{
  "type": "Domain",
  "indicator": "e.tm",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/e.tm",
    "alexa": "http://www.alexa.com/siteinfo/e.tm",
    "indicator": "e.tm",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3262125391,
      "indicator": "e.tm",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "65708c534aadf7adf4f27d77",
          "name": "enom.com & 4vendeta.com - ReduceRight malware hosting/creation",
          "description": "",
          "modified": "2023-12-06T14:59:31.122000",
          "created": "2023-12-06T14:59:31.122000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 302,
            "domain": 634,
            "URL": 2988,
            "hostname": 1208
          },
          "indicator_count": 5132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63ed77f49d449cb532e24728",
          "name": "hybrid scan of twitch cdn js file",
          "description": "function E(e,t,r,n, if i+= String.fromCharCode(a) if I am not a member of the C.subarray, or i-d.",
          "modified": "2023-03-18T00:05:45.328000",
          "created": "2023-02-16T00:25:24.282000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "localappdata",
            "unicode",
            "hash seen",
            "size",
            "runtime process",
            "sha256",
            "temp",
            "sha1",
            "suspicious",
            "hybrid",
            "close",
            "click",
            "hosts",
            "ransomware",
            "february",
            "general",
            "strings",
            "malicious",
            "date",
            "error",
            "uint8array",
            "typeerror",
            "array",
            "regexp",
            "textdecoder",
            "57343",
            "typeof r",
            "12863",
            "void",
            "path",
            "april",
            "june",
            "august",
            "generator",
            "null"
          ],
          "references": [
            "https://static.twitchcdn.net/assets/amazon-ivs-wasmworker.min-28c086bb59605350be07.js",
            "https://hybrid-analysis.com/sample/bcbea668407e956a651826abd5e59e4a473536465863e4af18949529e88db35d/63ed6cf79611136f180fde53"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 256,
            "hostname": 57,
            "domain": 48,
            "FileHash-SHA256": 81,
            "FileHash-MD5": 51,
            "FileHash-SHA1": 50
          },
          "indicator_count": 543,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1171 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63ed767fb937767a5e0ff9bf",
          "name": "https://static.twitchcdn.net/assets/amazon-ivs-wasmworker.min-28c086bb59605350be07.js",
          "description": "function E(e,t,r,n, if i+= String.fromCharCode(a) if I am not a member of the C.subarray, or i-d.",
          "modified": "2023-02-16T00:19:11.372000",
          "created": "2023-02-16T00:19:11.372000",
          "tags": [
            "date",
            "error",
            "uint8array",
            "typeerror",
            "array",
            "regexp",
            "textdecoder",
            "57343",
            "typeof r",
            "12863",
            "void",
            "path",
            "february",
            "april",
            "june",
            "august",
            "generator",
            "null"
          ],
          "references": [
            "https://static.twitchcdn.net/assets/amazon-ivs-wasmworker.min-28c086bb59605350be07.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 230,
            "hostname": 56,
            "FileHash-SHA256": 20,
            "domain": 41
          },
          "indicator_count": 347,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1201 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62616627ee302d24b23523c3",
          "name": "enom.com & 4vendeta.com - ReduceRight malware hosting/creation",
          "description": "New RegExp(M) is a new type, and it will change any of the elements to the same type if you want to add them to your HTML page or add a third element.",
          "modified": "2022-05-21T00:03:44.725000",
          "created": "2022-04-21T14:11:51.629000",
          "tags": [
            "tbody",
            "span",
            "thead",
            "tfoot",
            "multiple",
            "type",
            "href",
            "input",
            "halflings",
            "gradienttype1",
            "twitter",
            "false",
            "fontface",
            "fatface",
            "woff2",
            "u0259",
            "u1e001eff",
            "u2020",
            "u20a020ab",
            "u20ad20cf",
            "u2113",
            "u2c602c7f",
            "typesubmit",
            "function",
            "typeof c",
            "formdata",
            "this",
            "typeof define",
            "null",
            "typeof f",
            "object",
            "boolean",
            "typeof module",
            "error",
            "reflect",
            "math",
            "regexp",
            "number",
            "array",
            "typeerror",
            "string",
            "symbol",
            "typeof e",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "js foundation",
            "account",
            "open",
            "navitem",
            "text",
            "mainnav",
            "click",
            "blank",
            "copyright",
            "u0027",
            "value",
            "body",
            "firefox",
            "enum",
            "html",
            "msie",
            "applewebkit",
            "traceconsole",
            "form",
            "iframe",
            "legend",
            "nonmsdombrowser",
            "callbackindex",
            "callbackframeid",
            "eventtarget",
            "eventargument",
            "validation",
            "explorer",
            "target",
            "plugin",
            "bootstrap",
            "https",
            "conflict",
            "focus",
            "next",
            "trigger",
            "checkbox",
            "delta",
            "scroll",
            "sourceid",
            "date",
            "sessiontoken",
            "sessionexpires",
            "void",
            "rangeerror",
            "utf16",
            "illegal input",
            "global",
            "chrome",
            "opredge",
            "opera",
            "safari",
            "version",
            "sxa0",
            "browser",
            "typeof require",
            "dom node",
            "typeof d",
            "component",
            "typeof h",
            "bubble",
            "reduceright",
            "script",
            "typeof n",
            "jhnew ia",
            "gtm5sn6brv",
            "path",
            "host",
            "trackpageview",
            "gw8yd4p2eny",
            "select",
            "strong",
            "uint8array",
            "android",
            "verify",
            "stop",
            "enterprise",
            "widget",
            "window",
            "generator",
            "reload",
            "r300",
            "caca",
            "closure library",
            "xdfunction",
            "adfunction",
            "cdfunction",
            "ddfunction",
            "bded",
            "please",
            "typeemail",
            "email",
            "jarallaxinner",
            "webkit",
            "property",
            "transform",
            "trident",
            "edge",
            "ipodi",
            "ipadi",
            "androidi",
            "blackberryi",
            "windows phonei",
            "xfunction",
            "pfunction",
            "wfunction",
            "show navigation",
            "mjquery",
            "typeof",
            "defaulttype",
            "hidden",
            "show",
            "shown",
            "startr",
            "endr",
            "federico zivolo",
            "distributed",
            "mit license",
            "statict",
            "flip"
          ],
          "references": [
            "xfe-IP-78.142.35.163-stix2-2.1-export.json",
            "xfe-URL-Enom.com-stix2-2.1-export.json",
            "xfe-URL-4vendeta.com-stix2-2.1-export.json",
            "https://4vendeta.com/assets/js/jquery.min.js",
            "https://4vendeta.com/assets/js/popper.min.js",
            "https://4vendeta.com/assets/js/bootstrap.min.js",
            "https://4vendeta.com/assets/js/meanmenu.min.js",
            "https://4vendeta.com/assets/js/parallax.min.js",
            "https://4vendeta.com/assets/js/ajaxchimp.min.js",
            "https://www.googletagmanager.com/gtag/js?id=UA-92521958-1",
            "https://www.googletagmanager.com/gtag/js?id=G-W8YD4P2ENY&l=dataLayer&cx=c",
            "https://www.gstatic.com/recaptcha/releases/QENb_qRrX0-mQMyENQjD6Fuj/recaptcha__en.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-5SN6BRV",
            "https://static.zdassets.com/ekr/snippet.js?key=7342b695-e394-4f25-89a0-da9d262a48da",
            "https://cp.enom.com/js/jquery-3.5.1.min.js",
            "https://cp.enom.com/responsive/_js/knockout-3.3.0.min.js",
            "https://cp.enom.com/js/global-functions.js",
            "https://cp.enom.com/js/punycode.min.js",
            "https://cp.enom.com/js/jquery.disableonsubmit.min.js",
            "https://cp.enom.com/js/jquery.cookie.min.js",
            "https://cp.enom.com/js/cart.minicart.min.js",
            "https://cp.enom.com/js/openWin.min.js",
            "https://cp.enom.com/js/jquery.jgrowl.min.js",
            "https://cp.enom.com/scripts/Session.min.js",
            "https://cp.enom.com/responsive/_js/init.min.js",
            "https://cp.enom.com/responsive/_js/bootstrap.js",
            "https://cp.enom.com/WebResource.axd?d=6rtXrDcnyiYD-9dFDFOkxTRcPVSrAN8fR-cHKzNqPTy7bHic-2LLMHDnielTzEI-sd1KplHrRBudcZJOm0-lxubO7k41&t=637453818340000000",
            "https://cp.enom.com/ScriptResource.axd?d=fVjQa-0YyNqO6JmV36bw6eBJdTjE2YSdtcunOWcKYcBNn73MOJKQA_rxX3YMhcxLTgyDsGTKy0p9NEPvxzpqEpBKtm3GLb2GgI1LFYMC0Xr2lh71ZCttzgNGFnc5mS_Fc_DY5UH0M19Mr958h1jvmK4kzAM1&t=363be08",
            "https://cp.enom.com/ScriptResource.axd?d=lDjPFfAIWSrEAVNgTHTrISQmLEFmHAaibvNJQuGRZDbWpGFPLrFwaGVpjCUsI6HkqzbpwmaAa0cJCrq8f0eqEvIsQM8lvN_dVYVyESnohON4oTvdMZHDmwG83uJA4m2oqykP8TTTSIeV2oaNrlIXaX8cOxC5Cv6aGmjpdB2u-227wdn30&t=363be08",
            "https://cdn.optimizely.com/js/26241557.js",
            "https://cp.enom.com/verisign-seal.htm",
            "https://cp.enom.com/global/TopMenu.ascx.js",
            "http://alp-vision.com/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
            "http://alp-vision.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
            "http://alp-vision.com/wp-content/cache/autoptimize/js/autoptimize_78b4f9b28399aa3c8a405e45931ad058.js",
            "http://alp-vision.com/wp-includes/css/dist/block-library/style.min.css?ver=5.7.6",
            "http://fonts.googleapis.com/css?family=Abril+Fatface%3Aregular&subset=latin%2Ccyrillic&ver=5.7.6",
            "http://alp-vision.com/wp-content/themes/alp-vision/css/bootstrap.css?ver=1.0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2989,
            "hostname": 1208,
            "domain": 634,
            "FileHash-SHA256": 302
          },
          "indicator_count": 5133,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1472 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6261fd6a8d527fa569351e63",
          "name": "Malware hosting - unrealservers.net & heymman.com",
          "description": "function S.name, a.com, has been added to the end of a page to make sure it does not end up in an unauthorised place. and it will not get any more.",
          "modified": "2022-05-21T00:03:44.725000",
          "created": "2022-04-22T00:57:14.125000",
          "tags": [
            "e2f0fc",
            "fd7a07",
            "f0482b",
            "gradienttype0",
            "a5bcce",
            "helvetica",
            "negative",
            "arial",
            "bcd3e4",
            "style sheet",
            "nonce",
            "script",
            "please do",
            "not copy",
            "and paste",
            "this code",
            "cgrecaptchacfg",
            "ngrecaptcha",
            "recaptchaapi",
            "render",
            "onload",
            "select",
            "error",
            "strong",
            "uint8array",
            "string",
            "null",
            "number",
            "function",
            "input",
            "array",
            "iframe",
            "date",
            "android",
            "verify",
            "stop",
            "this",
            "span",
            "enterprise",
            "click",
            "widget",
            "window",
            "form",
            "generator",
            "reload",
            "void",
            "dd2d2f",
            "e8e8e8",
            "d8d8d8",
            "fcfcfc",
            "e5e5e5",
            "lucida",
            "unicode",
            "lucida grande",
            "f9f9f9",
            "footer",
            "unavailable",
            "ngsanitize",
            "order now",
            "invalid",
            "snippet",
            "month",
            "hours",
            "fullyear",
            "regexp",
            "eeee",
            "mmmm d",
            "mena",
            "christ"
          ],
          "references": [
            "xfe-URL-heymman.com-stix2-2.1-export.json",
            "https://ajax.googleapis.com/ajax/libs/angularjs/1.4.8/angular.min.js",
            "https://ajax.googleapis.com/ajax/libs/angularjs/1.4.2/angular-sanitize.js",
            "https://www.heymman.com/script.js",
            "https://www.heymman.com/style/main.css",
            "https://www.gstatic.com/recaptcha/releases/QENb_qRrX0-mQMyENQjD6Fuj/recaptcha__en.js",
            "https://www.google.com/recaptcha/api.js",
            "https://unrealservers.net/master.css",
            "xfe-URL-Ndevix.com-stix2-2.1-export.json",
            "xfe-URL-Misk.com-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 427,
            "URL": 1183,
            "FileHash-SHA256": 162,
            "domain": 441,
            "email": 4
          },
          "indicator_count": 2217,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1472 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f86049cb1c945f7701075",
          "name": "Hetzner - malware hosting",
          "description": "function ar(aw,av,au,at) is a new type of tracking, which uses the same code as the Matomo tracking tool and its built-up functionality to track where a tracker is located.",
          "modified": "2022-05-20T00:01:19.453000",
          "created": "2022-04-20T04:03:16.817000",
          "tags": [
            "param",
            "locale",
            "return",
            "stripped",
            "regexp",
            "html",
            "lang",
            "lightweight",
            "dual",
            "javascript i18n",
            "entity",
            "body",
            "meta",
            "typeradio",
            "ttav",
            "width",
            "ttaelt",
            "shadowwidth",
            "tagtotip",
            "html element",
            "shadow",
            "closebtncolors",
            "fadein",
            "null",
            "sticky",
            "close",
            "false",
            "path",
            "config",
            "span",
            "iframe",
            "kill",
            "inside",
            "first",
            "typetext",
            "typepassword",
            "input",
            "typeof define",
            "typeof module",
            "html tags",
            "px20trnf",
            "dom element",
            "date",
            "this",
            "typeof e",
            "function",
            "left",
            "bottom",
            "nullt",
            "right",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "js foundation",
            "error",
            "captcha",
            "access site",
            "click",
            "strong",
            "ddos",
            "hetzner online",
            "gmbh element",
            "lztextlink",
            "script",
            "lzrscr",
            "scrb64d",
            "livezilladata",
            "ovlcwm",
            "activedocument",
            "lzsds",
            "lzsde",
            "lzsdeg",
            "cant load",
            "gv1023",
            "typecheckbox",
            "5deg",
            "20deg",
            "45deg",
            "2000px00",
            "2000px0",
            "10px00",
            "60px0",
            "mintime",
            "await",
            "number",
            "typeof n",
            "typeof symbol",
            "cookieconsent",
            "showcookiemodal",
            "cookie banner",
            "agree",
            "agreed",
            "expiresthu",
            "anchorregex",
            "typeerror",
            "swiper",
            "hammer",
            "bnm",
            "software",
            "azaz",
            "form",
            "void",
            "zert",
            "accept",
            "android",
            "trace",
            "import",
            "string",
            "please",
            "blob",
            "matomo",
            "post",
            "javascript",
            "link",
            "license"
          ],
          "references": [
            "xfe-IP-136.243.64.87-stix2-2.1-export.json",
            "https://matomo.hetzner.com/matomo.js",
            "xfe-URL-matomo.hetzner.com-stix2-2.1-export.json",
            "https:///livesupport.hetzner.de/resource.php?t=js&1=jsglobal.min.js&2=jsbox.min.js&3=jstrack.min.js&v=ahgzixd7&4=jsextern.min.js",
            "https://livesupport.hetzner.de/server.php?rqst=track&output=jcrpt&group=Produktberatung&hg=Pw__&hcgs=MQ__&htgs=MQ__&ovltwo=MQ__&ovlv=djI_&ovlc=MQ__&esc=IzU4NTg1YQ__&epc=I0JFMTUyRA__&ovlts=MA__&ovlmr=MTAw&ovlmb=MjY_&hfk=MQ__&ovloo=MQ__&hots=MQ__&hott=MQ__&nse=0.615520170244701",
            "https://livesupport.hetzner.de/script.php?id=eec8dcd79d6fdf905136b99875c1d599",
            "https://accounts.hetzner.com/login",
            "https://accounts.hetzner.com/build/runtime.188fa053.js",
            "https://accounts.hetzner.com/build/755.5a8586e9.js",
            "https://accounts.hetzner.com/build/app.dc073715.js",
            "https://accounts.hetzner.com/build/802.3a7546ef.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery-migrate.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/ui/jquery-ui.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/styles/login.css.php",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/wz_tooltip.js",
            "xfe-URL-livesupport.hetzner.de-stix2-2.1-export.json",
            "xfe-URL-konsoleh.your-server.de-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ActiveDocument",
              "display_name": "ActiveDocument",
              "target": null
            },
            {
              "id": "OVLCWM",
              "display_name": "OVLCWM",
              "target": null
            },
            {
              "id": "Hammer",
              "display_name": "Hammer",
              "target": null
            },
            {
              "id": "BNM",
              "display_name": "BNM",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2308,
            "hostname": 949,
            "FileHash-SHA256": 125,
            "domain": 372,
            "FileHash-SHA1": 3,
            "FileHash-MD5": 256
          },
          "indicator_count": 4013,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1473 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "xfe-URL-livesupport.hetzner.de-stix2-2.1-export.json",
        "https://cp.enom.com/verisign-seal.htm",
        "https://ajax.googleapis.com/ajax/libs/angularjs/1.4.8/angular.min.js",
        "https://cp.enom.com/responsive/_js/knockout-3.3.0.min.js",
        "https://www.gstatic.com/recaptcha/releases/QENb_qRrX0-mQMyENQjD6Fuj/recaptcha__en.js",
        "https://cp.enom.com/js/jquery-3.5.1.min.js",
        "https://accounts.hetzner.com/login",
        "https://www.googletagmanager.com/gtm.js?id=GTM-5SN6BRV",
        "https://ajax.googleapis.com/ajax/libs/angularjs/1.4.2/angular-sanitize.js",
        "xfe-URL-konsoleh.your-server.de-stix2-2.1-export.json",
        "https://4vendeta.com/assets/js/meanmenu.min.js",
        "https://cp.enom.com/js/jquery.cookie.min.js",
        "http://fonts.googleapis.com/css?family=Abril+Fatface%3Aregular&subset=latin%2Ccyrillic&ver=5.7.6",
        "https://www.heymman.com/style/main.css",
        "xfe-URL-Misk.com-stix2-2.1-export.json",
        "https://livesupport.hetzner.de/script.php?id=eec8dcd79d6fdf905136b99875c1d599",
        "https://accounts.hetzner.com/build/runtime.188fa053.js",
        "https://cp.enom.com/ScriptResource.axd?d=fVjQa-0YyNqO6JmV36bw6eBJdTjE2YSdtcunOWcKYcBNn73MOJKQA_rxX3YMhcxLTgyDsGTKy0p9NEPvxzpqEpBKtm3GLb2GgI1LFYMC0Xr2lh71ZCttzgNGFnc5mS_Fc_DY5UH0M19Mr958h1jvmK4kzAM1&t=363be08",
        "https://static.twitchcdn.net/assets/amazon-ivs-wasmworker.min-28c086bb59605350be07.js",
        "https://cp.enom.com/js/jquery.jgrowl.min.js",
        "http://alp-vision.com/wp-content/cache/autoptimize/js/autoptimize_78b4f9b28399aa3c8a405e45931ad058.js",
        "https://cp.enom.com/responsive/_js/bootstrap.js",
        "https://www.googletagmanager.com/gtag/js?id=UA-92521958-1",
        "https://static.zdassets.com/ekr/snippet.js?key=7342b695-e394-4f25-89a0-da9d262a48da",
        "https://konsoleh.your-server.de/templates/ui-default/de/styles/login.css.php",
        "https:///livesupport.hetzner.de/resource.php?t=js&1=jsglobal.min.js&2=jsbox.min.js&3=jstrack.min.js&v=ahgzixd7&4=jsextern.min.js",
        "https://accounts.hetzner.com/build/755.5a8586e9.js",
        "https://cp.enom.com/js/jquery.disableonsubmit.min.js",
        "https://cp.enom.com/js/punycode.min.js",
        "https://livesupport.hetzner.de/server.php?rqst=track&output=jcrpt&group=Produktberatung&hg=Pw__&hcgs=MQ__&htgs=MQ__&ovltwo=MQ__&ovlv=djI_&ovlc=MQ__&esc=IzU4NTg1YQ__&epc=I0JFMTUyRA__&ovlts=MA__&ovlmr=MTAw&ovlmb=MjY_&hfk=MQ__&ovloo=MQ__&hots=MQ__&hott=MQ__&nse=0.615520170244701",
        "xfe-IP-136.243.64.87-stix2-2.1-export.json",
        "https://accounts.hetzner.com/build/app.dc073715.js",
        "https://accounts.hetzner.com/build/802.3a7546ef.js",
        "https://www.googletagmanager.com/gtag/js?id=G-W8YD4P2ENY&l=dataLayer&cx=c",
        "https://cp.enom.com/js/global-functions.js",
        "http://alp-vision.com/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
        "xfe-URL-Enom.com-stix2-2.1-export.json",
        "https://cp.enom.com/js/openWin.min.js",
        "https://matomo.hetzner.com/matomo.js",
        "https://cp.enom.com/scripts/Session.min.js",
        "xfe-IP-78.142.35.163-stix2-2.1-export.json",
        "xfe-URL-heymman.com-stix2-2.1-export.json",
        "https://4vendeta.com/assets/js/jquery.min.js",
        "https://4vendeta.com/assets/js/parallax.min.js",
        "https://cp.enom.com/ScriptResource.axd?d=lDjPFfAIWSrEAVNgTHTrISQmLEFmHAaibvNJQuGRZDbWpGFPLrFwaGVpjCUsI6HkqzbpwmaAa0cJCrq8f0eqEvIsQM8lvN_dVYVyESnohON4oTvdMZHDmwG83uJA4m2oqykP8TTTSIeV2oaNrlIXaX8cOxC5Cv6aGmjpdB2u-227wdn30&t=363be08",
        "http://alp-vision.com/wp-includes/css/dist/block-library/style.min.css?ver=5.7.6",
        "https://cp.enom.com/responsive/_js/init.min.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/wz_tooltip.js",
        "http://alp-vision.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
        "xfe-URL-Ndevix.com-stix2-2.1-export.json",
        "xfe-URL-4vendeta.com-stix2-2.1-export.json",
        "http://alp-vision.com/wp-content/themes/alp-vision/css/bootstrap.css?ver=1.0",
        "https://cp.enom.com/WebResource.axd?d=6rtXrDcnyiYD-9dFDFOkxTRcPVSrAN8fR-cHKzNqPTy7bHic-2LLMHDnielTzEI-sd1KplHrRBudcZJOm0-lxubO7k41&t=637453818340000000",
        "https://unrealservers.net/master.css",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery-migrate.js",
        "https://cp.enom.com/js/cart.minicart.min.js",
        "https://hybrid-analysis.com/sample/bcbea668407e956a651826abd5e59e4a473536465863e4af18949529e88db35d/63ed6cf79611136f180fde53",
        "https://cdn.optimizely.com/js/26241557.js",
        "https://4vendeta.com/assets/js/ajaxchimp.min.js",
        "xfe-URL-matomo.hetzner.com-stix2-2.1-export.json",
        "https://www.google.com/recaptcha/api.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/ui/jquery-ui.js",
        "https://4vendeta.com/assets/js/popper.min.js",
        "https://www.heymman.com/script.js",
        "https://cp.enom.com/global/TopMenu.ascx.js",
        "https://4vendeta.com/assets/js/bootstrap.min.js"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Hammer",
            "Activedocument",
            "Bnm",
            "Ovlcwm",
            "Reduceright"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "65708c534aadf7adf4f27d77",
      "name": "enom.com & 4vendeta.com - ReduceRight malware hosting/creation",
      "description": "",
      "modified": "2023-12-06T14:59:31.122000",
      "created": "2023-12-06T14:59:31.122000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 302,
        "domain": 634,
        "URL": 2988,
        "hostname": 1208
      },
      "indicator_count": 5132,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63ed77f49d449cb532e24728",
      "name": "hybrid scan of twitch cdn js file",
      "description": "function E(e,t,r,n, if i+= String.fromCharCode(a) if I am not a member of the C.subarray, or i-d.",
      "modified": "2023-03-18T00:05:45.328000",
      "created": "2023-02-16T00:25:24.282000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "runtime data",
        "ansi",
        "localappdata",
        "unicode",
        "hash seen",
        "size",
        "runtime process",
        "sha256",
        "temp",
        "sha1",
        "suspicious",
        "hybrid",
        "close",
        "click",
        "hosts",
        "ransomware",
        "february",
        "general",
        "strings",
        "malicious",
        "date",
        "error",
        "uint8array",
        "typeerror",
        "array",
        "regexp",
        "textdecoder",
        "57343",
        "typeof r",
        "12863",
        "void",
        "path",
        "april",
        "june",
        "august",
        "generator",
        "null"
      ],
      "references": [
        "https://static.twitchcdn.net/assets/amazon-ivs-wasmworker.min-28c086bb59605350be07.js",
        "https://hybrid-analysis.com/sample/bcbea668407e956a651826abd5e59e4a473536465863e4af18949529e88db35d/63ed6cf79611136f180fde53"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 256,
        "hostname": 57,
        "domain": 48,
        "FileHash-SHA256": 81,
        "FileHash-MD5": 51,
        "FileHash-SHA1": 50
      },
      "indicator_count": 543,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1171 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63ed767fb937767a5e0ff9bf",
      "name": "https://static.twitchcdn.net/assets/amazon-ivs-wasmworker.min-28c086bb59605350be07.js",
      "description": "function E(e,t,r,n, if i+= String.fromCharCode(a) if I am not a member of the C.subarray, or i-d.",
      "modified": "2023-02-16T00:19:11.372000",
      "created": "2023-02-16T00:19:11.372000",
      "tags": [
        "date",
        "error",
        "uint8array",
        "typeerror",
        "array",
        "regexp",
        "textdecoder",
        "57343",
        "typeof r",
        "12863",
        "void",
        "path",
        "february",
        "april",
        "june",
        "august",
        "generator",
        "null"
      ],
      "references": [
        "https://static.twitchcdn.net/assets/amazon-ivs-wasmworker.min-28c086bb59605350be07.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 230,
        "hostname": 56,
        "FileHash-SHA256": 20,
        "domain": 41
      },
      "indicator_count": 347,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1201 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "62616627ee302d24b23523c3",
      "name": "enom.com & 4vendeta.com - ReduceRight malware hosting/creation",
      "description": "New RegExp(M) is a new type, and it will change any of the elements to the same type if you want to add them to your HTML page or add a third element.",
      "modified": "2022-05-21T00:03:44.725000",
      "created": "2022-04-21T14:11:51.629000",
      "tags": [
        "tbody",
        "span",
        "thead",
        "tfoot",
        "multiple",
        "type",
        "href",
        "input",
        "halflings",
        "gradienttype1",
        "twitter",
        "false",
        "fontface",
        "fatface",
        "woff2",
        "u0259",
        "u1e001eff",
        "u2020",
        "u20a020ab",
        "u20ad20cf",
        "u2113",
        "u2c602c7f",
        "typesubmit",
        "function",
        "typeof c",
        "formdata",
        "this",
        "typeof define",
        "null",
        "typeof f",
        "object",
        "boolean",
        "typeof module",
        "error",
        "reflect",
        "math",
        "regexp",
        "number",
        "array",
        "typeerror",
        "string",
        "symbol",
        "typeof e",
        "typeof t",
        "class",
        "attr",
        "pseudo",
        "child",
        "js foundation",
        "account",
        "open",
        "navitem",
        "text",
        "mainnav",
        "click",
        "blank",
        "copyright",
        "u0027",
        "value",
        "body",
        "firefox",
        "enum",
        "html",
        "msie",
        "applewebkit",
        "traceconsole",
        "form",
        "iframe",
        "legend",
        "nonmsdombrowser",
        "callbackindex",
        "callbackframeid",
        "eventtarget",
        "eventargument",
        "validation",
        "explorer",
        "target",
        "plugin",
        "bootstrap",
        "https",
        "conflict",
        "focus",
        "next",
        "trigger",
        "checkbox",
        "delta",
        "scroll",
        "sourceid",
        "date",
        "sessiontoken",
        "sessionexpires",
        "void",
        "rangeerror",
        "utf16",
        "illegal input",
        "global",
        "chrome",
        "opredge",
        "opera",
        "safari",
        "version",
        "sxa0",
        "browser",
        "typeof require",
        "dom node",
        "typeof d",
        "component",
        "typeof h",
        "bubble",
        "reduceright",
        "script",
        "typeof n",
        "jhnew ia",
        "gtm5sn6brv",
        "path",
        "host",
        "trackpageview",
        "gw8yd4p2eny",
        "select",
        "strong",
        "uint8array",
        "android",
        "verify",
        "stop",
        "enterprise",
        "widget",
        "window",
        "generator",
        "reload",
        "r300",
        "caca",
        "closure library",
        "xdfunction",
        "adfunction",
        "cdfunction",
        "ddfunction",
        "bded",
        "please",
        "typeemail",
        "email",
        "jarallaxinner",
        "webkit",
        "property",
        "transform",
        "trident",
        "edge",
        "ipodi",
        "ipadi",
        "androidi",
        "blackberryi",
        "windows phonei",
        "xfunction",
        "pfunction",
        "wfunction",
        "show navigation",
        "mjquery",
        "typeof",
        "defaulttype",
        "hidden",
        "show",
        "shown",
        "startr",
        "endr",
        "federico zivolo",
        "distributed",
        "mit license",
        "statict",
        "flip"
      ],
      "references": [
        "xfe-IP-78.142.35.163-stix2-2.1-export.json",
        "xfe-URL-Enom.com-stix2-2.1-export.json",
        "xfe-URL-4vendeta.com-stix2-2.1-export.json",
        "https://4vendeta.com/assets/js/jquery.min.js",
        "https://4vendeta.com/assets/js/popper.min.js",
        "https://4vendeta.com/assets/js/bootstrap.min.js",
        "https://4vendeta.com/assets/js/meanmenu.min.js",
        "https://4vendeta.com/assets/js/parallax.min.js",
        "https://4vendeta.com/assets/js/ajaxchimp.min.js",
        "https://www.googletagmanager.com/gtag/js?id=UA-92521958-1",
        "https://www.googletagmanager.com/gtag/js?id=G-W8YD4P2ENY&l=dataLayer&cx=c",
        "https://www.gstatic.com/recaptcha/releases/QENb_qRrX0-mQMyENQjD6Fuj/recaptcha__en.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-5SN6BRV",
        "https://static.zdassets.com/ekr/snippet.js?key=7342b695-e394-4f25-89a0-da9d262a48da",
        "https://cp.enom.com/js/jquery-3.5.1.min.js",
        "https://cp.enom.com/responsive/_js/knockout-3.3.0.min.js",
        "https://cp.enom.com/js/global-functions.js",
        "https://cp.enom.com/js/punycode.min.js",
        "https://cp.enom.com/js/jquery.disableonsubmit.min.js",
        "https://cp.enom.com/js/jquery.cookie.min.js",
        "https://cp.enom.com/js/cart.minicart.min.js",
        "https://cp.enom.com/js/openWin.min.js",
        "https://cp.enom.com/js/jquery.jgrowl.min.js",
        "https://cp.enom.com/scripts/Session.min.js",
        "https://cp.enom.com/responsive/_js/init.min.js",
        "https://cp.enom.com/responsive/_js/bootstrap.js",
        "https://cp.enom.com/WebResource.axd?d=6rtXrDcnyiYD-9dFDFOkxTRcPVSrAN8fR-cHKzNqPTy7bHic-2LLMHDnielTzEI-sd1KplHrRBudcZJOm0-lxubO7k41&t=637453818340000000",
        "https://cp.enom.com/ScriptResource.axd?d=fVjQa-0YyNqO6JmV36bw6eBJdTjE2YSdtcunOWcKYcBNn73MOJKQA_rxX3YMhcxLTgyDsGTKy0p9NEPvxzpqEpBKtm3GLb2GgI1LFYMC0Xr2lh71ZCttzgNGFnc5mS_Fc_DY5UH0M19Mr958h1jvmK4kzAM1&t=363be08",
        "https://cp.enom.com/ScriptResource.axd?d=lDjPFfAIWSrEAVNgTHTrISQmLEFmHAaibvNJQuGRZDbWpGFPLrFwaGVpjCUsI6HkqzbpwmaAa0cJCrq8f0eqEvIsQM8lvN_dVYVyESnohON4oTvdMZHDmwG83uJA4m2oqykP8TTTSIeV2oaNrlIXaX8cOxC5Cv6aGmjpdB2u-227wdn30&t=363be08",
        "https://cdn.optimizely.com/js/26241557.js",
        "https://cp.enom.com/verisign-seal.htm",
        "https://cp.enom.com/global/TopMenu.ascx.js",
        "http://alp-vision.com/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
        "http://alp-vision.com/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
        "http://alp-vision.com/wp-content/cache/autoptimize/js/autoptimize_78b4f9b28399aa3c8a405e45931ad058.js",
        "http://alp-vision.com/wp-includes/css/dist/block-library/style.min.css?ver=5.7.6",
        "http://fonts.googleapis.com/css?family=Abril+Fatface%3Aregular&subset=latin%2Ccyrillic&ver=5.7.6",
        "http://alp-vision.com/wp-content/themes/alp-vision/css/bootstrap.css?ver=1.0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ReduceRight",
          "display_name": "ReduceRight",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2989,
        "hostname": 1208,
        "domain": 634,
        "FileHash-SHA256": 302
      },
      "indicator_count": 5133,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1472 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6261fd6a8d527fa569351e63",
      "name": "Malware hosting - unrealservers.net & heymman.com",
      "description": "function S.name, a.com, has been added to the end of a page to make sure it does not end up in an unauthorised place. and it will not get any more.",
      "modified": "2022-05-21T00:03:44.725000",
      "created": "2022-04-22T00:57:14.125000",
      "tags": [
        "e2f0fc",
        "fd7a07",
        "f0482b",
        "gradienttype0",
        "a5bcce",
        "helvetica",
        "negative",
        "arial",
        "bcd3e4",
        "style sheet",
        "nonce",
        "script",
        "please do",
        "not copy",
        "and paste",
        "this code",
        "cgrecaptchacfg",
        "ngrecaptcha",
        "recaptchaapi",
        "render",
        "onload",
        "select",
        "error",
        "strong",
        "uint8array",
        "string",
        "null",
        "number",
        "function",
        "input",
        "array",
        "iframe",
        "date",
        "android",
        "verify",
        "stop",
        "this",
        "span",
        "enterprise",
        "click",
        "widget",
        "window",
        "form",
        "generator",
        "reload",
        "void",
        "dd2d2f",
        "e8e8e8",
        "d8d8d8",
        "fcfcfc",
        "e5e5e5",
        "lucida",
        "unicode",
        "lucida grande",
        "f9f9f9",
        "footer",
        "unavailable",
        "ngsanitize",
        "order now",
        "invalid",
        "snippet",
        "month",
        "hours",
        "fullyear",
        "regexp",
        "eeee",
        "mmmm d",
        "mena",
        "christ"
      ],
      "references": [
        "xfe-URL-heymman.com-stix2-2.1-export.json",
        "https://ajax.googleapis.com/ajax/libs/angularjs/1.4.8/angular.min.js",
        "https://ajax.googleapis.com/ajax/libs/angularjs/1.4.2/angular-sanitize.js",
        "https://www.heymman.com/script.js",
        "https://www.heymman.com/style/main.css",
        "https://www.gstatic.com/recaptcha/releases/QENb_qRrX0-mQMyENQjD6Fuj/recaptcha__en.js",
        "https://www.google.com/recaptcha/api.js",
        "https://unrealservers.net/master.css",
        "xfe-URL-Ndevix.com-stix2-2.1-export.json",
        "xfe-URL-Misk.com-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 427,
        "URL": 1183,
        "FileHash-SHA256": 162,
        "domain": 441,
        "email": 4
      },
      "indicator_count": 2217,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1472 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "625f86049cb1c945f7701075",
      "name": "Hetzner - malware hosting",
      "description": "function ar(aw,av,au,at) is a new type of tracking, which uses the same code as the Matomo tracking tool and its built-up functionality to track where a tracker is located.",
      "modified": "2022-05-20T00:01:19.453000",
      "created": "2022-04-20T04:03:16.817000",
      "tags": [
        "param",
        "locale",
        "return",
        "stripped",
        "regexp",
        "html",
        "lang",
        "lightweight",
        "dual",
        "javascript i18n",
        "entity",
        "body",
        "meta",
        "typeradio",
        "ttav",
        "width",
        "ttaelt",
        "shadowwidth",
        "tagtotip",
        "html element",
        "shadow",
        "closebtncolors",
        "fadein",
        "null",
        "sticky",
        "close",
        "false",
        "path",
        "config",
        "span",
        "iframe",
        "kill",
        "inside",
        "first",
        "typetext",
        "typepassword",
        "input",
        "typeof define",
        "typeof module",
        "html tags",
        "px20trnf",
        "dom element",
        "date",
        "this",
        "typeof e",
        "function",
        "left",
        "bottom",
        "nullt",
        "right",
        "next",
        "february",
        "april",
        "june",
        "august",
        "atom",
        "cookie",
        "back",
        "bounce",
        "typeof t",
        "class",
        "attr",
        "pseudo",
        "child",
        "js foundation",
        "error",
        "captcha",
        "access site",
        "click",
        "strong",
        "ddos",
        "hetzner online",
        "gmbh element",
        "lztextlink",
        "script",
        "lzrscr",
        "scrb64d",
        "livezilladata",
        "ovlcwm",
        "activedocument",
        "lzsds",
        "lzsde",
        "lzsdeg",
        "cant load",
        "gv1023",
        "typecheckbox",
        "5deg",
        "20deg",
        "45deg",
        "2000px00",
        "2000px0",
        "10px00",
        "60px0",
        "mintime",
        "await",
        "number",
        "typeof n",
        "typeof symbol",
        "cookieconsent",
        "showcookiemodal",
        "cookie banner",
        "agree",
        "agreed",
        "expiresthu",
        "anchorregex",
        "typeerror",
        "swiper",
        "hammer",
        "bnm",
        "software",
        "azaz",
        "form",
        "void",
        "zert",
        "accept",
        "android",
        "trace",
        "import",
        "string",
        "please",
        "blob",
        "matomo",
        "post",
        "javascript",
        "link",
        "license"
      ],
      "references": [
        "xfe-IP-136.243.64.87-stix2-2.1-export.json",
        "https://matomo.hetzner.com/matomo.js",
        "xfe-URL-matomo.hetzner.com-stix2-2.1-export.json",
        "https:///livesupport.hetzner.de/resource.php?t=js&1=jsglobal.min.js&2=jsbox.min.js&3=jstrack.min.js&v=ahgzixd7&4=jsextern.min.js",
        "https://livesupport.hetzner.de/server.php?rqst=track&output=jcrpt&group=Produktberatung&hg=Pw__&hcgs=MQ__&htgs=MQ__&ovltwo=MQ__&ovlv=djI_&ovlc=MQ__&esc=IzU4NTg1YQ__&epc=I0JFMTUyRA__&ovlts=MA__&ovlmr=MTAw&ovlmb=MjY_&hfk=MQ__&ovloo=MQ__&hots=MQ__&hott=MQ__&nse=0.615520170244701",
        "https://livesupport.hetzner.de/script.php?id=eec8dcd79d6fdf905136b99875c1d599",
        "https://accounts.hetzner.com/login",
        "https://accounts.hetzner.com/build/runtime.188fa053.js",
        "https://accounts.hetzner.com/build/755.5a8586e9.js",
        "https://accounts.hetzner.com/build/app.dc073715.js",
        "https://accounts.hetzner.com/build/802.3a7546ef.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery-migrate.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/ui/jquery-ui.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/styles/login.css.php",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/wz_tooltip.js",
        "xfe-URL-livesupport.hetzner.de-stix2-2.1-export.json",
        "xfe-URL-konsoleh.your-server.de-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ActiveDocument",
          "display_name": "ActiveDocument",
          "target": null
        },
        {
          "id": "OVLCWM",
          "display_name": "OVLCWM",
          "target": null
        },
        {
          "id": "Hammer",
          "display_name": "Hammer",
          "target": null
        },
        {
          "id": "BNM",
          "display_name": "BNM",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2308,
        "hostname": 949,
        "FileHash-SHA256": 125,
        "domain": 372,
        "FileHash-SHA1": 3,
        "FileHash-MD5": 256
      },
      "indicator_count": 4013,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1473 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "e.tm",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "e.tm",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780284853.8380446
}