{
  "type": "Domain",
  "indicator": "element.show",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/element.show",
    "alexa": "http://www.alexa.com/siteinfo/element.show",
    "indicator": "element.show",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 2811756799,
      "indicator": "element.show",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 26,
      "pulses": [
        {
          "id": "68038f7eb6f6810aa6d6439f",
          "name": "\"+g+\"",
          "description": "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.aspx?Id=855bdfc1-7dbc-4a86-9d27-89ebb0ecf166&archival=False",
          "modified": "2025-09-01T08:05:25.121000",
          "created": "2025-04-19T11:56:46.933000",
          "tags": [
            "copyright",
            "customevent",
            "typeof e",
            "boomerang",
            "typeof t",
            "macintosh",
            "os x",
            "post",
            "typeof",
            "iframe",
            "date",
            "poka menu",
            "nie znaleziono",
            "poka start",
            "poka",
            "max dostpnych",
            "pierwsza",
            "ostatnia",
            "nastpna",
            "poprzednia",
            "brak danych",
            "first",
            "ceidg",
            "wystpi bd",
            "error",
            "true",
            "null",
            "linkdownload",
            "show",
            "ctrlmappings",
            "version",
            "versionchange",
            "body",
            "false",
            "span",
            "input",
            "paginate",
            "next",
            "last",
            "selectstart",
            "loop",
            "function",
            "bootstrap",
            "datatables",
            "responsive",
            "2016 sprymedia",
            "amd define",
            "object",
            "commonjs",
            "window",
            "browser",
            "button",
            "datatable",
            "sprymedia ltd",
            "columns",
            "colidx",
            "column",
            "parent",
            "child",
            "param",
            "display",
            "click",
            "middle",
            "class",
            "target",
            "never",
            "find",
            "footer",
            "close",
            "regexp",
            "matches",
            "cookie",
            "inputmask",
            "input mask",
            "robin herbots",
            "mit license",
            "xmlhttprequest",
            "left",
            "month",
            "boolean",
            "maxdate",
            "right",
            "daterangepicker",
            "yyyymmdd",
            "calendar",
            "jquery",
            "webpackrequire",
            "typeof symbol",
            "type",
            "setprototypeof",
            "maskpos",
            "wrapnativesuper",
            "backspace",
            "insert",
            "internal",
            "mask",
            "void",
            "this",
            "nie mona",
            "array",
            "nonmsdombrowser",
            "horizontal",
            "leftarrow",
            "uparrow",
            "rightarrow",
            "downarrow",
            "explorer",
            "form",
            "legend",
            "hmmss",
            "mmmm d",
            "yyyy h",
            "typeof define",
            "number",
            "locale",
            "character",
            "seeknext",
            "masked",
            "input plugin",
            "josh bush",
            "azaz",
            "azaz09",
            "black",
            "kontrast",
            "arrcookies",
            "getcookielang",
            "and information",
            "on business",
            "sign",
            "twoja",
            "opinia",
            "informacja o",
            "notify ui",
            "widget",
            "eric hynds",
            "dual",
            "name",
            "dtopt",
            "example",
            "using",
            "open",
            "adata",
            "hungarian",
            "aria",
            "legacy",
            "trident",
            "format",
            "nuke",
            "apos",
            "bitcoin",
            "outer",
            "mark",
            "info",
            "reload",
            "behaviour",
            "write",
            "buttons",
            "anything",
            "prop",
            "thecookie",
            "create",
            "thevalue",
            "string name",
            "pluginscookie",
            "author",
            "eventkey",
            "datakey",
            "default",
            "dataapikey",
            "defaulttype",
            "config",
            "shown",
            "trigger",
            "delta",
            "guard",
            "arrow",
            "leave",
            "scroll",
            "dataspy",
            "sessiontimeout",
            "return",
            "settimeout",
            "mytimerid",
            "requestcounter",
            "starttimer",
            "stop",
            "typeof n",
            "adminlte",
            "typeof o",
            "main",
            "js application",
            "adminlte v2",
            "colorlib",
            "ui date",
            "written",
            "jacek wysocki",
            "poprzedni",
            "marzec",
            "kwiecie",
            "czerwiec",
            "lipiec",
            "sierpie",
            "wrzesie",
            "openpopup",
            "href",
            "toggle",
            "msviewport",
            "popover",
            "json",
            "json text",
            "string",
            "otherwise",
            "holder",
            "mind",
            "copy",
            "meta",
            "third",
            "text",
            "choice",
            "confirm",
            "nie pytaj",
            "site",
            "title",
            "value",
            "alert",
            "warn",
            "migrate",
            "foundation",
            "see http",
            "forget",
            "newvalue",
            "nones5",
            "fall",
            "wrongvalid",
            "onerror",
            "year",
            "fast",
            "argument",
            "popper",
            "method",
            "data",
            "html",
            "flip",
            "factory",
            "onload",
            "tbody",
            "courier",
            "elem",
            "handle",
            "expando",
            "match",
            "selector",
            "sizzle",
            "android",
            "capture",
            "seed",
            "pass",
            "enough",
            "code",
            "bind",
            "core",
            "local",
            "verify",
            "accept",
            "done",
            "override",
            "inject",
            "possible",
            "hold",
            "45deg",
            "larger",
            "screen styling",
            "90deg",
            "support",
            "sidebar mini",
            "e1f0ff",
            "font awesome",
            "free",
            "autocomplete",
            "folder",
            "expanded folder",
            "tabela",
            "sorting",
            "xform",
            "nadpisane style",
            "menlo",
            "monaco",
            "consolas",
            "mono",
            "courier new",
            "browse",
            "twitter",
            "pt serif",
            "georgia",
            "times new",
            "roman",
            "times",
            "typetime",
            "import",
            "roboto",
            "http",
            "label",
            "demos",
            "effect",
            "inst",
            "super",
            "speed",
            "bounce",
            "hack",
            "logic",
            "shift",
            "double",
            "february",
            "april",
            "june",
            "august",
            "friday",
            "erase",
            "atom",
            "caja",
            "spinner",
            "refresh",
            "alpha",
            "sentinel",
            "back",
            "blind",
            "drop",
            "ceidg.gov.pl - centralna ewidencja i informacja o dzia\u0142alno\u015bci g",
            "prosz czeka",
            "pobierz plik"
          ],
          "references": [
            "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.aspx?Id=855bdfc1-7dbc-4a86-9d27-89ebb0ecf166&archival=False",
            "UE_pl_top.svg",
            "UE_pl_top_sm.svg",
            "XZ4AH-ABKPW-SQPBC-CYWES-BCG6V",
            "dataTables.lang.js.pobrane",
            "EntryChangeHistory.aspx.js.pobrane",
            "dataTables.input.js.pobrane",
            "responsive.bootstrap4.js.pobrane",
            "dataTables.bootstrap4.js.pobrane",
            "dataTables.responsive.js.pobrane",
            "jquery.session.js.pobrane",
            "inputmask.binding.js.pobrane",
            "daterangepicker.js.pobrane",
            "jquery.inputmask.min.js.pobrane",
            "ScriptResource.axd",
            "moment-with-locales.min.js.pobrane",
            "jquery.maskedinput-1.2.2.js.pobrane",
            "feedback.js.pobrane",
            "jquery.notify.min.js.pobrane",
            "jquery.dataTables.js.pobrane",
            "jquery.cookie.js.pobrane",
            "bootstrap.js.pobrane",
            "SessionTimeout.js.pobrane",
            "adminlte.min.js.pobrane",
            "jquery.easing.1.3.js.pobrane",
            "jquery.feedbackBadge.min.js.pobrane",
            "ui.datepicker-pl.js.pobrane",
            "ceidg-master.js.pobrane",
            "CommonResponsive.js.pobrane",
            "json2.js.pobrane",
            "jquery.alerts.js.pobrane",
            "jquery-migrate-1.2.1.js.pobrane",
            "dataTables.bootstrap4.css",
            "CommonScripts.js.pobrane",
            "popper.js.pobrane",
            "responsive.bootstrap4.css",
            "jquery-3.0.0.js.pobrane",
            "daterangepicker.css",
            "AdminLTE.css",
            "ui.notify.css",
            "ceidg.css",
            "bootstrap-gov-pl.css",
            "biznes.css",
            "jquery-ui.js.pobrane",
            "saved_resource.html"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 25,
            "URL": 165,
            "domain": 353,
            "hostname": 215,
            "email": 2
          },
          "indicator_count": 767,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "272 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657098ff4c59f8ac3f86f613",
          "name": "v2 of web.basemark.com plus all suggested ioc,s dont forget about the dropped js files from the 2nd hybrid link",
          "description": "",
          "modified": "2023-12-06T15:53:35.032000",
          "created": "2023-12-06T15:53:35.032000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1168,
            "hostname": 1366,
            "domain": 412,
            "URL": 3576,
            "email": 2,
            "FileHash-MD5": 61,
            "FileHash-SHA1": 54
          },
          "indicator_count": 6639,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c57c7b19b62c501601a",
          "name": "Hurricane Electric - csp.he.net :)",
          "description": "",
          "modified": "2023-12-06T14:59:35.479000",
          "created": "2023-12-06T14:59:35.479000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 186,
            "hostname": 490,
            "URL": 1339,
            "domain": 311
          },
          "indicator_count": 2326,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c27074200c710e3b35c",
          "name": "Malware hosting - metronetinc.com",
          "description": "",
          "modified": "2023-12-06T14:58:47.235000",
          "created": "2023-12-06T14:58:47.235000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 447,
            "hostname": 1241,
            "domain": 536,
            "URL": 3731
          },
          "indicator_count": 5955,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c13ee010f81d3f9b3af",
          "name": "Malware hosting - hostrocket.com",
          "description": "",
          "modified": "2023-12-06T14:58:27.115000",
          "created": "2023-12-06T14:58:27.115000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 232,
            "hostname": 963,
            "domain": 412,
            "URL": 2337,
            "email": 3,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 3949,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708b77797823dea739cc25",
          "name": "ReduceRight malware-",
          "description": "",
          "modified": "2023-12-06T14:55:51.023000",
          "created": "2023-12-06T14:55:51.023000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 110,
            "domain": 541,
            "URL": 2043,
            "hostname": 1106
          },
          "indicator_count": 3800,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708b5e9b8ce0f5fd87fb98",
          "name": "ewqopweowia543.ga",
          "description": "",
          "modified": "2023-12-06T14:55:26.621000",
          "created": "2023-12-06T14:55:26.621000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "hostname": 706,
            "domain": 234,
            "FileHash-SHA256": 238,
            "URL": 1386
          },
          "indicator_count": 2565,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657080d20f7e10c1e37fcf89",
          "name": "TarrantCounty.com ~ 03.01.2022",
          "description": "",
          "modified": "2023-12-06T14:10:26.301000",
          "created": "2023-12-06T14:10:26.301000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1078,
            "domain": 838,
            "hostname": 1607,
            "URL": 4134,
            "email": 3,
            "FileHash-SHA1": 2,
            "CIDR": 4,
            "FileHash-MD5": 15
          },
          "indicator_count": 7681,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707fe17dfdfe16066d16de",
          "name": "Bexar.org",
          "description": "",
          "modified": "2023-12-06T14:06:25.800000",
          "created": "2023-12-06T14:06:25.800000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1735,
            "hostname": 1833,
            "domain": 1025,
            "URL": 4668,
            "email": 4,
            "FileHash-MD5": 133,
            "FileHash-SHA1": 6,
            "CIDR": 5
          },
          "indicator_count": 9409,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6425a2f9c155fd53b9922bcd",
          "name": "v2 of web.basemark.com plus all suggested ioc,s dont forget about the dropped js files from the 2nd hybrid link",
          "description": "hope peeps are gona learn from 3cx that false positives are in fact often not false",
          "modified": "2023-04-29T13:05:05.409000",
          "created": "2023-03-30T14:55:53.652000",
          "tags": [
            "trojan",
            "apt",
            "ansi",
            "dropped file",
            "runtime data",
            "chromeua",
            "optout",
            "programfiles",
            "typeof e",
            "localappdata",
            "error",
            "date",
            "generator",
            "path",
            "null",
            "void",
            "win64",
            "twitter",
            "this",
            "critical",
            "desktop",
            "dark",
            "light",
            "meta",
            "roboto",
            "span",
            "class",
            "template",
            "blink",
            "suspicious",
            "facebook",
            "mexico",
            "malicious",
            "mozilla",
            "strings",
            "qakbot",
            "://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/e7740c893812cea8e34ffb04331dcc45762dec73def71929bfbabcbfb22e93e9",
            "https://hybrid-analysis.com/sample/e7740c893812cea8e34ffb04331dcc45762dec73def71929bfbabcbfb22e93e9/641e30763dcad56bc2075661",
            "http://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00m%00a%00r%00k"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 412,
            "FileHash-SHA256": 1168,
            "URL": 3576,
            "hostname": 1366,
            "email": 2,
            "FileHash-MD5": 61,
            "FileHash-SHA1": 54
          },
          "indicator_count": 6639,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "1128 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "642594b9402f0edc523a1149",
          "name": "http://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00m%00a%00r%00k&#039;",
          "description": "",
          "modified": "2023-04-29T13:05:05.409000",
          "created": "2023-03-30T13:55:05.516000",
          "tags": [
            "trojan",
            "apt",
            "ansi",
            "dropped file",
            "runtime data",
            "chromeua",
            "optout",
            "programfiles",
            "typeof e",
            "localappdata",
            "error",
            "date",
            "generator",
            "path",
            "null",
            "void",
            "win64",
            "twitter",
            "this",
            "critical",
            "desktop",
            "dark",
            "light",
            "meta",
            "roboto",
            "span",
            "class",
            "template",
            "blink",
            "suspicious",
            "facebook",
            "mexico",
            "malicious",
            "mozilla",
            "strings",
            "qakbot",
            "://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00"
          ],
          "references": [
            "://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00m%00a%00r%00k",
            "https://hybrid-analysis.com/sample/e7740c893812cea8e34ffb04331dcc45762dec73def71929bfbabcbfb22e93e9/641e30763dcad56bc2075661"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 243,
            "email": 2,
            "domain": 240,
            "URL": 101,
            "FileHash-MD5": 61,
            "FileHash-SHA1": 54,
            "FileHash-SHA256": 99
          },
          "indicator_count": 800,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "1128 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62ea8bf5508d5839c2e68b66",
          "name": "This what you dont see your browser doing in the background",
          "description": "",
          "modified": "2022-08-03T14:53:41.744000",
          "created": "2022-08-03T14:53:41.744000",
          "tags": [
            "regexp",
            "array",
            "attr",
            "class",
            "css1compat",
            "null",
            "string",
            "error",
            "function",
            "invalid json",
            "text",
            "date",
            "activexobject",
            "number",
            "utmb",
            "firefox",
            "shockwave flash",
            "utma",
            "utmz",
            "iframe",
            "classspan",
            "span",
            "typecheckbox",
            "gradienttype0",
            "typeradio",
            "classicon",
            "typesearch",
            "typesubmit",
            "href",
            "typebutton",
            "https://www.virustotal.com/static/css/bootstrap.min.css?20150630",
            "https://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js",
            "https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.7.1.min.js",
            "https://www.virustotal.com/static/js/base.min-2013121902.js",
            "https://www.virustotal.com/static/js/bootmin-2013092601.js"
          ],
          "references": [
            "https://www.virustotal.com/static/css/bootstrap.min.css?20150630",
            "https://www.virustotal.com/static/js/bootmin-2013092601.js",
            "https://www.virustotal.com/static/js/base.min-2013121902.js",
            "https://www.virustotal.com/en/file/undefined/analysis/",
            "https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.7.1.min.js",
            "https://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js",
            "bootstrap.min.css",
            "ga.js",
            "bootmin-2013092601 2.js",
            "bootmin-2013092601.js",
            "jquery.min.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 193,
            "hostname": 384,
            "domain": 146,
            "URL": 972
          },
          "indicator_count": 1695,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 392,
          "modified_text": "1397 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62751d6e20ce7971fe122760",
          "name": "layerhost.com",
          "description": "function ra(a,b,c,d,e,f, a new type of node, which can only be defined by its own type, is the same as its current type.",
          "modified": "2022-06-05T00:03:45.266000",
          "created": "2022-05-06T13:06:54.626000",
          "tags": [
            "typeerror",
            "function",
            "string",
            "urlsearchparams",
            "array",
            "object",
            "typeof t",
            "incorrect",
            "boolean",
            "iterator",
            "target",
            "error",
            "typeof o",
            "date",
            "typeof symbol",
            "window",
            "promise",
            "iere",
            "typeof ne",
            "null",
            "body",
            "this",
            "regexp",
            "please",
            "blob",
            "matomo",
            "post",
            "javascript",
            "link",
            "license",
            "info",
            "campaigns",
            "storagetest",
            "typeof json",
            "sufeffxa0",
            "typeof c",
            "document",
            "invalid attempt",
            "chat",
            "search",
            "language",
            "feel",
            "file",
            "call",
            "strongstart",
            "address",
            "again",
            "attrs",
            "cparseint",
            "dparseint",
            "bparseint",
            "9999px",
            "fparseint",
            "eparseint",
            "bnull",
            "gparseint",
            "iparseint",
            "blank",
            "trident",
            "fixedpos",
            "fixedheader",
            "click",
            "rotate",
            "dataslider",
            "eventtarget",
            "basicstructure",
            "moztransition",
            "gthis",
            "preventdefault",
            "bthis",
            "regexcss",
            "xthis",
            "true",
            "filterizr api",
            "filterizr",
            "value",
            "ease",
            "steps",
            "idle",
            "classcallcheck",
            "reveal",
            "init",
            "drilldown",
            "dropdown",
            "dropdownmenu",
            "orbit",
            "slider",
            "burn",
            "sticky",
            "keyboard",
            "eventkey",
            "apple cmd",
            "mapping",
            "mouse",
            "input",
            "cache",
            "button",
            "checkbox",
            "shift",
            "typeof b",
            "pseudo",
            "child",
            "class",
            "attr",
            "void",
            "secure",
            "result"
          ],
          "references": [
            "xfe-IP-134.73.11.118-stix2-2.1-export.json",
            "xfe-URL-Powr.io-stix2-2.1-export 2.json",
            "xfe-URL-Layerhost.com-stix2-2.1-export.json",
            "xfe-URL-https___www.gandi.net-stix2-2.1-export.json",
            "https://www.powr.io/powr.js?platform=html",
            "https://www.layerhost.com/assets/js/vendor/jquery.min.js",
            "https://www.layerhost.com/assets/js/vendor/what-input.js",
            "https://www.layerhost.com/assets/js/vendor/foundation.min.js",
            "https://www.layerhost.com/assets/js/jquery.filterizr.min.js",
            "https://www.layerhost.com/assets/js/yui.js",
            "https://www.layerhost.com/assets/js/app.js",
            "https://www.layerhost.com/assets/js/slider.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/languages/en.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-2d0d2b7c.js",
            "https://tag.aticdn.net/616708/smarttag.js",
            "https://analytics.gandi.net/piwik.js",
            "https://www.gandi.net/static/js/modern.27ee934b0dc5.js",
            "https://www.gandi.net/static/js/legacy.7cc648e3ff7a.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "EventTarget",
              "display_name": "EventTarget",
              "target": null
            },
            {
              "id": "Filterizr API",
              "display_name": "Filterizr API",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 350,
            "URL": 2035,
            "hostname": 718,
            "FileHash-SHA256": 355,
            "CVE": 1,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 3461,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1456 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62756a0d14664003affb0555",
          "name": "hush.com 301 to hushmail.com",
          "description": "var b[f, gw.b, \"dust\" - a.g - has been added to an Array by the end of the year, if there is any chance of it being added.",
          "modified": "2022-06-05T00:03:45.266000",
          "created": "2022-05-06T18:33:49.161000",
          "tags": [
            "widget",
            "null",
            "regexp",
            "array",
            "copyright",
            "license",
            "calltrkswap",
            "date",
            "typeof s",
            "xmlhttprequest",
            "typeof r",
            "script",
            "vd",
            "number",
            "string",
            "ienew ca",
            "closure library",
            "error",
            "quota",
            "aafunction",
            "dafunction",
            "function",
            "typeof o",
            "reduceright",
            "aw1070742489",
            "uint8array",
            "void",
            "code",
            "typeof symbol",
            "wickedclientid",
            "wickedemail",
            "wickedurl",
            "wickednullurl",
            "typeof e",
            "direct",
            "typeof require",
            "modulenotfound",
            "mini",
            "cnull",
            "anull",
            "nl50",
            "pnull",
            "okcancel",
            "compiled",
            "true",
            "android",
            "trident",
            "form",
            "window",
            "false",
            "acronym",
            "body",
            "canvas",
            "embed",
            "footer",
            "iframe",
            "keygen",
            "legend",
            "mark",
            "meta",
            "ruby",
            "small",
            "span",
            "template",
            "blank",
            "twitter",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "js foundation",
            "typeof module",
            "width",
            "object",
            "this",
            "accept",
            "fnumber",
            "gtmmf25krh",
            "host",
            "path"
          ],
          "references": [
            "xfe-URL-Hush.com-stix2-2.1-export.json",
            "https://www.googletagmanager.com/gtag/js?id=AW-1070742489&l=dataLayer&cx=c",
            "https://www.googletagmanager.com/gtm.js?id=GTM-MF25KRH",
            "https://www.hushmail.com/shared/javascript/jquery-3.5.1.min.js",
            "https://www.hushmail.com/javascriptinclude/eNrLKC3OyE3MzIkvT00qzixJtSpITE_V98lPz8xzyy_K1csqtjI0MzK2MDcwsbS0ysCq2qkov7w4tSi4JLGkGFUDAF_tIM0,.en_US.68448bd8190f2f2bae9633f547bbbbbe.0.js",
            "https://www.hushmail.com/javascriptinclude/eNpNzEEOQDAQQNEbtVoM7Sks7GXopB0pkQ5xfWJl-5P3JWGh4AvukSRzoKKtqlWlf0Wt4k3rnG2g641Pl6QNOU83zcIn-QMj6ZHpHQ2FF97jiHOmj0ED4FxfwQOf9yPU.en_US.68448bd8190f2f2bae9633f547bbbbbe.0.js",
            "https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js",
            "https://widget.wickedreports.com/widget.js",
            "https://www.googletagmanager.com/gtag/js?id=AW-1070742489",
            "https://www.hushmail.com/status/",
            "https://script.tapfiliate.com/tapfiliate.js",
            "https://www.googletagmanager.com/gtag/js?id=UA-1837381-13",
            "https://widget.wickedreports.com/v2/3469/wr-dafa9fae816c2f65d24d1eb593b58626.js",
            "https://cdn.callrail.com/companies/431115301/7c8f964bc12313c75ad2/12/swap.js",
            "https://js.callrail.com/group/0/7c8f964bc12313c75ad2/06ababf0-8852-4eef-95e1-285ae467a93a/poll.js?t=1651861725881&ids%5B%5D=431115301",
            "https://js.callrail.com/group/0/7c8f964bc12313c75ad2/06ababf0-8852-4eef-95e1-285ae467a93a/poll.js?t=1651861793229&ids%5B%5D=431115301",
            "https://widget.trustpilot.com/trustboxes/5406e65db0d04a09e042d5fc/index.html?templateId=5406e65db0d04a09e042d5fc&businessunitId=4bdc496b000064000505a89d#locale=en-US&styleHeight=28px&styleWidth=100%25&theme=light"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Vd",
              "display_name": "Vd",
              "target": null
            },
            {
              "id": "OkCancel",
              "display_name": "OkCancel",
              "target": null
            },
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1531",
              "name": "Account Access Removal",
              "display_name": "T1531 - Account Access Removal"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1917,
            "hostname": 698,
            "FileHash-SHA256": 116,
            "domain": 263
          },
          "indicator_count": 2994,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1456 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "628e33df0169fe33f79b766b",
          "name": "Seems to be coming from space . Space malware? \u4e91\u9002\u914d(AllMobilize Inc.)  --\u4f01\u4e1a\u6d4f\u89c8\u5668\u53ca\u79fb\u52a8\u5316\u89e3\u51b3\u65b9\u6848\u4f9b\u5e94\u5546 | \u4e91\u9002\u914d",
          "description": "AllMobilize, Amaze, and all its partners - all of them with the same name - are now available to use on Facebook, Twitter, Instagram and other social media platforms, including Facebook.",
          "modified": "2022-05-25T13:49:19.876000",
          "created": "2022-05-25T13:49:19.876000",
          "tags": [
            "ebeef5",
            "dcdfe6",
            "e64552",
            "helvetica",
            "ffffff",
            "pingfang sc",
            "helveticaneue",
            "arial",
            "microsoft yahei",
            "45deg",
            "post",
            "sqdl",
            "sqhz",
            "eptyzj",
            "zjxcys",
            "doform",
            "modernizr",
            "typeradio",
            "tagnames",
            "boolean",
            "date",
            "array",
            "error",
            "typeof t",
            "dtft",
            "amaze ui",
            "function",
            "regexp",
            "d1dd2",
            "mstransitionend",
            "team",
            "android",
            "february",
            "april",
            "june",
            "august",
            "void",
            "null",
            "type",
            "elem",
            "index",
            "handle",
            "sizzle",
            "check",
            "target",
            "hooks",
            "prop",
            "copy",
            "class",
            "mark",
            "internal",
            "stack",
            "false",
            "code",
            "accept",
            "seed",
            "first",
            "body",
            "jquery",
            "pass",
            "bind",
            "core",
            "local",
            "verify",
            "done",
            "find",
            "inject",
            "possible",
            "hold",
            "trigger",
            "camel",
            "bubble",
            "window",
            "middle",
            "capture",
            "iframe",
            "fall",
            "stop",
            "panic",
            "back",
            "speed",
            "grab",
            "install",
            "open",
            "invalid request",
            "button",
            "input",
            "cpu os",
            "span",
            "label",
            "this",
            "trident",
            "pykey",
            "eventparams",
            "object",
            "event",
            "infinity",
            "pykeye",
            "string",
            "typeof",
            "typeof e",
            "typeof r",
            "typeof s",
            "typeof console",
            "contenttype",
            "number",
            "\u4e91\u9002\u914d\uff0c\u4f01\u4e1a\u79fb\u52a8\u5316\uff0c\u4f01\u4e1a\u79fb\u52a8\u5316\u89e3\u51b3\u65b9\u6848\uff0c\u4e91\u9002\u914d\u8de8\u5c4f",
            "\u4e91\u9002\u914d\u7f51\u7ad9\u9002\u914d",
            "\u4e91\u9002\u914d\u8de8\u5c4f\u4e91",
            "\u4e91\u9002\u914d\u8de8\u5c4f\u5e94\u7528",
            "\u4f01\u4e1aoa\u79fb\u52a8\u5316\u3001\u4f01\u4e1a\u79fb\u52a8\u95e8\u6237\u3001\u79fb\u52a8\u5e94\u7528\u7ba1\u7406\u3001\u79fb\u52a8\u5e94\u7528\u5e73\u53f0",
            "xcloud",
            "amaze",
            "sdp enterplorer",
            "siebel domino",
            "siebel",
            "domino",
            "allmobilize",
            "apipc",
            "ui amaze"
          ],
          "references": [
            "https://www.yunshipei.com/",
            "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
            "https://stats.ipinyou.com/adv?a=SR..sxcg_4d0DhagaJWCLj_ZdX&u=https%3A%2F%2Fwww.yunshipei.com%2F&rd=1653485491040&v=2&e=sr%3D390x844%26sc%3D32-bit%26je%3Dfalse%26lg%3Den-us%26vb%3D1%26did%3D%26dt%3D%26ps%3D390x3885%26vp%3D390x664%26ec%3DUTF-8%26vbt%3D1822%26sp%3D0%26ur%3D%26st%3D%26ev%3Dvg",
            "https://goutong.baidu.com/site/270/98c14a71a44014f7aa9d23449a55ae8f/b.js?siteId=3064033",
            "https://stats.ipinyou.com/presadv?a=SR..sxcg_4d0DhagaJWCLj_ZdX&cb=py.cb",
            "https://fm.ipinyou.com/j/a.js",
            "https://www.yunshipei.com/assets/js/jquery.js",
            "https://www.yunshipei.com/assets/js/amazeui.min.js",
            "https://www.yunshipei.com/assets/js/app.min.js",
            "https://sgoutong.baidu.com/embed/1652930761/asset/embed/css/mobile/main.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 652,
            "URL": 1482,
            "domain": 242,
            "FileHash-SHA256": 142,
            "FileHash-MD5": 3
          },
          "indicator_count": 2521,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1467 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "628bc74f5b92614c08d99f88",
          "name": "Update Agent - Dinan.",
          "description": "",
          "modified": "2022-05-23T17:41:35.234000",
          "created": "2022-05-23T17:41:35.234000",
          "tags": [
            "dinan",
            "performance",
            "update agent",
            "help center",
            "products",
            "lubricants",
            "engine hardware",
            "exhaust",
            "dinan dealer",
            "dealer login",
            "mini",
            "contact",
            "agent",
            "download",
            "alpha",
            "verdana",
            "arial",
            "opacity35",
            "copyright",
            "foundation",
            "opacity0",
            "opacity70",
            "opacity80",
            "hubspot script",
            "loader",
            "closure library",
            "number",
            "string",
            "regexp",
            "uint8array",
            "date",
            "fnumber",
            "aw1027984682",
            "xdfunction",
            "code",
            "null",
            "error",
            "activexobject",
            "xmlhttprequest",
            "android",
            "worker",
            "installtrigger",
            "ccon",
            "false",
            "error occured",
            "body",
            "please",
            "shippingphone",
            "event",
            "item",
            "shippingaddress",
            "billingphone",
            "promise",
            "click",
            "window",
            "this",
            "close",
            "model",
            "drop",
            "main",
            "facebook",
            "form",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "open",
            "express",
            "spinner",
            "copy",
            "typeof e",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "function",
            "typeof module",
            "0x4b3a",
            "error message",
            "signifydglobal",
            "0x1c7d",
            "current order",
            "x0x4b3a",
            "gtmpkdjjpc",
            "host",
            "path",
            "adfunction"
          ],
          "references": [
            "https://www.googletagmanager.com/gtm.js?id=GTM-PKDJJPC",
            "https://cdn-scripts.signifyd.com/api/script-tag.js",
            "https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js",
            "https://www.dinancars.com/assets/js/combine/min/v1653077793/e88cd3e3db8ab2b910e50cf4deb60529f/default;jquery-ui.min;js.cookie;util;nav;cart;accountfunctions;jquery.activity-indicator-1.0.0.min;drawer_plugin;floating_label_gen;jquery.autoellipsis-1.0.10;fresco;fresco-custom;isotope_imagesloaded.min;promo_autoplus_helpers;slick.min;widgets;jquery.custom-carousel;waterfall_helpers/",
            "https://imgs.signifyd.com/fp/tags.js?org_id=w2txo5aa&session_id=7632E9E9-DE48-41D8-9BAC-1E27A98D17EC&pageid=2",
            "https://www.googletagmanager.com/gtag/js?id=AW-1027984682",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1027984682/?random=1653327072015&cv=9&fst=1653327072015&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=6&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa5b0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Fwww.dinancars.com%2Fabout%2F&ref=https%3A%2F%2Fwww.dinancars.com%2Fupdate-agent&tiba=About%20Dinan%20-%20Dinan&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
            "https://js.hs-scripts.com/8009596.js",
            "https://www.dinancars.com/assets/css/jquery-ui-custom.css",
            "https://www.dinancars.com/update-agent"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1495",
              "name": "Firmware Corruption",
              "display_name": "T1495 - Firmware Corruption"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1806,
            "hostname": 682,
            "FileHash-SHA256": 240,
            "domain": 274
          },
          "indicator_count": 3002,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1468 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f93fe2c0237a71e262354",
          "name": "Malware hosting - metronetinc.com",
          "description": "If(65535) by the end of the year, if (65534) a.sigBytes is a single word, then if, as expected, b.com(d)",
          "modified": "2022-05-20T00:01:19.453000",
          "created": "2022-04-20T05:02:54.354000",
          "tags": [
            "ebattid",
            "click",
            "getclicktarget",
            "date",
            "contexttrack",
            "view",
            "installtrigger",
            "processlink",
            "typeof blog",
            "msie",
            "image",
            "function",
            "asyncfunction",
            "proxy",
            "typeof t",
            "symbol",
            "typeof n",
            "typeerror",
            "typeof window",
            "array",
            "foundation",
            "mit license",
            "http",
            "typeof define",
            "ui disable",
            "selection",
            "ui focusable",
            "this",
            "typeof module",
            "handles",
            "notice block",
            "dataid",
            "block",
            "desc",
            "ofyncl",
            "sorry",
            "cloc",
            "null",
            "object",
            "makes",
            "close",
            "code",
            "find",
            "typeof e",
            "nullt",
            "bottom",
            "left",
            "html",
            "right",
            "width",
            "next",
            "february",
            "april",
            "june",
            "august",
            "back",
            "bounce",
            "atom",
            "cookie",
            "must",
            "number",
            "livevalidation",
            "copyright",
            "alec hill",
            "modified",
            "oracle",
            "format",
            "email",
            "error",
            "closure library",
            "zindex1",
            "msgesture",
            "mspointerdown",
            "fnumber",
            "woothemes",
            "tyler smith",
            "regexp",
            "class",
            "attr",
            "pseudo",
            "child",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "source",
            "ud83dudc6cud83c",
            "script",
            "boolean",
            "reduceright",
            "x3ex3cscriptx3e",
            "x3ex3ciframex3e",
            "string",
            "custom",
            "trackevent",
            "path",
            "derek",
            "void",
            "iterator",
            "facebook pixel",
            "pixel code",
            "facebook",
            "service",
            "phonenumber",
            "meta",
            "optin",
            "elqsitevisited",
            "qnew date",
            "rnew date",
            "dlkey",
            "dllookup",
            "httponly",
            "pfunction",
            "contenttype",
            "zfunction",
            "bfunction",
            "mvoid",
            "ofunction",
            "g3xj902fy6q",
            "r300",
            "uint8array",
            "typeof d",
            "caca",
            "array int8array",
            "caregexp",
            "legacy",
            "customevent",
            "09af",
            "ver0",
            "tag0",
            "extdata0",
            "ua ch",
            "window",
            "math",
            "redfq",
            "base64",
            "azaz09s",
            "jeff mott",
            "https",
            "kenji urushima",
            "explorer"
          ],
          "references": [
            "xfe-URL-metronetinc.com-stix2-2.1-export.json",
            "https://a2.adform.net/Serving/TrackPoint/?pm=508052&ADFPageName=Metronet%7CHomepage&ADFdivider=%7C&ord=735079476141&Set1=en-US%7Cen-US%7C390x844%7C32&ADFtpmode=2&loc=https%3A%2F%2Fwww.metronetinc.com%2F",
            "https://a2.adform.net/serving/scripts/trackpoint/async/",
            "https://www.googleadservices.com/pagead/conversion_async.js",
            "https://www.googletagmanager.com/gtag/js?id=G-3XJ902FY6Q&l=dataLayer&cx=c",
            "https://www.google-analytics.com/analytics.js",
            "https://img03.en25.com/i/elqCfg.min.js",
            "https://connect.facebook.net/signals/config/2196524664009793?v=2.9.57&r=stable",
            "https://connect.facebook.net/signals/plugins/identity.js?v=2.9.57",
            "https://www.googletagmanager.com/gtm.js?id=GTM-W3GQ4F",
            "https://static.zdassets.com/ekr/snippet.js?key=e7dd7ff5-a219-47a1-b096-069f750c234f",
            "https://www.metronetinc.com/wp-includes/js/wp-emoji-release.min.js?ver=5.8.4",
            "https://www.metronetinc.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0",
            "https://www.metronetinc.com/wp-content/themes/MetroNet/js/jquery.flexslider-min.js?ver=5.8.4",
            "https://www.metronetinc.com/wp-content/themes/MetroNet/js/flexslider-init.js?ver=5.8.4",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/982771034/?random=1650430003990&cv=9&fst=1650430003990&num=1&label=Remarketing%20-%20All%20Pages&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=3&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.metronetinc.com%2F&tiba=MetroNet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%2C%20Streaming%20TV%2C",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/646812378/?random=1650430003991&cv=9&fst=1650430003991&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=3&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.metronetinc.com%2F&tiba=MetroNet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%2C%20Streaming%20TV%2C%20and%20Phone&hn=www.googleadservic",
            "https://www.googleadservices.com/pagead/conversion/646812378/?random=1650430003991&cv=9&fst=1650430003991&num=1&value=0&label=6dFBCIm13s4BENqltrQC&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=3&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.metronetinc.com%2F&tiba=MetroNet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%2C%20Streaming%20TV%2C%20and%20Phone&",
            "https://bat.bing.com/p/action/140000459.js",
            "https://img03.en25.com/i/livevalidation_standalone.compressed.js",
            "https://www.metronetinc.com/wp-content/plugins/lt-ajax-mn-channelguide/jquery-ui.min.js?ver=1.2",
            "https://www.metronetinc.com/wp-content/plugins/lt-ajax-mn-channelguide/lt-ajax-mn-channelguide.js?ver=1.1",
            "https://www.metronetinc.com/wp-content/plugins/atomic-blocks/dist/assets/js/dismiss.js?ver=1625889728",
            "https://www.metronetinc.com/wp-includes/js/hoverIntent.min.js?ver=1.10.1",
            "https://www.metronetinc.com/wp-includes/js/jquery/ui/core.min.js?ver=1.12.1",
            "https://www.metronetinc.com/wp-content/plugins/pixel-caffeine/build/frontend.js?ver=2.3.3",
            "https://stats.wp.com/e-202216.js",
            "https://bs.serving-sys.com/Serving/ActivityServer.bs?cn=as&ActivityID=1073779012&rnd=922949.8781851793",
            "https://secure-ds.serving-sys.com/SemiCachedScripts/ebAttribution.js",
            "https://11057407.fls.doubleclick.net/activityi;src=11057407;type=count0;cat=sitev0;ord=1;num=5426507653008;gtm=2wg4i1;auiddc=1460077727.1650429649;~oref=https%3A%2F%2Fwww.metronetinc.com%2F",
            "xfe-URL-bat.bing.com-stix2-2.1-export 2.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Tunisia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 447,
            "hostname": 1241,
            "URL": 3731,
            "domain": 536
          },
          "indicator_count": 5955,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1472 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f86049cb1c945f7701075",
          "name": "Hetzner - malware hosting",
          "description": "function ar(aw,av,au,at) is a new type of tracking, which uses the same code as the Matomo tracking tool and its built-up functionality to track where a tracker is located.",
          "modified": "2022-05-20T00:01:19.453000",
          "created": "2022-04-20T04:03:16.817000",
          "tags": [
            "param",
            "locale",
            "return",
            "stripped",
            "regexp",
            "html",
            "lang",
            "lightweight",
            "dual",
            "javascript i18n",
            "entity",
            "body",
            "meta",
            "typeradio",
            "ttav",
            "width",
            "ttaelt",
            "shadowwidth",
            "tagtotip",
            "html element",
            "shadow",
            "closebtncolors",
            "fadein",
            "null",
            "sticky",
            "close",
            "false",
            "path",
            "config",
            "span",
            "iframe",
            "kill",
            "inside",
            "first",
            "typetext",
            "typepassword",
            "input",
            "typeof define",
            "typeof module",
            "html tags",
            "px20trnf",
            "dom element",
            "date",
            "this",
            "typeof e",
            "function",
            "left",
            "bottom",
            "nullt",
            "right",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "js foundation",
            "error",
            "captcha",
            "access site",
            "click",
            "strong",
            "ddos",
            "hetzner online",
            "gmbh element",
            "lztextlink",
            "script",
            "lzrscr",
            "scrb64d",
            "livezilladata",
            "ovlcwm",
            "activedocument",
            "lzsds",
            "lzsde",
            "lzsdeg",
            "cant load",
            "gv1023",
            "typecheckbox",
            "5deg",
            "20deg",
            "45deg",
            "2000px00",
            "2000px0",
            "10px00",
            "60px0",
            "mintime",
            "await",
            "number",
            "typeof n",
            "typeof symbol",
            "cookieconsent",
            "showcookiemodal",
            "cookie banner",
            "agree",
            "agreed",
            "expiresthu",
            "anchorregex",
            "typeerror",
            "swiper",
            "hammer",
            "bnm",
            "software",
            "azaz",
            "form",
            "void",
            "zert",
            "accept",
            "android",
            "trace",
            "import",
            "string",
            "please",
            "blob",
            "matomo",
            "post",
            "javascript",
            "link",
            "license"
          ],
          "references": [
            "xfe-IP-136.243.64.87-stix2-2.1-export.json",
            "https://matomo.hetzner.com/matomo.js",
            "xfe-URL-matomo.hetzner.com-stix2-2.1-export.json",
            "https:///livesupport.hetzner.de/resource.php?t=js&1=jsglobal.min.js&2=jsbox.min.js&3=jstrack.min.js&v=ahgzixd7&4=jsextern.min.js",
            "https://livesupport.hetzner.de/server.php?rqst=track&output=jcrpt&group=Produktberatung&hg=Pw__&hcgs=MQ__&htgs=MQ__&ovltwo=MQ__&ovlv=djI_&ovlc=MQ__&esc=IzU4NTg1YQ__&epc=I0JFMTUyRA__&ovlts=MA__&ovlmr=MTAw&ovlmb=MjY_&hfk=MQ__&ovloo=MQ__&hots=MQ__&hott=MQ__&nse=0.615520170244701",
            "https://livesupport.hetzner.de/script.php?id=eec8dcd79d6fdf905136b99875c1d599",
            "https://accounts.hetzner.com/login",
            "https://accounts.hetzner.com/build/runtime.188fa053.js",
            "https://accounts.hetzner.com/build/755.5a8586e9.js",
            "https://accounts.hetzner.com/build/app.dc073715.js",
            "https://accounts.hetzner.com/build/802.3a7546ef.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery-migrate.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/ui/jquery-ui.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/styles/login.css.php",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/wz_tooltip.js",
            "xfe-URL-livesupport.hetzner.de-stix2-2.1-export.json",
            "xfe-URL-konsoleh.your-server.de-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ActiveDocument",
              "display_name": "ActiveDocument",
              "target": null
            },
            {
              "id": "OVLCWM",
              "display_name": "OVLCWM",
              "target": null
            },
            {
              "id": "Hammer",
              "display_name": "Hammer",
              "target": null
            },
            {
              "id": "BNM",
              "display_name": "BNM",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2308,
            "hostname": 949,
            "FileHash-SHA256": 125,
            "domain": 372,
            "FileHash-SHA1": 3,
            "FileHash-MD5": 256
          },
          "indicator_count": 4013,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1472 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f492a0581b2eb202e47c9",
          "name": "Malware hosting - hostrocket.com",
          "description": "ChunkLoadError, a new type of error, failed to load a chunk of JavaScript, according to the web browser operator, E.noconflict.com, as well as the website itself.",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T23:43:38.539000",
          "tags": [
            "jxuiwidget",
            "null",
            "function",
            "jxuihtmldiv",
            "date",
            "jxuilabel",
            "zendesk chat",
            "regexp",
            "api update",
            "jxuihtmla",
            "window",
            "chat",
            "void",
            "error",
            "loader",
            "back",
            "click",
            "close",
            "agent",
            "hello",
            "form",
            "banned",
            "cookie",
            "small",
            "legacy",
            "direct",
            "colorbox core",
            "style",
            "user style",
            "colorbox",
            "html",
            "6deg",
            "e5e5e5",
            "dbdbdb",
            "d2d2d2",
            "eaedef",
            "michael farrell",
            "home",
            "helvetica",
            "ssd shared",
            "page",
            "formnum",
            "hidden",
            "current",
            "hostrocket",
            "dotblock",
            "fast",
            "href",
            "price slider",
            "tooltip",
            "dotblock popup",
            "callback",
            "rect",
            "cycle plugin",
            "number",
            "auto",
            "shuffle",
            "manual",
            "roll",
            "speed",
            "stop",
            "false",
            "first",
            "look",
            "copyright",
            "gpl version",
            "http",
            "document",
            "ui effects",
            "width",
            "left",
            "bottom",
            "this",
            "atom",
            "html id",
            "price",
            "timer",
            "value",
            "processor",
            "example",
            "storage",
            "string",
            "class",
            "thecookie",
            "create",
            "thevalue",
            "param",
            "type",
            "pluginscookie",
            "author",
            "jquery",
            "u00a0",
            "option",
            "body",
            "optgroup",
            "multiple",
            "selectboxhover",
            "selectbox",
            "label",
            "control",
            "slideshow",
            "jack moore",
            "mit license",
            "overlay",
            "wrapper",
            "content",
            "loadedcontent",
            "loadingoverlay",
            "next",
            "iframe",
            "array",
            "attr",
            "tools",
            "ui library",
            "no copyrights",
            "or licenses",
            "like",
            "media",
            "john resig",
            "dual",
            "gtmkw8b5l",
            "classes",
            "host",
            "path",
            "element",
            "trackpageview",
            "typeerror",
            "typeof symbol",
            "typeof e",
            "typeof t",
            "referenceerror",
            "promise",
            "script",
            "boolean",
            "typeof n"
          ],
          "references": [
            "xfe-URL-hostrocket.com-stix2-2.1-export 2.json",
            "https://www.googletagmanager.com/gtm.js?id=GTM-KW8B5L",
            "https://www.hostrocket.com/js/jquery-1.6.1.min.js",
            "https://www.hostrocket.com/js/jquery.tools.min.js",
            "https://www.hostrocket.com/js/jquery.colorbox-min.js",
            "https://www.hostrocket.com/js/jquery.selectBox.min.js",
            "https://www.hostrocket.com/js/jquery.cookie.js",
            "https://www.hostrocket.com/js/jquery.price_slider.js",
            "https://www.hostrocket.com/js/jquery-ui-1.8.13.custom.min.js",
            "https://www.hostrocket.com/js/jquery.cycle.all.js",
            "https://www.hostrocket.com/js/jquery.behavior.js",
            "https://www.hostrocket.com/contact-files/contact-form.js",
            "https://www.hostrocket.com/css/style.css",
            "https://www.hostrocket.com/css/colorbox.css",
            "https://www.hostrocket.com/css/style-nophone.css",
            "https://v2.zopim.com/bin/v/widget_v2.329.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 963,
            "email": 3,
            "domain": 412,
            "URL": 2338,
            "FileHash-SHA256": 232,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 3950,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1473 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f05c71e903844d907b1ae",
          "name": "Russian Malware Strain",
          "description": "The full text of the new Dictionary of Human Rights, compiled by the Office of National Statistics (ONS), has been published on the internet, with the help of a few words: \"Glasgow\".",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T18:56:07.131000",
          "tags": [
            "bapunycode",
            "s700",
            "array",
            "topmailru",
            "error",
            "tmrtmr",
            "rbclickid",
            "tmrdebug1",
            "tadaeaxbyb",
            "bbdaea",
            "cbdaea",
            "uadaea",
            "ver1",
            "typemini",
            "verb0",
            "youtube",
            "content",
            "smartbanner",
            "null",
            "text",
            "smart banner",
            "copyright",
            "android",
            "windows store",
            "title",
            "price",
            "click",
            "date",
            "twitter",
            "string",
            "regexp",
            "number",
            "typeerror",
            "symbol",
            "array int8array",
            "argument",
            "rafunction",
            "iframe",
            "please",
            "image",
            "v[1]-1:k+=",
            "dpjquery",
            "document",
            "function",
            "this",
            "left",
            "bottom",
            "html",
            "nulle",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "attr",
            "class",
            "invalid json",
            "domparser",
            "edge",
            "sxa0",
            "qafunction",
            "trident",
            "ondomready",
            "make sure",
            "gc",
            "65535",
            "boolean",
            "counter",
            "segoe ui",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "form",
            "impact",
            "light",
            "bad idp",
            "cvtx",
            "bad event",
            "typeof b",
            "closure library",
            "f1518500249",
            "f1859775393",
            "body"
          ],
          "references": [
            "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
            "xfe-URL-Xelent.ru-stix2-2.1-export.json",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
            "http://mc.yandex.ru/metrika/watch.js",
            "http://metrika.installtraffic.com/js/watch.js",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
            "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
            "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
            "http://loviotvet.ru/lib/project/common.js",
            "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
            "https://apis.google.com/js/plusone.js",
            "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
            "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
            "https://top-fwz1.mail.ru/js/code.js",
            "https://bitrix.info/ba.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "V[1]-1:k+=",
              "display_name": "V[1]-1:k+=",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1987,
            "hostname": 733,
            "FileHash-SHA256": 294,
            "domain": 354
          },
          "indicator_count": 3368,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1473 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62549aabb033e7afc5069f98",
          "name": "Malware - victim=fr",
          "description": "Mme, Mlle,   M. Compte, yn \u00f4l \u00c2\u00a31.5m (\u20ac2.4m; \u00e2\u201a\u00ac1m)",
          "modified": "2022-05-11T21:04:45.103000",
          "created": "2022-04-11T21:16:27.786000",
          "tags": [
            "freebox",
            "free",
            "mois pendant",
            "sabonner voir",
            "fibre free",
            "la fibre",
            "votre",
            "wifi",
            "freebox en",
            "offre",
            "delta",
            "face",
            "prix",
            "date",
            "this",
            "typeof e",
            "true",
            "function",
            "left",
            "bottom",
            "html",
            "nullt",
            "false",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "close",
            "null",
            "back",
            "bounce",
            "kolab",
            "target",
            "object",
            "tcfuiservice",
            "reflect",
            "typeof proxy",
            "boolean",
            "agree",
            "disagree",
            "select",
            "save",
            "learn",
            "click",
            "gnu gpl",
            "copyright",
            "javascript code",
            "license",
            "extwin1",
            "framed1",
            "roundcube",
            "webmail client",
            "script",
            "team",
            "format",
            "regexp",
            "software",
            "error",
            "pseudo",
            "child",
            "the software",
            "sufeffxa0",
            "class",
            "attr",
            "javascript",
            "express",
            "nous",
            "didomi",
            "typeof t",
            "hmuvfyyh",
            "sekindo",
            "lkqd",
            "aol cdn",
            "ffffff",
            "montserrat",
            "adsl",
            "offres adsl",
            "internet",
            "t\u00e9l\u00e9phone",
            "t\u00e9l\u00e9phonie",
            "mobiles",
            "forfaits mobiles",
            "tv",
            "t\u00e9l\u00e9vision",
            "vod",
            "vid\u00e9o \u00e0 la demande",
            "multiposte",
            "radio",
            "routeur",
            "freeplayer",
            "multiplay",
            "d\u00e9groupage",
            "total",
            "partiel",
            "e-mail",
            "mail",
            "m\u00e9l",
            "fournisseur d'acc\u00e8s",
            "i.s.p.",
            "isp",
            "internaute",
            "internautes",
            "france",
            "fran\u00e7ais",
            "zimbra",
            "le webmail",
            "free fait",
            "webmail imp",
            "cela n",
            "webmail zimbra",
            "stockage",
            "pour migrer",
            "accder",
            "testteltext",
            "sans",
            "testziptext",
            "testziptext i",
            "testteltext i",
            "typenumber",
            "screenh",
            "tvbycanal",
            "tvbycanal147",
            "tvbycanal204",
            "tvbycanal83",
            "tvbycanal80",
            "tvbycanal34",
            "4000",
            "typeof console",
            "console",
            "nullc",
            "nulld",
            "customevent",
            "msanimationend",
            "typeof n",
            "typeof r",
            "x20trnf",
            "width",
            "accept",
            "json",
            "moz o",
            "custom build",
            "https",
            "xmlhttprequest",
            "typeof module",
            "webkit",
            "android",
            "flash",
            "span",
            "un espace",
            "phpmysql",
            "helvetica"
          ],
          "references": [
            "xfe-IP-212.27.63.109-stix2-2.1-export.json",
            "http://pageperso.free.fr/im/css/free.css",
            "http://passback.free.fr/pub/pp_300x250.html",
            "https://subscribe.free.fr/accesgratuit/index.html",
            "https://subscribe.free.fr/assets/js/vendor/modernizr.custom.js",
            "https://subscribe.free.fr/assets/js/vendor/jquery-1.9.1.min.js",
            "https://subscribe.free.fr/assets/js/plugins.min.js",
            "https://subscribe.free.fr/assets/js/vendor/wow.min.js",
            "https://subscribe.free.fr/assets/js/main.min.js",
            "https://subscribe.free.fr/assets/css/accesgratuit.min.css",
            "https://subscribe.free.fr/assets/css/app2.min.css",
            "https://webmail.free.fr/",
            "https://sdk.privacy-center.org/87df2f8d-232a-4617-8efc-3764b3bbd0c0/loader.js?target=webmail.free.fr",
            "https://webmail.free.fr/program/js/jquery.min.js?s=1510166541",
            "https://webmail.free.fr/program/js/app.min.js?s=1510166525",
            "https://sdk.privacy-center.org/ui-gdpr-en.a96c69ed0cb8f37a2deea6c49dd453517875ac60.js",
            "https://webmail.free.fr/plugins/jqueryui/js/jquery-ui.min.js?s=1510166524",
            "https://www.free.fr/freebox/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1078,
            "URL": 2104,
            "domain": 290,
            "FileHash-SHA256": 117,
            "FileHash-MD5": 4,
            "FileHash-SHA1": 2
          },
          "indicator_count": 3595,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1480 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6252f5fd2d3d29e0ac449f15",
          "name": "ReduceRight malware-",
          "description": "In e, a new RegExp, has been added to the list of properties that can be used to store information in a single place, as well as a \"sizzle\" on the side of the page.",
          "modified": "2022-05-10T00:02:48.350000",
          "created": "2022-04-10T15:21:33.873000",
          "tags": [
            "post",
            "regexp",
            "error parsing",
            "adresponse",
            "body",
            "typeof t",
            "ads returned",
            "bingapistraceid",
            "accept",
            "error",
            "azaz09",
            "date",
            "typeof e",
            "uint8array",
            "typeof module",
            "typeof define",
            "notset",
            "genericdata",
            "ipv4address",
            "ipv6address",
            "phonenumber",
            "reduceright",
            "number",
            "string",
            "g34x541384l",
            "r300",
            "copyright",
            "dafunction",
            "gafunction",
            "void",
            "function",
            "bootstrap",
            "javascript",
            "typeof c",
            "twitter",
            "mit license",
            "focus",
            "azaz",
            "this",
            "nullt",
            "bottom",
            "left",
            "html",
            "right",
            "width",
            "next",
            "february",
            "april",
            "june",
            "august",
            "null",
            "back",
            "bounce",
            "atom",
            "cookie",
            "close",
            "pseudo",
            "child",
            "sufeffxa0",
            "class",
            "attr"
          ],
          "references": [
            "xfe-URL-tvsqpjwdni.com-stix2-2.1-export.json",
            "https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js",
            "https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js",
            "https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js",
            "https://www.googletagmanager.com/gtag/js?id=G-34X541384L",
            "https://h6.msn.com/bingna/lib/aria-webjs-compact-sdk/aria-webjs-compact-sdk-1.2.1.min.js",
            "https://h6.msn.com/nativeads/ms-nativeads-airfind.min.js?date=2022310"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1106,
            "URL": 2043,
            "domain": 541,
            "FileHash-SHA256": 110
          },
          "indicator_count": 3800,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1482 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625045b8e764847c54ed286e",
          "name": "ewqopweowia543.ga",
          "description": "If you want to know what type of Touches you will get when you get stuck in the middle of a page, then ask for a random number of letters or numbers, or, if you can't find one.",
          "modified": "2022-05-08T00:03:14.586000",
          "created": "2022-04-08T14:24:56.301000",
          "tags": [
            "90deg",
            "250px",
            "helvetica neue",
            "helvetica",
            "roboto",
            "georgia",
            "typesearch",
            "typecheckbox",
            "label",
            "liberation mono",
            "function",
            "constructor",
            "param",
            "object",
            "class",
            "event",
            "abide",
            "number",
            "initializes",
            "drilldown",
            "window",
            "sticky",
            "false",
            "null",
            "body",
            "this",
            "date",
            "path",
            "anchor",
            "open",
            "trigger",
            "small",
            "close",
            "void",
            "form",
            "fast",
            "prop",
            "error",
            "shift",
            "test",
            "burn",
            "android",
            "back",
            "killswitch",
            "find",
            "desktop",
            "fall",
            "linear",
            "value",
            "webpackrequire",
            "return",
            "mouse",
            "factory",
            "moduleid",
            "apple cmd",
            "regexp",
            "elem",
            "handle",
            "expando",
            "match",
            "selector",
            "type",
            "sizzle",
            "target",
            "mark",
            "copy",
            "capture",
            "seed",
            "pass",
            "code",
            "bind",
            "core",
            "local",
            "verify",
            "accept",
            "done",
            "internal",
            "inject",
            "possible",
            "hold",
            "camel",
            "first",
            "middle",
            "gc",
            "eq",
            "post",
            "xava",
            "gbva",
            "hbva",
            "ibva",
            "lcva",
            "cdva",
            "oeva",
            "peva",
            "65535",
            "boolean",
            "counter",
            "segoe ui",
            "typeerror",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "impact",
            "light"
          ],
          "references": [
            "xfe-URL-ewqopweowia543.ga-stix2-2.0-export.json",
            "https://mc.yandex.ru/metrika/watch.js",
            "https://ssl.google-analytics.com/ga.js",
            "https://vestacp.com/bower_components/jquery/dist/jquery.js",
            "https://vestacp.com/bower_components/what-input/dist/what-input.js",
            "https://vestacp.com/bower_components/foundation-sites/dist/js/foundation.js",
            "https://vestacp.com/js/app.js",
            "https://vestacp.com/css/app.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Eq",
              "display_name": "Eq",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 706,
            "URL": 1386,
            "CVE": 1,
            "FileHash-SHA256": 238,
            "domain": 234
          },
          "indicator_count": 2565,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1484 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62617d42a6121d5abd3c6942",
          "name": "Hurricane Electric - csp.he.net :)",
          "description": "Here is the full text of the code that Google.com used to create its search engine, \"search.cse\", for the first time. and, in the event, it is:",
          "modified": "2022-04-21T15:50:26.260000",
          "created": "2022-04-21T15:50:26.260000",
          "tags": [
            "flexslider",
            "target",
            "boolean",
            "slideshow",
            "next",
            "integer",
            "prev",
            "smooth height",
            "sync",
            "prevent ios",
            "pause",
            "date",
            "null",
            "privat",
            "leave",
            "sans",
            "woff2",
            "fontface",
            "u1c801c88",
            "u20b4",
            "u2de02dff",
            "ua640a69f",
            "ufe2efe2f",
            "u04b004b1",
            "u2116",
            "navtop",
            "currentdiv",
            "validation",
            "drop down",
            "collapse",
            "tool tips",
            "popovers",
            "fix navbar",
            "click",
            "scroll",
            "begin",
            "regexp",
            "span",
            "xmpb",
            "onwss",
            "styless",
            "mstransitionend",
            "text",
            "error",
            "infinity",
            "false",
            "february",
            "april",
            "june",
            "august",
            "gray",
            "e00000",
            "replaced",
            "gene",
            "dc143c",
            "align buttons",
            "for stuff",
            "inside this",
            "blockform",
            "woo hoo",
            "post",
            "xava",
            "gbva",
            "hbva",
            "ibva",
            "lcva",
            "cdva",
            "oeva",
            "peva",
            "string",
            "object",
            "number",
            "azaz09",
            "copyright",
            "closure library",
            "typeerror",
            "symbol",
            "vd",
            "silk",
            "edge",
            "style",
            "google",
            "android",
            "form",
            "trident",
            "template",
            "embed",
            "iframe",
            "keygen",
            "meta",
            "acronym",
            "code",
            "legend",
            "main",
            "mark",
            "small",
            "class",
            "close",
            "blank",
            "array",
            "attr",
            "function",
            "invalid json",
            "domparser",
            "ffffff",
            "cccccc",
            "c41130",
            "f6f6f6",
            "knew w",
            "hnew w",
            "lnew w"
          ],
          "references": [
            "https://csp.he.net/styles/style.css",
            "https://www.google.com/cse/cse.js?cx=016402751031109241230:v7vojvfohnq",
            "https://ajax.googleapis.com/ajax/libs/jquery/1.7.2/jquery.min.js",
            "https://www.google.com/cse/static/element/3e1664f444e6eb06/cse_element__en.js?usqp=CAI%3D",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1068215855/?random=1650555348274&cv=9&fst=1650555348274&num=1&label=viUgCKmAuwMQr9yu_QM&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fhe.net%2F&tiba=Hurricane%20Electric%20Internet%20Services%20-%20Internet%20Backbone%20and%20Colocation%20Provider&hn=www.googleadservices.com&rfmt=3&fmt=4",
            "https://www.googleadservices.com/pagead/conversion.js",
            "https://ssl.google-analytics.com/ga.js",
            "http://fonts.googleapis.com/css?family=Open+Sans:300"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "FlexSlider",
              "display_name": "FlexSlider",
              "target": null
            },
            {
              "id": "Vd",
              "display_name": "Vd",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 311,
            "hostname": 490,
            "URL": 1339,
            "FileHash-SHA256": 186
          },
          "indicator_count": 2326,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1501 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "62276abfaa65cd33f64331f8",
          "name": "TarrantCounty.com ~ 03.01.2022",
          "description": "",
          "modified": "2022-04-07T00:04:02.553000",
          "created": "2022-03-08T14:39:59.235000",
          "tags": [
            "march",
            "lookup go",
            "rescan add",
            "verdict report",
            "de summary",
            "http",
            "redirects links",
            "behaviour",
            "similar dom",
            "content api",
            "value",
            "search url",
            "search domain",
            "scan url",
            "url search",
            "domain scan",
            "url url",
            "motor vehicle",
            "aqb1",
            "eventsevent10",
            "meta",
            "show",
            "download go",
            "full url",
            "reverse dns",
            "resource",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "response",
            "main",
            "milan",
            "apache",
            "paris",
            "accept"
          ],
          "references": [
            "TarrantCounty3df.pdf",
            "TarantCounty2df.pdf",
            "TarrantCounty4df.pdf",
            "TarrantCounty5df.pdf",
            "tarrant23df.pdf",
            "TarrantCounty1df.pdf",
            "tarrantcounty.com:en:elections:Voter-Information:Voter- Registration.html%22,.pdf",
            "TarrantCounty6df.pdf",
            "TarrantCounty7df.pdf",
            "TarrantCounty10df.pdf",
            "TarrantCounty9df.pdf",
            "TarrantCounty17df.pdf",
            "TarrantCounty15df.pdf",
            "TarrantCounty12df.pdf",
            "TarrantCounty14df.pdf",
            "tarrantcounty8df.pdf",
            "TarrantCounty18df.pdf",
            "TarrantCounty19df.pdf",
            "TarrantCounty21df.pdf",
            "tarrantcounty22df.pdf",
            "TarrantCounty20df.pdf",
            "tarrantcountydf.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4134,
            "hostname": 1607,
            "domain": 838,
            "FileHash-SHA256": 1078,
            "FileHash-SHA1": 2,
            "email": 3,
            "CIDR": 4,
            "FileHash-MD5": 15
          },
          "indicator_count": 7681,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 405,
          "modified_text": "1515 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "621fff12d2c54f70fea90576",
          "name": "Bexar.org",
          "description": "",
          "modified": "2022-04-01T00:01:54.852000",
          "created": "2022-03-02T23:34:42.531000",
          "tags": [],
          "references": [
            "www.bexar.org - urlscan.io.pdf",
            "bexar api 4.pdf",
            "bexar api 8.pdf",
            "bexar 6.pdf",
            "bexar api 2.pdf",
            "bexar api 7.pdf",
            "bexar api 3.pdf",
            "bexar api 9.pdf",
            "bexar api 12.pdf",
            "bexar api 17.pdf",
            "bexar api 15.pdf",
            "bexar api 18.pdf",
            "bexar api 10.pdf",
            "bexar api 19.pdf",
            "bexar api 20.pdf",
            "bexar api 13.pdf",
            "bexar api 21.pdf",
            "bexar api 14.pdf",
            "bexar api 22.pdf",
            "bexar1.pdf",
            "bexar api5.pdf",
            "bexar2.pdf",
            "bexar3.pdf",
            "bexar.org 3.2.22.pdf",
            "bexar6.pdf",
            "bexar5.pdf",
            "bexar api_1.pdf",
            "bexar10.pdf",
            "bexar api.pdf",
            "bexar_v1df.pdf",
            "bexarv4df.pdf",
            "bexarv2df.pdf",
            "bexarv6df.pdf",
            "bexasv3df.pdf",
            "bexarv7df.pdf",
            "bear_v apidf.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1833,
            "URL": 4669,
            "domain": 1025,
            "FileHash-SHA256": 1735,
            "email": 4,
            "FileHash-MD5": 133,
            "FileHash-SHA1": 6,
            "CIDR": 5
          },
          "indicator_count": 9410,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1521 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://mc.yandex.ru/metrika/watch.js",
        "https://www.hostrocket.com/css/style.css",
        "https://www.googleadservices.com/pagead/conversion.js",
        "https://www.metronetinc.com/wp-includes/js/hoverIntent.min.js?ver=1.10.1",
        "bexar api 10.pdf",
        "https://www.metronetinc.com/wp-includes/js/jquery/ui/core.min.js?ver=1.12.1",
        "bootmin-2013092601.js",
        "bexar api 12.pdf",
        "bexar api 18.pdf",
        "https://www.layerhost.com/assets/js/vendor/jquery.min.js",
        "https://widget.wickedreports.com/widget.js",
        "https://stats.ipinyou.com/presadv?a=SR..sxcg_4d0DhagaJWCLj_ZdX&cb=py.cb",
        "xfe-IP-212.27.63.109-stix2-2.1-export.json",
        "http://pageperso.free.fr/im/css/free.css",
        "https://webmail.free.fr/program/js/app.min.js?s=1510166525",
        "TarantCounty2df.pdf",
        "jquery-3.0.0.js.pobrane",
        "TarrantCounty15df.pdf",
        "responsive.bootstrap4.js.pobrane",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/ui/jquery-ui.js",
        "http://fonts.googleapis.com/css?family=Open+Sans:300",
        "bexarv7df.pdf",
        "TarrantCounty18df.pdf",
        "https://hybrid-analysis.com/sample/e7740c893812cea8e34ffb04331dcc45762dec73def71929bfbabcbfb22e93e9",
        "https://script.tapfiliate.com/tapfiliate.js",
        "https://www.free.fr/freebox/",
        "http://metrika.installtraffic.com/js/watch.js",
        "jquery.session.js.pobrane",
        "https://sdk.privacy-center.org/87df2f8d-232a-4617-8efc-3764b3bbd0c0/loader.js?target=webmail.free.fr",
        "https://www.metronetinc.com/wp-content/plugins/lt-ajax-mn-channelguide/jquery-ui.min.js?ver=1.2",
        "CommonScripts.js.pobrane",
        "https://bs.serving-sys.com/Serving/ActivityServer.bs?cn=as&ActivityID=1073779012&rnd=922949.8781851793",
        "ScriptResource.axd",
        "dataTables.bootstrap4.css",
        "https://accounts.hetzner.com/build/755.5a8586e9.js",
        "jquery-ui.js.pobrane",
        "https://www.layerhost.com/assets/js/yui.js",
        "https://www.googletagmanager.com/gtag/js?id=AW-1070742489",
        "https://js.callrail.com/group/0/7c8f964bc12313c75ad2/06ababf0-8852-4eef-95e1-285ae467a93a/poll.js?t=1651861793229&ids%5B%5D=431115301",
        "https://goutong.baidu.com/site/270/98c14a71a44014f7aa9d23449a55ae8f/b.js?siteId=3064033",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
        "http://passback.free.fr/pub/pp_300x250.html",
        "https://www.googletagmanager.com/gtag/js?id=AW-1070742489&l=dataLayer&cx=c",
        "https://www.metronetinc.com/wp-content/themes/MetroNet/js/jquery.flexslider-min.js?ver=5.8.4",
        "https://webmail.free.fr/program/js/jquery.min.js?s=1510166541",
        "bexar.org 3.2.22.pdf",
        "https:///livesupport.hetzner.de/resource.php?t=js&1=jsglobal.min.js&2=jsbox.min.js&3=jstrack.min.js&v=ahgzixd7&4=jsextern.min.js",
        "xfe-URL-Powr.io-stix2-2.1-export 2.json",
        "responsive.bootstrap4.css",
        "TarrantCounty10df.pdf",
        "https://subscribe.free.fr/assets/js/vendor/wow.min.js",
        "TarrantCounty3df.pdf",
        "https://www.hostrocket.com/js/jquery.tools.min.js",
        "jquery.inputmask.min.js.pobrane",
        "https://stats.ipinyou.com/adv?a=SR..sxcg_4d0DhagaJWCLj_ZdX&u=https%3A%2F%2Fwww.yunshipei.com%2F&rd=1653485491040&v=2&e=sr%3D390x844%26sc%3D32-bit%26je%3Dfalse%26lg%3Den-us%26vb%3D1%26did%3D%26dt%3D%26ps%3D390x3885%26vp%3D390x664%26ec%3DUTF-8%26vbt%3D1822%26sp%3D0%26ur%3D%26st%3D%26ev%3Dvg",
        "https://secure-ds.serving-sys.com/SemiCachedScripts/ebAttribution.js",
        "https://www.google.com/cse/static/element/3e1664f444e6eb06/cse_element__en.js?usqp=CAI%3D",
        "https://a2.adform.net/Serving/TrackPoint/?pm=508052&ADFPageName=Metronet%7CHomepage&ADFdivider=%7C&ord=735079476141&Set1=en-US%7Cen-US%7C390x844%7C32&ADFtpmode=2&loc=https%3A%2F%2Fwww.metronetinc.com%2F",
        "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
        "https://www.hostrocket.com/contact-files/contact-form.js",
        "http://mc.yandex.ru/metrika/watch.js",
        "https://imgs.signifyd.com/fp/tags.js?org_id=w2txo5aa&session_id=7632E9E9-DE48-41D8-9BAC-1E27A98D17EC&pageid=2",
        "https://www.google-analytics.com/analytics.js",
        "xfe-URL-Layerhost.com-stix2-2.1-export.json",
        "https://subscribe.free.fr/assets/css/accesgratuit.min.css",
        "https://ssl.google-analytics.com/ga.js",
        "daterangepicker.js.pobrane",
        "bear_v apidf.pdf",
        "https://www.hushmail.com/shared/javascript/jquery-3.5.1.min.js",
        "https://livesupport.hetzner.de/server.php?rqst=track&output=jcrpt&group=Produktberatung&hg=Pw__&hcgs=MQ__&htgs=MQ__&ovltwo=MQ__&ovlv=djI_&ovlc=MQ__&esc=IzU4NTg1YQ__&epc=I0JFMTUyRA__&ovlts=MA__&ovlmr=MTAw&ovlmb=MjY_&hfk=MQ__&ovloo=MQ__&hots=MQ__&hott=MQ__&nse=0.615520170244701",
        "https://www.hostrocket.com/js/jquery.price_slider.js",
        "bexarv6df.pdf",
        "xfe-URL-ewqopweowia543.ga-stix2-2.0-export.json",
        "tarrantcountydf.pdf",
        "jquery.cookie.js.pobrane",
        "https://matomo.hetzner.com/matomo.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-KW8B5L",
        "https://www.metronetinc.com/wp-content/plugins/lt-ajax-mn-channelguide/lt-ajax-mn-channelguide.js?ver=1.1",
        "https://accounts.hetzner.com/build/app.dc073715.js",
        "xfe-URL-matomo.hetzner.com-stix2-2.1-export.json",
        "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
        "https://www.googletagmanager.com/gtag/js?id=G-3XJ902FY6Q&l=dataLayer&cx=c",
        "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
        "https://fm.ipinyou.com/j/a.js",
        "bexar api 21.pdf",
        "https://img03.en25.com/i/elqCfg.min.js",
        "bootstrap.js.pobrane",
        "xfe-URL-bat.bing.com-stix2-2.1-export 2.json",
        "https://www.metronetinc.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0",
        "UE_pl_top.svg",
        "https://www.virustotal.com/static/js/base.min-2013121902.js",
        "ceidg.css",
        "https://www.yunshipei.com/assets/js/jquery.js",
        "https://h6.msn.com/bingna/lib/aria-webjs-compact-sdk/aria-webjs-compact-sdk-1.2.1.min.js",
        "bexar1.pdf",
        "biznes.css",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery.js",
        "https://vestacp.com/css/app.css",
        "xfe-URL-konsoleh.your-server.de-stix2-2.1-export.json",
        "SessionTimeout.js.pobrane",
        "jquery.alerts.js.pobrane",
        "bexar api 20.pdf",
        "bexar api 3.pdf",
        "https://www.metronetinc.com/wp-includes/js/wp-emoji-release.min.js?ver=5.8.4",
        "https://www.yunshipei.com/assets/js/app.min.js",
        "bexar6.pdf",
        "https://cdn.callrail.com/companies/431115301/7c8f964bc12313c75ad2/12/swap.js",
        "bootstrap-gov-pl.css",
        "https://www.layerhost.com/assets/js/slider.js",
        "https://subscribe.free.fr/assets/css/app2.min.css",
        "https://www.googletagmanager.com/gtag/js?id=AW-1027984682",
        "https://www.hushmail.com/status/",
        "ceidg-master.js.pobrane",
        "http://loviotvet.ru/lib/project/common.js",
        "bootmin-2013092601 2.js",
        "https://analytics.gandi.net/piwik.js",
        "ga.js",
        "tarrantcounty22df.pdf",
        "inputmask.binding.js.pobrane",
        "bexar api 15.pdf",
        "https://www.yunshipei.com/",
        "https://www.googletagmanager.com/gtm.js?id=GTM-PKDJJPC",
        "https://accounts.hetzner.com/login",
        "https://www.powr.io/powr.js?platform=html",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1027984682/?random=1653327072015&cv=9&fst=1653327072015&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=6&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa5b0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Fwww.dinancars.com%2Fabout%2F&ref=https%3A%2F%2Fwww.dinancars.com%2Fupdate-agent&tiba=About%20Dinan%20-%20Dinan&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://www.virustotal.com/en/file/undefined/analysis/",
        "https://static.zdassets.com/ekr/snippet.js?key=e7dd7ff5-a219-47a1-b096-069f750c234f",
        "https://connect.facebook.net/signals/plugins/identity.js?v=2.9.57",
        "https://www.hushmail.com/javascriptinclude/eNpNzEEOQDAQQNEbtVoM7Sks7GXopB0pkQ5xfWJl-5P3JWGh4AvukSRzoKKtqlWlf0Wt4k3rnG2g641Pl6QNOU83zcIn-QMj6ZHpHQ2FF97jiHOmj0ED4FxfwQOf9yPU.en_US.68448bd8190f2f2bae9633f547bbbbbe.0.js",
        "TarrantCounty19df.pdf",
        "jquery.dataTables.js.pobrane",
        "TarrantCounty9df.pdf",
        "https://www.layerhost.com/assets/js/vendor/foundation.min.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-MF25KRH",
        "bexar2.pdf",
        "https://webmail.free.fr/",
        "https://www.googleadservices.com/pagead/conversion/646812378/?random=1650430003991&cv=9&fst=1650430003991&num=1&value=0&label=6dFBCIm13s4BENqltrQC&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=3&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.metronetinc.com%2F&tiba=MetroNet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%2C%20Streaming%20TV%2C%20and%20Phone&",
        "www.bexar.org - urlscan.io.pdf",
        "https://vestacp.com/bower_components/foundation-sites/dist/js/foundation.js",
        "moment-with-locales.min.js.pobrane",
        "xfe-URL-tvsqpjwdni.com-stix2-2.1-export.json",
        "https://subscribe.free.fr/assets/js/main.min.js",
        "jquery.feedbackBadge.min.js.pobrane",
        "TarrantCounty21df.pdf",
        "jquery.maskedinput-1.2.2.js.pobrane",
        "https://www.metronetinc.com/wp-content/plugins/atomic-blocks/dist/assets/js/dismiss.js?ver=1625889728",
        "xfe-URL-https___www.gandi.net-stix2-2.1-export.json",
        "bexarv2df.pdf",
        "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
        "xfe-URL-Xelent.ru-stix2-2.1-export.json",
        "https://subscribe.free.fr/assets/js/vendor/jquery-1.9.1.min.js",
        "bexar api_1.pdf",
        "https://www.yunshipei.com/assets/js/amazeui.min.js",
        "jquery-migrate-1.2.1.js.pobrane",
        "bexar api 8.pdf",
        "bexar api 9.pdf",
        "popper.js.pobrane",
        "xfe-URL-hostrocket.com-stix2-2.1-export 2.json",
        "://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00m%00a%00r%00k",
        "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1068215855/?random=1650555348274&cv=9&fst=1650555348274&num=1&label=viUgCKmAuwMQr9yu_QM&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fhe.net%2F&tiba=Hurricane%20Electric%20Internet%20Services%20-%20Internet%20Backbone%20and%20Colocation%20Provider&hn=www.googleadservices.com&rfmt=3&fmt=4",
        "jquery.min.js",
        "https://www.layerhost.com/assets/js/jquery.filterizr.min.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/wz_tooltip.js",
        "TarrantCounty12df.pdf",
        "bexar5.pdf",
        "TarrantCounty20df.pdf",
        "https://www.hostrocket.com/js/jquery.cookie.js",
        "https://www.google.com/cse/cse.js?cx=016402751031109241230:v7vojvfohnq",
        "bexarv4df.pdf",
        "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
        "https://accounts.hetzner.com/build/802.3a7546ef.js",
        "https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js",
        "bexar api 17.pdf",
        "https://widget.trustpilot.com/bootstrap/v5/tp.widget.bootstrap.min.js",
        "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.aspx?Id=855bdfc1-7dbc-4a86-9d27-89ebb0ecf166&archival=False",
        "https://bitrix.info/ba.js",
        "https://tag.aticdn.net/616708/smarttag.js",
        "https://www.hostrocket.com/js/jquery-1.6.1.min.js",
        "https://h6.msn.com/nativeads/ms-nativeads-airfind.min.js?date=2022310",
        "AdminLTE.css",
        "https://vestacp.com/bower_components/what-input/dist/what-input.js",
        "http://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00m%00a%00r%00k",
        "https://stats.wp.com/e-202216.js",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
        "https://js.callrail.com/group/0/7c8f964bc12313c75ad2/06ababf0-8852-4eef-95e1-285ae467a93a/poll.js?t=1651861725881&ids%5B%5D=431115301",
        "dataTables.responsive.js.pobrane",
        "https://sdk.privacy-center.org/ui-gdpr-en.a96c69ed0cb8f37a2deea6c49dd453517875ac60.js",
        "bexar 6.pdf",
        "bexar10.pdf",
        "https://www.gandi.net/static/js/legacy.7cc648e3ff7a.js",
        "UE_pl_top_sm.svg",
        "bexar api.pdf",
        "https://hybrid-analysis.com/sample/e7740c893812cea8e34ffb04331dcc45762dec73def71929bfbabcbfb22e93e9/641e30763dcad56bc2075661",
        "https://accounts.hetzner.com/build/runtime.188fa053.js",
        "https://cdnjs.cloudflare.com/ajax/libs/jqueryui/1.12.1/jquery-ui.min.js",
        "https://www.hostrocket.com/js/jquery.colorbox-min.js",
        "https://webmail.free.fr/plugins/jqueryui/js/jquery-ui.min.js?s=1510166524",
        "https://www.hostrocket.com/css/style-nophone.css",
        "https://www.googletagmanager.com/gtm.js?id=GTM-W3GQ4F",
        "adminlte.min.js.pobrane",
        "https://vestacp.com/js/app.js",
        "saved_resource.html",
        "jquery.easing.1.3.js.pobrane",
        "https://konsoleh.your-server.de/templates/ui-default/de/styles/login.css.php",
        "TarrantCounty7df.pdf",
        "xfe-IP-136.243.64.87-stix2-2.1-export.json",
        "bexasv3df.pdf",
        "dataTables.lang.js.pobrane",
        "https://www.layerhost.com/assets/js/vendor/what-input.js",
        "https://livesupport.hetzner.de/script.php?id=eec8dcd79d6fdf905136b99875c1d599",
        "https://www.virustotal.com/static/css/bootstrap.min.css?20150630",
        "daterangepicker.css",
        "https://subscribe.free.fr/assets/js/plugins.min.js",
        "https://connect.facebook.net/signals/config/2196524664009793?v=2.9.57&r=stable",
        "https://ajax.aspnetcdn.com/ajax/jQuery/jquery-1.7.1.min.js",
        "https://www.metronetinc.com/wp-content/plugins/pixel-caffeine/build/frontend.js?ver=2.3.3",
        "https://v2.zopim.com/bin/v/widget_v2.329.js",
        "https://csp.he.net/styles/style.css",
        "https://www.dinancars.com/assets/css/jquery-ui-custom.css",
        "tarrantcounty8df.pdf",
        "bexar api 7.pdf",
        "bexar3.pdf",
        "https://subscribe.free.fr/accesgratuit/index.html",
        "https://img03.en25.com/i/livevalidation_standalone.compressed.js",
        "https://cdnjs.cloudflare.com/ajax/libs/twitter-bootstrap/3.3.7/js/bootstrap.min.js",
        "EntryChangeHistory.aspx.js.pobrane",
        "https://www.dinancars.com/assets/js/combine/min/v1653077793/e88cd3e3db8ab2b910e50cf4deb60529f/default;jquery-ui.min;js.cookie;util;nav;cart;accountfunctions;jquery.activity-indicator-1.0.0.min;drawer_plugin;floating_label_gen;jquery.autoellipsis-1.0.10;fresco;fresco-custom;isotope_imagesloaded.min;promo_autoplus_helpers;slick.min;widgets;jquery.custom-carousel;waterfall_helpers/",
        "XZ4AH-ABKPW-SQPBC-CYWES-BCG6V",
        "xfe-IP-134.73.11.118-stix2-2.1-export.json",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/646812378/?random=1650430003991&cv=9&fst=1650430003991&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=3&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.metronetinc.com%2F&tiba=MetroNet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%2C%20Streaming%20TV%2C%20and%20Phone&hn=www.googleadservic",
        "https://www.hostrocket.com/js/jquery.cycle.all.js",
        "tarrantcounty.com:en:elections:Voter-Information:Voter- Registration.html%22,.pdf",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/languages/en.js",
        "https://sgoutong.baidu.com/embed/1652930761/asset/embed/css/mobile/main.css",
        "https://a2.adform.net/serving/scripts/trackpoint/async/",
        "ui.datepicker-pl.js.pobrane",
        "TarrantCounty5df.pdf",
        "https://apis.google.com/js/plusone.js",
        "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
        "ui.notify.css",
        "TarrantCounty1df.pdf",
        "https://www.hostrocket.com/js/jquery.selectBox.min.js",
        "https://js.hs-scripts.com/8009596.js",
        "xfe-URL-Hush.com-stix2-2.1-export.json",
        "CommonResponsive.js.pobrane",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery-migrate.js",
        "https://widget.wickedreports.com/v2/3469/wr-dafa9fae816c2f65d24d1eb593b58626.js",
        "https://ajax.googleapis.com/ajax/libs/jquery/3.3.1/jquery.min.js",
        "https://11057407.fls.doubleclick.net/activityi;src=11057407;type=count0;cat=sitev0;ord=1;num=5426507653008;gtm=2wg4i1;auiddc=1460077727.1650429649;~oref=https%3A%2F%2Fwww.metronetinc.com%2F",
        "bexar_v1df.pdf",
        "tarrant23df.pdf",
        "bexar api 13.pdf",
        "bexar api 4.pdf",
        "https://www.layerhost.com/assets/js/app.js",
        "https://vestacp.com/bower_components/jquery/dist/jquery.js",
        "bexar api 2.pdf",
        "bexar api5.pdf",
        "bexar api 19.pdf",
        "https://www.gandi.net/static/js/modern.27ee934b0dc5.js",
        "https://www.hostrocket.com/js/jquery.behavior.js",
        "https://www.hushmail.com/javascriptinclude/eNrLKC3OyE3MzIkvT00qzixJtSpITE_V98lPz8xzyy_K1csqtjI0MzK2MDcwsbS0ysCq2qkov7w4tSi4JLGkGFUDAF_tIM0,.en_US.68448bd8190f2f2bae9633f547bbbbbe.0.js",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-2d0d2b7c.js",
        "https://cdn-scripts.signifyd.com/api/script-tag.js",
        "dataTables.input.js.pobrane",
        "TarrantCounty4df.pdf",
        "https://ajax.googleapis.com/ajax/libs/jquery/1.7.1/jquery.min.js",
        "https://widget.trustpilot.com/trustboxes/5406e65db0d04a09e042d5fc/index.html?templateId=5406e65db0d04a09e042d5fc&businessunitId=4bdc496b000064000505a89d#locale=en-US&styleHeight=28px&styleWidth=100%25&theme=light",
        "TarrantCounty14df.pdf",
        "bexar api 14.pdf",
        "https://ajax.googleapis.com/ajax/libs/jquery/1.7.2/jquery.min.js",
        "dataTables.bootstrap4.js.pobrane",
        "feedback.js.pobrane",
        "https://www.googletagmanager.com/gtag/js?id=UA-1837381-13",
        "jquery.notify.min.js.pobrane",
        "https://www.hostrocket.com/css/colorbox.css",
        "https://top-fwz1.mail.ru/js/code.js",
        "https://www.virustotal.com/static/js/bootmin-2013092601.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/982771034/?random=1650430003990&cv=9&fst=1650430003990&num=1&label=Remarketing%20-%20All%20Pages&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=3&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.metronetinc.com%2F&tiba=MetroNet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%20%E2%80%93%20100%25%20Fiber%20Optic%20Internet%2C%20Streaming%20TV%2C",
        "https://www.metronetinc.com/wp-content/themes/MetroNet/js/flexslider-init.js?ver=5.8.4",
        "https://www.hostrocket.com/js/jquery-ui-1.8.13.custom.min.js",
        "https://subscribe.free.fr/assets/js/vendor/modernizr.custom.js",
        "TarrantCounty17df.pdf",
        "bexar api 22.pdf",
        "json2.js.pobrane",
        "https://www.dinancars.com/update-agent",
        "TarrantCounty6df.pdf",
        "https://www.googleadservices.com/pagead/conversion_async.js",
        "xfe-URL-livesupport.hetzner.de-stix2-2.1-export.json",
        "bootstrap.min.css",
        "https://www.googletagmanager.com/gtag/js?id=G-34X541384L",
        "https://bat.bing.com/p/action/140000459.js",
        "xfe-URL-metronetinc.com-stix2-2.1-export.json"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Filterizr api",
            "Bnm",
            "Flexslider",
            "Reduceright",
            "Gc",
            "Hammer",
            "Okcancel",
            "Ovlcwm",
            "Activedocument",
            "Eq",
            "Eventtarget",
            "V[1]-1:k+=",
            "Vd"
          ],
          "industries": [
            "Government"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 26,
  "pulses": [
    {
      "id": "68038f7eb6f6810aa6d6439f",
      "name": "\"+g+\"",
      "description": "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.aspx?Id=855bdfc1-7dbc-4a86-9d27-89ebb0ecf166&archival=False",
      "modified": "2025-09-01T08:05:25.121000",
      "created": "2025-04-19T11:56:46.933000",
      "tags": [
        "copyright",
        "customevent",
        "typeof e",
        "boomerang",
        "typeof t",
        "macintosh",
        "os x",
        "post",
        "typeof",
        "iframe",
        "date",
        "poka menu",
        "nie znaleziono",
        "poka start",
        "poka",
        "max dostpnych",
        "pierwsza",
        "ostatnia",
        "nastpna",
        "poprzednia",
        "brak danych",
        "first",
        "ceidg",
        "wystpi bd",
        "error",
        "true",
        "null",
        "linkdownload",
        "show",
        "ctrlmappings",
        "version",
        "versionchange",
        "body",
        "false",
        "span",
        "input",
        "paginate",
        "next",
        "last",
        "selectstart",
        "loop",
        "function",
        "bootstrap",
        "datatables",
        "responsive",
        "2016 sprymedia",
        "amd define",
        "object",
        "commonjs",
        "window",
        "browser",
        "button",
        "datatable",
        "sprymedia ltd",
        "columns",
        "colidx",
        "column",
        "parent",
        "child",
        "param",
        "display",
        "click",
        "middle",
        "class",
        "target",
        "never",
        "find",
        "footer",
        "close",
        "regexp",
        "matches",
        "cookie",
        "inputmask",
        "input mask",
        "robin herbots",
        "mit license",
        "xmlhttprequest",
        "left",
        "month",
        "boolean",
        "maxdate",
        "right",
        "daterangepicker",
        "yyyymmdd",
        "calendar",
        "jquery",
        "webpackrequire",
        "typeof symbol",
        "type",
        "setprototypeof",
        "maskpos",
        "wrapnativesuper",
        "backspace",
        "insert",
        "internal",
        "mask",
        "void",
        "this",
        "nie mona",
        "array",
        "nonmsdombrowser",
        "horizontal",
        "leftarrow",
        "uparrow",
        "rightarrow",
        "downarrow",
        "explorer",
        "form",
        "legend",
        "hmmss",
        "mmmm d",
        "yyyy h",
        "typeof define",
        "number",
        "locale",
        "character",
        "seeknext",
        "masked",
        "input plugin",
        "josh bush",
        "azaz",
        "azaz09",
        "black",
        "kontrast",
        "arrcookies",
        "getcookielang",
        "and information",
        "on business",
        "sign",
        "twoja",
        "opinia",
        "informacja o",
        "notify ui",
        "widget",
        "eric hynds",
        "dual",
        "name",
        "dtopt",
        "example",
        "using",
        "open",
        "adata",
        "hungarian",
        "aria",
        "legacy",
        "trident",
        "format",
        "nuke",
        "apos",
        "bitcoin",
        "outer",
        "mark",
        "info",
        "reload",
        "behaviour",
        "write",
        "buttons",
        "anything",
        "prop",
        "thecookie",
        "create",
        "thevalue",
        "string name",
        "pluginscookie",
        "author",
        "eventkey",
        "datakey",
        "default",
        "dataapikey",
        "defaulttype",
        "config",
        "shown",
        "trigger",
        "delta",
        "guard",
        "arrow",
        "leave",
        "scroll",
        "dataspy",
        "sessiontimeout",
        "return",
        "settimeout",
        "mytimerid",
        "requestcounter",
        "starttimer",
        "stop",
        "typeof n",
        "adminlte",
        "typeof o",
        "main",
        "js application",
        "adminlte v2",
        "colorlib",
        "ui date",
        "written",
        "jacek wysocki",
        "poprzedni",
        "marzec",
        "kwiecie",
        "czerwiec",
        "lipiec",
        "sierpie",
        "wrzesie",
        "openpopup",
        "href",
        "toggle",
        "msviewport",
        "popover",
        "json",
        "json text",
        "string",
        "otherwise",
        "holder",
        "mind",
        "copy",
        "meta",
        "third",
        "text",
        "choice",
        "confirm",
        "nie pytaj",
        "site",
        "title",
        "value",
        "alert",
        "warn",
        "migrate",
        "foundation",
        "see http",
        "forget",
        "newvalue",
        "nones5",
        "fall",
        "wrongvalid",
        "onerror",
        "year",
        "fast",
        "argument",
        "popper",
        "method",
        "data",
        "html",
        "flip",
        "factory",
        "onload",
        "tbody",
        "courier",
        "elem",
        "handle",
        "expando",
        "match",
        "selector",
        "sizzle",
        "android",
        "capture",
        "seed",
        "pass",
        "enough",
        "code",
        "bind",
        "core",
        "local",
        "verify",
        "accept",
        "done",
        "override",
        "inject",
        "possible",
        "hold",
        "45deg",
        "larger",
        "screen styling",
        "90deg",
        "support",
        "sidebar mini",
        "e1f0ff",
        "font awesome",
        "free",
        "autocomplete",
        "folder",
        "expanded folder",
        "tabela",
        "sorting",
        "xform",
        "nadpisane style",
        "menlo",
        "monaco",
        "consolas",
        "mono",
        "courier new",
        "browse",
        "twitter",
        "pt serif",
        "georgia",
        "times new",
        "roman",
        "times",
        "typetime",
        "import",
        "roboto",
        "http",
        "label",
        "demos",
        "effect",
        "inst",
        "super",
        "speed",
        "bounce",
        "hack",
        "logic",
        "shift",
        "double",
        "february",
        "april",
        "june",
        "august",
        "friday",
        "erase",
        "atom",
        "caja",
        "spinner",
        "refresh",
        "alpha",
        "sentinel",
        "back",
        "blind",
        "drop",
        "ceidg.gov.pl - centralna ewidencja i informacja o dzia\u0142alno\u015bci g",
        "prosz czeka",
        "pobierz plik"
      ],
      "references": [
        "https://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.aspx?Id=855bdfc1-7dbc-4a86-9d27-89ebb0ecf166&archival=False",
        "UE_pl_top.svg",
        "UE_pl_top_sm.svg",
        "XZ4AH-ABKPW-SQPBC-CYWES-BCG6V",
        "dataTables.lang.js.pobrane",
        "EntryChangeHistory.aspx.js.pobrane",
        "dataTables.input.js.pobrane",
        "responsive.bootstrap4.js.pobrane",
        "dataTables.bootstrap4.js.pobrane",
        "dataTables.responsive.js.pobrane",
        "jquery.session.js.pobrane",
        "inputmask.binding.js.pobrane",
        "daterangepicker.js.pobrane",
        "jquery.inputmask.min.js.pobrane",
        "ScriptResource.axd",
        "moment-with-locales.min.js.pobrane",
        "jquery.maskedinput-1.2.2.js.pobrane",
        "feedback.js.pobrane",
        "jquery.notify.min.js.pobrane",
        "jquery.dataTables.js.pobrane",
        "jquery.cookie.js.pobrane",
        "bootstrap.js.pobrane",
        "SessionTimeout.js.pobrane",
        "adminlte.min.js.pobrane",
        "jquery.easing.1.3.js.pobrane",
        "jquery.feedbackBadge.min.js.pobrane",
        "ui.datepicker-pl.js.pobrane",
        "ceidg-master.js.pobrane",
        "CommonResponsive.js.pobrane",
        "json2.js.pobrane",
        "jquery.alerts.js.pobrane",
        "jquery-migrate-1.2.1.js.pobrane",
        "dataTables.bootstrap4.css",
        "CommonScripts.js.pobrane",
        "popper.js.pobrane",
        "responsive.bootstrap4.css",
        "jquery-3.0.0.js.pobrane",
        "daterangepicker.css",
        "AdminLTE.css",
        "ui.notify.css",
        "ceidg.css",
        "bootstrap-gov-pl.css",
        "biznes.css",
        "jquery-ui.js.pobrane",
        "saved_resource.html"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3,
        "FileHash-SHA1": 4,
        "FileHash-SHA256": 25,
        "URL": 165,
        "domain": 353,
        "hostname": 215,
        "email": 2
      },
      "indicator_count": 767,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "272 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "657098ff4c59f8ac3f86f613",
      "name": "v2 of web.basemark.com plus all suggested ioc,s dont forget about the dropped js files from the 2nd hybrid link",
      "description": "",
      "modified": "2023-12-06T15:53:35.032000",
      "created": "2023-12-06T15:53:35.032000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1168,
        "hostname": 1366,
        "domain": 412,
        "URL": 3576,
        "email": 2,
        "FileHash-MD5": 61,
        "FileHash-SHA1": 54
      },
      "indicator_count": 6639,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c57c7b19b62c501601a",
      "name": "Hurricane Electric - csp.he.net :)",
      "description": "",
      "modified": "2023-12-06T14:59:35.479000",
      "created": "2023-12-06T14:59:35.479000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 186,
        "hostname": 490,
        "URL": 1339,
        "domain": 311
      },
      "indicator_count": 2326,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c27074200c710e3b35c",
      "name": "Malware hosting - metronetinc.com",
      "description": "",
      "modified": "2023-12-06T14:58:47.235000",
      "created": "2023-12-06T14:58:47.235000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 447,
        "hostname": 1241,
        "domain": 536,
        "URL": 3731
      },
      "indicator_count": 5955,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c13ee010f81d3f9b3af",
      "name": "Malware hosting - hostrocket.com",
      "description": "",
      "modified": "2023-12-06T14:58:27.115000",
      "created": "2023-12-06T14:58:27.115000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 232,
        "hostname": 963,
        "domain": 412,
        "URL": 2337,
        "email": 3,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1
      },
      "indicator_count": 3949,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708b77797823dea739cc25",
      "name": "ReduceRight malware-",
      "description": "",
      "modified": "2023-12-06T14:55:51.023000",
      "created": "2023-12-06T14:55:51.023000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 110,
        "domain": 541,
        "URL": 2043,
        "hostname": 1106
      },
      "indicator_count": 3800,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708b5e9b8ce0f5fd87fb98",
      "name": "ewqopweowia543.ga",
      "description": "",
      "modified": "2023-12-06T14:55:26.621000",
      "created": "2023-12-06T14:55:26.621000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "hostname": 706,
        "domain": 234,
        "FileHash-SHA256": 238,
        "URL": 1386
      },
      "indicator_count": 2565,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "657080d20f7e10c1e37fcf89",
      "name": "TarrantCounty.com ~ 03.01.2022",
      "description": "",
      "modified": "2023-12-06T14:10:26.301000",
      "created": "2023-12-06T14:10:26.301000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1078,
        "domain": 838,
        "hostname": 1607,
        "URL": 4134,
        "email": 3,
        "FileHash-SHA1": 2,
        "CIDR": 4,
        "FileHash-MD5": 15
      },
      "indicator_count": 7681,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707fe17dfdfe16066d16de",
      "name": "Bexar.org",
      "description": "",
      "modified": "2023-12-06T14:06:25.800000",
      "created": "2023-12-06T14:06:25.800000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1735,
        "hostname": 1833,
        "domain": 1025,
        "URL": 4668,
        "email": 4,
        "FileHash-MD5": 133,
        "FileHash-SHA1": 6,
        "CIDR": 5
      },
      "indicator_count": 9409,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6425a2f9c155fd53b9922bcd",
      "name": "v2 of web.basemark.com plus all suggested ioc,s dont forget about the dropped js files from the 2nd hybrid link",
      "description": "hope peeps are gona learn from 3cx that false positives are in fact often not false",
      "modified": "2023-04-29T13:05:05.409000",
      "created": "2023-03-30T14:55:53.652000",
      "tags": [
        "trojan",
        "apt",
        "ansi",
        "dropped file",
        "runtime data",
        "chromeua",
        "optout",
        "programfiles",
        "typeof e",
        "localappdata",
        "error",
        "date",
        "generator",
        "path",
        "null",
        "void",
        "win64",
        "twitter",
        "this",
        "critical",
        "desktop",
        "dark",
        "light",
        "meta",
        "roboto",
        "span",
        "class",
        "template",
        "blink",
        "suspicious",
        "facebook",
        "mexico",
        "malicious",
        "mozilla",
        "strings",
        "qakbot",
        "://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/e7740c893812cea8e34ffb04331dcc45762dec73def71929bfbabcbfb22e93e9",
        "https://hybrid-analysis.com/sample/e7740c893812cea8e34ffb04331dcc45762dec73def71929bfbabcbfb22e93e9/641e30763dcad56bc2075661",
        "http://web.basemark.com/result/?4A3D0fmu%1C%00%00%00B%00a%00s%00e%00m%00a%00r%00k"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 412,
        "FileHash-SHA256": 1168,
        "URL": 3576,
        "hostname": 1366,
        "email": 2,
        "FileHash-MD5": 61,
        "FileHash-SHA1": 54
      },
      "indicator_count": 6639,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "1128 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "element.show",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "element.show",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780242648.6276646
}