{
  "type": "URL",
  "indicator": "http://socket.mcucc.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "http://socket.mcucc.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 2799609034,
      "indicator": "http://socket.mcucc.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 17,
      "pulses": [
        {
          "id": "69d4db11500ea6dcbc2afd10",
          "name": "ZETALYTICS.COM PT2 CREATED 2 YEARS AGO by StreamMiningEx Public TLP:  Green clone",
          "description": "",
          "modified": "2026-04-07T10:23:13.255000",
          "created": "2026-04-07T10:23:13.255000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65707f425121331bce0945cd",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "FileHash-SHA256": 932,
            "URL": 1267,
            "domain": 140
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "54 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "658481716d9034bb0d52212d",
          "name": "Apple Attack | Floxif Spyware | Threat Network | Virus Network",
          "description": "Threat Network affecting and/or originating from Apple server. Malware attacks apple airpods, tv, apple store\napple trade, apple tv\napple watch, apple card, apple og?, apple server.\nSystemUpdate.dll issue. Device may partially attempt, device will show latest update, com[promised devices may have throttled update on attempt.\n\nFloxif:\nShort bio\nTrojan.Floxif is Malwarebytes\u2019 detection name for a file-changing Trojanthat targets Windows systems.\n\nSymptoms\nTrojan.Floxif can change legitimate files into infected files. Then the infected files act as a backdoor, giving the threat actor control over the machine.\n\nStaged data. Floxif primarily target Windows, Apple is less vulnerable to buy can be experience a Floxif attack.",
          "modified": "2024-01-20T14:03:29.247000",
          "created": "2023-12-21T18:18:25.746000",
          "tags": [
            "bitrep",
            "learn",
            "apple card",
            "apple",
            "apple store",
            "apple tv",
            "watch vision",
            "airpods tv",
            "apple watch",
            "buy apple",
            "apple trade",
            "footer",
            "media",
            "find",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malicious site",
            "hostname",
            "hostnames",
            "detection list",
            "blacklist",
            "malware",
            "alexa",
            "ip address",
            "whois record",
            "ssl certificate",
            "iocs",
            "whois whois",
            "historical ssl",
            "communicating",
            "threat network",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "attack",
            "probe",
            "search",
            "threat",
            "paste",
            "contacted",
            "april",
            "threat roundup",
            "pe resource",
            "lcid1033",
            "smlen",
            "spn647",
            "bv6fet56ww",
            "february",
            "core",
            "name verdict",
            "falcon sandbox",
            "threat analyzer",
            "samples",
            "generic malware",
            "tag count",
            "malware generic",
            "tue dec",
            "threat report",
            "summary",
            "first",
            "http response",
            "final url",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "self",
            "server apple",
            "connection",
            "html info",
            "title apple",
            "meta tags",
            "indextab og",
            "apple og",
            "spyware",
            "plugins",
            "cab",
            "fraud urls",
            "data collection",
            "staged data",
            "privilege escalation",
            "defense evasion",
            "evasive",
            "stealthy",
            "serial number",
            "symantec time",
            "stamping",
            "algorithm",
            "thumbprint",
            "from",
            "symantec sha256",
            "sha256 code",
            "signing ca",
            "class",
            "vhash",
            "authentihash",
            "imphash",
            "rich pe",
            "ssdeep",
            "file type",
            "win32 dll",
            "magic pe32",
            "intel",
            "ms windows",
            "compiler",
            "vs2008",
            "rticon english",
            "vs2005",
            "chi2",
            "contained",
            "info compiler",
            "products",
            "header target",
            "machine intel",
            "utc entry",
            "floxif",
            "serving ip",
            "address",
            "headers nel",
            "dynamic expires",
            "gmt server",
            "file sharing",
            "personal data"
          ],
          "references": [
            "https://www.apple.com/qtactivex/qtplugin.cab",
            "https://www.hybrid-analysis.com/sample/f9fab0bda2e82393cdcbb235dd41b48e00552116101deb0215bc64032741dcad",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/. [ phishing, driver, malvertizing, targeting]",
            "http://www.screensaver.com/ruxitbeacon",
            "https://otx.alienvault.com/indicator/hostname/ac-netstorage.apple.com [front facing withu4ever.com dating app/fraud service stores Apple data]",
            "http://dns1.whitelist.camect.com    [interesting]",
            "https://www.jbits.courts.state.co    [interesting]",
            "http://www.sos.state.co/                   [interesting]",
            "https://www.virustotal.com/gui/file/b883f5fab23c459f41dee72e3f89fc19734fa2f505cb5bee192960f4a0f94062/summary",
            "https://www.virustotal.com/gui/url/2cb82dbaba5c1a7ea415992f28e2d35d06187a8cfc59691b43c1589e072b2c24/summary",
            "Crowdsourced YARA  Rulesets",
            "Matches rule Malware_Floxif_mpsvc_dll from ruleset gen_floxif by Florian Roth (Nextron Systems",
            "Matches rule Windows_Virus_Floxif_493d1897 from ruleset Windows_Virus_Floxif by Elastic Security",
            "Matches rule SUSP_XORed_MSDOS_Stub_Message from ruleset gen_xor_hunting by Florian Roth",
            "https://www.malwarebytes.com/blog/detections/trojan-floxif",
            "20.190.160.2         Microsoft  [exploit_source]",
            "20.190.160.67       Microsoft  [exploit_source]",
            "20.190.160.73       Microsoft  [exploit_source]",
            "watson.events.data.microsoft.com      [traffic manager]",
            "http://watson.microsoft.com/StageOne/rundll32_exe/6_1_7600_16385/4a5bc637StackHash_2264/0_0_0_0/00000000/c0000005/63df0a5b.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.1.17514&SM=LEN&SPN=647&BV=6FET56WW&MID=54046387-FC68-43CA-9068-077C0A157181.   [stack hash]",
            "watson.telemetry.microsoft.us   [Data traffic manager]",
            "www.anyxxxtube.net [tracking]",
            "https://shitting.takefile.link/4cgeojxano82/2375.Kty10122__scatting__Shit-Porn.net_.mp4.html [file sharing, personal network storage and backup]"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Apple",
              "display_name": "Apple",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 609,
            "FileHash-SHA1": 361,
            "FileHash-SHA256": 1977,
            "domain": 460,
            "hostname": 992,
            "URL": 3115
          },
          "indicator_count": 7514,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "862 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a0bc9f2837fed9426cdd",
          "name": "Apple Music.app (by @kailula)",
          "description": "",
          "modified": "2023-12-06T16:26:36.394000",
          "created": "2023-12-06T16:26:36.394000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1235,
            "domain": 324,
            "hostname": 1559,
            "URL": 2278,
            "FileHash-SHA1": 1
          },
          "indicator_count": 5397,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "657092f9499206cd87c73969",
          "name": "iphone",
          "description": "",
          "modified": "2023-12-06T15:27:53.981000",
          "created": "2023-12-06T15:27:53.981000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1768,
            "hostname": 808,
            "domain": 306,
            "URL": 1938,
            "FileHash-SHA1": 1
          },
          "indicator_count": 4821,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708a2e80d8b1c10621df33",
          "name": "HP Firmware Update-OJP8600_N911g-n_2011A.dmg",
          "description": "",
          "modified": "2023-12-06T14:50:22.893000",
          "created": "2023-12-06T14:50:22.893000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-SHA256": 228,
            "hostname": 247,
            "URL": 286,
            "domain": 16,
            "FileHash-MD5": 1
          },
          "indicator_count": 779,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570810b6b17147085608503",
          "name": "Apple Music.app",
          "description": "",
          "modified": "2023-12-06T14:11:23.015000",
          "created": "2023-12-06T14:11:23.015000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1235,
            "domain": 324,
            "hostname": 1559,
            "URL": 2278,
            "FileHash-SHA1": 1
          },
          "indicator_count": 5397,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "657080e2831409d23c8d24a5",
          "name": "iMessages.app 03.01.2022",
          "description": "",
          "modified": "2023-12-06T14:10:42.459000",
          "created": "2023-12-06T14:10:42.459000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1768,
            "hostname": 808,
            "domain": 306,
            "URL": 1937,
            "FileHash-SHA1": 1
          },
          "indicator_count": 4820,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707f425121331bce0945cd",
          "name": "ZETALYTICS.COM PT2",
          "description": "",
          "modified": "2023-12-06T14:03:46.820000",
          "created": "2023-12-06T14:03:46.820000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "FileHash-SHA256": 932,
            "URL": 1267,
            "domain": 140
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707ea9c0f2231d524c00ae",
          "name": "www.zetalytics.com",
          "description": "",
          "modified": "2023-12-06T14:01:12.637000",
          "created": "2023-12-06T14:01:12.637000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 632,
            "URL": 747,
            "hostname": 368,
            "domain": 116,
            "email": 1,
            "FileHash-SHA1": 2
          },
          "indicator_count": 1866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e7ab22bbbb24b60b0ede98",
          "name": "Apple Music.app (by @kailula)",
          "description": "",
          "modified": "2023-08-24T19:10:26.385000",
          "created": "2023-08-24T19:10:26.385000",
          "tags": [
            "whois",
            "whois record",
            "ssl certificate",
            "chinese",
            "ip check",
            "mac malware",
            "collection ii",
            "steg icons",
            "wired",
            "collection",
            "korlia",
            "trickbot"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6228c8698878b924d3b309b6",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2278,
            "hostname": 1559,
            "domain": 324,
            "FileHash-SHA256": 1235,
            "FileHash-SHA1": 1
          },
          "indicator_count": 5397,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "1010 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6342b2b087554c9d5209b50b",
          "name": "iphone",
          "description": "",
          "modified": "2022-11-09T00:03:32.403000",
          "created": "2022-10-09T11:38:24.078000",
          "tags": [],
          "references": [
            "iMessages.app"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "622775d4f2c38a89fdd0128a",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Lazzo115",
            "id": "210949",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 306,
            "URL": 1938,
            "hostname": 808,
            "FileHash-SHA256": 1768,
            "FileHash-SHA1": 1
          },
          "indicator_count": 4821,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 8,
          "modified_text": "1299 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62436e76f30ed9c47b94d92f",
          "name": "HP Firmware Update-OJP8600_N911g-n_2011A.dmg",
          "description": "",
          "modified": "2022-04-28T00:00:15.198000",
          "created": "2022-03-29T20:39:18.119000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 286,
            "hostname": 247,
            "domain": 16,
            "CVE": 1,
            "FileHash-SHA256": 228,
            "FileHash-MD5": 1
          },
          "indicator_count": 779,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1494 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62310336c0071a6c73cd7c34",
          "name": "AppleAutoUpdate",
          "description": "",
          "modified": "2022-04-14T00:01:40.805000",
          "created": "2022-03-15T21:20:54.633000",
          "tags": [
            "WannaCry",
            "Apple Zero Day"
          ],
          "references": [
            "AppleAutoUpdate.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Win.Ransomware.WannaCry-9856297-0",
              "display_name": "Win.Ransomware.WannaCry-9856297-0",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4607,
            "hostname": 1953,
            "domain": 619,
            "FileHash-SHA256": 2226
          },
          "indicator_count": 9405,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 410,
          "modified_text": "1508 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6228c8698878b924d3b309b6",
          "name": "Apple Music.app",
          "description": "",
          "modified": "2022-04-08T00:05:40.239000",
          "created": "2022-03-09T15:31:53.378000",
          "tags": [
            "whois",
            "whois record",
            "ssl certificate",
            "chinese",
            "ip check",
            "mac malware",
            "collection ii",
            "steg icons",
            "wired",
            "collection",
            "korlia",
            "trickbot"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2278,
            "hostname": 1559,
            "domain": 324,
            "FileHash-SHA256": 1235,
            "FileHash-SHA1": 1
          },
          "indicator_count": 5397,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 408,
          "modified_text": "1514 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "622775d4f2c38a89fdd0128a",
          "name": "iMessages.app 03.01.2022",
          "description": "",
          "modified": "2022-04-07T00:04:02.553000",
          "created": "2022-03-08T15:27:16.349000",
          "tags": [],
          "references": [
            "iMessages.app"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 306,
            "URL": 1937,
            "hostname": 808,
            "FileHash-SHA256": 1768,
            "FileHash-SHA1": 1
          },
          "indicator_count": 4820,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1515 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6219004f53e3ae2316efea12",
          "name": "ZETALYTICS.COM PT2",
          "description": "",
          "modified": "2022-03-27T00:00:39.057000",
          "created": "2022-02-25T16:14:07.302000",
          "tags": [
            "ssl certificate",
            "whois",
            "whois record"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "China"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 547,
            "URL": 1267,
            "domain": 140,
            "FileHash-SHA256": 932
          },
          "indicator_count": 2886,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1526 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6211eaee20bc9b0534df6133",
          "name": "www.zetalytics.com",
          "description": "",
          "modified": "2022-03-24T00:00:00.271000",
          "created": "2022-02-20T07:17:02.872000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "issuer",
            "cus cngo",
            "daddy secure",
            "g2 lscottsdale",
            "ouhttp",
            "validity",
            "info",
            "date",
            "tucows domains",
            "server",
            "algorithm",
            "iana id",
            "registrar url",
            "status",
            "registrar whois",
            "rank value",
            "ingestion time",
            "statvoo",
            "utc alexa",
            "utc cisco",
            "umbrella",
            "submission",
            "history first",
            "analysis",
            "utc http",
            "response final",
            "url https",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "tools",
            "Ransomware",
            "POSSIBLE ETERNAL BLUE"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "China",
            "Australia",
            "Belgium"
          ],
          "malware_families": [
            {
              "id": "TEL:NoPowShell!msil",
              "display_name": "TEL:NoPowShell!msil",
              "target": null
            },
            {
              "id": "PWS:Win32/QQPass.GP",
              "display_name": "PWS:Win32/QQPass.GP",
              "target": "/malware/PWS:Win32/QQPass.GP"
            },
            {
              "id": "Win.Malware.Razy-6783523-0",
              "display_name": "Win.Malware.Razy-6783523-0",
              "target": null
            },
            {
              "id": "Win.Trojan.Pasta-827",
              "display_name": "Win.Trojan.Pasta-827",
              "target": null
            },
            {
              "id": "Ransom:Win32/Wannaren.A",
              "display_name": "Ransom:Win32/Wannaren.A",
              "target": "/malware/Ransom:Win32/Wannaren.A"
            },
            {
              "id": "Win.Malware.Zusy-6840460-0",
              "display_name": "Win.Malware.Zusy-6840460-0",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent-1201096",
              "display_name": "Win.Trojan.Agent-1201096",
              "target": null
            },
            {
              "id": "Win32:Dropper-GUP\\ [Drp]",
              "display_name": "Win32:Dropper-GUP\\ [Drp]",
              "target": null
            },
            {
              "id": "Worm:Win32/Macoute",
              "display_name": "Worm:Win32/Macoute",
              "target": "/malware/Worm:Win32/Macoute"
            },
            {
              "id": "Win32:Sobig-H\\ [Wrm]",
              "display_name": "Win32:Sobig-H\\ [Wrm]",
              "target": null
            },
            {
              "id": "Win.Worm.Sobig-5",
              "display_name": "Win.Worm.Sobig-5",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Berbew",
              "display_name": "Backdoor:Win32/Berbew",
              "target": "/malware/Backdoor:Win32/Berbew"
            },
            {
              "id": "Win.Trojan.Crypted-30",
              "display_name": "Win.Trojan.Crypted-30",
              "target": null
            },
            {
              "id": "#VirTool:Win32/Obfuscator.ADB",
              "display_name": "#VirTool:Win32/Obfuscator.ADB",
              "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
            },
            {
              "id": "Win.Trojan.Kazy-6878",
              "display_name": "Win.Trojan.Kazy-6878",
              "target": null
            },
            {
              "id": "Win32:VB-FBX",
              "display_name": "Win32:VB-FBX",
              "target": null
            },
            {
              "id": "Win.Worm.Pajetbin-6726648-0",
              "display_name": "Win.Worm.Pajetbin-6726648-0",
              "target": null
            },
            {
              "id": "Trojan:Win32/Vindor.B",
              "display_name": "Trojan:Win32/Vindor.B",
              "target": "/malware/Trojan:Win32/Vindor.B"
            },
            {
              "id": "MSIL:BrowseFox-FC\\ [Adw]",
              "display_name": "MSIL:BrowseFox-FC\\ [Adw]",
              "target": null
            },
            {
              "id": "Win.Ransomware.Teslacrypt-7082109-1",
              "display_name": "Win.Ransomware.Teslacrypt-7082109-1",
              "target": null
            },
            {
              "id": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
              "display_name": "ALF:HSTR:Trojan:Win32/Injector.YY!bit",
              "target": null
            },
            {
              "id": "Win32:Papras-AX\\ [Trj]",
              "display_name": "Win32:Papras-AX\\ [Trj]",
              "target": null
            },
            {
              "id": "ALF:HSTR:MITM:UtilAds",
              "display_name": "ALF:HSTR:MITM:UtilAds",
              "target": null
            },
            {
              "id": "Win.Malware.Autoit-6753917-0",
              "display_name": "Win.Malware.Autoit-6753917-0",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 368,
            "URL": 747,
            "domain": 116,
            "FileHash-SHA256": 632,
            "email": 1,
            "FileHash-SHA1": 2
          },
          "indicator_count": 1866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 408,
          "modified_text": "1529 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.malwarebytes.com/blog/detections/trojan-floxif",
        "www.anyxxxtube.net [tracking]",
        "https://www.hybrid-analysis.com/sample/f9fab0bda2e82393cdcbb235dd41b48e00552116101deb0215bc64032741dcad",
        "20.190.160.73       Microsoft  [exploit_source]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/. [ phishing, driver, malvertizing, targeting]",
        "watson.telemetry.microsoft.us   [Data traffic manager]",
        "https://www.apple.com/qtactivex/qtplugin.cab",
        "watson.events.data.microsoft.com      [traffic manager]",
        "http://dns1.whitelist.camect.com    [interesting]",
        "http://www.screensaver.com/ruxitbeacon",
        "http://www.sos.state.co/                   [interesting]",
        "Crowdsourced YARA  Rulesets",
        "AppleAutoUpdate.pdf",
        "https://otx.alienvault.com/indicator/hostname/ac-netstorage.apple.com [front facing withu4ever.com dating app/fraud service stores Apple data]",
        "https://www.virustotal.com/gui/file/b883f5fab23c459f41dee72e3f89fc19734fa2f505cb5bee192960f4a0f94062/summary",
        "http://watson.microsoft.com/StageOne/rundll32_exe/6_1_7600_16385/4a5bc637StackHash_2264/0_0_0_0/00000000/c0000005/63df0a5b.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.1.17514&SM=LEN&SPN=647&BV=6FET56WW&MID=54046387-FC68-43CA-9068-077C0A157181.   [stack hash]",
        "20.190.160.2         Microsoft  [exploit_source]",
        "https://www.virustotal.com/gui/url/2cb82dbaba5c1a7ea415992f28e2d35d06187a8cfc59691b43c1589e072b2c24/summary",
        "20.190.160.67       Microsoft  [exploit_source]",
        "https://www.jbits.courts.state.co    [interesting]",
        "https://shitting.takefile.link/4cgeojxano82/2375.Kty10122__scatting__Shit-Porn.net_.mp4.html [file sharing, personal network storage and backup]",
        "Matches rule SUSP_XORed_MSDOS_Stub_Message from ruleset gen_xor_hunting by Florian Roth",
        "iMessages.app",
        "Matches rule Malware_Floxif_mpsvc_dll from ruleset gen_floxif by Florian Roth (Nextron Systems",
        "Matches rule Windows_Virus_Floxif_493d1897 from ruleset Windows_Virus_Floxif by Elastic Security"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Win32:papras-ax\\ [trj]",
            "Msil:browsefox-fc\\ [adw]",
            "Apple",
            "Win.malware.autoit-6753917-0",
            "Win.worm.sobig-5",
            "Win.ransomware.wannacry-9856297-0",
            "Win.trojan.kazy-6878",
            "Win.trojan.crypted-30",
            "Alf:hstr:mitm:utilads",
            "#virtool:win32/obfuscator.adb",
            "Tel:nopowshell!msil",
            "Malware",
            "Alf:hstr:trojan:win32/injector.yy!bit",
            "Backdoor:win32/berbew",
            "Worm:win32/macoute",
            "Pws:win32/qqpass.gp",
            "Win.trojan.agent-1201096",
            "Win32:sobig-h\\ [wrm]",
            "Trojan:win32/vindor.b",
            "Tulach",
            "Win.worm.pajetbin-6726648-0",
            "Win.trojan.pasta-827",
            "Win.malware.razy-6783523-0",
            "Win32:vb-fbx",
            "Ransom:win32/wannaren.a",
            "Win.malware.zusy-6840460-0",
            "Win32:dropper-gup\\ [drp]",
            "Win.ransomware.teslacrypt-7082109-1"
          ],
          "industries": [
            "Technology"
          ],
          "unique_indicators": 29583
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/mcucc.com",
    "whois": "http://whois.domaintools.com/mcucc.com",
    "domain": "mcucc.com",
    "hostname": "socket.mcucc.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 17,
  "pulses": [
    {
      "id": "69d4db11500ea6dcbc2afd10",
      "name": "ZETALYTICS.COM PT2 CREATED 2 YEARS AGO by StreamMiningEx Public TLP:  Green clone",
      "description": "",
      "modified": "2026-04-07T10:23:13.255000",
      "created": "2026-04-07T10:23:13.255000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65707f425121331bce0945cd",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 547,
        "FileHash-SHA256": 932,
        "URL": 1267,
        "domain": 140
      },
      "indicator_count": 2886,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "54 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "658481716d9034bb0d52212d",
      "name": "Apple Attack | Floxif Spyware | Threat Network | Virus Network",
      "description": "Threat Network affecting and/or originating from Apple server. Malware attacks apple airpods, tv, apple store\napple trade, apple tv\napple watch, apple card, apple og?, apple server.\nSystemUpdate.dll issue. Device may partially attempt, device will show latest update, com[promised devices may have throttled update on attempt.\n\nFloxif:\nShort bio\nTrojan.Floxif is Malwarebytes\u2019 detection name for a file-changing Trojanthat targets Windows systems.\n\nSymptoms\nTrojan.Floxif can change legitimate files into infected files. Then the infected files act as a backdoor, giving the threat actor control over the machine.\n\nStaged data. Floxif primarily target Windows, Apple is less vulnerable to buy can be experience a Floxif attack.",
      "modified": "2024-01-20T14:03:29.247000",
      "created": "2023-12-21T18:18:25.746000",
      "tags": [
        "bitrep",
        "learn",
        "apple card",
        "apple",
        "apple store",
        "apple tv",
        "watch vision",
        "airpods tv",
        "apple watch",
        "buy apple",
        "apple trade",
        "footer",
        "media",
        "find",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malicious site",
        "hostname",
        "hostnames",
        "detection list",
        "blacklist",
        "malware",
        "alexa",
        "ip address",
        "whois record",
        "ssl certificate",
        "iocs",
        "whois whois",
        "historical ssl",
        "communicating",
        "threat network",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "attack",
        "probe",
        "search",
        "threat",
        "paste",
        "contacted",
        "april",
        "threat roundup",
        "pe resource",
        "lcid1033",
        "smlen",
        "spn647",
        "bv6fet56ww",
        "february",
        "core",
        "name verdict",
        "falcon sandbox",
        "threat analyzer",
        "samples",
        "generic malware",
        "tag count",
        "malware generic",
        "tue dec",
        "threat report",
        "summary",
        "first",
        "http response",
        "final url",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "self",
        "server apple",
        "connection",
        "html info",
        "title apple",
        "meta tags",
        "indextab og",
        "apple og",
        "spyware",
        "plugins",
        "cab",
        "fraud urls",
        "data collection",
        "staged data",
        "privilege escalation",
        "defense evasion",
        "evasive",
        "stealthy",
        "serial number",
        "symantec time",
        "stamping",
        "algorithm",
        "thumbprint",
        "from",
        "symantec sha256",
        "sha256 code",
        "signing ca",
        "class",
        "vhash",
        "authentihash",
        "imphash",
        "rich pe",
        "ssdeep",
        "file type",
        "win32 dll",
        "magic pe32",
        "intel",
        "ms windows",
        "compiler",
        "vs2008",
        "rticon english",
        "vs2005",
        "chi2",
        "contained",
        "info compiler",
        "products",
        "header target",
        "machine intel",
        "utc entry",
        "floxif",
        "serving ip",
        "address",
        "headers nel",
        "dynamic expires",
        "gmt server",
        "file sharing",
        "personal data"
      ],
      "references": [
        "https://www.apple.com/qtactivex/qtplugin.cab",
        "https://www.hybrid-analysis.com/sample/f9fab0bda2e82393cdcbb235dd41b48e00552116101deb0215bc64032741dcad",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/. [ phishing, driver, malvertizing, targeting]",
        "http://www.screensaver.com/ruxitbeacon",
        "https://otx.alienvault.com/indicator/hostname/ac-netstorage.apple.com [front facing withu4ever.com dating app/fraud service stores Apple data]",
        "http://dns1.whitelist.camect.com    [interesting]",
        "https://www.jbits.courts.state.co    [interesting]",
        "http://www.sos.state.co/                   [interesting]",
        "https://www.virustotal.com/gui/file/b883f5fab23c459f41dee72e3f89fc19734fa2f505cb5bee192960f4a0f94062/summary",
        "https://www.virustotal.com/gui/url/2cb82dbaba5c1a7ea415992f28e2d35d06187a8cfc59691b43c1589e072b2c24/summary",
        "Crowdsourced YARA  Rulesets",
        "Matches rule Malware_Floxif_mpsvc_dll from ruleset gen_floxif by Florian Roth (Nextron Systems",
        "Matches rule Windows_Virus_Floxif_493d1897 from ruleset Windows_Virus_Floxif by Elastic Security",
        "Matches rule SUSP_XORed_MSDOS_Stub_Message from ruleset gen_xor_hunting by Florian Roth",
        "https://www.malwarebytes.com/blog/detections/trojan-floxif",
        "20.190.160.2         Microsoft  [exploit_source]",
        "20.190.160.67       Microsoft  [exploit_source]",
        "20.190.160.73       Microsoft  [exploit_source]",
        "watson.events.data.microsoft.com      [traffic manager]",
        "http://watson.microsoft.com/StageOne/rundll32_exe/6_1_7600_16385/4a5bc637StackHash_2264/0_0_0_0/00000000/c0000005/63df0a5b.htm?LCID=1033&OS=6.1.7601.2.00010100.1.0.1.17514&SM=LEN&SPN=647&BV=6FET56WW&MID=54046387-FC68-43CA-9068-077C0A157181.   [stack hash]",
        "watson.telemetry.microsoft.us   [Data traffic manager]",
        "www.anyxxxtube.net [tracking]",
        "https://shitting.takefile.link/4cgeojxano82/2375.Kty10122__scatting__Shit-Porn.net_.mp4.html [file sharing, personal network storage and backup]"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Apple",
          "display_name": "Apple",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 609,
        "FileHash-SHA1": 361,
        "FileHash-SHA256": 1977,
        "domain": 460,
        "hostname": 992,
        "URL": 3115
      },
      "indicator_count": 7514,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "862 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a0bc9f2837fed9426cdd",
      "name": "Apple Music.app (by @kailula)",
      "description": "",
      "modified": "2023-12-06T16:26:36.394000",
      "created": "2023-12-06T16:26:36.394000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1235,
        "domain": 324,
        "hostname": 1559,
        "URL": 2278,
        "FileHash-SHA1": 1
      },
      "indicator_count": 5397,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "657092f9499206cd87c73969",
      "name": "iphone",
      "description": "",
      "modified": "2023-12-06T15:27:53.981000",
      "created": "2023-12-06T15:27:53.981000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1768,
        "hostname": 808,
        "domain": 306,
        "URL": 1938,
        "FileHash-SHA1": 1
      },
      "indicator_count": 4821,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708a2e80d8b1c10621df33",
      "name": "HP Firmware Update-OJP8600_N911g-n_2011A.dmg",
      "description": "",
      "modified": "2023-12-06T14:50:22.893000",
      "created": "2023-12-06T14:50:22.893000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-SHA256": 228,
        "hostname": 247,
        "URL": 286,
        "domain": 16,
        "FileHash-MD5": 1
      },
      "indicator_count": 779,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570810b6b17147085608503",
      "name": "Apple Music.app",
      "description": "",
      "modified": "2023-12-06T14:11:23.015000",
      "created": "2023-12-06T14:11:23.015000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1235,
        "domain": 324,
        "hostname": 1559,
        "URL": 2278,
        "FileHash-SHA1": 1
      },
      "indicator_count": 5397,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "657080e2831409d23c8d24a5",
      "name": "iMessages.app 03.01.2022",
      "description": "",
      "modified": "2023-12-06T14:10:42.459000",
      "created": "2023-12-06T14:10:42.459000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1768,
        "hostname": 808,
        "domain": 306,
        "URL": 1937,
        "FileHash-SHA1": 1
      },
      "indicator_count": 4820,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707f425121331bce0945cd",
      "name": "ZETALYTICS.COM PT2",
      "description": "",
      "modified": "2023-12-06T14:03:46.820000",
      "created": "2023-12-06T14:03:46.820000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 547,
        "FileHash-SHA256": 932,
        "URL": 1267,
        "domain": 140
      },
      "indicator_count": 2886,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707ea9c0f2231d524c00ae",
      "name": "www.zetalytics.com",
      "description": "",
      "modified": "2023-12-06T14:01:12.637000",
      "created": "2023-12-06T14:01:12.637000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 632,
        "URL": 747,
        "hostname": 368,
        "domain": 116,
        "email": 1,
        "FileHash-SHA1": 2
      },
      "indicator_count": 1866,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64e7ab22bbbb24b60b0ede98",
      "name": "Apple Music.app (by @kailula)",
      "description": "",
      "modified": "2023-08-24T19:10:26.385000",
      "created": "2023-08-24T19:10:26.385000",
      "tags": [
        "whois",
        "whois record",
        "ssl certificate",
        "chinese",
        "ip check",
        "mac malware",
        "collection ii",
        "steg icons",
        "wired",
        "collection",
        "korlia",
        "trickbot"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6228c8698878b924d3b309b6",
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2278,
        "hostname": 1559,
        "domain": 324,
        "FileHash-SHA256": 1235,
        "FileHash-SHA1": 1
      },
      "indicator_count": 5397,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "1010 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "http://socket.mcucc.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "http://socket.mcucc.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780247282.3033445
}