{
  "type": "Domain",
  "indicator": "host.id",
  "general": {
    "sections": [
      "general",
      "geo",
      "url_list",
      "passive_dns",
      "malware",
      "whois",
      "http_scans"
    ],
    "whois": "http://whois.domaintools.com/host.id",
    "alexa": "http://www.alexa.com/siteinfo/host.id",
    "indicator": "host.id",
    "type": "domain",
    "type_title": "Domain",
    "validation": [],
    "base_indicator": {
      "id": 1458019018,
      "indicator": "host.id",
      "type": "domain",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 8,
      "pulses": [
        {
          "id": "67ff12aea0b9ba91d923da14",
          "name": "Threat Actor Profile: El Machete",
          "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
          "modified": "2025-04-16T02:15:10.602000",
          "created": "2025-04-16T02:15:10.602000",
          "tags": [
            "threat_actor",
            "unknown",
            "T1497",
            "T1114",
            "T1566.001",
            "T1059.003",
            "T1081",
            "T1059.006",
            "T1059",
            "T1566.002",
            "T1082",
            "T1027",
            "T1071.001",
            "T1566",
            "T1041",
            "T1105",
            "T1204.001",
            "T1049",
            "T1055",
            "T1036",
            "T1503",
            "T1114.001",
            "T1053",
            "T1140",
            "T1012",
            "T1071",
            "T1112",
            "T1036.005",
            "T1547",
            "T1057",
            "T1008",
            "T1518",
            "T1021",
            "T1011",
            "T1060",
            "T1539",
            "T1587",
            "T1087",
            "T1095",
            "T1102",
            "T1070",
            "T1130",
            "T1552",
            "T1106",
            "T1190",
            "T1007",
            "T1133",
            "T1090",
            "T1016",
            "T1137",
            "T1119",
            "T1124",
            "T1005",
            "T1059.001",
            "T1115",
            "T1562.001",
            "T1543",
            "T1078",
            "T1083",
            "T1530",
            "T1085",
            "T1003",
            "T1120",
            "T1218",
            "T1048",
            "T1553",
            "T1490",
            "T1497.003",
            "T1571",
            "T1204.002",
            "T1595.002",
            "T1102.002",
            "T1583.003",
            "T1027.009",
            "T1027.013",
            "T1132",
            "T1562",
            "T1110",
            "T1059.005",
            "T1218.007",
            "T1204",
            "T1550",
            "T1136",
            "T1555",
            "T1176",
            "T1204_-_User_Execution",
            "T1566_-_Phishing",
            "T1561",
            "T1583",
            "T1485",
            "T1127",
            "T1595",
            "T1573",
            "T1189",
            "T1486",
            "T1531",
            "T1529",
            "T1053.005",
            "T1047.",
            "target:Dominican Republic",
            "target:Venezuela",
            "target:Italy",
            "target:Colombia",
            "target:Ecuador",
            "target:Guatemala",
            "target:Belgium",
            "target:Malaysia",
            "target:Brazil",
            "target:France",
            "target:Indonesia",
            "target:United Kingdom",
            "target:China",
            "target:Germany",
            "target:Mexico",
            "target:Argentina",
            "target:Netherlands",
            "target:Japan",
            "target:Bolivia",
            "target:Yibuti",
            "target:Vietnam",
            "target:Fiyi",
            "target:Cuba",
            "target:Camboya",
            "target:Taiw\u00e1n",
            "target:United States",
            "target:Sweden",
            "target:Ukraine",
            "target:South Korea",
            "target:Nicaragua",
            "target:Canada",
            "target:Russia",
            "target:otros"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 9,
            "hostname": 18,
            "domain": 59
          },
          "indicator_count": 86,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 56,
          "modified_text": "410 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ff1245d4dc2a56e5561a57",
          "name": "Threat Actor Profile: El Machete",
          "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
          "modified": "2025-04-16T02:13:25.801000",
          "created": "2025-04-16T02:13:25.801000",
          "tags": [
            "threat_actor",
            "unknown",
            "T1497",
            "T1114",
            "T1566.001",
            "T1059.003",
            "T1081",
            "T1059.006",
            "T1059",
            "T1566.002",
            "T1082",
            "T1027",
            "T1071.001",
            "T1566",
            "T1041",
            "T1105",
            "T1204.001",
            "T1049",
            "T1055",
            "T1036",
            "T1503",
            "T1114.001",
            "T1053",
            "T1140",
            "T1012",
            "T1071",
            "T1112",
            "T1036.005",
            "T1547",
            "T1057",
            "T1008",
            "T1518",
            "T1021",
            "T1011",
            "T1060",
            "T1539",
            "T1587",
            "T1087",
            "T1095",
            "T1102",
            "T1070",
            "T1130",
            "T1552",
            "T1106",
            "T1190",
            "T1007",
            "T1133",
            "T1090",
            "T1016",
            "T1137",
            "T1119",
            "T1124",
            "T1005",
            "T1059.001",
            "T1115",
            "T1562.001",
            "T1543",
            "T1078",
            "T1083",
            "T1530",
            "T1085",
            "T1003",
            "T1120",
            "T1218",
            "T1048",
            "T1553",
            "T1490",
            "T1497.003",
            "T1571",
            "T1204.002",
            "T1595.002",
            "T1102.002",
            "T1583.003",
            "T1027.009",
            "T1027.013",
            "T1132",
            "T1562",
            "T1110",
            "T1059.005",
            "T1218.007",
            "T1204",
            "T1550",
            "T1136",
            "T1555",
            "T1176",
            "T1204_-_User_Execution",
            "T1566_-_Phishing",
            "T1561",
            "T1583",
            "T1485",
            "T1127",
            "T1595",
            "T1573",
            "T1189",
            "T1486",
            "T1531",
            "T1529",
            "T1053.005",
            "T1047.",
            "target:Dominican Republic",
            "target:Venezuela",
            "target:Italy",
            "target:Colombia",
            "target:Ecuador",
            "target:Guatemala",
            "target:Belgium",
            "target:Malaysia",
            "target:Brazil",
            "target:France",
            "target:Indonesia",
            "target:United Kingdom",
            "target:China",
            "target:Germany",
            "target:Mexico",
            "target:Argentina",
            "target:Netherlands",
            "target:Japan",
            "target:Bolivia",
            "target:Yibuti",
            "target:Vietnam",
            "target:Fiyi",
            "target:Cuba",
            "target:Camboya",
            "target:Taiw\u00e1n",
            "target:United States",
            "target:Sweden",
            "target:Ukraine",
            "target:South Korea",
            "target:Nicaragua",
            "target:Canada",
            "target:Russia",
            "target:otros"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 9,
            "hostname": 18,
            "domain": 59
          },
          "indicator_count": 86,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 56,
          "modified_text": "410 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6773390f17d71879c414676a",
          "name": "El Machete",
          "description": "El Machete es un grupo de ciberespionaje activo desde al menos 2014, enfocado en atacar principalmente a naciones de habla hispana. Este grupo es conocido por su sofisticada malware y t\u00e1cticas de exfiltraci\u00f3n de datos, con un enfoque en objetivos de alto perfil, como agencias gubernamentales y organizaciones estrat\u00e9gicas.",
          "modified": "2025-01-30T00:00:18.927000",
          "created": "2024-12-31T00:21:35.813000",
          "tags": [
            "cve201711882",
            "cve20201472",
            "El Machete"
          ],
          "references": [],
          "public": 1,
          "adversary": "El Machete",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 473,
            "FileHash-SHA1": 471,
            "FileHash-SHA256": 500,
            "CVE": 9,
            "domain": 60,
            "hostname": 18
          },
          "indicator_count": 1531,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 60,
          "modified_text": "486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "67733b72d522398f5ea0a12d",
          "name": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar",
          "description": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar con Intereses en la Administraci\u00f3n P\u00fablica de la Rep\u00fablica Dominicana, Diciembre 2024",
          "modified": "2025-01-30T00:00:18.927000",
          "created": "2024-12-31T00:31:46.858000",
          "tags": [
            "cve201711882",
            "cve20201472"
          ],
          "references": [],
          "public": 1,
          "adversary": "El Machete, TAG-100, Mirage, Unamed_Grooup",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "fraevolquez",
            "id": "91700",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2631,
            "FileHash-SHA1": 2168,
            "FileHash-SHA256": 3401,
            "CVE": 25,
            "domain": 977,
            "hostname": 1226
          },
          "indicator_count": 10428,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "486 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "672025a446db1f324cbda420",
          "name": "Katz and Mouse Game:  MaaS Infostealers Adapt to Patched Chrome Defenses \u2014 Elastic Security Labs",
          "description": "",
          "modified": "2024-10-29T00:00:36.726000",
          "created": "2024-10-29T00:00:36.726000",
          "tags": [
            "chrome",
            "stealc",
            "lumma",
            "google",
            "september",
            "chromekatz",
            "google chrome",
            "chrome process",
            "windows",
            "july",
            "team",
            "vidar",
            "metastealer",
            "legacy"
          ],
          "references": [
            "https://www.elastic.co/security-labs/katz-and-mouse-game"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ChrisTan0",
            "id": "262536",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-MD5": 2,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 5,
            "YARA": 1,
            "domain": 4
          },
          "indicator_count": 15,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 42,
          "modified_text": "579 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "652e382249b6450188a20316",
          "name": "New BLISTER Malware Involved in Network Infiltration",
          "description": "",
          "modified": "2023-11-16T07:01:26.974000",
          "created": "2023-10-17T07:30:42.274000",
          "tags": [
            "blister",
            "blister loader",
            "security labs",
            "labs",
            "elastic",
            "new development",
            "palo alto",
            "mythic",
            "vlc dll",
            "different",
            "august",
            "virustotal",
            "june",
            "test",
            "trojan",
            "persistence",
            "blister malware",
            "strong",
            "security",
            "startup folder",
            "execution",
            "binary proxy",
            "malware",
            "cobaltstrike",
            "bitrat",
            "urls",
            "please",
            "javascript",
            "group",
            "push",
            "team",
            "red dev",
            "bitrat malware",
            "xmm0",
            "pla unit",
            "maria bitrat",
            "nanocore rat",
            "ave maria",
            "jackal",
            "nodestealer",
            "bomb",
            "discord",
            "purecrypter",
            "quasar rat",
            "avemariarat",
            "hido",
            "powershell",
            "melissa",
            "netwire rc",
            "oilrig",
            "mask",
            "bluenoroff",
            "panda",
            "back",
            "xworm",
            "xavier",
            "adobot",
            "orcus rat",
            "pandora rat",
            "raccoon",
            "vlad",
            "bill",
            "tinynuke",
            "remcos",
            "cobalt strike",
            "zloader",
            "agent tesla",
            "ficker stealer",
            "avemaria",
            "download",
            "stealth mango",
            "ixeshe",
            "aluminum",
            "msupdater",
            "nettraveler",
            "keyboy",
            "sednit",
            "sofacy",
            "oceanlotus",
            "holmium",
            "scarcruft",
            "venus",
            "sykipot",
            "leviathan",
            "amoeba",
            "hoodoo",
            "dragon",
            "star",
            "matanbuchus",
            "comnie",
            "termite",
            "emdivi",
            "greenbug",
            "careto",
            "cobalt",
            "cyber",
            "icefog",
            "trident",
            "dnspionage",
            "darkhotel",
            "luder",
            "nemim",
            "tapaoux",
            "pioneer",
            "havex",
            "machete",
            "evilnum",
            "carbanak",
            "gcman",
            "ghostnet",
            "bitter",
            "infy",
            "karakurt",
            "kinsing",
            "mercury",
            "naikon",
            "nitro",
            "strongpity",
            "powerpool",
            "indra",
            "sauron",
            "sidewinder",
            "redalpha",
            "mantis",
            "rocke",
            "mimic",
            "silence",
            "guardian",
            "teamspy",
            "teamtnt",
            "teamxrat",
            "turla",
            "snake",
            "wraith",
            "pfinet",
            "krypton",
            "zoopark",
            "sha256 trend",
            "micro detection",
            "script c",
            "unique string",
            "windows",
            "lnk file",
            "windows native",
            "payload",
            "launchcolorcpl",
            "amadey",
            "clipbanker",
            "launch",
            "apache"
          ],
          "references": [
            "September 06th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3180 - New BLISTER Malware Involved in Network Infiltration.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 74,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "cryptocti",
            "id": "110256",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 57,
            "FileHash-SHA1": 59,
            "FileHash-SHA256": 61,
            "domain": 10,
            "hostname": 6,
            "YARA": 3,
            "URL": 3
          },
          "indicator_count": 199,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 500,
          "modified_text": "927 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "64520cce3fe76f7af80a6cda",
          "name": "Elastic Security Labs discovers the LOBSHOT malware | Elastic",
          "description": "",
          "modified": "2023-05-03T07:27:10.400000",
          "created": "2023-05-03T07:27:10.400000",
          "tags": [
            "lobshot",
            "security labs",
            "google ads",
            "hidden virtual",
            "yara signature"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6450b06a0dd67d58d571eaf8",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "tr2222200",
            "id": "207905",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1,
            "IPv4": 1,
            "URL": 1,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 9,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 186,
          "modified_text": "1124 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        },
        {
          "id": "6450b06a0dd67d58d571eaf8",
          "name": "Elastic Security Labs discovers the LOBSHOT malware | Elastic",
          "description": "",
          "modified": "2023-05-02T06:40:42.269000",
          "created": "2023-05-02T06:40:42.269000",
          "tags": [
            "lobshot",
            "security labs",
            "google ads",
            "hidden virtual",
            "yara signature"
          ],
          "references": [
            "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunter_NL",
            "id": "171283",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1,
            "IPv4": 1,
            "URL": 1,
            "domain": 4,
            "hostname": 2
          },
          "indicator_count": 9,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 862,
          "modified_text": "1125 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "domain",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware",
        "September 06th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3180 - New BLISTER Malware Involved in Network Infiltration.pdf",
        "https://www.elastic.co/security-labs/katz-and-mouse-game"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": []
        },
        "other": {
          "adversary": [
            "El Machete",
            "El Machete, TAG-100, Mirage, Unamed_Grooup"
          ],
          "malware_families": [],
          "industries": []
        }
      }
    },
    "false_positive": []
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 8,
  "pulses": [
    {
      "id": "67ff12aea0b9ba91d923da14",
      "name": "Threat Actor Profile: El Machete",
      "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
      "modified": "2025-04-16T02:15:10.602000",
      "created": "2025-04-16T02:15:10.602000",
      "tags": [
        "threat_actor",
        "unknown",
        "T1497",
        "T1114",
        "T1566.001",
        "T1059.003",
        "T1081",
        "T1059.006",
        "T1059",
        "T1566.002",
        "T1082",
        "T1027",
        "T1071.001",
        "T1566",
        "T1041",
        "T1105",
        "T1204.001",
        "T1049",
        "T1055",
        "T1036",
        "T1503",
        "T1114.001",
        "T1053",
        "T1140",
        "T1012",
        "T1071",
        "T1112",
        "T1036.005",
        "T1547",
        "T1057",
        "T1008",
        "T1518",
        "T1021",
        "T1011",
        "T1060",
        "T1539",
        "T1587",
        "T1087",
        "T1095",
        "T1102",
        "T1070",
        "T1130",
        "T1552",
        "T1106",
        "T1190",
        "T1007",
        "T1133",
        "T1090",
        "T1016",
        "T1137",
        "T1119",
        "T1124",
        "T1005",
        "T1059.001",
        "T1115",
        "T1562.001",
        "T1543",
        "T1078",
        "T1083",
        "T1530",
        "T1085",
        "T1003",
        "T1120",
        "T1218",
        "T1048",
        "T1553",
        "T1490",
        "T1497.003",
        "T1571",
        "T1204.002",
        "T1595.002",
        "T1102.002",
        "T1583.003",
        "T1027.009",
        "T1027.013",
        "T1132",
        "T1562",
        "T1110",
        "T1059.005",
        "T1218.007",
        "T1204",
        "T1550",
        "T1136",
        "T1555",
        "T1176",
        "T1204_-_User_Execution",
        "T1566_-_Phishing",
        "T1561",
        "T1583",
        "T1485",
        "T1127",
        "T1595",
        "T1573",
        "T1189",
        "T1486",
        "T1531",
        "T1529",
        "T1053.005",
        "T1047.",
        "target:Dominican Republic",
        "target:Venezuela",
        "target:Italy",
        "target:Colombia",
        "target:Ecuador",
        "target:Guatemala",
        "target:Belgium",
        "target:Malaysia",
        "target:Brazil",
        "target:France",
        "target:Indonesia",
        "target:United Kingdom",
        "target:China",
        "target:Germany",
        "target:Mexico",
        "target:Argentina",
        "target:Netherlands",
        "target:Japan",
        "target:Bolivia",
        "target:Yibuti",
        "target:Vietnam",
        "target:Fiyi",
        "target:Cuba",
        "target:Camboya",
        "target:Taiw\u00e1n",
        "target:United States",
        "target:Sweden",
        "target:Ukraine",
        "target:South Korea",
        "target:Nicaragua",
        "target:Canada",
        "target:Russia",
        "target:otros"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 9,
        "hostname": 18,
        "domain": 59
      },
      "indicator_count": 86,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 56,
      "modified_text": "410 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67ff1245d4dc2a56e5561a57",
      "name": "Threat Actor Profile: El Machete",
      "description": "# El Machete - Threat Actor Profile\n\n**Report Date**: 2025-04-16\n\n**Actor Type**: unknown\n\n## Description\nEl Machete is a cyber espionage group primarily targeting Spanish-speaking nations. It has been active since at least 2014 and is known for its sophisticated malware and data exfiltration tactics. The group focuses on high-profile targets and is noted for its targeted spear-phishing campaigns.\n\n## Techniques\n* T1497\n* T1114\n* T1566.001\n* T1059.003\n* T1081\n* ... y 92 m\u00e1s\n\n## Targeted Sectors\n* Administraci\u00f3n p\u00fablica\n* Servicios p\u00fablicos\n* Seguridad nacional y asuntos internacionales\n* Telecomunicaciones\n* Servicios educativos\n\n## Targeted Countries\n* Rep\u00fablica Dominicana\n* Venezuela\n* Italia\n* Colombia\n* Ecuador\n* ... y 28 m\u00e1s",
      "modified": "2025-04-16T02:13:25.801000",
      "created": "2025-04-16T02:13:25.801000",
      "tags": [
        "threat_actor",
        "unknown",
        "T1497",
        "T1114",
        "T1566.001",
        "T1059.003",
        "T1081",
        "T1059.006",
        "T1059",
        "T1566.002",
        "T1082",
        "T1027",
        "T1071.001",
        "T1566",
        "T1041",
        "T1105",
        "T1204.001",
        "T1049",
        "T1055",
        "T1036",
        "T1503",
        "T1114.001",
        "T1053",
        "T1140",
        "T1012",
        "T1071",
        "T1112",
        "T1036.005",
        "T1547",
        "T1057",
        "T1008",
        "T1518",
        "T1021",
        "T1011",
        "T1060",
        "T1539",
        "T1587",
        "T1087",
        "T1095",
        "T1102",
        "T1070",
        "T1130",
        "T1552",
        "T1106",
        "T1190",
        "T1007",
        "T1133",
        "T1090",
        "T1016",
        "T1137",
        "T1119",
        "T1124",
        "T1005",
        "T1059.001",
        "T1115",
        "T1562.001",
        "T1543",
        "T1078",
        "T1083",
        "T1530",
        "T1085",
        "T1003",
        "T1120",
        "T1218",
        "T1048",
        "T1553",
        "T1490",
        "T1497.003",
        "T1571",
        "T1204.002",
        "T1595.002",
        "T1102.002",
        "T1583.003",
        "T1027.009",
        "T1027.013",
        "T1132",
        "T1562",
        "T1110",
        "T1059.005",
        "T1218.007",
        "T1204",
        "T1550",
        "T1136",
        "T1555",
        "T1176",
        "T1204_-_User_Execution",
        "T1566_-_Phishing",
        "T1561",
        "T1583",
        "T1485",
        "T1127",
        "T1595",
        "T1573",
        "T1189",
        "T1486",
        "T1531",
        "T1529",
        "T1053.005",
        "T1047.",
        "target:Dominican Republic",
        "target:Venezuela",
        "target:Italy",
        "target:Colombia",
        "target:Ecuador",
        "target:Guatemala",
        "target:Belgium",
        "target:Malaysia",
        "target:Brazil",
        "target:France",
        "target:Indonesia",
        "target:United Kingdom",
        "target:China",
        "target:Germany",
        "target:Mexico",
        "target:Argentina",
        "target:Netherlands",
        "target:Japan",
        "target:Bolivia",
        "target:Yibuti",
        "target:Vietnam",
        "target:Fiyi",
        "target:Cuba",
        "target:Camboya",
        "target:Taiw\u00e1n",
        "target:United States",
        "target:Sweden",
        "target:Ukraine",
        "target:South Korea",
        "target:Nicaragua",
        "target:Canada",
        "target:Russia",
        "target:otros"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 9,
        "hostname": 18,
        "domain": 59
      },
      "indicator_count": 86,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 56,
      "modified_text": "410 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6773390f17d71879c414676a",
      "name": "El Machete",
      "description": "El Machete es un grupo de ciberespionaje activo desde al menos 2014, enfocado en atacar principalmente a naciones de habla hispana. Este grupo es conocido por su sofisticada malware y t\u00e1cticas de exfiltraci\u00f3n de datos, con un enfoque en objetivos de alto perfil, como agencias gubernamentales y organizaciones estrat\u00e9gicas.",
      "modified": "2025-01-30T00:00:18.927000",
      "created": "2024-12-31T00:21:35.813000",
      "tags": [
        "cve201711882",
        "cve20201472",
        "El Machete"
      ],
      "references": [],
      "public": 1,
      "adversary": "El Machete",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 473,
        "FileHash-SHA1": 471,
        "FileHash-SHA256": 500,
        "CVE": 9,
        "domain": 60,
        "hostname": 18
      },
      "indicator_count": 1531,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 60,
      "modified_text": "486 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "67733b72d522398f5ea0a12d",
      "name": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar",
      "description": "Indicadores de Compromiso Estudiio de Inteligencia de Amenaza para Maestr\u00eda UASD Sobre Actores identificados en SOC Radar con Intereses en la Administraci\u00f3n P\u00fablica de la Rep\u00fablica Dominicana, Diciembre 2024",
      "modified": "2025-01-30T00:00:18.927000",
      "created": "2024-12-31T00:31:46.858000",
      "tags": [
        "cve201711882",
        "cve20201472"
      ],
      "references": [],
      "public": 1,
      "adversary": "El Machete, TAG-100, Mirage, Unamed_Grooup",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "fraevolquez",
        "id": "91700",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2631,
        "FileHash-SHA1": 2168,
        "FileHash-SHA256": 3401,
        "CVE": 25,
        "domain": 977,
        "hostname": 1226
      },
      "indicator_count": 10428,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "486 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "672025a446db1f324cbda420",
      "name": "Katz and Mouse Game:  MaaS Infostealers Adapt to Patched Chrome Defenses \u2014 Elastic Security Labs",
      "description": "",
      "modified": "2024-10-29T00:00:36.726000",
      "created": "2024-10-29T00:00:36.726000",
      "tags": [
        "chrome",
        "stealc",
        "lumma",
        "google",
        "september",
        "chromekatz",
        "google chrome",
        "chrome process",
        "windows",
        "july",
        "team",
        "vidar",
        "metastealer",
        "legacy"
      ],
      "references": [
        "https://www.elastic.co/security-labs/katz-and-mouse-game"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ChrisTan0",
        "id": "262536",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-MD5": 2,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 5,
        "YARA": 1,
        "domain": 4
      },
      "indicator_count": 15,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 42,
      "modified_text": "579 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "652e382249b6450188a20316",
      "name": "New BLISTER Malware Involved in Network Infiltration",
      "description": "",
      "modified": "2023-11-16T07:01:26.974000",
      "created": "2023-10-17T07:30:42.274000",
      "tags": [
        "blister",
        "blister loader",
        "security labs",
        "labs",
        "elastic",
        "new development",
        "palo alto",
        "mythic",
        "vlc dll",
        "different",
        "august",
        "virustotal",
        "june",
        "test",
        "trojan",
        "persistence",
        "blister malware",
        "strong",
        "security",
        "startup folder",
        "execution",
        "binary proxy",
        "malware",
        "cobaltstrike",
        "bitrat",
        "urls",
        "please",
        "javascript",
        "group",
        "push",
        "team",
        "red dev",
        "bitrat malware",
        "xmm0",
        "pla unit",
        "maria bitrat",
        "nanocore rat",
        "ave maria",
        "jackal",
        "nodestealer",
        "bomb",
        "discord",
        "purecrypter",
        "quasar rat",
        "avemariarat",
        "hido",
        "powershell",
        "melissa",
        "netwire rc",
        "oilrig",
        "mask",
        "bluenoroff",
        "panda",
        "back",
        "xworm",
        "xavier",
        "adobot",
        "orcus rat",
        "pandora rat",
        "raccoon",
        "vlad",
        "bill",
        "tinynuke",
        "remcos",
        "cobalt strike",
        "zloader",
        "agent tesla",
        "ficker stealer",
        "avemaria",
        "download",
        "stealth mango",
        "ixeshe",
        "aluminum",
        "msupdater",
        "nettraveler",
        "keyboy",
        "sednit",
        "sofacy",
        "oceanlotus",
        "holmium",
        "scarcruft",
        "venus",
        "sykipot",
        "leviathan",
        "amoeba",
        "hoodoo",
        "dragon",
        "star",
        "matanbuchus",
        "comnie",
        "termite",
        "emdivi",
        "greenbug",
        "careto",
        "cobalt",
        "cyber",
        "icefog",
        "trident",
        "dnspionage",
        "darkhotel",
        "luder",
        "nemim",
        "tapaoux",
        "pioneer",
        "havex",
        "machete",
        "evilnum",
        "carbanak",
        "gcman",
        "ghostnet",
        "bitter",
        "infy",
        "karakurt",
        "kinsing",
        "mercury",
        "naikon",
        "nitro",
        "strongpity",
        "powerpool",
        "indra",
        "sauron",
        "sidewinder",
        "redalpha",
        "mantis",
        "rocke",
        "mimic",
        "silence",
        "guardian",
        "teamspy",
        "teamtnt",
        "teamxrat",
        "turla",
        "snake",
        "wraith",
        "pfinet",
        "krypton",
        "zoopark",
        "sha256 trend",
        "micro detection",
        "script c",
        "unique string",
        "windows",
        "lnk file",
        "windows native",
        "payload",
        "launchcolorcpl",
        "amadey",
        "clipbanker",
        "launch",
        "apache"
      ],
      "references": [
        "September 06th, 2023 - CryptoGen Cyber Threat Intelligence Advisory #3180 - New BLISTER Malware Involved in Network Infiltration.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 74,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "cryptocti",
        "id": "110256",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_110256/resized/80/avatar_e237a4257c.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 57,
        "FileHash-SHA1": 59,
        "FileHash-SHA256": 61,
        "domain": 10,
        "hostname": 6,
        "YARA": 3,
        "URL": 3
      },
      "indicator_count": 199,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 500,
      "modified_text": "927 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "64520cce3fe76f7af80a6cda",
      "name": "Elastic Security Labs discovers the LOBSHOT malware | Elastic",
      "description": "",
      "modified": "2023-05-03T07:27:10.400000",
      "created": "2023-05-03T07:27:10.400000",
      "tags": [
        "lobshot",
        "security labs",
        "google ads",
        "hidden virtual",
        "yara signature"
      ],
      "references": [
        "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6450b06a0dd67d58d571eaf8",
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "tr2222200",
        "id": "207905",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1,
        "IPv4": 1,
        "URL": 1,
        "domain": 4,
        "hostname": 2
      },
      "indicator_count": 9,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 186,
      "modified_text": "1124 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    },
    {
      "id": "6450b06a0dd67d58d571eaf8",
      "name": "Elastic Security Labs discovers the LOBSHOT malware | Elastic",
      "description": "",
      "modified": "2023-05-02T06:40:42.269000",
      "created": "2023-05-02T06:40:42.269000",
      "tags": [
        "lobshot",
        "security labs",
        "google ads",
        "hidden virtual",
        "yara signature"
      ],
      "references": [
        "https://www.elastic.co/security-labs/elastic-security-labs-discovers-lobshot-malware"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunter_NL",
        "id": "171283",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_171283/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1,
        "IPv4": 1,
        "URL": 1,
        "domain": 4,
        "hostname": 2
      },
      "indicator_count": 9,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 862,
      "modified_text": "1125 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "domain",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "host.id",
    "type": "Domain"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "host.id",
    "found": false,
    "verdict": "clean",
    "urls": [],
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780214679.773512
}