{
  "type": "Domain",
  "indicator": "cpp-support.help",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/cpp-support.help",
    "alexa": "http://www.alexa.com/siteinfo/cpp-support.help",
    "indicator": "cpp-support.help",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4070106174,
      "indicator": "cpp-support.help",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6879b440a485a8ebfe244fc0",
          "name": "Malware Filter - Phishing List - 17-07-2025",
          "description": "",
          "modified": "2025-07-18T02:41:04.600000",
          "created": "2025-07-18T02:41:04.600000",
          "tags": [],
          "references": [
            "https://malware-filter.gitlab.io/malware-filter/phishing-filter-domains.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 37,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 662,
            "domain": 441
          },
          "indicator_count": 1103,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1624,
          "modified_text": "320 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "682ee870f0dd8303a54b1a2f",
          "name": "Uncovering a Malware Operation Through ICICI Bank Phishing Site Investigation",
          "description": "A detailed investigation into an ICICI Bank phishing site has revealed a sophisticated malware operation. The analysis, conducted by Aarsh Jawa, uncovered the use of advanced techniques to steal sensitive information and deploy malware. This operation highlights the importance of vigilance and robust cybersecurity measures to protect against phishing attacks and malware infiltration.",
          "modified": "2025-05-22T09:03:44.829000",
          "created": "2025-05-22T09:03:44.829000",
          "tags": [
            "icici bank",
            "play store",
            "telegram",
            "icici",
            "bank",
            "phishing site",
            "jawa5 min",
            "android banking",
            "apks",
            "fake icici",
            "discord",
            "trojan",
            "tanglebot",
            "intelligence security"
          ],
          "references": [
            "https://medium.com/@aarshjawa/how-investigating-an-icici-bank-phishing-site-uncovered-a-malware-operation-45ecac000609"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "TangleBot",
              "display_name": "TangleBot",
              "target": null
            },
            {
              "id": "Intelligence Security",
              "display_name": "Intelligence Security",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [
            "Banks",
            "Financial"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 2,
            "URL": 2,
            "domain": 1,
            "hostname": 1
          },
          "indicator_count": 8,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 543,
          "modified_text": "376 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://malware-filter.gitlab.io/malware-filter/phishing-filter-domains.txt",
        "https://medium.com/@aarshjawa/how-investigating-an-icici-bank-phishing-site-uncovered-a-malware-operation-45ecac000609"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Intelligence security",
            "Tanglebot"
          ],
          "industries": [
            "Banks",
            "Financial"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6879b440a485a8ebfe244fc0",
      "name": "Malware Filter - Phishing List - 17-07-2025",
      "description": "",
      "modified": "2025-07-18T02:41:04.600000",
      "created": "2025-07-18T02:41:04.600000",
      "tags": [],
      "references": [
        "https://malware-filter.gitlab.io/malware-filter/phishing-filter-domains.txt"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 37,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 662,
        "domain": 441
      },
      "indicator_count": 1103,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1624,
      "modified_text": "320 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "682ee870f0dd8303a54b1a2f",
      "name": "Uncovering a Malware Operation Through ICICI Bank Phishing Site Investigation",
      "description": "A detailed investigation into an ICICI Bank phishing site has revealed a sophisticated malware operation. The analysis, conducted by Aarsh Jawa, uncovered the use of advanced techniques to steal sensitive information and deploy malware. This operation highlights the importance of vigilance and robust cybersecurity measures to protect against phishing attacks and malware infiltration.",
      "modified": "2025-05-22T09:03:44.829000",
      "created": "2025-05-22T09:03:44.829000",
      "tags": [
        "icici bank",
        "play store",
        "telegram",
        "icici",
        "bank",
        "phishing site",
        "jawa5 min",
        "android banking",
        "apks",
        "fake icici",
        "discord",
        "trojan",
        "tanglebot",
        "intelligence security"
      ],
      "references": [
        "https://medium.com/@aarshjawa/how-investigating-an-icici-bank-phishing-site-uncovered-a-malware-operation-45ecac000609"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "TangleBot",
          "display_name": "TangleBot",
          "target": null
        },
        {
          "id": "Intelligence Security",
          "display_name": "Intelligence Security",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [
        "Banks",
        "Financial"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 2,
        "URL": 2,
        "domain": 1,
        "hostname": 1
      },
      "indicator_count": 8,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 543,
      "modified_text": "376 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "cpp-support.help",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "cpp-support.help",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780460528.5357583
}