{
  "type": "URL",
  "indicator": "http://lykywid.com/login.php",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "http://lykywid.com/login.php",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3928685025,
      "indicator": "http://lykywid.com/login.php",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 9,
      "pulses": [
        {
          "id": "68705b9e13e074fa3c778902",
          "name": "check",
          "description": "",
          "modified": "2026-01-23T01:10:39.457000",
          "created": "2025-07-11T00:32:30.277000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 421,
            "FileHash-MD5": 25,
            "FileHash-SHA1": 22,
            "FileHash-SHA256": 133,
            "domain": 270,
            "hostname": 35
          },
          "indicator_count": 906,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "129 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "683e4307a059dee6d1ade4ed",
          "name": "lumma",
          "description": "",
          "modified": "2026-01-04T22:52:50.774000",
          "created": "2025-06-03T00:34:15.050000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 31,
            "FileHash-SHA1": 22,
            "FileHash-SHA256": 90,
            "URL": 550,
            "domain": 380,
            "hostname": 33
          },
          "indicator_count": 1106,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "147 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68ddc902283b04c489f7e1cd",
          "name": "Malicious Probe - WannaCry \u2022 WannaCrypt- Ransomware",
          "description": "Malicious remote cab / drive by via an alt google redirect , clicked image , suspicious, low amount of search results.\nRead coded image. Target/s phone -cnc and infected. #dead_connect #decrypted #hacked #nametactics",
          "modified": "2025-11-01T00:02:59.726000",
          "created": "2025-10-02T00:36:18.296000",
          "tags": [
            "ip address",
            "key identifier",
            "x509v3 subject",
            "data",
            "v3 serial",
            "cus ogoogle",
            "trust",
            "cnwr3 validity",
            "subject public",
            "key info",
            "links",
            "dynamicloader",
            "high",
            "et exploit",
            "ms17010",
            "msf style",
            "probe ms17010",
            "generic flags",
            "dns lookup",
            "ransom",
            "write",
            "malware",
            "wannacrypt",
            "wannacry",
            "eternal blue",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "command",
            "spawns",
            "development att",
            "ssl certificate",
            "programfiles",
            "username",
            "windir",
            "userprofile",
            "mitre att",
            "ck matrix",
            "localappdata",
            "comspec",
            "model",
            "hybrid",
            "path",
            "click",
            "strings",
            "sabey type",
            "quasi type",
            "pegasus relationship",
            "fbi? files"
          ],
          "references": [
            "www.forensickb.com \u2022 Computer Forensics, Malware Analysis & Digital Investigations",
            "Eternal Blue Wannacry \u2022 WannaCry Crypter",
            "https://hybrid-analysis.com/sample/8ed6c58fb2a5d50252bf106d31ed9e230925124443e4243bec9515c82ef0450c/68ddc351e27cb562e902d674"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCrypt",
              "display_name": "WannaCrypt",
              "target": null
            },
            {
              "id": "Eternal Blue",
              "display_name": "Eternal Blue",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4246,
            "domain": 757,
            "hostname": 1039,
            "email": 1,
            "FileHash-SHA256": 2738,
            "FileHash-SHA1": 152,
            "FileHash-MD5": 140,
            "CVE": 1,
            "SSLCertFingerprint": 3
          },
          "indicator_count": 9077,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 146,
          "modified_text": "212 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68ddc9048ba0719321307d03",
          "name": "Malicious Probe - WannaCry \u2022 WannaCrypt- Ransomware",
          "description": "Malicious remote cab / drive by via an alt google redirect , clicked image , suspicious, low amount of search results.\nRead coded image. Target/s phone -cnc and infected. #dead_connect #decrypted #hacked #nametactics",
          "modified": "2025-11-01T00:02:59.726000",
          "created": "2025-10-02T00:36:20.247000",
          "tags": [
            "ip address",
            "key identifier",
            "x509v3 subject",
            "data",
            "v3 serial",
            "cus ogoogle",
            "trust",
            "cnwr3 validity",
            "subject public",
            "key info",
            "links",
            "dynamicloader",
            "high",
            "et exploit",
            "ms17010",
            "msf style",
            "probe ms17010",
            "generic flags",
            "dns lookup",
            "ransom",
            "write",
            "malware",
            "wannacrypt",
            "wannacry",
            "eternal blue",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "command",
            "spawns",
            "development att",
            "ssl certificate",
            "programfiles",
            "username",
            "windir",
            "userprofile",
            "mitre att",
            "ck matrix",
            "localappdata",
            "comspec",
            "model",
            "hybrid",
            "path",
            "click",
            "strings",
            "sabey type",
            "quasi type",
            "pegasus relationship",
            "fbi? files"
          ],
          "references": [
            "www.forensickb.com \u2022 Computer Forensics, Malware Analysis & Digital Investigations",
            "Eternal Blue Wannacry \u2022 WannaCry Crypter",
            "https://hybrid-analysis.com/sample/8ed6c58fb2a5d50252bf106d31ed9e230925124443e4243bec9515c82ef0450c/68ddc351e27cb562e902d674"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCrypt",
              "display_name": "WannaCrypt",
              "target": null
            },
            {
              "id": "Eternal Blue",
              "display_name": "Eternal Blue",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4246,
            "domain": 757,
            "hostname": 1039,
            "email": 1,
            "FileHash-SHA256": 2738,
            "FileHash-SHA1": 152,
            "FileHash-MD5": 140,
            "CVE": 1,
            "SSLCertFingerprint": 3
          },
          "indicator_count": 9077,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 147,
          "modified_text": "212 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "688c8526be7a4df33863b5c5",
          "name": "VirusTotal - Shiz.ivr",
          "description": "*Win.Trojan.Shiz.ivr\n*PWS:Win32/Simda.D\n*virtool #injection#infostealer #network #cnc #block_not #virustotal_google #cnc #checking #procmem_yara\n#injection_inter_process\n#injection_create_remote_thread\n#antidebug_windows\n#multiple_useragents\n#network_fake_useragent\n#persistence_autorun\n#cape_detected_threat\n#antiav_detectfile\n#modify_proxy\n#deletes_self\n#infostealer_cookies\n#injection_createremotethread\n#suricata_alert\n~ vashti",
          "modified": "2025-08-31T08:01:04.297000",
          "created": "2025-08-01T09:13:10.510000",
          "tags": [
            "dynamicloader",
            "unknown",
            "msie",
            "windows nt",
            "slcc2",
            "media center",
            "suspicious",
            "search",
            "high",
            "show",
            "copy",
            "possible",
            "write",
            "internal",
            "malware",
            "push",
            "local",
            "next",
            "contacted",
            "domains",
            "pulses",
            "related tags",
            "file type",
            "date april",
            "pm size",
            "sha1 sha256",
            "imphash pehash",
            "virustotal api",
            "bq jul",
            "united",
            "trojan",
            "backdoor",
            "virtool",
            "cnc beacon",
            "entries",
            "path max",
            "passive dns",
            "next associated",
            "cookie",
            "twitter",
            "body",
            "date",
            "medium",
            "simda",
            "global"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 10303,
            "hostname": 1413,
            "FileHash-SHA256": 1868,
            "domain": 1877,
            "FileHash-MD5": 357,
            "FileHash-SHA1": 348,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 16168,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 149,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6786a59af06fee17c8decf9d",
          "name": "netcfg",
          "description": "000ceafd276003f46d06828bb0459b3ccdc2b44013a313b69d6270a224199034",
          "modified": "2025-05-31T02:36:52.299000",
          "created": "2025-01-14T17:57:46.687000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 222,
            "domain": 216,
            "hostname": 4,
            "FileHash-SHA256": 1
          },
          "indicator_count": 443,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "366 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67fb185eb96e9791cf24ced4",
          "name": "Shiz/Packy",
          "description": "",
          "modified": "2025-05-13T01:03:15.390000",
          "created": "2025-04-13T01:50:22.707000",
          "tags": [],
          "references": [
            "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 26,
            "URL": 191,
            "domain": 344,
            "hostname": 2
          },
          "indicator_count": 563,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "384 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "678349edca4868e4cf8b298b",
          "name": "tfdbpg",
          "description": "0000121f09166c3e1e001b833301977f3f9461f756b46818e1acf377edb2454f",
          "modified": "2025-01-12T04:49:49.365000",
          "created": "2025-01-12T04:49:49.365000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 237,
            "domain": 228,
            "hostname": 8,
            "FileHash-SHA256": 1
          },
          "indicator_count": 474,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "505 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a4293d5bc5c915eac829e0",
          "name": "Ransom:Win32/Crowti.A : Android Windows | Win.Trojan.Simda CnC",
          "description": "",
          "modified": "2024-08-25T21:00:52.039000",
          "created": "2024-07-26T22:54:53.598000",
          "tags": [
            "united",
            "unknown",
            "a domains",
            "accept",
            "link",
            "passive dns",
            "encrypt",
            "trmp",
            "ok server",
            "date",
            "meta",
            "whois lookup",
            "create date",
            "domain",
            "expiry date",
            "update date",
            "update",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr10",
            "validity",
            "public key",
            "info",
            "key algorithm",
            "dns replication",
            "subdomains",
            "first",
            "historical ssl",
            "record type",
            "ttl value",
            "cname",
            "certificates",
            "show",
            "entries",
            "yara rule",
            "delete",
            "search",
            "intel",
            "ms windows",
            "copy",
            "binary file",
            "get updates",
            "write",
            "as44273 host",
            "redacted for",
            "moved",
            "record value",
            "as54113",
            "body",
            "scan endpoints",
            "all scoreblue",
            "pulse submit",
            "url analysis",
            "urls",
            "files",
            "ip address",
            "files ip",
            "address domain",
            "as61969 team",
            "germany unknown",
            "msie",
            "chrome",
            "precondition",
            "gmt content",
            "united kingdom",
            "as396982 google",
            "as8075",
            "ireland unknown",
            "as21301",
            "aaaa",
            "status",
            "sha1",
            "windows nt",
            "sha256",
            "size",
            "ascii text",
            "pattern match",
            "mitre att",
            "ck id",
            "show technique",
            "span",
            "format",
            "click",
            "hybrid",
            "twitter",
            "generator",
            "tsvt",
            "strings",
            "download",
            "path",
            "contact",
            "suspicious",
            "invalid url",
            "open ports",
            "body html",
            "head title",
            "title head",
            "body h1",
            "reference",
            "bad request",
            "server",
            "version",
            "trojandropper",
            "ransom",
            "checkin",
            "ipv4",
            "trojan",
            "virtool",
            "http post",
            "theme directory",
            "without referer",
            "cycbot",
            "http response",
            "final url",
            "status code",
            "body length",
            "kb body",
            "headers server",
            "gmt etag",
            "gmt date",
            "referrer",
            "code signing",
            "serial number",
            "ca valid",
            "from",
            "valid",
            "valid usage",
            "verisign time",
            "stamping",
            "thumbprint",
            "class",
            "error",
            "info header",
            "name md5",
            "type",
            "language",
            "contained",
            "overlay",
            "gandi sas",
            "dynadot",
            "registrar",
            "dynadot inc",
            "cloudflare",
            "net technology",
            "corporation",
            "bigrock",
            "dynadot llc",
            "namecheap",
            "ip detections",
            "country",
            "contacted",
            "defense evasion",
            "access ta0006",
            "ta0009 command",
            "control ta0011",
            "impact ta0034",
            "impact ta0040",
            "ta0040",
            "samplepath",
            "pattern urls",
            "pattern domains",
            "memory pattern",
            "domains domain",
            "ip traffic",
            "typo squatting",
            "realteck audio",
            "phish",
            "mr windows",
            "partru",
            "goog mal",
            "android windows",
            "maze",
            "apple",
            "malware",
            "worm",
            "skynet",
            "microsoft",
            "trojan evader",
            "simda cnc",
            "showing",
            "filehash",
            "pulse pulses",
            "av detections",
            "ids detections",
            "delphi",
            "network",
            "crowdstrike"
          ],
          "references": [
            "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
            "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
            "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
            "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
            "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
            "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
            "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
            "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
            "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
            "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
            "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
            "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6",
            "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
            "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
            "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
            "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
            "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
            "BigRock: gadyzyh.com",
            "Matches rule ET INFO Namecheap URL",
            "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
            "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
            "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
            "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
            "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
            "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
            "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
            "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
            "Matches rule Windows Processes Suspicious Parent Directory by vburov"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Australia",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "TrojanDownloader:Win32/Upatre.E",
              "display_name": "TrojanDownloader:Win32/Upatre.E",
              "target": "/malware/TrojanDownloader:Win32/Upatre.E"
            },
            {
              "id": "Ransom:Win32/Crowti.A",
              "display_name": "Ransom:Win32/Crowti.A",
              "target": "/malware/Ransom:Win32/Crowti.A"
            },
            {
              "id": "Cycbot",
              "display_name": "Cycbot",
              "target": null
            },
            {
              "id": "VirTool:Win32/Injector",
              "display_name": "VirTool:Win32/Injector",
              "target": "/malware/VirTool:Win32/Injector"
            },
            {
              "id": "Win.Trojan.Simda",
              "display_name": "Win.Trojan.Simda",
              "target": null
            },
            {
              "id": "TEL:Win32/Qjwmonkey.A",
              "display_name": "TEL:Win32/Qjwmonkey.A",
              "target": "/malware/TEL:Win32/Qjwmonkey.A"
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "TA0034",
              "name": "Impact",
              "display_name": "TA0034 - Impact"
            },
            {
              "id": "TA0040",
              "name": "Impact",
              "display_name": "TA0040 - Impact"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 549,
            "domain": 1182,
            "hostname": 590,
            "URL": 961,
            "FileHash-SHA256": 2466,
            "FileHash-MD5": 562,
            "SSLCertFingerprint": 7,
            "email": 4
          },
          "indicator_count": 6321,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "644 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
        "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
        "Matches rule ET INFO Namecheap URL",
        "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6",
        "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
        "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
        "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
        "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
        "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
        "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
        "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
        "Eternal Blue Wannacry \u2022 WannaCry Crypter",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
        "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
        "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
        "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
        "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
        "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
        "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3",
        "Matches rule Windows Processes Suspicious Parent Directory by vburov",
        "https://hybrid-analysis.com/sample/8ed6c58fb2a5d50252bf106d31ed9e230925124443e4243bec9515c82ef0450c/68ddc351e27cb562e902d674",
        "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
        "www.forensickb.com \u2022 Computer Forensics, Malware Analysis & Digital Investigations",
        "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
        "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
        "BigRock: gadyzyh.com"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Win.trojan.simda",
            "Et",
            "Virtool:win32/injector",
            "Cycbot",
            "Ransomware",
            "Trojandownloader:win32/upatre.e",
            "Tel:win32/qjwmonkey.a",
            "Wannacry",
            "Wannacrypt",
            "Eternal blue",
            "Ransom:win32/crowti.a"
          ],
          "industries": [],
          "unique_indicators": 31049
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/lykywid.com",
    "whois": "http://whois.domaintools.com/lykywid.com",
    "domain": "lykywid.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 9,
  "pulses": [
    {
      "id": "68705b9e13e074fa3c778902",
      "name": "check",
      "description": "",
      "modified": "2026-01-23T01:10:39.457000",
      "created": "2025-07-11T00:32:30.277000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 421,
        "FileHash-MD5": 25,
        "FileHash-SHA1": 22,
        "FileHash-SHA256": 133,
        "domain": 270,
        "hostname": 35
      },
      "indicator_count": 906,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "129 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "683e4307a059dee6d1ade4ed",
      "name": "lumma",
      "description": "",
      "modified": "2026-01-04T22:52:50.774000",
      "created": "2025-06-03T00:34:15.050000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 31,
        "FileHash-SHA1": 22,
        "FileHash-SHA256": 90,
        "URL": 550,
        "domain": 380,
        "hostname": 33
      },
      "indicator_count": 1106,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "147 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68ddc902283b04c489f7e1cd",
      "name": "Malicious Probe - WannaCry \u2022 WannaCrypt- Ransomware",
      "description": "Malicious remote cab / drive by via an alt google redirect , clicked image , suspicious, low amount of search results.\nRead coded image. Target/s phone -cnc and infected. #dead_connect #decrypted #hacked #nametactics",
      "modified": "2025-11-01T00:02:59.726000",
      "created": "2025-10-02T00:36:18.296000",
      "tags": [
        "ip address",
        "key identifier",
        "x509v3 subject",
        "data",
        "v3 serial",
        "cus ogoogle",
        "trust",
        "cnwr3 validity",
        "subject public",
        "key info",
        "links",
        "dynamicloader",
        "high",
        "et exploit",
        "ms17010",
        "msf style",
        "probe ms17010",
        "generic flags",
        "dns lookup",
        "ransom",
        "write",
        "malware",
        "wannacrypt",
        "wannacry",
        "eternal blue",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "command",
        "spawns",
        "development att",
        "ssl certificate",
        "programfiles",
        "username",
        "windir",
        "userprofile",
        "mitre att",
        "ck matrix",
        "localappdata",
        "comspec",
        "model",
        "hybrid",
        "path",
        "click",
        "strings",
        "sabey type",
        "quasi type",
        "pegasus relationship",
        "fbi? files"
      ],
      "references": [
        "www.forensickb.com \u2022 Computer Forensics, Malware Analysis & Digital Investigations",
        "Eternal Blue Wannacry \u2022 WannaCry Crypter",
        "https://hybrid-analysis.com/sample/8ed6c58fb2a5d50252bf106d31ed9e230925124443e4243bec9515c82ef0450c/68ddc351e27cb562e902d674"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCrypt",
          "display_name": "WannaCrypt",
          "target": null
        },
        {
          "id": "Eternal Blue",
          "display_name": "Eternal Blue",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4246,
        "domain": 757,
        "hostname": 1039,
        "email": 1,
        "FileHash-SHA256": 2738,
        "FileHash-SHA1": 152,
        "FileHash-MD5": 140,
        "CVE": 1,
        "SSLCertFingerprint": 3
      },
      "indicator_count": 9077,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 146,
      "modified_text": "212 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68ddc9048ba0719321307d03",
      "name": "Malicious Probe - WannaCry \u2022 WannaCrypt- Ransomware",
      "description": "Malicious remote cab / drive by via an alt google redirect , clicked image , suspicious, low amount of search results.\nRead coded image. Target/s phone -cnc and infected. #dead_connect #decrypted #hacked #nametactics",
      "modified": "2025-11-01T00:02:59.726000",
      "created": "2025-10-02T00:36:20.247000",
      "tags": [
        "ip address",
        "key identifier",
        "x509v3 subject",
        "data",
        "v3 serial",
        "cus ogoogle",
        "trust",
        "cnwr3 validity",
        "subject public",
        "key info",
        "links",
        "dynamicloader",
        "high",
        "et exploit",
        "ms17010",
        "msf style",
        "probe ms17010",
        "generic flags",
        "dns lookup",
        "ransom",
        "write",
        "malware",
        "wannacrypt",
        "wannacry",
        "eternal blue",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "command",
        "spawns",
        "development att",
        "ssl certificate",
        "programfiles",
        "username",
        "windir",
        "userprofile",
        "mitre att",
        "ck matrix",
        "localappdata",
        "comspec",
        "model",
        "hybrid",
        "path",
        "click",
        "strings",
        "sabey type",
        "quasi type",
        "pegasus relationship",
        "fbi? files"
      ],
      "references": [
        "www.forensickb.com \u2022 Computer Forensics, Malware Analysis & Digital Investigations",
        "Eternal Blue Wannacry \u2022 WannaCry Crypter",
        "https://hybrid-analysis.com/sample/8ed6c58fb2a5d50252bf106d31ed9e230925124443e4243bec9515c82ef0450c/68ddc351e27cb562e902d674"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCrypt",
          "display_name": "WannaCrypt",
          "target": null
        },
        {
          "id": "Eternal Blue",
          "display_name": "Eternal Blue",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4246,
        "domain": 757,
        "hostname": 1039,
        "email": 1,
        "FileHash-SHA256": 2738,
        "FileHash-SHA1": 152,
        "FileHash-MD5": 140,
        "CVE": 1,
        "SSLCertFingerprint": 3
      },
      "indicator_count": 9077,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 147,
      "modified_text": "212 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "688c8526be7a4df33863b5c5",
      "name": "VirusTotal - Shiz.ivr",
      "description": "*Win.Trojan.Shiz.ivr\n*PWS:Win32/Simda.D\n*virtool #injection#infostealer #network #cnc #block_not #virustotal_google #cnc #checking #procmem_yara\n#injection_inter_process\n#injection_create_remote_thread\n#antidebug_windows\n#multiple_useragents\n#network_fake_useragent\n#persistence_autorun\n#cape_detected_threat\n#antiav_detectfile\n#modify_proxy\n#deletes_self\n#infostealer_cookies\n#injection_createremotethread\n#suricata_alert\n~ vashti",
      "modified": "2025-08-31T08:01:04.297000",
      "created": "2025-08-01T09:13:10.510000",
      "tags": [
        "dynamicloader",
        "unknown",
        "msie",
        "windows nt",
        "slcc2",
        "media center",
        "suspicious",
        "search",
        "high",
        "show",
        "copy",
        "possible",
        "write",
        "internal",
        "malware",
        "push",
        "local",
        "next",
        "contacted",
        "domains",
        "pulses",
        "related tags",
        "file type",
        "date april",
        "pm size",
        "sha1 sha256",
        "imphash pehash",
        "virustotal api",
        "bq jul",
        "united",
        "trojan",
        "backdoor",
        "virtool",
        "cnc beacon",
        "entries",
        "path max",
        "passive dns",
        "next associated",
        "cookie",
        "twitter",
        "body",
        "date",
        "medium",
        "simda",
        "global"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 10303,
        "hostname": 1413,
        "FileHash-SHA256": 1868,
        "domain": 1877,
        "FileHash-MD5": 357,
        "FileHash-SHA1": 348,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 16168,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 149,
      "modified_text": "274 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6786a59af06fee17c8decf9d",
      "name": "netcfg",
      "description": "000ceafd276003f46d06828bb0459b3ccdc2b44013a313b69d6270a224199034",
      "modified": "2025-05-31T02:36:52.299000",
      "created": "2025-01-14T17:57:46.687000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 222,
        "domain": 216,
        "hostname": 4,
        "FileHash-SHA256": 1
      },
      "indicator_count": 443,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "366 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67fb185eb96e9791cf24ced4",
      "name": "Shiz/Packy",
      "description": "",
      "modified": "2025-05-13T01:03:15.390000",
      "created": "2025-04-13T01:50:22.707000",
      "tags": [],
      "references": [
        "https://www.virustotal.com/graph/gf9fb2090ae8e450dadda45c0596ab774ed1984e89aab4679bc3fc02096e22fa3"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 26,
        "URL": 191,
        "domain": 344,
        "hostname": 2
      },
      "indicator_count": 563,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "384 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "678349edca4868e4cf8b298b",
      "name": "tfdbpg",
      "description": "0000121f09166c3e1e001b833301977f3f9461f756b46818e1acf377edb2454f",
      "modified": "2025-01-12T04:49:49.365000",
      "created": "2025-01-12T04:49:49.365000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 237,
        "domain": 228,
        "hostname": 8,
        "FileHash-SHA256": 1
      },
      "indicator_count": 474,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "505 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66a4293d5bc5c915eac829e0",
      "name": "Ransom:Win32/Crowti.A : Android Windows | Win.Trojan.Simda CnC",
      "description": "",
      "modified": "2024-08-25T21:00:52.039000",
      "created": "2024-07-26T22:54:53.598000",
      "tags": [
        "united",
        "unknown",
        "a domains",
        "accept",
        "link",
        "passive dns",
        "encrypt",
        "trmp",
        "ok server",
        "date",
        "meta",
        "whois lookup",
        "create date",
        "domain",
        "expiry date",
        "update date",
        "update",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr10",
        "validity",
        "public key",
        "info",
        "key algorithm",
        "dns replication",
        "subdomains",
        "first",
        "historical ssl",
        "record type",
        "ttl value",
        "cname",
        "certificates",
        "show",
        "entries",
        "yara rule",
        "delete",
        "search",
        "intel",
        "ms windows",
        "copy",
        "binary file",
        "get updates",
        "write",
        "as44273 host",
        "redacted for",
        "moved",
        "record value",
        "as54113",
        "body",
        "scan endpoints",
        "all scoreblue",
        "pulse submit",
        "url analysis",
        "urls",
        "files",
        "ip address",
        "files ip",
        "address domain",
        "as61969 team",
        "germany unknown",
        "msie",
        "chrome",
        "precondition",
        "gmt content",
        "united kingdom",
        "as396982 google",
        "as8075",
        "ireland unknown",
        "as21301",
        "aaaa",
        "status",
        "sha1",
        "windows nt",
        "sha256",
        "size",
        "ascii text",
        "pattern match",
        "mitre att",
        "ck id",
        "show technique",
        "span",
        "format",
        "click",
        "hybrid",
        "twitter",
        "generator",
        "tsvt",
        "strings",
        "download",
        "path",
        "contact",
        "suspicious",
        "invalid url",
        "open ports",
        "body html",
        "head title",
        "title head",
        "body h1",
        "reference",
        "bad request",
        "server",
        "version",
        "trojandropper",
        "ransom",
        "checkin",
        "ipv4",
        "trojan",
        "virtool",
        "http post",
        "theme directory",
        "without referer",
        "cycbot",
        "http response",
        "final url",
        "status code",
        "body length",
        "kb body",
        "headers server",
        "gmt etag",
        "gmt date",
        "referrer",
        "code signing",
        "serial number",
        "ca valid",
        "from",
        "valid",
        "valid usage",
        "verisign time",
        "stamping",
        "thumbprint",
        "class",
        "error",
        "info header",
        "name md5",
        "type",
        "language",
        "contained",
        "overlay",
        "gandi sas",
        "dynadot",
        "registrar",
        "dynadot inc",
        "cloudflare",
        "net technology",
        "corporation",
        "bigrock",
        "dynadot llc",
        "namecheap",
        "ip detections",
        "country",
        "contacted",
        "defense evasion",
        "access ta0006",
        "ta0009 command",
        "control ta0011",
        "impact ta0034",
        "impact ta0040",
        "ta0040",
        "samplepath",
        "pattern urls",
        "pattern domains",
        "memory pattern",
        "domains domain",
        "ip traffic",
        "typo squatting",
        "realteck audio",
        "phish",
        "mr windows",
        "partru",
        "goog mal",
        "android windows",
        "maze",
        "apple",
        "malware",
        "worm",
        "skynet",
        "microsoft",
        "trojan evader",
        "simda cnc",
        "showing",
        "filehash",
        "pulse pulses",
        "av detections",
        "ids detections",
        "delphi",
        "network",
        "crowdstrike"
      ],
      "references": [
        "43.204.54.95 AS 16509 (AMAZON-02), http://r10.i.lencr.org/, www.maketrumppresidentagain.site",
        "trojan.shiz/razy: FileHash-SHA256 02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8",
        "trojan.shiz/razy | CS Sigma: Matches rule System File Execution Location Anomaly by Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Benche",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst",
        "trojan.shiz/razy | CS IDS: Matches rule ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
        "trojan.shiz/razy | CS IDS: Matches rule MALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan",
        "trojan.shiz/razy | CS IDS: Matches rule PROTOCOL-DNS large number of NXDOMAIN replies - possible DNS cache poisoning",
        "trojan.shiz/razy | Capabilities Collection Log keystrokes via polling",
        "https://www.virustotal.com/gui/file/02ed9fac1ebab76f551f1c27c0831541a3e0a6a716b392b16f34689b8fba08d8/detection",
        "https://otx.alienvault.com/indicator/file/e6f8e2706058064d8f38d12923e52cec7a128218b39ca1fe60a2dde7ac3d158f | binary_yara mpress_2_xx_x86",
        "Ransom:Win32/Crowti.A: FileHash-SHA256 1ffa6a3f8844b5955fc5e7329a6fb766cc1f35b39201ceaf0bca282b5b0b8cf6",
        "Ransom:Win32/Crowti.A: FileHash-MD5 d34cf3663902900ddf46b937449472b9",
        "Ransom:Win32/Crowti.A: FileHash-SHA1 05a49b7502099932ff628ca5a8583397b7e2dca2",
        "VirTool:Win32/Injector: FileHash-SHA256 0806653f8af2e9c2530e453f8b1fea47f62f86b5b0b65487ddcfd014eea8e9fe",
        "VirTool:Win32/Injector: FileHash-MD5 baa1a920d33eee94e123f5dfb6bbe7456692e020d682ae45f0de66130f9ea0da",
        "VirTool:Win32/Injector: FileHash-SHA1 3e7124373729e9ec90ea1d01222bfdd84b0484e5",
        "BigRock: gadyzyh.com",
        "Matches rule ET INFO Namecheap URL",
        "POLICY Unsupported/Fake Internet Explorer Version MSIE 2",
        "Win.Trojan.Simda: FileHash-SHA256 0187e1392266fff224de9e3d3fbbe1a05cea8b823906ad27ff577c6e348f6e3b",
        "Win.Trojan.Simda: FileHash-SHA1 fec01e5e59034cafc2b1e95c23068e075f9dbe69",
        "Win.Trojan.Simda: FileHash-MD5 efe12fc770fb8647e22adb7f814666e7",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA256 30ffb056ad64037a918d80c120db5d0032b29feb7db97ed19824646381165a5d",
        "TEL:Win32/Qjwmonkey.A: FileHash-SHA1 51efdae4ba6bfec8e6f4ae2d7f6dc8cca42db1da",
        "TEL:Win32/Qjwmonkey.A: FileHash-MD5 535ce96e43fe532e1ddfd804dbde9c6a",
        "Matches rule Files With System Process Name In Unsuspected Locations by Sander Wiebing, Tim Shelton, Nasreddine Bencherch",
        "Matches rule Windows Processes Suspicious Parent Directory by vburov"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Australia",
        "Netherlands"
      ],
      "malware_families": [
        {
          "id": "TrojanDownloader:Win32/Upatre.E",
          "display_name": "TrojanDownloader:Win32/Upatre.E",
          "target": "/malware/TrojanDownloader:Win32/Upatre.E"
        },
        {
          "id": "Ransom:Win32/Crowti.A",
          "display_name": "Ransom:Win32/Crowti.A",
          "target": "/malware/Ransom:Win32/Crowti.A"
        },
        {
          "id": "Cycbot",
          "display_name": "Cycbot",
          "target": null
        },
        {
          "id": "VirTool:Win32/Injector",
          "display_name": "VirTool:Win32/Injector",
          "target": "/malware/VirTool:Win32/Injector"
        },
        {
          "id": "Win.Trojan.Simda",
          "display_name": "Win.Trojan.Simda",
          "target": null
        },
        {
          "id": "TEL:Win32/Qjwmonkey.A",
          "display_name": "TEL:Win32/Qjwmonkey.A",
          "target": "/malware/TEL:Win32/Qjwmonkey.A"
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "TA0034",
          "name": "Impact",
          "display_name": "TA0034 - Impact"
        },
        {
          "id": "TA0040",
          "name": "Impact",
          "display_name": "TA0040 - Impact"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 549,
        "domain": 1182,
        "hostname": 590,
        "URL": 961,
        "FileHash-SHA256": 2466,
        "FileHash-MD5": 562,
        "SSLCertFingerprint": 7,
        "email": 4
      },
      "indicator_count": 6321,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "644 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "http://lykywid.com/login.php",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "http://lykywid.com/login.php",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780319892.9482346
}