{
  "type": "URL",
  "indicator": "http://hammerjs.github.io/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "http://hammerjs.github.io/",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "whitelist",
        "message": "Whitelisted domain github.io",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain github.io",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3427849584,
      "indicator": "http://hammerjs.github.io/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "68dbee57fc8b1739c2223376",
          "name": "Serious Privacy Violations \u2022 Groundup Monitoring  a Household \u2022 IoT",
          "description": "Thank you for the tip. It\u2019s taken me 98 days to get to this one. Enlightening. \n\nI\u2019m going to reserve my comments. A lot of new stuff here. \n#Intrusive\n#helix #helix_foundry_connection #amazon #advesaries_in_the_middle",
          "modified": "2025-10-30T14:05:43.818000",
          "created": "2025-09-30T14:51:03.111000",
          "tags": [
            "united",
            "trojandropper",
            "passive dns",
            "lowfi",
            "head meta",
            "moved title",
            "twitter",
            "moved",
            "a href",
            "present sep",
            "aaaa",
            "ireland",
            "ip address",
            "emails",
            "reverse dns",
            "malware",
            "unruy",
            "upatre",
            "snowjan",
            "zusy",
            "vb",
            "x.com",
            "downloader",
            "trojan",
            "agent",
            "pe32 executable",
            "intel",
            "ms windows",
            "reads",
            "medium",
            "write",
            "delete",
            "top source",
            "push",
            "germany unknown",
            "name servers",
            "head body",
            "urls",
            "files ip",
            "url analysis",
            "address",
            "asn as3320",
            "present jun",
            "present jul",
            "present may",
            "present oct",
            "present feb",
            "present nov",
            "url hostname",
            "server response",
            "learn",
            "command",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "development att",
            "ssl certificate",
            "path",
            "sha256",
            "pattern match",
            "ffffff",
            "general",
            "iframe",
            "click",
            "strings",
            "leon",
            "dns requests",
            "domain address",
            "http",
            "files domain",
            "files related",
            "ireland unknown",
            "files",
            "dublin",
            "ireland asn",
            "as16509",
            "script urls",
            "dubai real",
            "meta",
            "encrypt",
            "austria unknown",
            "austria asn",
            "asnone dns",
            "resolutions",
            "handle",
            "rdap database",
            "iana registrar",
            "helix",
            "foundry",
            "iot",
            "apple",
            "itunes",
            "amazon",
            "unknown ns",
            "found",
            "content type",
            "gmt server",
            "x xss",
            "certificate",
            "domain add",
            "error",
            "code",
            "date",
            "entries",
            "next associated",
            "body html",
            "title",
            "present aug",
            "servers",
            "status",
            "for privacy",
            "redacted for",
            "spawns",
            "ck techniques",
            "url add",
            "pulse pulses",
            "related nids",
            "files location",
            "flag united",
            "showing",
            "media",
            "cname",
            "invalid url",
            "creation date",
            "body",
            "sha1",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "ascii text",
            "mitre att",
            "show technique",
            "hybrid",
            "local"
          ],
          "references": [
            "families.google/intl/pt-PT_ALL/familylink \u2022 cameyo.google \u2022 googlecampaigns.com \u2022. chrome.com.bh",
            "t-iot.de \u2022 dockerregistry.xlab.t-iot.de\t \u2022 netbox.nic.xlab.t-iot.de",
            "www.n-helix.com - Foundry remnant",
            "itunes.apple.com \u2022 api.amazon.com",
            "https://webclientshellserver-prod-trafficmanager-net.s-0005.dual-s-msedge.net",
            "https://www.matchsticksandgasoline.com/2018/11/2/18051280/the-morning-after-colorado-if-you-want-to-be-a-goalie-skip-these-highlights-mark-giordano",
            "http://s.vebnox.com \u2022  vebnox.com \u2022 http://stulancer.vebnox.com \u2022 vebnox.com \u2022  http://vedonate.vebnox.com \u2022 vebnox.com \u2022  https://home.vebnox.com vebnox.com \u2022 https://vedonate.vebnox.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Trojan:Win32/QQpass",
              "display_name": "Trojan:Win32/QQpass",
              "target": "/malware/Trojan:Win32/QQpass"
            },
            {
              "id": "Win.Malware.Zusy",
              "display_name": "Win.Malware.Zusy",
              "target": null
            },
            {
              "id": "Trojandropper:Win32/VB.IL",
              "display_name": "Trojandropper:Win32/VB.IL",
              "target": "/malware/Trojandropper:Win32/VB.IL"
            },
            {
              "id": "Win.Malware.Snojan",
              "display_name": "Win.Malware.Snojan",
              "target": null
            },
            {
              "id": "Win.Packed",
              "display_name": "Win.Packed",
              "target": null
            },
            {
              "id": "Upatre",
              "display_name": "Upatre",
              "target": null
            },
            {
              "id": "#Lowfi:HSTR:MSIL/PossibleDownloader.S01",
              "display_name": "#Lowfi:HSTR:MSIL/PossibleDownloader.S01",
              "target": null
            },
            {
              "id": "Unruy",
              "display_name": "Unruy",
              "target": null
            },
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            },
            {
              "id": "ALF:Trojan:Win32/Agent.WTK!MTB",
              "display_name": "ALF:Trojan:Win32/Agent.WTK!MTB",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3399,
            "domain": 790,
            "FileHash-MD5": 174,
            "FileHash-SHA1": 171,
            "FileHash-SHA256": 3349,
            "hostname": 1325,
            "email": 10,
            "SSLCertFingerprint": 9
          },
          "indicator_count": 9227,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 148,
          "modified_text": "213 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "689d7fd544aa8cf483b02d5c",
          "name": "Sinkhole | Win32/Dofoil.R CnC Beacon",
          "description": "#LowFI:VBExpensiveLoop\n*Worm:Win32/Gamarue [Static Pe Anomaly \u2022\nContains Pe Overlay \u2022\nBinary Yara]\n- Win32/Dofoil.R CnC Beacon |\nAlerts:\n\u2022 suspicious_iocontrol_codes\n\u2022 physical_drive_access",
          "modified": "2025-09-13T06:02:44.359000",
          "created": "2025-08-14T06:19:01.666000",
          "tags": [
            "lowfi",
            "united",
            "entries",
            "passive dns",
            "open ports",
            "next associated",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "domain",
            "address",
            "creation date",
            "name servers",
            "date",
            "hostname add",
            "dynamicloader",
            "medium",
            "fake",
            "high",
            "post",
            "show",
            "search",
            "observed http",
            "reg add",
            "copy",
            "write",
            "june",
            "malware",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "sha1",
            "sha256",
            "size",
            "pattern match",
            "ascii text",
            "mitre att",
            "ck id",
            "null",
            "error",
            "click",
            "body",
            "august",
            "hybrid",
            "general",
            "local",
            "path",
            "strings",
            "refresh",
            "tools",
            "meta",
            "onload",
            "span",
            "learn",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "javascript",
            "defense evasion",
            "spawns",
            "mask",
            "generator"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 175,
            "FileHash-SHA1": 180,
            "FileHash-SHA256": 458,
            "URL": 436,
            "domain": 69,
            "hostname": 156,
            "email": 1,
            "SSLCertFingerprint": 9
          },
          "indicator_count": 1484,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 145,
          "modified_text": "260 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a598f3d4e8c2cffd4f73",
          "name": "SMS SPY  \u2022 Remote Access",
          "description": "",
          "modified": "2023-12-06T16:47:19.410000",
          "created": "2023-12-06T16:47:19.410000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1043,
            "hostname": 684,
            "domain": 639,
            "FileHash-MD5": 382,
            "FileHash-SHA1": 212,
            "URL": 2215
          },
          "indicator_count": 5175,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "650b67e5a3ff15727eed5a06",
          "name": "SMS SPY  \u2022 Remote Access",
          "description": "Malvertizing. Spyware\nMalbranding:\nTagging tool tags allows adversaries to tag targets name in malicious website. Target may be lured by salacious content featuring their own name or someone known to person,  click on link infecting devices.",
          "modified": "2023-10-20T21:00:45.519000",
          "created": "2023-09-20T21:45:09.422000",
          "tags": [
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "united",
            "engineering",
            "phishing",
            "bank",
            "cobalt strike",
            "emotet",
            "phishtank",
            "spammer",
            "malware site",
            "deepscan",
            "malicious",
            "smsspy",
            "bradesco",
            "stealer",
            "facebook",
            "download",
            "service",
            "zbot",
            "formbook",
            "coinminer",
            "raccoonstealer",
            "social engineering",
            "vj75",
            "http",
            "oid3",
            "vis1",
            "redirect chain",
            "z554903578",
            "slfrd1",
            "xpccbgarern6r",
            "xpcyqqhir7yvq",
            "xpchgxkc32lbs",
            "pattern match",
            "q0o0mahttp",
            "pfunction",
            "lkvoid",
            "glfunction",
            "befunction",
            "mrtk",
            "7jfjrw",
            "zzvyn6uhsb"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Trojan:MSIL/RacoonStealer",
              "display_name": "Trojan:MSIL/RacoonStealer",
              "target": "/malware/Trojan:MSIL/RacoonStealer"
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/Zbot",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/Zbot",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Bradesco",
              "display_name": "TrojanSpy:Win32/Bradesco",
              "target": "/malware/TrojanSpy:Win32/Bradesco"
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 36,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 639,
            "hostname": 684,
            "FileHash-MD5": 382,
            "FileHash-SHA1": 212,
            "FileHash-SHA256": 1043,
            "URL": 2215
          },
          "indicator_count": 5175,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "954 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f86049cb1c945f7701075",
          "name": "Hetzner - malware hosting",
          "description": "function ar(aw,av,au,at) is a new type of tracking, which uses the same code as the Matomo tracking tool and its built-up functionality to track where a tracker is located.",
          "modified": "2022-05-20T00:01:19.453000",
          "created": "2022-04-20T04:03:16.817000",
          "tags": [
            "param",
            "locale",
            "return",
            "stripped",
            "regexp",
            "html",
            "lang",
            "lightweight",
            "dual",
            "javascript i18n",
            "entity",
            "body",
            "meta",
            "typeradio",
            "ttav",
            "width",
            "ttaelt",
            "shadowwidth",
            "tagtotip",
            "html element",
            "shadow",
            "closebtncolors",
            "fadein",
            "null",
            "sticky",
            "close",
            "false",
            "path",
            "config",
            "span",
            "iframe",
            "kill",
            "inside",
            "first",
            "typetext",
            "typepassword",
            "input",
            "typeof define",
            "typeof module",
            "html tags",
            "px20trnf",
            "dom element",
            "date",
            "this",
            "typeof e",
            "function",
            "left",
            "bottom",
            "nullt",
            "right",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "js foundation",
            "error",
            "captcha",
            "access site",
            "click",
            "strong",
            "ddos",
            "hetzner online",
            "gmbh element",
            "lztextlink",
            "script",
            "lzrscr",
            "scrb64d",
            "livezilladata",
            "ovlcwm",
            "activedocument",
            "lzsds",
            "lzsde",
            "lzsdeg",
            "cant load",
            "gv1023",
            "typecheckbox",
            "5deg",
            "20deg",
            "45deg",
            "2000px00",
            "2000px0",
            "10px00",
            "60px0",
            "mintime",
            "await",
            "number",
            "typeof n",
            "typeof symbol",
            "cookieconsent",
            "showcookiemodal",
            "cookie banner",
            "agree",
            "agreed",
            "expiresthu",
            "anchorregex",
            "typeerror",
            "swiper",
            "hammer",
            "bnm",
            "software",
            "azaz",
            "form",
            "void",
            "zert",
            "accept",
            "android",
            "trace",
            "import",
            "string",
            "please",
            "blob",
            "matomo",
            "post",
            "javascript",
            "link",
            "license"
          ],
          "references": [
            "xfe-IP-136.243.64.87-stix2-2.1-export.json",
            "https://matomo.hetzner.com/matomo.js",
            "xfe-URL-matomo.hetzner.com-stix2-2.1-export.json",
            "https:///livesupport.hetzner.de/resource.php?t=js&1=jsglobal.min.js&2=jsbox.min.js&3=jstrack.min.js&v=ahgzixd7&4=jsextern.min.js",
            "https://livesupport.hetzner.de/server.php?rqst=track&output=jcrpt&group=Produktberatung&hg=Pw__&hcgs=MQ__&htgs=MQ__&ovltwo=MQ__&ovlv=djI_&ovlc=MQ__&esc=IzU4NTg1YQ__&epc=I0JFMTUyRA__&ovlts=MA__&ovlmr=MTAw&ovlmb=MjY_&hfk=MQ__&ovloo=MQ__&hots=MQ__&hott=MQ__&nse=0.615520170244701",
            "https://livesupport.hetzner.de/script.php?id=eec8dcd79d6fdf905136b99875c1d599",
            "https://accounts.hetzner.com/login",
            "https://accounts.hetzner.com/build/runtime.188fa053.js",
            "https://accounts.hetzner.com/build/755.5a8586e9.js",
            "https://accounts.hetzner.com/build/app.dc073715.js",
            "https://accounts.hetzner.com/build/802.3a7546ef.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery-migrate.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/ui/jquery-ui.js",
            "https://konsoleh.your-server.de/templates/ui-default/de/styles/login.css.php",
            "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/wz_tooltip.js",
            "xfe-URL-livesupport.hetzner.de-stix2-2.1-export.json",
            "xfe-URL-konsoleh.your-server.de-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ActiveDocument",
              "display_name": "ActiveDocument",
              "target": null
            },
            {
              "id": "OVLCWM",
              "display_name": "OVLCWM",
              "target": null
            },
            {
              "id": "Hammer",
              "display_name": "Hammer",
              "target": null
            },
            {
              "id": "BNM",
              "display_name": "BNM",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2308,
            "hostname": 949,
            "FileHash-SHA256": 125,
            "domain": 372,
            "FileHash-SHA1": 3,
            "FileHash-MD5": 256
          },
          "indicator_count": 4013,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1473 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f3287d722d8d85700b75d",
          "name": "Leaseweb.com - malware hosting",
          "description": "function D(t,e,n), as well as window.com, has been frozen by a single function, as part of a series of \"snoopers' checks\"...",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T22:07:03.024000",
          "tags": [
            "11px center",
            "html",
            "typetext",
            "typeurl",
            "typeemail",
            "typetel",
            "typenumber",
            "typedate",
            "color",
            "marketo forms",
            "cross domain",
            "null",
            "click",
            "forceclose",
            "lightbox",
            "slideshow",
            "controls",
            "hide",
            "safari",
            "image",
            "mozilla",
            "explorer",
            "entity",
            "linear",
            "date",
            "jquery",
            "iframe",
            "close",
            "loops",
            "class",
            "stretch",
            "false",
            "function",
            "abbb",
            "typeerror",
            "boolean",
            "body",
            "object",
            "array",
            "regexp",
            "bind",
            "error",
            "void",
            "hammer",
            "form",
            "this",
            "views slideshow",
            "zindex1",
            "ajax",
            "href",
            "default",
            "thumb",
            "msgesture",
            "mspointerdown",
            "next",
            "stop",
            "type",
            "index",
            "event",
            "snapabugcbmbtn",
            "chat",
            "hidden",
            "leaf",
            "open",
            "dump",
            "window",
            "win32",
            "footer",
            "front",
            "drupal",
            "command",
            "implement",
            "copyright",
            "route",
            "foundation",
            "thecookie",
            "remove",
            "example",
            "backport",
            "grab",
            "span",
            "import",
            "attr",
            "string",
            "invalid json",
            "domparser",
            "number",
            "script",
            "closure library",
            "symbol",
            "array int8array",
            "caregexp",
            "legacy",
            "boardman",
            "fontface",
            "typeof d",
            "promise",
            "parseint",
            "marketo",
            "rangeerror",
            "uint8array",
            "typeof b",
            "buffer",
            "path",
            "takk",
            "kiitos",
            "buttons};kb(convertedmessage);break;case\"/sys\":var",
            "acum",
            "ufunction",
            "ffunction",
            "gfunction",
            "mchtd",
            "cancel",
            "thank",
            "enter",
            "please",
            "cobrowsing",
            "accept",
            "decline",
            "back",
            "comment",
            "grazie",
            "klik",
            "super",
            "dados",
            "hello",
            "vd",
            "reduceright",
            "trackevent",
            "lead",
            "query",
            "videos",
            "leaseweb",
            "trackpageview",
            "contact",
            "download",
            "metal",
            "code",
            "functional",
            "member",
            "hnew regexp",
            "qfunction",
            "adview",
            "addbillinginfo",
            "addtocart",
            "addtolist",
            "install",
            "cookiebot",
            "iabv2",
            "jsonversion",
            "cookie script",
            "methodstrict",
            "ticket",
            "id attribute",
            "cookiebot setup",
            "cookieconsent",
            "customevent",
            "09af",
            "ver0",
            "tag0",
            "extdata0",
            "ua ch",
            "invalid",
            "iterator",
            "service",
            "phonenumber",
            "facebook",
            "meta",
            "ytconfig",
            "edge",
            "swhealthlog",
            "logsdatabasev2",
            "trident",
            "android",
            "infinity",
            "pnull",
            "style",
            "ctnull",
            "post",
            "uint32array",
            "fanull",
            "license",
            "ynull",
            "config"
          ],
          "references": [
            "https://consent.cookiebot.com/1e27dadb-e278-4c02-aa4f-43f9222c4fbb/cc.js?renew=false&referer=www.leaseweb.com&culture=en&dnt=false",
            "https://j.clarity.ms/s/0.6.34/clarity.js",
            "https://www.google-analytics.com/plugins/ua/linkid.js",
            "https://www.youtube.com/s/player/19eb72e4/www-widgetapi.vflset/www-widgetapi.js",
            "https://www.youtube.com/iframe_api",
            "https://connect.facebook.net/signals/config/399164440484826?v=2.9.57&r=stable",
            "https://bat.bing.com/bat.js",
            "https://consent.cookiebot.com/uc.js?cbid=1e27dadb-e278-4c02-aa4f-43f9222c4fbb&culture=en",
            "https://snap.licdn.com/li.lms-analytics/insight.min.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-NWPHSS",
            "https://storage.googleapis.com/snapengage-eu/js/e9219576-8f74-40b5-8b6f-bbad33f6ca57.js",
            "https://munchkin.marketo.net/161/munchkin.js",
            "https://app-lon04.marketo.com/js/forms2/js/forms2.min.js",
            "https://munchkin.marketo.net/munchkin.js",
            "https://www.leaseweb.com/sites/all/modules/custom/lsw_marketo/js/lsw_marketo_forms.js",
            "https://use.fortawesome.com/03018d9d.js",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1001847692/?random=1650405011980&cv=9&fst=1650405011980&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/952389962/?random=1650405011982&cv=9&fst=1650405011982&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
            "https://eu.snapengage.com/chatjs/ServiceGetConfig?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
            "https://eu.snapengage.com/chatjs/servicegetproactivegeodata?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
            "https://bat.bing.com/p/action/5602105.js",
            "https://eu.snapengage.com/chatjs/servicegetallavailableagents?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57&t=1",
            "https://www.googleadservices.com/pagead/conversion_async.js",
            "https://www.leaseweb.com/sites/default/files/js/js_kwxcSFD2Y0_BPtdJClYUy5H8THI_5EycUmIgIGWaGYs.js",
            "https://www.leaseweb.com/sites/default/files/js/js_wcSNEXVJ4Xjhkf8qhMguEPZJTDTMNmPaJM-YWdAOhQE.js",
            "https://www.leaseweb.com/sites/default/files/js/js_kI_QwKJlaBz9CzQdENdUBFiEl4aehfjf4_-9taiwcCE.js",
            "https://www.leaseweb.com/sites/default/files/js/js_zoLA7TweXam0kYiqJrXepqBWmyDoP1sLSlHoZcveFnY.js",
            "https://www.leaseweb.com/sites/default/files/js/js_6FowaFXT9bT78hf9earPdGcdTmvsFiaBzKgFl9P4fSo.js",
            "https://www.leaseweb.com/sites/default/files/js/js_6lTJ_m6ahwXas7Efbw8ZYEMSaecrGw8ilNALfvIPNUw.js",
            "https://analytics.twitter.com/i/adsct?type=javascript&version=2.0.4&p_id=Twitter&p_user_id=0&txn_id=nxsfu&events=%5B%5B%22pageview%22%2Cnull%5D%5D&tw_sale_amount=0&tw_order_quantity=0&tw_iframe_status=0&event_id=511b6f48-2639-478c-a251-b09fcbae76e7&tw_document_href=https%3A%2F%2Fwww.leaseweb.com%2F&tpx_cb=twttr.conversion.loadPixels",
            "https://bid.g.doubleclick.net/xbbe/pixel?d=KAE",
            "https://consentcdn.cookiebot.com/sdk/bc-v4.min.html",
            "https://app-lon04.marketo.com/index.php/form/XDFrame",
            "https://app-lon04.marketo.com/js/forms2/css/forms2-theme-plain.css",
            "https://www.leaseweb.com/sites/default/files/css/css_47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU.css",
            "https://www.leaseweb.com/sites/default/files/css/css_7CYF9En6DNp6AojfSKnT8USKR3GvzPwznmTqLTKT9VM.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Tunisia"
          ],
          "malware_families": [
            {
              "id": "Ajax",
              "display_name": "Ajax",
              "target": null
            },
            {
              "id": "Kiitos",
              "display_name": "Kiitos",
              "target": null
            },
            {
              "id": "Takk",
              "display_name": "Takk",
              "target": null
            },
            {
              "id": "Acum",
              "display_name": "Acum",
              "target": null
            },
            {
              "id": "buttons};kb(convertedMessage);break;case\"/SYS\":var",
              "display_name": "buttons};kb(convertedMessage);break;case\"/SYS\":var",
              "target": null
            },
            {
              "id": "Vd",
              "display_name": "Vd",
              "target": null
            },
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 648,
            "domain": 469,
            "URL": 2037,
            "FileHash-SHA256": 705,
            "email": 7
          },
          "indicator_count": 3866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1474 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "xfe-IP-136.243.64.87-stix2-2.1-export.json",
        "https://connect.facebook.net/signals/config/399164440484826?v=2.9.57&r=stable",
        "https://eu.snapengage.com/chatjs/servicegetproactivegeodata?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
        "https://www.leaseweb.com/sites/default/files/js/js_kI_QwKJlaBz9CzQdENdUBFiEl4aehfjf4_-9taiwcCE.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/styles/login.css.php",
        "https://j.clarity.ms/s/0.6.34/clarity.js",
        "t-iot.de \u2022 dockerregistry.xlab.t-iot.de\t \u2022 netbox.nic.xlab.t-iot.de",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1001847692/?random=1650405011980&cv=9&fst=1650405011980&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://livesupport.hetzner.de/server.php?rqst=track&output=jcrpt&group=Produktberatung&hg=Pw__&hcgs=MQ__&htgs=MQ__&ovltwo=MQ__&ovlv=djI_&ovlc=MQ__&esc=IzU4NTg1YQ__&epc=I0JFMTUyRA__&ovlts=MA__&ovlmr=MTAw&ovlmb=MjY_&hfk=MQ__&ovloo=MQ__&hots=MQ__&hott=MQ__&nse=0.615520170244701",
        "https://accounts.hetzner.com/build/802.3a7546ef.js",
        "https://bid.g.doubleclick.net/xbbe/pixel?d=KAE",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NWPHSS",
        "https://www.youtube.com/iframe_api",
        "https://bat.bing.com/bat.js",
        "https://eu.snapengage.com/chatjs/ServiceGetConfig?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
        "https://www.leaseweb.com/sites/default/files/js/js_6lTJ_m6ahwXas7Efbw8ZYEMSaecrGw8ilNALfvIPNUw.js",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery-migrate.js",
        "https://www.google-analytics.com/plugins/ua/linkid.js",
        "https://www.matchsticksandgasoline.com/2018/11/2/18051280/the-morning-after-colorado-if-you-want-to-be-a-goalie-skip-these-highlights-mark-giordano",
        "https://www.youtube.com/s/player/19eb72e4/www-widgetapi.vflset/www-widgetapi.js",
        "https://use.fortawesome.com/03018d9d.js",
        "https://www.leaseweb.com/sites/default/files/js/js_zoLA7TweXam0kYiqJrXepqBWmyDoP1sLSlHoZcveFnY.js",
        "xfe-URL-livesupport.hetzner.de-stix2-2.1-export.json",
        "https://www.leaseweb.com/sites/all/modules/custom/lsw_marketo/js/lsw_marketo_forms.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/wz_tooltip.js",
        "www.n-helix.com - Foundry remnant",
        "https://app-lon04.marketo.com/index.php/form/XDFrame",
        "https://matomo.hetzner.com/matomo.js",
        "https://storage.googleapis.com/snapengage-eu/js/e9219576-8f74-40b5-8b6f-bbad33f6ca57.js",
        "https://app-lon04.marketo.com/js/forms2/css/forms2-theme-plain.css",
        "http://s.vebnox.com \u2022  vebnox.com \u2022 http://stulancer.vebnox.com \u2022 vebnox.com \u2022  http://vedonate.vebnox.com \u2022 vebnox.com \u2022  https://home.vebnox.com vebnox.com \u2022 https://vedonate.vebnox.com",
        "https://www.leaseweb.com/sites/default/files/css/css_47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU.css",
        "https://www.leaseweb.com/sites/default/files/js/js_wcSNEXVJ4Xjhkf8qhMguEPZJTDTMNmPaJM-YWdAOhQE.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/952389962/?random=1650405011982&cv=9&fst=1650405011982&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://consentcdn.cookiebot.com/sdk/bc-v4.min.html",
        "https://bat.bing.com/p/action/5602105.js",
        "https://app-lon04.marketo.com/js/forms2/js/forms2.min.js",
        "https://accounts.hetzner.com/build/runtime.188fa053.js",
        "itunes.apple.com \u2022 api.amazon.com",
        "https://livesupport.hetzner.de/script.php?id=eec8dcd79d6fdf905136b99875c1d599",
        "https://munchkin.marketo.net/munchkin.js",
        "https://eu.snapengage.com/chatjs/servicegetallavailableagents?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57&t=1",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/ui/jquery-ui.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery.js",
        "xfe-URL-konsoleh.your-server.de-stix2-2.1-export.json",
        "https://webclientshellserver-prod-trafficmanager-net.s-0005.dual-s-msedge.net",
        "https://www.leaseweb.com/sites/default/files/js/js_6FowaFXT9bT78hf9earPdGcdTmvsFiaBzKgFl9P4fSo.js",
        "https://analytics.twitter.com/i/adsct?type=javascript&version=2.0.4&p_id=Twitter&p_user_id=0&txn_id=nxsfu&events=%5B%5B%22pageview%22%2Cnull%5D%5D&tw_sale_amount=0&tw_order_quantity=0&tw_iframe_status=0&event_id=511b6f48-2639-478c-a251-b09fcbae76e7&tw_document_href=https%3A%2F%2Fwww.leaseweb.com%2F&tpx_cb=twttr.conversion.loadPixels",
        "https://consent.cookiebot.com/1e27dadb-e278-4c02-aa4f-43f9222c4fbb/cc.js?renew=false&referer=www.leaseweb.com&culture=en&dnt=false",
        "https://www.leaseweb.com/sites/default/files/css/css_7CYF9En6DNp6AojfSKnT8USKR3GvzPwznmTqLTKT9VM.css",
        "https://www.googleadservices.com/pagead/conversion_async.js",
        "families.google/intl/pt-PT_ALL/familylink \u2022 cameyo.google \u2022 googlecampaigns.com \u2022. chrome.com.bh",
        "https:///livesupport.hetzner.de/resource.php?t=js&1=jsglobal.min.js&2=jsbox.min.js&3=jstrack.min.js&v=ahgzixd7&4=jsextern.min.js",
        "https://www.leaseweb.com/sites/default/files/js/js_kwxcSFD2Y0_BPtdJClYUy5H8THI_5EycUmIgIGWaGYs.js",
        "xfe-URL-matomo.hetzner.com-stix2-2.1-export.json",
        "https://accounts.hetzner.com/login",
        "https://consent.cookiebot.com/uc.js?cbid=1e27dadb-e278-4c02-aa4f-43f9222c4fbb&culture=en",
        "https://accounts.hetzner.com/build/app.dc073715.js",
        "https://munchkin.marketo.net/161/munchkin.js",
        "https://accounts.hetzner.com/build/755.5a8586e9.js"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Formbook",
            "Upatre",
            "Trojandropper:win32/vb.il",
            "Win.malware.snojan",
            "Win.malware.zusy",
            "Acum",
            "Trojan:win32/qqpass",
            "Cobalt strike",
            "Takk",
            "Trojanspy:win32/bradesco",
            "Ajax",
            "Bnm",
            "Hammer",
            "Ovlcwm",
            "Trojan:msil/racoonstealer",
            "#lowfi:hstr:msil/possibledownloader.s01",
            "Alf:trojan:win32/agent.wtk!mtb",
            "Alf:heraklezeval:trojan:win32/zbot",
            "Vd",
            "Unruy",
            "Buttons};kb(convertedmessage);break;case\"/sys\":var",
            "Reduceright",
            "Kiitos",
            "Win.packed",
            "Activedocument",
            "Malware"
          ],
          "industries": [],
          "unique_indicators": 22285
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/github.io",
    "whois": "http://whois.domaintools.com/github.io",
    "domain": "github.io",
    "hostname": "hammerjs.github.io"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "68dbee57fc8b1739c2223376",
      "name": "Serious Privacy Violations \u2022 Groundup Monitoring  a Household \u2022 IoT",
      "description": "Thank you for the tip. It\u2019s taken me 98 days to get to this one. Enlightening. \n\nI\u2019m going to reserve my comments. A lot of new stuff here. \n#Intrusive\n#helix #helix_foundry_connection #amazon #advesaries_in_the_middle",
      "modified": "2025-10-30T14:05:43.818000",
      "created": "2025-09-30T14:51:03.111000",
      "tags": [
        "united",
        "trojandropper",
        "passive dns",
        "lowfi",
        "head meta",
        "moved title",
        "twitter",
        "moved",
        "a href",
        "present sep",
        "aaaa",
        "ireland",
        "ip address",
        "emails",
        "reverse dns",
        "malware",
        "unruy",
        "upatre",
        "snowjan",
        "zusy",
        "vb",
        "x.com",
        "downloader",
        "trojan",
        "agent",
        "pe32 executable",
        "intel",
        "ms windows",
        "reads",
        "medium",
        "write",
        "delete",
        "top source",
        "push",
        "germany unknown",
        "name servers",
        "head body",
        "urls",
        "files ip",
        "url analysis",
        "address",
        "asn as3320",
        "present jun",
        "present jul",
        "present may",
        "present oct",
        "present feb",
        "present nov",
        "url hostname",
        "server response",
        "learn",
        "command",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "development att",
        "ssl certificate",
        "path",
        "sha256",
        "pattern match",
        "ffffff",
        "general",
        "iframe",
        "click",
        "strings",
        "leon",
        "dns requests",
        "domain address",
        "http",
        "files domain",
        "files related",
        "ireland unknown",
        "files",
        "dublin",
        "ireland asn",
        "as16509",
        "script urls",
        "dubai real",
        "meta",
        "encrypt",
        "austria unknown",
        "austria asn",
        "asnone dns",
        "resolutions",
        "handle",
        "rdap database",
        "iana registrar",
        "helix",
        "foundry",
        "iot",
        "apple",
        "itunes",
        "amazon",
        "unknown ns",
        "found",
        "content type",
        "gmt server",
        "x xss",
        "certificate",
        "domain add",
        "error",
        "code",
        "date",
        "entries",
        "next associated",
        "body html",
        "title",
        "present aug",
        "servers",
        "status",
        "for privacy",
        "redacted for",
        "spawns",
        "ck techniques",
        "url add",
        "pulse pulses",
        "related nids",
        "files location",
        "flag united",
        "showing",
        "media",
        "cname",
        "invalid url",
        "creation date",
        "body",
        "sha1",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "ascii text",
        "mitre att",
        "show technique",
        "hybrid",
        "local"
      ],
      "references": [
        "families.google/intl/pt-PT_ALL/familylink \u2022 cameyo.google \u2022 googlecampaigns.com \u2022. chrome.com.bh",
        "t-iot.de \u2022 dockerregistry.xlab.t-iot.de\t \u2022 netbox.nic.xlab.t-iot.de",
        "www.n-helix.com - Foundry remnant",
        "itunes.apple.com \u2022 api.amazon.com",
        "https://webclientshellserver-prod-trafficmanager-net.s-0005.dual-s-msedge.net",
        "https://www.matchsticksandgasoline.com/2018/11/2/18051280/the-morning-after-colorado-if-you-want-to-be-a-goalie-skip-these-highlights-mark-giordano",
        "http://s.vebnox.com \u2022  vebnox.com \u2022 http://stulancer.vebnox.com \u2022 vebnox.com \u2022  http://vedonate.vebnox.com \u2022 vebnox.com \u2022  https://home.vebnox.com vebnox.com \u2022 https://vedonate.vebnox.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Trojan:Win32/QQpass",
          "display_name": "Trojan:Win32/QQpass",
          "target": "/malware/Trojan:Win32/QQpass"
        },
        {
          "id": "Win.Malware.Zusy",
          "display_name": "Win.Malware.Zusy",
          "target": null
        },
        {
          "id": "Trojandropper:Win32/VB.IL",
          "display_name": "Trojandropper:Win32/VB.IL",
          "target": "/malware/Trojandropper:Win32/VB.IL"
        },
        {
          "id": "Win.Malware.Snojan",
          "display_name": "Win.Malware.Snojan",
          "target": null
        },
        {
          "id": "Win.Packed",
          "display_name": "Win.Packed",
          "target": null
        },
        {
          "id": "Upatre",
          "display_name": "Upatre",
          "target": null
        },
        {
          "id": "#Lowfi:HSTR:MSIL/PossibleDownloader.S01",
          "display_name": "#Lowfi:HSTR:MSIL/PossibleDownloader.S01",
          "target": null
        },
        {
          "id": "Unruy",
          "display_name": "Unruy",
          "target": null
        },
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        },
        {
          "id": "ALF:Trojan:Win32/Agent.WTK!MTB",
          "display_name": "ALF:Trojan:Win32/Agent.WTK!MTB",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3399,
        "domain": 790,
        "FileHash-MD5": 174,
        "FileHash-SHA1": 171,
        "FileHash-SHA256": 3349,
        "hostname": 1325,
        "email": 10,
        "SSLCertFingerprint": 9
      },
      "indicator_count": 9227,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 148,
      "modified_text": "213 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "689d7fd544aa8cf483b02d5c",
      "name": "Sinkhole | Win32/Dofoil.R CnC Beacon",
      "description": "#LowFI:VBExpensiveLoop\n*Worm:Win32/Gamarue [Static Pe Anomaly \u2022\nContains Pe Overlay \u2022\nBinary Yara]\n- Win32/Dofoil.R CnC Beacon |\nAlerts:\n\u2022 suspicious_iocontrol_codes\n\u2022 physical_drive_access",
      "modified": "2025-09-13T06:02:44.359000",
      "created": "2025-08-14T06:19:01.666000",
      "tags": [
        "lowfi",
        "united",
        "entries",
        "passive dns",
        "open ports",
        "next associated",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "domain",
        "address",
        "creation date",
        "name servers",
        "date",
        "hostname add",
        "dynamicloader",
        "medium",
        "fake",
        "high",
        "post",
        "show",
        "search",
        "observed http",
        "reg add",
        "copy",
        "write",
        "june",
        "malware",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "sha1",
        "sha256",
        "size",
        "pattern match",
        "ascii text",
        "mitre att",
        "ck id",
        "null",
        "error",
        "click",
        "body",
        "august",
        "hybrid",
        "general",
        "local",
        "path",
        "strings",
        "refresh",
        "tools",
        "meta",
        "onload",
        "span",
        "learn",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "javascript",
        "defense evasion",
        "spawns",
        "mask",
        "generator"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 175,
        "FileHash-SHA1": 180,
        "FileHash-SHA256": 458,
        "URL": 436,
        "domain": 69,
        "hostname": 156,
        "email": 1,
        "SSLCertFingerprint": 9
      },
      "indicator_count": 1484,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 145,
      "modified_text": "260 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a598f3d4e8c2cffd4f73",
      "name": "SMS SPY  \u2022 Remote Access",
      "description": "",
      "modified": "2023-12-06T16:47:19.410000",
      "created": "2023-12-06T16:47:19.410000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1043,
        "hostname": 684,
        "domain": 639,
        "FileHash-MD5": 382,
        "FileHash-SHA1": 212,
        "URL": 2215
      },
      "indicator_count": 5175,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "650b67e5a3ff15727eed5a06",
      "name": "SMS SPY  \u2022 Remote Access",
      "description": "Malvertizing. Spyware\nMalbranding:\nTagging tool tags allows adversaries to tag targets name in malicious website. Target may be lured by salacious content featuring their own name or someone known to person,  click on link infecting devices.",
      "modified": "2023-10-20T21:00:45.519000",
      "created": "2023-09-20T21:45:09.422000",
      "tags": [
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "united",
        "engineering",
        "phishing",
        "bank",
        "cobalt strike",
        "emotet",
        "phishtank",
        "spammer",
        "malware site",
        "deepscan",
        "malicious",
        "smsspy",
        "bradesco",
        "stealer",
        "facebook",
        "download",
        "service",
        "zbot",
        "formbook",
        "coinminer",
        "raccoonstealer",
        "social engineering",
        "vj75",
        "http",
        "oid3",
        "vis1",
        "redirect chain",
        "z554903578",
        "slfrd1",
        "xpccbgarern6r",
        "xpcyqqhir7yvq",
        "xpchgxkc32lbs",
        "pattern match",
        "q0o0mahttp",
        "pfunction",
        "lkvoid",
        "glfunction",
        "befunction",
        "mrtk",
        "7jfjrw",
        "zzvyn6uhsb"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Trojan:MSIL/RacoonStealer",
          "display_name": "Trojan:MSIL/RacoonStealer",
          "target": "/malware/Trojan:MSIL/RacoonStealer"
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/Zbot",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/Zbot",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Bradesco",
          "display_name": "TrojanSpy:Win32/Bradesco",
          "target": "/malware/TrojanSpy:Win32/Bradesco"
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 36,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 639,
        "hostname": 684,
        "FileHash-MD5": 382,
        "FileHash-SHA1": 212,
        "FileHash-SHA256": 1043,
        "URL": 2215
      },
      "indicator_count": 5175,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "954 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "625f86049cb1c945f7701075",
      "name": "Hetzner - malware hosting",
      "description": "function ar(aw,av,au,at) is a new type of tracking, which uses the same code as the Matomo tracking tool and its built-up functionality to track where a tracker is located.",
      "modified": "2022-05-20T00:01:19.453000",
      "created": "2022-04-20T04:03:16.817000",
      "tags": [
        "param",
        "locale",
        "return",
        "stripped",
        "regexp",
        "html",
        "lang",
        "lightweight",
        "dual",
        "javascript i18n",
        "entity",
        "body",
        "meta",
        "typeradio",
        "ttav",
        "width",
        "ttaelt",
        "shadowwidth",
        "tagtotip",
        "html element",
        "shadow",
        "closebtncolors",
        "fadein",
        "null",
        "sticky",
        "close",
        "false",
        "path",
        "config",
        "span",
        "iframe",
        "kill",
        "inside",
        "first",
        "typetext",
        "typepassword",
        "input",
        "typeof define",
        "typeof module",
        "html tags",
        "px20trnf",
        "dom element",
        "date",
        "this",
        "typeof e",
        "function",
        "left",
        "bottom",
        "nullt",
        "right",
        "next",
        "february",
        "april",
        "june",
        "august",
        "atom",
        "cookie",
        "back",
        "bounce",
        "typeof t",
        "class",
        "attr",
        "pseudo",
        "child",
        "js foundation",
        "error",
        "captcha",
        "access site",
        "click",
        "strong",
        "ddos",
        "hetzner online",
        "gmbh element",
        "lztextlink",
        "script",
        "lzrscr",
        "scrb64d",
        "livezilladata",
        "ovlcwm",
        "activedocument",
        "lzsds",
        "lzsde",
        "lzsdeg",
        "cant load",
        "gv1023",
        "typecheckbox",
        "5deg",
        "20deg",
        "45deg",
        "2000px00",
        "2000px0",
        "10px00",
        "60px0",
        "mintime",
        "await",
        "number",
        "typeof n",
        "typeof symbol",
        "cookieconsent",
        "showcookiemodal",
        "cookie banner",
        "agree",
        "agreed",
        "expiresthu",
        "anchorregex",
        "typeerror",
        "swiper",
        "hammer",
        "bnm",
        "software",
        "azaz",
        "form",
        "void",
        "zert",
        "accept",
        "android",
        "trace",
        "import",
        "string",
        "please",
        "blob",
        "matomo",
        "post",
        "javascript",
        "link",
        "license"
      ],
      "references": [
        "xfe-IP-136.243.64.87-stix2-2.1-export.json",
        "https://matomo.hetzner.com/matomo.js",
        "xfe-URL-matomo.hetzner.com-stix2-2.1-export.json",
        "https:///livesupport.hetzner.de/resource.php?t=js&1=jsglobal.min.js&2=jsbox.min.js&3=jstrack.min.js&v=ahgzixd7&4=jsextern.min.js",
        "https://livesupport.hetzner.de/server.php?rqst=track&output=jcrpt&group=Produktberatung&hg=Pw__&hcgs=MQ__&htgs=MQ__&ovltwo=MQ__&ovlv=djI_&ovlc=MQ__&esc=IzU4NTg1YQ__&epc=I0JFMTUyRA__&ovlts=MA__&ovlmr=MTAw&ovlmb=MjY_&hfk=MQ__&ovloo=MQ__&hots=MQ__&hott=MQ__&nse=0.615520170244701",
        "https://livesupport.hetzner.de/script.php?id=eec8dcd79d6fdf905136b99875c1d599",
        "https://accounts.hetzner.com/login",
        "https://accounts.hetzner.com/build/runtime.188fa053.js",
        "https://accounts.hetzner.com/build/755.5a8586e9.js",
        "https://accounts.hetzner.com/build/app.dc073715.js",
        "https://accounts.hetzner.com/build/802.3a7546ef.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/jquery-migrate.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/jquery/ui/jquery-ui.js",
        "https://konsoleh.your-server.de/templates/ui-default/de/styles/login.css.php",
        "https://konsoleh.your-server.de/templates/ui-default/de/javascripts/wz_tooltip.js",
        "xfe-URL-livesupport.hetzner.de-stix2-2.1-export.json",
        "xfe-URL-konsoleh.your-server.de-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ActiveDocument",
          "display_name": "ActiveDocument",
          "target": null
        },
        {
          "id": "OVLCWM",
          "display_name": "OVLCWM",
          "target": null
        },
        {
          "id": "Hammer",
          "display_name": "Hammer",
          "target": null
        },
        {
          "id": "BNM",
          "display_name": "BNM",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2308,
        "hostname": 949,
        "FileHash-SHA256": 125,
        "domain": 372,
        "FileHash-SHA1": 3,
        "FileHash-MD5": 256
      },
      "indicator_count": 4013,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1473 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "625f3287d722d8d85700b75d",
      "name": "Leaseweb.com - malware hosting",
      "description": "function D(t,e,n), as well as window.com, has been frozen by a single function, as part of a series of \"snoopers' checks\"...",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T22:07:03.024000",
      "tags": [
        "11px center",
        "html",
        "typetext",
        "typeurl",
        "typeemail",
        "typetel",
        "typenumber",
        "typedate",
        "color",
        "marketo forms",
        "cross domain",
        "null",
        "click",
        "forceclose",
        "lightbox",
        "slideshow",
        "controls",
        "hide",
        "safari",
        "image",
        "mozilla",
        "explorer",
        "entity",
        "linear",
        "date",
        "jquery",
        "iframe",
        "close",
        "loops",
        "class",
        "stretch",
        "false",
        "function",
        "abbb",
        "typeerror",
        "boolean",
        "body",
        "object",
        "array",
        "regexp",
        "bind",
        "error",
        "void",
        "hammer",
        "form",
        "this",
        "views slideshow",
        "zindex1",
        "ajax",
        "href",
        "default",
        "thumb",
        "msgesture",
        "mspointerdown",
        "next",
        "stop",
        "type",
        "index",
        "event",
        "snapabugcbmbtn",
        "chat",
        "hidden",
        "leaf",
        "open",
        "dump",
        "window",
        "win32",
        "footer",
        "front",
        "drupal",
        "command",
        "implement",
        "copyright",
        "route",
        "foundation",
        "thecookie",
        "remove",
        "example",
        "backport",
        "grab",
        "span",
        "import",
        "attr",
        "string",
        "invalid json",
        "domparser",
        "number",
        "script",
        "closure library",
        "symbol",
        "array int8array",
        "caregexp",
        "legacy",
        "boardman",
        "fontface",
        "typeof d",
        "promise",
        "parseint",
        "marketo",
        "rangeerror",
        "uint8array",
        "typeof b",
        "buffer",
        "path",
        "takk",
        "kiitos",
        "buttons};kb(convertedmessage);break;case\"/sys\":var",
        "acum",
        "ufunction",
        "ffunction",
        "gfunction",
        "mchtd",
        "cancel",
        "thank",
        "enter",
        "please",
        "cobrowsing",
        "accept",
        "decline",
        "back",
        "comment",
        "grazie",
        "klik",
        "super",
        "dados",
        "hello",
        "vd",
        "reduceright",
        "trackevent",
        "lead",
        "query",
        "videos",
        "leaseweb",
        "trackpageview",
        "contact",
        "download",
        "metal",
        "code",
        "functional",
        "member",
        "hnew regexp",
        "qfunction",
        "adview",
        "addbillinginfo",
        "addtocart",
        "addtolist",
        "install",
        "cookiebot",
        "iabv2",
        "jsonversion",
        "cookie script",
        "methodstrict",
        "ticket",
        "id attribute",
        "cookiebot setup",
        "cookieconsent",
        "customevent",
        "09af",
        "ver0",
        "tag0",
        "extdata0",
        "ua ch",
        "invalid",
        "iterator",
        "service",
        "phonenumber",
        "facebook",
        "meta",
        "ytconfig",
        "edge",
        "swhealthlog",
        "logsdatabasev2",
        "trident",
        "android",
        "infinity",
        "pnull",
        "style",
        "ctnull",
        "post",
        "uint32array",
        "fanull",
        "license",
        "ynull",
        "config"
      ],
      "references": [
        "https://consent.cookiebot.com/1e27dadb-e278-4c02-aa4f-43f9222c4fbb/cc.js?renew=false&referer=www.leaseweb.com&culture=en&dnt=false",
        "https://j.clarity.ms/s/0.6.34/clarity.js",
        "https://www.google-analytics.com/plugins/ua/linkid.js",
        "https://www.youtube.com/s/player/19eb72e4/www-widgetapi.vflset/www-widgetapi.js",
        "https://www.youtube.com/iframe_api",
        "https://connect.facebook.net/signals/config/399164440484826?v=2.9.57&r=stable",
        "https://bat.bing.com/bat.js",
        "https://consent.cookiebot.com/uc.js?cbid=1e27dadb-e278-4c02-aa4f-43f9222c4fbb&culture=en",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NWPHSS",
        "https://storage.googleapis.com/snapengage-eu/js/e9219576-8f74-40b5-8b6f-bbad33f6ca57.js",
        "https://munchkin.marketo.net/161/munchkin.js",
        "https://app-lon04.marketo.com/js/forms2/js/forms2.min.js",
        "https://munchkin.marketo.net/munchkin.js",
        "https://www.leaseweb.com/sites/all/modules/custom/lsw_marketo/js/lsw_marketo_forms.js",
        "https://use.fortawesome.com/03018d9d.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1001847692/?random=1650405011980&cv=9&fst=1650405011980&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/952389962/?random=1650405011982&cv=9&fst=1650405011982&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://eu.snapengage.com/chatjs/ServiceGetConfig?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
        "https://eu.snapengage.com/chatjs/servicegetproactivegeodata?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
        "https://bat.bing.com/p/action/5602105.js",
        "https://eu.snapengage.com/chatjs/servicegetallavailableagents?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57&t=1",
        "https://www.googleadservices.com/pagead/conversion_async.js",
        "https://www.leaseweb.com/sites/default/files/js/js_kwxcSFD2Y0_BPtdJClYUy5H8THI_5EycUmIgIGWaGYs.js",
        "https://www.leaseweb.com/sites/default/files/js/js_wcSNEXVJ4Xjhkf8qhMguEPZJTDTMNmPaJM-YWdAOhQE.js",
        "https://www.leaseweb.com/sites/default/files/js/js_kI_QwKJlaBz9CzQdENdUBFiEl4aehfjf4_-9taiwcCE.js",
        "https://www.leaseweb.com/sites/default/files/js/js_zoLA7TweXam0kYiqJrXepqBWmyDoP1sLSlHoZcveFnY.js",
        "https://www.leaseweb.com/sites/default/files/js/js_6FowaFXT9bT78hf9earPdGcdTmvsFiaBzKgFl9P4fSo.js",
        "https://www.leaseweb.com/sites/default/files/js/js_6lTJ_m6ahwXas7Efbw8ZYEMSaecrGw8ilNALfvIPNUw.js",
        "https://analytics.twitter.com/i/adsct?type=javascript&version=2.0.4&p_id=Twitter&p_user_id=0&txn_id=nxsfu&events=%5B%5B%22pageview%22%2Cnull%5D%5D&tw_sale_amount=0&tw_order_quantity=0&tw_iframe_status=0&event_id=511b6f48-2639-478c-a251-b09fcbae76e7&tw_document_href=https%3A%2F%2Fwww.leaseweb.com%2F&tpx_cb=twttr.conversion.loadPixels",
        "https://bid.g.doubleclick.net/xbbe/pixel?d=KAE",
        "https://consentcdn.cookiebot.com/sdk/bc-v4.min.html",
        "https://app-lon04.marketo.com/index.php/form/XDFrame",
        "https://app-lon04.marketo.com/js/forms2/css/forms2-theme-plain.css",
        "https://www.leaseweb.com/sites/default/files/css/css_47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU.css",
        "https://www.leaseweb.com/sites/default/files/css/css_7CYF9En6DNp6AojfSKnT8USKR3GvzPwznmTqLTKT9VM.css"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Tunisia"
      ],
      "malware_families": [
        {
          "id": "Ajax",
          "display_name": "Ajax",
          "target": null
        },
        {
          "id": "Kiitos",
          "display_name": "Kiitos",
          "target": null
        },
        {
          "id": "Takk",
          "display_name": "Takk",
          "target": null
        },
        {
          "id": "Acum",
          "display_name": "Acum",
          "target": null
        },
        {
          "id": "buttons};kb(convertedMessage);break;case\"/SYS\":var",
          "display_name": "buttons};kb(convertedMessage);break;case\"/SYS\":var",
          "target": null
        },
        {
          "id": "Vd",
          "display_name": "Vd",
          "target": null
        },
        {
          "id": "ReduceRight",
          "display_name": "ReduceRight",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "display_name": "T1490 - Inhibit System Recovery"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 648,
        "domain": 469,
        "URL": 2037,
        "FileHash-SHA256": 705,
        "email": 7
      },
      "indicator_count": 3866,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1474 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "http://hammerjs.github.io/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "http://hammerjs.github.io/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780283445.604093
}