{
  "type": "Domain",
  "indicator": "github.community",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/github.community",
    "alexa": "http://www.alexa.com/siteinfo/github.community",
    "indicator": "github.community",
    "type": "domain",
    "type_title": "Domain",
    "validation": [
      {
        "source": "whitelist",
        "message": "Whitelisted domain github.community",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 2081647561,
      "indicator": "github.community",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 8,
      "pulses": [
        {
          "id": "69228447b9c71795633314df",
          "name": "Keep Corrupt - University of Alberta Incidents continue to escalate - 04.24.26",
          "description": "Recovered accounts that have been used & abused - courtesy of decisions by non-technical leadership = accounts for UAlberta students -> PW manager made inaccessible (tied to UAlberta account) during a Data-Breach.\nWhen PW manager & Accounts returned, was populated by these (many = fraudulent; some appear to be abuse of legitimate services, while others do not, yet don't know function or origin)\n\nNot representative of OG PW manager. Many (most) accts. used/abused (on-going). \n\nDon't have a backup of original = hard to compare. Don't quite know what the majority of these companies etc. are for and/or do exactly. Putting them together as they roll-in.\nCan't turn them off in most cases - I don't have access to the U of A accounts these originate from and/or original recovery methods. \n\n2 more batches to add to this pulse (Need to add into VT) 02.16.26\n\nCountries listed are where 2 victims (UAlberta Graduates) have citizenship or some tie with.",
          "modified": "2026-05-24T21:18:51.782000",
          "created": "2025-11-23T03:49:27.649000",
          "tags": [
            "geoip",
            "as54113",
            "fastly",
            "as20940",
            "as15169",
            "google",
            "as214401",
            "maincubesas",
            "gmbh",
            "apache geoip",
            "facebook",
            "UAlberta",
            "AHS",
            "Treaty 8",
            "GoA",
            "Alberta",
            "Edmonton",
            "YEG"
          ],
          "references": [
            "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a",
            "URLscanio, FSio, vT",
            "03.11.14: https://www.virustotal.com/graph/embed/ge2e309eb8bd34fcca56398089b2291058dfe1fca69dc4e5aa66db0365caf735b?theme=dark",
            "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/summary",
            "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/iocs",
            "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a (11.22.25)"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Cura\u00e7ao",
            "Guatemala",
            "Sint Maarten (Dutch part)",
            "Tanzania, United Republic of",
            "Barbados",
            "United States of America",
            "Bahamas",
            "Anguilla",
            "Canada",
            "Saint Vincent and the Grenadines",
            "United Kingdom of Great Britain and Northern Ireland",
            "Kenya",
            "France",
            "Aruba",
            "Mexico",
            "Poland",
            "Costa Rica",
            "Ireland",
            "Trinidad and Tobago",
            "Netherlands",
            "Slovakia",
            "Spain",
            "Philippines"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government",
            "Technology",
            "Telecommunications",
            "Education",
            "Healthcare",
            "Finance",
            "Retail",
            "Hospitality",
            "Transportation"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 3,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CIDR": 47,
            "FileHash-MD5": 53,
            "FileHash-SHA1": 16,
            "FileHash-SHA256": 1059,
            "URL": 6374,
            "domain": 3314,
            "email": 1395,
            "hostname": 3740,
            "CVE": 1
          },
          "indicator_count": 15999,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 136,
          "modified_text": "6 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0dad06d8bb37ada19229bc",
          "name": "Credit:Q.Vashti [Exposing_Malware_in20_Linnux] - clone >post today had related items",
          "description": "",
          "modified": "2026-05-20T12:45:58.360000",
          "created": "2026-05-20T12:45:58.360000",
          "tags": [
            "ipv4",
            "url http",
            "expiration",
            "url https",
            "eid1338769034",
            "united",
            "unknown ns",
            "present jun",
            "unknown cname",
            "name servers",
            "search",
            "servers",
            "showing",
            "ip address",
            "creation date",
            "date",
            "encrypt",
            "sha256",
            "submitted",
            "passive dns",
            "urls",
            "address",
            "xmpg",
            "malware",
            "span",
            "extgstate",
            "bbox",
            "subtypeform",
            "rlength",
            "resource",
            "rfit",
            "pattern match",
            "path",
            "code",
            "cobalt strike",
            "false",
            "cloud",
            "core",
            "footer",
            "meta",
            "black",
            "ransomware",
            "r980",
            "facebook",
            "discord",
            "stream",
            "form",
            "contact",
            "story",
            "february",
            "rats",
            "stack",
            "defense",
            "launcher",
            "trace",
            "august",
            "hellokitty",
            "twitter",
            "upgrade",
            "android",
            "decryptor",
            "green",
            "enterprise",
            "team",
            "small",
            "systemd",
            "service",
            "python",
            "shell",
            "reload",
            "find",
            "haiduc",
            "hybrid",
            "general",
            "suspicious",
            "click",
            "strings",
            "iframe",
            "loader",
            "tools",
            "template",
            "daily",
            "hypervisor",
            "capture",
            "stars",
            "download",
            "copy",
            "cobaltstrike",
            "install",
            "madcap",
            "protect",
            "shift",
            "beyond",
            "leverage",
            "agent",
            "info",
            "xmrig",
            "attack",
            "demonbot",
            "multi",
            "live",
            "grep",
            "pass",
            "ri falsek",
            "process",
            "xobject",
            "format",
            "june",
            "crypto",
            "close",
            "learn",
            "ck id",
            "name tactics",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "apis",
            "found"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "684690d6dc730b0842d341a7",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 39,
            "FileHash-SHA1": 48,
            "FileHash-SHA256": 67,
            "domain": 173,
            "hostname": 110,
            "URL": 429,
            "email": 10
          },
          "indicator_count": 876,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "10 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0dacb22ae45efab0266fc2",
          "name": "Credit:Q.Vashti [Exposing_Malware_in20_Linnux] - clone >post today had related items",
          "description": "",
          "modified": "2026-05-20T12:44:34.775000",
          "created": "2026-05-20T12:44:34.775000",
          "tags": [
            "ipv4",
            "url http",
            "expiration",
            "url https",
            "eid1338769034",
            "united",
            "unknown ns",
            "present jun",
            "unknown cname",
            "name servers",
            "search",
            "servers",
            "showing",
            "ip address",
            "creation date",
            "date",
            "encrypt",
            "sha256",
            "submitted",
            "passive dns",
            "urls",
            "address",
            "xmpg",
            "malware",
            "span",
            "extgstate",
            "bbox",
            "subtypeform",
            "rlength",
            "resource",
            "rfit",
            "pattern match",
            "path",
            "code",
            "cobalt strike",
            "false",
            "cloud",
            "core",
            "footer",
            "meta",
            "black",
            "ransomware",
            "r980",
            "facebook",
            "discord",
            "stream",
            "form",
            "contact",
            "story",
            "february",
            "rats",
            "stack",
            "defense",
            "launcher",
            "trace",
            "august",
            "hellokitty",
            "twitter",
            "upgrade",
            "android",
            "decryptor",
            "green",
            "enterprise",
            "team",
            "small",
            "systemd",
            "service",
            "python",
            "shell",
            "reload",
            "find",
            "haiduc",
            "hybrid",
            "general",
            "suspicious",
            "click",
            "strings",
            "iframe",
            "loader",
            "tools",
            "template",
            "daily",
            "hypervisor",
            "capture",
            "stars",
            "download",
            "copy",
            "cobaltstrike",
            "install",
            "madcap",
            "protect",
            "shift",
            "beyond",
            "leverage",
            "agent",
            "info",
            "xmrig",
            "attack",
            "demonbot",
            "multi",
            "live",
            "grep",
            "pass",
            "ri falsek",
            "process",
            "xobject",
            "format",
            "june",
            "crypto",
            "close",
            "learn",
            "ck id",
            "name tactics",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "apis",
            "found"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "684690d6dc730b0842d341a7",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 39,
            "FileHash-SHA1": 48,
            "FileHash-SHA256": 67,
            "domain": 173,
            "hostname": 110,
            "URL": 429,
            "email": 10
          },
          "indicator_count": 876,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "10 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0dacb2971f3103a0dddbcc",
          "name": "Credit:Q.Vashti [Exposing_Malware_in20_Linnux] - clone >post today had related items",
          "description": "",
          "modified": "2026-05-20T12:44:34.547000",
          "created": "2026-05-20T12:44:34.547000",
          "tags": [
            "ipv4",
            "url http",
            "expiration",
            "url https",
            "eid1338769034",
            "united",
            "unknown ns",
            "present jun",
            "unknown cname",
            "name servers",
            "search",
            "servers",
            "showing",
            "ip address",
            "creation date",
            "date",
            "encrypt",
            "sha256",
            "submitted",
            "passive dns",
            "urls",
            "address",
            "xmpg",
            "malware",
            "span",
            "extgstate",
            "bbox",
            "subtypeform",
            "rlength",
            "resource",
            "rfit",
            "pattern match",
            "path",
            "code",
            "cobalt strike",
            "false",
            "cloud",
            "core",
            "footer",
            "meta",
            "black",
            "ransomware",
            "r980",
            "facebook",
            "discord",
            "stream",
            "form",
            "contact",
            "story",
            "february",
            "rats",
            "stack",
            "defense",
            "launcher",
            "trace",
            "august",
            "hellokitty",
            "twitter",
            "upgrade",
            "android",
            "decryptor",
            "green",
            "enterprise",
            "team",
            "small",
            "systemd",
            "service",
            "python",
            "shell",
            "reload",
            "find",
            "haiduc",
            "hybrid",
            "general",
            "suspicious",
            "click",
            "strings",
            "iframe",
            "loader",
            "tools",
            "template",
            "daily",
            "hypervisor",
            "capture",
            "stars",
            "download",
            "copy",
            "cobaltstrike",
            "install",
            "madcap",
            "protect",
            "shift",
            "beyond",
            "leverage",
            "agent",
            "info",
            "xmrig",
            "attack",
            "demonbot",
            "multi",
            "live",
            "grep",
            "pass",
            "ri falsek",
            "process",
            "xobject",
            "format",
            "june",
            "crypto",
            "close",
            "learn",
            "ck id",
            "name tactics",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "apis",
            "found"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "684690d6dc730b0842d341a7",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 39,
            "FileHash-SHA1": 48,
            "FileHash-SHA256": 67,
            "domain": 173,
            "hostname": 110,
            "URL": 429,
            "email": 10
          },
          "indicator_count": 876,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "10 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6941e87912ebb7843300906d",
          "name": "Telus Github",
          "description": "Telus has a Github. They are one of Canada's 'big 3' ISPs. They are compromised.",
          "modified": "2026-01-15T23:03:27.378000",
          "created": "2025-12-16T23:17:13.020000",
          "tags": [
            "type",
            "path",
            "secure",
            "date",
            "accept",
            "self",
            "httponly",
            "samesitelax",
            "expireswed",
            "updated",
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "prefetch8 ansi",
            "ansi",
            "show process",
            "hash seen",
            "threat level",
            "pcap",
            "sha256",
            "pcap processing",
            "ck id",
            "suspicious",
            "hybrid",
            "comspec",
            "close",
            "click",
            "hosts",
            "general",
            "model",
            "strings",
            "contact",
            "hybrid analysis",
            "api key",
            "vetting process",
            "please note",
            "please",
            "virus",
            "ransomware",
            "static",
            "indicator of compromise",
            "ioc",
            "extraction",
            "emulation",
            "platform",
            "javascript",
            "static analyzer",
            "analyzer"
          ],
          "references": [
            "http://hybrid-analysis.com/sample/f62e99ffe34a3f0c186ac31d151d22dd940884f79bbaafcc6061a2a9387f45a8/6941e0586df20223a505d490",
            "http://hybrid-analysis.com/sample/f62e99ffe34a3f0c186ac31d151d22dd940884f79bbaafcc6061a2a9387f45a8",
            "https://www.filescan.io/uploads/6941e02584afa5547b586bac/reports/a23ea43a-ad21-4306-9f47-1a8deaa129c0/ioc",
            "https://www.virustotal.com/gui/collection/5967f31c865dce02efd16cebad1e75bd838298965361912987dd932a513f9212/iocs",
            "https://www.virustotal.com/gui/collection/5967f31c865dce02efd16cebad1e75bd838298965361912987dd932a513f9212/summary",
            "https://app.threat.zone/submission/12b7b619-0e5a-4996-9bb5-493ef98f2803/url-analysis-report"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada",
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            }
          ],
          "industries": [
            "Telecommunications",
            "Technology",
            "Healthcare",
            "Education"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 32,
            "FileHash-SHA1": 31,
            "FileHash-SHA256": 31,
            "SSLCertFingerprint": 11,
            "URL": 197,
            "domain": 27,
            "email": 2,
            "hostname": 101
          },
          "indicator_count": 432,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 131,
          "modified_text": "135 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "684690d6dc730b0842d341a7",
          "name": "Exposing_Malware_in20Linux-Based_Multi-Cloud_Environments_R1Final.pdf",
          "description": "Falcon Sandbox: \nRansomware/Banking\nDetected indicator that file is ransomware\ndetails\n\"5 | Exposing Malware in Linux-Based Multi-Cloud Environments Ransomware and cryptominers Ransomware The impact of a ransomware attack can range from being a nuisance (e.g., having to restore data from backups and clean up the network) to being devastating (e.g., having to pay large sums of money to regain access to key assets). Unfortunately, when talking about cloud environments, the results tend to be more on the devastating side. Recently, cybercriminals have started calculating the damage they might cause to the valuation of a company going through a financial event to make the potential impact of their attack clear and incentivize ransom payments.5 At the same time, they\\x2122ve been honing their tactics with increasingly sophisticated techniques to target victim organizations\u2026more: https://www.hybrid-analysis.com/sample/92c1ca86f4d025e72acb94ae3cbdd3c6435aaa1b5e3fc3dcb06f8501b5dd3bb7/62e7fdd19a99ce4fa32e6d64",
          "modified": "2025-07-09T07:03:10.726000",
          "created": "2025-06-09T07:44:22.507000",
          "tags": [
            "ipv4",
            "url http",
            "expiration",
            "url https",
            "eid1338769034",
            "united",
            "unknown ns",
            "present jun",
            "unknown cname",
            "name servers",
            "search",
            "servers",
            "showing",
            "ip address",
            "creation date",
            "date",
            "encrypt",
            "sha256",
            "submitted",
            "passive dns",
            "urls",
            "address",
            "xmpg",
            "malware",
            "span",
            "extgstate",
            "bbox",
            "subtypeform",
            "rlength",
            "resource",
            "rfit",
            "pattern match",
            "path",
            "code",
            "cobalt strike",
            "false",
            "cloud",
            "core",
            "footer",
            "meta",
            "black",
            "ransomware",
            "r980",
            "facebook",
            "discord",
            "stream",
            "form",
            "contact",
            "story",
            "february",
            "rats",
            "stack",
            "defense",
            "launcher",
            "trace",
            "august",
            "hellokitty",
            "twitter",
            "upgrade",
            "android",
            "decryptor",
            "green",
            "enterprise",
            "team",
            "small",
            "systemd",
            "service",
            "python",
            "shell",
            "reload",
            "find",
            "haiduc",
            "hybrid",
            "general",
            "suspicious",
            "click",
            "strings",
            "iframe",
            "loader",
            "tools",
            "template",
            "daily",
            "hypervisor",
            "capture",
            "stars",
            "download",
            "copy",
            "cobaltstrike",
            "install",
            "madcap",
            "protect",
            "shift",
            "beyond",
            "leverage",
            "agent",
            "info",
            "xmrig",
            "attack",
            "demonbot",
            "multi",
            "live",
            "grep",
            "pass",
            "ri falsek",
            "process",
            "xobject",
            "format",
            "june",
            "crypto",
            "close",
            "learn",
            "ck id",
            "name tactics",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "apis",
            "found"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1016",
              "name": "System Network Configuration Discovery",
              "display_name": "T1016 - System Network Configuration Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1489",
              "name": "Service Stop",
              "display_name": "T1489 - Service Stop"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1530",
              "name": "Data from Cloud Storage Object",
              "display_name": "T1530 - Data from Cloud Storage Object"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 39,
            "FileHash-SHA1": 48,
            "FileHash-SHA256": 67,
            "domain": 173,
            "hostname": 110,
            "URL": 429,
            "email": 10
          },
          "indicator_count": 876,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "326 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707f99cdb1ac2e75738328",
          "name": "https://github.com/WSP-LAB/FUGIO",
          "description": "",
          "modified": "2023-12-06T14:05:13.366000",
          "created": "2023-12-06T14:05:13.366000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 156,
            "hostname": 31,
            "domain": 4,
            "URL": 22,
            "FileHash-MD5": 2
          },
          "indicator_count": 215,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "621d2887ea4e51d3704ed7aa",
          "name": "https://github.com/WSP-LAB/FUGIO",
          "description": "",
          "modified": "2022-02-28T19:54:47.152000",
          "created": "2022-02-28T19:54:47.152000",
          "tags": [
            "php object",
            "path",
            "secure",
            "samesitelax",
            "github",
            "submission",
            "uymikh0a",
            "httponly",
            "expirestue",
            "self",
            "accept"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 156,
            "hostname": 31,
            "domain": 4,
            "URL": 22,
            "FileHash-MD5": 2
          },
          "indicator_count": 215,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 405,
          "modified_text": "1552 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/summary",
        "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/iocs",
        "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a",
        "https://app.threat.zone/submission/12b7b619-0e5a-4996-9bb5-493ef98f2803/url-analysis-report",
        "URLscanio, FSio, vT",
        "https://www.filescan.io/uploads/6941e02584afa5547b586bac/reports/a23ea43a-ad21-4306-9f47-1a8deaa129c0/ioc",
        "https://www.virustotal.com/gui/collection/5967f31c865dce02efd16cebad1e75bd838298965361912987dd932a513f9212/summary",
        "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a (11.22.25)",
        "http://hybrid-analysis.com/sample/f62e99ffe34a3f0c186ac31d151d22dd940884f79bbaafcc6061a2a9387f45a8/6941e0586df20223a505d490",
        "https://www.virustotal.com/gui/collection/5967f31c865dce02efd16cebad1e75bd838298965361912987dd932a513f9212/iocs",
        "03.11.14: https://www.virustotal.com/graph/embed/ge2e309eb8bd34fcca56398089b2291058dfe1fca69dc4e5aa66db0365caf735b?theme=dark",
        "http://hybrid-analysis.com/sample/f62e99ffe34a3f0c186ac31d151d22dd940884f79bbaafcc6061a2a9387f45a8"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Cobalt strike"
          ],
          "industries": [
            "Telecommunications",
            "Retail",
            "Healthcare",
            "Technology",
            "Hospitality",
            "Transportation",
            "Finance",
            "Government",
            "Education"
          ]
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 8,
  "pulses": [
    {
      "id": "69228447b9c71795633314df",
      "name": "Keep Corrupt - University of Alberta Incidents continue to escalate - 04.24.26",
      "description": "Recovered accounts that have been used & abused - courtesy of decisions by non-technical leadership = accounts for UAlberta students -> PW manager made inaccessible (tied to UAlberta account) during a Data-Breach.\nWhen PW manager & Accounts returned, was populated by these (many = fraudulent; some appear to be abuse of legitimate services, while others do not, yet don't know function or origin)\n\nNot representative of OG PW manager. Many (most) accts. used/abused (on-going). \n\nDon't have a backup of original = hard to compare. Don't quite know what the majority of these companies etc. are for and/or do exactly. Putting them together as they roll-in.\nCan't turn them off in most cases - I don't have access to the U of A accounts these originate from and/or original recovery methods. \n\n2 more batches to add to this pulse (Need to add into VT) 02.16.26\n\nCountries listed are where 2 victims (UAlberta Graduates) have citizenship or some tie with.",
      "modified": "2026-05-24T21:18:51.782000",
      "created": "2025-11-23T03:49:27.649000",
      "tags": [
        "geoip",
        "as54113",
        "fastly",
        "as20940",
        "as15169",
        "google",
        "as214401",
        "maincubesas",
        "gmbh",
        "apache geoip",
        "facebook",
        "UAlberta",
        "AHS",
        "Treaty 8",
        "GoA",
        "Alberta",
        "Edmonton",
        "YEG"
      ],
      "references": [
        "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a",
        "URLscanio, FSio, vT",
        "03.11.14: https://www.virustotal.com/graph/embed/ge2e309eb8bd34fcca56398089b2291058dfe1fca69dc4e5aa66db0365caf735b?theme=dark",
        "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/summary",
        "https://www.virustotal.com/gui/collection/6a41ae1cf2d3d51fedd2393d893c3b26ed0352dde2e0851d03f0bae9aaa69ae1/iocs",
        "https://viz.greynoise.io/ip/analysis/3cf1334a-df9d-448f-8145-d5fe67637c1a (11.22.25)"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Cura\u00e7ao",
        "Guatemala",
        "Sint Maarten (Dutch part)",
        "Tanzania, United Republic of",
        "Barbados",
        "United States of America",
        "Bahamas",
        "Anguilla",
        "Canada",
        "Saint Vincent and the Grenadines",
        "United Kingdom of Great Britain and Northern Ireland",
        "Kenya",
        "France",
        "Aruba",
        "Mexico",
        "Poland",
        "Costa Rica",
        "Ireland",
        "Trinidad and Tobago",
        "Netherlands",
        "Slovakia",
        "Spain",
        "Philippines"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Government",
        "Technology",
        "Telecommunications",
        "Education",
        "Healthcare",
        "Finance",
        "Retail",
        "Hospitality",
        "Transportation"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 3,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CIDR": 47,
        "FileHash-MD5": 53,
        "FileHash-SHA1": 16,
        "FileHash-SHA256": 1059,
        "URL": 6374,
        "domain": 3314,
        "email": 1395,
        "hostname": 3740,
        "CVE": 1
      },
      "indicator_count": 15999,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 136,
      "modified_text": "6 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0dad06d8bb37ada19229bc",
      "name": "Credit:Q.Vashti [Exposing_Malware_in20_Linnux] - clone >post today had related items",
      "description": "",
      "modified": "2026-05-20T12:45:58.360000",
      "created": "2026-05-20T12:45:58.360000",
      "tags": [
        "ipv4",
        "url http",
        "expiration",
        "url https",
        "eid1338769034",
        "united",
        "unknown ns",
        "present jun",
        "unknown cname",
        "name servers",
        "search",
        "servers",
        "showing",
        "ip address",
        "creation date",
        "date",
        "encrypt",
        "sha256",
        "submitted",
        "passive dns",
        "urls",
        "address",
        "xmpg",
        "malware",
        "span",
        "extgstate",
        "bbox",
        "subtypeform",
        "rlength",
        "resource",
        "rfit",
        "pattern match",
        "path",
        "code",
        "cobalt strike",
        "false",
        "cloud",
        "core",
        "footer",
        "meta",
        "black",
        "ransomware",
        "r980",
        "facebook",
        "discord",
        "stream",
        "form",
        "contact",
        "story",
        "february",
        "rats",
        "stack",
        "defense",
        "launcher",
        "trace",
        "august",
        "hellokitty",
        "twitter",
        "upgrade",
        "android",
        "decryptor",
        "green",
        "enterprise",
        "team",
        "small",
        "systemd",
        "service",
        "python",
        "shell",
        "reload",
        "find",
        "haiduc",
        "hybrid",
        "general",
        "suspicious",
        "click",
        "strings",
        "iframe",
        "loader",
        "tools",
        "template",
        "daily",
        "hypervisor",
        "capture",
        "stars",
        "download",
        "copy",
        "cobaltstrike",
        "install",
        "madcap",
        "protect",
        "shift",
        "beyond",
        "leverage",
        "agent",
        "info",
        "xmrig",
        "attack",
        "demonbot",
        "multi",
        "live",
        "grep",
        "pass",
        "ri falsek",
        "process",
        "xobject",
        "format",
        "june",
        "crypto",
        "close",
        "learn",
        "ck id",
        "name tactics",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "apis",
        "found"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1530",
          "name": "Data from Cloud Storage Object",
          "display_name": "T1530 - Data from Cloud Storage Object"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "684690d6dc730b0842d341a7",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 39,
        "FileHash-SHA1": 48,
        "FileHash-SHA256": 67,
        "domain": 173,
        "hostname": 110,
        "URL": 429,
        "email": 10
      },
      "indicator_count": 876,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "10 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0dacb22ae45efab0266fc2",
      "name": "Credit:Q.Vashti [Exposing_Malware_in20_Linnux] - clone >post today had related items",
      "description": "",
      "modified": "2026-05-20T12:44:34.775000",
      "created": "2026-05-20T12:44:34.775000",
      "tags": [
        "ipv4",
        "url http",
        "expiration",
        "url https",
        "eid1338769034",
        "united",
        "unknown ns",
        "present jun",
        "unknown cname",
        "name servers",
        "search",
        "servers",
        "showing",
        "ip address",
        "creation date",
        "date",
        "encrypt",
        "sha256",
        "submitted",
        "passive dns",
        "urls",
        "address",
        "xmpg",
        "malware",
        "span",
        "extgstate",
        "bbox",
        "subtypeform",
        "rlength",
        "resource",
        "rfit",
        "pattern match",
        "path",
        "code",
        "cobalt strike",
        "false",
        "cloud",
        "core",
        "footer",
        "meta",
        "black",
        "ransomware",
        "r980",
        "facebook",
        "discord",
        "stream",
        "form",
        "contact",
        "story",
        "february",
        "rats",
        "stack",
        "defense",
        "launcher",
        "trace",
        "august",
        "hellokitty",
        "twitter",
        "upgrade",
        "android",
        "decryptor",
        "green",
        "enterprise",
        "team",
        "small",
        "systemd",
        "service",
        "python",
        "shell",
        "reload",
        "find",
        "haiduc",
        "hybrid",
        "general",
        "suspicious",
        "click",
        "strings",
        "iframe",
        "loader",
        "tools",
        "template",
        "daily",
        "hypervisor",
        "capture",
        "stars",
        "download",
        "copy",
        "cobaltstrike",
        "install",
        "madcap",
        "protect",
        "shift",
        "beyond",
        "leverage",
        "agent",
        "info",
        "xmrig",
        "attack",
        "demonbot",
        "multi",
        "live",
        "grep",
        "pass",
        "ri falsek",
        "process",
        "xobject",
        "format",
        "june",
        "crypto",
        "close",
        "learn",
        "ck id",
        "name tactics",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "apis",
        "found"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1530",
          "name": "Data from Cloud Storage Object",
          "display_name": "T1530 - Data from Cloud Storage Object"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "684690d6dc730b0842d341a7",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 39,
        "FileHash-SHA1": 48,
        "FileHash-SHA256": 67,
        "domain": 173,
        "hostname": 110,
        "URL": 429,
        "email": 10
      },
      "indicator_count": 876,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "10 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0dacb2971f3103a0dddbcc",
      "name": "Credit:Q.Vashti [Exposing_Malware_in20_Linnux] - clone >post today had related items",
      "description": "",
      "modified": "2026-05-20T12:44:34.547000",
      "created": "2026-05-20T12:44:34.547000",
      "tags": [
        "ipv4",
        "url http",
        "expiration",
        "url https",
        "eid1338769034",
        "united",
        "unknown ns",
        "present jun",
        "unknown cname",
        "name servers",
        "search",
        "servers",
        "showing",
        "ip address",
        "creation date",
        "date",
        "encrypt",
        "sha256",
        "submitted",
        "passive dns",
        "urls",
        "address",
        "xmpg",
        "malware",
        "span",
        "extgstate",
        "bbox",
        "subtypeform",
        "rlength",
        "resource",
        "rfit",
        "pattern match",
        "path",
        "code",
        "cobalt strike",
        "false",
        "cloud",
        "core",
        "footer",
        "meta",
        "black",
        "ransomware",
        "r980",
        "facebook",
        "discord",
        "stream",
        "form",
        "contact",
        "story",
        "february",
        "rats",
        "stack",
        "defense",
        "launcher",
        "trace",
        "august",
        "hellokitty",
        "twitter",
        "upgrade",
        "android",
        "decryptor",
        "green",
        "enterprise",
        "team",
        "small",
        "systemd",
        "service",
        "python",
        "shell",
        "reload",
        "find",
        "haiduc",
        "hybrid",
        "general",
        "suspicious",
        "click",
        "strings",
        "iframe",
        "loader",
        "tools",
        "template",
        "daily",
        "hypervisor",
        "capture",
        "stars",
        "download",
        "copy",
        "cobaltstrike",
        "install",
        "madcap",
        "protect",
        "shift",
        "beyond",
        "leverage",
        "agent",
        "info",
        "xmrig",
        "attack",
        "demonbot",
        "multi",
        "live",
        "grep",
        "pass",
        "ri falsek",
        "process",
        "xobject",
        "format",
        "june",
        "crypto",
        "close",
        "learn",
        "ck id",
        "name tactics",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "apis",
        "found"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1530",
          "name": "Data from Cloud Storage Object",
          "display_name": "T1530 - Data from Cloud Storage Object"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "684690d6dc730b0842d341a7",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 39,
        "FileHash-SHA1": 48,
        "FileHash-SHA256": 67,
        "domain": 173,
        "hostname": 110,
        "URL": 429,
        "email": 10
      },
      "indicator_count": 876,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "10 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6941e87912ebb7843300906d",
      "name": "Telus Github",
      "description": "Telus has a Github. They are one of Canada's 'big 3' ISPs. They are compromised.",
      "modified": "2026-01-15T23:03:27.378000",
      "created": "2025-12-16T23:17:13.020000",
      "tags": [
        "type",
        "path",
        "secure",
        "date",
        "accept",
        "self",
        "httponly",
        "samesitelax",
        "expireswed",
        "updated",
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "prefetch8 ansi",
        "ansi",
        "show process",
        "hash seen",
        "threat level",
        "pcap",
        "sha256",
        "pcap processing",
        "ck id",
        "suspicious",
        "hybrid",
        "comspec",
        "close",
        "click",
        "hosts",
        "general",
        "model",
        "strings",
        "contact",
        "hybrid analysis",
        "api key",
        "vetting process",
        "please note",
        "please",
        "virus",
        "ransomware",
        "static",
        "indicator of compromise",
        "ioc",
        "extraction",
        "emulation",
        "platform",
        "javascript",
        "static analyzer",
        "analyzer"
      ],
      "references": [
        "http://hybrid-analysis.com/sample/f62e99ffe34a3f0c186ac31d151d22dd940884f79bbaafcc6061a2a9387f45a8/6941e0586df20223a505d490",
        "http://hybrid-analysis.com/sample/f62e99ffe34a3f0c186ac31d151d22dd940884f79bbaafcc6061a2a9387f45a8",
        "https://www.filescan.io/uploads/6941e02584afa5547b586bac/reports/a23ea43a-ad21-4306-9f47-1a8deaa129c0/ioc",
        "https://www.virustotal.com/gui/collection/5967f31c865dce02efd16cebad1e75bd838298965361912987dd932a513f9212/iocs",
        "https://www.virustotal.com/gui/collection/5967f31c865dce02efd16cebad1e75bd838298965361912987dd932a513f9212/summary",
        "https://app.threat.zone/submission/12b7b619-0e5a-4996-9bb5-493ef98f2803/url-analysis-report"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada",
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        }
      ],
      "industries": [
        "Telecommunications",
        "Technology",
        "Healthcare",
        "Education"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 32,
        "FileHash-SHA1": 31,
        "FileHash-SHA256": 31,
        "SSLCertFingerprint": 11,
        "URL": 197,
        "domain": 27,
        "email": 2,
        "hostname": 101
      },
      "indicator_count": 432,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 131,
      "modified_text": "135 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "684690d6dc730b0842d341a7",
      "name": "Exposing_Malware_in20Linux-Based_Multi-Cloud_Environments_R1Final.pdf",
      "description": "Falcon Sandbox: \nRansomware/Banking\nDetected indicator that file is ransomware\ndetails\n\"5 | Exposing Malware in Linux-Based Multi-Cloud Environments Ransomware and cryptominers Ransomware The impact of a ransomware attack can range from being a nuisance (e.g., having to restore data from backups and clean up the network) to being devastating (e.g., having to pay large sums of money to regain access to key assets). Unfortunately, when talking about cloud environments, the results tend to be more on the devastating side. Recently, cybercriminals have started calculating the damage they might cause to the valuation of a company going through a financial event to make the potential impact of their attack clear and incentivize ransom payments.5 At the same time, they\\x2122ve been honing their tactics with increasingly sophisticated techniques to target victim organizations\u2026more: https://www.hybrid-analysis.com/sample/92c1ca86f4d025e72acb94ae3cbdd3c6435aaa1b5e3fc3dcb06f8501b5dd3bb7/62e7fdd19a99ce4fa32e6d64",
      "modified": "2025-07-09T07:03:10.726000",
      "created": "2025-06-09T07:44:22.507000",
      "tags": [
        "ipv4",
        "url http",
        "expiration",
        "url https",
        "eid1338769034",
        "united",
        "unknown ns",
        "present jun",
        "unknown cname",
        "name servers",
        "search",
        "servers",
        "showing",
        "ip address",
        "creation date",
        "date",
        "encrypt",
        "sha256",
        "submitted",
        "passive dns",
        "urls",
        "address",
        "xmpg",
        "malware",
        "span",
        "extgstate",
        "bbox",
        "subtypeform",
        "rlength",
        "resource",
        "rfit",
        "pattern match",
        "path",
        "code",
        "cobalt strike",
        "false",
        "cloud",
        "core",
        "footer",
        "meta",
        "black",
        "ransomware",
        "r980",
        "facebook",
        "discord",
        "stream",
        "form",
        "contact",
        "story",
        "february",
        "rats",
        "stack",
        "defense",
        "launcher",
        "trace",
        "august",
        "hellokitty",
        "twitter",
        "upgrade",
        "android",
        "decryptor",
        "green",
        "enterprise",
        "team",
        "small",
        "systemd",
        "service",
        "python",
        "shell",
        "reload",
        "find",
        "haiduc",
        "hybrid",
        "general",
        "suspicious",
        "click",
        "strings",
        "iframe",
        "loader",
        "tools",
        "template",
        "daily",
        "hypervisor",
        "capture",
        "stars",
        "download",
        "copy",
        "cobaltstrike",
        "install",
        "madcap",
        "protect",
        "shift",
        "beyond",
        "leverage",
        "agent",
        "info",
        "xmrig",
        "attack",
        "demonbot",
        "multi",
        "live",
        "grep",
        "pass",
        "ri falsek",
        "process",
        "xobject",
        "format",
        "june",
        "crypto",
        "close",
        "learn",
        "ck id",
        "name tactics",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "apis",
        "found"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1016",
          "name": "System Network Configuration Discovery",
          "display_name": "T1016 - System Network Configuration Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1489",
          "name": "Service Stop",
          "display_name": "T1489 - Service Stop"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1530",
          "name": "Data from Cloud Storage Object",
          "display_name": "T1530 - Data from Cloud Storage Object"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 33,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 39,
        "FileHash-SHA1": 48,
        "FileHash-SHA256": 67,
        "domain": 173,
        "hostname": 110,
        "URL": 429,
        "email": 10
      },
      "indicator_count": 876,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "326 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707f99cdb1ac2e75738328",
      "name": "https://github.com/WSP-LAB/FUGIO",
      "description": "",
      "modified": "2023-12-06T14:05:13.366000",
      "created": "2023-12-06T14:05:13.366000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 156,
        "hostname": 31,
        "domain": 4,
        "URL": 22,
        "FileHash-MD5": 2
      },
      "indicator_count": 215,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "621d2887ea4e51d3704ed7aa",
      "name": "https://github.com/WSP-LAB/FUGIO",
      "description": "",
      "modified": "2022-02-28T19:54:47.152000",
      "created": "2022-02-28T19:54:47.152000",
      "tags": [
        "php object",
        "path",
        "secure",
        "samesitelax",
        "github",
        "submission",
        "uymikh0a",
        "httponly",
        "expirestue",
        "self",
        "accept"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 156,
        "hostname": 31,
        "domain": 4,
        "URL": 22,
        "FileHash-MD5": 2
      },
      "indicator_count": 215,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 405,
      "modified_text": "1552 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "github.community",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "github.community",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780223542.790544
}