{
  "type": "Domain",
  "indicator": "echoloa.bexla9rin.in.net",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/echoloa.bexla9rin.in.net",
    "alexa": "http://www.alexa.com/siteinfo/echoloa.bexla9rin.in.net",
    "indicator": "echoloa.bexla9rin.in.net",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {},
    "pulse_info": {
      "count": 0,
      "pulses": [],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 0,
  "pulses": [],
  "error": null,
  "vt": {
    "type": "Domain",
    "indicator": "echoloa.bexla9rin.in.net",
    "stats": {
      "malicious": 9,
      "suspicious": 3,
      "harmless": 47,
      "undetected": 32,
      "total": 91,
      "verdict": "malicious",
      "ratio": "9/91"
    },
    "verdict": "malicious",
    "ratio": "9/91",
    "registrar": "PDR Ltd. d/b/a PublicDomainRegistry.com",
    "creation_date": 783144000,
    "reputation": 0,
    "tags": [
      "dga"
    ],
    "categories": {},
    "top_detections": [
      {
        "vendor": "ADMINUSLabs",
        "result": "malicious",
        "category": "malicious"
      },
      {
        "vendor": "BitDefender",
        "result": "malware",
        "category": "malicious"
      },
      {
        "vendor": "Certego",
        "result": "malicious",
        "category": "malicious"
      },
      {
        "vendor": "CyRadar",
        "result": "malware",
        "category": "malicious"
      },
      {
        "vendor": "Forcepoint ThreatSeeker",
        "result": "suspicious",
        "category": "suspicious"
      },
      {
        "vendor": "G-Data",
        "result": "malware",
        "category": "malicious"
      },
      {
        "vendor": "Gridinsoft",
        "result": "suspicious",
        "category": "suspicious"
      },
      {
        "vendor": "Lionic",
        "result": "malware",
        "category": "malicious"
      },
      {
        "vendor": "MalwareURL",
        "result": "malware",
        "category": "malicious"
      },
      {
        "vendor": "SOCRadar",
        "result": "suspicious",
        "category": "suspicious"
      }
    ],
    "last_analysis": 1778342170,
    "error": null
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "echoloa.bexla9rin.in.net",
    "found": true,
    "verdict": "malicious",
    "url_count": 1,
    "online_count": 0,
    "blacklists": {
      "spamhaus_dbl": "malware_domain",
      "surbl": "not listed"
    },
    "urls": [
      {
        "url": "https://echoloa.bexla9rin.in.net/cdk-msdn-3457325-null/load-file0dsdf567.chk",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2026-04-25",
        "tags": [
          "ClearFake"
        ]
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780189209.4900782
}