{
  "type": "Domain",
  "indicator": "cyberfear.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/cyberfear.com",
    "alexa": "http://www.alexa.com/siteinfo/cyberfear.com",
    "indicator": "cyberfear.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3400163871,
      "indicator": "cyberfear.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 15,
      "pulses": [
        {
          "id": "6834fbfc39f435042ef10cd8",
          "name": "Twitter Feed - PaduckLee - 26-05-2025",
          "description": "",
          "modified": "2025-05-26T23:40:44.940000",
          "created": "2025-05-26T23:40:44.940000",
          "tags": [
            "ransomware"
          ],
          "references": [
            "https://x.com/PaduckLee/status/1926895191354376266"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1,
            "FileHash-MD5": 1,
            "domain": 1
          },
          "indicator_count": 3,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1623,
          "modified_text": "370 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708a0ebac8772c2a67c7e9",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "",
          "modified": "2023-12-06T14:49:50.754000",
          "created": "2023-12-06T14:49:50.754000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA256": 50,
            "FileHash-SHA1": 26,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570844f02a76f986c48cf20",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "",
          "modified": "2023-12-06T14:25:19.464000",
          "created": "2023-12-06T14:25:19.464000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA256": 50,
            "FileHash-SHA1": 26,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570844a3b4a08f43446898a",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "",
          "modified": "2023-12-06T14:25:14.362000",
          "created": "2023-12-06T14:25:14.362000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA256": 50,
            "FileHash-SHA1": 26,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708445e5d8848f75e580ce",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "",
          "modified": "2023-12-06T14:25:09.808000",
          "created": "2023-12-06T14:25:09.808000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA256": 50,
            "FileHash-SHA1": 26,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708407a5cf4c0504fd0357",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "",
          "modified": "2023-12-06T14:24:07.941000",
          "created": "2023-12-06T14:24:07.941000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA256": 50,
            "FileHash-SHA1": 26,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657084050011524abcdf1bdf",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "",
          "modified": "2023-12-06T14:24:04.080000",
          "created": "2023-12-06T14:24:04.080000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA256": 50,
            "FileHash-SHA1": 26,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "655b186b3d62757abfd34221",
          "name": "Understanding the Phobos affiliate structure and activity",
          "description": "The most prolific variants of the Phobos ransomware family have been identified by Cisco Talos Intelligence and are commonly seen as being run by a dispersed group of cybercriminal groups, which target high-value servers.",
          "modified": "2023-11-20T08:27:23.030000",
          "created": "2023-11-20T08:27:23.030000",
          "tags": [
            "ransomware",
            "threat spotlight",
            "phobos",
            "virustotal",
            "elbie",
            "raas",
            "talos",
            "appliance",
            "phobos variant",
            "ttps",
            "devos",
            "phobos sample",
            "lazagne",
            "mimikatz",
            "desktop",
            "stub",
            "crysis",
            "8base",
            "clop"
          ],
          "references": [
            "https://blog.talosintelligence.com/understanding-the-phobos-affiliate-structure/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Crysis",
              "display_name": "Crysis",
              "target": null
            },
            {
              "id": "8Base",
              "display_name": "8Base",
              "target": null
            },
            {
              "id": "Clop",
              "display_name": "Clop",
              "target": null
            },
            {
              "id": "Phobos",
              "display_name": "Phobos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1531",
              "name": "Account Access Removal",
              "display_name": "T1531 - Account Access Removal"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1552",
              "name": "Unsecured Credentials",
              "display_name": "T1552 - Unsecured Credentials"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "domain": 23,
            "email": 2
          },
          "indicator_count": 26,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "924 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63f6affbb34efc8ec8d6dd80",
          "name": "InQuest - 22-02-2023",
          "description": "",
          "modified": "2023-03-25T00:02:33.269000",
          "created": "2023-02-23T00:14:51.733000",
          "tags": [],
          "references": [
            "https://labs.inquest.net/iocdb"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1598,
            "hostname": 232,
            "FileHash-SHA256": 147,
            "domain": 1055,
            "FileHash-MD5": 28,
            "FileHash-SHA1": 14
          },
          "indicator_count": 3074,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1623,
          "modified_text": "1164 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "623dc649bd28a75d3180c68b",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "A new strain of ransomware called LokiLocker has been identified by BlackBerry Threat Intelligence and is likely to be released in the next few months or even more, but its origins are unclear, so far.",
          "modified": "2022-04-24T00:01:15.470000",
          "created": "2022-03-25T13:40:25.411000",
          "tags": [
            "lokilocker",
            "lockbit",
            "cor20 metadata",
            "drops",
            "loki",
            "koivm",
            "checker",
            "raas",
            "tactic",
            "norse mythology",
            "windows pcs",
            "locky",
            "lokibot",
            "confuserex"
          ],
          "references": [
            "https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "LokiLocker",
              "display_name": "LokiLocker",
              "target": null
            },
            {
              "id": "Drops",
              "display_name": "Drops",
              "target": null
            },
            {
              "id": "COR20 MetaData",
              "display_name": "COR20 MetaData",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "manuelzepeda",
            "id": "102853",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 50,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 62,
          "modified_text": "1499 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6233e2f0db3b7a843b869753",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "",
          "modified": "2022-04-17T00:01:27.728000",
          "created": "2022-03-18T01:40:00.311000",
          "tags": [
            "lokilocker",
            "loki",
            "koivm",
            "checker",
            "raas",
            "tactic",
            "norse mythology",
            "windows pcs",
            "locky",
            "lokibot",
            "confuserex"
          ],
          "references": [
            "https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "caralin0702",
            "id": "73972",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 50,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 102,
          "modified_text": "1506 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62344fb3a21ccc45cc1c76b6",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "A new strain of ransomware called LokiLocker has been identified by BlackBerry Threat Intelligence and is likely to be released in the next few months or even more, but its origins are unclear, so far.",
          "modified": "2022-04-17T00:01:27.728000",
          "created": "2022-03-18T09:24:02.998000",
          "tags": [
            "lokilocker",
            "lockbit",
            "cor20 metadata",
            "drops",
            "loki",
            "koivm",
            "checker",
            "raas",
            "tactic",
            "norse mythology",
            "windows pcs",
            "locky",
            "lokibot",
            "confuserex"
          ],
          "references": [
            "https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "LokiLocker",
              "display_name": "LokiLocker",
              "target": null
            },
            {
              "id": "Drops",
              "display_name": "Drops",
              "target": null
            },
            {
              "id": "COR20 MetaData",
              "display_name": "COR20 MetaData",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "rishadarakkal",
            "id": "183757",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 50,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 52,
          "modified_text": "1506 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "623346b35e2416503cd10f92",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "A new strain of ransomware called LokiLocker has been identified by BlackBerry Threat Intelligence and is likely to be released in the next few months or even more, but its origins are unclear, so far.",
          "modified": "2022-04-16T00:04:53.479000",
          "created": "2022-03-17T14:33:22.865000",
          "tags": [
            "lokilocker",
            "raas",
            "NetGuard"
          ],
          "references": [
            "https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "LokiLocker",
              "display_name": "LokiLocker",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "BinaryDefense",
            "id": "111374",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_111374/resized/80/avatar_ca13c2b840.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 50,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 272,
          "modified_text": "1507 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6231f5ad9724f041542667df",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "A new strain of ransomware called LokiLocker has been identified by BlackBerry Threat Intelligence and is likely to be released in the next few months or even more, but its origins are unclear, so far.",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T14:35:25.294000",
          "tags": [
            "lokilocker",
            "lockbit",
            "cor20 metadata",
            "drops",
            "loki",
            "koivm",
            "checker",
            "raas",
            "tactic",
            "norse mythology",
            "windows pcs",
            "locky",
            "lokibot",
            "confuserex"
          ],
          "references": [
            "https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "LokiLocker",
              "display_name": "LokiLocker",
              "target": null
            },
            {
              "id": "Drops",
              "display_name": "Drops",
              "target": null
            },
            {
              "id": "COR20 MetaData",
              "display_name": "COR20 MetaData",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "jackl3-3",
            "id": "40027",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 50,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 86,
          "modified_text": "1508 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6231f5af4430c8dc60822ef8",
          "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
          "description": "A new strain of ransomware called LokiLocker has been identified by BlackBerry Threat Intelligence and is likely to be released in the next few months or even more, but its origins are unclear, so far.",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T14:35:27.512000",
          "tags": [
            "lokilocker",
            "lockbit",
            "cor20 metadata",
            "drops",
            "loki",
            "koivm",
            "checker",
            "raas",
            "tactic",
            "norse mythology",
            "windows pcs",
            "locky",
            "lokibot",
            "confuserex"
          ],
          "references": [
            "https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "LokiLocker",
              "display_name": "LokiLocker",
              "target": null
            },
            {
              "id": "Drops",
              "display_name": "Drops",
              "target": null
            },
            {
              "id": "COR20 MetaData",
              "display_name": "COR20 MetaData",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1135",
              "name": "Network Share Discovery",
              "display_name": "T1135 - Network Share Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1561",
              "name": "Disk Wipe",
              "display_name": "T1561 - Disk Wipe"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "jackl3-3",
            "id": "40027",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 26,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 50,
            "domain": 16
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 86,
          "modified_text": "1508 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://labs.inquest.net/iocdb",
        "https://x.com/PaduckLee/status/1926895191354376266",
        "https://blog.talosintelligence.com/understanding-the-phobos-affiliate-structure/",
        "https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Lockbit",
            "Phobos",
            "Cor20 metadata",
            "8base",
            "Crysis",
            "Lokilocker",
            "Clop",
            "Drops"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 15,
  "pulses": [
    {
      "id": "6834fbfc39f435042ef10cd8",
      "name": "Twitter Feed - PaduckLee - 26-05-2025",
      "description": "",
      "modified": "2025-05-26T23:40:44.940000",
      "created": "2025-05-26T23:40:44.940000",
      "tags": [
        "ransomware"
      ],
      "references": [
        "https://x.com/PaduckLee/status/1926895191354376266"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1,
        "FileHash-MD5": 1,
        "domain": 1
      },
      "indicator_count": 3,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1623,
      "modified_text": "370 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708a0ebac8772c2a67c7e9",
      "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
      "description": "",
      "modified": "2023-12-06T14:49:50.754000",
      "created": "2023-12-06T14:49:50.754000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA256": 50,
        "FileHash-SHA1": 26,
        "domain": 16
      },
      "indicator_count": 118,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570844f02a76f986c48cf20",
      "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
      "description": "",
      "modified": "2023-12-06T14:25:19.464000",
      "created": "2023-12-06T14:25:19.464000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA256": 50,
        "FileHash-SHA1": 26,
        "domain": 16
      },
      "indicator_count": 118,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570844a3b4a08f43446898a",
      "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
      "description": "",
      "modified": "2023-12-06T14:25:14.362000",
      "created": "2023-12-06T14:25:14.362000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA256": 50,
        "FileHash-SHA1": 26,
        "domain": 16
      },
      "indicator_count": 118,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708445e5d8848f75e580ce",
      "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
      "description": "",
      "modified": "2023-12-06T14:25:09.808000",
      "created": "2023-12-06T14:25:09.808000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA256": 50,
        "FileHash-SHA1": 26,
        "domain": 16
      },
      "indicator_count": 118,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708407a5cf4c0504fd0357",
      "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
      "description": "",
      "modified": "2023-12-06T14:24:07.941000",
      "created": "2023-12-06T14:24:07.941000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA256": 50,
        "FileHash-SHA1": 26,
        "domain": 16
      },
      "indicator_count": 118,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "657084050011524abcdf1bdf",
      "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
      "description": "",
      "modified": "2023-12-06T14:24:04.080000",
      "created": "2023-12-06T14:24:04.080000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA256": 50,
        "FileHash-SHA1": 26,
        "domain": 16
      },
      "indicator_count": 118,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "655b186b3d62757abfd34221",
      "name": "Understanding the Phobos affiliate structure and activity",
      "description": "The most prolific variants of the Phobos ransomware family have been identified by Cisco Talos Intelligence and are commonly seen as being run by a dispersed group of cybercriminal groups, which target high-value servers.",
      "modified": "2023-11-20T08:27:23.030000",
      "created": "2023-11-20T08:27:23.030000",
      "tags": [
        "ransomware",
        "threat spotlight",
        "phobos",
        "virustotal",
        "elbie",
        "raas",
        "talos",
        "appliance",
        "phobos variant",
        "ttps",
        "devos",
        "phobos sample",
        "lazagne",
        "mimikatz",
        "desktop",
        "stub",
        "crysis",
        "8base",
        "clop"
      ],
      "references": [
        "https://blog.talosintelligence.com/understanding-the-phobos-affiliate-structure/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Crysis",
          "display_name": "Crysis",
          "target": null
        },
        {
          "id": "8Base",
          "display_name": "8Base",
          "target": null
        },
        {
          "id": "Clop",
          "display_name": "Clop",
          "target": null
        },
        {
          "id": "Phobos",
          "display_name": "Phobos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1505",
          "name": "Server Software Component",
          "display_name": "T1505 - Server Software Component"
        },
        {
          "id": "T1531",
          "name": "Account Access Removal",
          "display_name": "T1531 - Account Access Removal"
        },
        {
          "id": "T1199",
          "name": "Trusted Relationship",
          "display_name": "T1199 - Trusted Relationship"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1552",
          "name": "Unsecured Credentials",
          "display_name": "T1552 - Unsecured Credentials"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "domain": 23,
        "email": 2
      },
      "indicator_count": 26,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "924 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63f6affbb34efc8ec8d6dd80",
      "name": "InQuest - 22-02-2023",
      "description": "",
      "modified": "2023-03-25T00:02:33.269000",
      "created": "2023-02-23T00:14:51.733000",
      "tags": [],
      "references": [
        "https://labs.inquest.net/iocdb"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1598,
        "hostname": 232,
        "FileHash-SHA256": 147,
        "domain": 1055,
        "FileHash-MD5": 28,
        "FileHash-SHA1": 14
      },
      "indicator_count": 3074,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1623,
      "modified_text": "1164 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "623dc649bd28a75d3180c68b",
      "name": "New Ransomware Family Identified: LokiLocker RaaS Targets Windows Systems",
      "description": "A new strain of ransomware called LokiLocker has been identified by BlackBerry Threat Intelligence and is likely to be released in the next few months or even more, but its origins are unclear, so far.",
      "modified": "2022-04-24T00:01:15.470000",
      "created": "2022-03-25T13:40:25.411000",
      "tags": [
        "lokilocker",
        "lockbit",
        "cor20 metadata",
        "drops",
        "loki",
        "koivm",
        "checker",
        "raas",
        "tactic",
        "norse mythology",
        "windows pcs",
        "locky",
        "lokibot",
        "confuserex"
      ],
      "references": [
        "https://blogs.blackberry.com/en/2022/03/lokilocker-ransomware"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "LokiLocker",
          "display_name": "LokiLocker",
          "target": null
        },
        {
          "id": "Drops",
          "display_name": "Drops",
          "target": null
        },
        {
          "id": "COR20 MetaData",
          "display_name": "COR20 MetaData",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1135",
          "name": "Network Share Discovery",
          "display_name": "T1135 - Network Share Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1561",
          "name": "Disk Wipe",
          "display_name": "T1561 - Disk Wipe"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "manuelzepeda",
        "id": "102853",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 26,
        "FileHash-SHA1": 26,
        "FileHash-SHA256": 50,
        "domain": 16
      },
      "indicator_count": 118,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 62,
      "modified_text": "1499 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "cyberfear.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "cyberfear.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780350183.2854257
}