{
  "type": "URL",
  "indicator": "http://gistsstack.com/panel/fre.php",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "http://gistsstack.com/panel/fre.php",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 229204727,
      "indicator": "http://gistsstack.com/panel/fre.php",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 8,
      "pulses": [
        {
          "id": "5a3abf3b3f63a576d6913a17",
          "name": "CVE-2017-11882 Exploited to Deliver a Cracked Version of the Loki Infostealer",
          "description": "The Cobalt hacking group was one of the first to promptly and actively exploit CVE-2017-11882 (patched last November) in their cybercriminal campaigns. We uncovered several others following suit in early December, delivering a plethora of threats that included Pony/FAREIT, FormBook, ZBOT, and Ursnif. Another stood out to us: a recent campaign that used the same vulnerability to install a \u201ccracked\u201d version of the information-stealing Loki.",
          "modified": "2017-12-20T19:51:23.575000",
          "created": "2017-12-20T19:51:23.575000",
          "tags": [
            "Loki",
            "malware",
            "office",
            "hta",
            "trendmicro"
          ],
          "references": [
            "https://documents.trendmicro.com/assets/appendix-CVE-2017-11882-exploited-to-deliver-a-cracked-version-of-the-loki-infostealer.pdf",
            "http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-11882-exploited-deliver-cracked-version-loki-infostealer/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 90,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 89,
            "URL": 119,
            "CVE": 1
          },
          "indicator_count": 209,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386535,
          "modified_text": "3082 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707ac561d098f29ff6de19",
          "name": "CVE-2017-11882 Exploited to Deliver a Cracked Version of the Loki Infostealer",
          "description": "",
          "modified": "2023-12-06T13:44:37.436000",
          "created": "2023-12-06T13:44:37.436000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-SHA256": 89,
            "URL": 119
          },
          "indicator_count": 209,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "656a980f14b5a32303bf865b",
          "name": "CNC server.telegrafix.com",
          "description": "",
          "modified": "2023-12-02T02:35:59.820000",
          "created": "2023-12-02T02:35:59.820000",
          "tags": [
            "record type",
            "ttl value",
            "data",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "server",
            "whois lookup",
            "creation date",
            "dnssec",
            "domain name",
            "status",
            "abuse contact",
            "email",
            "registrar abuse",
            "contact phone",
            "date",
            "whois lookups",
            "iana id",
            "domain status",
            "registrar url",
            "registrar whois",
            "first",
            "execution",
            "tsara brashears",
            "ssl certificate",
            "april",
            "threat roundup",
            "october",
            "december",
            "roundup",
            "september",
            "whois record",
            "blustealer",
            "raspberry robin",
            "redline stealer",
            "gopuram",
            "hacktool",
            "skynet",
            "android",
            "quasar",
            "download",
            "malware",
            "hijacker",
            "monitoring",
            "installer",
            "ermac",
            "attack",
            "blackguard",
            "core",
            "awful",
            "twitter",
            "agent tesla",
            "trickbot",
            "ursnif",
            "chaos",
            "metasploit",
            "formbook",
            "metro",
            "name verdict",
            "exit",
            "traffic",
            "node tcp",
            "et tor",
            "known tor",
            "relayrouter",
            "united",
            "team malware",
            "firehol et",
            "tor known",
            "redline",
            "detection list",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malicious url",
            "blacklist",
            "phishing",
            "union",
            "team",
            "bank",
            "unsafe",
            "contacted",
            "bundled",
            "project",
            "ransomexx"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Lithuania"
          ],
          "malware_families": [
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65423978ca5e5c9931b586a5",
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3674,
            "domain": 1422,
            "FileHash-SHA1": 117,
            "FileHash-SHA256": 3178,
            "URL": 8884,
            "email": 2,
            "CVE": 3,
            "FileHash-MD5": 167
          },
          "indicator_count": 17447,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "656a978cf39ec3cdc99278cc",
          "name": "RedLine",
          "description": "",
          "modified": "2023-12-02T02:33:48.848000",
          "created": "2023-12-02T02:33:48.848000",
          "tags": [
            "record type",
            "ttl value",
            "data",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "server",
            "whois lookup",
            "creation date",
            "dnssec",
            "domain name",
            "status",
            "abuse contact",
            "email",
            "registrar abuse",
            "contact phone",
            "date",
            "whois lookups",
            "iana id",
            "domain status",
            "registrar url",
            "registrar whois",
            "first",
            "execution",
            "tsara brashears",
            "ssl certificate",
            "april",
            "threat roundup",
            "october",
            "december",
            "roundup",
            "september",
            "whois record",
            "blustealer",
            "raspberry robin",
            "redline stealer",
            "gopuram",
            "hacktool",
            "skynet",
            "android",
            "quasar",
            "download",
            "malware",
            "hijacker",
            "monitoring",
            "installer",
            "ermac",
            "attack",
            "blackguard",
            "core",
            "awful",
            "twitter",
            "agent tesla",
            "trickbot",
            "ursnif",
            "chaos",
            "metasploit",
            "formbook",
            "metro",
            "name verdict",
            "exit",
            "traffic",
            "node tcp",
            "et tor",
            "known tor",
            "relayrouter",
            "united",
            "team malware",
            "firehol et",
            "tor known",
            "redline",
            "detection list",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malicious url",
            "blacklist",
            "phishing",
            "union",
            "team",
            "bank",
            "unsafe",
            "contacted",
            "bundled",
            "project",
            "ransomexx"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Lithuania"
          ],
          "malware_families": [
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65423a941aa6527fbbe40a53",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3674,
            "domain": 1422,
            "FileHash-SHA1": 117,
            "FileHash-SHA256": 3178,
            "URL": 8884,
            "email": 2,
            "CVE": 3,
            "FileHash-MD5": 167
          },
          "indicator_count": 17447,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "910 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65423978ca5e5c9931b586a5",
          "name": "CNC server.telegrafix.com",
          "description": "Brute force passwords using SSH on server RELAY\nTargeted individual, adult content, malvertizing, keylogging, monitoring, hacking, CNC, remoted devices, tracking, malware attack,etc.\n(Auto populated: The last HTTPS certificate was signed by the US government's Department of Homeland Security (DHS), but what exactly is it and what does the certificate actually say?. and how does it look?)",
          "modified": "2023-12-01T10:01:56.921000",
          "created": "2023-11-01T11:41:44.861000",
          "tags": [
            "record type",
            "ttl value",
            "data",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "server",
            "whois lookup",
            "creation date",
            "dnssec",
            "domain name",
            "status",
            "abuse contact",
            "email",
            "registrar abuse",
            "contact phone",
            "date",
            "whois lookups",
            "iana id",
            "domain status",
            "registrar url",
            "registrar whois",
            "first",
            "execution",
            "tsara brashears",
            "ssl certificate",
            "april",
            "threat roundup",
            "october",
            "december",
            "roundup",
            "september",
            "whois record",
            "blustealer",
            "raspberry robin",
            "redline stealer",
            "gopuram",
            "hacktool",
            "skynet",
            "android",
            "quasar",
            "download",
            "malware",
            "hijacker",
            "monitoring",
            "installer",
            "ermac",
            "attack",
            "blackguard",
            "core",
            "awful",
            "twitter",
            "agent tesla",
            "trickbot",
            "ursnif",
            "chaos",
            "metasploit",
            "formbook",
            "metro",
            "name verdict",
            "exit",
            "traffic",
            "node tcp",
            "et tor",
            "known tor",
            "relayrouter",
            "united",
            "team malware",
            "firehol et",
            "tor known",
            "redline",
            "detection list",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malicious url",
            "blacklist",
            "phishing",
            "union",
            "team",
            "bank",
            "unsafe",
            "contacted",
            "bundled",
            "project",
            "ransomexx"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Lithuania"
          ],
          "malware_families": [
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 42,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3674,
            "domain": 1422,
            "FileHash-SHA1": 117,
            "FileHash-SHA256": 3178,
            "URL": 8884,
            "email": 2,
            "CVE": 3,
            "FileHash-MD5": 167
          },
          "indicator_count": 17447,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "911 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65423a941aa6527fbbe40a53",
          "name": "RedLine",
          "description": "CNC server.telegrafix.com. Brute force passwords using SSH on server RELAY\nTargeted individual, monitoring, hacking, CNC, remoted devices, tracking, malware attack,etc.\n(Auto populated: The last HTTPS certificate was signed by the US government's Department of Homeland Security (DHS), but what exactly is it and what does the certificate actually say?. and how does it look?)",
          "modified": "2023-12-01T10:01:56.921000",
          "created": "2023-11-01T11:46:28.418000",
          "tags": [
            "record type",
            "ttl value",
            "data",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "server",
            "whois lookup",
            "creation date",
            "dnssec",
            "domain name",
            "status",
            "abuse contact",
            "email",
            "registrar abuse",
            "contact phone",
            "date",
            "whois lookups",
            "iana id",
            "domain status",
            "registrar url",
            "registrar whois",
            "first",
            "execution",
            "tsara brashears",
            "ssl certificate",
            "april",
            "threat roundup",
            "october",
            "december",
            "roundup",
            "september",
            "whois record",
            "blustealer",
            "raspberry robin",
            "redline stealer",
            "gopuram",
            "hacktool",
            "skynet",
            "android",
            "quasar",
            "download",
            "malware",
            "hijacker",
            "monitoring",
            "installer",
            "ermac",
            "attack",
            "blackguard",
            "core",
            "awful",
            "twitter",
            "agent tesla",
            "trickbot",
            "ursnif",
            "chaos",
            "metasploit",
            "formbook",
            "metro",
            "name verdict",
            "exit",
            "traffic",
            "node tcp",
            "et tor",
            "known tor",
            "relayrouter",
            "united",
            "team malware",
            "firehol et",
            "tor known",
            "redline",
            "detection list",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malicious url",
            "blacklist",
            "phishing",
            "union",
            "team",
            "bank",
            "unsafe",
            "contacted",
            "bundled",
            "project",
            "ransomexx"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Lithuania"
          ],
          "malware_families": [
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 45,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3674,
            "domain": 1422,
            "FileHash-SHA1": 117,
            "FileHash-SHA256": 3178,
            "URL": 8884,
            "email": 2,
            "CVE": 3,
            "FileHash-MD5": 167
          },
          "indicator_count": 17447,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "911 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6545a281ce7426288033f81e",
          "name": "CNC server.telegrafix.com",
          "description": "",
          "modified": "2023-12-01T10:01:56.921000",
          "created": "2023-11-04T01:46:41.933000",
          "tags": [
            "record type",
            "ttl value",
            "data",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "server",
            "whois lookup",
            "creation date",
            "dnssec",
            "domain name",
            "status",
            "abuse contact",
            "email",
            "registrar abuse",
            "contact phone",
            "date",
            "whois lookups",
            "iana id",
            "domain status",
            "registrar url",
            "registrar whois",
            "first",
            "execution",
            "tsara brashears",
            "ssl certificate",
            "april",
            "threat roundup",
            "october",
            "december",
            "roundup",
            "september",
            "whois record",
            "blustealer",
            "raspberry robin",
            "redline stealer",
            "gopuram",
            "hacktool",
            "skynet",
            "android",
            "quasar",
            "download",
            "malware",
            "hijacker",
            "monitoring",
            "installer",
            "ermac",
            "attack",
            "blackguard",
            "core",
            "awful",
            "twitter",
            "agent tesla",
            "trickbot",
            "ursnif",
            "chaos",
            "metasploit",
            "formbook",
            "metro",
            "name verdict",
            "exit",
            "traffic",
            "node tcp",
            "et tor",
            "known tor",
            "relayrouter",
            "united",
            "team malware",
            "firehol et",
            "tor known",
            "redline",
            "detection list",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malicious url",
            "blacklist",
            "phishing",
            "union",
            "team",
            "bank",
            "unsafe",
            "contacted",
            "bundled",
            "project",
            "ransomexx"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Lithuania"
          ],
          "malware_families": [
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65423978ca5e5c9931b586a5",
          "export_count": 46,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3674,
            "domain": 1422,
            "FileHash-SHA1": 117,
            "FileHash-SHA256": 3178,
            "URL": 8884,
            "email": 2,
            "CVE": 3,
            "FileHash-MD5": 167
          },
          "indicator_count": 17447,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "911 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "652b1d2b113b44d8a0745592",
          "name": "LokiBot (LokiPWS) IoC between 2020 and 2023 - Collection made from public sources",
          "description": "These IoC are a collection of LokiBot C2 Data collected from public sources and automatically enriched by OTX. \nIf you find any true false positives, please contact me via my socials: https://linktr.ee/gi7w0rm",
          "modified": "2023-11-13T22:04:06.580000",
          "created": "2023-10-14T22:58:51.814000",
          "tags": [
            "LokiBot",
            "LokiPWS",
            "stealer"
          ],
          "references": [
            "https://raw.githubusercontent.com/Gi7w0rm/MalwareConfigLists/main/LokiBot/lokibot_2020_to_2023.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "win.lokipws",
              "display_name": "win.lokipws",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/Lokibot",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/Lokibot",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "@Gi7w0rm",
            "id": "165134",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 31,
            "FileHash-SHA1": 2,
            "URL": 6013,
            "domain": 2170,
            "hostname": 328
          },
          "indicator_count": 8544,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "928 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-11882-exploited-deliver-cracked-version-loki-infostealer/",
        "https://documents.trendmicro.com/assets/appendix-CVE-2017-11882-exploited-to-deliver-a-cracked-version-of-the-loki-infostealer.pdf",
        "https://raw.githubusercontent.com/Gi7w0rm/MalwareConfigLists/main/LokiBot/lokibot_2020_to_2023.txt"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 209
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Redline",
            "Alf:heraklezeval:trojan:win32/lokibot",
            "Win.lokipws"
          ],
          "industries": [],
          "unique_indicators": 26709
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/gistsstack.com",
    "whois": "http://whois.domaintools.com/gistsstack.com",
    "domain": "gistsstack.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 8,
  "pulses": [
    {
      "id": "5a3abf3b3f63a576d6913a17",
      "name": "CVE-2017-11882 Exploited to Deliver a Cracked Version of the Loki Infostealer",
      "description": "The Cobalt hacking group was one of the first to promptly and actively exploit CVE-2017-11882 (patched last November) in their cybercriminal campaigns. We uncovered several others following suit in early December, delivering a plethora of threats that included Pony/FAREIT, FormBook, ZBOT, and Ursnif. Another stood out to us: a recent campaign that used the same vulnerability to install a \u201ccracked\u201d version of the information-stealing Loki.",
      "modified": "2017-12-20T19:51:23.575000",
      "created": "2017-12-20T19:51:23.575000",
      "tags": [
        "Loki",
        "malware",
        "office",
        "hta",
        "trendmicro"
      ],
      "references": [
        "https://documents.trendmicro.com/assets/appendix-CVE-2017-11882-exploited-to-deliver-a-cracked-version-of-the-loki-infostealer.pdf",
        "http://blog.trendmicro.com/trendlabs-security-intelligence/cve-2017-11882-exploited-deliver-cracked-version-loki-infostealer/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 90,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 89,
        "URL": 119,
        "CVE": 1
      },
      "indicator_count": 209,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386535,
      "modified_text": "3082 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707ac561d098f29ff6de19",
      "name": "CVE-2017-11882 Exploited to Deliver a Cracked Version of the Loki Infostealer",
      "description": "",
      "modified": "2023-12-06T13:44:37.436000",
      "created": "2023-12-06T13:44:37.436000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-SHA256": 89,
        "URL": 119
      },
      "indicator_count": 209,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "656a980f14b5a32303bf865b",
      "name": "CNC server.telegrafix.com",
      "description": "",
      "modified": "2023-12-02T02:35:59.820000",
      "created": "2023-12-02T02:35:59.820000",
      "tags": [
        "record type",
        "ttl value",
        "data",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "server",
        "whois lookup",
        "creation date",
        "dnssec",
        "domain name",
        "status",
        "abuse contact",
        "email",
        "registrar abuse",
        "contact phone",
        "date",
        "whois lookups",
        "iana id",
        "domain status",
        "registrar url",
        "registrar whois",
        "first",
        "execution",
        "tsara brashears",
        "ssl certificate",
        "april",
        "threat roundup",
        "october",
        "december",
        "roundup",
        "september",
        "whois record",
        "blustealer",
        "raspberry robin",
        "redline stealer",
        "gopuram",
        "hacktool",
        "skynet",
        "android",
        "quasar",
        "download",
        "malware",
        "hijacker",
        "monitoring",
        "installer",
        "ermac",
        "attack",
        "blackguard",
        "core",
        "awful",
        "twitter",
        "agent tesla",
        "trickbot",
        "ursnif",
        "chaos",
        "metasploit",
        "formbook",
        "metro",
        "name verdict",
        "exit",
        "traffic",
        "node tcp",
        "et tor",
        "known tor",
        "relayrouter",
        "united",
        "team malware",
        "firehol et",
        "tor known",
        "redline",
        "detection list",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malicious url",
        "blacklist",
        "phishing",
        "union",
        "team",
        "bank",
        "unsafe",
        "contacted",
        "bundled",
        "project",
        "ransomexx"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Lithuania"
      ],
      "malware_families": [
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65423978ca5e5c9931b586a5",
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3674,
        "domain": 1422,
        "FileHash-SHA1": 117,
        "FileHash-SHA256": 3178,
        "URL": 8884,
        "email": 2,
        "CVE": 3,
        "FileHash-MD5": 167
      },
      "indicator_count": 17447,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "656a978cf39ec3cdc99278cc",
      "name": "RedLine",
      "description": "",
      "modified": "2023-12-02T02:33:48.848000",
      "created": "2023-12-02T02:33:48.848000",
      "tags": [
        "record type",
        "ttl value",
        "data",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "server",
        "whois lookup",
        "creation date",
        "dnssec",
        "domain name",
        "status",
        "abuse contact",
        "email",
        "registrar abuse",
        "contact phone",
        "date",
        "whois lookups",
        "iana id",
        "domain status",
        "registrar url",
        "registrar whois",
        "first",
        "execution",
        "tsara brashears",
        "ssl certificate",
        "april",
        "threat roundup",
        "october",
        "december",
        "roundup",
        "september",
        "whois record",
        "blustealer",
        "raspberry robin",
        "redline stealer",
        "gopuram",
        "hacktool",
        "skynet",
        "android",
        "quasar",
        "download",
        "malware",
        "hijacker",
        "monitoring",
        "installer",
        "ermac",
        "attack",
        "blackguard",
        "core",
        "awful",
        "twitter",
        "agent tesla",
        "trickbot",
        "ursnif",
        "chaos",
        "metasploit",
        "formbook",
        "metro",
        "name verdict",
        "exit",
        "traffic",
        "node tcp",
        "et tor",
        "known tor",
        "relayrouter",
        "united",
        "team malware",
        "firehol et",
        "tor known",
        "redline",
        "detection list",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malicious url",
        "blacklist",
        "phishing",
        "union",
        "team",
        "bank",
        "unsafe",
        "contacted",
        "bundled",
        "project",
        "ransomexx"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Lithuania"
      ],
      "malware_families": [
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65423a941aa6527fbbe40a53",
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3674,
        "domain": 1422,
        "FileHash-SHA1": 117,
        "FileHash-SHA256": 3178,
        "URL": 8884,
        "email": 2,
        "CVE": 3,
        "FileHash-MD5": 167
      },
      "indicator_count": 17447,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "910 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65423978ca5e5c9931b586a5",
      "name": "CNC server.telegrafix.com",
      "description": "Brute force passwords using SSH on server RELAY\nTargeted individual, adult content, malvertizing, keylogging, monitoring, hacking, CNC, remoted devices, tracking, malware attack,etc.\n(Auto populated: The last HTTPS certificate was signed by the US government's Department of Homeland Security (DHS), but what exactly is it and what does the certificate actually say?. and how does it look?)",
      "modified": "2023-12-01T10:01:56.921000",
      "created": "2023-11-01T11:41:44.861000",
      "tags": [
        "record type",
        "ttl value",
        "data",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "server",
        "whois lookup",
        "creation date",
        "dnssec",
        "domain name",
        "status",
        "abuse contact",
        "email",
        "registrar abuse",
        "contact phone",
        "date",
        "whois lookups",
        "iana id",
        "domain status",
        "registrar url",
        "registrar whois",
        "first",
        "execution",
        "tsara brashears",
        "ssl certificate",
        "april",
        "threat roundup",
        "october",
        "december",
        "roundup",
        "september",
        "whois record",
        "blustealer",
        "raspberry robin",
        "redline stealer",
        "gopuram",
        "hacktool",
        "skynet",
        "android",
        "quasar",
        "download",
        "malware",
        "hijacker",
        "monitoring",
        "installer",
        "ermac",
        "attack",
        "blackguard",
        "core",
        "awful",
        "twitter",
        "agent tesla",
        "trickbot",
        "ursnif",
        "chaos",
        "metasploit",
        "formbook",
        "metro",
        "name verdict",
        "exit",
        "traffic",
        "node tcp",
        "et tor",
        "known tor",
        "relayrouter",
        "united",
        "team malware",
        "firehol et",
        "tor known",
        "redline",
        "detection list",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malicious url",
        "blacklist",
        "phishing",
        "union",
        "team",
        "bank",
        "unsafe",
        "contacted",
        "bundled",
        "project",
        "ransomexx"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Lithuania"
      ],
      "malware_families": [
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 42,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3674,
        "domain": 1422,
        "FileHash-SHA1": 117,
        "FileHash-SHA256": 3178,
        "URL": 8884,
        "email": 2,
        "CVE": 3,
        "FileHash-MD5": 167
      },
      "indicator_count": 17447,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "911 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65423a941aa6527fbbe40a53",
      "name": "RedLine",
      "description": "CNC server.telegrafix.com. Brute force passwords using SSH on server RELAY\nTargeted individual, monitoring, hacking, CNC, remoted devices, tracking, malware attack,etc.\n(Auto populated: The last HTTPS certificate was signed by the US government's Department of Homeland Security (DHS), but what exactly is it and what does the certificate actually say?. and how does it look?)",
      "modified": "2023-12-01T10:01:56.921000",
      "created": "2023-11-01T11:46:28.418000",
      "tags": [
        "record type",
        "ttl value",
        "data",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "server",
        "whois lookup",
        "creation date",
        "dnssec",
        "domain name",
        "status",
        "abuse contact",
        "email",
        "registrar abuse",
        "contact phone",
        "date",
        "whois lookups",
        "iana id",
        "domain status",
        "registrar url",
        "registrar whois",
        "first",
        "execution",
        "tsara brashears",
        "ssl certificate",
        "april",
        "threat roundup",
        "october",
        "december",
        "roundup",
        "september",
        "whois record",
        "blustealer",
        "raspberry robin",
        "redline stealer",
        "gopuram",
        "hacktool",
        "skynet",
        "android",
        "quasar",
        "download",
        "malware",
        "hijacker",
        "monitoring",
        "installer",
        "ermac",
        "attack",
        "blackguard",
        "core",
        "awful",
        "twitter",
        "agent tesla",
        "trickbot",
        "ursnif",
        "chaos",
        "metasploit",
        "formbook",
        "metro",
        "name verdict",
        "exit",
        "traffic",
        "node tcp",
        "et tor",
        "known tor",
        "relayrouter",
        "united",
        "team malware",
        "firehol et",
        "tor known",
        "redline",
        "detection list",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malicious url",
        "blacklist",
        "phishing",
        "union",
        "team",
        "bank",
        "unsafe",
        "contacted",
        "bundled",
        "project",
        "ransomexx"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Lithuania"
      ],
      "malware_families": [
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 45,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3674,
        "domain": 1422,
        "FileHash-SHA1": 117,
        "FileHash-SHA256": 3178,
        "URL": 8884,
        "email": 2,
        "CVE": 3,
        "FileHash-MD5": 167
      },
      "indicator_count": 17447,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "911 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6545a281ce7426288033f81e",
      "name": "CNC server.telegrafix.com",
      "description": "",
      "modified": "2023-12-01T10:01:56.921000",
      "created": "2023-11-04T01:46:41.933000",
      "tags": [
        "record type",
        "ttl value",
        "data",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "server",
        "whois lookup",
        "creation date",
        "dnssec",
        "domain name",
        "status",
        "abuse contact",
        "email",
        "registrar abuse",
        "contact phone",
        "date",
        "whois lookups",
        "iana id",
        "domain status",
        "registrar url",
        "registrar whois",
        "first",
        "execution",
        "tsara brashears",
        "ssl certificate",
        "april",
        "threat roundup",
        "october",
        "december",
        "roundup",
        "september",
        "whois record",
        "blustealer",
        "raspberry robin",
        "redline stealer",
        "gopuram",
        "hacktool",
        "skynet",
        "android",
        "quasar",
        "download",
        "malware",
        "hijacker",
        "monitoring",
        "installer",
        "ermac",
        "attack",
        "blackguard",
        "core",
        "awful",
        "twitter",
        "agent tesla",
        "trickbot",
        "ursnif",
        "chaos",
        "metasploit",
        "formbook",
        "metro",
        "name verdict",
        "exit",
        "traffic",
        "node tcp",
        "et tor",
        "known tor",
        "relayrouter",
        "united",
        "team malware",
        "firehol et",
        "tor known",
        "redline",
        "detection list",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malicious url",
        "blacklist",
        "phishing",
        "union",
        "team",
        "bank",
        "unsafe",
        "contacted",
        "bundled",
        "project",
        "ransomexx"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Lithuania"
      ],
      "malware_families": [
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65423978ca5e5c9931b586a5",
      "export_count": 46,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3674,
        "domain": 1422,
        "FileHash-SHA1": 117,
        "FileHash-SHA256": 3178,
        "URL": 8884,
        "email": 2,
        "CVE": 3,
        "FileHash-MD5": 167
      },
      "indicator_count": 17447,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "911 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "652b1d2b113b44d8a0745592",
      "name": "LokiBot (LokiPWS) IoC between 2020 and 2023 - Collection made from public sources",
      "description": "These IoC are a collection of LokiBot C2 Data collected from public sources and automatically enriched by OTX. \nIf you find any true false positives, please contact me via my socials: https://linktr.ee/gi7w0rm",
      "modified": "2023-11-13T22:04:06.580000",
      "created": "2023-10-14T22:58:51.814000",
      "tags": [
        "LokiBot",
        "LokiPWS",
        "stealer"
      ],
      "references": [
        "https://raw.githubusercontent.com/Gi7w0rm/MalwareConfigLists/main/LokiBot/lokibot_2020_to_2023.txt"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "win.lokipws",
          "display_name": "win.lokipws",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/Lokibot",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/Lokibot",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "@Gi7w0rm",
        "id": "165134",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 31,
        "FileHash-SHA1": 2,
        "URL": 6013,
        "domain": 2170,
        "hostname": 328
      },
      "indicator_count": 8544,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "928 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "http://gistsstack.com/panel/fre.php",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "http://gistsstack.com/panel/fre.php",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780170402.7459877
}