{
  "type": "Domain",
  "indicator": "e.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/e.com",
    "alexa": "http://www.alexa.com/siteinfo/e.com",
    "indicator": "e.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2264672693,
      "indicator": "e.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 50,
      "pulses": [
        {
          "id": "699969651d3b082f6b583fae",
          "name": "PDFKIT.net",
          "description": "Data Points. Search tall components CVE's for more info on this.",
          "modified": "2026-04-01T00:44:45.494000",
          "created": "2026-02-21T08:14:29.258000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 370,
            "hostname": 444,
            "FileHash-SHA1": 1292,
            "FileHash-SHA256": 4067,
            "URL": 192,
            "FileHash-MD5": 1255,
            "email": 16,
            "CVE": 58
          },
          "indicator_count": 7694,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 50,
          "modified_text": "19 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69aa7a7b91633d9a88f06f85",
          "name": "Q Vashti post \"monitored target\"",
          "description": "",
          "modified": "2026-03-06T16:17:21.212000",
          "created": "2026-03-06T06:55:55.582000",
          "tags": [
            "indicator",
            "source",
            "ck id",
            "show technique",
            "mitre att",
            "ck matrix",
            "openservice",
            "sha384",
            "file",
            "virtualfree",
            "path",
            "getprocaddress",
            "pattern match",
            "potential ip",
            "open",
            "date",
            "click",
            "error",
            "null",
            "false",
            "stream",
            "enterprise",
            "body",
            "crypto",
            "compiler",
            "entropy",
            "refresh",
            "download",
            "factory",
            "bind",
            "strings",
            "twitter",
            "roboto",
            "contact",
            "window",
            "tools",
            "span",
            "value",
            "access type",
            "file execution",
            "setval",
            "userprofile",
            "debugger",
            "hybrid",
            "persistence",
            "general",
            "suspicious",
            "target"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1029",
              "name": "Scheduled Transfer",
              "display_name": "T1029 - Scheduled Transfer"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1213",
              "name": "Data from Information Repositories",
              "display_name": "T1213 - Data from Information Repositories"
            },
            {
              "id": "T1217",
              "name": "Browser Bookmark Discovery",
              "display_name": "T1217 - Browser Bookmark Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1559",
              "name": "Inter-Process Communication",
              "display_name": "T1559 - Inter-Process Communication"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1565",
              "name": "Data Manipulation",
              "display_name": "T1565 - Data Manipulation"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "68409862e1722725233acace",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 54,
            "FileHash-SHA1": 35,
            "FileHash-SHA256": 24,
            "SSLCertFingerprint": 3,
            "URL": 296,
            "domain": 317,
            "hostname": 648,
            "email": 3
          },
          "indicator_count": 1380,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 47,
          "modified_text": "44 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "695cc5b5337bc1ac1273946a",
          "name": "Macbook Air Macbook Air",
          "description": "Macbook Air Macbook Air",
          "modified": "2026-02-05T07:00:52.044000",
          "created": "2026-01-06T08:20:05.305000",
          "tags": [
            "doctype",
            "public",
            "data",
            "drive",
            "problems1",
            "no problems",
            "upload",
            "tue aug",
            "scanid",
            "archivetype",
            "june",
            "look",
            "accept",
            "internal",
            "ransomware",
            "error",
            "trace",
            "sparkle",
            "fusion",
            "alphabet",
            "path",
            "archivesize",
            "archivemd5",
            "archivesha256",
            "open",
            "whirlpool",
            "syst",
            "stream",
            "mercury",
            "import",
            "info",
            "dangerous file",
            "modified",
            "tue jul",
            "mon sep",
            "mon mar",
            "sigtype1",
            "false",
            "warp",
            "powershell",
            "specs",
            "subscore1",
            "Mac",
            "Apple"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 12573,
            "FileHash-SHA1": 14594,
            "FileHash-SHA256": 12489,
            "URL": 88,
            "domain": 98,
            "email": 15,
            "hostname": 119
          },
          "indicator_count": 39976,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 128,
          "modified_text": "73 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "695ca8b688eb56b3a0247098",
          "name": "System32 - Subfolders",
          "description": "E:\\Suss-SG2\\System32 - Subfolders.zip",
          "modified": "2026-02-05T06:03:21.110000",
          "created": "2026-01-06T06:16:22.880000",
          "tags": [
            "tue apr",
            "scanid",
            "mon mar",
            "archivesize",
            "archivesha1",
            "archivesha256",
            "archivecreated",
            "f archiveowner",
            "sigtype1",
            "sigclass1",
            "look",
            "powershell",
            "first",
            "strings",
            "dllinject",
            "june",
            "span",
            "error",
            "fail",
            "rooter",
            "info",
            "alphabet",
            "false",
            "path",
            "service",
            "dword",
            "shell",
            "model",
            "assistant",
            "code",
            "syst",
            "checker",
            "rest",
            "core",
            "tencent",
            "null",
            "accept",
            "open",
            "pass",
            "internal",
            "meta",
            "root",
            "desktop",
            "window",
            "maximu",
            "stream",
            "android",
            "comp",
            "date",
            "whirlpool",
            "kevin",
            "sett",
            "locale",
            "cloud",
            "malware",
            "class"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 148,
            "CIDR": 2,
            "FileHash-MD5": 9860,
            "FileHash-SHA1": 10592,
            "FileHash-SHA256": 8443,
            "domain": 147,
            "email": 6,
            "hostname": 49
          },
          "indicator_count": 29247,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 130,
          "modified_text": "73 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954ae6971517cdd7beb3d77",
          "name": "Security Vendors\\Norton",
          "description": "Security Vendors\\Norton",
          "modified": "2026-01-30T04:03:08.625000",
          "created": "2025-12-31T05:02:33.034000",
          "tags": [
            "data",
            "drive",
            "no problems",
            "upload",
            "mon mar",
            "scanid",
            "sigtype1",
            "sigclass1",
            "rule matched1",
            "subscore1",
            "look",
            "june",
            "dllinject",
            "alphabet",
            "info",
            "winmm",
            "null",
            "malware",
            "powershell",
            "autorun",
            "jack",
            "first",
            "internal",
            "whirlpool",
            "updater",
            "code",
            "spyeye",
            "runescape",
            "warp",
            "upgrade",
            "copy",
            "defender",
            "date",
            "xmrigminer",
            "kevin",
            "eraser",
            "ding",
            "Norton",
            "Telus"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 59,
            "URL": 42,
            "CVE": 2,
            "FileHash-MD5": 1355,
            "FileHash-SHA1": 1177,
            "FileHash-SHA256": 948,
            "email": 4,
            "hostname": 37
          },
          "indicator_count": 3624,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 130,
          "modified_text": "79 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69546fab13abfdf3e825b1e4",
          "name": "Norton\\08.30.23",
          "description": "Norton\\08.30.23",
          "modified": "2026-01-30T00:01:11.705000",
          "created": "2025-12-31T00:34:51.728000",
          "tags": [
            "data",
            "drive",
            "no problems",
            "upload",
            "problems1",
            "progressb",
            "wed aug",
            "scanid",
            "mon mar",
            "sigtype1",
            "look",
            "june",
            "dllinject",
            "winmm",
            "alphabet",
            "autorun",
            "powershell",
            "info",
            "malware",
            "first",
            "jack",
            "whirlpool",
            "internal",
            "surtr",
            "ursnif",
            "code",
            "spyeye",
            "runescape",
            "warp",
            "null",
            "defender",
            "copy",
            "strings",
            "burn",
            "dreambot",
            "gozi",
            "isfb",
            "iron",
            "bitcoin",
            "steam",
            "date",
            "xmrigminer",
            "kevin",
            "ding",
            "Norton",
            "Telus"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            }
          ],
          "industries": [
            "Technology",
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 52,
            "URL": 37,
            "CVE": 1,
            "FileHash-MD5": 1241,
            "FileHash-SHA1": 879,
            "FileHash-SHA256": 823,
            "email": 4,
            "hostname": 26
          },
          "indicator_count": 3063,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "80 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "694b02eb945649ff909f06d5",
          "name": "$RECYCLE . BIN\\ -> Part 2",
          "description": "E:\\Suss-SG2\\$RECYCLE.BIN\\\n\nVictim Google Pixel Telus ISP Norton AV Device\nDevice connected to AHS/Covenant Health, University of Alberta, Government of Alberta",
          "modified": "2026-01-28T02:03:16.337000",
          "created": "2025-12-23T21:00:27.029000",
          "tags": [
            "Telus",
            "YEG",
            "AHS",
            "Pixel",
            "ConnectCare",
            "Norton",
            "UAlberta",
            "Google"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada",
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government",
            "Education",
            "Technology",
            "Telecommunications",
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 65761,
            "FileHash-SHA1": 56561,
            "FileHash-SHA256": 43672,
            "domain": 1373,
            "email": 39,
            "URL": 466,
            "hostname": 818,
            "CVE": 3,
            "CIDR": 2
          },
          "indicator_count": 168695,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "68409862e1722725233acace",
          "name": "Monitored Target- bounty-50872035906958562",
          "description": "Monitored Target- bounty-50872035906958562\n(Whitelisted?)\n\u2022 Spyware\nAccesses potentially sensitive information from local browsers |\n\u2022Found a string that may be used as part of an injection method |\n\u2022 Stealer/Phishing\n\u2022 Reads FTP client related files\n\u2022 Persistence\n\u2022 Creates a fake system process\n\u2022 Modifies System Certificates Settings\n\u2022 Modifies auto-execute functionality by setting/creating a value in the registry\n\u2022 Modifies auto-execute functionality to enable the debugger hack\n\u2022 Writes data to a remote process\n\u2022 Writes to the hosts file\n\u2022 Fingerprint\nQueries +",
          "modified": "2025-07-04T18:05:18.397000",
          "created": "2025-06-04T19:02:57.999000",
          "tags": [
            "indicator",
            "source",
            "ck id",
            "show technique",
            "mitre att",
            "ck matrix",
            "openservice",
            "sha384",
            "file",
            "virtualfree",
            "path",
            "getprocaddress",
            "pattern match",
            "potential ip",
            "open",
            "date",
            "click",
            "error",
            "null",
            "false",
            "stream",
            "enterprise",
            "body",
            "crypto",
            "compiler",
            "entropy",
            "refresh",
            "download",
            "factory",
            "bind",
            "strings",
            "twitter",
            "roboto",
            "contact",
            "window",
            "tools",
            "span",
            "value",
            "access type",
            "file execution",
            "setval",
            "userprofile",
            "debugger",
            "hybrid",
            "persistence",
            "general",
            "suspicious",
            "target"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1021",
              "name": "Remote Services",
              "display_name": "T1021 - Remote Services"
            },
            {
              "id": "T1029",
              "name": "Scheduled Transfer",
              "display_name": "T1029 - Scheduled Transfer"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1124",
              "name": "System Time Discovery",
              "display_name": "T1124 - System Time Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1213",
              "name": "Data from Information Repositories",
              "display_name": "T1213 - Data from Information Repositories"
            },
            {
              "id": "T1217",
              "name": "Browser Bookmark Discovery",
              "display_name": "T1217 - Browser Bookmark Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1559",
              "name": "Inter-Process Communication",
              "display_name": "T1559 - Inter-Process Communication"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1565",
              "name": "Data Manipulation",
              "display_name": "T1565 - Data Manipulation"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 54,
            "FileHash-SHA1": 35,
            "FileHash-SHA256": 24,
            "SSLCertFingerprint": 3,
            "URL": 294,
            "domain": 317,
            "hostname": 648,
            "email": 3
          },
          "indicator_count": 1378,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 139,
          "modified_text": "289 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67fa493f49755096b93cd648",
          "name": "AkiraBot\u2019s Use of GPT Models in Web Channel Abuse",
          "description": "Here is a full list of domains, websites and services used by people to send spam, spam and other spam messages:. and here is the full set of names: (Snob):.",
          "modified": "2025-04-12T11:06:39.048000",
          "created": "2025-04-12T11:06:39.048000",
          "tags": [
            "servicewrap",
            "beservicewrap",
            "getkira",
            "gogoservicewrap",
            "goservicewrap",
            "joinnowkira",
            "joinuseakira",
            "kiraone",
            "loveservice",
            "mybkira",
            "service"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 26,
            "URL": 1,
            "domain": 1
          },
          "indicator_count": 28,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 486,
          "modified_text": "372 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "66f235b9a7a94a6a61acd651",
          "name": "n0paste - Show paste: \\\"No Problems\\\" - dos meses del URLscan",
          "description": "This pulse represents a 'scattered sample' of data extracted from 'submissions of interest' made to virustotal, filescan_itsec, HybridAnalysis, anyrun_app, DynamiteLab, and triage (over a period of two months) which were submitted to urlscanio & subsequently GreyNoiseIO (which I've come across both from live samples and also those from offlined data). I don't particularly anticipate this will correlate w. anything specific - but at least will be put in one more place for further analysis & increased visibility.",
          "modified": "2025-03-07T08:38:08.584000",
          "created": "2024-09-24T03:44:57.902000",
          "tags": [
            "geoip",
            "public url",
            "as16509",
            "amazon02",
            "as20940",
            "akamaiasn1",
            "as8075",
            "as15169",
            "google",
            "akamaias",
            "facebook",
            "telecom",
            "twitter",
            "media",
            "win64",
            "level3",
            "mini",
            "ukraine",
            "proton",
            "ghost",
            "win32",
            "cuba",
            "mexico",
            "indonesia",
            "seznam",
            "as3359",
            "as852"
          ],
          "references": [
            "https://metadefender.com/results/file/bzI1MDMwMVFWaXRDS0hpWElYcnV0QllCYlB1",
            "https://mwdb.cert.pl/file/efb45096e24a61b488eb809bd8edf874d15bb498dd75ced8b888b020c87e5c6c",
            "https://n0paste.eu/UH6n5pD/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada",
            "Anguilla",
            "Poland",
            "Aruba",
            "Australia",
            "Barbados",
            "Costa Rica",
            "Guatemala",
            "Philippines",
            "Panama",
            "Sint Maarten (Dutch part)",
            "Saint Martin (French part)",
            "Cayman Islands",
            "Cura\u00e7ao",
            "Mexico",
            "Saint Vincent and the Grenadines",
            "Saint Kitts and Nevis",
            "Tanzania, United Republic of",
            "Netherlands",
            "Ukraine",
            "Trinidad and Tobago",
            "Japan",
            "Bahamas",
            "United Kingdom of Great Britain and Northern Ireland",
            "Georgia"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education",
            "Technology",
            "Government",
            "Telecommunications",
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1,
            "CIDR": 1186,
            "CVE": 4,
            "FileHash-MD5": 29,
            "FileHash-SHA1": 3,
            "URL": 25493,
            "domain": 5396,
            "email": 10,
            "hostname": 10770
          },
          "indicator_count": 42892,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 147,
          "modified_text": "408 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "666ac558d08da6cfb3ba135b",
          "name": "Thor Lite Scanner - Cigabuntu (Parrot Version) vs. The Book of Shadows",
          "description": "A little unclear on &#x27;just exactly what all of this is&#x27; - Other than Huntress Catching things and Thor & Bitdefender Gravutyzone ****ing the bed\n\nScan ID: S-6vsmMgE47Gk\nScan Id: S-H9GdDtmU2vU\n\n06.13.24: https://www.virustotal.com/graph/embed/g14ccc2b5794648cc838da283a8fbfcda4d95dde6ddc44798be19c2832778787f?theme=dark",
          "modified": "2024-07-13T09:05:44.647000",
          "created": "2024-06-13T10:09:28.617000",
          "tags": [
            "entity",
            "please",
            "javascript",
            "valhalla",
            "php",
            "filename ioc",
            "mon jun",
            "module",
            "sigtype1",
            "reasonscount",
            "tue jun",
            "exploit code",
            "file names",
            "matched1",
            "score",
            "shellcode",
            "form",
            "mimikatz",
            "powershell",
            "cobaltstrike",
            "null",
            "trace",
            "shell",
            "import",
            "empire",
            "hermanos",
            "cobalt strike",
            "void",
            "body",
            "exploit",
            "webshell",
            "antak",
            "anomaly",
            "error",
            "generic",
            "target",
            "obfus",
            "skeletonkey",
            "virustotal",
            "dllimport",
            "false",
            "flash",
            "info",
            "click",
            "macos",
            "test",
            "powersploit",
            "powercat",
            "tools",
            "metasploit",
            "twitter",
            "open",
            "path",
            "xploit"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g14ccc2b5794648cc838da283a8fbfcda4d95dde6ddc44798be19c2832778787f?theme=dark",
            "https://www.virustotal.com/gui/collection/a5d9ceedc1dd9b912db6270e583ef306f5d3130912ffe4c519496cb53b2179f9/summary",
            "https://www.virustotal.com/gui/collection/a5d9ceedc1dd9b912db6270e583ef306f5d3130912ffe4c519496cb53b2179f9/iocs",
            "https://www.virustotal.com/gui/collection/a5d9ceedc1dd9b912db6270e583ef306f5d3130912ffe4c519496cb53b2179f9/graph"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "VALHALLA",
              "display_name": "VALHALLA",
              "target": null
            },
            {
              "id": "PHP",
              "display_name": "PHP",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1087",
              "name": "Account Discovery",
              "display_name": "T1087 - Account Discovery"
            },
            {
              "id": "T1098",
              "name": "Account Manipulation",
              "display_name": "T1098 - Account Manipulation"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1505",
              "name": "Server Software Component",
              "display_name": "T1505 - Server Software Component"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1550",
              "name": "Use Alternate Authentication Material",
              "display_name": "T1550 - Use Alternate Authentication Material"
            },
            {
              "id": "T1552",
              "name": "Unsecured Credentials",
              "display_name": "T1552 - Unsecured Credentials"
            },
            {
              "id": "T1558",
              "name": "Steal or Forge Kerberos Tickets",
              "display_name": "T1558 - Steal or Forge Kerberos Tickets"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1569",
              "name": "System Services",
              "display_name": "T1569 - System Services"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 74,
            "CVE": 156,
            "FileHash-MD5": 828,
            "FileHash-SHA1": 1126,
            "FileHash-SHA256": 746,
            "domain": 130,
            "email": 4,
            "hostname": 21
          },
          "indicator_count": 3085,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 130,
          "modified_text": "645 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709510e5b078aa5f09ca51",
          "name": "widevinecdm.dll seemingly problematic - supply chain holy god mother of fu.k",
          "description": "",
          "modified": "2023-12-06T15:36:48.409000",
          "created": "2023-12-06T15:36:48.409000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1447,
            "FileHash-MD5": 199,
            "FileHash-SHA1": 197,
            "domain": 267,
            "hostname": 871,
            "URL": 1930,
            "email": 2
          },
          "indicator_count": 4913,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657091a4533a832480459e15",
          "name": "dos.myflorida.com:elections",
          "description": "",
          "modified": "2023-12-06T15:22:12.430000",
          "created": "2023-12-06T15:22:12.430000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 809,
            "hostname": 160,
            "domain": 105,
            "URL": 434,
            "CIDR": 1,
            "FileHash-MD5": 9,
            "FileHash-SHA1": 1
          },
          "indicator_count": 1519,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709196f6f15be052923aec",
          "name": "DanaNessel.com ~ Michigan Attorney General",
          "description": "",
          "modified": "2023-12-06T15:21:58.367000",
          "created": "2023-12-06T15:21:58.367000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-SHA256": 726,
            "hostname": 312,
            "domain": 287,
            "URL": 1081,
            "email": 1,
            "CIDR": 4,
            "FileHash-MD5": 13,
            "FileHash-SHA1": 24
          },
          "indicator_count": 2450,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709186b4721854f288709d",
          "name": "DCDemocraticparty.org",
          "description": "",
          "modified": "2023-12-06T15:21:42.506000",
          "created": "2023-12-06T15:21:42.506000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1403,
            "URL": 992,
            "hostname": 382,
            "domain": 221,
            "CIDR": 9,
            "FileHash-MD5": 87,
            "FileHash-SHA1": 15
          },
          "indicator_count": 3109,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708b98527049ba5438e5ad",
          "name": "http://milab.cs.purded.edu/media/tasklog/  - a lot of data",
          "description": "",
          "modified": "2023-12-06T14:56:24.859000",
          "created": "2023-12-06T14:56:24.859000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 403,
            "FileHash-SHA256": 161,
            "hostname": 482,
            "URL": 929
          },
          "indicator_count": 1975,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708b9517363fdfb72ab1d4",
          "name": "http://milab.cs.purded.edu/media/tasklog/  - a lot of data",
          "description": "",
          "modified": "2023-12-06T14:56:21.300000",
          "created": "2023-12-06T14:56:21.300000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 403,
            "FileHash-SHA256": 161,
            "hostname": 482,
            "URL": 929
          },
          "indicator_count": 1975,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570841ce0f526e54683ab2c",
          "name": "mesacounty.us_05.21.2019",
          "description": "",
          "modified": "2023-12-06T14:24:28.383000",
          "created": "2023-12-06T14:24:28.383000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 706,
            "domain": 65,
            "hostname": 165,
            "URL": 493,
            "CIDR": 1,
            "FileHash-MD5": 6
          },
          "indicator_count": 1436,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657083fdc68c74974fe8a9fb",
          "name": "cass.ballottrax.net:voter:%22",
          "description": "",
          "modified": "2023-12-06T14:23:56.285000",
          "created": "2023-12-06T14:23:56.285000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 640,
            "hostname": 145,
            "domain": 121,
            "URL": 510,
            "CIDR": 5,
            "FileHash-MD5": 10
          },
          "indicator_count": 1431,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657083f0caaf3104532d619b",
          "name": "apps.crowdtangle.com:chrome-extension%22",
          "description": "",
          "modified": "2023-12-06T14:23:44.276000",
          "created": "2023-12-06T14:23:44.276000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 796,
            "hostname": 313,
            "domain": 123,
            "URL": 880,
            "CIDR": 9,
            "FileHash-MD5": 50,
            "FileHash-SHA1": 2
          },
          "indicator_count": 2173,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657081e1d76cdb2f325ea5f3",
          "name": "apps.crowdtangle.com:public-hub:covid19:us%22",
          "description": "",
          "modified": "2023-12-06T14:14:57.245000",
          "created": "2023-12-06T14:14:57.245000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 808,
            "hostname": 367,
            "domain": 149,
            "URL": 1095,
            "CIDR": 9,
            "FileHash-MD5": 50,
            "FileHash-SHA1": 2
          },
          "indicator_count": 2480,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657081ba0df0b5e6590b26fb",
          "name": "www.dominionvoting.com:%22 ~ 03.01.2022",
          "description": "",
          "modified": "2023-12-06T14:14:18.256000",
          "created": "2023-12-06T14:14:18.256000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 776,
            "hostname": 131,
            "domain": 114,
            "URL": 500,
            "CIDR": 2,
            "FileHash-MD5": 9
          },
          "indicator_count": 1532,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570819b0888b5212998e2ae",
          "name": "www.vrsystems.com:%22 ~ 03.02.2022",
          "description": "",
          "modified": "2023-12-06T14:13:47.648000",
          "created": "2023-12-06T14:13:47.648000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 339,
            "FileHash-SHA256": 1161,
            "domain": 154,
            "URL": 723,
            "CIDR": 2,
            "FileHash-MD5": 27,
            "FileHash-SHA1": 6
          },
          "indicator_count": 2412,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708191cdba4e9f07ba1f93",
          "name": "mail.ru:%22,",
          "description": "",
          "modified": "2023-12-06T14:13:36.976000",
          "created": "2023-12-06T14:13:36.976000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 2753,
            "hostname": 1341,
            "domain": 447,
            "URL": 3301,
            "CIDR": 65,
            "FileHash-MD5": 112,
            "FileHash-SHA1": 2
          },
          "indicator_count": 8021,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570818c5411bc133a940bc5",
          "name": "Scytl.us:%22, 12.14.21",
          "description": "",
          "modified": "2023-12-06T14:13:32.889000",
          "created": "2023-12-06T14:13:32.889000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1104,
            "hostname": 186,
            "domain": 124,
            "URL": 707,
            "CIDR": 4,
            "FileHash-MD5": 8,
            "FileHash-SHA1": 1
          },
          "indicator_count": 2134,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63dbc92dd6dd6d29e1a637a7",
          "name": "192.99.158.243:80 (appie.com)",
          "description": "[object Object",
          "modified": "2023-03-04T14:02:04.452000",
          "created": "2023-02-02T14:31:09.039000",
          "tags": [
            "malware",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "unicode",
            "localappdata",
            "hash seen",
            "runtime process",
            "temp",
            "sha256",
            "sha1",
            "win64",
            "entropy",
            "suspicious",
            "ransomware",
            "general",
            "date",
            "mozilla",
            "accept",
            "strings",
            "malicious",
            "windows nt",
            "khtml",
            "gecko",
            "request url",
            "format details",
            "request get",
            "host",
            "raw hex",
            "c4 e7",
            "c0 a8",
            "f3 c2",
            "get favic"
          ],
          "references": [
            "I first found this like 3 or 4 years ago cant belive its still a thing - appie.com/favicon.ico - change the i to a capital I",
            "Here is the full text of the request for the image of Favicon, which was sent to the appie.com website by the US government in 2008.. and the subject:.",
            "https://hybrid-analysis.com/sample/29e0152b350f004f7dfe6f2188d014aab87a723b9c4b613c579f6add610242b8/63bcd2c7dc34a339c406a344"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 156,
            "hostname": 44,
            "domain": 29,
            "FileHash-SHA256": 65,
            "FileHash-MD5": 52,
            "FileHash-SHA1": 51
          },
          "indicator_count": 397,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "1142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63dbc58e164ab858b1501214",
          "name": "I first found this like 3 or 4 years ago cant belive its still a thing - appie.com/favicon.ico - change the i to a capital I",
          "description": "Here is the full text of the request for the image of Favicon, which was sent to the appie.com website by the US government in 2008.. and the subject:.",
          "modified": "2023-02-02T14:15:42.486000",
          "created": "2023-02-02T14:15:42.486000",
          "tags": [
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "request get",
            "host",
            "raw hex",
            "c0 a8",
            "f3 c2",
            "get favic"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 44,
            "domain": 3,
            "FileHash-SHA256": 1,
            "hostname": 4
          },
          "indicator_count": 52,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1172 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63c8b5fe14c9a2744aafc835",
          "name": "Sign in \u2013 Google accounts google account from e.com ????  - T1105 Ingress Tool Transfer ???",
          "description": "Click here to find out more about the world's most northerly languages and ethnic groups, which are available on the BBC World News website and iPlayer (in English, iPad and mobile).",
          "modified": "2023-01-19T03:16:14.824000",
          "created": "2023-01-19T03:16:14.824000",
          "tags": [
            "analysis",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "localappdata",
            "unicode",
            "programfiles",
            "input",
            "report",
            "windir",
            "ransomware",
            "suspicious",
            "general",
            "strings",
            "google",
            "sign",
            "google account",
            "email",
            "forgot email",
            "use private",
            "browsing",
            "learn",
            "create account",
            "e.com"
          ],
          "references": [
            "https://myaccount.google.com/u/1/accountlinking?hl=en-GB",
            "https://www.hybrid-analysis.com/sample/134aa68a3c3fdc7232e01975247699b806576d0954e695042f44f4b74a7acba1/63c883a9634ab92b2b44d552",
            "e.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 3,
            "FileHash-SHA256": 5,
            "URL": 24,
            "hostname": 1,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 35,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1186 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63c8b2f10c9b8b2344261988",
          "name": "Sign in \u2013 Google accounts google account from e.com ????  - T1105 Ingress Tool Transfer ???",
          "description": "Click here to find out more about the world's most northerly languages and ethnic groups, which are available on the BBC World News website and iPlayer (in English, iPad and mobile).",
          "modified": "2023-01-19T03:03:13.013000",
          "created": "2023-01-19T03:03:13.013000",
          "tags": [
            "analysis",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "localappdata",
            "unicode",
            "programfiles",
            "input",
            "report",
            "windir",
            "ransomware",
            "suspicious",
            "general",
            "strings",
            "google",
            "sign",
            "google account",
            "email",
            "forgot email",
            "use private",
            "browsing",
            "learn",
            "create account",
            "e.com"
          ],
          "references": [
            "https://myaccount.google.com/u/1/accountlinking?hl=en-GB",
            "https://www.hybrid-analysis.com/sample/134aa68a3c3fdc7232e01975247699b806576d0954e695042f44f4b74a7acba1/63c883a9634ab92b2b44d552",
            "e.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 3,
            "FileHash-SHA256": 5,
            "URL": 24,
            "hostname": 1,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 35,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1186 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6398fe16df6290d8fcac2f77",
          "name": "widevinecdm.dll seemingly problematic - supply chain holy god mother of fu.k",
          "description": "https://hybrid-analysis.com/sample/db695a96adb70d5f6246273f4e6c218b2c44f02b3726c3dee4d56b6428bb0ddf",
          "modified": "2023-01-12T21:02:22.235000",
          "created": "2022-12-13T22:35:02.021000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "threat level",
            "date",
            "sha256",
            "unicode",
            "size",
            "pcap",
            "pcap processing",
            "runtime process",
            "accept",
            "suspicious",
            "hybrid",
            "malicious",
            "close",
            "click",
            "hosts",
            "ransomware",
            "general",
            "local",
            "path",
            "mozilla",
            "strings",
            "localappdata",
            "temp",
            "prefetch8 ansi",
            "entropy",
            "win64",
            "disabled hash",
            "friendly",
            "mozi",
            "trident",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "file",
            "type data",
            "download file",
            "db695a96adb70d5f6246273f4e6c218b2c44f02b3726c3dee4d56b6428bb0ddf",
            "widevinecdm.dll",
            "https://hybrid-analysis.com/sample/db695a96adb70d5f6246273f4e6c2"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 32,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 871,
            "URL": 1930,
            "domain": 267,
            "FileHash-SHA256": 1447,
            "FileHash-MD5": 199,
            "FileHash-SHA1": 197,
            "email": 2
          },
          "indicator_count": 4913,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 396,
          "modified_text": "1193 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63012cdfb8b36960045a2deb",
          "name": "dos.myflorida.com:elections",
          "description": "",
          "modified": "2022-09-19T00:10:46.535000",
          "created": "2022-08-20T18:50:07.448000",
          "tags": [
            "Ransomware"
          ],
          "references": [
            "dos.myflorida.com:elections.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransom:Win32/Wannaren.A",
              "display_name": "Ransom:Win32/Wannaren.A",
              "target": "/malware/Ransom:Win32/Wannaren.A"
            }
          ],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 160,
            "URL": 435,
            "domain": 105,
            "FileHash-SHA256": 809,
            "CIDR": 1,
            "FileHash-MD5": 9,
            "FileHash-SHA1": 1
          },
          "indicator_count": 1520,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 405,
          "modified_text": "1309 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "630117b532da21a9155b2b79",
          "name": "DanaNessel.com ~ Michigan Attorney General",
          "description": "",
          "modified": "2022-09-19T00:10:46.535000",
          "created": "2022-08-20T17:19:49.134000",
          "tags": [
            "detections type",
            "name",
            "dns replication",
            "date",
            "subdomains",
            "files referring",
            "android",
            "lookups",
            "registrant",
            "first",
            "key identifier",
            "x509v3 subject",
            "ranks rank",
            "value ingestion",
            "time statvoo",
            "utc alexa",
            "dns records",
            "record type",
            "ttl value",
            "data",
            "domain status",
            "server",
            "dnssec",
            "domain name",
            "status",
            "abuse contact",
            "email",
            "registrar abuse",
            "contact phone"
          ],
          "references": [
            "dananessel.com.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1082,
            "hostname": 312,
            "domain": 287,
            "FileHash-SHA256": 726,
            "CVE": 2,
            "email": 1,
            "FileHash-SHA1": 24,
            "CIDR": 4,
            "FileHash-MD5": 13
          },
          "indicator_count": 2451,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 405,
          "modified_text": "1309 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63003c89e59330c5e5aa71f2",
          "name": "DCDemocraticparty.org",
          "description": "",
          "modified": "2022-09-18T00:03:55.814000",
          "created": "2022-08-20T01:44:41.321000",
          "tags": [
            "url search",
            "domain scan",
            "url url",
            "search url",
            "search domain",
            "scan url",
            "august",
            "lookup go",
            "rescan add",
            "verdict report",
            "behaviour",
            "http",
            "request chain",
            "de summary",
            "redirects links",
            "similar dom",
            "meta",
            "value",
            "variables",
            "sentry",
            "imageclientapi",
            "reactdom",
            "react",
            "object",
            "fbq function",
            "htmlcomponent",
            "function",
            "Apple's crappy FaceTime ~ Nothing has changed",
            "Ransomware"
          ],
          "references": [
            "dcdemocraticparty.org.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransom:Win32/Wannaren.A",
              "display_name": "Ransom:Win32/Wannaren.A",
              "target": "/malware/Ransom:Win32/Wannaren.A"
            }
          ],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 382,
            "URL": 993,
            "domain": 221,
            "FileHash-SHA256": 1403,
            "CIDR": 9,
            "FileHash-MD5": 87,
            "FileHash-SHA1": 15
          },
          "indicator_count": 3110,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1310 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62951232023c3cdc0a0f7a1c",
          "name": "support.apple.com:de-de:HT204247%22",
          "description": "",
          "modified": "2022-06-29T00:00:46.963000",
          "created": "2022-05-30T18:51:30.784000",
          "tags": [],
          "references": [
            "support.apple.com:de-de:HT204247%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 423,
            "hostname": 188,
            "domain": 33,
            "FileHash-SHA256": 278,
            "CIDR": 3,
            "FileHash-MD5": 4
          },
          "indicator_count": 929,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1391 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62950fb67eafeb1abddac9e6",
          "name": "music.apple.com:deeplink?p=subscribe-",
          "description": "",
          "modified": "2022-06-29T00:00:46.963000",
          "created": "2022-05-30T18:40:54.292000",
          "tags": [],
          "references": [
            "music.apple.com:deeplink?p=subscribe-.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 266,
            "domain": 32,
            "URL": 552,
            "FileHash-SHA256": 464,
            "CIDR": 3,
            "FileHash-MD5": 158
          },
          "indicator_count": 1475,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1391 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6294ec64b4e171f3a7107138",
          "name": "www.icloud.com:%22,",
          "description": "",
          "modified": "2022-06-29T00:00:46.963000",
          "created": "2022-05-30T16:10:12.299000",
          "tags": [],
          "references": [
            "www.icloud.com:%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 140,
            "URL": 196,
            "domain": 48,
            "FileHash-SHA256": 241,
            "CIDR": 5,
            "FileHash-MD5": 6
          },
          "indicator_count": 636,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1391 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6294eb02fc943581d0bf4ef1",
          "name": "www.apple.com:airtag:?cid=CDM-USA-DM-P0021742-498177%22",
          "description": "",
          "modified": "2022-06-29T00:00:46.963000",
          "created": "2022-05-30T16:04:18.749000",
          "tags": [],
          "references": [
            "www.apple.com:airtag:?cid=CDM-USA-DM-P0021742-498177%22,           %22request%22:.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 489,
            "hostname": 80,
            "domain": 38,
            "FileHash-SHA256": 518,
            "CIDR": 2,
            "FileHash-MD5": 5
          },
          "indicator_count": 1132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1391 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6254b50f075fa30a99c7021c",
          "name": "http://milab.cs.purded.edu/media/tasklog/  - a lot of data",
          "description": "http://milab.cs.purdue.edu/media/tasklog/bdc8bf95-e987-4a6f-b1ff-05a9e6e0b4a5/CEXP_15519067005351d04a-bf72-4df4-808a-5c67b40f0754_esp.txt\n\nhttp://milab.cs.purdue.edu/media/tasklog/fd60d718-4d6b-40b3-9e58-7b98cf1926a9/CEXP_155185615171517675-b8e9-4f8d-8037-c653e15a1646_esp.txt\nhttp://milab.cs.purdue.edu/media/tasklog/b4eff735-7a01-4a85-8a47-83ba1eaaaf12/CEXP_1551906810861a9201-696e-4aaf-a0da-08ce69d2b709_esp.txt\nhttp://milab.cs.purdue.edu/media/tasklog/e955eceb-a623-424f-9067-9cbb00e1ba93/CEXP_15519006996bbfc155-775c-4bde-9e5c-cccca344ce12_esp.txt",
          "modified": "2022-05-11T00:02:13.446000",
          "created": "2022-04-11T23:09:03.497000",
          "tags": [
            "ts val",
            "flags",
            "unknown",
            "ip6 fe80",
            "tcid",
            "icmp6",
            "ei6oa",
            "smhl4",
            "nonpx",
            "scls"
          ],
          "references": [
            "http://milab.cs.purdue.edu/media/tasklog/fd60d718-4d6b-40b3-9e58-7b98cf1926a9/CEXP_155185615171517675-b8e9-4f8d-8037-c653e15a1646_esp.txt",
            "http://milab.cs.purdue.edu/media/tasklog/bdc8bf95-e987-4a6f-b1ff-05a9e6e0b4a5/CEXP_15519067005351d04a-bf72-4df4-808a-5c67b40f0754_esp.txt",
            "http://milab.cs.purdue.edu/media/tasklog/b4eff735-7a01-4a85-8a47-83ba1eaaaf12/CEXP_1551906810861a9201-696e-4aaf-a0da-08ce69d2b709_esp.txt",
            "http://milab.cs.purdue.edu/media/tasklog/e955eceb-a623-424f-9067-9cbb00e1ba93/CEXP_15519006996bbfc155-775c-4bde-9e5c-cccca344ce12_esp.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 929,
            "hostname": 482,
            "domain": 403,
            "FileHash-SHA256": 161
          },
          "indicator_count": 1975,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 395,
          "modified_text": "1440 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6254b50d3a75591979e89aff",
          "name": "http://milab.cs.purded.edu/media/tasklog/  - a lot of data",
          "description": "http://milab.cs.purdue.edu/media/tasklog/bdc8bf95-e987-4a6f-b1ff-05a9e6e0b4a5/CEXP_15519067005351d04a-bf72-4df4-808a-5c67b40f0754_esp.txt\n\nhttp://milab.cs.purdue.edu/media/tasklog/fd60d718-4d6b-40b3-9e58-7b98cf1926a9/CEXP_155185615171517675-b8e9-4f8d-8037-c653e15a1646_esp.txt\nhttp://milab.cs.purdue.edu/media/tasklog/b4eff735-7a01-4a85-8a47-83ba1eaaaf12/CEXP_1551906810861a9201-696e-4aaf-a0da-08ce69d2b709_esp.txt\nhttp://milab.cs.purdue.edu/media/tasklog/e955eceb-a623-424f-9067-9cbb00e1ba93/CEXP_15519006996bbfc155-775c-4bde-9e5c-cccca344ce12_esp.txt",
          "modified": "2022-05-11T00:02:13.446000",
          "created": "2022-04-11T23:09:01.491000",
          "tags": [
            "ts val",
            "flags",
            "unknown",
            "ip6 fe80",
            "tcid",
            "icmp6",
            "ei6oa",
            "smhl4",
            "nonpx",
            "scls"
          ],
          "references": [
            "http://milab.cs.purdue.edu/media/tasklog/fd60d718-4d6b-40b3-9e58-7b98cf1926a9/CEXP_155185615171517675-b8e9-4f8d-8037-c653e15a1646_esp.txt",
            "http://milab.cs.purdue.edu/media/tasklog/bdc8bf95-e987-4a6f-b1ff-05a9e6e0b4a5/CEXP_15519067005351d04a-bf72-4df4-808a-5c67b40f0754_esp.txt",
            "http://milab.cs.purdue.edu/media/tasklog/b4eff735-7a01-4a85-8a47-83ba1eaaaf12/CEXP_1551906810861a9201-696e-4aaf-a0da-08ce69d2b709_esp.txt",
            "http://milab.cs.purdue.edu/media/tasklog/e955eceb-a623-424f-9067-9cbb00e1ba93/CEXP_15519006996bbfc155-775c-4bde-9e5c-cccca344ce12_esp.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 929,
            "hostname": 482,
            "domain": 403,
            "FileHash-SHA256": 161
          },
          "indicator_count": 1975,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 393,
          "modified_text": "1440 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "623b79549932302fcfd8a8a9",
          "name": "apps.apple.com:us:app:theskimm:id1034995058%22,",
          "description": "",
          "modified": "2022-04-22T00:03:50.614000",
          "created": "2022-03-23T19:47:32.321000",
          "tags": [],
          "references": [
            "apps.apple.com:us:app:theskimm:id1034995058%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 222,
            "URL": 362,
            "domain": 28,
            "FileHash-SHA256": 363,
            "email": 1,
            "CIDR": 1,
            "FileHash-MD5": 59
          },
          "indicator_count": 1036,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1459 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6231e48eb1fb59ef10548bc6",
          "name": "apps.crowdtangle.com:chrome-extension%22",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T13:22:22.953000",
          "tags": [
            "WannaCry"
          ],
          "references": [
            "apps.crowdtangle.com:chrome-extension%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Win.Ransomware.WannaCry-9856297-0",
              "display_name": "Win.Ransomware.WannaCry-9856297-0",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 313,
            "URL": 881,
            "domain": 123,
            "FileHash-SHA256": 796,
            "CIDR": 9,
            "FileHash-MD5": 50,
            "FileHash-SHA1": 2
          },
          "indicator_count": 2174,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1466 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6231b7fd00609c5f8465e5df",
          "name": "apps.apple.com:app:id853371601?utm_campaign=MPR- en&utm_medium=email&utm_source=MyBusiness-GMB-en%22,.pdf",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T10:12:13.832000",
          "tags": [],
          "references": [
            "apps.apple.com:app:id853371601?utm_campaign=MPR- en&utm_medium=email&utm_source=MyBusiness-GMB-en%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 426,
            "URL": 350,
            "domain": 23,
            "hostname": 157,
            "email": 1,
            "CIDR": 5,
            "FileHash-MD5": 61
          },
          "indicator_count": 1023,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1466 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6231b8c75c00dc7eb498994a",
          "name": "apps.apple.com:app:id1040093707?mt=8%22",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T10:15:35.074000",
          "tags": [],
          "references": [
            "apps.apple.com:app:id1040093707?mt=8%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 208,
            "URL": 343,
            "FileHash-SHA256": 387,
            "domain": 31,
            "email": 1,
            "CIDR": 1,
            "FileHash-MD5": 70
          },
          "indicator_count": 1041,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1466 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6231ba5a96572fb746c07098",
          "name": "apps.apple.com:us:app:coinbase-bitcoin-wallet:id886427730? utm_campaign=campaign_2737332&utm_medium=email&utm_source=Iterable%22,.pdf",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T10:22:18.503000",
          "tags": [],
          "references": [
            "apps.apple.com:us:app:coinbase-bitcoin-wallet:id886427730? utm_campaign=campaign_2737332&utm_medium=email&utm_source=Iterable%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 26,
            "FileHash-SHA256": 392,
            "URL": 344,
            "hostname": 150,
            "email": 2,
            "FileHash-MD5": 65,
            "FileHash-SHA1": 1
          },
          "indicator_count": 980,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1466 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6231bb17924fbfee6900bc6d",
          "name": "apps.apple.com:us:app:theskimm:id1034995058%22",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T10:25:27.785000",
          "tags": [],
          "references": [
            "apps.apple.com:us:app:theskimm:id1034995058%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 279,
            "domain": 19,
            "hostname": 188,
            "FileHash-SHA256": 362,
            "email": 1,
            "CIDR": 1,
            "FileHash-MD5": 59
          },
          "indicator_count": 909,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1466 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6231eff11998f0376e1e3edf",
          "name": "cass.ballottrax.net:voter:%22",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T14:10:57.861000",
          "tags": [],
          "references": [
            "cass.ballottrax.net:voter:%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 511,
            "hostname": 145,
            "domain": 121,
            "FileHash-SHA256": 640,
            "CIDR": 5,
            "FileHash-MD5": 10
          },
          "indicator_count": 1432,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1466 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "623224f0534ee0708b12ebd6",
          "name": "mesacounty.us_05.21.2019",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T17:57:04.363000",
          "tags": [],
          "references": [
            "mesacounty.us_05.21.2019.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 494,
            "domain": 65,
            "FileHash-SHA256": 706,
            "hostname": 165,
            "CIDR": 1,
            "FileHash-MD5": 6
          },
          "indicator_count": 1437,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1466 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6230f641aa7ee98e0cf54ff1",
          "name": "apps.apple.com:us:app:virgin-pulse:id793322895?.",
          "description": "",
          "modified": "2022-04-14T00:01:40.805000",
          "created": "2022-03-15T20:25:37.053000",
          "tags": [],
          "references": [
            "apps.apple.com:us:app:virgin-pulse:id793322895?.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 414,
            "domain": 30,
            "hostname": 200,
            "FileHash-SHA256": 361,
            "email": 3,
            "CIDR": 5,
            "FileHash-MD5": 56
          },
          "indicator_count": 1069,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1467 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6230e0c5997d9783e5d83f74",
          "name": "www.apple.com:ipad:cellular.%22",
          "description": "",
          "modified": "2022-04-14T00:01:40.805000",
          "created": "2022-03-15T18:53:57.725000",
          "tags": [],
          "references": [
            "www.apple.com:ipad:cellular.%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 289,
            "hostname": 95,
            "domain": 25,
            "FileHash-SHA256": 233,
            "CIDR": 1,
            "FileHash-MD5": 3
          },
          "indicator_count": 646,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1467 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6230e19d7d96c52a97e1f745",
          "name": "apple.com:sg:iphone:cellular.09.18.21.",
          "description": "",
          "modified": "2022-04-14T00:01:40.805000",
          "created": "2022-03-15T18:57:33.586000",
          "tags": [],
          "references": [
            "apple.com:sg:iphone:cellular.09.18.21.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 132,
            "URL": 364,
            "domain": 26,
            "FileHash-SHA256": 248,
            "CIDR": 1,
            "FileHash-MD5": 3
          },
          "indicator_count": 774,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1467 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.virustotal.com/gui/collection/a5d9ceedc1dd9b912db6270e583ef306f5d3130912ffe4c519496cb53b2179f9/graph",
        "dcdemocraticparty.org.pdf",
        "dananessel.com.pdf",
        "https://www.virustotal.com/graph/embed/g14ccc2b5794648cc838da283a8fbfcda4d95dde6ddc44798be19c2832778787f?theme=dark",
        "apps.apple.com:us:app:theskimm:id1034995058%22,.pdf",
        "https://mwdb.cert.pl/file/efb45096e24a61b488eb809bd8edf874d15bb498dd75ced8b888b020c87e5c6c",
        "apps.apple.com:app:id853371601?utm_campaign=MPR- en&utm_medium=email&utm_source=MyBusiness-GMB-en%22,.pdf",
        "apple.com:sg:iphone:cellular.09.18.21.pdf",
        "e.com",
        "https://www.virustotal.com/gui/collection/a5d9ceedc1dd9b912db6270e583ef306f5d3130912ffe4c519496cb53b2179f9/summary",
        "www.apple.com:airtag:?cid=CDM-USA-DM-P0021742-498177%22,           %22request%22:.pdf",
        "support.apple.com:de-de:HT204247%22,.pdf",
        "http://milab.cs.purdue.edu/media/tasklog/b4eff735-7a01-4a85-8a47-83ba1eaaaf12/CEXP_1551906810861a9201-696e-4aaf-a0da-08ce69d2b709_esp.txt",
        "Here is the full text of the request for the image of Favicon, which was sent to the appie.com website by the US government in 2008.. and the subject:.",
        "http://milab.cs.purdue.edu/media/tasklog/e955eceb-a623-424f-9067-9cbb00e1ba93/CEXP_15519006996bbfc155-775c-4bde-9e5c-cccca344ce12_esp.txt",
        "apps.apple.com:app:id1040093707?mt=8%22,.pdf",
        "I first found this like 3 or 4 years ago cant belive its still a thing - appie.com/favicon.ico - change the i to a capital I",
        "https://hybrid-analysis.com/sample/29e0152b350f004f7dfe6f2188d014aab87a723b9c4b613c579f6add610242b8/63bcd2c7dc34a339c406a344",
        "https://metadefender.com/results/file/bzI1MDMwMVFWaXRDS0hpWElYcnV0QllCYlB1",
        "apps.crowdtangle.com:chrome-extension%22,.pdf",
        "music.apple.com:deeplink?p=subscribe-.pdf",
        "www.icloud.com:%22,.pdf",
        "https://myaccount.google.com/u/1/accountlinking?hl=en-GB",
        "www.apple.com:ipad:cellular.%22,.pdf",
        "mesacounty.us_05.21.2019.pdf",
        "https://www.hybrid-analysis.com/sample/134aa68a3c3fdc7232e01975247699b806576d0954e695042f44f4b74a7acba1/63c883a9634ab92b2b44d552",
        "https://n0paste.eu/UH6n5pD/",
        "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f",
        "http://milab.cs.purdue.edu/media/tasklog/fd60d718-4d6b-40b3-9e58-7b98cf1926a9/CEXP_155185615171517675-b8e9-4f8d-8037-c653e15a1646_esp.txt",
        "apps.apple.com:us:app:virgin-pulse:id793322895?.pdf",
        "cass.ballottrax.net:voter:%22,.pdf",
        "apps.apple.com:us:app:coinbase-bitcoin-wallet:id886427730? utm_campaign=campaign_2737332&utm_medium=email&utm_source=Iterable%22,.pdf",
        "http://milab.cs.purdue.edu/media/tasklog/bdc8bf95-e987-4a6f-b1ff-05a9e6e0b4a5/CEXP_15519067005351d04a-bf72-4df4-808a-5c67b40f0754_esp.txt",
        "dos.myflorida.com:elections.pdf",
        "https://www.virustotal.com/gui/collection/a5d9ceedc1dd9b912db6270e583ef306f5d3130912ffe4c519496cb53b2179f9/iocs"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Ransom:win32/wannaren.a",
            "Valhalla",
            "Win.ransomware.wannacry-9856297-0",
            "Php"
          ],
          "industries": [
            "Technology",
            "Government",
            "Healthcare",
            "Telecommunications",
            "Education"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 50,
  "pulses": [
    {
      "id": "699969651d3b082f6b583fae",
      "name": "PDFKIT.net",
      "description": "Data Points. Search tall components CVE's for more info on this.",
      "modified": "2026-04-01T00:44:45.494000",
      "created": "2026-02-21T08:14:29.258000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 370,
        "hostname": 444,
        "FileHash-SHA1": 1292,
        "FileHash-SHA256": 4067,
        "URL": 192,
        "FileHash-MD5": 1255,
        "email": 16,
        "CVE": 58
      },
      "indicator_count": 7694,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 50,
      "modified_text": "19 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69aa7a7b91633d9a88f06f85",
      "name": "Q Vashti post \"monitored target\"",
      "description": "",
      "modified": "2026-03-06T16:17:21.212000",
      "created": "2026-03-06T06:55:55.582000",
      "tags": [
        "indicator",
        "source",
        "ck id",
        "show technique",
        "mitre att",
        "ck matrix",
        "openservice",
        "sha384",
        "file",
        "virtualfree",
        "path",
        "getprocaddress",
        "pattern match",
        "potential ip",
        "open",
        "date",
        "click",
        "error",
        "null",
        "false",
        "stream",
        "enterprise",
        "body",
        "crypto",
        "compiler",
        "entropy",
        "refresh",
        "download",
        "factory",
        "bind",
        "strings",
        "twitter",
        "roboto",
        "contact",
        "window",
        "tools",
        "span",
        "value",
        "access type",
        "file execution",
        "setval",
        "userprofile",
        "debugger",
        "hybrid",
        "persistence",
        "general",
        "suspicious",
        "target"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1569",
          "name": "System Services",
          "display_name": "T1569 - System Services"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1029",
          "name": "Scheduled Transfer",
          "display_name": "T1029 - Scheduled Transfer"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1124",
          "name": "System Time Discovery",
          "display_name": "T1124 - System Time Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1213",
          "name": "Data from Information Repositories",
          "display_name": "T1213 - Data from Information Repositories"
        },
        {
          "id": "T1217",
          "name": "Browser Bookmark Discovery",
          "display_name": "T1217 - Browser Bookmark Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1559",
          "name": "Inter-Process Communication",
          "display_name": "T1559 - Inter-Process Communication"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1565",
          "name": "Data Manipulation",
          "display_name": "T1565 - Data Manipulation"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "68409862e1722725233acace",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 54,
        "FileHash-SHA1": 35,
        "FileHash-SHA256": 24,
        "SSLCertFingerprint": 3,
        "URL": 296,
        "domain": 317,
        "hostname": 648,
        "email": 3
      },
      "indicator_count": 1380,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 47,
      "modified_text": "44 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "695cc5b5337bc1ac1273946a",
      "name": "Macbook Air Macbook Air",
      "description": "Macbook Air Macbook Air",
      "modified": "2026-02-05T07:00:52.044000",
      "created": "2026-01-06T08:20:05.305000",
      "tags": [
        "doctype",
        "public",
        "data",
        "drive",
        "problems1",
        "no problems",
        "upload",
        "tue aug",
        "scanid",
        "archivetype",
        "june",
        "look",
        "accept",
        "internal",
        "ransomware",
        "error",
        "trace",
        "sparkle",
        "fusion",
        "alphabet",
        "path",
        "archivesize",
        "archivemd5",
        "archivesha256",
        "open",
        "whirlpool",
        "syst",
        "stream",
        "mercury",
        "import",
        "info",
        "dangerous file",
        "modified",
        "tue jul",
        "mon sep",
        "mon mar",
        "sigtype1",
        "false",
        "warp",
        "powershell",
        "specs",
        "subscore1",
        "Mac",
        "Apple"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 12573,
        "FileHash-SHA1": 14594,
        "FileHash-SHA256": 12489,
        "URL": 88,
        "domain": 98,
        "email": 15,
        "hostname": 119
      },
      "indicator_count": 39976,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 128,
      "modified_text": "73 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "695ca8b688eb56b3a0247098",
      "name": "System32 - Subfolders",
      "description": "E:\\Suss-SG2\\System32 - Subfolders.zip",
      "modified": "2026-02-05T06:03:21.110000",
      "created": "2026-01-06T06:16:22.880000",
      "tags": [
        "tue apr",
        "scanid",
        "mon mar",
        "archivesize",
        "archivesha1",
        "archivesha256",
        "archivecreated",
        "f archiveowner",
        "sigtype1",
        "sigclass1",
        "look",
        "powershell",
        "first",
        "strings",
        "dllinject",
        "june",
        "span",
        "error",
        "fail",
        "rooter",
        "info",
        "alphabet",
        "false",
        "path",
        "service",
        "dword",
        "shell",
        "model",
        "assistant",
        "code",
        "syst",
        "checker",
        "rest",
        "core",
        "tencent",
        "null",
        "accept",
        "open",
        "pass",
        "internal",
        "meta",
        "root",
        "desktop",
        "window",
        "maximu",
        "stream",
        "android",
        "comp",
        "date",
        "whirlpool",
        "kevin",
        "sett",
        "locale",
        "cloud",
        "malware",
        "class"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 148,
        "CIDR": 2,
        "FileHash-MD5": 9860,
        "FileHash-SHA1": 10592,
        "FileHash-SHA256": 8443,
        "domain": 147,
        "email": 6,
        "hostname": 49
      },
      "indicator_count": 29247,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 130,
      "modified_text": "73 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6954ae6971517cdd7beb3d77",
      "name": "Security Vendors\\Norton",
      "description": "Security Vendors\\Norton",
      "modified": "2026-01-30T04:03:08.625000",
      "created": "2025-12-31T05:02:33.034000",
      "tags": [
        "data",
        "drive",
        "no problems",
        "upload",
        "mon mar",
        "scanid",
        "sigtype1",
        "sigclass1",
        "rule matched1",
        "subscore1",
        "look",
        "june",
        "dllinject",
        "alphabet",
        "info",
        "winmm",
        "null",
        "malware",
        "powershell",
        "autorun",
        "jack",
        "first",
        "internal",
        "whirlpool",
        "updater",
        "code",
        "spyeye",
        "runescape",
        "warp",
        "upgrade",
        "copy",
        "defender",
        "date",
        "xmrigminer",
        "kevin",
        "eraser",
        "ding",
        "Norton",
        "Telus"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1110",
          "name": "Brute Force",
          "display_name": "T1110 - Brute Force"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 59,
        "URL": 42,
        "CVE": 2,
        "FileHash-MD5": 1355,
        "FileHash-SHA1": 1177,
        "FileHash-SHA256": 948,
        "email": 4,
        "hostname": 37
      },
      "indicator_count": 3624,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 130,
      "modified_text": "79 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69546fab13abfdf3e825b1e4",
      "name": "Norton\\08.30.23",
      "description": "Norton\\08.30.23",
      "modified": "2026-01-30T00:01:11.705000",
      "created": "2025-12-31T00:34:51.728000",
      "tags": [
        "data",
        "drive",
        "no problems",
        "upload",
        "problems1",
        "progressb",
        "wed aug",
        "scanid",
        "mon mar",
        "sigtype1",
        "look",
        "june",
        "dllinject",
        "winmm",
        "alphabet",
        "autorun",
        "powershell",
        "info",
        "malware",
        "first",
        "jack",
        "whirlpool",
        "internal",
        "surtr",
        "ursnif",
        "code",
        "spyeye",
        "runescape",
        "warp",
        "null",
        "defender",
        "copy",
        "strings",
        "burn",
        "dreambot",
        "gozi",
        "isfb",
        "iron",
        "bitcoin",
        "steam",
        "date",
        "xmrigminer",
        "kevin",
        "ding",
        "Norton",
        "Telus"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1110",
          "name": "Brute Force",
          "display_name": "T1110 - Brute Force"
        }
      ],
      "industries": [
        "Technology",
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 52,
        "URL": 37,
        "CVE": 1,
        "FileHash-MD5": 1241,
        "FileHash-SHA1": 879,
        "FileHash-SHA256": 823,
        "email": 4,
        "hostname": 26
      },
      "indicator_count": 3063,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 129,
      "modified_text": "80 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "694b02eb945649ff909f06d5",
      "name": "$RECYCLE . BIN\\ -> Part 2",
      "description": "E:\\Suss-SG2\\$RECYCLE.BIN\\\n\nVictim Google Pixel Telus ISP Norton AV Device\nDevice connected to AHS/Covenant Health, University of Alberta, Government of Alberta",
      "modified": "2026-01-28T02:03:16.337000",
      "created": "2025-12-23T21:00:27.029000",
      "tags": [
        "Telus",
        "YEG",
        "AHS",
        "Pixel",
        "ConnectCare",
        "Norton",
        "UAlberta",
        "Google"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada",
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Government",
        "Education",
        "Technology",
        "Telecommunications",
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 65761,
        "FileHash-SHA1": 56561,
        "FileHash-SHA256": 43672,
        "domain": 1373,
        "email": 39,
        "URL": 466,
        "hostname": 818,
        "CVE": 3,
        "CIDR": 2
      },
      "indicator_count": 168695,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 129,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "68409862e1722725233acace",
      "name": "Monitored Target- bounty-50872035906958562",
      "description": "Monitored Target- bounty-50872035906958562\n(Whitelisted?)\n\u2022 Spyware\nAccesses potentially sensitive information from local browsers |\n\u2022Found a string that may be used as part of an injection method |\n\u2022 Stealer/Phishing\n\u2022 Reads FTP client related files\n\u2022 Persistence\n\u2022 Creates a fake system process\n\u2022 Modifies System Certificates Settings\n\u2022 Modifies auto-execute functionality by setting/creating a value in the registry\n\u2022 Modifies auto-execute functionality to enable the debugger hack\n\u2022 Writes data to a remote process\n\u2022 Writes to the hosts file\n\u2022 Fingerprint\nQueries +",
      "modified": "2025-07-04T18:05:18.397000",
      "created": "2025-06-04T19:02:57.999000",
      "tags": [
        "indicator",
        "source",
        "ck id",
        "show technique",
        "mitre att",
        "ck matrix",
        "openservice",
        "sha384",
        "file",
        "virtualfree",
        "path",
        "getprocaddress",
        "pattern match",
        "potential ip",
        "open",
        "date",
        "click",
        "error",
        "null",
        "false",
        "stream",
        "enterprise",
        "body",
        "crypto",
        "compiler",
        "entropy",
        "refresh",
        "download",
        "factory",
        "bind",
        "strings",
        "twitter",
        "roboto",
        "contact",
        "window",
        "tools",
        "span",
        "value",
        "access type",
        "file execution",
        "setval",
        "userprofile",
        "debugger",
        "hybrid",
        "persistence",
        "general",
        "suspicious",
        "target"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/12e727ab081000ced2629fef1d40f"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1569",
          "name": "System Services",
          "display_name": "T1569 - System Services"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1021",
          "name": "Remote Services",
          "display_name": "T1021 - Remote Services"
        },
        {
          "id": "T1029",
          "name": "Scheduled Transfer",
          "display_name": "T1029 - Scheduled Transfer"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1049",
          "name": "System Network Connections Discovery",
          "display_name": "T1049 - System Network Connections Discovery"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1087",
          "name": "Account Discovery",
          "display_name": "T1087 - Account Discovery"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1124",
          "name": "System Time Discovery",
          "display_name": "T1124 - System Time Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1213",
          "name": "Data from Information Repositories",
          "display_name": "T1213 - Data from Information Repositories"
        },
        {
          "id": "T1217",
          "name": "Browser Bookmark Discovery",
          "display_name": "T1217 - Browser Bookmark Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1559",
          "name": "Inter-Process Communication",
          "display_name": "T1559 - Inter-Process Communication"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1565",
          "name": "Data Manipulation",
          "display_name": "T1565 - Data Manipulation"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 54,
        "FileHash-SHA1": 35,
        "FileHash-SHA256": 24,
        "SSLCertFingerprint": 3,
        "URL": 294,
        "domain": 317,
        "hostname": 648,
        "email": 3
      },
      "indicator_count": 1378,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 139,
      "modified_text": "289 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67fa493f49755096b93cd648",
      "name": "AkiraBot\u2019s Use of GPT Models in Web Channel Abuse",
      "description": "Here is a full list of domains, websites and services used by people to send spam, spam and other spam messages:. and here is the full set of names: (Snob):.",
      "modified": "2025-04-12T11:06:39.048000",
      "created": "2025-04-12T11:06:39.048000",
      "tags": [
        "servicewrap",
        "beservicewrap",
        "getkira",
        "gogoservicewrap",
        "goservicewrap",
        "joinnowkira",
        "joinuseakira",
        "kiraone",
        "loveservice",
        "mybkira",
        "service"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "cryptocti",
        "id": "110256",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 26,
        "URL": 1,
        "domain": 1
      },
      "indicator_count": 28,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 486,
      "modified_text": "372 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "66f235b9a7a94a6a61acd651",
      "name": "n0paste - Show paste: \\\"No Problems\\\" - dos meses del URLscan",
      "description": "This pulse represents a 'scattered sample' of data extracted from 'submissions of interest' made to virustotal, filescan_itsec, HybridAnalysis, anyrun_app, DynamiteLab, and triage (over a period of two months) which were submitted to urlscanio & subsequently GreyNoiseIO (which I've come across both from live samples and also those from offlined data). I don't particularly anticipate this will correlate w. anything specific - but at least will be put in one more place for further analysis & increased visibility.",
      "modified": "2025-03-07T08:38:08.584000",
      "created": "2024-09-24T03:44:57.902000",
      "tags": [
        "geoip",
        "public url",
        "as16509",
        "amazon02",
        "as20940",
        "akamaiasn1",
        "as8075",
        "as15169",
        "google",
        "akamaias",
        "facebook",
        "telecom",
        "twitter",
        "media",
        "win64",
        "level3",
        "mini",
        "ukraine",
        "proton",
        "ghost",
        "win32",
        "cuba",
        "mexico",
        "indonesia",
        "seznam",
        "as3359",
        "as852"
      ],
      "references": [
        "https://metadefender.com/results/file/bzI1MDMwMVFWaXRDS0hpWElYcnV0QllCYlB1",
        "https://mwdb.cert.pl/file/efb45096e24a61b488eb809bd8edf874d15bb498dd75ced8b888b020c87e5c6c",
        "https://n0paste.eu/UH6n5pD/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada",
        "Anguilla",
        "Poland",
        "Aruba",
        "Australia",
        "Barbados",
        "Costa Rica",
        "Guatemala",
        "Philippines",
        "Panama",
        "Sint Maarten (Dutch part)",
        "Saint Martin (French part)",
        "Cayman Islands",
        "Cura\u00e7ao",
        "Mexico",
        "Saint Vincent and the Grenadines",
        "Saint Kitts and Nevis",
        "Tanzania, United Republic of",
        "Netherlands",
        "Ukraine",
        "Trinidad and Tobago",
        "Japan",
        "Bahamas",
        "United Kingdom of Great Britain and Northern Ireland",
        "Georgia"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education",
        "Technology",
        "Government",
        "Telecommunications",
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1,
        "CIDR": 1186,
        "CVE": 4,
        "FileHash-MD5": 29,
        "FileHash-SHA1": 3,
        "URL": 25493,
        "domain": 5396,
        "email": 10,
        "hostname": 10770
      },
      "indicator_count": 42892,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 147,
      "modified_text": "408 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "e.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "e.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776648222.6527333
}