{
  "type": "URL",
  "indicator": "http://183.215.23.242:9091",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "http://183.215.23.242:9091",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3628891766,
      "indicator": "http://183.215.23.242:9091",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 23,
      "pulses": [
        {
          "id": "68207c3797a9a4b7ba37517f",
          "name": "[GS-25-19131] Mirai Botnet IOCs - SEC-1275-1",
          "description": "Search for the Mirai botnet,  \u00c2\u00a31.5m, and the results of the search will appear on the BBC News website at 21:00 GMT on Thursday, 2 March 2017.",
          "modified": "2025-06-10T10:03:50.769000",
          "created": "2025-05-11T10:30:15.296000",
          "tags": [
            "ddos",
            "mirai internet",
            "things",
            "mirai",
            "mirai botnet",
            "iocs",
            "linux",
            "botnet mirai",
            "gs2519131",
            "gs2519129",
            "gs2519125",
            "ipv4",
            "twitter",
            "gs2519126"
          ],
          "references": [
            "https://1275.ru/ioc/gs-25-19131-mirai-botnet-iocs_11023",
            "https://1275.ru/ioc/gs-25-19129-mirai-botnet-iocs_11015",
            "https://1275.ru/ioc/gs-25-19128-mirai-botnet-iocs_11001",
            "https://1275.ru/ioc/gs-25-19127-mirai-botnet-iocs_10989",
            "https://1275.ru/ioc/gs-25-19125-mirai-botnet-iocs_10956",
            "https://1275.ru/ioc/gs-25-19126-mirai-botnet-iocs_10970"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Gnostis",
            "id": "44738",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_44738/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-MD5": 783,
            "FileHash-SHA1": 783,
            "FileHash-SHA256": 783,
            "URL": 3496,
            "domain": 18,
            "hostname": 63
          },
          "indicator_count": 5928,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 172,
          "modified_text": "354 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6819c44db7eb5c82e7653bee",
          "name": "[GS-25-18122] Mirai Botnet IOCs - SEC-1275-1",
          "description": "",
          "modified": "2025-06-05T08:03:40.910000",
          "created": "2025-05-06T08:11:57.632000",
          "tags": [
            "mirai botnet",
            "iocs",
            "mirai",
            "linux",
            "botnet mirai",
            "outlaw",
            "gs2519125",
            "botnet iocs",
            "gs25181222",
            "gs2518120",
            "xmrig",
            "twitter",
            "gs2518122"
          ],
          "references": [
            "https://1275.ru/ioc/gs-25-18122-mirai-botnet-iocs_10913",
            "https://1275.ru/ioc/gs-25-18120-mirai-botnet-iocs_10854",
            "https://1275.ru/ioc/gs-25-18119-mirai-botnet-iocs_10829",
            "https://1275.ru/ioc/gs-25-18118-mirai-botnet-iocs_10825",
            "https://1275.ru/ioc/gs-25-17115-mirai-botnet-iocs-2_10696",
            "https://1275.ru/ioc/gs-25-17115-mirai-botnet-iocs_10682",
            "https://1275.ru/ioc/gs-25-17113-mirai-botnet-iocs_10658",
            "https://1275.ru/ioc/gs-25-17112-mirai-botnet-iocs_10640"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Gnostis",
            "id": "44738",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_44738/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 980,
            "FileHash-SHA1": 980,
            "FileHash-SHA256": 980,
            "URL": 3518,
            "domain": 7,
            "hostname": 7
          },
          "indicator_count": 6472,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 171,
          "modified_text": "359 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67ea50bafb26cf033718b2d4",
          "name": "[GS-25-1490] Mirai Botnet IOCs - SEC-1275-1",
          "description": "",
          "modified": "2025-04-30T08:01:46.210000",
          "created": "2025-03-31T08:22:18.821000",
          "tags": [
            "mirai botnet",
            "iocs",
            "mirai",
            "botnet iocs",
            "gorillabot",
            "linux",
            "botnet mirai",
            "gs251387",
            "gs2513862",
            "gs251386",
            "malware"
          ],
          "references": [
            "https://1275.ru/ioc/gs-25-1490-mirai-botnet-iocs_10200"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Gnostis",
            "id": "44738",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_44738/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 3,
            "FileHash-MD5": 329,
            "FileHash-SHA1": 329,
            "FileHash-SHA256": 329,
            "URL": 3516,
            "hostname": 3
          },
          "indicator_count": 4509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 172,
          "modified_text": "395 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268ce06cd3b9ed1471f8b",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:50.368000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e26917892eba29e13b15ca",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:07:02.862000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 65,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 63,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e2690fa8796bb997357f70",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:06:55.260000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 58,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e26906a8796bb997357f6f",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:06:46.047000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 61,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268fa7dc9ecf76f1021fb",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:06:34.731000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 60,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268f307c60b2138af80fd",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:06:27.028000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 58,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268e8016e9ee13c769105",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:06:16.939000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 58,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268df3de865e9729fd2b3",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:06:07.006000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 58,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268d6150e8a66b8a044f4",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:58.087000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 58,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e2686e04a9be9a8511850f",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:04:14.463000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 26,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268c5988bbadb6ac18d61",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:41.806000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268b94f6cabc075ee54cb",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:29.769000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268b7a4177a46ed263b2b",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:27.725000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268b5bf94fd7a6cdfb575",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:25.449000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268b3dbc82f4e92ede460",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:23.643000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268a99dc029fbf63674b1",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:13.489000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e268a298cc52ca5efe2543",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:05:06.077000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e26878fef6ee4dab3b4a81",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:04:24.246000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e2687774ab48d2161f7ef9",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:04:23.680000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63e26876c3c9c9710f2e66a5",
          "name": "KillNet-DDoS-Blocklist",
          "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
          "modified": "2023-03-09T14:03:42.242000",
          "created": "2023-02-07T15:04:22.960000",
          "tags": [
            "KillNet",
            "DDOS"
          ],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "FHS-Services",
            "id": "51336",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 17438
          },
          "indicator_count": 17438,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 57,
          "modified_text": "1178 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://1275.ru/ioc/gs-25-18118-mirai-botnet-iocs_10825",
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt",
        "https://1275.ru/ioc/gs-25-19126-mirai-botnet-iocs_10970",
        "https://1275.ru/ioc/gs-25-18120-mirai-botnet-iocs_10854",
        "https://1275.ru/ioc/gs-25-19129-mirai-botnet-iocs_11015",
        "https://1275.ru/ioc/gs-25-18119-mirai-botnet-iocs_10829",
        "https://1275.ru/ioc/gs-25-17115-mirai-botnet-iocs_10682",
        "https://1275.ru/ioc/gs-25-17112-mirai-botnet-iocs_10640",
        "https://1275.ru/ioc/gs-25-1490-mirai-botnet-iocs_10200",
        "https://1275.ru/ioc/gs-25-19131-mirai-botnet-iocs_11023",
        "https://1275.ru/ioc/gs-25-19128-mirai-botnet-iocs_11001",
        "https://1275.ru/ioc/gs-25-19125-mirai-botnet-iocs_10956",
        "https://1275.ru/ioc/gs-25-17115-mirai-botnet-iocs-2_10696",
        "https://1275.ru/ioc/gs-25-17113-mirai-botnet-iocs_10658",
        "https://1275.ru/ioc/gs-25-18122-mirai-botnet-iocs_10913",
        "https://1275.ru/ioc/gs-25-19127-mirai-botnet-iocs_10989"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "RUSSIAN THREAT ACTOR, KILLNET"
          ],
          "malware_families": [
            "Mirai"
          ],
          "industries": [
            "Healthcare"
          ],
          "unique_indicators": 46308
        }
      }
    },
    "false_positive": [],
    "alexa": "",
    "whois": "http://whois.domaintools.com/183.215.23.242",
    "domain": "Unavailable",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 23,
  "pulses": [
    {
      "id": "68207c3797a9a4b7ba37517f",
      "name": "[GS-25-19131] Mirai Botnet IOCs - SEC-1275-1",
      "description": "Search for the Mirai botnet,  \u00c2\u00a31.5m, and the results of the search will appear on the BBC News website at 21:00 GMT on Thursday, 2 March 2017.",
      "modified": "2025-06-10T10:03:50.769000",
      "created": "2025-05-11T10:30:15.296000",
      "tags": [
        "ddos",
        "mirai internet",
        "things",
        "mirai",
        "mirai botnet",
        "iocs",
        "linux",
        "botnet mirai",
        "gs2519131",
        "gs2519129",
        "gs2519125",
        "ipv4",
        "twitter",
        "gs2519126"
      ],
      "references": [
        "https://1275.ru/ioc/gs-25-19131-mirai-botnet-iocs_11023",
        "https://1275.ru/ioc/gs-25-19129-mirai-botnet-iocs_11015",
        "https://1275.ru/ioc/gs-25-19128-mirai-botnet-iocs_11001",
        "https://1275.ru/ioc/gs-25-19127-mirai-botnet-iocs_10989",
        "https://1275.ru/ioc/gs-25-19125-mirai-botnet-iocs_10956",
        "https://1275.ru/ioc/gs-25-19126-mirai-botnet-iocs_10970"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 28,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Gnostis",
        "id": "44738",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_44738/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 2,
        "FileHash-MD5": 783,
        "FileHash-SHA1": 783,
        "FileHash-SHA256": 783,
        "URL": 3496,
        "domain": 18,
        "hostname": 63
      },
      "indicator_count": 5928,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 172,
      "modified_text": "354 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6819c44db7eb5c82e7653bee",
      "name": "[GS-25-18122] Mirai Botnet IOCs - SEC-1275-1",
      "description": "",
      "modified": "2025-06-05T08:03:40.910000",
      "created": "2025-05-06T08:11:57.632000",
      "tags": [
        "mirai botnet",
        "iocs",
        "mirai",
        "linux",
        "botnet mirai",
        "outlaw",
        "gs2519125",
        "botnet iocs",
        "gs25181222",
        "gs2518120",
        "xmrig",
        "twitter",
        "gs2518122"
      ],
      "references": [
        "https://1275.ru/ioc/gs-25-18122-mirai-botnet-iocs_10913",
        "https://1275.ru/ioc/gs-25-18120-mirai-botnet-iocs_10854",
        "https://1275.ru/ioc/gs-25-18119-mirai-botnet-iocs_10829",
        "https://1275.ru/ioc/gs-25-18118-mirai-botnet-iocs_10825",
        "https://1275.ru/ioc/gs-25-17115-mirai-botnet-iocs-2_10696",
        "https://1275.ru/ioc/gs-25-17115-mirai-botnet-iocs_10682",
        "https://1275.ru/ioc/gs-25-17113-mirai-botnet-iocs_10658",
        "https://1275.ru/ioc/gs-25-17112-mirai-botnet-iocs_10640"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Gnostis",
        "id": "44738",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_44738/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 980,
        "FileHash-SHA1": 980,
        "FileHash-SHA256": 980,
        "URL": 3518,
        "domain": 7,
        "hostname": 7
      },
      "indicator_count": 6472,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 171,
      "modified_text": "359 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67ea50bafb26cf033718b2d4",
      "name": "[GS-25-1490] Mirai Botnet IOCs - SEC-1275-1",
      "description": "",
      "modified": "2025-04-30T08:01:46.210000",
      "created": "2025-03-31T08:22:18.821000",
      "tags": [
        "mirai botnet",
        "iocs",
        "mirai",
        "botnet iocs",
        "gorillabot",
        "linux",
        "botnet mirai",
        "gs251387",
        "gs2513862",
        "gs251386",
        "malware"
      ],
      "references": [
        "https://1275.ru/ioc/gs-25-1490-mirai-botnet-iocs_10200"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Gnostis",
        "id": "44738",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_44738/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 3,
        "FileHash-MD5": 329,
        "FileHash-SHA1": 329,
        "FileHash-SHA256": 329,
        "URL": 3516,
        "hostname": 3
      },
      "indicator_count": 4509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 172,
      "modified_text": "395 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63e268ce06cd3b9ed1471f8b",
      "name": "KillNet-DDoS-Blocklist",
      "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
      "modified": "2023-03-09T14:03:42.242000",
      "created": "2023-02-07T15:05:50.368000",
      "tags": [
        "KillNet",
        "DDOS"
      ],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FHS-Services",
        "id": "51336",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 17438
      },
      "indicator_count": 17438,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 57,
      "modified_text": "1178 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63e26917892eba29e13b15ca",
      "name": "KillNet-DDoS-Blocklist",
      "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
      "modified": "2023-03-09T14:03:42.242000",
      "created": "2023-02-07T15:07:02.862000",
      "tags": [
        "KillNet",
        "DDOS"
      ],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 65,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FHS-Services",
        "id": "51336",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 17438
      },
      "indicator_count": 17438,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 63,
      "modified_text": "1178 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63e2690fa8796bb997357f70",
      "name": "KillNet-DDoS-Blocklist",
      "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
      "modified": "2023-03-09T14:03:42.242000",
      "created": "2023-02-07T15:06:55.260000",
      "tags": [
        "KillNet",
        "DDOS"
      ],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FHS-Services",
        "id": "51336",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 17438
      },
      "indicator_count": 17438,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 58,
      "modified_text": "1178 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63e26906a8796bb997357f6f",
      "name": "KillNet-DDoS-Blocklist",
      "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
      "modified": "2023-03-09T14:03:42.242000",
      "created": "2023-02-07T15:06:46.047000",
      "tags": [
        "KillNet",
        "DDOS"
      ],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FHS-Services",
        "id": "51336",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 17438
      },
      "indicator_count": 17438,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 61,
      "modified_text": "1178 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63e268fa7dc9ecf76f1021fb",
      "name": "KillNet-DDoS-Blocklist",
      "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
      "modified": "2023-03-09T14:03:42.242000",
      "created": "2023-02-07T15:06:34.731000",
      "tags": [
        "KillNet",
        "DDOS"
      ],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FHS-Services",
        "id": "51336",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 17438
      },
      "indicator_count": 17438,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 60,
      "modified_text": "1178 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63e268f307c60b2138af80fd",
      "name": "KillNet-DDoS-Blocklist",
      "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
      "modified": "2023-03-09T14:03:42.242000",
      "created": "2023-02-07T15:06:27.028000",
      "tags": [
        "KillNet",
        "DDOS"
      ],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FHS-Services",
        "id": "51336",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 17438
      },
      "indicator_count": 17438,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 58,
      "modified_text": "1178 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63e268e8016e9ee13c769105",
      "name": "KillNet-DDoS-Blocklist",
      "description": "KillNet-DDoS-Blocklist - KillNet has targeted the U.S. healthcare industry in the past and is actively targeting\nthe health and public health sector. The group is known to launch DDoS attacks and operates multiple\npublic channels aimed at recruitment and garnering attention from these attacks.",
      "modified": "2023-03-09T14:03:42.242000",
      "created": "2023-02-07T15:06:16.939000",
      "tags": [
        "KillNet",
        "DDOS"
      ],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "RUSSIAN THREAT ACTOR, KILLNET",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "FHS-Services",
        "id": "51336",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 17438
      },
      "indicator_count": 17438,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 58,
      "modified_text": "1178 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "http://183.215.23.242:9091",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "http://183.215.23.242:9091",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780173337.2247257
}