{
  "type": "Domain",
  "indicator": "fmniltb.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/fmniltb.com",
    "alexa": "http://www.alexa.com/siteinfo/fmniltb.com",
    "indicator": "fmniltb.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 1579280992,
      "indicator": "fmniltb.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 13,
      "pulses": [
        {
          "id": "63f52b7667fbf57d995082a2",
          "name": "Mylobot: Investigating a proxy botnet",
          "description": "Mylobot is a malware that targets Windows systems, it first appeared in 2017 and until now hasn\u2019t received much attention over the years. In this article, we'll focus on its main capability, which is transforming the infected system into a proxy. We'll also see how it's distributed and the capabilities of its downloader. We'll try to make a connection between Mylobot and BHProxies (a residential proxy service), and finally we'll present the telemetry we were able to collect since we started tracking it in 2018.",
          "modified": "2023-03-23T19:01:24.397000",
          "created": "2023-02-21T20:37:09.420000",
          "tags": [
            "Mylobot",
            "WillExec dropper",
            "proxy bot",
            "windows API",
            "BHProxies"
          ],
          "references": [
            "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1094",
              "name": "Custom Command and Control Protocol",
              "display_name": "T1094 - Custom Command and Control Protocol"
            },
            {
              "id": "T1022",
              "name": "Data Encrypted",
              "display_name": "T1022 - Data Encrypted"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 410,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 11,
            "domain": 24
          },
          "indicator_count": 51,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 387172,
          "modified_text": "1168 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "5bec53edbc977065131869ff",
          "name": "Mylobot Continues Global Infections",
          "description": "CenturyLink Threat Research Labs has been tracking the Mylobot botnet, a sophisticated malware family that is categorized as a downloader. What makes Mylobot dangerous is its ability to download and execute any type of payload after it infects a host. This means at any time it could download any other type of malware the attacker desires. A detailed walkthrough and reverse engineering analysis of Mylobot was first reported in June by Deep Instinct. During the time we have been monitoring Mylobot we have observed it downloading the Khalesi malware as a second stage to infected hosts. Kaspersky Lab reports that the information stealing Khalesi malware is one of the top downloaded malware families in 2018.",
          "modified": "2019-05-07T11:43:26.115000",
          "created": "2018-11-14T16:57:16.907000",
          "tags": [
            "mylobot"
          ],
          "references": [
            "https://www.netformation.com/our-pov/mylobot-continues-global-infections/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 119,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1411,
            "FileHash-SHA256": 4,
            "URL": 1397
          },
          "indicator_count": 2812,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 387224,
          "modified_text": "2584 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657097fa0613ec3a4732c03c",
          "name": "Mylobot: Investigating a proxy botnet",
          "description": "",
          "modified": "2023-12-06T15:49:14.809000",
          "created": "2023-12-06T15:49:14.809000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 11,
            "domain": 24
          },
          "indicator_count": 51,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657097a2d798f6e0b499c780",
          "name": "Mylobot: Investigating a proxy botnet",
          "description": "",
          "modified": "2023-12-06T15:47:46.291000",
          "created": "2023-12-06T15:47:46.291000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 11,
            "domain": 24
          },
          "indicator_count": 51,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657097a09a555f128e4c9a94",
          "name": "Mylobot: Investigating a proxy botnet",
          "description": "",
          "modified": "2023-12-06T15:47:44.681000",
          "created": "2023-12-06T15:47:44.681000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 11,
            "domain": 24
          },
          "indicator_count": 51,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709782d5ec440ffe204586",
          "name": "Mylobot: Investigating a proxy botnet | BitSight",
          "description": "",
          "modified": "2023-12-06T15:47:14.952000",
          "created": "2023-12-06T15:47:14.952000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 11,
            "FileHash-SHA1": 11,
            "FileHash-SHA256": 11,
            "domain": 24,
            "URL": 27,
            "hostname": 12
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709780d5b9c35c812a7736",
          "name": "Mylobot",
          "description": "",
          "modified": "2023-12-06T15:47:12.161000",
          "created": "2023-12-06T15:47:12.161000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 11,
            "FileHash-SHA1": 11,
            "FileHash-SHA256": 11,
            "domain": 24,
            "URL": 27,
            "hostname": 12
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709773b7bdb9ee16bbac5e",
          "name": "Mylobot: Investigating a proxy botnet",
          "description": "",
          "modified": "2023-12-06T15:46:59.130000",
          "created": "2023-12-06T15:46:59.130000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 11,
            "domain": 24
          },
          "indicator_count": 51,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63f5e96e1a3225fac3f64c58",
          "name": "Mylobot: Investigating a proxy botnet | BitSight",
          "description": "Questions about whether or not you want to use the same product as your business partner or your third party have been answered by a panel of experts, who have come up with a range of options.",
          "modified": "2023-03-24T10:05:05.159000",
          "created": "2023-02-22T10:07:42.104000",
          "tags": [
            "mylobot",
            "bitsight",
            "willexec",
            "appdata",
            "bhproxies",
            "mylobot proxy",
            "figure",
            "ip address",
            "mylobot sample",
            "pe file",
            "windefender",
            "third",
            "download",
            "khalesi",
            "zusy",
            "june",
            "backconnect",
            "indonesia"
          ],
          "references": [
            "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Iran, Islamic Republic of",
            "Indonesia",
            "India"
          ],
          "malware_families": [
            {
              "id": "WillExec",
              "display_name": "WillExec",
              "target": null
            },
            {
              "id": "BitSight",
              "display_name": "BitSight",
              "target": null
            },
            {
              "id": "Mylobot",
              "display_name": "Mylobot",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 27,
            "FileHash-MD5": 11,
            "FileHash-SHA1": 11,
            "FileHash-SHA256": 11,
            "domain": 24,
            "hostname": 12
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1167 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63f5b202ed6dc237d0fb15f0",
          "name": "Mylobot",
          "description": "A sophisticated botnet known as MyloBot has compromised thousands of systems, with most of them located in India, the U.S., Indonesia, and Iran.\n\nThat's according to new findings from BitSight, which said it's \"currently seeing more than 50,000 unique infected systems every day,\" down from a high of 250,000 unique hosts in 2020.\nFurthermore, an analysis of MyloBot's infrastructure has found connections to a residential proxy service called BHProxies, indicating that the compromised machines are being used by the latter.\nMyloBot, which emerged on the threat landscape in 2017, was first documented by Deep Instinct in 2018, calling out its anti-analysis techniques and its ability to function as a downloader.",
          "modified": "2023-03-24T06:00:31.449000",
          "created": "2023-02-22T06:11:14.847000",
          "tags": [
            "mylobot",
            "bitsight",
            "willexec",
            "appdata",
            "bhproxies",
            "mylobot proxy",
            "figure",
            "ip address",
            "mylobot sample",
            "pe file",
            "windefender",
            "third",
            "download",
            "khalesi",
            "zusy",
            "june",
            "backconnect",
            "indonesia"
          ],
          "references": [
            "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Iran, Islamic Republic of",
            "Indonesia",
            "India"
          ],
          "malware_families": [
            {
              "id": "WillExec",
              "display_name": "WillExec",
              "target": null
            },
            {
              "id": "BitSight",
              "display_name": "BitSight",
              "target": null
            },
            {
              "id": "Mylobot",
              "display_name": "Mylobot",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [
            "Cryptocurrency"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "jeffchandy",
            "id": "215558",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_215558/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 11,
            "FileHash-SHA1": 11,
            "FileHash-SHA256": 11,
            "URL": 27,
            "domain": 24,
            "hostname": 12
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1167 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63f73f6972afc1d703485e1b",
          "name": "Mylobot: Investigating a proxy botnet",
          "description": "",
          "modified": "2023-03-23T19:01:24.397000",
          "created": "2023-02-23T10:26:49.635000",
          "tags": [
            "Mylobot",
            "WillExec dropper",
            "proxy bot",
            "windows API",
            "BHProxies"
          ],
          "references": [
            "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1094",
              "name": "Custom Command and Control Protocol",
              "display_name": "T1094 - Custom Command and Control Protocol"
            },
            {
              "id": "T1022",
              "name": "Data Encrypted",
              "display_name": "T1022 - Data Encrypted"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "63f52b7667fbf57d995082a2",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 11,
            "domain": 24
          },
          "indicator_count": 51,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "1168 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63f73f7fb5c59336e02b4ad5",
          "name": "Mylobot: Investigating a proxy botnet",
          "description": "",
          "modified": "2023-03-23T19:01:24.397000",
          "created": "2023-02-23T10:27:11.502000",
          "tags": [
            "Mylobot",
            "WillExec dropper",
            "proxy bot",
            "windows API",
            "BHProxies"
          ],
          "references": [
            "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1094",
              "name": "Custom Command and Control Protocol",
              "display_name": "T1094 - Custom Command and Control Protocol"
            },
            {
              "id": "T1022",
              "name": "Data Encrypted",
              "display_name": "T1022 - Data Encrypted"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "63f73f6972afc1d703485e1b",
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 11,
            "domain": 24
          },
          "indicator_count": 51,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "1168 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64005cacfc6c8fe022ab9e44",
          "name": "Mylobot: Investigating a proxy botnet",
          "description": "",
          "modified": "2023-03-23T19:01:24.397000",
          "created": "2023-03-02T08:22:04.179000",
          "tags": [
            "Mylobot",
            "WillExec dropper",
            "proxy bot",
            "windows API",
            "BHProxies"
          ],
          "references": [
            "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1608",
              "name": "Stage Capabilities",
              "display_name": "T1608 - Stage Capabilities"
            },
            {
              "id": "T1094",
              "name": "Custom Command and Control Protocol",
              "display_name": "T1094 - Custom Command and Control Protocol"
            },
            {
              "id": "T1022",
              "name": "Data Encrypted",
              "display_name": "T1022 - Data Encrypted"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "63f73f7fb5c59336e02b4ad5",
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8,
            "FileHash-SHA1": 8,
            "FileHash-SHA256": 11,
            "domain": 24
          },
          "indicator_count": 51,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 277,
          "modified_text": "1168 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.netformation.com/our-pov/mylobot-continues-global-infections/",
        "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Willexec",
            "Bitsight",
            "Mylobot"
          ],
          "industries": [
            "Cryptocurrency"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 13,
  "pulses": [
    {
      "id": "63f52b7667fbf57d995082a2",
      "name": "Mylobot: Investigating a proxy botnet",
      "description": "Mylobot is a malware that targets Windows systems, it first appeared in 2017 and until now hasn\u2019t received much attention over the years. In this article, we'll focus on its main capability, which is transforming the infected system into a proxy. We'll also see how it's distributed and the capabilities of its downloader. We'll try to make a connection between Mylobot and BHProxies (a residential proxy service), and finally we'll present the telemetry we were able to collect since we started tracking it in 2018.",
      "modified": "2023-03-23T19:01:24.397000",
      "created": "2023-02-21T20:37:09.420000",
      "tags": [
        "Mylobot",
        "WillExec dropper",
        "proxy bot",
        "windows API",
        "BHProxies"
      ],
      "references": [
        "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1608",
          "name": "Stage Capabilities",
          "display_name": "T1608 - Stage Capabilities"
        },
        {
          "id": "T1094",
          "name": "Custom Command and Control Protocol",
          "display_name": "T1094 - Custom Command and Control Protocol"
        },
        {
          "id": "T1022",
          "name": "Data Encrypted",
          "display_name": "T1022 - Data Encrypted"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 410,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8,
        "FileHash-SHA1": 8,
        "FileHash-SHA256": 11,
        "domain": 24
      },
      "indicator_count": 51,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 387172,
      "modified_text": "1168 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "5bec53edbc977065131869ff",
      "name": "Mylobot Continues Global Infections",
      "description": "CenturyLink Threat Research Labs has been tracking the Mylobot botnet, a sophisticated malware family that is categorized as a downloader. What makes Mylobot dangerous is its ability to download and execute any type of payload after it infects a host. This means at any time it could download any other type of malware the attacker desires. A detailed walkthrough and reverse engineering analysis of Mylobot was first reported in June by Deep Instinct. During the time we have been monitoring Mylobot we have observed it downloading the Khalesi malware as a second stage to infected hosts. Kaspersky Lab reports that the information stealing Khalesi malware is one of the top downloaded malware families in 2018.",
      "modified": "2019-05-07T11:43:26.115000",
      "created": "2018-11-14T16:57:16.907000",
      "tags": [
        "mylobot"
      ],
      "references": [
        "https://www.netformation.com/our-pov/mylobot-continues-global-infections/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 119,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1411,
        "FileHash-SHA256": 4,
        "URL": 1397
      },
      "indicator_count": 2812,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 387224,
      "modified_text": "2584 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "657097fa0613ec3a4732c03c",
      "name": "Mylobot: Investigating a proxy botnet",
      "description": "",
      "modified": "2023-12-06T15:49:14.809000",
      "created": "2023-12-06T15:49:14.809000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8,
        "FileHash-SHA1": 8,
        "FileHash-SHA256": 11,
        "domain": 24
      },
      "indicator_count": 51,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "657097a2d798f6e0b499c780",
      "name": "Mylobot: Investigating a proxy botnet",
      "description": "",
      "modified": "2023-12-06T15:47:46.291000",
      "created": "2023-12-06T15:47:46.291000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8,
        "FileHash-SHA1": 8,
        "FileHash-SHA256": 11,
        "domain": 24
      },
      "indicator_count": 51,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "657097a09a555f128e4c9a94",
      "name": "Mylobot: Investigating a proxy botnet",
      "description": "",
      "modified": "2023-12-06T15:47:44.681000",
      "created": "2023-12-06T15:47:44.681000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8,
        "FileHash-SHA1": 8,
        "FileHash-SHA256": 11,
        "domain": 24
      },
      "indicator_count": 51,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65709782d5ec440ffe204586",
      "name": "Mylobot: Investigating a proxy botnet | BitSight",
      "description": "",
      "modified": "2023-12-06T15:47:14.952000",
      "created": "2023-12-06T15:47:14.952000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 11,
        "FileHash-SHA1": 11,
        "FileHash-SHA256": 11,
        "domain": 24,
        "URL": 27,
        "hostname": 12
      },
      "indicator_count": 96,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65709780d5b9c35c812a7736",
      "name": "Mylobot",
      "description": "",
      "modified": "2023-12-06T15:47:12.161000",
      "created": "2023-12-06T15:47:12.161000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 11,
        "FileHash-SHA1": 11,
        "FileHash-SHA256": 11,
        "domain": 24,
        "URL": 27,
        "hostname": 12
      },
      "indicator_count": 96,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65709773b7bdb9ee16bbac5e",
      "name": "Mylobot: Investigating a proxy botnet",
      "description": "",
      "modified": "2023-12-06T15:46:59.130000",
      "created": "2023-12-06T15:46:59.130000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8,
        "FileHash-SHA1": 8,
        "FileHash-SHA256": 11,
        "domain": 24
      },
      "indicator_count": 51,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63f5e96e1a3225fac3f64c58",
      "name": "Mylobot: Investigating a proxy botnet | BitSight",
      "description": "Questions about whether or not you want to use the same product as your business partner or your third party have been answered by a panel of experts, who have come up with a range of options.",
      "modified": "2023-03-24T10:05:05.159000",
      "created": "2023-02-22T10:07:42.104000",
      "tags": [
        "mylobot",
        "bitsight",
        "willexec",
        "appdata",
        "bhproxies",
        "mylobot proxy",
        "figure",
        "ip address",
        "mylobot sample",
        "pe file",
        "windefender",
        "third",
        "download",
        "khalesi",
        "zusy",
        "june",
        "backconnect",
        "indonesia"
      ],
      "references": [
        "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Iran, Islamic Republic of",
        "Indonesia",
        "India"
      ],
      "malware_families": [
        {
          "id": "WillExec",
          "display_name": "WillExec",
          "target": null
        },
        {
          "id": "BitSight",
          "display_name": "BitSight",
          "target": null
        },
        {
          "id": "Mylobot",
          "display_name": "Mylobot",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 27,
        "FileHash-MD5": 11,
        "FileHash-SHA1": 11,
        "FileHash-SHA256": 11,
        "domain": 24,
        "hostname": 12
      },
      "indicator_count": 96,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "1167 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63f5b202ed6dc237d0fb15f0",
      "name": "Mylobot",
      "description": "A sophisticated botnet known as MyloBot has compromised thousands of systems, with most of them located in India, the U.S., Indonesia, and Iran.\n\nThat's according to new findings from BitSight, which said it's \"currently seeing more than 50,000 unique infected systems every day,\" down from a high of 250,000 unique hosts in 2020.\nFurthermore, an analysis of MyloBot's infrastructure has found connections to a residential proxy service called BHProxies, indicating that the compromised machines are being used by the latter.\nMyloBot, which emerged on the threat landscape in 2017, was first documented by Deep Instinct in 2018, calling out its anti-analysis techniques and its ability to function as a downloader.",
      "modified": "2023-03-24T06:00:31.449000",
      "created": "2023-02-22T06:11:14.847000",
      "tags": [
        "mylobot",
        "bitsight",
        "willexec",
        "appdata",
        "bhproxies",
        "mylobot proxy",
        "figure",
        "ip address",
        "mylobot sample",
        "pe file",
        "windefender",
        "third",
        "download",
        "khalesi",
        "zusy",
        "june",
        "backconnect",
        "indonesia"
      ],
      "references": [
        "https://www.bitsight.com/blog/mylobot-investigating-proxy-botnet"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Iran, Islamic Republic of",
        "Indonesia",
        "India"
      ],
      "malware_families": [
        {
          "id": "WillExec",
          "display_name": "WillExec",
          "target": null
        },
        {
          "id": "BitSight",
          "display_name": "BitSight",
          "target": null
        },
        {
          "id": "Mylobot",
          "display_name": "Mylobot",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [
        "Cryptocurrency"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "jeffchandy",
        "id": "215558",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_215558/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 11,
        "FileHash-SHA1": 11,
        "FileHash-SHA256": 11,
        "URL": 27,
        "domain": 24,
        "hostname": 12
      },
      "indicator_count": 96,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 57,
      "modified_text": "1167 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "fmniltb.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "fmniltb.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780515196.1981409
}