{
  "type": "Domain",
  "indicator": "fancyapps.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/fancyapps.com",
    "alexa": "http://www.alexa.com/siteinfo/fancyapps.com",
    "indicator": "fancyapps.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [
      {
        "source": "majestic",
        "message": "Whitelisted domain fancyapps.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3155077003,
      "indicator": "fancyapps.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 10,
      "pulses": [
        {
          "id": "69eb254f17eb4a2a990f07e5",
          "name": "LevelBlue - Open Threat Exchange",
          "description": "[ As part of security research, we look at some of the most well-known vulnerabilities in the PDF ecosystem, and how they can be identified and mitigated, with the help of a simple hash.] [64xxxx]",
          "modified": "2026-05-28T07:10:11.800000",
          "created": "2026-04-24T08:09:51.488000",
          "tags": [
            "pdfkit",
            "cve202225765",
            "exploit script",
            "github",
            "unicordev",
            "cves",
            "xml external",
            "entity",
            "pdfs",
            "knowledge base",
            "python",
            "mozilla",
            "virustotal",
            "cisa",
            "apple",
            "microsoft",
            "pdfkit ruby",
            "remote code",
            "execution",
            "urls",
            "malware",
            "raid",
            "caddywiper",
            "wipes",
            "cve202543529",
            "webkit",
            "february",
            "cve202620643",
            "bypass",
            "march",
            "webkit bug",
            "command",
            "control",
            "levelblue",
            "open threat"
          ],
          "references": [
            "https://otx.alienvault.com/indicator/ip/198.49.23.145#:~:text=CIDR:%206%20%7C%20CVE:%20107,infrastructure%20into%20global%20botnet%20clusters."
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Wipes",
              "display_name": "Wipes",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1084,
            "FileHash-SHA1": 874,
            "FileHash-SHA256": 3052,
            "CVE": 36,
            "domain": 437,
            "hostname": 1086,
            "URL": 1411,
            "CIDR": 15,
            "email": 13
          },
          "indicator_count": 8008,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "4 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "654e46078568d62bc323e093",
          "name": "Imaging Center affected by WebToolbar \u2022 Critical C2 and Mitre Att",
          "description": "Critical - dpqhhab.exe\n216d5b6361d88c59cd0fb66c0ca94a27f6c1e0d592fc325b6d58929d4d5a1e76",
          "modified": "2023-12-10T13:00:37.604000",
          "created": "2023-11-10T15:02:31.518000",
          "tags": [
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "heur",
            "alexa top",
            "safe site",
            "million",
            "malware",
            "malware site",
            "phishing site",
            "malicious site",
            "crack",
            "wacatac",
            "unsafe",
            "phishing",
            "xrat",
            "xtrat",
            "nircmd",
            "swrort",
            "iframe",
            "downldr",
            "installcore",
            "agent",
            "unruy",
            "filetour",
            "cleaner",
            "patcher",
            "adload",
            "win64",
            "artemis",
            "riskware",
            "genkryptik",
            "fuery",
            "alexa",
            "blacklist https",
            "united",
            "ip address",
            "presenoker",
            "opencandy",
            "exploit",
            "quasar rat",
            "mimikatz",
            "malicious",
            "applicunwnt",
            "acint",
            "systweak",
            "behav",
            "tiggre",
            "conduit",
            "trojanspy",
            "webtoolbar",
            "gc",
            "xfbml1",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "script",
            "appdata",
            "mitre att",
            "date",
            "unknown",
            "error",
            "hybrid",
            "general",
            "local",
            "click",
            "facebook",
            "strings",
            "class",
            "generator",
            "critical",
            "ssl certificate",
            "whois record",
            "threat roundup",
            "october",
            "contacted",
            "january",
            "resolutions",
            "whois whois",
            "june",
            "communicating",
            "february"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 41,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 221,
            "FileHash-SHA1": 171,
            "FileHash-SHA256": 2904,
            "domain": 4834,
            "hostname": 1631,
            "CVE": 9,
            "URL": 5670
          },
          "indicator_count": 15440,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "904 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "654e46130211d24d7f9ef311",
          "name": "Imaging Center affected by WebToolbar \u2022 Critical C2 and Mitre Att",
          "description": "Critical - dpqhhab.exe\n216d5b6361d88c59cd0fb66c0ca94a27f6c1e0d592fc325b6d58929d4d5a1e76",
          "modified": "2023-12-10T13:00:37.604000",
          "created": "2023-11-10T15:02:43.841000",
          "tags": [
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "heur",
            "alexa top",
            "safe site",
            "million",
            "malware",
            "malware site",
            "phishing site",
            "malicious site",
            "crack",
            "wacatac",
            "unsafe",
            "phishing",
            "xrat",
            "xtrat",
            "nircmd",
            "swrort",
            "iframe",
            "downldr",
            "installcore",
            "agent",
            "unruy",
            "filetour",
            "cleaner",
            "patcher",
            "adload",
            "win64",
            "artemis",
            "riskware",
            "genkryptik",
            "fuery",
            "alexa",
            "blacklist https",
            "united",
            "ip address",
            "presenoker",
            "opencandy",
            "exploit",
            "quasar rat",
            "mimikatz",
            "malicious",
            "applicunwnt",
            "acint",
            "systweak",
            "behav",
            "tiggre",
            "conduit",
            "trojanspy",
            "webtoolbar",
            "gc",
            "xfbml1",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "script",
            "appdata",
            "mitre att",
            "date",
            "unknown",
            "error",
            "hybrid",
            "general",
            "local",
            "click",
            "facebook",
            "strings",
            "class",
            "generator",
            "critical",
            "ssl certificate",
            "whois record",
            "threat roundup",
            "october",
            "contacted",
            "january",
            "resolutions",
            "whois whois",
            "june",
            "communicating",
            "february"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 41,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 221,
            "FileHash-SHA1": 171,
            "FileHash-SHA256": 2904,
            "domain": 4834,
            "hostname": 1631,
            "CVE": 9,
            "URL": 5670
          },
          "indicator_count": 15440,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "904 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "654e469fbf2e1c732bbeb7a3",
          "name": "Imaging Center affected by WebToolbar \u2022 Critical C2 and Mitre Att",
          "description": "Critical - dpqhhab.exe\n216d5b6361d88c59cd0fb66c0ca94a27f6c1e0d592fc325b6d58929d4d5a1e76\n\nAllows bad actor to alter diagnosis without physician override or documentation of.",
          "modified": "2023-12-10T13:00:37.604000",
          "created": "2023-11-10T15:05:03.947000",
          "tags": [
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "heur",
            "alexa top",
            "safe site",
            "million",
            "malware",
            "malware site",
            "phishing site",
            "malicious site",
            "crack",
            "wacatac",
            "unsafe",
            "phishing",
            "xrat",
            "xtrat",
            "nircmd",
            "swrort",
            "iframe",
            "downldr",
            "installcore",
            "agent",
            "unruy",
            "filetour",
            "cleaner",
            "patcher",
            "adload",
            "win64",
            "artemis",
            "riskware",
            "genkryptik",
            "fuery",
            "alexa",
            "blacklist https",
            "united",
            "ip address",
            "presenoker",
            "opencandy",
            "exploit",
            "quasar rat",
            "mimikatz",
            "malicious",
            "applicunwnt",
            "acint",
            "systweak",
            "behav",
            "tiggre",
            "conduit",
            "trojanspy",
            "webtoolbar",
            "gc",
            "xfbml1",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "script",
            "appdata",
            "mitre att",
            "date",
            "unknown",
            "error",
            "hybrid",
            "general",
            "local",
            "click",
            "facebook",
            "strings",
            "class",
            "generator",
            "critical",
            "ssl certificate",
            "whois record",
            "threat roundup",
            "october",
            "contacted",
            "january",
            "resolutions",
            "whois whois",
            "june",
            "communicating",
            "february"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 40,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 221,
            "FileHash-SHA1": 171,
            "FileHash-SHA256": 2904,
            "domain": 4834,
            "hostname": 1631,
            "CVE": 9,
            "URL": 5670
          },
          "indicator_count": 15440,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "904 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a8bf416a1c314819ea53",
          "name": "Remote Access Related |  APK attack targets independent artists",
          "description": "",
          "modified": "2023-12-06T17:00:47.888000",
          "created": "2023-12-06T17:00:47.888000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 5,
            "FileHash-SHA256": 2385,
            "hostname": 1054,
            "domain": 713,
            "URL": 3595,
            "FileHash-MD5": 1104,
            "FileHash-SHA1": 585,
            "FilePath": 1
          },
          "indicator_count": 9442,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6528fa2179cc1554d7f434c6",
          "name": "Remote Access Related |  APK attack targets independent artists",
          "description": "Suppression, malware,\nPassword,Exploit/Shellcode *Defacement *Unsafe.AI_Score_ * FileRepMetagen [PUP]\nrevenge-rat,stealer,, Steganos Software GmbH Privacy Suite, Ransom_WannaCrypt.R002C0DJO20,\nWacatac.B, Trojan.HideLink, SuppoBox,Trojan.Downloader.Generic, TrojWare.JS.Obfuscated, Phish.HHH, Phishing_Netflix.EVT, Phishing.Microsoft,Trojan.AvsHepter, HTML:PhishingBank, Phishing.fz, Probably, Heur.HTMLUnescapeF, BehavesLike.HTML.SMSSendPhishing.S23, Gen:Variant.Zbot, BehavesLike.HTML.Faceliker",
          "modified": "2023-11-12T07:01:14.580000",
          "created": "2023-10-13T08:04:49.722000",
          "tags": [
            "alexa top",
            "blacklist",
            "phishing",
            "million",
            "site",
            "cisco umbrella",
            "path",
            "maxage31536000",
            "expiressat",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "pragma",
            "html info",
            "title kedence",
            "official apk",
            "meta tags",
            "apk download",
            "android",
            "google tag",
            "utc google",
            "utc na",
            "whois record",
            "contacted",
            "ssl certificate",
            "communicating",
            "referrer",
            "historical ssl",
            "bundled",
            "resolutions",
            "contacted urls",
            "hackers install",
            "malware",
            "fakedout threat",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "united",
            "phishing site",
            "malware site",
            "malicious site",
            "heur",
            "anonymizer",
            "malicious host",
            "crack",
            "maltiverse",
            "driverpack",
            "ransomware",
            "opencandy",
            "artemis",
            "riskware",
            "installcore",
            "suppobox",
            "bank",
            "agent",
            "patcher",
            "generic",
            "t",
            "safe site",
            "iframe",
            "downldr",
            "presenoker",
            "exploit",
            "genkryptik",
            "dropper",
            "fakealert",
            "quasar rat",
            "xtrat",
            "softcnapp",
            "cleaner",
            "xrat",
            "applicunwnt",
            "mimikatz",
            "team",
            "azorult",
            "service",
            "runescape",
            "facebook",
            "download",
            "logo analysis",
            "size81b type",
            "mime",
            "scan10132023",
            "results",
            "multi scan",
            "analysis",
            "update",
            "view details",
            "na visit",
            "sansx22",
            "3px 3px",
            "indicator",
            "file",
            "general",
            "email address",
            "pattern match",
            "ck id",
            "t1114",
            "show technique",
            "mitre att",
            "ck matrix",
            "script",
            "antivirus",
            "svg scalable",
            "vector graphics",
            "span",
            "twitter",
            "hybrid",
            "ascii text",
            "appdata",
            "windows nt",
            "png image",
            "jpeg image",
            "jfif",
            "date",
            "flag",
            "markmonitor",
            "name server",
            "server",
            "enom",
            "whois privacy",
            "cloudflare",
            "domain address",
            "show",
            "osint",
            "f8f9fa",
            "eeeeee",
            "click",
            "unknown",
            "open",
            "error",
            "body",
            "hosts",
            "strings",
            "class",
            "critical",
            "meta",
            "scroll",
            "atom"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "T",
              "display_name": "T",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 31,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 713,
            "FileHash-MD5": 1104,
            "FileHash-SHA1": 585,
            "FileHash-SHA256": 2385,
            "hostname": 1054,
            "URL": 3596,
            "CVE": 5,
            "FilePath": 1
          },
          "indicator_count": 9443,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "932 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1d23d050527b7aa07cfd",
          "name": "Remote Access Related | APK attack targets independent artists",
          "description": "",
          "modified": "2023-11-12T07:01:14.580000",
          "created": "2023-10-30T03:04:03.323000",
          "tags": [
            "alexa top",
            "blacklist",
            "phishing",
            "million",
            "site",
            "cisco umbrella",
            "path",
            "maxage31536000",
            "expiressat",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "pragma",
            "html info",
            "title kedence",
            "official apk",
            "meta tags",
            "apk download",
            "android",
            "google tag",
            "utc google",
            "utc na",
            "whois record",
            "contacted",
            "ssl certificate",
            "communicating",
            "referrer",
            "historical ssl",
            "bundled",
            "resolutions",
            "contacted urls",
            "hackers install",
            "malware",
            "fakedout threat",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "united",
            "phishing site",
            "malware site",
            "malicious site",
            "heur",
            "anonymizer",
            "malicious host",
            "crack",
            "maltiverse",
            "driverpack",
            "ransomware",
            "opencandy",
            "artemis",
            "riskware",
            "installcore",
            "suppobox",
            "bank",
            "agent",
            "patcher",
            "generic",
            "t",
            "safe site",
            "iframe",
            "downldr",
            "presenoker",
            "exploit",
            "genkryptik",
            "dropper",
            "fakealert",
            "quasar rat",
            "xtrat",
            "softcnapp",
            "cleaner",
            "xrat",
            "applicunwnt",
            "mimikatz",
            "team",
            "azorult",
            "service",
            "runescape",
            "facebook",
            "download",
            "logo analysis",
            "size81b type",
            "mime",
            "scan10132023",
            "results",
            "multi scan",
            "analysis",
            "update",
            "view details",
            "na visit",
            "sansx22",
            "3px 3px",
            "indicator",
            "file",
            "general",
            "email address",
            "pattern match",
            "ck id",
            "t1114",
            "show technique",
            "mitre att",
            "ck matrix",
            "script",
            "antivirus",
            "svg scalable",
            "vector graphics",
            "span",
            "twitter",
            "hybrid",
            "ascii text",
            "appdata",
            "windows nt",
            "png image",
            "jpeg image",
            "jfif",
            "date",
            "flag",
            "markmonitor",
            "name server",
            "server",
            "enom",
            "whois privacy",
            "cloudflare",
            "domain address",
            "show",
            "osint",
            "f8f9fa",
            "eeeeee",
            "click",
            "unknown",
            "open",
            "error",
            "body",
            "hosts",
            "strings",
            "class",
            "critical",
            "meta",
            "scroll",
            "atom"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "T",
              "display_name": "T",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6528fa2179cc1554d7f434c6",
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 713,
            "FileHash-MD5": 1104,
            "FileHash-SHA1": 585,
            "FileHash-SHA256": 2385,
            "hostname": 1054,
            "URL": 3596,
            "CVE": 5,
            "FilePath": 1
          },
          "indicator_count": 9443,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "932 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "627a3399312417bb7f844a55",
          "name": "hoster.kz",
          "description": "WebPacker.ru is a web-based tool designed to help people find and find the best way to get through the web, but only if you are a browser user or an administrator.",
          "modified": "2022-06-09T00:00:13.607000",
          "created": "2022-05-10T09:42:49.434000",
          "tags": [
            "regexp",
            "null",
            "shift",
            "function",
            "click",
            "bksp",
            "width",
            "body",
            "namedepartment",
            "altgr",
            "span",
            "date",
            "error",
            "class",
            "this",
            "refresh",
            "prop",
            "close",
            "accept",
            "jquery",
            "iframe",
            "embed",
            "inputmask",
            "void",
            "chrs",
            "alternation",
            "seeknext",
            "type",
            "input",
            "masktoken",
            "window",
            "mask",
            "form",
            "backspace",
            "insert",
            "qe",
            "copyright",
            "closure library",
            "trackevent",
            "number",
            "string",
            "version",
            "uint8array",
            "gtmn3zrpw",
            "host",
            "path",
            "derek",
            "code",
            "bapunycode",
            "s700",
            "index",
            "label",
            "link",
            "stylesheet",
            "textcss",
            "script",
            "array",
            "10000",
            "style",
            "xmlhttprequest",
            "load",
            "virtualpageview",
            "ymuid",
            "post"
          ],
          "references": [
            "xfe-IP-185.100.65.26-stix2-2.1-export.json",
            "xfe-URL-Hoster.kz-stix2-2.1-export.json",
            "https://almapbx.hoster.kz/hoster_v2/widget/lead_hunter/?code=75455&protocol=https://&url=https://hoster.kz/",
            "https://bitrix.info/ba.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-N3ZRPW",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1055680023/?random=1652174969236&cv=9&fst=1652174969236&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635470&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=2&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg590&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fhoster.kz%2F&ref=https%3A%2F%2Fhoster.kz%2F&tiba=%D0%A5%D0%BE%D1%81%D1%82%D0%B8%D0%BD%D0%B3%20%D0%B2%20%D0%9A%D0%B0%D0%B7%D0%B0%D1%85%D1%81%D1%82%D0%B0%D0%BD%D0%B5%2C%20%D0%BA%D1%83%D0%BF%D0",
            "https://almapbx.hoster.kz/hoster_v2/widget/lead_hunter/js/jquery.inputmask.bundle.js",
            "https://hoster.kz/js/html5.js",
            "https://hoster.kz/js/jcarousellite_1.0.1.pack.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qe",
              "display_name": "Qe",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3010,
            "hostname": 1225,
            "domain": 1427,
            "FileHash-SHA256": 136,
            "CVE": 1,
            "email": 2
          },
          "indicator_count": 5801,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1453 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6266c416c4598fa139868c64",
          "name": "\u05de\u05e9\u05e8\u05d3 \u05e4\u05e8\u05e1\u05d5\u05dd \u05d5\u05d1\u05e0\u05d9\u05d9\u05ea \u05d0\u05ea\u05e8\u05d9\u05dd | TOPWEB - \u05d8\u05d5\u05e4 \u05d5\u05d5\u05d1- \u05d4\u05d5\u05e4\u05db\u05d9\u05dd \u05e2\u05e1\u05e7\u05d9\u05dd \u05dc\u05de\u05d5\u05ea\u05d2\u05d9\u05dd \u05d1\u05d3\u05d9\u05d2\u05d9\u05d8\u05dc",
          "description": "New RegExp(M) is a new type, and it will change any of the elements to the same type if you want to add them to your HTML page or add a third element.",
          "modified": "2022-05-25T00:04:03.622000",
          "created": "2022-04-25T15:53:58.206000",
          "tags": [
            "init",
            "803911410135716",
            "pageview",
            "date",
            "datalayer",
            "gtmnqnvc6k",
            "copyright",
            "closure library",
            "facebook",
            "google",
            "linkedin",
            "reddit",
            "tumblr",
            "digg",
            "stumbleupon",
            "telegram",
            "whatsapp",
            "email",
            "kfunction",
            "u05deu05dcu05d0",
            "aw363516812",
            "error",
            "promise",
            "inull",
            "webfontconfig",
            "webfont",
            "gc",
            "number",
            "string",
            "uint8array",
            "regexp",
            "xhfunction",
            "yhfunction",
            "host",
            "path",
            "code",
            "topweb",
            "top web",
            "beyond",
            "forex",
            "hackeru",
            "one stop",
            "shop",
            "bgroup",
            "typesubmit",
            "datasecret",
            "shape",
            "html",
            "span",
            "false",
            "scrl",
            "haschildren",
            "zoomindown",
            "show hide",
            "dark",
            "checkbox",
            "back",
            "light",
            "typeof e",
            "formdata",
            "typeof symbol",
            "customevent",
            "post",
            "refill",
            "wpcf7",
            "wpcf7locale",
            "wpcf7unittag",
            "reflect",
            "math",
            "array",
            "object",
            "typeerror",
            "symbol",
            "function",
            "null",
            "title",
            "body",
            "click",
            "lecount",
            "count",
            "typeof define",
            "typeof t",
            "this",
            "close",
            "twitter",
            "open",
            "next",
            "blank",
            "xpercent0",
            "failure",
            "xpercent50",
            "essential grid",
            "blackberry",
            "author",
            "themepunch",
            "android",
            "typeof module",
            "tweenlite",
            "version",
            "onull",
            "updates and",
            "tools",
            "linear",
            "ticker",
            "bounce",
            "alpha",
            "fancybox",
            "plugin",
            "janis skarnelis",
            "100n",
            "right",
            "bottom",
            "left",
            "html tags",
            "ox20trnf",
            "dom element",
            "class",
            "attr",
            "pseudo",
            "child",
            "js foundation",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "source",
            "image",
            "ud83dudc6cud83c"
          ],
          "references": [
            "xfe-URL-anyweb.co.il-stix2-2.1-export.json",
            "https://anyweb.co.il/wp-includes/js/wp-emoji-release.min.js?ver=5.7.3",
            "https://anyweb.co.il/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
            "https://anyweb.co.il/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
            "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/lightbox.js?ver=2.0.9.1",
            "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.tools.min.js?ver=2.0.9.1",
            "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.essential.min.js?ver=2.0.9.1",
            "https://anyweb.co.il/wp-content/themes/superfine/assets/js/assets.js?ver=5.7.3",
            "https://anyweb.co.il/wp-content/themes/superfine/assets/js/post-like.min.js?ver=1.0",
            "https://anyweb.co.il/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
            "https://anyweb.co.il/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.1",
            "https://anyweb.co.il/wp-content/themes/superfine/assets/js/script.js",
            "https://anyweb.co.il/wp-includes/js/wp-embed.min.js?ver=5.7.3",
            "https://anyweb.co.il/wp-includes/css/dist/block-library/style.min.css?ver=5.7.3",
            "https://topweb.co.il/",
            "https://www.googletagmanager.com/gtm.js?id=GTM-NQNVC6K",
            "https://topweb.co.il/wp-content/plugins/litespeed-cache/assets/js/webfontloader.min.js",
            "https://topweb.co.il/wp-content/litespeed/js/c3a18f91ebd798da3e120a12aec7c615.js?ver=7c615",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/363516812/?random=1650901467024&cv=9&fst=1650901467024&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa4k0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Ftopweb.co.il%2F&tiba=%D7%9E%D7%A9%D7%A8%D7%93%20%D7%A4%D7%A8%D7%A1%D7%95%D7%9D%20%D7%95%D7%91%D7%A0%D7%99%D7%99%D7%AA%20%D7%90%D7%AA%D7%A8%D7%99%D7%9D%20%7C%20TOPWEB%20-%20%D7%98%D"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1158,
            "FileHash-SHA256": 671,
            "hostname": 304,
            "domain": 329,
            "email": 2
          },
          "indicator_count": 2464,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1468 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f05c71e903844d907b1ae",
          "name": "Russian Malware Strain",
          "description": "The full text of the new Dictionary of Human Rights, compiled by the Office of National Statistics (ONS), has been published on the internet, with the help of a few words: \"Glasgow\".",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T18:56:07.131000",
          "tags": [
            "bapunycode",
            "s700",
            "array",
            "topmailru",
            "error",
            "tmrtmr",
            "rbclickid",
            "tmrdebug1",
            "tadaeaxbyb",
            "bbdaea",
            "cbdaea",
            "uadaea",
            "ver1",
            "typemini",
            "verb0",
            "youtube",
            "content",
            "smartbanner",
            "null",
            "text",
            "smart banner",
            "copyright",
            "android",
            "windows store",
            "title",
            "price",
            "click",
            "date",
            "twitter",
            "string",
            "regexp",
            "number",
            "typeerror",
            "symbol",
            "array int8array",
            "argument",
            "rafunction",
            "iframe",
            "please",
            "image",
            "v[1]-1:k+=",
            "dpjquery",
            "document",
            "function",
            "this",
            "left",
            "bottom",
            "html",
            "nulle",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "attr",
            "class",
            "invalid json",
            "domparser",
            "edge",
            "sxa0",
            "qafunction",
            "trident",
            "ondomready",
            "make sure",
            "gc",
            "65535",
            "boolean",
            "counter",
            "segoe ui",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "form",
            "impact",
            "light",
            "bad idp",
            "cvtx",
            "bad event",
            "typeof b",
            "closure library",
            "f1518500249",
            "f1859775393",
            "body"
          ],
          "references": [
            "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
            "xfe-URL-Xelent.ru-stix2-2.1-export.json",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
            "http://mc.yandex.ru/metrika/watch.js",
            "http://metrika.installtraffic.com/js/watch.js",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
            "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
            "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
            "http://loviotvet.ru/lib/project/common.js",
            "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
            "https://apis.google.com/js/plusone.js",
            "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
            "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
            "https://top-fwz1.mail.ru/js/code.js",
            "https://bitrix.info/ba.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "V[1]-1:k+=",
              "display_name": "V[1]-1:k+=",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1987,
            "hostname": 733,
            "FileHash-SHA256": 294,
            "domain": 354
          },
          "indicator_count": 3368,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1474 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://bitrix.info/ba.js",
        "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.tools.min.js?ver=2.0.9.1",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
        "http://mc.yandex.ru/metrika/watch.js",
        "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
        "xfe-IP-185.100.65.26-stix2-2.1-export.json",
        "https://anyweb.co.il/wp-includes/css/dist/block-library/style.min.css?ver=5.7.3",
        "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
        "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
        "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
        "https://almapbx.hoster.kz/hoster_v2/widget/lead_hunter/?code=75455&protocol=https://&url=https://hoster.kz/",
        "https://almapbx.hoster.kz/hoster_v2/widget/lead_hunter/js/jquery.inputmask.bundle.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/363516812/?random=1650901467024&cv=9&fst=1650901467024&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa4k0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Ftopweb.co.il%2F&tiba=%D7%9E%D7%A9%D7%A8%D7%93%20%D7%A4%D7%A8%D7%A1%D7%95%D7%9D%20%D7%95%D7%91%D7%A0%D7%99%D7%99%D7%AA%20%D7%90%D7%AA%D7%A8%D7%99%D7%9D%20%7C%20TOPWEB%20-%20%D7%98%D",
        "https://anyweb.co.il/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
        "https://topweb.co.il/wp-content/plugins/litespeed-cache/assets/js/webfontloader.min.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1055680023/?random=1652174969236&cv=9&fst=1652174969236&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635470&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=2&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg590&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fhoster.kz%2F&ref=https%3A%2F%2Fhoster.kz%2F&tiba=%D0%A5%D0%BE%D1%81%D1%82%D0%B8%D0%BD%D0%B3%20%D0%B2%20%D0%9A%D0%B0%D0%B7%D0%B0%D1%85%D1%81%D1%82%D0%B0%D0%BD%D0%B5%2C%20%D0%BA%D1%83%D0%BF%D0",
        "xfe-URL-Xelent.ru-stix2-2.1-export.json",
        "https://apis.google.com/js/plusone.js",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/post-like.min.js?ver=1.0",
        "https://anyweb.co.il/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.1",
        "https://hoster.kz/js/jcarousellite_1.0.1.pack.js",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
        "xfe-URL-anyweb.co.il-stix2-2.1-export.json",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.essential.min.js?ver=2.0.9.1",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/lightbox.js?ver=2.0.9.1",
        "https://anyweb.co.il/wp-includes/js/wp-embed.min.js?ver=5.7.3",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/script.js",
        "https://anyweb.co.il/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
        "xfe-URL-Hoster.kz-stix2-2.1-export.json",
        "https://www.googletagmanager.com/gtm.js?id=GTM-N3ZRPW",
        "http://loviotvet.ru/lib/project/common.js",
        "https://topweb.co.il/",
        "https://anyweb.co.il/wp-includes/js/wp-emoji-release.min.js?ver=5.7.3",
        "https://topweb.co.il/wp-content/litespeed/js/c3a18f91ebd798da3e120a12aec7c615.js?ver=7c615",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NQNVC6K",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/assets.js?ver=5.7.3",
        "https://otx.alienvault.com/indicator/ip/198.49.23.145#:~:text=CIDR:%206%20%7C%20CVE:%20107,infrastructure%20into%20global%20botnet%20clusters.",
        "https://hoster.kz/js/html5.js",
        "http://metrika.installtraffic.com/js/watch.js",
        "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
        "https://top-fwz1.mail.ru/js/code.js",
        "https://anyweb.co.il/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Trojanspy",
            "Gc",
            "Webtoolbar",
            "Maltiverse",
            "V[1]-1:k+=",
            "T",
            "Wipes",
            "Qe"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 10,
  "pulses": [
    {
      "id": "69eb254f17eb4a2a990f07e5",
      "name": "LevelBlue - Open Threat Exchange",
      "description": "[ As part of security research, we look at some of the most well-known vulnerabilities in the PDF ecosystem, and how they can be identified and mitigated, with the help of a simple hash.] [64xxxx]",
      "modified": "2026-05-28T07:10:11.800000",
      "created": "2026-04-24T08:09:51.488000",
      "tags": [
        "pdfkit",
        "cve202225765",
        "exploit script",
        "github",
        "unicordev",
        "cves",
        "xml external",
        "entity",
        "pdfs",
        "knowledge base",
        "python",
        "mozilla",
        "virustotal",
        "cisa",
        "apple",
        "microsoft",
        "pdfkit ruby",
        "remote code",
        "execution",
        "urls",
        "malware",
        "raid",
        "caddywiper",
        "wipes",
        "cve202543529",
        "webkit",
        "february",
        "cve202620643",
        "bypass",
        "march",
        "webkit bug",
        "command",
        "control",
        "levelblue",
        "open threat"
      ],
      "references": [
        "https://otx.alienvault.com/indicator/ip/198.49.23.145#:~:text=CIDR:%206%20%7C%20CVE:%20107,infrastructure%20into%20global%20botnet%20clusters."
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Wipes",
          "display_name": "Wipes",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1084,
        "FileHash-SHA1": 874,
        "FileHash-SHA256": 3052,
        "CVE": 36,
        "domain": 437,
        "hostname": 1086,
        "URL": 1411,
        "CIDR": 15,
        "email": 13
      },
      "indicator_count": 8008,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 70,
      "modified_text": "4 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "654e46078568d62bc323e093",
      "name": "Imaging Center affected by WebToolbar \u2022 Critical C2 and Mitre Att",
      "description": "Critical - dpqhhab.exe\n216d5b6361d88c59cd0fb66c0ca94a27f6c1e0d592fc325b6d58929d4d5a1e76",
      "modified": "2023-12-10T13:00:37.604000",
      "created": "2023-11-10T15:02:31.518000",
      "tags": [
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "heur",
        "alexa top",
        "safe site",
        "million",
        "malware",
        "malware site",
        "phishing site",
        "malicious site",
        "crack",
        "wacatac",
        "unsafe",
        "phishing",
        "xrat",
        "xtrat",
        "nircmd",
        "swrort",
        "iframe",
        "downldr",
        "installcore",
        "agent",
        "unruy",
        "filetour",
        "cleaner",
        "patcher",
        "adload",
        "win64",
        "artemis",
        "riskware",
        "genkryptik",
        "fuery",
        "alexa",
        "blacklist https",
        "united",
        "ip address",
        "presenoker",
        "opencandy",
        "exploit",
        "quasar rat",
        "mimikatz",
        "malicious",
        "applicunwnt",
        "acint",
        "systweak",
        "behav",
        "tiggre",
        "conduit",
        "trojanspy",
        "webtoolbar",
        "gc",
        "xfbml1",
        "pattern match",
        "file",
        "ascii text",
        "indicator",
        "windows nt",
        "script",
        "appdata",
        "mitre att",
        "date",
        "unknown",
        "error",
        "hybrid",
        "general",
        "local",
        "click",
        "facebook",
        "strings",
        "class",
        "generator",
        "critical",
        "ssl certificate",
        "whois record",
        "threat roundup",
        "october",
        "contacted",
        "january",
        "resolutions",
        "whois whois",
        "june",
        "communicating",
        "february"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 41,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 221,
        "FileHash-SHA1": 171,
        "FileHash-SHA256": 2904,
        "domain": 4834,
        "hostname": 1631,
        "CVE": 9,
        "URL": 5670
      },
      "indicator_count": 15440,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "904 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "654e46130211d24d7f9ef311",
      "name": "Imaging Center affected by WebToolbar \u2022 Critical C2 and Mitre Att",
      "description": "Critical - dpqhhab.exe\n216d5b6361d88c59cd0fb66c0ca94a27f6c1e0d592fc325b6d58929d4d5a1e76",
      "modified": "2023-12-10T13:00:37.604000",
      "created": "2023-11-10T15:02:43.841000",
      "tags": [
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "heur",
        "alexa top",
        "safe site",
        "million",
        "malware",
        "malware site",
        "phishing site",
        "malicious site",
        "crack",
        "wacatac",
        "unsafe",
        "phishing",
        "xrat",
        "xtrat",
        "nircmd",
        "swrort",
        "iframe",
        "downldr",
        "installcore",
        "agent",
        "unruy",
        "filetour",
        "cleaner",
        "patcher",
        "adload",
        "win64",
        "artemis",
        "riskware",
        "genkryptik",
        "fuery",
        "alexa",
        "blacklist https",
        "united",
        "ip address",
        "presenoker",
        "opencandy",
        "exploit",
        "quasar rat",
        "mimikatz",
        "malicious",
        "applicunwnt",
        "acint",
        "systweak",
        "behav",
        "tiggre",
        "conduit",
        "trojanspy",
        "webtoolbar",
        "gc",
        "xfbml1",
        "pattern match",
        "file",
        "ascii text",
        "indicator",
        "windows nt",
        "script",
        "appdata",
        "mitre att",
        "date",
        "unknown",
        "error",
        "hybrid",
        "general",
        "local",
        "click",
        "facebook",
        "strings",
        "class",
        "generator",
        "critical",
        "ssl certificate",
        "whois record",
        "threat roundup",
        "october",
        "contacted",
        "january",
        "resolutions",
        "whois whois",
        "june",
        "communicating",
        "february"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 41,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 221,
        "FileHash-SHA1": 171,
        "FileHash-SHA256": 2904,
        "domain": 4834,
        "hostname": 1631,
        "CVE": 9,
        "URL": 5670
      },
      "indicator_count": 15440,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "904 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "654e469fbf2e1c732bbeb7a3",
      "name": "Imaging Center affected by WebToolbar \u2022 Critical C2 and Mitre Att",
      "description": "Critical - dpqhhab.exe\n216d5b6361d88c59cd0fb66c0ca94a27f6c1e0d592fc325b6d58929d4d5a1e76\n\nAllows bad actor to alter diagnosis without physician override or documentation of.",
      "modified": "2023-12-10T13:00:37.604000",
      "created": "2023-11-10T15:05:03.947000",
      "tags": [
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "heur",
        "alexa top",
        "safe site",
        "million",
        "malware",
        "malware site",
        "phishing site",
        "malicious site",
        "crack",
        "wacatac",
        "unsafe",
        "phishing",
        "xrat",
        "xtrat",
        "nircmd",
        "swrort",
        "iframe",
        "downldr",
        "installcore",
        "agent",
        "unruy",
        "filetour",
        "cleaner",
        "patcher",
        "adload",
        "win64",
        "artemis",
        "riskware",
        "genkryptik",
        "fuery",
        "alexa",
        "blacklist https",
        "united",
        "ip address",
        "presenoker",
        "opencandy",
        "exploit",
        "quasar rat",
        "mimikatz",
        "malicious",
        "applicunwnt",
        "acint",
        "systweak",
        "behav",
        "tiggre",
        "conduit",
        "trojanspy",
        "webtoolbar",
        "gc",
        "xfbml1",
        "pattern match",
        "file",
        "ascii text",
        "indicator",
        "windows nt",
        "script",
        "appdata",
        "mitre att",
        "date",
        "unknown",
        "error",
        "hybrid",
        "general",
        "local",
        "click",
        "facebook",
        "strings",
        "class",
        "generator",
        "critical",
        "ssl certificate",
        "whois record",
        "threat roundup",
        "october",
        "contacted",
        "january",
        "resolutions",
        "whois whois",
        "june",
        "communicating",
        "february"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 40,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 221,
        "FileHash-SHA1": 171,
        "FileHash-SHA256": 2904,
        "domain": 4834,
        "hostname": 1631,
        "CVE": 9,
        "URL": 5670
      },
      "indicator_count": 15440,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "904 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a8bf416a1c314819ea53",
      "name": "Remote Access Related |  APK attack targets independent artists",
      "description": "",
      "modified": "2023-12-06T17:00:47.888000",
      "created": "2023-12-06T17:00:47.888000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 5,
        "FileHash-SHA256": 2385,
        "hostname": 1054,
        "domain": 713,
        "URL": 3595,
        "FileHash-MD5": 1104,
        "FileHash-SHA1": 585,
        "FilePath": 1
      },
      "indicator_count": 9442,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6528fa2179cc1554d7f434c6",
      "name": "Remote Access Related |  APK attack targets independent artists",
      "description": "Suppression, malware,\nPassword,Exploit/Shellcode *Defacement *Unsafe.AI_Score_ * FileRepMetagen [PUP]\nrevenge-rat,stealer,, Steganos Software GmbH Privacy Suite, Ransom_WannaCrypt.R002C0DJO20,\nWacatac.B, Trojan.HideLink, SuppoBox,Trojan.Downloader.Generic, TrojWare.JS.Obfuscated, Phish.HHH, Phishing_Netflix.EVT, Phishing.Microsoft,Trojan.AvsHepter, HTML:PhishingBank, Phishing.fz, Probably, Heur.HTMLUnescapeF, BehavesLike.HTML.SMSSendPhishing.S23, Gen:Variant.Zbot, BehavesLike.HTML.Faceliker",
      "modified": "2023-11-12T07:01:14.580000",
      "created": "2023-10-13T08:04:49.722000",
      "tags": [
        "alexa top",
        "blacklist",
        "phishing",
        "million",
        "site",
        "cisco umbrella",
        "path",
        "maxage31536000",
        "expiressat",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "pragma",
        "html info",
        "title kedence",
        "official apk",
        "meta tags",
        "apk download",
        "android",
        "google tag",
        "utc google",
        "utc na",
        "whois record",
        "contacted",
        "ssl certificate",
        "communicating",
        "referrer",
        "historical ssl",
        "bundled",
        "resolutions",
        "contacted urls",
        "hackers install",
        "malware",
        "fakedout threat",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "united",
        "phishing site",
        "malware site",
        "malicious site",
        "heur",
        "anonymizer",
        "malicious host",
        "crack",
        "maltiverse",
        "driverpack",
        "ransomware",
        "opencandy",
        "artemis",
        "riskware",
        "installcore",
        "suppobox",
        "bank",
        "agent",
        "patcher",
        "generic",
        "t",
        "safe site",
        "iframe",
        "downldr",
        "presenoker",
        "exploit",
        "genkryptik",
        "dropper",
        "fakealert",
        "quasar rat",
        "xtrat",
        "softcnapp",
        "cleaner",
        "xrat",
        "applicunwnt",
        "mimikatz",
        "team",
        "azorult",
        "service",
        "runescape",
        "facebook",
        "download",
        "logo analysis",
        "size81b type",
        "mime",
        "scan10132023",
        "results",
        "multi scan",
        "analysis",
        "update",
        "view details",
        "na visit",
        "sansx22",
        "3px 3px",
        "indicator",
        "file",
        "general",
        "email address",
        "pattern match",
        "ck id",
        "t1114",
        "show technique",
        "mitre att",
        "ck matrix",
        "script",
        "antivirus",
        "svg scalable",
        "vector graphics",
        "span",
        "twitter",
        "hybrid",
        "ascii text",
        "appdata",
        "windows nt",
        "png image",
        "jpeg image",
        "jfif",
        "date",
        "flag",
        "markmonitor",
        "name server",
        "server",
        "enom",
        "whois privacy",
        "cloudflare",
        "domain address",
        "show",
        "osint",
        "f8f9fa",
        "eeeeee",
        "click",
        "unknown",
        "open",
        "error",
        "body",
        "hosts",
        "strings",
        "class",
        "critical",
        "meta",
        "scroll",
        "atom"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "T",
          "display_name": "T",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 31,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 713,
        "FileHash-MD5": 1104,
        "FileHash-SHA1": 585,
        "FileHash-SHA256": 2385,
        "hostname": 1054,
        "URL": 3596,
        "CVE": 5,
        "FilePath": 1
      },
      "indicator_count": 9443,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "932 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f1d23d050527b7aa07cfd",
      "name": "Remote Access Related | APK attack targets independent artists",
      "description": "",
      "modified": "2023-11-12T07:01:14.580000",
      "created": "2023-10-30T03:04:03.323000",
      "tags": [
        "alexa top",
        "blacklist",
        "phishing",
        "million",
        "site",
        "cisco umbrella",
        "path",
        "maxage31536000",
        "expiressat",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "pragma",
        "html info",
        "title kedence",
        "official apk",
        "meta tags",
        "apk download",
        "android",
        "google tag",
        "utc google",
        "utc na",
        "whois record",
        "contacted",
        "ssl certificate",
        "communicating",
        "referrer",
        "historical ssl",
        "bundled",
        "resolutions",
        "contacted urls",
        "hackers install",
        "malware",
        "fakedout threat",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "united",
        "phishing site",
        "malware site",
        "malicious site",
        "heur",
        "anonymizer",
        "malicious host",
        "crack",
        "maltiverse",
        "driverpack",
        "ransomware",
        "opencandy",
        "artemis",
        "riskware",
        "installcore",
        "suppobox",
        "bank",
        "agent",
        "patcher",
        "generic",
        "t",
        "safe site",
        "iframe",
        "downldr",
        "presenoker",
        "exploit",
        "genkryptik",
        "dropper",
        "fakealert",
        "quasar rat",
        "xtrat",
        "softcnapp",
        "cleaner",
        "xrat",
        "applicunwnt",
        "mimikatz",
        "team",
        "azorult",
        "service",
        "runescape",
        "facebook",
        "download",
        "logo analysis",
        "size81b type",
        "mime",
        "scan10132023",
        "results",
        "multi scan",
        "analysis",
        "update",
        "view details",
        "na visit",
        "sansx22",
        "3px 3px",
        "indicator",
        "file",
        "general",
        "email address",
        "pattern match",
        "ck id",
        "t1114",
        "show technique",
        "mitre att",
        "ck matrix",
        "script",
        "antivirus",
        "svg scalable",
        "vector graphics",
        "span",
        "twitter",
        "hybrid",
        "ascii text",
        "appdata",
        "windows nt",
        "png image",
        "jpeg image",
        "jfif",
        "date",
        "flag",
        "markmonitor",
        "name server",
        "server",
        "enom",
        "whois privacy",
        "cloudflare",
        "domain address",
        "show",
        "osint",
        "f8f9fa",
        "eeeeee",
        "click",
        "unknown",
        "open",
        "error",
        "body",
        "hosts",
        "strings",
        "class",
        "critical",
        "meta",
        "scroll",
        "atom"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "T",
          "display_name": "T",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6528fa2179cc1554d7f434c6",
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 713,
        "FileHash-MD5": 1104,
        "FileHash-SHA1": 585,
        "FileHash-SHA256": 2385,
        "hostname": 1054,
        "URL": 3596,
        "CVE": 5,
        "FilePath": 1
      },
      "indicator_count": 9443,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "932 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "627a3399312417bb7f844a55",
      "name": "hoster.kz",
      "description": "WebPacker.ru is a web-based tool designed to help people find and find the best way to get through the web, but only if you are a browser user or an administrator.",
      "modified": "2022-06-09T00:00:13.607000",
      "created": "2022-05-10T09:42:49.434000",
      "tags": [
        "regexp",
        "null",
        "shift",
        "function",
        "click",
        "bksp",
        "width",
        "body",
        "namedepartment",
        "altgr",
        "span",
        "date",
        "error",
        "class",
        "this",
        "refresh",
        "prop",
        "close",
        "accept",
        "jquery",
        "iframe",
        "embed",
        "inputmask",
        "void",
        "chrs",
        "alternation",
        "seeknext",
        "type",
        "input",
        "masktoken",
        "window",
        "mask",
        "form",
        "backspace",
        "insert",
        "qe",
        "copyright",
        "closure library",
        "trackevent",
        "number",
        "string",
        "version",
        "uint8array",
        "gtmn3zrpw",
        "host",
        "path",
        "derek",
        "code",
        "bapunycode",
        "s700",
        "index",
        "label",
        "link",
        "stylesheet",
        "textcss",
        "script",
        "array",
        "10000",
        "style",
        "xmlhttprequest",
        "load",
        "virtualpageview",
        "ymuid",
        "post"
      ],
      "references": [
        "xfe-IP-185.100.65.26-stix2-2.1-export.json",
        "xfe-URL-Hoster.kz-stix2-2.1-export.json",
        "https://almapbx.hoster.kz/hoster_v2/widget/lead_hunter/?code=75455&protocol=https://&url=https://hoster.kz/",
        "https://bitrix.info/ba.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-N3ZRPW",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1055680023/?random=1652174969236&cv=9&fst=1652174969236&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635470&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=2&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg590&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fhoster.kz%2F&ref=https%3A%2F%2Fhoster.kz%2F&tiba=%D0%A5%D0%BE%D1%81%D1%82%D0%B8%D0%BD%D0%B3%20%D0%B2%20%D0%9A%D0%B0%D0%B7%D0%B0%D1%85%D1%81%D1%82%D0%B0%D0%BD%D0%B5%2C%20%D0%BA%D1%83%D0%BF%D0",
        "https://almapbx.hoster.kz/hoster_v2/widget/lead_hunter/js/jquery.inputmask.bundle.js",
        "https://hoster.kz/js/html5.js",
        "https://hoster.kz/js/jcarousellite_1.0.1.pack.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Qe",
          "display_name": "Qe",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3010,
        "hostname": 1225,
        "domain": 1427,
        "FileHash-SHA256": 136,
        "CVE": 1,
        "email": 2
      },
      "indicator_count": 5801,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 70,
      "modified_text": "1453 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6266c416c4598fa139868c64",
      "name": "\u05de\u05e9\u05e8\u05d3 \u05e4\u05e8\u05e1\u05d5\u05dd \u05d5\u05d1\u05e0\u05d9\u05d9\u05ea \u05d0\u05ea\u05e8\u05d9\u05dd | TOPWEB - \u05d8\u05d5\u05e4 \u05d5\u05d5\u05d1- \u05d4\u05d5\u05e4\u05db\u05d9\u05dd \u05e2\u05e1\u05e7\u05d9\u05dd \u05dc\u05de\u05d5\u05ea\u05d2\u05d9\u05dd \u05d1\u05d3\u05d9\u05d2\u05d9\u05d8\u05dc",
      "description": "New RegExp(M) is a new type, and it will change any of the elements to the same type if you want to add them to your HTML page or add a third element.",
      "modified": "2022-05-25T00:04:03.622000",
      "created": "2022-04-25T15:53:58.206000",
      "tags": [
        "init",
        "803911410135716",
        "pageview",
        "date",
        "datalayer",
        "gtmnqnvc6k",
        "copyright",
        "closure library",
        "facebook",
        "google",
        "linkedin",
        "reddit",
        "tumblr",
        "digg",
        "stumbleupon",
        "telegram",
        "whatsapp",
        "email",
        "kfunction",
        "u05deu05dcu05d0",
        "aw363516812",
        "error",
        "promise",
        "inull",
        "webfontconfig",
        "webfont",
        "gc",
        "number",
        "string",
        "uint8array",
        "regexp",
        "xhfunction",
        "yhfunction",
        "host",
        "path",
        "code",
        "topweb",
        "top web",
        "beyond",
        "forex",
        "hackeru",
        "one stop",
        "shop",
        "bgroup",
        "typesubmit",
        "datasecret",
        "shape",
        "html",
        "span",
        "false",
        "scrl",
        "haschildren",
        "zoomindown",
        "show hide",
        "dark",
        "checkbox",
        "back",
        "light",
        "typeof e",
        "formdata",
        "typeof symbol",
        "customevent",
        "post",
        "refill",
        "wpcf7",
        "wpcf7locale",
        "wpcf7unittag",
        "reflect",
        "math",
        "array",
        "object",
        "typeerror",
        "symbol",
        "function",
        "null",
        "title",
        "body",
        "click",
        "lecount",
        "count",
        "typeof define",
        "typeof t",
        "this",
        "close",
        "twitter",
        "open",
        "next",
        "blank",
        "xpercent0",
        "failure",
        "xpercent50",
        "essential grid",
        "blackberry",
        "author",
        "themepunch",
        "android",
        "typeof module",
        "tweenlite",
        "version",
        "onull",
        "updates and",
        "tools",
        "linear",
        "ticker",
        "bounce",
        "alpha",
        "fancybox",
        "plugin",
        "janis skarnelis",
        "100n",
        "right",
        "bottom",
        "left",
        "html tags",
        "ox20trnf",
        "dom element",
        "class",
        "attr",
        "pseudo",
        "child",
        "js foundation",
        "udc66udc67",
        "ud83d",
        "ufe0f",
        "ud83e",
        "udc68udc69",
        "udfcbudfcc",
        "u2640u2642",
        "source",
        "image",
        "ud83dudc6cud83c"
      ],
      "references": [
        "xfe-URL-anyweb.co.il-stix2-2.1-export.json",
        "https://anyweb.co.il/wp-includes/js/wp-emoji-release.min.js?ver=5.7.3",
        "https://anyweb.co.il/wp-includes/js/jquery/jquery.min.js?ver=3.5.1",
        "https://anyweb.co.il/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/lightbox.js?ver=2.0.9.1",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.tools.min.js?ver=2.0.9.1",
        "https://anyweb.co.il/wp-content/plugins/essential-grid/public/assets/js/jquery.themepunch.essential.min.js?ver=2.0.9.1",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/assets.js?ver=5.7.3",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/post-like.min.js?ver=1.0",
        "https://anyweb.co.il/wp-includes/js/dist/vendor/wp-polyfill.min.js?ver=7.4.4",
        "https://anyweb.co.il/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.1",
        "https://anyweb.co.il/wp-content/themes/superfine/assets/js/script.js",
        "https://anyweb.co.il/wp-includes/js/wp-embed.min.js?ver=5.7.3",
        "https://anyweb.co.il/wp-includes/css/dist/block-library/style.min.css?ver=5.7.3",
        "https://topweb.co.il/",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NQNVC6K",
        "https://topweb.co.il/wp-content/plugins/litespeed-cache/assets/js/webfontloader.min.js",
        "https://topweb.co.il/wp-content/litespeed/js/c3a18f91ebd798da3e120a12aec7c615.js?ver=7c615",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/363516812/?random=1650901467024&cv=9&fst=1650901467024&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa4k0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Ftopweb.co.il%2F&tiba=%D7%9E%D7%A9%D7%A8%D7%93%20%D7%A4%D7%A8%D7%A1%D7%95%D7%9D%20%D7%95%D7%91%D7%A0%D7%99%D7%99%D7%AA%20%D7%90%D7%AA%D7%A8%D7%99%D7%9D%20%7C%20TOPWEB%20-%20%D7%98%D"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1158,
        "FileHash-SHA256": 671,
        "hostname": 304,
        "domain": 329,
        "email": 2
      },
      "indicator_count": 2464,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 70,
      "modified_text": "1468 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "625f05c71e903844d907b1ae",
      "name": "Russian Malware Strain",
      "description": "The full text of the new Dictionary of Human Rights, compiled by the Office of National Statistics (ONS), has been published on the internet, with the help of a few words: \"Glasgow\".",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T18:56:07.131000",
      "tags": [
        "bapunycode",
        "s700",
        "array",
        "topmailru",
        "error",
        "tmrtmr",
        "rbclickid",
        "tmrdebug1",
        "tadaeaxbyb",
        "bbdaea",
        "cbdaea",
        "uadaea",
        "ver1",
        "typemini",
        "verb0",
        "youtube",
        "content",
        "smartbanner",
        "null",
        "text",
        "smart banner",
        "copyright",
        "android",
        "windows store",
        "title",
        "price",
        "click",
        "date",
        "twitter",
        "string",
        "regexp",
        "number",
        "typeerror",
        "symbol",
        "array int8array",
        "argument",
        "rafunction",
        "iframe",
        "please",
        "image",
        "v[1]-1:k+=",
        "dpjquery",
        "document",
        "function",
        "this",
        "left",
        "bottom",
        "html",
        "nulle",
        "next",
        "february",
        "april",
        "june",
        "august",
        "atom",
        "cookie",
        "back",
        "bounce",
        "attr",
        "class",
        "invalid json",
        "domparser",
        "edge",
        "sxa0",
        "qafunction",
        "trident",
        "ondomready",
        "make sure",
        "gc",
        "65535",
        "boolean",
        "counter",
        "segoe ui",
        "lucida",
        "ecommerce",
        "ext link",
        "comic",
        "form",
        "impact",
        "light",
        "bad idp",
        "cvtx",
        "bad event",
        "typeof b",
        "closure library",
        "f1518500249",
        "f1859775393",
        "body"
      ],
      "references": [
        "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
        "xfe-URL-Xelent.ru-stix2-2.1-export.json",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
        "http://mc.yandex.ru/metrika/watch.js",
        "http://metrika.installtraffic.com/js/watch.js",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
        "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
        "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
        "http://loviotvet.ru/lib/project/common.js",
        "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
        "https://apis.google.com/js/plusone.js",
        "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
        "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
        "https://top-fwz1.mail.ru/js/code.js",
        "https://bitrix.info/ba.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "V[1]-1:k+=",
          "display_name": "V[1]-1:k+=",
          "target": null
        },
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1987,
        "hostname": 733,
        "FileHash-SHA256": 294,
        "domain": 354
      },
      "indicator_count": 3368,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1474 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "fancyapps.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "fancyapps.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780319041.811928
}