{
  "type": "Domain",
  "indicator": "dcontrols.pro",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/dcontrols.pro",
    "alexa": "http://www.alexa.com/siteinfo/dcontrols.pro",
    "indicator": "dcontrols.pro",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4150652333,
      "indicator": "dcontrols.pro",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "691b8869e00b107fa20d9482",
          "name": "ThreatFix",
          "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
          "modified": "2026-01-23T11:01:07.175000",
          "created": "2025-11-17T20:41:11.797000",
          "tags": [
            "",
            "ransomware",
            "malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "",
              "display_name": "",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "zlepos384",
            "id": "103244",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8010,
            "FileHash-SHA1": 7922,
            "FileHash-SHA256": 8893,
            "URL": 57004,
            "domain": 36018,
            "hostname": 96473
          },
          "indicator_count": 214320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "128 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "692dae2bdfd7e18df0f1e5b0",
          "name": "qAWSDFGHJ",
          "description": "Web users are being urged to check their accounts before they use them, as well as taking part in a series of security checks. and a number of other security-related web-based sites.",
          "modified": "2025-12-31T15:01:28.564000",
          "created": "2025-12-01T15:03:07.147000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "SOC__critical43",
            "id": "361186",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 25,
            "hostname": 4
          },
          "indicator_count": 29,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 22,
          "modified_text": "151 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "692d7519544b62e86aa47157",
          "name": "EbeeNov2025 Pt5",
          "description": "Multiple APT/threat actors, Malware and Campaigns",
          "modified": "2025-12-31T10:00:16.038000",
          "created": "2025-12-01T10:59:37.970000",
          "tags": [
            "filehashsha256",
            "filehashmd5",
            "filehashsha1",
            "filepath",
            "cve20243721 cve",
            "cve20131599 cve",
            "cve20143206 cve",
            "cve20179841 cve",
            "cve20199082 cve",
            "cve20208958 cve"
          ],
          "references": [
            "Book1.csv"
          ],
          "public": 1,
          "adversary": "APT24, Autumn Dragon, Operation DreamJob, Water Gamayun, Shai-Hulud Campaign Infecting Macs via Face",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "IMEBEEIMFINE",
            "id": "343873",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 54,
            "CVE": 35,
            "FileHash-MD5": 221,
            "FileHash-SHA1": 188,
            "FileHash-SHA256": 232,
            "domain": 150,
            "email": 1,
            "hostname": 40
          },
          "indicator_count": 921,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 41,
          "modified_text": "151 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69269a713e9ed36acadcbd6f",
          "name": "IOC - Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix",
          "description": "Novel \"JackFix\" attack: Acronis TRU researchers discover an ongoing campaign that leverages a novel combination of screen hijacking techniques with ClickFix, displaying a realistic, full-screen Windows Update of \u201cCritical Windows Security Updates\u201d to trick victims into executing malicious commands.\nAdult content bait strategy: Campaign leverages fake adult websites (xHamster, PornHub clones) as its phishing mechanism, likely distributed via malvertising. The adult theme, and possible connection to shady websites, add to victim\u2019s psychological pressure, making victims more likely to comply with sudden \u201csecurity update\u201d installation instructions.",
          "modified": "2025-12-26T06:00:46.039000",
          "created": "2025-11-26T06:13:05.062000",
          "tags": [],
          "references": [
            "https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "celestre",
            "id": "295357",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 25,
            "hostname": 4
          },
          "indicator_count": 29,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "156 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "691b86538bc9d6168b54ed7e",
          "name": "ThreatFix",
          "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
          "modified": "2025-12-17T20:05:25.178000",
          "created": "2025-11-17T20:32:18.360000",
          "tags": [
            "malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "zlepos384",
            "id": "103244",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 55,
            "FileHash-SHA1": 53,
            "FileHash-SHA256": 54,
            "URL": 1581,
            "domain": 374,
            "hostname": 1629
          },
          "indicator_count": 3746,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 35,
          "modified_text": "165 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Book1.csv",
        "https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "APT24, Autumn Dragon, Operation DreamJob, Water Gamayun, Shai-Hulud Campaign Infecting Macs via Face"
          ],
          "malware_families": [
            ""
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "691b8869e00b107fa20d9482",
      "name": "ThreatFix",
      "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
      "modified": "2026-01-23T11:01:07.175000",
      "created": "2025-11-17T20:41:11.797000",
      "tags": [
        "",
        "ransomware",
        "malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "",
          "display_name": "",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "zlepos384",
        "id": "103244",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8010,
        "FileHash-SHA1": 7922,
        "FileHash-SHA256": 8893,
        "URL": 57004,
        "domain": 36018,
        "hostname": 96473
      },
      "indicator_count": 214320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "128 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "692dae2bdfd7e18df0f1e5b0",
      "name": "qAWSDFGHJ",
      "description": "Web users are being urged to check their accounts before they use them, as well as taking part in a series of security checks. and a number of other security-related web-based sites.",
      "modified": "2025-12-31T15:01:28.564000",
      "created": "2025-12-01T15:03:07.147000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "SOC__critical43",
        "id": "361186",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 25,
        "hostname": 4
      },
      "indicator_count": 29,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 22,
      "modified_text": "151 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "692d7519544b62e86aa47157",
      "name": "EbeeNov2025 Pt5",
      "description": "Multiple APT/threat actors, Malware and Campaigns",
      "modified": "2025-12-31T10:00:16.038000",
      "created": "2025-12-01T10:59:37.970000",
      "tags": [
        "filehashsha256",
        "filehashmd5",
        "filehashsha1",
        "filepath",
        "cve20243721 cve",
        "cve20131599 cve",
        "cve20143206 cve",
        "cve20179841 cve",
        "cve20199082 cve",
        "cve20208958 cve"
      ],
      "references": [
        "Book1.csv"
      ],
      "public": 1,
      "adversary": "APT24, Autumn Dragon, Operation DreamJob, Water Gamayun, Shai-Hulud Campaign Infecting Macs via Face",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "IMEBEEIMFINE",
        "id": "343873",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 54,
        "CVE": 35,
        "FileHash-MD5": 221,
        "FileHash-SHA1": 188,
        "FileHash-SHA256": 232,
        "domain": 150,
        "email": 1,
        "hostname": 40
      },
      "indicator_count": 921,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 41,
      "modified_text": "151 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69269a713e9ed36acadcbd6f",
      "name": "IOC - Fake adult websites pop realistic Windows Update screen to deliver stealers via ClickFix",
      "description": "Novel \"JackFix\" attack: Acronis TRU researchers discover an ongoing campaign that leverages a novel combination of screen hijacking techniques with ClickFix, displaying a realistic, full-screen Windows Update of \u201cCritical Windows Security Updates\u201d to trick victims into executing malicious commands.\nAdult content bait strategy: Campaign leverages fake adult websites (xHamster, PornHub clones) as its phishing mechanism, likely distributed via malvertising. The adult theme, and possible connection to shady websites, add to victim\u2019s psychological pressure, making victims more likely to comply with sudden \u201csecurity update\u201d installation instructions.",
      "modified": "2025-12-26T06:00:46.039000",
      "created": "2025-11-26T06:13:05.062000",
      "tags": [],
      "references": [
        "https://www.acronis.com/en/tru/posts/fake-adult-websites-pop-realistic-windows-update-screen-to-deliver-stealers-via-clickfix/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "celestre",
        "id": "295357",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 25,
        "hostname": 4
      },
      "indicator_count": 29,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "156 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "691b86538bc9d6168b54ed7e",
      "name": "ThreatFix",
      "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
      "modified": "2025-12-17T20:05:25.178000",
      "created": "2025-11-17T20:32:18.360000",
      "tags": [
        "malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "zlepos384",
        "id": "103244",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 55,
        "FileHash-SHA1": 53,
        "FileHash-SHA256": 54,
        "URL": 1581,
        "domain": 374,
        "hostname": 1629
      },
      "indicator_count": 3746,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 35,
      "modified_text": "165 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "dcontrols.pro",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "dcontrols.pro",
    "found": true,
    "verdict": "malicious",
    "url_count": 2,
    "online_count": 0,
    "blacklists": {
      "spamhaus_dbl": "malware_domain",
      "surbl": "not listed"
    },
    "urls": [
      {
        "url": "https://dcontrols.pro/xxx.html",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2025-11-14",
        "tags": [
          "xHamster"
        ]
      },
      {
        "url": "https://dcontrols.pro/xhamster.html",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2025-11-14",
        "tags": [
          "xHamster"
        ]
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780266677.358866
}