{
  "type": "URL",
  "indicator": "http://plus.google.com/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "http://plus.google.com/",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "alexa",
        "message": "Alexa rank: #1",
        "name": "Listed on Alexa"
      },
      {
        "source": "akamai",
        "message": "Akamai rank: #3",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain google.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain google.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 1186621424,
      "indicator": "http://plus.google.com/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "6a1bd66fc9c0dac3fc1c3d4d",
          "name": "Bluesnarfing - Accessibility Feautures Part 2 * VirusTotal Droidy Android Sandbox",
          "description": "A recent Veteran client who was forced to abandon a new smartphone & revert to a legacy model. The target device's pairing registry was flooded with unauthorized \"Toyota Corolla\" profiles. This disruptive exploit effectively displaced the user, highlighting an emerging threat pattern targeting vulnerable individuals. The vulnerability lies within the smartphone's automated peripheral linking layer. Attackers broadcast spoofed identifiers that the smartphone automatically accepts. This floods and corrupts the local registry database, rendering the device unmanageable. 1 Bluesnarfing: Attackers exploit authentication flaws to gain unauthorized access to internal data, allowing them to copy contacts, text messages, and photos without user permission, 2 Man-in-the-Middle (MitM) Relays: Attackers capture and relay wireless signals over long distances, fooling a phone into believing it is next to a trusted vehicle or accessory when it is miles away, 3 BLE Spoofing Attacks, & 4. Bluejacking.",
          "modified": "2026-06-02T02:18:27.414000",
          "created": "2026-05-31T06:34:23.017000",
          "tags": [
            "a domains",
            "present jun",
            "name servers",
            "meta",
            "toyota",
            "date",
            "present jul",
            "moved",
            "domains",
            "new cars",
            "body",
            "title",
            "aaaa",
            "cname",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "number",
            "cus oamazon",
            "cnamazon rsa",
            "m04 validity",
            "subject public",
            "key info",
            "key algorithm",
            "united",
            "name",
            "create date",
            "domain",
            "expiry date",
            "update date",
            "current object",
            "process",
            "e0 dd",
            "dc d8",
            "b7 fe",
            "c1 fc",
            "f8 b6",
            "ba df",
            "b0 s",
            "da dc",
            "android",
            "unknown",
            "detail info",
            "behaviour",
            "detect operator",
            "antisimulator",
            "check root",
            "access network",
            "connect",
            "contentresolver",
            "flag",
            "componentname",
            "extras",
            "service",
            "toyota owners",
            "us california",
            "torrance",
            "accessibility features",
            "veterans hearing aids",
            "veterans bluetooth",
            "tacoma",
            "corrolla"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_VirusTotal%20Droidy.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208130&Signature=wtAr8J0ruv23wHZcOhupkZaq%2BBIhOLdQM0FwFnG9Vv4vfEv%2F0zvCPxhakLMeyzbmzNDul6j3OrPU4VxY7xMr2bzDRY9pb7yc7gyKykIX%2FzqiMKw9NJaYvd858j7wnYC6wK%2FPMRE%2Fr45iiPDrxLcEri4h9vW0C8YhUTP%2FD1hJFQty2KS6nKXTIlTjfunUA3XfgDhYR3hy4HqRTmkCxzHv0KJs2XvbEzODP5GEQjSxKQXlo",
            "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_Tencent%20HABO.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208156&Signature=LkY0drhs4Hyo8VkdUIwaxW7Ej1h8Uzhf6E3mpwOzCp%2BseX1pZcB2eVzZGa3U1bp2woAxF8N0w6ItA6hh14Ecaq26YEU78OQHluBOjDD05wYLm1kZDESgfOQZ93owFEXKy267LJtLTldA%2BQMhApZM0zZBKfF9VzZRqQCwvXusUk5fLOX5kpUYUgixwVHamIXwbLG9CgxX6OdWPTKpVWxfsi2dmlWhGmWuuVTIjVyqxH8aV%2BU5FRhyccS8",
            "06:51 AM 09/18/2014 06:51 AM 09/12/2039 541a810a 0b8464eae298da2d9ec5a12271309acb25e25465",
            "Certificate Issuer: C:US, CN:Michael LaPean, L:Torrance, O:Toyota Motor Sales, ST:California, OU:Toyota Owners Michael LaPean Toyota Motor Sales Toyota Owners US California Torrance"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 9,
            "FileHash-SHA1": 6,
            "email": 2,
            "hostname": 104,
            "URL": 198,
            "domain": 28,
            "IPv6": 8,
            "FileHash-SHA256": 42,
            "IPv4": 56
          },
          "indicator_count": 453,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1bd66eeaaf6d7290ac299d",
          "name": "Bluesnarfing - Accessibility Feautures Part 2 * VirusTotal Droidy Android Sandbox",
          "description": "A recent Veteran client who was forced to abandon a new smartphone & revert to a legacy model. The target device's pairing registry was flooded with unauthorized \"Toyota Corolla\" profiles. This disruptive exploit effectively displaced the user, highlighting an emerging threat pattern targeting vulnerable individuals. The vulnerability lies within the smartphone's automated peripheral linking layer. Attackers broadcast spoofed identifiers that the smartphone automatically accepts. This floods and corrupts the local registry database, rendering the device unmanageable. 1 Bluesnarfing: Attackers exploit authentication flaws to gain unauthorized access to internal data, allowing them to copy contacts, text messages, and photos without user permission, 2 Man-in-the-Middle (MitM) Relays: Attackers capture and relay wireless signals over long distances, fooling a phone into believing it is next to a trusted vehicle or accessory when it is miles away, 3 BLE Spoofing Attacks, & 4. Bluejacking.",
          "modified": "2026-05-31T06:34:22.530000",
          "created": "2026-05-31T06:34:22.530000",
          "tags": [
            "a domains",
            "present jun",
            "name servers",
            "meta",
            "toyota",
            "date",
            "present jul",
            "moved",
            "domains",
            "new cars",
            "body",
            "title",
            "aaaa",
            "cname",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "number",
            "cus oamazon",
            "cnamazon rsa",
            "m04 validity",
            "subject public",
            "key info",
            "key algorithm",
            "united",
            "name",
            "create date",
            "domain",
            "expiry date",
            "update date",
            "current object",
            "process",
            "e0 dd",
            "dc d8",
            "b7 fe",
            "c1 fc",
            "f8 b6",
            "ba df",
            "b0 s",
            "da dc",
            "android",
            "unknown",
            "detail info",
            "behaviour",
            "detect operator",
            "antisimulator",
            "check root",
            "access network",
            "connect",
            "contentresolver",
            "flag",
            "componentname",
            "extras",
            "service",
            "toyota owners",
            "us california",
            "torrance",
            "accessibility features",
            "veterans hearing aids",
            "veterans bluetooth",
            "tacoma",
            "corrolla"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_VirusTotal%20Droidy.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208130&Signature=wtAr8J0ruv23wHZcOhupkZaq%2BBIhOLdQM0FwFnG9Vv4vfEv%2F0zvCPxhakLMeyzbmzNDul6j3OrPU4VxY7xMr2bzDRY9pb7yc7gyKykIX%2FzqiMKw9NJaYvd858j7wnYC6wK%2FPMRE%2Fr45iiPDrxLcEri4h9vW0C8YhUTP%2FD1hJFQty2KS6nKXTIlTjfunUA3XfgDhYR3hy4HqRTmkCxzHv0KJs2XvbEzODP5GEQjSxKQXlo",
            "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_Tencent%20HABO.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208156&Signature=LkY0drhs4Hyo8VkdUIwaxW7Ej1h8Uzhf6E3mpwOzCp%2BseX1pZcB2eVzZGa3U1bp2woAxF8N0w6ItA6hh14Ecaq26YEU78OQHluBOjDD05wYLm1kZDESgfOQZ93owFEXKy267LJtLTldA%2BQMhApZM0zZBKfF9VzZRqQCwvXusUk5fLOX5kpUYUgixwVHamIXwbLG9CgxX6OdWPTKpVWxfsi2dmlWhGmWuuVTIjVyqxH8aV%2BU5FRhyccS8",
            "06:51 AM 09/18/2014 06:51 AM 09/12/2039 541a810a 0b8464eae298da2d9ec5a12271309acb25e25465",
            "Certificate Issuer: C:US, CN:Michael LaPean, L:Torrance, O:Toyota Motor Sales, ST:California, OU:Toyota Owners Michael LaPean Toyota Motor Sales Toyota Owners US California Torrance"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 9,
            "FileHash-SHA1": 6,
            "email": 2,
            "hostname": 80,
            "URL": 94,
            "domain": 22,
            "IPv6": 8,
            "FileHash-SHA256": 32,
            "IPv4": 26
          },
          "indicator_count": 279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "3 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6998d15c75b59044877602c1",
          "name": "Corrupt.... Files",
          "description": "beaware",
          "modified": "2026-04-01T00:44:45.494000",
          "created": "2026-02-20T21:25:48.559000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 706,
            "FileHash-SHA1": 859,
            "FileHash-SHA256": 1480,
            "URL": 743,
            "domain": 1565,
            "email": 55,
            "hostname": 912,
            "CVE": 54,
            "CIDR": 27
          },
          "indicator_count": 6401,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "63 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698548fdc5e1b22b45457eb4",
          "name": "http://support[.]apple[.]com/kb/HT5012 - 02.05.26",
          "description": "\"Learn more about trusted certificates\" -> http://support[.]apple[.]com/kb/HT5012\nTrust Store Version 2025082000\nTrust Asset Version 1012",
          "modified": "2026-03-08T02:01:42.135000",
          "created": "2026-02-06T01:50:53.485000",
          "tags": [
            "vhash",
            "ssdeep",
            "html internet",
            "magic html",
            "unicode text",
            "utf8",
            "trid text",
            "magika html",
            "file size",
            "please",
            "javascript",
            "malware",
            "virus",
            "trojan",
            "ransomware",
            "static",
            "analysis",
            "indicator of compromise",
            "ioc",
            "extraction",
            "emulation",
            "online",
            "submit",
            "sample",
            "download",
            "platform",
            "url",
            "sandbox",
            "scanner",
            "reputation",
            "phishing",
            "warning icon",
            "share report",
            "domain",
            "apple mapkit",
            "java",
            "manager",
            "report",
            "home search",
            "insights",
            "login check",
            "android",
            "write",
            "login report",
            "overview",
            "tags submit",
            "tags url",
            "finishing url",
            "asn norway",
            "title available",
            "apple",
            "static analyzer",
            "analyzer",
            "type",
            "website title",
            "apple support",
            "date",
            "security",
            "access control",
            "plan search",
            "submission",
            "february",
            "error",
            "vxstream",
            "apt",
            "hybrid analysis",
            "api key",
            "vetting process",
            "please note",
            "prefetch8 ansi",
            "ansi",
            "show process",
            "hash seen",
            "programfiles",
            "ck id",
            "command decode",
            "mitre att",
            "suricata ipv4",
            "windir",
            "suspicious",
            "comspec",
            "hybrid",
            "model",
            "close",
            "click",
            "hosts",
            "general",
            "path",
            "form",
            "strings",
            "contact",
            "p2404",
            "attrdataver186",
            "p11770919978",
            "processorcores6",
            "tpmversion0",
            "telemetrylevel1",
            "oemmodeldell",
            "osuilocaleenus",
            "osskuid48",
            "osnamewin",
            "main",
            "sha1",
            "Apple",
            "iPadOS",
            "Freedom"
          ],
          "references": [
            "https://www.virustotal.com/gui/url/aec932cd6ff44a6b8a13e3573f47d7e543cc0e1cc25f6d4fa2e0b0f1b8c44603/details",
            "https://www.virustotal.com/gui/file/3447d0e0dce83b163308c04dffeb52afb9f22d756b57d516fb1930d60303278d/details",
            "https://www.filescan.io/uploads/69853e76930564ff3c8e3576/reports/132722cc-526c-428b-85d8-bb863204ec6f/ioc",
            "https://urlquery.net/report/f7f1fb29-f7fb-4aec-be06-978b4bb296ab",
            "https://app.threat.zone/submission/f373032a-49fe-46f2-be28-a4636cbeb3c2/url-analysis-report",
            "https://hybrid-analysis.com/sample/04fcf10162401756459d90569bdda9bd3f264efc7ce75e2ca96a8fc93e159bdb",
            "http://hybrid-analysis.com/sample/04fcf10162401756459d90569bdda9bd3f264efc7ce75e2ca96a8fc93e159bdb/698522a0b8d0f8b6c404b7b4",
            "https://app.any.run/tasks/40ac99f3-0bf0-4455-996b-01e9ba0aaf79",
            "https://www.virustotal.com/gui/collection/fc2724a35b1672bcbcbb1af5a8e77d1e6095818a9db880a18661208aa9e9f1ed",
            "https://www.virustotal.com/gui/collection/fc2724a35b1672bcbcbb1af5a8e77d1e6095818a9db880a18661208aa9e9f1ed/iocs",
            "https://www.virustotal.com/graph/embed/g70516ab17e6a482eb6641c8d15f795a9d0fbc493ae9d4c3ca0e0617754ba679c?theme=dark",
            "https://viz.greynoise.io/ip/analysis/66ca01e5-ac9a-4baf-b088-901cfbe72cac"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            }
          ],
          "industries": [
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 29,
            "FileHash-SHA1": 24,
            "FileHash-SHA256": 126,
            "URL": 323,
            "SSLCertFingerprint": 8,
            "domain": 14,
            "email": 4,
            "hostname": 138
          },
          "indicator_count": 666,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 132,
          "modified_text": "87 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.virustotal.com/gui/collection/fc2724a35b1672bcbcbb1af5a8e77d1e6095818a9db880a18661208aa9e9f1ed",
        "https://viz.greynoise.io/ip/analysis/66ca01e5-ac9a-4baf-b088-901cfbe72cac",
        "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_VirusTotal%20Droidy.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208130&Signature=wtAr8J0ruv23wHZcOhupkZaq%2BBIhOLdQM0FwFnG9Vv4vfEv%2F0zvCPxhakLMeyzbmzNDul6j3OrPU4VxY7xMr2bzDRY9pb7yc7gyKykIX%2FzqiMKw9NJaYvd858j7wnYC6wK%2FPMRE%2Fr45iiPDrxLcEri4h9vW0C8YhUTP%2FD1hJFQty2KS6nKXTIlTjfunUA3XfgDhYR3hy4HqRTmkCxzHv0KJs2XvbEzODP5GEQjSxKQXlo",
        "https://app.threat.zone/submission/f373032a-49fe-46f2-be28-a4636cbeb3c2/url-analysis-report",
        "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_Tencent%20HABO.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208156&Signature=LkY0drhs4Hyo8VkdUIwaxW7Ej1h8Uzhf6E3mpwOzCp%2BseX1pZcB2eVzZGa3U1bp2woAxF8N0w6ItA6hh14Ecaq26YEU78OQHluBOjDD05wYLm1kZDESgfOQZ93owFEXKy267LJtLTldA%2BQMhApZM0zZBKfF9VzZRqQCwvXusUk5fLOX5kpUYUgixwVHamIXwbLG9CgxX6OdWPTKpVWxfsi2dmlWhGmWuuVTIjVyqxH8aV%2BU5FRhyccS8",
        "https://urlquery.net/report/f7f1fb29-f7fb-4aec-be06-978b4bb296ab",
        "https://app.any.run/tasks/40ac99f3-0bf0-4455-996b-01e9ba0aaf79",
        "https://hybrid-analysis.com/sample/04fcf10162401756459d90569bdda9bd3f264efc7ce75e2ca96a8fc93e159bdb",
        "https://www.virustotal.com/gui/file/3447d0e0dce83b163308c04dffeb52afb9f22d756b57d516fb1930d60303278d/details",
        "https://www.filescan.io/uploads/69853e76930564ff3c8e3576/reports/132722cc-526c-428b-85d8-bb863204ec6f/ioc",
        "http://hybrid-analysis.com/sample/04fcf10162401756459d90569bdda9bd3f264efc7ce75e2ca96a8fc93e159bdb/698522a0b8d0f8b6c404b7b4",
        "06:51 AM 09/18/2014 06:51 AM 09/12/2039 541a810a 0b8464eae298da2d9ec5a12271309acb25e25465",
        "https://www.virustotal.com/graph/embed/g70516ab17e6a482eb6641c8d15f795a9d0fbc493ae9d4c3ca0e0617754ba679c?theme=dark",
        "https://www.virustotal.com/gui/url/aec932cd6ff44a6b8a13e3573f47d7e543cc0e1cc25f6d4fa2e0b0f1b8c44603/details",
        "https://www.virustotal.com/gui/collection/fc2724a35b1672bcbcbb1af5a8e77d1e6095818a9db880a18661208aa9e9f1ed/iocs",
        "Certificate Issuer: C:US, CN:Michael LaPean, L:Torrance, O:Toyota Motor Sales, ST:California, OU:Toyota Owners Michael LaPean Toyota Motor Sales Toyota Owners US California Torrance"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Technology"
          ],
          "unique_indicators": 6097
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/google.com",
    "whois": "http://whois.domaintools.com/google.com",
    "domain": "google.com",
    "hostname": "plus.google.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "6a1bd66fc9c0dac3fc1c3d4d",
      "name": "Bluesnarfing - Accessibility Feautures Part 2 * VirusTotal Droidy Android Sandbox",
      "description": "A recent Veteran client who was forced to abandon a new smartphone & revert to a legacy model. The target device's pairing registry was flooded with unauthorized \"Toyota Corolla\" profiles. This disruptive exploit effectively displaced the user, highlighting an emerging threat pattern targeting vulnerable individuals. The vulnerability lies within the smartphone's automated peripheral linking layer. Attackers broadcast spoofed identifiers that the smartphone automatically accepts. This floods and corrupts the local registry database, rendering the device unmanageable. 1 Bluesnarfing: Attackers exploit authentication flaws to gain unauthorized access to internal data, allowing them to copy contacts, text messages, and photos without user permission, 2 Man-in-the-Middle (MitM) Relays: Attackers capture and relay wireless signals over long distances, fooling a phone into believing it is next to a trusted vehicle or accessory when it is miles away, 3 BLE Spoofing Attacks, & 4. Bluejacking.",
      "modified": "2026-06-02T02:18:27.414000",
      "created": "2026-05-31T06:34:23.017000",
      "tags": [
        "a domains",
        "present jun",
        "name servers",
        "meta",
        "toyota",
        "date",
        "present jul",
        "moved",
        "domains",
        "new cars",
        "body",
        "title",
        "aaaa",
        "cname",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "number",
        "cus oamazon",
        "cnamazon rsa",
        "m04 validity",
        "subject public",
        "key info",
        "key algorithm",
        "united",
        "name",
        "create date",
        "domain",
        "expiry date",
        "update date",
        "current object",
        "process",
        "e0 dd",
        "dc d8",
        "b7 fe",
        "c1 fc",
        "f8 b6",
        "ba df",
        "b0 s",
        "da dc",
        "android",
        "unknown",
        "detail info",
        "behaviour",
        "detect operator",
        "antisimulator",
        "check root",
        "access network",
        "connect",
        "contentresolver",
        "flag",
        "componentname",
        "extras",
        "service",
        "toyota owners",
        "us california",
        "torrance",
        "accessibility features",
        "veterans hearing aids",
        "veterans bluetooth",
        "tacoma",
        "corrolla"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_VirusTotal%20Droidy.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208130&Signature=wtAr8J0ruv23wHZcOhupkZaq%2BBIhOLdQM0FwFnG9Vv4vfEv%2F0zvCPxhakLMeyzbmzNDul6j3OrPU4VxY7xMr2bzDRY9pb7yc7gyKykIX%2FzqiMKw9NJaYvd858j7wnYC6wK%2FPMRE%2Fr45iiPDrxLcEri4h9vW0C8YhUTP%2FD1hJFQty2KS6nKXTIlTjfunUA3XfgDhYR3hy4HqRTmkCxzHv0KJs2XvbEzODP5GEQjSxKQXlo",
        "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_Tencent%20HABO.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208156&Signature=LkY0drhs4Hyo8VkdUIwaxW7Ej1h8Uzhf6E3mpwOzCp%2BseX1pZcB2eVzZGa3U1bp2woAxF8N0w6ItA6hh14Ecaq26YEU78OQHluBOjDD05wYLm1kZDESgfOQZ93owFEXKy267LJtLTldA%2BQMhApZM0zZBKfF9VzZRqQCwvXusUk5fLOX5kpUYUgixwVHamIXwbLG9CgxX6OdWPTKpVWxfsi2dmlWhGmWuuVTIjVyqxH8aV%2BU5FRhyccS8",
        "06:51 AM 09/18/2014 06:51 AM 09/12/2039 541a810a 0b8464eae298da2d9ec5a12271309acb25e25465",
        "Certificate Issuer: C:US, CN:Michael LaPean, L:Torrance, O:Toyota Motor Sales, ST:California, OU:Toyota Owners Michael LaPean Toyota Motor Sales Toyota Owners US California Torrance"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 9,
        "FileHash-SHA1": 6,
        "email": 2,
        "hostname": 104,
        "URL": 198,
        "domain": 28,
        "IPv6": 8,
        "FileHash-SHA256": 42,
        "IPv4": 56
      },
      "indicator_count": 453,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1bd66eeaaf6d7290ac299d",
      "name": "Bluesnarfing - Accessibility Feautures Part 2 * VirusTotal Droidy Android Sandbox",
      "description": "A recent Veteran client who was forced to abandon a new smartphone & revert to a legacy model. The target device's pairing registry was flooded with unauthorized \"Toyota Corolla\" profiles. This disruptive exploit effectively displaced the user, highlighting an emerging threat pattern targeting vulnerable individuals. The vulnerability lies within the smartphone's automated peripheral linking layer. Attackers broadcast spoofed identifiers that the smartphone automatically accepts. This floods and corrupts the local registry database, rendering the device unmanageable. 1 Bluesnarfing: Attackers exploit authentication flaws to gain unauthorized access to internal data, allowing them to copy contacts, text messages, and photos without user permission, 2 Man-in-the-Middle (MitM) Relays: Attackers capture and relay wireless signals over long distances, fooling a phone into believing it is next to a trusted vehicle or accessory when it is miles away, 3 BLE Spoofing Attacks, & 4. Bluejacking.",
      "modified": "2026-05-31T06:34:22.530000",
      "created": "2026-05-31T06:34:22.530000",
      "tags": [
        "a domains",
        "present jun",
        "name servers",
        "meta",
        "toyota",
        "date",
        "present jul",
        "moved",
        "domains",
        "new cars",
        "body",
        "title",
        "aaaa",
        "cname",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "number",
        "cus oamazon",
        "cnamazon rsa",
        "m04 validity",
        "subject public",
        "key info",
        "key algorithm",
        "united",
        "name",
        "create date",
        "domain",
        "expiry date",
        "update date",
        "current object",
        "process",
        "e0 dd",
        "dc d8",
        "b7 fe",
        "c1 fc",
        "f8 b6",
        "ba df",
        "b0 s",
        "da dc",
        "android",
        "unknown",
        "detail info",
        "behaviour",
        "detect operator",
        "antisimulator",
        "check root",
        "access network",
        "connect",
        "contentresolver",
        "flag",
        "componentname",
        "extras",
        "service",
        "toyota owners",
        "us california",
        "torrance",
        "accessibility features",
        "veterans hearing aids",
        "veterans bluetooth",
        "tacoma",
        "corrolla"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_VirusTotal%20Droidy.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208130&Signature=wtAr8J0ruv23wHZcOhupkZaq%2BBIhOLdQM0FwFnG9Vv4vfEv%2F0zvCPxhakLMeyzbmzNDul6j3OrPU4VxY7xMr2bzDRY9pb7yc7gyKykIX%2FzqiMKw9NJaYvd858j7wnYC6wK%2FPMRE%2Fr45iiPDrxLcEri4h9vW0C8YhUTP%2FD1hJFQty2KS6nKXTIlTjfunUA3XfgDhYR3hy4HqRTmkCxzHv0KJs2XvbEzODP5GEQjSxKQXlo",
        "https://vtbehaviour.commondatastorage.googleapis.com/18cc9428ef5bf4bbd58cdb631b1ed7d723ce36f369c0e8b35896d87aef0f85ef_Tencent%20HABO.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1780208156&Signature=LkY0drhs4Hyo8VkdUIwaxW7Ej1h8Uzhf6E3mpwOzCp%2BseX1pZcB2eVzZGa3U1bp2woAxF8N0w6ItA6hh14Ecaq26YEU78OQHluBOjDD05wYLm1kZDESgfOQZ93owFEXKy267LJtLTldA%2BQMhApZM0zZBKfF9VzZRqQCwvXusUk5fLOX5kpUYUgixwVHamIXwbLG9CgxX6OdWPTKpVWxfsi2dmlWhGmWuuVTIjVyqxH8aV%2BU5FRhyccS8",
        "06:51 AM 09/18/2014 06:51 AM 09/12/2039 541a810a 0b8464eae298da2d9ec5a12271309acb25e25465",
        "Certificate Issuer: C:US, CN:Michael LaPean, L:Torrance, O:Toyota Motor Sales, ST:California, OU:Toyota Owners Michael LaPean Toyota Motor Sales Toyota Owners US California Torrance"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 9,
        "FileHash-SHA1": 6,
        "email": 2,
        "hostname": 80,
        "URL": 94,
        "domain": 22,
        "IPv6": 8,
        "FileHash-SHA256": 32,
        "IPv4": 26
      },
      "indicator_count": 279,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "3 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6998d15c75b59044877602c1",
      "name": "Corrupt.... Files",
      "description": "beaware",
      "modified": "2026-04-01T00:44:45.494000",
      "created": "2026-02-20T21:25:48.559000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 706,
        "FileHash-SHA1": 859,
        "FileHash-SHA256": 1480,
        "URL": 743,
        "domain": 1565,
        "email": 55,
        "hostname": 912,
        "CVE": 54,
        "CIDR": 27
      },
      "indicator_count": 6401,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "63 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698548fdc5e1b22b45457eb4",
      "name": "http://support[.]apple[.]com/kb/HT5012 - 02.05.26",
      "description": "\"Learn more about trusted certificates\" -> http://support[.]apple[.]com/kb/HT5012\nTrust Store Version 2025082000\nTrust Asset Version 1012",
      "modified": "2026-03-08T02:01:42.135000",
      "created": "2026-02-06T01:50:53.485000",
      "tags": [
        "vhash",
        "ssdeep",
        "html internet",
        "magic html",
        "unicode text",
        "utf8",
        "trid text",
        "magika html",
        "file size",
        "please",
        "javascript",
        "malware",
        "virus",
        "trojan",
        "ransomware",
        "static",
        "analysis",
        "indicator of compromise",
        "ioc",
        "extraction",
        "emulation",
        "online",
        "submit",
        "sample",
        "download",
        "platform",
        "url",
        "sandbox",
        "scanner",
        "reputation",
        "phishing",
        "warning icon",
        "share report",
        "domain",
        "apple mapkit",
        "java",
        "manager",
        "report",
        "home search",
        "insights",
        "login check",
        "android",
        "write",
        "login report",
        "overview",
        "tags submit",
        "tags url",
        "finishing url",
        "asn norway",
        "title available",
        "apple",
        "static analyzer",
        "analyzer",
        "type",
        "website title",
        "apple support",
        "date",
        "security",
        "access control",
        "plan search",
        "submission",
        "february",
        "error",
        "vxstream",
        "apt",
        "hybrid analysis",
        "api key",
        "vetting process",
        "please note",
        "prefetch8 ansi",
        "ansi",
        "show process",
        "hash seen",
        "programfiles",
        "ck id",
        "command decode",
        "mitre att",
        "suricata ipv4",
        "windir",
        "suspicious",
        "comspec",
        "hybrid",
        "model",
        "close",
        "click",
        "hosts",
        "general",
        "path",
        "form",
        "strings",
        "contact",
        "p2404",
        "attrdataver186",
        "p11770919978",
        "processorcores6",
        "tpmversion0",
        "telemetrylevel1",
        "oemmodeldell",
        "osuilocaleenus",
        "osskuid48",
        "osnamewin",
        "main",
        "sha1",
        "Apple",
        "iPadOS",
        "Freedom"
      ],
      "references": [
        "https://www.virustotal.com/gui/url/aec932cd6ff44a6b8a13e3573f47d7e543cc0e1cc25f6d4fa2e0b0f1b8c44603/details",
        "https://www.virustotal.com/gui/file/3447d0e0dce83b163308c04dffeb52afb9f22d756b57d516fb1930d60303278d/details",
        "https://www.filescan.io/uploads/69853e76930564ff3c8e3576/reports/132722cc-526c-428b-85d8-bb863204ec6f/ioc",
        "https://urlquery.net/report/f7f1fb29-f7fb-4aec-be06-978b4bb296ab",
        "https://app.threat.zone/submission/f373032a-49fe-46f2-be28-a4636cbeb3c2/url-analysis-report",
        "https://hybrid-analysis.com/sample/04fcf10162401756459d90569bdda9bd3f264efc7ce75e2ca96a8fc93e159bdb",
        "http://hybrid-analysis.com/sample/04fcf10162401756459d90569bdda9bd3f264efc7ce75e2ca96a8fc93e159bdb/698522a0b8d0f8b6c404b7b4",
        "https://app.any.run/tasks/40ac99f3-0bf0-4455-996b-01e9ba0aaf79",
        "https://www.virustotal.com/gui/collection/fc2724a35b1672bcbcbb1af5a8e77d1e6095818a9db880a18661208aa9e9f1ed",
        "https://www.virustotal.com/gui/collection/fc2724a35b1672bcbcbb1af5a8e77d1e6095818a9db880a18661208aa9e9f1ed/iocs",
        "https://www.virustotal.com/graph/embed/g70516ab17e6a482eb6641c8d15f795a9d0fbc493ae9d4c3ca0e0617754ba679c?theme=dark",
        "https://viz.greynoise.io/ip/analysis/66ca01e5-ac9a-4baf-b088-901cfbe72cac"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        }
      ],
      "industries": [
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 29,
        "FileHash-SHA1": 24,
        "FileHash-SHA256": 126,
        "URL": 323,
        "SSLCertFingerprint": 8,
        "domain": 14,
        "email": 4,
        "hostname": 138
      },
      "indicator_count": 666,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 132,
      "modified_text": "87 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "http://plus.google.com/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "http://plus.google.com/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780472228.8538604
}