mtb oct",
            "ipv4 add",
            "urls",
            "twitter",
            "trojan",
            "cycbot",
            "dynamicloader",
            "medium",
            "ms windows",
            "write",
            "yara rule",
            "named pipe",
            "pe32",
            "defender",
            "install",
            "smartassembly",
            "malware",
            "local",
            "dns query",
            "xxx adult",
            "site top",
            "level domain",
            "total",
            "whitelisted",
            "yara detections",
            "dyndns domain",
            "filehash",
            "av detections",
            "ids detections",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "acceptencoding",
            "as46606",
            "xserver",
            "killer gecko",
            "host",
            "hello2malware",
            "cnlocalhost",
            "dclocal",
            "guard",
            "url analysis",
            "files",
            "reverse dns",
            "azerbaijan asn",
            "asnone related",
            "destination",
            "port",
            "unknown",
            "et smtp",
            "message",
            "united kingdom",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "found",
            "newremotehost",
            "newexternalport",
            "newprotocol",
            "newinternalport",
            "helloworld",
            "nids",
            "high",
            "ddos",
            "hstr",
            "mtb nov",
            "ransom",
            "msie",
            "chrome",
            "gmt content",
            "hostname add",
            "present jun",
            "germany unknown",
            "domain add",
            "asn as24940",
            "germany asn",
            "domain",
            "files ip",
            "address",
            "less",
            "script urls",
            "dennis schrder",
            "a domains",
            "prox",
            "aaaa",
            "present nov",
            "blog von",
            "apache",
            "dennis schroder",
            "servers",
            "emails",
            "dnssec",
            "as197540",
            "dns resolutions",
            "hostname",
            "verdict",
            "present",
            "directui",
            "element",
            "classinfobase",
            "write c",
            "getclassinfoptr",
            "sgpauiclassinfo",
            "file v2",
            "document",
            "explorer",
            "movie",
            "insert",
            "mitre att",
            "ck matrix",
            "path",
            "hybrid",
            "general",
            "iframe",
            "click",
            "strings",
            "forbidden",
            "default",
            "pdf library",
            "delete c",
            "https domain",
            "tls sni",
            "steals",
            "format",
            "for privacy",
            "name servers",
            "date",
            "japan unknown",
            "entries",
            "next associated",
            "gmt etag",
            "pragma",
            "body",
            "accept",
            "script domains",
            "gmt cache",
            "certificate",
            "alerts",
            "analysis date",
            "file score",
            "present sep",
            "iemobile",
            "ok accept",
            "mirai",
            "cdn.calltrk.com",
            "type indicator"
          ],
          "references": [
            "Redirect from actual firm called - https://coloradoinjurylaw.com/denver-sexual-abuse-lawyer/",
            "leg.colorado.gov \u2022\tmaps.app.goo.gl",
            "https://leg.colorado.gov/bills/hb20 ?",
            "https://mirai-nameko.jp/assets/delighters-js.php",
            "Government porn: https://thehotporn.info/ \u2022 http://live-sex.space/ \u2022 charoenpornintergroup.com",
            "https://fr.bongacams10.com/erikasexy1 \u2022  https://www.bigcitycreations.com/s/stories/a-unisex-guide-to-pairing-colors",
            "colorado.gov"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Germany",
            "Japan",
            "Italy",
            "Aruba",
            "Finland",
            "India",
            "United Kingdom of Great Britain and Northern Ireland",
            "Australia",
            "Hong Kong",
            "Hungary",
            "Switzerland",
            "China",
            "France",
            "T\u00fcrkiye",
            "Canada",
            "Poland"
          ],
          "malware_families": [
            {
              "id": "Cycbot",
              "display_name": "Cycbot",
              "target": null
            },
            {
              "id": "Backdoor:Linux/DemonBot.Aa!MTB",
              "display_name": "Backdoor:Linux/DemonBot.Aa!MTB",
              "target": "/malware/Backdoor:Linux/DemonBot.Aa!MTB"
            },
            {
              "id": "ALF:NID:Susp_NSIS_Stub.A",
              "display_name": "ALF:NID:Susp_NSIS_Stub.A",
              "target": null
            },
            {
              "id": "Trojan:Win32/Predator.PVD!MTB",
              "display_name": "Trojan:Win32/Predator.PVD!MTB",
              "target": "/malware/Trojan:Win32/Predator.PVD!MTB"
            },
            {
              "id": "Trojandropper:Win32/Cutwail.gen!K",
              "display_name": "Trojandropper:Win32/Cutwail.gen!K",
              "target": "/malware/Trojandropper:Win32/Cutwail.gen!K"
            },
            {
              "id": "#Lowfi:SuspiciousSectionName",
              "display_name": "#Lowfi:SuspiciousSectionName",
              "target": null
            },
            {
              "id": "NIDS",
              "display_name": "NIDS",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [
            "Legal",
            "Government",
            "Technology"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7782,
            "domain": 5008,
            "hostname": 2287,
            "FileHash-SHA1": 318,
            "email": 7,
            "FileHash-SHA256": 1608,
            "FileHash-MD5": 356,
            "SSLCertFingerprint": 11,
            "CVE": 1
          },
          "indicator_count": 17378,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "135 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68899ae621ead93f10b78da8",
          "name": "Hacking activities continue to affect multi block communities",
          "description": "Multi block complex (USA) continues to be affected by hacking and espionage activities. Every time I attempt to pulse a community, pulse is reset and malicious IoC\u2019s disappear. So here\u2019s another heap. #virtool #pws #crypter #ransom #tofsee #remote_activities #adversaries #berbew #hacking #denver_communities #infostealers",
          "modified": "2025-08-29T03:04:16.203000",
          "created": "2025-07-30T04:09:10.026000",
          "tags": [
            "url https",
            "location united",
            "asn as16509",
            "et smtp",
            "message",
            "high",
            "et info",
            "domain",
            "yara detections",
            "contacted",
            "show",
            "icmp traffic",
            "irc server",
            "copy",
            "malware",
            "destination",
            "port",
            "united",
            "unknown",
            "united kingdom",
            "search",
            "entries",
            "write",
            "next",
            "google",
            "cloudflar",
            "amazon02",
            "akamaias",
            "microsoft",
            "ip address",
            "as autonomous",
            "system",
            "cdn77 dat",
            "googlecl",
            "cisco",
            "umbrella rank",
            "cisco umbrella",
            "rank",
            "date checked",
            "url hostname",
            "server response",
            "google safe",
            "results may",
            "present apr",
            "present may",
            "files show",
            "trojan",
            "error aug",
            "spain",
            "win32",
            "passive dns",
            "next associated",
            "meta name",
            "frame src",
            "ok set",
            "cookie",
            "gmt date",
            "encrypt",
            "gmt content",
            "type",
            "medium",
            "checks system",
            "total",
            "read",
            "upatre",
            "dynamicloader",
            "dynamic",
            "pcap",
            "reads",
            "pe section",
            "pe file",
            "mtb jul",
            "backdoor",
            "win32upatre jul",
            "mtb jun",
            "ipv4 add",
            "pulse pulses",
            "fakeav",
            "downloader",
            "trojandropper",
            "win32upatre jun",
            "urls",
            "script urls",
            "showing",
            "script domains",
            "meta",
            "certificate",
            "next http",
            "scans show",
            "hostname add",
            "pulse submit",
            "url analysis",
            "files",
            "files ip",
            "address",
            "hostname",
            "verdict",
            "date hash",
            "avast avg",
            "vps reverse",
            "america flag",
            "overview ip",
            "whois registrar",
            "url add",
            "http",
            "related nids",
            "files location",
            "flag united",
            "script general",
            "full url",
            "present jul",
            "aaaa",
            "present jun",
            "moved",
            "content length",
            "content type",
            "x powered",
            "date",
            "mtb may",
            "mtb sep",
            "b jan",
            "mtb jan",
            "mtb dec",
            "asn as13335",
            "creation date",
            "unknown aaaa",
            "results jul",
            "present feb",
            "present oct",
            "win32spigot jul",
            "alfper",
            "found",
            "error",
            "domain add",
            "enom",
            "urls show",
            "address domain",
            "ip related",
            "pulses none",
            "record value",
            "emails",
            "name david",
            "lex name",
            "city",
            "country ng",
            "asn as15169",
            "pulses",
            "tags",
            "all ipv4",
            "reverse dns",
            "ashburn",
            "unknown ns",
            "llc dba",
            "name servers",
            "present jan",
            "present dec",
            "service",
            "ransom",
            "new pulse",
            "existing pulse",
            "files domain",
            "files related",
            "body html",
            "lowfi",
            "worm",
            "virtool",
            "ch ua",
            "sec ch",
            "rsa tls",
            "issuing ca",
            "mtb apr",
            "yara rule",
            "hardwareid",
            "checks",
            "vmprotectsdk",
            "vmprotectstub",
            "avgetblockcc",
            "delphi",
            "vmprotect"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 3262,
            "hostname": 3139,
            "FileHash-SHA256": 2614,
            "URL": 3078,
            "FileHash-MD5": 515,
            "FileHash-SHA1": 517,
            "email": 6,
            "CVE": 1
          },
          "indicator_count": 13132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 140,
          "modified_text": "233 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://leg.colorado.gov/bills/hb20 ?",
        "https://mirai-nameko.jp/assets/delighters-js.php",
        "leg.colorado.gov \u2022\tmaps.app.goo.gl",
        "Government porn: https://thehotporn.info/ \u2022 http://live-sex.space/ \u2022 charoenpornintergroup.com",
        "https://fr.bongacams10.com/erikasexy1 \u2022  https://www.bigcitycreations.com/s/stories/a-unisex-guide-to-pairing-colors",
        "colorado.gov",
        "Redirect from actual firm called - https://coloradoinjurylaw.com/denver-sexual-abuse-lawyer/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "#lowfi:suspicioussectionname",
            "Trojandropper:win32/cutwail.gen!k",
            "Trojan:win32/predator.pvd!mtb",
            "Alf:nid:susp_nsis_stub.a",
            "Cycbot",
            "Backdoor:linux/demonbot.aa!mtb",
            "Nids"
          ],
          "industries": [
            "Government",
            "Legal",
            "Technology"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "690af480b45560b4ae78a863",
      "name": "Mirai \u2022 Cycbot - Who is Dennis Schroeder (303) 444-4444 | Social Engineering ~ Legal",
      "description": "Mirai \u2022\nCycBot. Hackers connected\nto targets phone intercepting calls. |\nHi Dennis, how the heck are you? Who are you? We connected targets former phone to a lawyer to become familiar with botnet experience. Time spent speaking to several fraudulent people who pretend to be people they are not. \n\nFrom our side: A factual account was given to a professional sounding female phone actor who answered call without giving name of law firm or her own name / title , listened for some time , few screening questions, no one in \u2018 law firm\u2019 didn\u2019t know statutes of limitations.\n\nSad there was never a way for  target to contact find legitimate legal representation due to being in multiple botnets. \n Very disturbing. \n\n#colorado_government",
      "modified": "2025-12-05T06:05:48.164000",
      "created": "2025-11-05T06:53:52.767000",
      "tags": [
        "url https",
        "url http",
        "related pulses",
        "united",
        "redacted for",
        "meta",
        "accept encoding",
        "moved",
        "ip address",
        "record value",
        "encrypt",
        "backdoor",
        "trojandropper",
        "passive dns",
        "mtb oct",
        "ipv4 add",
        "urls",
        "twitter",
        "trojan",
        "cycbot",
        "dynamicloader",
        "medium",
        "ms windows",
        "write",
        "yara rule",
        "named pipe",
        "pe32",
        "defender",
        "install",
        "smartassembly",
        "malware",
        "local",
        "dns query",
        "xxx adult",
        "site top",
        "level domain",
        "total",
        "whitelisted",
        "yara detections",
        "dyndns domain",
        "filehash",
        "av detections",
        "ids detections",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "acceptencoding",
        "as46606",
        "xserver",
        "killer gecko",
        "host",
        "hello2malware",
        "cnlocalhost",
        "dclocal",
        "guard",
        "url analysis",
        "files",
        "reverse dns",
        "azerbaijan asn",
        "asnone related",
        "destination",
        "port",
        "unknown",
        "et smtp",
        "message",
        "united kingdom",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "found",
        "newremotehost",
        "newexternalport",
        "newprotocol",
        "newinternalport",
        "helloworld",
        "nids",
        "high",
        "ddos",
        "hstr",
        "mtb nov",
        "ransom",
        "msie",
        "chrome",
        "gmt content",
        "hostname add",
        "present jun",
        "germany unknown",
        "domain add",
        "asn as24940",
        "germany asn",
        "domain",
        "files ip",
        "address",
        "less",
        "script urls",
        "dennis schrder",
        "a domains",
        "prox",
        "aaaa",
        "present nov",
        "blog von",
        "apache",
        "dennis schroder",
        "servers",
        "emails",
        "dnssec",
        "as197540",
        "dns resolutions",
        "hostname",
        "verdict",
        "present",
        "directui",
        "element",
        "classinfobase",
        "write c",
        "getclassinfoptr",
        "sgpauiclassinfo",
        "file v2",
        "document",
        "explorer",
        "movie",
        "insert",
        "mitre att",
        "ck matrix",
        "path",
        "hybrid",
        "general",
        "iframe",
        "click",
        "strings",
        "forbidden",
        "default",
        "pdf library",
        "delete c",
        "https domain",
        "tls sni",
        "steals",
        "format",
        "for privacy",
        "name servers",
        "date",
        "japan unknown",
        "entries",
        "next associated",
        "gmt etag",
        "pragma",
        "body",
        "accept",
        "script domains",
        "gmt cache",
        "certificate",
        "alerts",
        "analysis date",
        "file score",
        "present sep",
        "iemobile",
        "ok accept",
        "mirai",
        "cdn.calltrk.com",
        "type indicator"
      ],
      "references": [
        "Redirect from actual firm called - https://coloradoinjurylaw.com/denver-sexual-abuse-lawyer/",
        "leg.colorado.gov \u2022\tmaps.app.goo.gl",
        "https://leg.colorado.gov/bills/hb20 ?",
        "https://mirai-nameko.jp/assets/delighters-js.php",
        "Government porn: https://thehotporn.info/ \u2022 http://live-sex.space/ \u2022 charoenpornintergroup.com",
        "https://fr.bongacams10.com/erikasexy1 \u2022  https://www.bigcitycreations.com/s/stories/a-unisex-guide-to-pairing-colors",
        "colorado.gov"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Germany",
        "Japan",
        "Italy",
        "Aruba",
        "Finland",
        "India",
        "United Kingdom of Great Britain and Northern Ireland",
        "Australia",
        "Hong Kong",
        "Hungary",
        "Switzerland",
        "China",
        "France",
        "T\u00fcrkiye",
        "Canada",
        "Poland"
      ],
      "malware_families": [
        {
          "id": "Cycbot",
          "display_name": "Cycbot",
          "target": null
        },
        {
          "id": "Backdoor:Linux/DemonBot.Aa!MTB",
          "display_name": "Backdoor:Linux/DemonBot.Aa!MTB",
          "target": "/malware/Backdoor:Linux/DemonBot.Aa!MTB"
        },
        {
          "id": "ALF:NID:Susp_NSIS_Stub.A",
          "display_name": "ALF:NID:Susp_NSIS_Stub.A",
          "target": null
        },
        {
          "id": "Trojan:Win32/Predator.PVD!MTB",
          "display_name": "Trojan:Win32/Predator.PVD!MTB",
          "target": "/malware/Trojan:Win32/Predator.PVD!MTB"
        },
        {
          "id": "Trojandropper:Win32/Cutwail.gen!K",
          "display_name": "Trojandropper:Win32/Cutwail.gen!K",
          "target": "/malware/Trojandropper:Win32/Cutwail.gen!K"
        },
        {
          "id": "#Lowfi:SuspiciousSectionName",
          "display_name": "#Lowfi:SuspiciousSectionName",
          "target": null
        },
        {
          "id": "NIDS",
          "display_name": "NIDS",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [
        "Legal",
        "Government",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 7782,
        "domain": 5008,
        "hostname": 2287,
        "FileHash-SHA1": 318,
        "email": 7,
        "FileHash-SHA256": 1608,
        "FileHash-MD5": 356,
        "SSLCertFingerprint": 11,
        "CVE": 1
      },
      "indicator_count": 17378,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 141,
      "modified_text": "135 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "690af483e0e2ee05752043cd",
      "name": "Mirai \u2022 Cycbot - Who is Dennis Schroeder (303) 444-4444 | Social Engineering ~ Legal",
      "description": "Mirai \u2022\nCycBot. Hackers connected\nto targets phone intercepting calls. |\nHi Dennis, how the heck are you? Who are you? We connected targets former phone to a lawyer to become familiar with botnet experience. Time spent speaking to several fraudulent people who pretend to be people they are not. \n\nFrom our side: A factual account was given to a professional sounding female phone actor who answered call without giving name of law firm or her own name / title , listened for some time , few screening questions, no one in \u2018 law firm\u2019 didn\u2019t know statutes of limitations.\n\nSad there was never a way for  target to contact find legitimate legal representation due to being in multiple botnets. \n Very disturbing. \n\n#colorado_government",
      "modified": "2025-12-05T06:05:48.164000",
      "created": "2025-11-05T06:53:55.844000",
      "tags": [
        "url https",
        "url http",
        "related pulses",
        "united",
        "redacted for",
        "meta",
        "accept encoding",
        "moved",
        "ip address",
        "record value",
        "encrypt",
        "backdoor",
        "trojandropper",
        "passive dns",
        "mtb oct",
        "ipv4 add",
        "urls",
        "twitter",
        "trojan",
        "cycbot",
        "dynamicloader",
        "medium",
        "ms windows",
        "write",
        "yara rule",
        "named pipe",
        "pe32",
        "defender",
        "install",
        "smartassembly",
        "malware",
        "local",
        "dns query",
        "xxx adult",
        "site top",
        "level domain",
        "total",
        "whitelisted",
        "yara detections",
        "dyndns domain",
        "filehash",
        "av detections",
        "ids detections",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "acceptencoding",
        "as46606",
        "xserver",
        "killer gecko",
        "host",
        "hello2malware",
        "cnlocalhost",
        "dclocal",
        "guard",
        "url analysis",
        "files",
        "reverse dns",
        "azerbaijan asn",
        "asnone related",
        "destination",
        "port",
        "unknown",
        "et smtp",
        "message",
        "united kingdom",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "found",
        "newremotehost",
        "newexternalport",
        "newprotocol",
        "newinternalport",
        "helloworld",
        "nids",
        "high",
        "ddos",
        "hstr",
        "mtb nov",
        "ransom",
        "msie",
        "chrome",
        "gmt content",
        "hostname add",
        "present jun",
        "germany unknown",
        "domain add",
        "asn as24940",
        "germany asn",
        "domain",
        "files ip",
        "address",
        "less",
        "script urls",
        "dennis schrder",
        "a domains",
        "prox",
        "aaaa",
        "present nov",
        "blog von",
        "apache",
        "dennis schroder",
        "servers",
        "emails",
        "dnssec",
        "as197540",
        "dns resolutions",
        "hostname",
        "verdict",
        "present",
        "directui",
        "element",
        "classinfobase",
        "write c",
        "getclassinfoptr",
        "sgpauiclassinfo",
        "file v2",
        "document",
        "explorer",
        "movie",
        "insert",
        "mitre att",
        "ck matrix",
        "path",
        "hybrid",
        "general",
        "iframe",
        "click",
        "strings",
        "forbidden",
        "default",
        "pdf library",
        "delete c",
        "https domain",
        "tls sni",
        "steals",
        "format",
        "for privacy",
        "name servers",
        "date",
        "japan unknown",
        "entries",
        "next associated",
        "gmt etag",
        "pragma",
        "body",
        "accept",
        "script domains",
        "gmt cache",
        "certificate",
        "alerts",
        "analysis date",
        "file score",
        "present sep",
        "iemobile",
        "ok accept",
        "mirai",
        "cdn.calltrk.com",
        "type indicator"
      ],
      "references": [
        "Redirect from actual firm called - https://coloradoinjurylaw.com/denver-sexual-abuse-lawyer/",
        "leg.colorado.gov \u2022\tmaps.app.goo.gl",
        "https://leg.colorado.gov/bills/hb20 ?",
        "https://mirai-nameko.jp/assets/delighters-js.php",
        "Government porn: https://thehotporn.info/ \u2022 http://live-sex.space/ \u2022 charoenpornintergroup.com",
        "https://fr.bongacams10.com/erikasexy1 \u2022  https://www.bigcitycreations.com/s/stories/a-unisex-guide-to-pairing-colors",
        "colorado.gov"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Germany",
        "Japan",
        "Italy",
        "Aruba",
        "Finland",
        "India",
        "United Kingdom of Great Britain and Northern Ireland",
        "Australia",
        "Hong Kong",
        "Hungary",
        "Switzerland",
        "China",
        "France",
        "T\u00fcrkiye",
        "Canada",
        "Poland"
      ],
      "malware_families": [
        {
          "id": "Cycbot",
          "display_name": "Cycbot",
          "target": null
        },
        {
          "id": "Backdoor:Linux/DemonBot.Aa!MTB",
          "display_name": "Backdoor:Linux/DemonBot.Aa!MTB",
          "target": "/malware/Backdoor:Linux/DemonBot.Aa!MTB"
        },
        {
          "id": "ALF:NID:Susp_NSIS_Stub.A",
          "display_name": "ALF:NID:Susp_NSIS_Stub.A",
          "target": null
        },
        {
          "id": "Trojan:Win32/Predator.PVD!MTB",
          "display_name": "Trojan:Win32/Predator.PVD!MTB",
          "target": "/malware/Trojan:Win32/Predator.PVD!MTB"
        },
        {
          "id": "Trojandropper:Win32/Cutwail.gen!K",
          "display_name": "Trojandropper:Win32/Cutwail.gen!K",
          "target": "/malware/Trojandropper:Win32/Cutwail.gen!K"
        },
        {
          "id": "#Lowfi:SuspiciousSectionName",
          "display_name": "#Lowfi:SuspiciousSectionName",
          "target": null
        },
        {
          "id": "NIDS",
          "display_name": "NIDS",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [
        "Legal",
        "Government",
        "Technology"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 7782,
        "domain": 5008,
        "hostname": 2287,
        "FileHash-SHA1": 318,
        "email": 7,
        "FileHash-SHA256": 1608,
        "FileHash-MD5": 356,
        "SSLCertFingerprint": 11,
        "CVE": 1
      },
      "indicator_count": 17378,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "135 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68899ae621ead93f10b78da8",
      "name": "Hacking activities continue to affect multi block communities",
      "description": "Multi block complex (USA) continues to be affected by hacking and espionage activities. Every time I attempt to pulse a community, pulse is reset and malicious IoC\u2019s disappear. So here\u2019s another heap. #virtool #pws #crypter #ransom #tofsee #remote_activities #adversaries #berbew #hacking #denver_communities #infostealers",
      "modified": "2025-08-29T03:04:16.203000",
      "created": "2025-07-30T04:09:10.026000",
      "tags": [
        "url https",
        "location united",
        "asn as16509",
        "et smtp",
        "message",
        "high",
        "et info",
        "domain",
        "yara detections",
        "contacted",
        "show",
        "icmp traffic",
        "irc server",
        "copy",
        "malware",
        "destination",
        "port",
        "united",
        "unknown",
        "united kingdom",
        "search",
        "entries",
        "write",
        "next",
        "google",
        "cloudflar",
        "amazon02",
        "akamaias",
        "microsoft",
        "ip address",
        "as autonomous",
        "system",
        "cdn77 dat",
        "googlecl",
        "cisco",
        "umbrella rank",
        "cisco umbrella",
        "rank",
        "date checked",
        "url hostname",
        "server response",
        "google safe",
        "results may",
        "present apr",
        "present may",
        "files show",
        "trojan",
        "error aug",
        "spain",
        "win32",
        "passive dns",
        "next associated",
        "meta name",
        "frame src",
        "ok set",
        "cookie",
        "gmt date",
        "encrypt",
        "gmt content",
        "type",
        "medium",
        "checks system",
        "total",
        "read",
        "upatre",
        "dynamicloader",
        "dynamic",
        "pcap",
        "reads",
        "pe section",
        "pe file",
        "mtb jul",
        "backdoor",
        "win32upatre jul",
        "mtb jun",
        "ipv4 add",
        "pulse pulses",
        "fakeav",
        "downloader",
        "trojandropper",
        "win32upatre jun",
        "urls",
        "script urls",
        "showing",
        "script domains",
        "meta",
        "certificate",
        "next http",
        "scans show",
        "hostname add",
        "pulse submit",
        "url analysis",
        "files",
        "files ip",
        "address",
        "hostname",
        "verdict",
        "date hash",
        "avast avg",
        "vps reverse",
        "america flag",
        "overview ip",
        "whois registrar",
        "url add",
        "http",
        "related nids",
        "files location",
        "flag united",
        "script general",
        "full url",
        "present jul",
        "aaaa",
        "present jun",
        "moved",
        "content length",
        "content type",
        "x powered",
        "date",
        "mtb may",
        "mtb sep",
        "b jan",
        "mtb jan",
        "mtb dec",
        "asn as13335",
        "creation date",
        "unknown aaaa",
        "results jul",
        "present feb",
        "present oct",
        "win32spigot jul",
        "alfper",
        "found",
        "error",
        "domain add",
        "enom",
        "urls show",
        "address domain",
        "ip related",
        "pulses none",
        "record value",
        "emails",
        "name david",
        "lex name",
        "city",
        "country ng",
        "asn as15169",
        "pulses",
        "tags",
        "all ipv4",
        "reverse dns",
        "ashburn",
        "unknown ns",
        "llc dba",
        "name servers",
        "present jan",
        "present dec",
        "service",
        "ransom",
        "new pulse",
        "existing pulse",
        "files domain",
        "files related",
        "body html",
        "lowfi",
        "worm",
        "virtool",
        "ch ua",
        "sec ch",
        "rsa tls",
        "issuing ca",
        "mtb apr",
        "yara rule",
        "hardwareid",
        "checks",
        "vmprotectsdk",
        "vmprotectstub",
        "avgetblockcc",
        "delphi",
        "vmprotect"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 3262,
        "hostname": 3139,
        "FileHash-SHA256": 2614,
        "URL": 3078,
        "FileHash-MD5": 515,
        "FileHash-SHA1": 517,
        "email": 6,
        "CVE": 1
      },
      "indicator_count": 13132,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 140,
      "modified_text": "233 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "cobaconstruct.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "cobaconstruct.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776613063.8317125
}