{
  "type": "Domain",
  "indicator": "getazurecommand.icu",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/getazurecommand.icu",
    "alexa": "http://www.alexa.com/siteinfo/getazurecommand.icu",
    "indicator": "getazurecommand.icu",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 4026184900,
      "indicator": "getazurecommand.icu",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "679ca175bea14c5736a7310a",
          "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
          "description": "Insikt Group has identified a complex infrastructure linked to the traffic distribution system TAG-124, which overlaps with several threat activity clusters and includes compromised WordPress sites and various servers. Multiple threat actors, including operators of Rhysida and Interlock ransomware, use TAG-124, reinforcing their connection through shared tactics and tools. Insikt Group anticipates that TAG-124 will continue to evolve and attract more users within the cybercriminal ecosystem.",
          "modified": "2025-03-02T10:01:50.929000",
          "created": "2025-01-31T10:09:56.422000",
          "tags": [
            "TAG-124",
            "MintsLoader",
            "TA582",
            "CleanUpLoader",
            "REMCOS"
          ],
          "references": [
            "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
          ],
          "public": 1,
          "adversary": "TAG-124",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "CleanUpLoader",
              "display_name": "CleanUpLoader",
              "target": null
            },
            {
              "id": "MintsLoader",
              "display_name": "MintsLoader",
              "target": null
            },
            {
              "id": "PyInstaller",
              "display_name": "PyInstaller",
              "target": null
            },
            {
              "id": "Remcos - S0332",
              "display_name": "Remcos - S0332",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1583.003",
              "name": "Virtual Private Server",
              "display_name": "T1583.003 - Virtual Private Server"
            },
            {
              "id": "T1583.004",
              "name": "Server",
              "display_name": "T1583.004 - Server"
            },
            {
              "id": "T1584.001",
              "name": "Domains",
              "display_name": "T1584.001 - Domains"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1608.004",
              "name": "Drive-by Target",
              "display_name": "T1608.004 - Drive-by Target"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 109,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 30,
            "domain": 52
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386769,
          "modified_text": "456 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67a1f245f3709030a9f0ccb7",
          "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
          "description": "A report by Insikt Group, based on an analysis of compromised WordPress sites, outlines the threat posed by a network of cybercriminal servers known as TAG-124, which is used to distribute malware.",
          "modified": "2025-03-06T10:04:51.026000",
          "created": "2025-02-04T10:56:05.010000",
          "tags": [
            "tag124",
            "cloudflare",
            "wordpress",
            "insikt group",
            "figure",
            "google chrome",
            "future",
            "urls",
            "ta582",
            "fake google",
            "rhysida",
            "powershell",
            "april",
            "insikt",
            "remcos",
            "interlock"
          ],
          "references": [
            "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
          ],
          "public": 1,
          "adversary": "Insikt",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Insikt",
              "display_name": "Insikt",
              "target": null
            },
            {
              "id": "Rhysida",
              "display_name": "Rhysida",
              "target": null
            },
            {
              "id": "REMCOS",
              "display_name": "REMCOS",
              "target": null
            },
            {
              "id": "Interlock",
              "display_name": "Interlock",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 30,
            "FileHash-SHA1": 30,
            "FileHash-SHA256": 30,
            "URL": 2,
            "domain": 254,
            "hostname": 112
          },
          "indicator_count": 458,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 863,
          "modified_text": "452 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67a05ff9c25a98bbfd9ac6f8",
          "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
          "description": "",
          "modified": "2025-03-02T10:01:50.929000",
          "created": "2025-02-03T06:19:37.640000",
          "tags": [
            "TAG-124",
            "MintsLoader",
            "TA582",
            "CleanUpLoader",
            "REMCOS"
          ],
          "references": [
            "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
          ],
          "public": 1,
          "adversary": "TAG-124",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "CleanUpLoader",
              "display_name": "CleanUpLoader",
              "target": null
            },
            {
              "id": "MintsLoader",
              "display_name": "MintsLoader",
              "target": null
            },
            {
              "id": "PyInstaller",
              "display_name": "PyInstaller",
              "target": null
            },
            {
              "id": "Remcos - S0332",
              "display_name": "Remcos - S0332",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1583.003",
              "name": "Virtual Private Server",
              "display_name": "T1583.003 - Virtual Private Server"
            },
            {
              "id": "T1583.004",
              "name": "Server",
              "display_name": "T1583.004 - Server"
            },
            {
              "id": "T1584.001",
              "name": "Domains",
              "display_name": "T1584.001 - Domains"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1608.004",
              "name": "Drive-by Target",
              "display_name": "T1608.004 - Drive-by Target"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "679ca175bea14c5736a7310a",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Tr1sa111",
            "id": "192483",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 30,
            "domain": 52
          },
          "indicator_count": 96,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 278,
          "modified_text": "456 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "679ba047fa5e47a0f6e2c071",
          "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
          "description": "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base\n\nInsikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked by Recorded Future as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, 404TDS, KongTuke, and Chaya_002. TAG-124 comprises a network of compromised WordPress sites, actor-controlled payload servers, a central server, a suspected management server, an additional panel, and other components. The threat actors behind TAG-124 demonstrate high levels of activity, including regularly updating URLs embedded in the compromised WordPress sites, adding servers, refining TDS logic to evade detection, and adapting infection tactics, as demonstrated by their recent implementation of the ClickFix technique.",
          "modified": "2025-03-01T15:01:42.461000",
          "created": "2025-01-30T15:52:39.738000",
          "tags": [
            "fake google",
            "chrome update",
            "matomo instance",
            "remcos rat",
            "c2 ip",
            "address",
            "ta582",
            "hashes"
          ],
          "references": [],
          "public": 1,
          "adversary": "TAG-124",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Rhysida",
              "display_name": "Rhysida",
              "target": null
            },
            {
              "id": "Interlock",
              "display_name": "Interlock",
              "target": null
            },
            {
              "id": "SocGholish",
              "display_name": "SocGholish",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "InformationTechnogyISAC",
            "id": "141282",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 7,
            "FileHash-SHA1": 7,
            "FileHash-SHA256": 30,
            "domain": 234,
            "hostname": 105
          },
          "indicator_count": 383,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 43,
          "modified_text": "457 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
      ],
      "related": {
        "alienvault": {
          "adversary": [
            "TAG-124"
          ],
          "malware_families": [
            "Remcos - s0332",
            "Mintsloader",
            "Cleanuploader",
            "Pyinstaller"
          ],
          "industries": []
        },
        "other": {
          "adversary": [
            "TAG-124",
            "Insikt"
          ],
          "malware_families": [
            "Cleanuploader",
            "Socgholish",
            "Insikt",
            "Interlock",
            "Mintsloader",
            "Pyinstaller",
            "Remcos",
            "Remcos - s0332",
            "Rhysida"
          ],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "679ca175bea14c5736a7310a",
      "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
      "description": "Insikt Group has identified a complex infrastructure linked to the traffic distribution system TAG-124, which overlaps with several threat activity clusters and includes compromised WordPress sites and various servers. Multiple threat actors, including operators of Rhysida and Interlock ransomware, use TAG-124, reinforcing their connection through shared tactics and tools. Insikt Group anticipates that TAG-124 will continue to evolve and attract more users within the cybercriminal ecosystem.",
      "modified": "2025-03-02T10:01:50.929000",
      "created": "2025-01-31T10:09:56.422000",
      "tags": [
        "TAG-124",
        "MintsLoader",
        "TA582",
        "CleanUpLoader",
        "REMCOS"
      ],
      "references": [
        "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
      ],
      "public": 1,
      "adversary": "TAG-124",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "CleanUpLoader",
          "display_name": "CleanUpLoader",
          "target": null
        },
        {
          "id": "MintsLoader",
          "display_name": "MintsLoader",
          "target": null
        },
        {
          "id": "PyInstaller",
          "display_name": "PyInstaller",
          "target": null
        },
        {
          "id": "Remcos - S0332",
          "display_name": "Remcos - S0332",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1583.003",
          "name": "Virtual Private Server",
          "display_name": "T1583.003 - Virtual Private Server"
        },
        {
          "id": "T1583.004",
          "name": "Server",
          "display_name": "T1583.004 - Server"
        },
        {
          "id": "T1584.001",
          "name": "Domains",
          "display_name": "T1584.001 - Domains"
        },
        {
          "id": "T1587.001",
          "name": "Malware",
          "display_name": "T1587.001 - Malware"
        },
        {
          "id": "T1608.004",
          "name": "Drive-by Target",
          "display_name": "T1608.004 - Drive-by Target"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 109,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 7,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 30,
        "domain": 52
      },
      "indicator_count": 96,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386769,
      "modified_text": "456 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67a1f245f3709030a9f0ccb7",
      "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
      "description": "A report by Insikt Group, based on an analysis of compromised WordPress sites, outlines the threat posed by a network of cybercriminal servers known as TAG-124, which is used to distribute malware.",
      "modified": "2025-03-06T10:04:51.026000",
      "created": "2025-02-04T10:56:05.010000",
      "tags": [
        "tag124",
        "cloudflare",
        "wordpress",
        "insikt group",
        "figure",
        "google chrome",
        "future",
        "urls",
        "ta582",
        "fake google",
        "rhysida",
        "powershell",
        "april",
        "insikt",
        "remcos",
        "interlock"
      ],
      "references": [
        "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
      ],
      "public": 1,
      "adversary": "Insikt",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Insikt",
          "display_name": "Insikt",
          "target": null
        },
        {
          "id": "Rhysida",
          "display_name": "Rhysida",
          "target": null
        },
        {
          "id": "REMCOS",
          "display_name": "REMCOS",
          "target": null
        },
        {
          "id": "Interlock",
          "display_name": "Interlock",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 30,
        "FileHash-SHA1": 30,
        "FileHash-SHA256": 30,
        "URL": 2,
        "domain": 254,
        "hostname": 112
      },
      "indicator_count": 458,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 863,
      "modified_text": "452 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67a05ff9c25a98bbfd9ac6f8",
      "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
      "description": "",
      "modified": "2025-03-02T10:01:50.929000",
      "created": "2025-02-03T06:19:37.640000",
      "tags": [
        "TAG-124",
        "MintsLoader",
        "TA582",
        "CleanUpLoader",
        "REMCOS"
      ],
      "references": [
        "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base"
      ],
      "public": 1,
      "adversary": "TAG-124",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "CleanUpLoader",
          "display_name": "CleanUpLoader",
          "target": null
        },
        {
          "id": "MintsLoader",
          "display_name": "MintsLoader",
          "target": null
        },
        {
          "id": "PyInstaller",
          "display_name": "PyInstaller",
          "target": null
        },
        {
          "id": "Remcos - S0332",
          "display_name": "Remcos - S0332",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1583.003",
          "name": "Virtual Private Server",
          "display_name": "T1583.003 - Virtual Private Server"
        },
        {
          "id": "T1583.004",
          "name": "Server",
          "display_name": "T1583.004 - Server"
        },
        {
          "id": "T1584.001",
          "name": "Domains",
          "display_name": "T1584.001 - Domains"
        },
        {
          "id": "T1587.001",
          "name": "Malware",
          "display_name": "T1587.001 - Malware"
        },
        {
          "id": "T1608.004",
          "name": "Drive-by Target",
          "display_name": "T1608.004 - Drive-by Target"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "679ca175bea14c5736a7310a",
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Tr1sa111",
        "id": "192483",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 7,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 30,
        "domain": 52
      },
      "indicator_count": 96,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 278,
      "modified_text": "456 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "679ba047fa5e47a0f6e2c071",
      "name": "TAG-124\u2019s Multi-Layered TDS Infrastructure and Extensive User Base",
      "description": "https://www.recordedfuture.com/research/tag-124-multi-layered-tds-infrastructure-extensive-user-base\n\nInsikt Group has identified multi-layered infrastructure linked to a traffic distribution system (TDS) tracked by Recorded Future as TAG-124, which overlaps with threat activity clusters known as LandUpdate808, 404TDS, KongTuke, and Chaya_002. TAG-124 comprises a network of compromised WordPress sites, actor-controlled payload servers, a central server, a suspected management server, an additional panel, and other components. The threat actors behind TAG-124 demonstrate high levels of activity, including regularly updating URLs embedded in the compromised WordPress sites, adding servers, refining TDS logic to evade detection, and adapting infection tactics, as demonstrated by their recent implementation of the ClickFix technique.",
      "modified": "2025-03-01T15:01:42.461000",
      "created": "2025-01-30T15:52:39.738000",
      "tags": [
        "fake google",
        "chrome update",
        "matomo instance",
        "remcos rat",
        "c2 ip",
        "address",
        "ta582",
        "hashes"
      ],
      "references": [],
      "public": 1,
      "adversary": "TAG-124",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Rhysida",
          "display_name": "Rhysida",
          "target": null
        },
        {
          "id": "Interlock",
          "display_name": "Interlock",
          "target": null
        },
        {
          "id": "SocGholish",
          "display_name": "SocGholish",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "InformationTechnogyISAC",
        "id": "141282",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 7,
        "FileHash-SHA1": 7,
        "FileHash-SHA256": 30,
        "domain": 234,
        "hostname": 105
      },
      "indicator_count": 383,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 43,
      "modified_text": "457 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "getazurecommand.icu",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "getazurecommand.icu",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780355273.664918
}