{
  "type": "Domain",
  "indicator": "fontgoogleapis.com",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/fontgoogleapis.com",
    "alexa": "http://www.alexa.com/siteinfo/fontgoogleapis.com",
    "indicator": "fontgoogleapis.com",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 3007831758,
      "indicator": "fontgoogleapis.com",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "60f1ec0277d7307b2d314643",
          "name": "Magecart skimmer using steganography",
          "description": "Magecart skimmer using steganography",
          "modified": "2021-07-16T20:28:49.749000",
          "created": "2021-07-16T20:28:49.749000",
          "tags": [
            "magecart",
            "skimmer"
          ],
          "references": [
            "https://twitter.com/MBThreatIntel/status/1416101496022724609"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Magecart",
              "display_name": "Magecart",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 239,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 12
          },
          "indicator_count": 12,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386614,
          "modified_text": "1780 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "657095a7912f63c2e41cda22",
          "name": "trifega.com - your welcome - my god two years ago i left specific details with sussex and surrey cybercrime team -",
          "description": "",
          "modified": "2023-12-06T15:39:18.737000",
          "created": "2023-12-06T15:39:18.737000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 745,
            "FileHash-SHA256": 1097,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6,
            "URL": 2764,
            "hostname": 1468
          },
          "indicator_count": 6086,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "63a8fc8d21e342461e0c53e5",
          "name": "trifega.com - your welcome - my god two years ago i left specific details with sussex and surrey cybercrime team -",
          "description": "2016 getsetpet.co.uk\ncentraserve.com /ltd purchased above domain after stealing frm my 1and1hosting acc transfering to google abusing it until july 2018 when it expired from my registration. Immediately purchased by Sebastian Clark director of centraserve ltd in essex uk. After this discovery it was moved to Trifega Ltd in the lsle of Whight for sale for \u00a3350 on trifega.com",
          "modified": "2023-01-25T01:02:11.128000",
          "created": "2022-12-26T01:44:45.883000",
          "tags": [
            "https://www.virustotal.com/gui/collection/54321340057709266cb812"
          ],
          "references": [
            "https://www.virustotal.com/graph/g87dbd51d317a43c59906ba09ca34598223bb3f1be82a45b48f8d4dd88bf28d92",
            "https://www.virustotal.com/gui/collection/54321340057709266cb812de770a121defeb7c8bb2fdf96fbdaab06213029c96"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 32,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2764,
            "hostname": 1468,
            "FileHash-SHA256": 1097,
            "domain": 745,
            "FileHash-MD5": 6,
            "FileHash-SHA1": 6
          },
          "indicator_count": 6086,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "1223 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://twitter.com/MBThreatIntel/status/1416101496022724609",
        "https://www.virustotal.com/gui/collection/54321340057709266cb812de770a121defeb7c8bb2fdf96fbdaab06213029c96",
        "https://www.virustotal.com/graph/g87dbd51d317a43c59906ba09ca34598223bb3f1be82a45b48f8d4dd88bf28d92"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [
            "Magecart"
          ],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": [
      {
        "assessment": "rejected",
        "assessment_date": "2021-07-20T20:31:44.431000",
        "report_date": "2021-07-17T09:29:21.676000"
      }
    ]
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "60f1ec0277d7307b2d314643",
      "name": "Magecart skimmer using steganography",
      "description": "Magecart skimmer using steganography",
      "modified": "2021-07-16T20:28:49.749000",
      "created": "2021-07-16T20:28:49.749000",
      "tags": [
        "magecart",
        "skimmer"
      ],
      "references": [
        "https://twitter.com/MBThreatIntel/status/1416101496022724609"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Magecart",
          "display_name": "Magecart",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 239,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 12
      },
      "indicator_count": 12,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386614,
      "modified_text": "1780 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "657095a7912f63c2e41cda22",
      "name": "trifega.com - your welcome - my god two years ago i left specific details with sussex and surrey cybercrime team -",
      "description": "",
      "modified": "2023-12-06T15:39:18.737000",
      "created": "2023-12-06T15:39:18.737000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 745,
        "FileHash-SHA256": 1097,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6,
        "URL": 2764,
        "hostname": 1468
      },
      "indicator_count": 6086,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "63a8fc8d21e342461e0c53e5",
      "name": "trifega.com - your welcome - my god two years ago i left specific details with sussex and surrey cybercrime team -",
      "description": "2016 getsetpet.co.uk\ncentraserve.com /ltd purchased above domain after stealing frm my 1and1hosting acc transfering to google abusing it until july 2018 when it expired from my registration. Immediately purchased by Sebastian Clark director of centraserve ltd in essex uk. After this discovery it was moved to Trifega Ltd in the lsle of Whight for sale for \u00a3350 on trifega.com",
      "modified": "2023-01-25T01:02:11.128000",
      "created": "2022-12-26T01:44:45.883000",
      "tags": [
        "https://www.virustotal.com/gui/collection/54321340057709266cb812"
      ],
      "references": [
        "https://www.virustotal.com/graph/g87dbd51d317a43c59906ba09ca34598223bb3f1be82a45b48f8d4dd88bf28d92",
        "https://www.virustotal.com/gui/collection/54321340057709266cb812de770a121defeb7c8bb2fdf96fbdaab06213029c96"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 32,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2764,
        "hostname": 1468,
        "FileHash-SHA256": 1097,
        "domain": 745,
        "FileHash-MD5": 6,
        "FileHash-SHA1": 6
      },
      "indicator_count": 6086,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "1223 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "fontgoogleapis.com",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "fontgoogleapis.com",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780284250.6133466
}