{
  "type": "Domain",
  "indicator": "ever-note.net",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/ever-note.net",
    "alexa": "http://www.alexa.com/siteinfo/ever-note.net",
    "indicator": "ever-note.net",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3605695921,
      "indicator": "ever-note.net",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "6a1562e873e9552952bc9d85",
          "name": "undefined",
          "description": "",
          "modified": "2026-05-31T05:20:48.924000",
          "created": "2026-05-26T09:07:52.801000",
          "tags": [
            "number",
            "label google",
            "llc regional",
            "arin country",
            "us continent",
            "address range",
            "cidr",
            "network name",
            "type",
            "status",
            "whois server",
            "entity gogl",
            "handle",
            "please",
            "google team",
            "orgtechhandle",
            "google llc",
            "orgtechphone",
            "orgtechref",
            "orgabusehandle",
            "orgabuseref"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 173,
            "hostname": 157,
            "CIDR": 1,
            "URL": 32,
            "email": 3,
            "IPv4": 7,
            "CVE": 1
          },
          "indicator_count": 374,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "5 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1562e6c36e0bce0bbc6e6d",
          "name": "undefined",
          "description": "",
          "modified": "2026-05-31T04:12:24.722000",
          "created": "2026-05-26T09:07:50.368000",
          "tags": [
            "number",
            "label google",
            "llc regional",
            "arin country",
            "us continent",
            "address range",
            "cidr",
            "network name",
            "type",
            "status",
            "whois server",
            "entity gogl",
            "handle",
            "please",
            "google team",
            "orgtechhandle",
            "google llc",
            "orgtechphone",
            "orgtechref",
            "orgabusehandle",
            "orgabuseref"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 171,
            "hostname": 151,
            "CIDR": 1,
            "URL": 28,
            "email": 3,
            "IPv4": 6,
            "CVE": 1
          },
          "indicator_count": 361,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "6 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1562e60a4d6b20ea54df6c",
          "name": "undefined",
          "description": "",
          "modified": "2026-05-31T04:12:24.118000",
          "created": "2026-05-26T09:07:49.970000",
          "tags": [
            "number",
            "label google",
            "llc regional",
            "arin country",
            "us continent",
            "address range",
            "cidr",
            "network name",
            "type",
            "status",
            "whois server",
            "entity gogl",
            "handle",
            "please",
            "google team",
            "orgtechhandle",
            "google llc",
            "orgtechphone",
            "orgtechref",
            "orgabusehandle",
            "orgabuseref"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 170,
            "hostname": 151,
            "CIDR": 1,
            "URL": 26,
            "email": 3,
            "IPv4": 6,
            "CVE": 1
          },
          "indicator_count": 358,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "6 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1562e62e5be9a7de4c0937",
          "name": "undefined",
          "description": "",
          "modified": "2026-05-31T04:12:14.707000",
          "created": "2026-05-26T09:07:50.912000",
          "tags": [
            "number",
            "label google",
            "llc regional",
            "arin country",
            "us continent",
            "address range",
            "cidr",
            "network name",
            "type",
            "status",
            "whois server",
            "entity gogl",
            "handle",
            "please",
            "google team",
            "orgtechhandle",
            "google llc",
            "orgtechphone",
            "orgtechref",
            "orgabusehandle",
            "orgabuseref"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 171,
            "hostname": 151,
            "CIDR": 1,
            "URL": 29,
            "email": 3,
            "IPv4": 6,
            "CVE": 1
          },
          "indicator_count": 362,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "6 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1562e7e7a6bccba96459bf",
          "name": "undefined",
          "description": "",
          "modified": "2026-05-31T04:12:13.279000",
          "created": "2026-05-26T09:07:51.650000",
          "tags": [
            "number",
            "label google",
            "llc regional",
            "arin country",
            "us continent",
            "address range",
            "cidr",
            "network name",
            "type",
            "status",
            "whois server",
            "entity gogl",
            "handle",
            "please",
            "google team",
            "orgtechhandle",
            "google llc",
            "orgtechphone",
            "orgtechref",
            "orgabusehandle",
            "orgabuseref"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 224,
            "hostname": 412,
            "CIDR": 9,
            "URL": 158,
            "email": 8,
            "FileHash-SHA1": 12,
            "IPv4": 36,
            "IPv6": 3,
            "FileHash-MD5": 8,
            "FileHash-SHA256": 57,
            "CVE": 1
          },
          "indicator_count": 928,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "6 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "647c2f894012e970bee9875e",
          "name": "Raccoon Stealer (Legion) Malware",
          "description": "Recorded future: Raccoon Stealer (Legion) IOCs",
          "modified": "2023-07-04T06:03:55.157000",
          "created": "2023-06-04T06:30:33.164000",
          "tags": [
            "domain",
            "ip address",
            "hash",
            "hashsha256",
            "hashmd5",
            "redacted"
          ],
          "references": [
            "Raccoon Stealer (Legion).csv"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Trojan:Win32/Raccoonstealer",
              "display_name": "Trojan:Win32/Raccoonstealer",
              "target": "/malware/Trojan:Win32/Raccoonstealer"
            },
            {
              "id": "777(Legion)",
              "display_name": "777(Legion)",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "akhanafeer",
            "id": "195327",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 40,
            "FileHash-MD5": 44,
            "FileHash-SHA1": 43,
            "FileHash-SHA256": 58,
            "domain": 78,
            "hostname": 23
          },
          "indicator_count": 286,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 72,
          "modified_text": "1062 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63b2e34caf4d7502e8d1abb2",
          "name": "\u201cMasquerAds\u201d \u2014 Google\u2019s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets",
          "description": "A newly uncovered technique to abuse Google\u2019s ad-words has revealed how threat actors are using the platform to spread malware through its search engine, Google Ads, and other ad sites..",
          "modified": "2023-02-01T13:04:04.062000",
          "created": "2023-01-02T13:59:40.798000",
          "tags": [
            "targeted",
            "obs studio",
            "viewer",
            "brave browser",
            "libreoffice",
            "axelar",
            "samourai wallet",
            "aptos wallet",
            "first horizon",
            "bank",
            "github",
            "sign",
            "secret",
            "embed",
            "learn",
            "strong",
            "unicode",
            "skip",
            "github sign",
            "instantly share",
            "star",
            "copy",
            "discord",
            "footer",
            "e&s",
            "vidar",
            "grammarly",
            "msi afterburner",
            "google ads",
            "google",
            "vermux",
            "gpus",
            "afterburner",
            "slack",
            "russia",
            "easy",
            "virustotal",
            "concept"
          ],
          "references": [
            "https://labs.guard.io/masquerads-googles-ad-words-massively-abused-by-threat-actors-targeting-organizations-gpus-42ae73ee8a1e",
            "https://gist.github.com/guardiolabs/2178c54367d20b0655b5cc5e9d297760"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "Google Ads",
              "display_name": "Google Ads",
              "target": null
            },
            {
              "id": "MSI Afterburner",
              "display_name": "MSI Afterburner",
              "target": null
            },
            {
              "id": "Grammarly",
              "display_name": "Grammarly",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 48,
            "FileHash-MD5": 3,
            "FileHash-SHA256": 7,
            "domain": 174,
            "FileHash-SHA1": 1,
            "hostname": 31
          },
          "indicator_count": 264,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1214 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63ae2a52745f31286f01dcde",
          "name": "\u201cMasquerAds\u201d \u2014 Google\u2019s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets",
          "description": "",
          "modified": "2023-01-29T00:00:01.036000",
          "created": "2022-12-30T00:01:22.993000",
          "tags": [
            "OSINT",
            "Phishing",
            "SEO Poisoning",
            "Google Ads",
            "TypoSquatting",
            "T1036",
            "T1608.006",
            "T1566"
          ],
          "references": [
            "https://community.riskiq.com/article/bde7076e"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 39,
            "domain": 167,
            "hostname": 28
          },
          "indicator_count": 234,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1621,
          "modified_text": "1218 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63ad751c3a357e39e9e5cc8d",
          "name": "Google Ads Malvertising Campaign Targets Users Searching for Popular Software",
          "description": "",
          "modified": "2023-01-28T11:01:09.937000",
          "created": "2022-12-29T11:08:12.176000",
          "tags": [
            "github",
            "sign",
            "secret",
            "embed",
            "learn",
            "strong",
            "unicode",
            "skip",
            "github sign",
            "instantly share",
            "star",
            "copy",
            "discord",
            "footer"
          ],
          "references": [
            "https://gist.github.com/guardiolabs/2178c54367d20b0655b5cc5e9d297760"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 6,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 7,
            "domain": 65,
            "hostname": 26
          },
          "indicator_count": 106,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 500,
          "modified_text": "1218 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63ad7aeeba5af237234ce040",
          "name": "Google\u2019s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets",
          "description": "A newly uncovered technique to abuse Google's ad-words by masquerade and redirect ad-clickers to malicious phishing pages.\n\nAccording to Guardio Labs, threat actors have been observed creating a network of benign sites that are promoted on the search engine, which when clicked, redirect the visitors to a phishing page containing a trojanized ZIP archive hosted on Dropbox or OneDrive. Among the impersonated software include AnyDesk, Dashlane, Grammarly, Malwarebytes, Microsoft Visual Studio, MSI Afterburner, Slack, and Zoom, among others.\n\nUsers are advised to strengthen their understanding of security knowledge and further enhance their ability to identify phishing attacks in order to avoid falling victim to such attacks.",
          "modified": "2023-01-28T11:01:09.937000",
          "created": "2022-12-29T11:33:01.913000",
          "tags": [
            "Crypto Wallet",
            "Phishing",
            "Organization",
            "GPUs",
            "Google-Ads"
          ],
          "references": [
            "https://gist.github.com/guardiolabs/2178c54367d20b0655b5cc5e9d297760",
            "https://labs.guard.io/masquerads-googles-ad-words-massively-abused-by-threat-actors-targeting-organizations-gpus-42ae73ee8a1e"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Russian Federation",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Racoon Stealer",
              "display_name": "Racoon Stealer",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1134",
              "name": "Access Token Manipulation",
              "display_name": "T1134 - Access Token Manipulation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            }
          ],
          "industries": [
            "Crypto",
            "Finance",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Superpro",
            "id": "61676",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 6,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 7,
            "domain": 65,
            "hostname": 26
          },
          "indicator_count": 106,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 213,
          "modified_text": "1218 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63ad3d988415a5779e1fa7ed",
          "name": "\u201cMasquerAds\u201d \u2014 Google\u2019s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets",
          "description": "The results of Vermux 2016-17 have been released and will be published in full on Wednesday, 2 January 2017, at 09:00 BST.. and they will appear on the BBC News website.",
          "modified": "2023-01-28T07:04:14.838000",
          "created": "2022-12-29T07:11:20.138000",
          "tags": [
            "vidar",
            "grammarly",
            "msi afterburner",
            "google ads",
            "google",
            "vermux",
            "gpus",
            "afterburner",
            "github",
            "slack",
            "russia",
            "easy",
            "virustotal",
            "concept",
            "activity",
            "geforce",
            "blender branded",
            "discord",
            "related malware",
            "targeted",
            "obs studio",
            "viewer",
            "brave browser",
            "libreoffice",
            "axelar",
            "samourai wallet",
            "aptos wallet",
            "first horizon",
            "bank"
          ],
          "references": [
            "masquerads_iocs_vermux.txt",
            "masquerads_iocs.txt",
            "https://labs.guard.io/masquerads-googles-ad-words-massively-abused-by-threat-actors-targeting-organizations-gpus-42ae73ee8a1e"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "Google Ads",
              "display_name": "Google Ads",
              "target": null
            },
            {
              "id": "MSI Afterburner",
              "display_name": "MSI Afterburner",
              "target": null
            },
            {
              "id": "Grammarly",
              "display_name": "Grammarly",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cyberasmi",
            "id": "169715",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 21,
            "domain": 174,
            "hostname": 31,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1,
            "FileHash-SHA256": 7
          },
          "indicator_count": 237,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1219 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "masquerads_iocs.txt",
        "https://community.riskiq.com/article/bde7076e",
        "https://gist.github.com/guardiolabs/2178c54367d20b0655b5cc5e9d297760",
        "masquerads_iocs_vermux.txt",
        "https://labs.guard.io/masquerads-googles-ad-words-massively-abused-by-threat-actors-targeting-organizations-gpus-42ae73ee8a1e",
        "Raccoon Stealer (Legion).csv"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Trojan:win32/raccoonstealer",
            "Google ads",
            "Vidar",
            "Racoon stealer",
            "Grammarly",
            "777(legion)",
            "Msi afterburner"
          ],
          "industries": [
            "Technology",
            "Crypto",
            "Finance"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "6a1562e873e9552952bc9d85",
      "name": "undefined",
      "description": "",
      "modified": "2026-05-31T05:20:48.924000",
      "created": "2026-05-26T09:07:52.801000",
      "tags": [
        "number",
        "label google",
        "llc regional",
        "arin country",
        "us continent",
        "address range",
        "cidr",
        "network name",
        "type",
        "status",
        "whois server",
        "entity gogl",
        "handle",
        "please",
        "google team",
        "orgtechhandle",
        "google llc",
        "orgtechphone",
        "orgtechref",
        "orgabusehandle",
        "orgabuseref"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 173,
        "hostname": 157,
        "CIDR": 1,
        "URL": 32,
        "email": 3,
        "IPv4": 7,
        "CVE": 1
      },
      "indicator_count": 374,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "5 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1562e6c36e0bce0bbc6e6d",
      "name": "undefined",
      "description": "",
      "modified": "2026-05-31T04:12:24.722000",
      "created": "2026-05-26T09:07:50.368000",
      "tags": [
        "number",
        "label google",
        "llc regional",
        "arin country",
        "us continent",
        "address range",
        "cidr",
        "network name",
        "type",
        "status",
        "whois server",
        "entity gogl",
        "handle",
        "please",
        "google team",
        "orgtechhandle",
        "google llc",
        "orgtechphone",
        "orgtechref",
        "orgabusehandle",
        "orgabuseref"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 171,
        "hostname": 151,
        "CIDR": 1,
        "URL": 28,
        "email": 3,
        "IPv4": 6,
        "CVE": 1
      },
      "indicator_count": 361,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "6 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1562e60a4d6b20ea54df6c",
      "name": "undefined",
      "description": "",
      "modified": "2026-05-31T04:12:24.118000",
      "created": "2026-05-26T09:07:49.970000",
      "tags": [
        "number",
        "label google",
        "llc regional",
        "arin country",
        "us continent",
        "address range",
        "cidr",
        "network name",
        "type",
        "status",
        "whois server",
        "entity gogl",
        "handle",
        "please",
        "google team",
        "orgtechhandle",
        "google llc",
        "orgtechphone",
        "orgtechref",
        "orgabusehandle",
        "orgabuseref"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 170,
        "hostname": 151,
        "CIDR": 1,
        "URL": 26,
        "email": 3,
        "IPv4": 6,
        "CVE": 1
      },
      "indicator_count": 358,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "6 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1562e62e5be9a7de4c0937",
      "name": "undefined",
      "description": "",
      "modified": "2026-05-31T04:12:14.707000",
      "created": "2026-05-26T09:07:50.912000",
      "tags": [
        "number",
        "label google",
        "llc regional",
        "arin country",
        "us continent",
        "address range",
        "cidr",
        "network name",
        "type",
        "status",
        "whois server",
        "entity gogl",
        "handle",
        "please",
        "google team",
        "orgtechhandle",
        "google llc",
        "orgtechphone",
        "orgtechref",
        "orgabusehandle",
        "orgabuseref"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 171,
        "hostname": 151,
        "CIDR": 1,
        "URL": 29,
        "email": 3,
        "IPv4": 6,
        "CVE": 1
      },
      "indicator_count": 362,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "6 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1562e7e7a6bccba96459bf",
      "name": "undefined",
      "description": "",
      "modified": "2026-05-31T04:12:13.279000",
      "created": "2026-05-26T09:07:51.650000",
      "tags": [
        "number",
        "label google",
        "llc regional",
        "arin country",
        "us continent",
        "address range",
        "cidr",
        "network name",
        "type",
        "status",
        "whois server",
        "entity gogl",
        "handle",
        "please",
        "google team",
        "orgtechhandle",
        "google llc",
        "orgtechphone",
        "orgtechref",
        "orgabusehandle",
        "orgabuseref"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 224,
        "hostname": 412,
        "CIDR": 9,
        "URL": 158,
        "email": 8,
        "FileHash-SHA1": 12,
        "IPv4": 36,
        "IPv6": 3,
        "FileHash-MD5": 8,
        "FileHash-SHA256": 57,
        "CVE": 1
      },
      "indicator_count": 928,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "6 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "647c2f894012e970bee9875e",
      "name": "Raccoon Stealer (Legion) Malware",
      "description": "Recorded future: Raccoon Stealer (Legion) IOCs",
      "modified": "2023-07-04T06:03:55.157000",
      "created": "2023-06-04T06:30:33.164000",
      "tags": [
        "domain",
        "ip address",
        "hash",
        "hashsha256",
        "hashmd5",
        "redacted"
      ],
      "references": [
        "Raccoon Stealer (Legion).csv"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Trojan:Win32/Raccoonstealer",
          "display_name": "Trojan:Win32/Raccoonstealer",
          "target": "/malware/Trojan:Win32/Raccoonstealer"
        },
        {
          "id": "777(Legion)",
          "display_name": "777(Legion)",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "akhanafeer",
        "id": "195327",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 40,
        "FileHash-MD5": 44,
        "FileHash-SHA1": 43,
        "FileHash-SHA256": 58,
        "domain": 78,
        "hostname": 23
      },
      "indicator_count": 286,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 72,
      "modified_text": "1062 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63b2e34caf4d7502e8d1abb2",
      "name": "\u201cMasquerAds\u201d \u2014 Google\u2019s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets",
      "description": "A newly uncovered technique to abuse Google\u2019s ad-words has revealed how threat actors are using the platform to spread malware through its search engine, Google Ads, and other ad sites..",
      "modified": "2023-02-01T13:04:04.062000",
      "created": "2023-01-02T13:59:40.798000",
      "tags": [
        "targeted",
        "obs studio",
        "viewer",
        "brave browser",
        "libreoffice",
        "axelar",
        "samourai wallet",
        "aptos wallet",
        "first horizon",
        "bank",
        "github",
        "sign",
        "secret",
        "embed",
        "learn",
        "strong",
        "unicode",
        "skip",
        "github sign",
        "instantly share",
        "star",
        "copy",
        "discord",
        "footer",
        "e&s",
        "vidar",
        "grammarly",
        "msi afterburner",
        "google ads",
        "google",
        "vermux",
        "gpus",
        "afterburner",
        "slack",
        "russia",
        "easy",
        "virustotal",
        "concept"
      ],
      "references": [
        "https://labs.guard.io/masquerads-googles-ad-words-massively-abused-by-threat-actors-targeting-organizations-gpus-42ae73ee8a1e",
        "https://gist.github.com/guardiolabs/2178c54367d20b0655b5cc5e9d297760"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Russian Federation"
      ],
      "malware_families": [
        {
          "id": "Google Ads",
          "display_name": "Google Ads",
          "target": null
        },
        {
          "id": "MSI Afterburner",
          "display_name": "MSI Afterburner",
          "target": null
        },
        {
          "id": "Grammarly",
          "display_name": "Grammarly",
          "target": null
        },
        {
          "id": "Vidar",
          "display_name": "Vidar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 48,
        "FileHash-MD5": 3,
        "FileHash-SHA256": 7,
        "domain": 174,
        "FileHash-SHA1": 1,
        "hostname": 31
      },
      "indicator_count": 264,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "1214 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63ae2a52745f31286f01dcde",
      "name": "\u201cMasquerAds\u201d \u2014 Google\u2019s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets",
      "description": "",
      "modified": "2023-01-29T00:00:01.036000",
      "created": "2022-12-30T00:01:22.993000",
      "tags": [
        "OSINT",
        "Phishing",
        "SEO Poisoning",
        "Google Ads",
        "TypoSquatting",
        "T1036",
        "T1608.006",
        "T1566"
      ],
      "references": [
        "https://community.riskiq.com/article/bde7076e"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 39,
        "domain": 167,
        "hostname": 28
      },
      "indicator_count": 234,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1621,
      "modified_text": "1218 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63ad751c3a357e39e9e5cc8d",
      "name": "Google Ads Malvertising Campaign Targets Users Searching for Popular Software",
      "description": "",
      "modified": "2023-01-28T11:01:09.937000",
      "created": "2022-12-29T11:08:12.176000",
      "tags": [
        "github",
        "sign",
        "secret",
        "embed",
        "learn",
        "strong",
        "unicode",
        "skip",
        "github sign",
        "instantly share",
        "star",
        "copy",
        "discord",
        "footer"
      ],
      "references": [
        "https://gist.github.com/guardiolabs/2178c54367d20b0655b5cc5e9d297760"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "cryptocti",
        "id": "110256",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 6,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 7,
        "domain": 65,
        "hostname": 26
      },
      "indicator_count": 106,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 500,
      "modified_text": "1218 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63ad7aeeba5af237234ce040",
      "name": "Google\u2019s Ad-Words Massively Abused by Threat Actors, Targeting Organizations, GPUs and Crypto Wallets",
      "description": "A newly uncovered technique to abuse Google's ad-words by masquerade and redirect ad-clickers to malicious phishing pages.\n\nAccording to Guardio Labs, threat actors have been observed creating a network of benign sites that are promoted on the search engine, which when clicked, redirect the visitors to a phishing page containing a trojanized ZIP archive hosted on Dropbox or OneDrive. Among the impersonated software include AnyDesk, Dashlane, Grammarly, Malwarebytes, Microsoft Visual Studio, MSI Afterburner, Slack, and Zoom, among others.\n\nUsers are advised to strengthen their understanding of security knowledge and further enhance their ability to identify phishing attacks in order to avoid falling victim to such attacks.",
      "modified": "2023-01-28T11:01:09.937000",
      "created": "2022-12-29T11:33:01.913000",
      "tags": [
        "Crypto Wallet",
        "Phishing",
        "Organization",
        "GPUs",
        "Google-Ads"
      ],
      "references": [
        "https://gist.github.com/guardiolabs/2178c54367d20b0655b5cc5e9d297760",
        "https://labs.guard.io/masquerads-googles-ad-words-massively-abused-by-threat-actors-targeting-organizations-gpus-42ae73ee8a1e"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Russian Federation",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Racoon Stealer",
          "display_name": "Racoon Stealer",
          "target": null
        },
        {
          "id": "Vidar",
          "display_name": "Vidar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1134",
          "name": "Access Token Manipulation",
          "display_name": "T1134 - Access Token Manipulation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        }
      ],
      "industries": [
        "Crypto",
        "Finance",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Superpro",
        "id": "61676",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 6,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1,
        "FileHash-SHA256": 7,
        "domain": 65,
        "hostname": 26
      },
      "indicator_count": 106,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 213,
      "modified_text": "1218 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "ever-note.net",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "ever-note.net",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780223339.5567732
}