{
  "type": "URL",
  "indicator": "https://admin.bookszap.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://admin.bookszap.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3785244750,
      "indicator": "https://admin.bookszap.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 8,
      "pulses": [
        {
          "id": "659ab3389d6c91dc01801fe5",
          "name": "Simda | Sabey Data Center | https://nsa.gov1.info/utah-data-center/",
          "description": "SIMDA is a family of backdoors capable of stealing information such as user names, passwords, and certificates. It steals information via its keylogging and HTML injection routines. \nReference: TrendMicro\n\nMALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda\nWin32.Trojan-Spy.Shiz.b\nParody named 'not the Whitehouse' -https://whois.domaintools.com/gov1.info\nM.Brian Sabey \nTargets Tsara Brashears",
          "modified": "2024-02-06T14:00:04.985000",
          "created": "2024-01-07T14:20:40.610000",
          "tags": [
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "redacted for",
            "privacy tech",
            "privacy admin",
            "date",
            "server",
            "country",
            "organization",
            "postal code",
            "stateprovince",
            "code",
            "whois record",
            "ssl certificate",
            "historical ssl",
            "whois whois",
            "september",
            "redline stealer",
            "whois",
            "threat roundup",
            "bangladesh",
            "communicating",
            "prynt stealer",
            "banker",
            "keylogger",
            "dtrack",
            "prynt",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "jpeg image",
            "jfif",
            "ascii text",
            "united",
            "appdata",
            "file",
            "indicator",
            "et tor",
            "known tor",
            "class",
            "unknown",
            "general",
            "hybrid",
            "local",
            "win64",
            "click",
            "twitter",
            "strings",
            "generator",
            "critical",
            "error",
            "trident",
            "cascade",
            "darpa",
            "registrar",
            "rdds service",
            "record",
            "registrant",
            "admin",
            "tech contact",
            "whois service",
            "form",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers nel",
            "contentencoding",
            "gmt connection",
            "search",
            "for privacy",
            "status",
            "showing",
            "passive dns",
            "urls",
            "ionos se",
            "creation date",
            "next",
            "aaaa",
            "pulse pulses",
            "files",
            "united kingdom",
            "whitelisted",
            "worm",
            "gmt contenttype",
            "scan endpoints",
            "all octoseek",
            "ipv4",
            "body",
            "http",
            "unique",
            "screenshot",
            "url http",
            "ip address",
            "internet se",
            "emails",
            "name servers",
            "dnssec",
            "as63949 linode",
            "all search",
            "otx octoseek",
            "related nids",
            "reverse dns",
            "netherlands asn",
            "contacted",
            "resolutions",
            "referrer",
            "mirai malware",
            "urls http",
            "parent referrer",
            "certificate",
            "record value",
            "entries",
            "dynamicloader",
            "yara rule",
            "high",
            "sinkhole cookie",
            "et trojan",
            "medium",
            "yara detections",
            "virtool",
            "value snkz",
            "less see",
            "possible",
            "august",
            "copy",
            "expiro",
            "public folder",
            "pictures",
            "videos",
            "music",
            "anomalous file",
            "media player",
            "url https",
            "delete c",
            "ms windows",
            "pe32",
            "intel",
            "windows nt",
            "wow64",
            "khtml",
            "gecko",
            "query",
            "write",
            "malware",
            "template",
            "findwindowa",
            "ollydbg",
            "regsetvalueexa",
            "regdword",
            "high process",
            "x8bxe5",
            "regbinary",
            "injection t1055",
            "t1055",
            "zeppelin",
            "win32",
            "internal",
            "malware beacon",
            "a checkin",
            "create c",
            "read c",
            "write c",
            "msie",
            "suspicious",
            "slcc2",
            "media center",
            "as20940",
            "as2914 ntt",
            "as16625 akamai",
            "a domains",
            "cdata",
            "script",
            "as8068",
            "mtb oct",
            "location canada",
            "trojanspy",
            "xpire.info",
            "searchmeup",
            "cname",
            "as35994 akamai",
            "as14061",
            "as9009 m247",
            "samples",
            "as25577 ide",
            "hostnames",
            "show",
            "info compiler",
            "products",
            "vs2008 sp1",
            "vs2008",
            "vs2010",
            "header target",
            "machine intel",
            "utc entry",
            "point",
            "sections",
            "info",
            "hashes c2ae",
            "zenbox",
            "detections file",
            "name",
            "html",
            "win32 exe",
            "javascript",
            "contacted ip",
            "ip detections",
            "gandi sas",
            "godaddy online",
            "cayman",
            "dynadot",
            "domains",
            "psiusa",
            "domain robot",
            "dynadot inc",
            "net technology",
            "tsara brashears",
            "apple phone",
            "unlocker",
            "shell code",
            "simda",
            "amazon 02",
            "metro",
            "infected",
            "qakbot"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [
            {
              "id": "Prynt",
              "display_name": "Prynt",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Xpire.info",
              "display_name": "Xpire.info",
              "target": null
            },
            {
              "id": "Searchmeup",
              "display_name": "Searchmeup",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 30,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2129,
            "FileHash-SHA1": 1459,
            "FileHash-SHA256": 5050,
            "URL": 7341,
            "domain": 3041,
            "hostname": 3214,
            "email": 12,
            "CVE": 1
          },
          "indicator_count": 22247,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "845 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "659ab33e614882a4a7451ca8",
          "name": "Simda | Sabey Data Center | https://nsa.gov1.info/utah-data-center/",
          "description": "SIMDA is a family of backdoors capable of stealing information such as user names, passwords, and certificates. It steals information via its keylogging and HTML injection routines. \nReference: TrendMicro\n\nMALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda\nWin32.Trojan-Spy.Shiz.b\nParody named 'not the Whitehouse' -https://whois.domaintools.com/gov1.info\nM.Brian Sabey \nTargets Tsara Brashears",
          "modified": "2024-02-06T14:00:04.985000",
          "created": "2024-01-07T14:20:46.936000",
          "tags": [
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "urls https",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "redacted for",
            "privacy tech",
            "privacy admin",
            "date",
            "server",
            "country",
            "organization",
            "postal code",
            "stateprovince",
            "code",
            "whois record",
            "ssl certificate",
            "historical ssl",
            "whois whois",
            "september",
            "redline stealer",
            "whois",
            "threat roundup",
            "bangladesh",
            "communicating",
            "prynt stealer",
            "banker",
            "keylogger",
            "dtrack",
            "prynt",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "jpeg image",
            "jfif",
            "ascii text",
            "united",
            "appdata",
            "file",
            "indicator",
            "et tor",
            "known tor",
            "class",
            "unknown",
            "general",
            "hybrid",
            "local",
            "win64",
            "click",
            "twitter",
            "strings",
            "generator",
            "critical",
            "error",
            "trident",
            "cascade",
            "darpa",
            "registrar",
            "rdds service",
            "record",
            "registrant",
            "admin",
            "tech contact",
            "whois service",
            "form",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "headers nel",
            "contentencoding",
            "gmt connection",
            "search",
            "for privacy",
            "status",
            "showing",
            "passive dns",
            "urls",
            "ionos se",
            "creation date",
            "next",
            "aaaa",
            "pulse pulses",
            "files",
            "united kingdom",
            "whitelisted",
            "worm",
            "gmt contenttype",
            "scan endpoints",
            "all octoseek",
            "ipv4",
            "body",
            "http",
            "unique",
            "screenshot",
            "url http",
            "ip address",
            "internet se",
            "emails",
            "name servers",
            "dnssec",
            "as63949 linode",
            "all search",
            "otx octoseek",
            "related nids",
            "reverse dns",
            "netherlands asn",
            "contacted",
            "resolutions",
            "referrer",
            "mirai malware",
            "urls http",
            "parent referrer",
            "certificate",
            "record value",
            "entries",
            "dynamicloader",
            "yara rule",
            "high",
            "sinkhole cookie",
            "et trojan",
            "medium",
            "yara detections",
            "virtool",
            "value snkz",
            "less see",
            "possible",
            "august",
            "copy",
            "expiro",
            "public folder",
            "pictures",
            "videos",
            "music",
            "anomalous file",
            "media player",
            "url https",
            "delete c",
            "ms windows",
            "pe32",
            "intel",
            "windows nt",
            "wow64",
            "khtml",
            "gecko",
            "query",
            "write",
            "malware",
            "template",
            "findwindowa",
            "ollydbg",
            "regsetvalueexa",
            "regdword",
            "high process",
            "x8bxe5",
            "regbinary",
            "injection t1055",
            "t1055",
            "zeppelin",
            "win32",
            "internal",
            "malware beacon",
            "a checkin",
            "create c",
            "read c",
            "write c",
            "msie",
            "suspicious",
            "slcc2",
            "media center",
            "as20940",
            "as2914 ntt",
            "as16625 akamai",
            "a domains",
            "cdata",
            "script",
            "as8068",
            "mtb oct",
            "location canada",
            "trojanspy",
            "xpire.info",
            "searchmeup",
            "cname",
            "as35994 akamai",
            "as14061",
            "as9009 m247",
            "samples",
            "as25577 ide",
            "hostnames",
            "show",
            "info compiler",
            "products",
            "vs2008 sp1",
            "vs2008",
            "vs2010",
            "header target",
            "machine intel",
            "utc entry",
            "point",
            "sections",
            "info",
            "hashes c2ae",
            "zenbox",
            "detections file",
            "name",
            "html",
            "win32 exe",
            "javascript",
            "contacted ip",
            "ip detections",
            "gandi sas",
            "godaddy online",
            "cayman",
            "dynadot",
            "domains",
            "psiusa",
            "domain robot",
            "dynadot inc",
            "net technology",
            "tsara brashears",
            "apple phone",
            "unlocker",
            "shell code",
            "simda",
            "amazon 02",
            "metro",
            "infected",
            "qakbot"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [
            {
              "id": "Prynt",
              "display_name": "Prynt",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Xpire.info",
              "display_name": "Xpire.info",
              "target": null
            },
            {
              "id": "Searchmeup",
              "display_name": "Searchmeup",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 31,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 2129,
            "FileHash-SHA1": 1459,
            "FileHash-SHA256": 5050,
            "URL": 7341,
            "domain": 3041,
            "hostname": 3214,
            "email": 12,
            "CVE": 1
          },
          "indicator_count": 22247,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "845 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655f6d7ac217661e4bc37f4d",
          "name": "Qbot | Miscellaneous Attacks",
          "description": "The following is a full list of links between malware and cyber-attackers, following a series of alerts from Phishtank, the UK-based cyber security firm, and the US government.",
          "modified": "2023-12-23T07:03:55.171000",
          "created": "2023-11-23T15:19:22.356000",
          "tags": [
            "pattern match",
            "ascii text",
            "file",
            "jpeg image",
            "exif standard",
            "tiff image",
            "png image",
            "united",
            "baseline",
            "rgba",
            "date",
            "class",
            "unknown",
            "hybrid",
            "accept",
            "local",
            "click",
            "strings",
            "generator",
            "critical",
            "error",
            "firehol",
            "detection list",
            "ip address",
            "blacklist",
            "botnet command",
            "control server",
            "noname057",
            "facebook",
            "phishtank",
            "blacklist http",
            "organization",
            "ssl certificate",
            "whois record",
            "contacted",
            "historical ssl",
            "n64xtx0vpihxzc",
            "whois whois",
            "qpyrn6pd http",
            "referrer",
            "execution",
            "communicating",
            "core",
            "discord",
            "hiddentear",
            "metro",
            "probe",
            "ransomexx",
            "quasar",
            "asyncrat",
            "bleachgap",
            "formbook",
            "nanocore",
            "roblox",
            "heur",
            "cyber threat",
            "engineering",
            "malware",
            "phishing",
            "malicious site",
            "phishing site",
            "covid19",
            "team",
            "bank",
            "cobalt strike",
            "artemis",
            "download",
            "zbot",
            "suppobox",
            "service",
            "downloader",
            "virut",
            "malicious",
            "emotet",
            "stealer",
            "exploit",
            "generic",
            "dropper",
            "unruy",
            "agent",
            "unsafe",
            "ramnit",
            "redline stealer",
            "smsspy",
            "bradesco",
            "fakealert",
            "qakbot",
            "outbreak",
            "qbot",
            "bankerx",
            "riskware",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "crack",
            "win64",
            "squirrelwaffle",
            "pony",
            "binder",
            "virustotal",
            "azorult",
            "zeus",
            "nymaim",
            "matsnu",
            "simda",
            "runescape",
            "cutwail",
            "dnspionage",
            "redirector",
            "fusioncore",
            "iframe",
            "killav",
            "raccoon",
            "daum",
            "installcore",
            "ransomware",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "presenoker",
            "downldr",
            "alexa",
            "applicunwnt",
            "opencandy",
            "cleaner",
            "wacatac",
            "xrat",
            "xtrat",
            "dbatloader",
            "infy",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "keygen",
            "fareit",
            "secrisk",
            "phish",
            "deepscan",
            "trojanspy",
            "maltiverse",
            "qpyrn6pd",
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
            "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
            "*otc.greatcall.com    [Botnetwork]",
            "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
            "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
            "tulach.cc.     [Malevolent | Modified description]",
            "https://tulach.cc/ [phishing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
            "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
            "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
          ],
          "public": 1,
          "adversary": "Qbot",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Roblox",
              "display_name": "Roblox",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 82,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 897,
            "FileHash-SHA1": 479,
            "URL": 9847,
            "domain": 2344,
            "hostname": 2398,
            "CVE": 22,
            "FileHash-SHA256": 4712
          },
          "indicator_count": 20699,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "890 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655f6d89b33758a190399f39",
          "name": "Qbot | Miscellaneous Attacks",
          "description": "The following is a full list of links between malware and cyber-attackers, following a series of alerts from Phishtank, the UK-based cyber security firm, and the US government.",
          "modified": "2023-12-23T07:03:55.171000",
          "created": "2023-11-23T15:19:37.838000",
          "tags": [
            "pattern match",
            "ascii text",
            "file",
            "jpeg image",
            "exif standard",
            "tiff image",
            "png image",
            "united",
            "baseline",
            "rgba",
            "date",
            "class",
            "unknown",
            "hybrid",
            "accept",
            "local",
            "click",
            "strings",
            "generator",
            "critical",
            "error",
            "firehol",
            "detection list",
            "ip address",
            "blacklist",
            "botnet command",
            "control server",
            "noname057",
            "facebook",
            "phishtank",
            "blacklist http",
            "organization",
            "ssl certificate",
            "whois record",
            "contacted",
            "historical ssl",
            "n64xtx0vpihxzc",
            "whois whois",
            "qpyrn6pd http",
            "referrer",
            "execution",
            "communicating",
            "core",
            "discord",
            "hiddentear",
            "metro",
            "probe",
            "ransomexx",
            "quasar",
            "asyncrat",
            "bleachgap",
            "formbook",
            "nanocore",
            "roblox",
            "heur",
            "cyber threat",
            "engineering",
            "malware",
            "phishing",
            "malicious site",
            "phishing site",
            "covid19",
            "team",
            "bank",
            "cobalt strike",
            "artemis",
            "download",
            "zbot",
            "suppobox",
            "service",
            "downloader",
            "virut",
            "malicious",
            "emotet",
            "stealer",
            "exploit",
            "generic",
            "dropper",
            "unruy",
            "agent",
            "unsafe",
            "ramnit",
            "redline stealer",
            "smsspy",
            "bradesco",
            "fakealert",
            "qakbot",
            "outbreak",
            "qbot",
            "bankerx",
            "riskware",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "crack",
            "win64",
            "squirrelwaffle",
            "pony",
            "binder",
            "virustotal",
            "azorult",
            "zeus",
            "nymaim",
            "matsnu",
            "simda",
            "runescape",
            "cutwail",
            "dnspionage",
            "redirector",
            "fusioncore",
            "iframe",
            "killav",
            "raccoon",
            "daum",
            "installcore",
            "ransomware",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "presenoker",
            "downldr",
            "alexa",
            "applicunwnt",
            "opencandy",
            "cleaner",
            "wacatac",
            "xrat",
            "xtrat",
            "dbatloader",
            "infy",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "keygen",
            "fareit",
            "secrisk",
            "phish",
            "deepscan",
            "trojanspy",
            "maltiverse",
            "qpyrn6pd",
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
            "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
            "*otc.greatcall.com    [Botnetwork]",
            "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
            "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
            "tulach.cc.     [Malevolent | Modified description]",
            "https://tulach.cc/ [phishing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
            "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
            "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
          ],
          "public": 1,
          "adversary": "Qbot",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Roblox",
              "display_name": "Roblox",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 84,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 897,
            "FileHash-SHA1": 479,
            "URL": 9847,
            "domain": 2344,
            "hostname": 2398,
            "CVE": 22,
            "FileHash-SHA256": 4712
          },
          "indicator_count": 20699,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "890 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655f6edffd3910161c2ad1a2",
          "name": "D26A | DNSpionage| Qbot | Tulach Malaware | https://theanimallawfirm.com/ | FakeAlert",
          "description": "",
          "modified": "2023-12-23T07:03:55.171000",
          "created": "2023-11-23T15:25:19.843000",
          "tags": [
            "pattern match",
            "ascii text",
            "file",
            "jpeg image",
            "exif standard",
            "tiff image",
            "png image",
            "united",
            "baseline",
            "rgba",
            "date",
            "class",
            "unknown",
            "hybrid",
            "accept",
            "local",
            "click",
            "strings",
            "generator",
            "critical",
            "error",
            "firehol",
            "detection list",
            "ip address",
            "blacklist",
            "botnet command",
            "control server",
            "noname057",
            "facebook",
            "phishtank",
            "blacklist http",
            "organization",
            "ssl certificate",
            "whois record",
            "contacted",
            "historical ssl",
            "n64xtx0vpihxzc",
            "whois whois",
            "qpyrn6pd http",
            "referrer",
            "execution",
            "communicating",
            "core",
            "discord",
            "hiddentear",
            "metro",
            "probe",
            "ransomexx",
            "quasar",
            "asyncrat",
            "bleachgap",
            "formbook",
            "nanocore",
            "roblox",
            "heur",
            "cyber threat",
            "engineering",
            "malware",
            "phishing",
            "malicious site",
            "phishing site",
            "covid19",
            "team",
            "bank",
            "cobalt strike",
            "artemis",
            "download",
            "zbot",
            "suppobox",
            "service",
            "downloader",
            "virut",
            "malicious",
            "emotet",
            "stealer",
            "exploit",
            "generic",
            "dropper",
            "unruy",
            "agent",
            "unsafe",
            "ramnit",
            "redline stealer",
            "smsspy",
            "bradesco",
            "fakealert",
            "qakbot",
            "outbreak",
            "qbot",
            "bankerx",
            "riskware",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "crack",
            "win64",
            "squirrelwaffle",
            "pony",
            "binder",
            "virustotal",
            "azorult",
            "zeus",
            "nymaim",
            "matsnu",
            "simda",
            "runescape",
            "cutwail",
            "dnspionage",
            "redirector",
            "fusioncore",
            "iframe",
            "killav",
            "raccoon",
            "daum",
            "installcore",
            "ransomware",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "presenoker",
            "downldr",
            "alexa",
            "applicunwnt",
            "opencandy",
            "cleaner",
            "wacatac",
            "xrat",
            "xtrat",
            "dbatloader",
            "infy",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "keygen",
            "fareit",
            "secrisk",
            "phish",
            "deepscan",
            "trojanspy",
            "maltiverse",
            "qpyrn6pd",
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
            "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
            "*otc.greatcall.com    [Botnetwork]",
            "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
            "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
            "tulach.cc.     [Malevolent | Modified description]",
            "https://tulach.cc/ [phishing]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
            "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
            "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
          ],
          "public": 1,
          "adversary": "Qbot",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Roblox",
              "display_name": "Roblox",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "655f6d89b33758a190399f39",
          "export_count": 86,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 897,
            "FileHash-SHA1": 479,
            "URL": 9847,
            "domain": 2344,
            "hostname": 2398,
            "CVE": 22,
            "FileHash-SHA256": 4712
          },
          "indicator_count": 20699,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "890 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655e7e82c65d8e9106e6a227",
          "name": "https://theanimallawfirm.com/",
          "description": "",
          "modified": "2023-12-22T21:04:18.086000",
          "created": "2023-11-22T22:19:46.485000",
          "tags": [
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "n64xtx0vpihxzc",
            "qpyrn6pd",
            "detection list",
            "blacklist http",
            "cisco umbrella",
            "site",
            "site top",
            "alexa top",
            "safe site",
            "heur",
            "html",
            "site safe",
            "million",
            "malware",
            "artemis",
            "win64",
            "downldr",
            "presenoker",
            "fakealert",
            "riskware",
            "qakbot",
            "applicunwnt",
            "opencandy",
            "fusioncore",
            "cleaner",
            "wacatac",
            "exploit",
            "iframe",
            "dbatloader",
            "raccoon",
            "service",
            "agent",
            "alexa",
            "xtrat",
            "team",
            "phish",
            "deepscan",
            "crack",
            "suspicious",
            "phishing",
            "xrat",
            "cve201711882",
            "d26a",
            "maltiverse",
            "trojanspy",
            "united",
            "cyber threat",
            "engineering",
            "malicious site",
            "bank",
            "phishing site",
            "covid19",
            "facebook",
            "download",
            "emotet",
            "stealer",
            "suppobox",
            "downloader",
            "unsafe",
            "malicious",
            "smsspy",
            "cobalt strike",
            "generic",
            "dropper",
            "formbook",
            "unruy",
            "virut",
            "azorult",
            "zbot",
            "matsnu",
            "cutwail",
            "bradesco",
            "outbreak",
            "qbot",
            "bankerx",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "squirrelwaffle",
            "pony",
            "binder",
            "ramnit",
            "virustotal",
            "zeus",
            "nymaim",
            "simda",
            "runescape",
            "dnspionage",
            "redirector",
            "killav",
            "dcrat",
            "alien",
            "astaroth",
            "filerepmalware",
            "control server",
            "asyncrat",
            "redline stealer",
            "daum",
            "name verdict"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "D26A",
              "display_name": "D26A",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 62,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 592,
            "FileHash-SHA1": 320,
            "FileHash-SHA256": 1159,
            "URL": 1257,
            "domain": 1219,
            "hostname": 403,
            "CVE": 15
          },
          "indicator_count": 4965,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "891 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655e7ed63ab06f2006c90b1c",
          "name": "DNSpionage, ",
          "description": "",
          "modified": "2023-12-22T21:04:18.086000",
          "created": "2023-11-22T22:21:10.853000",
          "tags": [
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "n64xtx0vpihxzc",
            "qpyrn6pd",
            "detection list",
            "blacklist http",
            "cisco umbrella",
            "site",
            "site top",
            "alexa top",
            "safe site",
            "heur",
            "html",
            "site safe",
            "million",
            "malware",
            "artemis",
            "win64",
            "downldr",
            "presenoker",
            "fakealert",
            "riskware",
            "qakbot",
            "applicunwnt",
            "opencandy",
            "fusioncore",
            "cleaner",
            "wacatac",
            "exploit",
            "iframe",
            "dbatloader",
            "raccoon",
            "service",
            "agent",
            "alexa",
            "xtrat",
            "team",
            "phish",
            "deepscan",
            "crack",
            "suspicious",
            "phishing",
            "xrat",
            "cve201711882",
            "d26a",
            "maltiverse",
            "trojanspy",
            "united",
            "cyber threat",
            "engineering",
            "malicious site",
            "bank",
            "phishing site",
            "covid19",
            "facebook",
            "download",
            "emotet",
            "stealer",
            "suppobox",
            "downloader",
            "unsafe",
            "malicious",
            "smsspy",
            "cobalt strike",
            "generic",
            "dropper",
            "formbook",
            "unruy",
            "virut",
            "azorult",
            "zbot",
            "matsnu",
            "cutwail",
            "bradesco",
            "outbreak",
            "qbot",
            "bankerx",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "squirrelwaffle",
            "pony",
            "binder",
            "ramnit",
            "virustotal",
            "zeus",
            "nymaim",
            "simda",
            "runescape",
            "dnspionage",
            "redirector",
            "killav",
            "dcrat",
            "alien",
            "astaroth",
            "filerepmalware",
            "control server",
            "asyncrat",
            "redline stealer",
            "daum",
            "name verdict"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "D26A",
              "display_name": "D26A",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "655e7e82c65d8e9106e6a227",
          "export_count": 64,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 592,
            "FileHash-SHA1": 320,
            "FileHash-SHA256": 1159,
            "URL": 1257,
            "domain": 1219,
            "hostname": 403,
            "CVE": 15
          },
          "indicator_count": 4965,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "891 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "656a9f3ad7db0aa9475e86d0",
          "name": "https://theanimallawfirm.com/",
          "description": "",
          "modified": "2023-12-22T21:04:18.086000",
          "created": "2023-12-02T03:06:34.870000",
          "tags": [
            "spyware",
            "injector",
            "jul jan",
            "tag count",
            "tue jan",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "n64xtx0vpihxzc",
            "qpyrn6pd",
            "detection list",
            "blacklist http",
            "cisco umbrella",
            "site",
            "site top",
            "alexa top",
            "safe site",
            "heur",
            "html",
            "site safe",
            "million",
            "malware",
            "artemis",
            "win64",
            "downldr",
            "presenoker",
            "fakealert",
            "riskware",
            "qakbot",
            "applicunwnt",
            "opencandy",
            "fusioncore",
            "cleaner",
            "wacatac",
            "exploit",
            "iframe",
            "dbatloader",
            "raccoon",
            "service",
            "agent",
            "alexa",
            "xtrat",
            "team",
            "phish",
            "deepscan",
            "crack",
            "suspicious",
            "phishing",
            "xrat",
            "cve201711882",
            "d26a",
            "maltiverse",
            "trojanspy",
            "united",
            "cyber threat",
            "engineering",
            "malicious site",
            "bank",
            "phishing site",
            "covid19",
            "facebook",
            "download",
            "emotet",
            "stealer",
            "suppobox",
            "downloader",
            "unsafe",
            "malicious",
            "smsspy",
            "cobalt strike",
            "generic",
            "dropper",
            "formbook",
            "unruy",
            "virut",
            "azorult",
            "zbot",
            "matsnu",
            "cutwail",
            "bradesco",
            "outbreak",
            "qbot",
            "bankerx",
            "nimda",
            "swrort",
            "adwind",
            "trojanx",
            "squirrelwaffle",
            "pony",
            "binder",
            "ramnit",
            "virustotal",
            "zeus",
            "nymaim",
            "simda",
            "runescape",
            "dnspionage",
            "redirector",
            "killav",
            "dcrat",
            "alien",
            "astaroth",
            "filerepmalware",
            "control server",
            "asyncrat",
            "redline stealer",
            "daum",
            "name verdict"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "D26A",
              "display_name": "D26A",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "655e7e82c65d8e9106e6a227",
          "export_count": 45,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 592,
            "FileHash-SHA1": 320,
            "FileHash-SHA256": 1159,
            "URL": 1257,
            "domain": 1219,
            "hostname": 403,
            "CVE": 15
          },
          "indicator_count": 4965,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "891 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
        "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
        "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
        "tulach.cc.     [Malevolent | Modified description]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
        "*otc.greatcall.com    [Botnetwork]",
        "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
        "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]",
        "https://tulach.cc/ [phishing]",
        "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Qbot"
          ],
          "malware_families": [
            "Searchmeup",
            "Xpire.info",
            "Maltiverse",
            "Prynt",
            "Tulach malware",
            "Roblox",
            "D26a",
            "Trojanspy"
          ],
          "industries": [],
          "unique_indicators": 43980
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/bookszap.com",
    "whois": "http://whois.domaintools.com/bookszap.com",
    "domain": "bookszap.com",
    "hostname": "admin.bookszap.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 8,
  "pulses": [
    {
      "id": "659ab3389d6c91dc01801fe5",
      "name": "Simda | Sabey Data Center | https://nsa.gov1.info/utah-data-center/",
      "description": "SIMDA is a family of backdoors capable of stealing information such as user names, passwords, and certificates. It steals information via its keylogging and HTML injection routines. \nReference: TrendMicro\n\nMALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda\nWin32.Trojan-Spy.Shiz.b\nParody named 'not the Whitehouse' -https://whois.domaintools.com/gov1.info\nM.Brian Sabey \nTargets Tsara Brashears",
      "modified": "2024-02-06T14:00:04.985000",
      "created": "2024-01-07T14:20:40.610000",
      "tags": [
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls https",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "redacted for",
        "privacy tech",
        "privacy admin",
        "date",
        "server",
        "country",
        "organization",
        "postal code",
        "stateprovince",
        "code",
        "whois record",
        "ssl certificate",
        "historical ssl",
        "whois whois",
        "september",
        "redline stealer",
        "whois",
        "threat roundup",
        "bangladesh",
        "communicating",
        "prynt stealer",
        "banker",
        "keylogger",
        "dtrack",
        "prynt",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "jpeg image",
        "jfif",
        "ascii text",
        "united",
        "appdata",
        "file",
        "indicator",
        "et tor",
        "known tor",
        "class",
        "unknown",
        "general",
        "hybrid",
        "local",
        "win64",
        "click",
        "twitter",
        "strings",
        "generator",
        "critical",
        "error",
        "trident",
        "cascade",
        "darpa",
        "registrar",
        "rdds service",
        "record",
        "registrant",
        "admin",
        "tech contact",
        "whois service",
        "form",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "headers nel",
        "contentencoding",
        "gmt connection",
        "search",
        "for privacy",
        "status",
        "showing",
        "passive dns",
        "urls",
        "ionos se",
        "creation date",
        "next",
        "aaaa",
        "pulse pulses",
        "files",
        "united kingdom",
        "whitelisted",
        "worm",
        "gmt contenttype",
        "scan endpoints",
        "all octoseek",
        "ipv4",
        "body",
        "http",
        "unique",
        "screenshot",
        "url http",
        "ip address",
        "internet se",
        "emails",
        "name servers",
        "dnssec",
        "as63949 linode",
        "all search",
        "otx octoseek",
        "related nids",
        "reverse dns",
        "netherlands asn",
        "contacted",
        "resolutions",
        "referrer",
        "mirai malware",
        "urls http",
        "parent referrer",
        "certificate",
        "record value",
        "entries",
        "dynamicloader",
        "yara rule",
        "high",
        "sinkhole cookie",
        "et trojan",
        "medium",
        "yara detections",
        "virtool",
        "value snkz",
        "less see",
        "possible",
        "august",
        "copy",
        "expiro",
        "public folder",
        "pictures",
        "videos",
        "music",
        "anomalous file",
        "media player",
        "url https",
        "delete c",
        "ms windows",
        "pe32",
        "intel",
        "windows nt",
        "wow64",
        "khtml",
        "gecko",
        "query",
        "write",
        "malware",
        "template",
        "findwindowa",
        "ollydbg",
        "regsetvalueexa",
        "regdword",
        "high process",
        "x8bxe5",
        "regbinary",
        "injection t1055",
        "t1055",
        "zeppelin",
        "win32",
        "internal",
        "malware beacon",
        "a checkin",
        "create c",
        "read c",
        "write c",
        "msie",
        "suspicious",
        "slcc2",
        "media center",
        "as20940",
        "as2914 ntt",
        "as16625 akamai",
        "a domains",
        "cdata",
        "script",
        "as8068",
        "mtb oct",
        "location canada",
        "trojanspy",
        "xpire.info",
        "searchmeup",
        "cname",
        "as35994 akamai",
        "as14061",
        "as9009 m247",
        "samples",
        "as25577 ide",
        "hostnames",
        "show",
        "info compiler",
        "products",
        "vs2008 sp1",
        "vs2008",
        "vs2010",
        "header target",
        "machine intel",
        "utc entry",
        "point",
        "sections",
        "info",
        "hashes c2ae",
        "zenbox",
        "detections file",
        "name",
        "html",
        "win32 exe",
        "javascript",
        "contacted ip",
        "ip detections",
        "gandi sas",
        "godaddy online",
        "cayman",
        "dynadot",
        "domains",
        "psiusa",
        "domain robot",
        "dynadot inc",
        "net technology",
        "tsara brashears",
        "apple phone",
        "unlocker",
        "shell code",
        "simda",
        "amazon 02",
        "metro",
        "infected",
        "qakbot"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [
        {
          "id": "Prynt",
          "display_name": "Prynt",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Xpire.info",
          "display_name": "Xpire.info",
          "target": null
        },
        {
          "id": "Searchmeup",
          "display_name": "Searchmeup",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 30,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2129,
        "FileHash-SHA1": 1459,
        "FileHash-SHA256": 5050,
        "URL": 7341,
        "domain": 3041,
        "hostname": 3214,
        "email": 12,
        "CVE": 1
      },
      "indicator_count": 22247,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "845 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "659ab33e614882a4a7451ca8",
      "name": "Simda | Sabey Data Center | https://nsa.gov1.info/utah-data-center/",
      "description": "SIMDA is a family of backdoors capable of stealing information such as user names, passwords, and certificates. It steals information via its keylogging and HTML injection routines. \nReference: TrendMicro\n\nMALWARE-CNC User-Agent known malicious user-agent string - Win.Trojan.Simda\nWin32.Trojan-Spy.Shiz.b\nParody named 'not the Whitehouse' -https://whois.domaintools.com/gov1.info\nM.Brian Sabey \nTargets Tsara Brashears",
      "modified": "2024-02-06T14:00:04.985000",
      "created": "2024-01-07T14:20:46.936000",
      "tags": [
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "urls https",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "redacted for",
        "privacy tech",
        "privacy admin",
        "date",
        "server",
        "country",
        "organization",
        "postal code",
        "stateprovince",
        "code",
        "whois record",
        "ssl certificate",
        "historical ssl",
        "whois whois",
        "september",
        "redline stealer",
        "whois",
        "threat roundup",
        "bangladesh",
        "communicating",
        "prynt stealer",
        "banker",
        "keylogger",
        "dtrack",
        "prynt",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "jpeg image",
        "jfif",
        "ascii text",
        "united",
        "appdata",
        "file",
        "indicator",
        "et tor",
        "known tor",
        "class",
        "unknown",
        "general",
        "hybrid",
        "local",
        "win64",
        "click",
        "twitter",
        "strings",
        "generator",
        "critical",
        "error",
        "trident",
        "cascade",
        "darpa",
        "registrar",
        "rdds service",
        "record",
        "registrant",
        "admin",
        "tech contact",
        "whois service",
        "form",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "headers nel",
        "contentencoding",
        "gmt connection",
        "search",
        "for privacy",
        "status",
        "showing",
        "passive dns",
        "urls",
        "ionos se",
        "creation date",
        "next",
        "aaaa",
        "pulse pulses",
        "files",
        "united kingdom",
        "whitelisted",
        "worm",
        "gmt contenttype",
        "scan endpoints",
        "all octoseek",
        "ipv4",
        "body",
        "http",
        "unique",
        "screenshot",
        "url http",
        "ip address",
        "internet se",
        "emails",
        "name servers",
        "dnssec",
        "as63949 linode",
        "all search",
        "otx octoseek",
        "related nids",
        "reverse dns",
        "netherlands asn",
        "contacted",
        "resolutions",
        "referrer",
        "mirai malware",
        "urls http",
        "parent referrer",
        "certificate",
        "record value",
        "entries",
        "dynamicloader",
        "yara rule",
        "high",
        "sinkhole cookie",
        "et trojan",
        "medium",
        "yara detections",
        "virtool",
        "value snkz",
        "less see",
        "possible",
        "august",
        "copy",
        "expiro",
        "public folder",
        "pictures",
        "videos",
        "music",
        "anomalous file",
        "media player",
        "url https",
        "delete c",
        "ms windows",
        "pe32",
        "intel",
        "windows nt",
        "wow64",
        "khtml",
        "gecko",
        "query",
        "write",
        "malware",
        "template",
        "findwindowa",
        "ollydbg",
        "regsetvalueexa",
        "regdword",
        "high process",
        "x8bxe5",
        "regbinary",
        "injection t1055",
        "t1055",
        "zeppelin",
        "win32",
        "internal",
        "malware beacon",
        "a checkin",
        "create c",
        "read c",
        "write c",
        "msie",
        "suspicious",
        "slcc2",
        "media center",
        "as20940",
        "as2914 ntt",
        "as16625 akamai",
        "a domains",
        "cdata",
        "script",
        "as8068",
        "mtb oct",
        "location canada",
        "trojanspy",
        "xpire.info",
        "searchmeup",
        "cname",
        "as35994 akamai",
        "as14061",
        "as9009 m247",
        "samples",
        "as25577 ide",
        "hostnames",
        "show",
        "info compiler",
        "products",
        "vs2008 sp1",
        "vs2008",
        "vs2010",
        "header target",
        "machine intel",
        "utc entry",
        "point",
        "sections",
        "info",
        "hashes c2ae",
        "zenbox",
        "detections file",
        "name",
        "html",
        "win32 exe",
        "javascript",
        "contacted ip",
        "ip detections",
        "gandi sas",
        "godaddy online",
        "cayman",
        "dynadot",
        "domains",
        "psiusa",
        "domain robot",
        "dynadot inc",
        "net technology",
        "tsara brashears",
        "apple phone",
        "unlocker",
        "shell code",
        "simda",
        "amazon 02",
        "metro",
        "infected",
        "qakbot"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [
        {
          "id": "Prynt",
          "display_name": "Prynt",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Xpire.info",
          "display_name": "Xpire.info",
          "target": null
        },
        {
          "id": "Searchmeup",
          "display_name": "Searchmeup",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 31,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 2129,
        "FileHash-SHA1": 1459,
        "FileHash-SHA256": 5050,
        "URL": 7341,
        "domain": 3041,
        "hostname": 3214,
        "email": 12,
        "CVE": 1
      },
      "indicator_count": 22247,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "845 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655f6d7ac217661e4bc37f4d",
      "name": "Qbot | Miscellaneous Attacks",
      "description": "The following is a full list of links between malware and cyber-attackers, following a series of alerts from Phishtank, the UK-based cyber security firm, and the US government.",
      "modified": "2023-12-23T07:03:55.171000",
      "created": "2023-11-23T15:19:22.356000",
      "tags": [
        "pattern match",
        "ascii text",
        "file",
        "jpeg image",
        "exif standard",
        "tiff image",
        "png image",
        "united",
        "baseline",
        "rgba",
        "date",
        "class",
        "unknown",
        "hybrid",
        "accept",
        "local",
        "click",
        "strings",
        "generator",
        "critical",
        "error",
        "firehol",
        "detection list",
        "ip address",
        "blacklist",
        "botnet command",
        "control server",
        "noname057",
        "facebook",
        "phishtank",
        "blacklist http",
        "organization",
        "ssl certificate",
        "whois record",
        "contacted",
        "historical ssl",
        "n64xtx0vpihxzc",
        "whois whois",
        "qpyrn6pd http",
        "referrer",
        "execution",
        "communicating",
        "core",
        "discord",
        "hiddentear",
        "metro",
        "probe",
        "ransomexx",
        "quasar",
        "asyncrat",
        "bleachgap",
        "formbook",
        "nanocore",
        "roblox",
        "heur",
        "cyber threat",
        "engineering",
        "malware",
        "phishing",
        "malicious site",
        "phishing site",
        "covid19",
        "team",
        "bank",
        "cobalt strike",
        "artemis",
        "download",
        "zbot",
        "suppobox",
        "service",
        "downloader",
        "virut",
        "malicious",
        "emotet",
        "stealer",
        "exploit",
        "generic",
        "dropper",
        "unruy",
        "agent",
        "unsafe",
        "ramnit",
        "redline stealer",
        "smsspy",
        "bradesco",
        "fakealert",
        "qakbot",
        "outbreak",
        "qbot",
        "bankerx",
        "riskware",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "crack",
        "win64",
        "squirrelwaffle",
        "pony",
        "binder",
        "virustotal",
        "azorult",
        "zeus",
        "nymaim",
        "matsnu",
        "simda",
        "runescape",
        "cutwail",
        "dnspionage",
        "redirector",
        "fusioncore",
        "iframe",
        "killav",
        "raccoon",
        "daum",
        "installcore",
        "ransomware",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "presenoker",
        "downldr",
        "alexa",
        "applicunwnt",
        "opencandy",
        "cleaner",
        "wacatac",
        "xrat",
        "xtrat",
        "dbatloader",
        "infy",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "keygen",
        "fareit",
        "secrisk",
        "phish",
        "deepscan",
        "trojanspy",
        "maltiverse",
        "qpyrn6pd",
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample"
      ],
      "references": [
        "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
        "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
        "*otc.greatcall.com    [Botnetwork]",
        "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
        "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
        "tulach.cc.     [Malevolent | Modified description]",
        "https://tulach.cc/ [phishing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
        "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
        "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
      ],
      "public": 1,
      "adversary": "Qbot",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Roblox",
          "display_name": "Roblox",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 82,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 897,
        "FileHash-SHA1": 479,
        "URL": 9847,
        "domain": 2344,
        "hostname": 2398,
        "CVE": 22,
        "FileHash-SHA256": 4712
      },
      "indicator_count": 20699,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "890 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655f6d89b33758a190399f39",
      "name": "Qbot | Miscellaneous Attacks",
      "description": "The following is a full list of links between malware and cyber-attackers, following a series of alerts from Phishtank, the UK-based cyber security firm, and the US government.",
      "modified": "2023-12-23T07:03:55.171000",
      "created": "2023-11-23T15:19:37.838000",
      "tags": [
        "pattern match",
        "ascii text",
        "file",
        "jpeg image",
        "exif standard",
        "tiff image",
        "png image",
        "united",
        "baseline",
        "rgba",
        "date",
        "class",
        "unknown",
        "hybrid",
        "accept",
        "local",
        "click",
        "strings",
        "generator",
        "critical",
        "error",
        "firehol",
        "detection list",
        "ip address",
        "blacklist",
        "botnet command",
        "control server",
        "noname057",
        "facebook",
        "phishtank",
        "blacklist http",
        "organization",
        "ssl certificate",
        "whois record",
        "contacted",
        "historical ssl",
        "n64xtx0vpihxzc",
        "whois whois",
        "qpyrn6pd http",
        "referrer",
        "execution",
        "communicating",
        "core",
        "discord",
        "hiddentear",
        "metro",
        "probe",
        "ransomexx",
        "quasar",
        "asyncrat",
        "bleachgap",
        "formbook",
        "nanocore",
        "roblox",
        "heur",
        "cyber threat",
        "engineering",
        "malware",
        "phishing",
        "malicious site",
        "phishing site",
        "covid19",
        "team",
        "bank",
        "cobalt strike",
        "artemis",
        "download",
        "zbot",
        "suppobox",
        "service",
        "downloader",
        "virut",
        "malicious",
        "emotet",
        "stealer",
        "exploit",
        "generic",
        "dropper",
        "unruy",
        "agent",
        "unsafe",
        "ramnit",
        "redline stealer",
        "smsspy",
        "bradesco",
        "fakealert",
        "qakbot",
        "outbreak",
        "qbot",
        "bankerx",
        "riskware",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "crack",
        "win64",
        "squirrelwaffle",
        "pony",
        "binder",
        "virustotal",
        "azorult",
        "zeus",
        "nymaim",
        "matsnu",
        "simda",
        "runescape",
        "cutwail",
        "dnspionage",
        "redirector",
        "fusioncore",
        "iframe",
        "killav",
        "raccoon",
        "daum",
        "installcore",
        "ransomware",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "presenoker",
        "downldr",
        "alexa",
        "applicunwnt",
        "opencandy",
        "cleaner",
        "wacatac",
        "xrat",
        "xtrat",
        "dbatloader",
        "infy",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "keygen",
        "fareit",
        "secrisk",
        "phish",
        "deepscan",
        "trojanspy",
        "maltiverse",
        "qpyrn6pd",
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample"
      ],
      "references": [
        "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
        "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
        "*otc.greatcall.com    [Botnetwork]",
        "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
        "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
        "tulach.cc.     [Malevolent | Modified description]",
        "https://tulach.cc/ [phishing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
        "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
        "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
      ],
      "public": 1,
      "adversary": "Qbot",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Roblox",
          "display_name": "Roblox",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 84,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 897,
        "FileHash-SHA1": 479,
        "URL": 9847,
        "domain": 2344,
        "hostname": 2398,
        "CVE": 22,
        "FileHash-SHA256": 4712
      },
      "indicator_count": 20699,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "890 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655f6edffd3910161c2ad1a2",
      "name": "D26A | DNSpionage| Qbot | Tulach Malaware | https://theanimallawfirm.com/ | FakeAlert",
      "description": "",
      "modified": "2023-12-23T07:03:55.171000",
      "created": "2023-11-23T15:25:19.843000",
      "tags": [
        "pattern match",
        "ascii text",
        "file",
        "jpeg image",
        "exif standard",
        "tiff image",
        "png image",
        "united",
        "baseline",
        "rgba",
        "date",
        "class",
        "unknown",
        "hybrid",
        "accept",
        "local",
        "click",
        "strings",
        "generator",
        "critical",
        "error",
        "firehol",
        "detection list",
        "ip address",
        "blacklist",
        "botnet command",
        "control server",
        "noname057",
        "facebook",
        "phishtank",
        "blacklist http",
        "organization",
        "ssl certificate",
        "whois record",
        "contacted",
        "historical ssl",
        "n64xtx0vpihxzc",
        "whois whois",
        "qpyrn6pd http",
        "referrer",
        "execution",
        "communicating",
        "core",
        "discord",
        "hiddentear",
        "metro",
        "probe",
        "ransomexx",
        "quasar",
        "asyncrat",
        "bleachgap",
        "formbook",
        "nanocore",
        "roblox",
        "heur",
        "cyber threat",
        "engineering",
        "malware",
        "phishing",
        "malicious site",
        "phishing site",
        "covid19",
        "team",
        "bank",
        "cobalt strike",
        "artemis",
        "download",
        "zbot",
        "suppobox",
        "service",
        "downloader",
        "virut",
        "malicious",
        "emotet",
        "stealer",
        "exploit",
        "generic",
        "dropper",
        "unruy",
        "agent",
        "unsafe",
        "ramnit",
        "redline stealer",
        "smsspy",
        "bradesco",
        "fakealert",
        "qakbot",
        "outbreak",
        "qbot",
        "bankerx",
        "riskware",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "crack",
        "win64",
        "squirrelwaffle",
        "pony",
        "binder",
        "virustotal",
        "azorult",
        "zeus",
        "nymaim",
        "matsnu",
        "simda",
        "runescape",
        "cutwail",
        "dnspionage",
        "redirector",
        "fusioncore",
        "iframe",
        "killav",
        "raccoon",
        "daum",
        "installcore",
        "ransomware",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "presenoker",
        "downldr",
        "alexa",
        "applicunwnt",
        "opencandy",
        "cleaner",
        "wacatac",
        "xrat",
        "xtrat",
        "dbatloader",
        "infy",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "keygen",
        "fareit",
        "secrisk",
        "phish",
        "deepscan",
        "trojanspy",
        "maltiverse",
        "qpyrn6pd",
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample"
      ],
      "references": [
        "https://www.hybrid-analysis.com/sample/d4e0619008da0bf555fd1d9af2797eaed02c89512239cbdaf64c08e795bb9658",
        "http://www.jamesbgriffinlaw.com/wp-content/plugins/formcraft/file-upload/server/content/files/16132c66b562a3---dewubomojagorekijufuruni [ Malicious Plugins]",
        "*otc.greatcall.com    [Botnetwork]",
        "https://www.norad.mil/ [ Modified by others| Parking Crew - is a Tracker]",
        "https://otx.alienvault.com/indicator/url/http://103.246.145.111/gateonl.php?hwid=WALKER-PC-WALKER&cpuname=Intel [ Malware Server | iTunes path hacktool]",
        "tulach.cc.     [Malevolent | Modified description]",
        "https://tulach.cc/ [phishing]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [ ELF - Descriptions modified by others]",
        "https://www.pornhub.com/video/search?search=tsara+brashears [NORAD.mil phone tracking. Description modified]",
        "s3.amazonaws.com   [Virut Tsara Brashears Botnetwork | Modified description]"
      ],
      "public": 1,
      "adversary": "Qbot",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Roblox",
          "display_name": "Roblox",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "655f6d89b33758a190399f39",
      "export_count": 86,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 897,
        "FileHash-SHA1": 479,
        "URL": 9847,
        "domain": 2344,
        "hostname": 2398,
        "CVE": 22,
        "FileHash-SHA256": 4712
      },
      "indicator_count": 20699,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "890 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655e7e82c65d8e9106e6a227",
      "name": "https://theanimallawfirm.com/",
      "description": "",
      "modified": "2023-12-22T21:04:18.086000",
      "created": "2023-11-22T22:19:46.485000",
      "tags": [
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "n64xtx0vpihxzc",
        "qpyrn6pd",
        "detection list",
        "blacklist http",
        "cisco umbrella",
        "site",
        "site top",
        "alexa top",
        "safe site",
        "heur",
        "html",
        "site safe",
        "million",
        "malware",
        "artemis",
        "win64",
        "downldr",
        "presenoker",
        "fakealert",
        "riskware",
        "qakbot",
        "applicunwnt",
        "opencandy",
        "fusioncore",
        "cleaner",
        "wacatac",
        "exploit",
        "iframe",
        "dbatloader",
        "raccoon",
        "service",
        "agent",
        "alexa",
        "xtrat",
        "team",
        "phish",
        "deepscan",
        "crack",
        "suspicious",
        "phishing",
        "xrat",
        "cve201711882",
        "d26a",
        "maltiverse",
        "trojanspy",
        "united",
        "cyber threat",
        "engineering",
        "malicious site",
        "bank",
        "phishing site",
        "covid19",
        "facebook",
        "download",
        "emotet",
        "stealer",
        "suppobox",
        "downloader",
        "unsafe",
        "malicious",
        "smsspy",
        "cobalt strike",
        "generic",
        "dropper",
        "formbook",
        "unruy",
        "virut",
        "azorult",
        "zbot",
        "matsnu",
        "cutwail",
        "bradesco",
        "outbreak",
        "qbot",
        "bankerx",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "squirrelwaffle",
        "pony",
        "binder",
        "ramnit",
        "virustotal",
        "zeus",
        "nymaim",
        "simda",
        "runescape",
        "dnspionage",
        "redirector",
        "killav",
        "dcrat",
        "alien",
        "astaroth",
        "filerepmalware",
        "control server",
        "asyncrat",
        "redline stealer",
        "daum",
        "name verdict"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "D26A",
          "display_name": "D26A",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 62,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 592,
        "FileHash-SHA1": 320,
        "FileHash-SHA256": 1159,
        "URL": 1257,
        "domain": 1219,
        "hostname": 403,
        "CVE": 15
      },
      "indicator_count": 4965,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "891 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655e7ed63ab06f2006c90b1c",
      "name": "DNSpionage, ",
      "description": "",
      "modified": "2023-12-22T21:04:18.086000",
      "created": "2023-11-22T22:21:10.853000",
      "tags": [
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "n64xtx0vpihxzc",
        "qpyrn6pd",
        "detection list",
        "blacklist http",
        "cisco umbrella",
        "site",
        "site top",
        "alexa top",
        "safe site",
        "heur",
        "html",
        "site safe",
        "million",
        "malware",
        "artemis",
        "win64",
        "downldr",
        "presenoker",
        "fakealert",
        "riskware",
        "qakbot",
        "applicunwnt",
        "opencandy",
        "fusioncore",
        "cleaner",
        "wacatac",
        "exploit",
        "iframe",
        "dbatloader",
        "raccoon",
        "service",
        "agent",
        "alexa",
        "xtrat",
        "team",
        "phish",
        "deepscan",
        "crack",
        "suspicious",
        "phishing",
        "xrat",
        "cve201711882",
        "d26a",
        "maltiverse",
        "trojanspy",
        "united",
        "cyber threat",
        "engineering",
        "malicious site",
        "bank",
        "phishing site",
        "covid19",
        "facebook",
        "download",
        "emotet",
        "stealer",
        "suppobox",
        "downloader",
        "unsafe",
        "malicious",
        "smsspy",
        "cobalt strike",
        "generic",
        "dropper",
        "formbook",
        "unruy",
        "virut",
        "azorult",
        "zbot",
        "matsnu",
        "cutwail",
        "bradesco",
        "outbreak",
        "qbot",
        "bankerx",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "squirrelwaffle",
        "pony",
        "binder",
        "ramnit",
        "virustotal",
        "zeus",
        "nymaim",
        "simda",
        "runescape",
        "dnspionage",
        "redirector",
        "killav",
        "dcrat",
        "alien",
        "astaroth",
        "filerepmalware",
        "control server",
        "asyncrat",
        "redline stealer",
        "daum",
        "name verdict"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "D26A",
          "display_name": "D26A",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "655e7e82c65d8e9106e6a227",
      "export_count": 64,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 592,
        "FileHash-SHA1": 320,
        "FileHash-SHA256": 1159,
        "URL": 1257,
        "domain": 1219,
        "hostname": 403,
        "CVE": 15
      },
      "indicator_count": 4965,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "891 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "656a9f3ad7db0aa9475e86d0",
      "name": "https://theanimallawfirm.com/",
      "description": "",
      "modified": "2023-12-22T21:04:18.086000",
      "created": "2023-12-02T03:06:34.870000",
      "tags": [
        "spyware",
        "injector",
        "jul jan",
        "tag count",
        "tue jan",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "n64xtx0vpihxzc",
        "qpyrn6pd",
        "detection list",
        "blacklist http",
        "cisco umbrella",
        "site",
        "site top",
        "alexa top",
        "safe site",
        "heur",
        "html",
        "site safe",
        "million",
        "malware",
        "artemis",
        "win64",
        "downldr",
        "presenoker",
        "fakealert",
        "riskware",
        "qakbot",
        "applicunwnt",
        "opencandy",
        "fusioncore",
        "cleaner",
        "wacatac",
        "exploit",
        "iframe",
        "dbatloader",
        "raccoon",
        "service",
        "agent",
        "alexa",
        "xtrat",
        "team",
        "phish",
        "deepscan",
        "crack",
        "suspicious",
        "phishing",
        "xrat",
        "cve201711882",
        "d26a",
        "maltiverse",
        "trojanspy",
        "united",
        "cyber threat",
        "engineering",
        "malicious site",
        "bank",
        "phishing site",
        "covid19",
        "facebook",
        "download",
        "emotet",
        "stealer",
        "suppobox",
        "downloader",
        "unsafe",
        "malicious",
        "smsspy",
        "cobalt strike",
        "generic",
        "dropper",
        "formbook",
        "unruy",
        "virut",
        "azorult",
        "zbot",
        "matsnu",
        "cutwail",
        "bradesco",
        "outbreak",
        "qbot",
        "bankerx",
        "nimda",
        "swrort",
        "adwind",
        "trojanx",
        "squirrelwaffle",
        "pony",
        "binder",
        "ramnit",
        "virustotal",
        "zeus",
        "nymaim",
        "simda",
        "runescape",
        "dnspionage",
        "redirector",
        "killav",
        "dcrat",
        "alien",
        "astaroth",
        "filerepmalware",
        "control server",
        "asyncrat",
        "redline stealer",
        "daum",
        "name verdict"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "D26A",
          "display_name": "D26A",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "655e7e82c65d8e9106e6a227",
      "export_count": 45,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 592,
        "FileHash-SHA1": 320,
        "FileHash-SHA256": 1159,
        "URL": 1257,
        "domain": 1219,
        "hostname": 403,
        "CVE": 15
      },
      "indicator_count": 4965,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "891 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://admin.bookszap.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://admin.bookszap.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780281526.6416912
}