{
  "type": "Domain",
  "indicator": "f8beta-2.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/f8beta-2.com",
    "alexa": "http://www.alexa.com/siteinfo/f8beta-2.com",
    "indicator": "f8beta-2.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4158838719,
      "indicator": "f8beta-2.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 21,
      "pulses": [
        {
          "id": "691b8869e00b107fa20d9482",
          "name": "ThreatFix",
          "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
          "modified": "2026-01-23T11:01:07.175000",
          "created": "2025-11-17T20:41:11.797000",
          "tags": [
            "",
            "ransomware",
            "malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "",
              "display_name": "",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "zlepos384",
            "id": "103244",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8010,
            "FileHash-SHA1": 7922,
            "FileHash-SHA256": 8893,
            "URL": 57004,
            "domain": 36018,
            "hostname": 96473
          },
          "indicator_count": 214320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "130 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6938d6e976fd2ec5441e5e78",
          "name": "URLHaus data - 09-12-2025 (Part 1)",
          "description": "",
          "modified": "2026-01-09T02:04:37.512000",
          "created": "2025-12-10T02:11:53.461000",
          "tags": [
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "ClearFake",
            "c2-monitor-auto",
            "dropped-by-amadey",
            "arm",
            "mirai",
            "AsyncRAT",
            "GoProxy",
            "fbf543",
            "Stealc",
            "xenorat",
            "1",
            "c2",
            "dropped-by-GCleaner",
            "apk",
            "ResolverRAT",
            "a310Logger",
            "dropped-by-Stealc",
            "jopa",
            "Vidar",
            "ascii",
            "Encoded",
            "PureLogsStealer",
            "PhantomStealer",
            "rev-base64-loader",
            "xworm",
            "AgentTesla",
            "encrypted",
            "GuLoader",
            "ClickFix",
            "quasar",
            "QuasarRAT",
            "trojan",
            "opendir",
            "sh",
            "WsgiDAV",
            "Koadic",
            "Formbook",
            "lnk",
            "botnetdomain",
            "powershell",
            "ps1",
            "MassLogger",
            "censys",
            "CobaltStrike",
            "backdoor",
            "sshdkit",
            "hajime",
            "ua-wget",
            "MaskGramStealer",
            "Sliver",
            "GoToResolve",
            "AdaptixC2",
            "geofenced",
            "USA",
            "donutloader",
            "mp3",
            "CoinMiner",
            "rat",
            "RemcosRAT",
            "gafgyt",
            "SuperH",
            "m68k",
            "x86",
            "PowerPC",
            "sparc"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 36,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 262,
            "hostname": 22,
            "domain": 11
          },
          "indicator_count": 295,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1626,
          "modified_text": "145 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69389d16f125c55734ffb6d4",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 158 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-08T22:03:46.665000",
          "created": "2025-12-09T22:05:10.053000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 114,
            "FileHash-SHA256": 4,
            "FileHash-MD5": 4,
            "hostname": 10
          },
          "indicator_count": 132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "145 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693872e458b5f630a2c8db64",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 155 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-08T19:00:37.613000",
          "created": "2025-12-09T19:05:08.457000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 114,
            "FileHash-SHA256": 4,
            "FileHash-MD5": 4,
            "hostname": 10
          },
          "indicator_count": 132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "145 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693864d56eb269dac3e817e8",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 152 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-08T18:01:22.264000",
          "created": "2025-12-09T18:05:09.344000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 113,
            "FileHash-SHA256": 4,
            "FileHash-MD5": 4,
            "hostname": 9
          },
          "indicator_count": 130,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "145 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693848b68c1ccb91c39d073d",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 151 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-08T16:02:39.992000",
          "created": "2025-12-09T16:05:10.721000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 113,
            "FileHash-SHA256": 4,
            "FileHash-MD5": 4,
            "hostname": 9
          },
          "indicator_count": 130,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "145 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693791e6d8503d012a88c0c4",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 82 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-08T03:03:15.187000",
          "created": "2025-12-09T03:05:10.961000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 43,
            "domain": 11,
            "FileHash-SHA256": 4,
            "FileHash-MD5": 4
          },
          "indicator_count": 62,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "145 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693783d50d5ca47d93cfbca6",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 76 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-08T02:04:09.685000",
          "created": "2025-12-09T02:05:09.660000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 43,
            "domain": 11,
            "FileHash-SHA256": 2,
            "FileHash-MD5": 2
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6937802c767e45cf529cc27f",
          "name": "URLHaus data - 08-12-2025 (Part 2)",
          "description": "",
          "modified": "2026-01-08T01:02:20.370000",
          "created": "2025-12-09T01:49:31.997000",
          "tags": [
            "ClearFake",
            "32-bit",
            "elf",
            "mips",
            "Mozi",
            "c2-monitor-auto",
            "dropped-by-amadey",
            "CoinMiner",
            "arm",
            "mirai",
            "geofenced",
            "SuperH",
            "ua-wget",
            "USA",
            "x86",
            "sparc",
            "arc",
            "m68k",
            "PowerPC",
            "sh",
            "zip",
            "Fake Job Platform",
            "a3dacb",
            "Fuery",
            "Vidar",
            "ascii",
            "Encoded",
            "PhantomStealer",
            "rat",
            "RemcosRAT",
            "DarkCloud",
            "encrypted",
            "GuLoader",
            "powershell",
            "ps1",
            "Formbook",
            "rev-base64-loader",
            "xworm",
            "AgentTesla",
            "NetSupport",
            "exe",
            "Stealc",
            "donutloader",
            "config",
            "json",
            "apk",
            "mamont",
            "AmateraStealer",
            "Unknown Stealer",
            "spymax",
            "AsyncRAT",
            "opendir",
            "Adware.Techsnab",
            "MaskGramStealer",
            "censys",
            "CobaltStrike",
            "hajime",
            "backdoor",
            "sshdkit",
            "cybergate",
            "banker",
            "PythonStealer",
            "stealer",
            "DarkTortilla",
            "trojan",
            "VanillaRatStub",
            "c2",
            "gafgyt",
            "x86-32",
            "perl",
            "netcat",
            "Amadey"
          ],
          "references": [
            "https://urlhaus.abuse.ch/browse/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 260,
            "domain": 6,
            "hostname": 4
          },
          "indicator_count": 270,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1625,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693759a7ddbb9f9c1559c27a",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-08",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 76 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-07T23:09:04.477000",
          "created": "2025-12-08T23:05:11.647000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 43,
            "domain": 11,
            "FileHash-SHA256": 2,
            "FileHash-MD5": 2
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69374b95d9056db64fa6e40d",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-08",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 76 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-07T22:05:19.067000",
          "created": "2025-12-08T22:05:09.249000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 43,
            "domain": 11,
            "FileHash-SHA256": 2,
            "FileHash-MD5": 2
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69373d8619cdec5a7e179d3b",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-08",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 74 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-07T21:08:17.630000",
          "created": "2025-12-08T21:05:10.322000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 43,
            "domain": 11,
            "FileHash-SHA256": 2,
            "FileHash-MD5": 2
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69372f75bc48c6a0cfefea7b",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-08",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 74 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-07T20:05:05.476000",
          "created": "2025-12-08T20:05:09.819000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 43,
            "domain": 11,
            "FileHash-SHA256": 2,
            "FileHash-MD5": 2
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69370544ece4dfb03258b83c",
          "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-08",
          "description": "Automated ThreatFox hunt for AsyncRAT indicators. 71 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-07T17:03:41.456000",
          "created": "2025-12-08T17:05:08.791000",
          "tags": [
            "asyncrat",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 43,
            "domain": 11,
            "FileHash-SHA256": 2,
            "FileHash-MD5": 2
          },
          "indicator_count": 58,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6936b46195009162774c555b",
          "name": "OSINT Volley 2025-12-08 - Unknown Stealer/Cobalt Strike/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Unknown Stealer(940), Cobalt Strike(156), Unknown malware(97), ZStealer(57), XWorm(35). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-07T11:01:28.839000",
          "created": "2025-12-08T11:20:01.582000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "unknown-stealer",
            "cobalt-strike",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 14,
            "hostname": 12,
            "URL": 61
          },
          "indicator_count": 87,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6936a651092d3c3dd81707d9",
          "name": "OSINT Volley 2025-12-08 - Unknown Stealer/Cobalt Strike/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Unknown Stealer(940), Cobalt Strike(145), Unknown malware(89), AsyncRAT(63), ZStealer(57). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-07T10:05:50.162000",
          "created": "2025-12-08T10:20:01.564000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "unknown-stealer",
            "cobalt-strike",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 11,
            "URL": 61,
            "domain": 12,
            "FileHash-SHA1": 3,
            "FileHash-SHA256": 2,
            "FileHash-MD5": 4
          },
          "indicator_count": 93,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "69368a32a47315fab9d1bd97",
          "name": "OSINT Volley 2025-12-08 - Unknown Stealer/Cobalt Strike/AsyncRAT",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Unknown Stealer(940), Cobalt Strike(145), AsyncRAT(63), ZStealer(57), Unknown malware(39). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-07T08:06:04.816000",
          "created": "2025-12-08T08:20:02.915000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "unknown-stealer",
            "cobalt-strike",
            "asyncrat"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 14,
            "domain": 3,
            "hostname": 7,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 26,
            "FileHash-MD5": 26
          },
          "indicator_count": 102,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "146 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693635d10384594f2e7325c0",
          "name": "OSINT Volley 2025-12-08 - Unknown Stealer/Cobalt Strike/AsyncRAT",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Unknown Stealer(940), Cobalt Strike(83), AsyncRAT(56), Unknown malware(37), XWorm(12). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-07T02:02:52.061000",
          "created": "2025-12-08T02:20:01.880000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "unknown-stealer",
            "cobalt-strike",
            "asyncrat"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 136,
            "URL": 8,
            "domain": 9
          },
          "indicator_count": 153,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "147 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693627c1a19b43f43b7630ea",
          "name": "OSINT Volley 2025-12-08 - Unknown Stealer/Cobalt Strike/AsyncRAT",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Unknown Stealer(940), Cobalt Strike(83), AsyncRAT(56), Unknown malware(35), XWorm(12). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-07T01:05:34.133000",
          "created": "2025-12-08T01:20:01.215000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "unknown-stealer",
            "cobalt-strike",
            "asyncrat"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8,
            "hostname": 136,
            "domain": 9
          },
          "indicator_count": 153,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "147 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "693619b2a8bd8a74fbdc1fad",
          "name": "OSINT Volley 2025-12-08 - Unknown Stealer/Cobalt Strike/AsyncRAT",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Unknown Stealer(940), Cobalt Strike(83), AsyncRAT(56), Unknown malware(32), XWorm(12). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-07T00:00:30.717000",
          "created": "2025-12-08T00:20:02.573000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "unknown-stealer",
            "cobalt-strike",
            "asyncrat"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 140,
            "domain": 9,
            "URL": 4
          },
          "indicator_count": 153,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "147 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6935fd9136a07a498ffe0fe3",
          "name": "OSINT Volley 2025-12-07 - Unknown Stealer/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Unknown Stealer(940), Unknown malware(63), Cobalt Strike(57), AsyncRAT(56), XWorm(12). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-06T22:00:29.488000",
          "created": "2025-12-07T22:20:01.446000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "unknown-stealer",
            "unknown-malware",
            "cobalt-strike"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 8,
            "hostname": 191
          },
          "indicator_count": 199,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "147 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            ""
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 21,
  "pulses": [
    {
      "id": "691b8869e00b107fa20d9482",
      "name": "ThreatFix",
      "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
      "modified": "2026-01-23T11:01:07.175000",
      "created": "2025-11-17T20:41:11.797000",
      "tags": [
        "",
        "ransomware",
        "malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "",
          "display_name": "",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "zlepos384",
        "id": "103244",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8010,
        "FileHash-SHA1": 7922,
        "FileHash-SHA256": 8893,
        "URL": 57004,
        "domain": 36018,
        "hostname": 96473
      },
      "indicator_count": 214320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "130 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6938d6e976fd2ec5441e5e78",
      "name": "URLHaus data - 09-12-2025 (Part 1)",
      "description": "",
      "modified": "2026-01-09T02:04:37.512000",
      "created": "2025-12-10T02:11:53.461000",
      "tags": [
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "ClearFake",
        "c2-monitor-auto",
        "dropped-by-amadey",
        "arm",
        "mirai",
        "AsyncRAT",
        "GoProxy",
        "fbf543",
        "Stealc",
        "xenorat",
        "1",
        "c2",
        "dropped-by-GCleaner",
        "apk",
        "ResolverRAT",
        "a310Logger",
        "dropped-by-Stealc",
        "jopa",
        "Vidar",
        "ascii",
        "Encoded",
        "PureLogsStealer",
        "PhantomStealer",
        "rev-base64-loader",
        "xworm",
        "AgentTesla",
        "encrypted",
        "GuLoader",
        "ClickFix",
        "quasar",
        "QuasarRAT",
        "trojan",
        "opendir",
        "sh",
        "WsgiDAV",
        "Koadic",
        "Formbook",
        "lnk",
        "botnetdomain",
        "powershell",
        "ps1",
        "MassLogger",
        "censys",
        "CobaltStrike",
        "backdoor",
        "sshdkit",
        "hajime",
        "ua-wget",
        "MaskGramStealer",
        "Sliver",
        "GoToResolve",
        "AdaptixC2",
        "geofenced",
        "USA",
        "donutloader",
        "mp3",
        "CoinMiner",
        "rat",
        "RemcosRAT",
        "gafgyt",
        "SuperH",
        "m68k",
        "x86",
        "PowerPC",
        "sparc"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 36,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 262,
        "hostname": 22,
        "domain": 11
      },
      "indicator_count": 295,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1626,
      "modified_text": "145 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "69389d16f125c55734ffb6d4",
      "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
      "description": "Automated ThreatFox hunt for AsyncRAT indicators. 158 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-08T22:03:46.665000",
      "created": "2025-12-09T22:05:10.053000",
      "tags": [
        "asyncrat",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 114,
        "FileHash-SHA256": 4,
        "FileHash-MD5": 4,
        "hostname": 10
      },
      "indicator_count": 132,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "145 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693872e458b5f630a2c8db64",
      "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
      "description": "Automated ThreatFox hunt for AsyncRAT indicators. 155 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-08T19:00:37.613000",
      "created": "2025-12-09T19:05:08.457000",
      "tags": [
        "asyncrat",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 114,
        "FileHash-SHA256": 4,
        "FileHash-MD5": 4,
        "hostname": 10
      },
      "indicator_count": 132,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "145 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693864d56eb269dac3e817e8",
      "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
      "description": "Automated ThreatFox hunt for AsyncRAT indicators. 152 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-08T18:01:22.264000",
      "created": "2025-12-09T18:05:09.344000",
      "tags": [
        "asyncrat",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 113,
        "FileHash-SHA256": 4,
        "FileHash-MD5": 4,
        "hostname": 9
      },
      "indicator_count": 130,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "145 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693848b68c1ccb91c39d073d",
      "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
      "description": "Automated ThreatFox hunt for AsyncRAT indicators. 151 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-08T16:02:39.992000",
      "created": "2025-12-09T16:05:10.721000",
      "tags": [
        "asyncrat",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 113,
        "FileHash-SHA256": 4,
        "FileHash-MD5": 4,
        "hostname": 9
      },
      "indicator_count": 130,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "145 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693791e6d8503d012a88c0c4",
      "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
      "description": "Automated ThreatFox hunt for AsyncRAT indicators. 82 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-08T03:03:15.187000",
      "created": "2025-12-09T03:05:10.961000",
      "tags": [
        "asyncrat",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 43,
        "domain": 11,
        "FileHash-SHA256": 4,
        "FileHash-MD5": 4
      },
      "indicator_count": 62,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "145 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693783d50d5ca47d93cfbca6",
      "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-09",
      "description": "Automated ThreatFox hunt for AsyncRAT indicators. 76 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-08T02:04:09.685000",
      "created": "2025-12-09T02:05:09.660000",
      "tags": [
        "asyncrat",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 43,
        "domain": 11,
        "FileHash-SHA256": 2,
        "FileHash-MD5": 2
      },
      "indicator_count": 58,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "146 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6937802c767e45cf529cc27f",
      "name": "URLHaus data - 08-12-2025 (Part 2)",
      "description": "",
      "modified": "2026-01-08T01:02:20.370000",
      "created": "2025-12-09T01:49:31.997000",
      "tags": [
        "ClearFake",
        "32-bit",
        "elf",
        "mips",
        "Mozi",
        "c2-monitor-auto",
        "dropped-by-amadey",
        "CoinMiner",
        "arm",
        "mirai",
        "geofenced",
        "SuperH",
        "ua-wget",
        "USA",
        "x86",
        "sparc",
        "arc",
        "m68k",
        "PowerPC",
        "sh",
        "zip",
        "Fake Job Platform",
        "a3dacb",
        "Fuery",
        "Vidar",
        "ascii",
        "Encoded",
        "PhantomStealer",
        "rat",
        "RemcosRAT",
        "DarkCloud",
        "encrypted",
        "GuLoader",
        "powershell",
        "ps1",
        "Formbook",
        "rev-base64-loader",
        "xworm",
        "AgentTesla",
        "NetSupport",
        "exe",
        "Stealc",
        "donutloader",
        "config",
        "json",
        "apk",
        "mamont",
        "AmateraStealer",
        "Unknown Stealer",
        "spymax",
        "AsyncRAT",
        "opendir",
        "Adware.Techsnab",
        "MaskGramStealer",
        "censys",
        "CobaltStrike",
        "hajime",
        "backdoor",
        "sshdkit",
        "cybergate",
        "banker",
        "PythonStealer",
        "stealer",
        "DarkTortilla",
        "trojan",
        "VanillaRatStub",
        "c2",
        "gafgyt",
        "x86-32",
        "perl",
        "netcat",
        "Amadey"
      ],
      "references": [
        "https://urlhaus.abuse.ch/browse/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 260,
        "domain": 6,
        "hostname": 4
      },
      "indicator_count": 270,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1625,
      "modified_text": "146 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "693759a7ddbb9f9c1559c27a",
      "name": "ThreatFox Hunt: AsyncRAT IOCs - 2025-12-08",
      "description": "Automated ThreatFox hunt for AsyncRAT indicators. 76 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-07T23:09:04.477000",
      "created": "2025-12-08T23:05:11.647000",
      "tags": [
        "asyncrat",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 43,
        "domain": 11,
        "FileHash-SHA256": 2,
        "FileHash-MD5": 2
      },
      "indicator_count": 58,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "146 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "f8beta-2.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "f8beta-2.com",
    "found": true,
    "verdict": "malicious",
    "url_count": 2,
    "online_count": 0,
    "blacklists": {
      "spamhaus_dbl": "botnet_cc_domain",
      "surbl": "not listed"
    },
    "urls": [
      {
        "url": "https://f8beta-2.com/Windows10Upgrade.exe",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2025-12-09",
        "tags": [
          "quasar",
          "QuasarRAT",
          "trojan"
        ]
      },
      {
        "url": "https://f8beta-2.com/system32.com.exe",
        "status": "offline",
        "threat": "malware_download",
        "date_added": "2025-12-08",
        "tags": [
          "rat",
          "trojan",
          "VanillaRatStub"
        ]
      }
    ],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780452432.5829322
}