{
  "type": "URL",
  "indicator": "https://affiliates.ssl.com/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://affiliates.ssl.com/",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "akamai",
        "message": "Akamai rank: #6716",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain ssl.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain ssl.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 4048899682,
      "indicator": "https://affiliates.ssl.com/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "68adee67c08cd025b05c2ab0",
          "name": "Collection of Collections - Updated - Malicious Certificates & University of Alberta DataBreach - 09.15.25.25",
          "description": "This Pulse is an attempt to aggregate all known certificates from all sources.\n\nEncrypted Communication: The malware uses Bitcoin and Ethereum addresses for communication, allowing it to receive commands and exfiltrate data securely.\nEvasion Techniques: The malware generates long and unusual domain parts using Domain Generation Algorithms to evade detection and establish communication with its C2 server.\nData Exfiltration: The malware can exfiltrate data to cloud storage services, enabling the threat actor to steal sensitive information from the compromised system.\nRemote Access: The malware leverages bidirectional communication and system binary proxy execution techniques to enable remote access and control over the infected system.\nIngress Tool Transfer: The malware downloads executable files from URLs, indicating its ability to download additional malicious payloads or updates to enhance its capabilities.",
          "modified": "2025-10-16T05:02:02.452000",
          "created": "2025-08-26T17:27:01.650000",
          "tags": [
            "http",
            "https",
            "kgs0",
            "kls0",
            "Malcerts",
            "Certificates",
            "Alberta",
            "GovAB",
            "UAlberta",
            "Speader"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g0cfdc207f7d14c9a9173c2f9b804dd92b17706ef2a8c41dba3e0af36353cd70b?theme=dark",
            "https://viz.greynoise.io/ip/analysis/408b56e2-1932-4975-b348-5a8a7c5991d4",
            "https://report.netcraft.com/submission/ATkcJjvq2iKUQhELceQs7q4WVU76Q8QG - Submitted IPv4s to Netcraft 08.29.25",
            "https://www.filescan.io/uploads/68b261771c81c34281d8af6d/reports/44924eb0-000d-42ad-944e-36bf849a406d/overview",
            "https://www.virustotal.com/gui/file/19ec86ce10a716e8e63804239052c96cfa0a7fb66c2820bda2e66358f622525c/community",
            "Added some URLs from FSio Report to URLScan"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada",
            "Netherlands",
            "Aruba",
            "Panama",
            "Poland",
            "Ukraine",
            "United Kingdom of Great Britain and Northern Ireland",
            "Anguilla",
            "United Arab Emirates",
            "Ireland",
            "Tanzania, United Republic of",
            "Philippines",
            "Japan",
            "Guatemala",
            "Mexico",
            "Bahamas",
            "Barbados",
            "Georgia",
            "Slovakia",
            "Sint Maarten (Dutch part)",
            "Kenya"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education",
            "Government",
            "Technology",
            "Telecommunications",
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1639,
            "FileHash-MD5": 1481,
            "FileHash-SHA1": 1421,
            "FileHash-SHA256": 5969,
            "domain": 707,
            "hostname": 2311,
            "email": 5,
            "CIDR": 13
          },
          "indicator_count": 13546,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 133,
          "modified_text": "229 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6818573fa6fa1ba5a75ee652",
          "name": "Page not found - SSL.com",
          "description": "https://www.virustotal.com/gui/file/1747bb2eb1fca933a67c54e930563151d1127c88a352602dbd02389b17e82f5b/behavior",
          "modified": "2025-06-04T00:04:41.418000",
          "created": "2025-05-05T06:14:23.448000",
          "tags": [
            "vhash",
            "ssdeep"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 209,
            "URL": 108,
            "hostname": 14,
            "domain": 4
          },
          "indicator_count": 340,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "363 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67d9aa3446a826d09e3fcbd1",
          "name": "SSL [.] com - (Unenriched)",
          "description": "Analysis of phishing domain/service - ssl dot com\n\nUpdated 04.09.25: was able to pull IOCs from graph (vT): https://www.virustotal.com/graph/embed/ga5becca9d0964040a5408d2de66d37952e5d92e7a3694941a8d11cc8bbf1fc94?theme=dark",
          "modified": "2025-05-08T21:00:41.641000",
          "created": "2025-03-18T17:15:32.007000",
          "tags": [
            "malware",
            "virus",
            "trojan",
            "ransomware",
            "static",
            "analysis",
            "indicator of compromise",
            "ioc",
            "extraction",
            "emulation",
            "online",
            "submit",
            "sample",
            "download",
            "platform",
            "sandbox",
            "vxstream",
            "apt",
            "hybrid analysis",
            "api key",
            "vetting process",
            "please note",
            "please",
            "javascript",
            "ansi",
            "pcap processing",
            "pcap",
            "prefetch8 ansi",
            "united",
            "date",
            "threat level",
            "show process",
            "hash seen",
            "programfiles",
            "win64",
            "comspec",
            "suspicious",
            "model",
            "hybrid",
            "close",
            "click",
            "hosts",
            "service",
            "general",
            "path",
            "encrypt",
            "strings",
            "contact",
            "SSL"
          ],
          "references": [
            "https://www.filescan.io/uploads/67d9a1b50a7899f3579c2e15/reports/e94f370c-9b21-4fc7-be6d-a23f17a236a0/ioc",
            "https://hybrid-analysis.com/sample/225749540c7c585ae4567062cfb85980f0966cc3386540b5259471b8e2e5315e",
            "https://www.virustotal.com/gui/domain/ssl.com/details",
            "https://hybrid-analysis.com/sample/225749540c7c585ae4567062cfb85980f0966cc3386540b5259471b8e2e5315e/67d9a21c369b542db10921d1",
            "https://www.virustotal.com/graph/embed/ga5becca9d0964040a5408d2de66d37952e5d92e7a3694941a8d11cc8bbf1fc94?theme=dark",
            "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c",
            "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c/iocs",
            "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c/summary",
            "https://metadefender.com/results/url/aHR0cDovL3NzbC5jb20=",
            "https://pastebin.com/yYxyUWra - 03.18.25 = Paste to CERT Related Pulses/References",
            "https://www.virustotal.com/graph/embed/ga5becca9d0964040a5408d2de66d37952e5d92e7a3694941a8d11cc8bbf1fc94?theme=dark - 04.09.25"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            }
          ],
          "industries": [
            "Technology",
            "Education",
            "Government",
            "Telecommunications",
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 39,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 218,
            "FileHash-MD5": 80,
            "FileHash-SHA1": 80,
            "FileHash-SHA256": 462,
            "domain": 31,
            "hostname": 225,
            "SSLCertFingerprint": 15,
            "email": 10
          },
          "indicator_count": 1121,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "389 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/ga5becca9d0964040a5408d2de66d37952e5d92e7a3694941a8d11cc8bbf1fc94?theme=dark",
        "https://pastebin.com/yYxyUWra - 03.18.25 = Paste to CERT Related Pulses/References",
        "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c",
        "https://www.virustotal.com/graph/embed/ga5becca9d0964040a5408d2de66d37952e5d92e7a3694941a8d11cc8bbf1fc94?theme=dark - 04.09.25",
        "https://hybrid-analysis.com/sample/225749540c7c585ae4567062cfb85980f0966cc3386540b5259471b8e2e5315e",
        "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c/summary",
        "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c/iocs",
        "https://report.netcraft.com/submission/ATkcJjvq2iKUQhELceQs7q4WVU76Q8QG - Submitted IPv4s to Netcraft 08.29.25",
        "https://www.filescan.io/uploads/68b261771c81c34281d8af6d/reports/44924eb0-000d-42ad-944e-36bf849a406d/overview",
        "https://metadefender.com/results/url/aHR0cDovL3NzbC5jb20=",
        "https://www.virustotal.com/graph/embed/g0cfdc207f7d14c9a9173c2f9b804dd92b17706ef2a8c41dba3e0af36353cd70b?theme=dark",
        "https://www.virustotal.com/gui/domain/ssl.com/details",
        "https://www.virustotal.com/gui/file/19ec86ce10a716e8e63804239052c96cfa0a7fb66c2820bda2e66358f622525c/community",
        "https://hybrid-analysis.com/sample/225749540c7c585ae4567062cfb85980f0966cc3386540b5259471b8e2e5315e/67d9a21c369b542db10921d1",
        "Added some URLs from FSio Report to URLScan",
        "https://www.filescan.io/uploads/67d9a1b50a7899f3579c2e15/reports/e94f370c-9b21-4fc7-be6d-a23f17a236a0/ioc",
        "https://viz.greynoise.io/ip/analysis/408b56e2-1932-4975-b348-5a8a7c5991d4"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Technology",
            "Telecommunications",
            "Education",
            "Healthcare",
            "Government"
          ],
          "unique_indicators": 6585
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/ssl.com",
    "whois": "http://whois.domaintools.com/ssl.com",
    "domain": "ssl.com",
    "hostname": "affiliates.ssl.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "68adee67c08cd025b05c2ab0",
      "name": "Collection of Collections - Updated - Malicious Certificates & University of Alberta DataBreach - 09.15.25.25",
      "description": "This Pulse is an attempt to aggregate all known certificates from all sources.\n\nEncrypted Communication: The malware uses Bitcoin and Ethereum addresses for communication, allowing it to receive commands and exfiltrate data securely.\nEvasion Techniques: The malware generates long and unusual domain parts using Domain Generation Algorithms to evade detection and establish communication with its C2 server.\nData Exfiltration: The malware can exfiltrate data to cloud storage services, enabling the threat actor to steal sensitive information from the compromised system.\nRemote Access: The malware leverages bidirectional communication and system binary proxy execution techniques to enable remote access and control over the infected system.\nIngress Tool Transfer: The malware downloads executable files from URLs, indicating its ability to download additional malicious payloads or updates to enhance its capabilities.",
      "modified": "2025-10-16T05:02:02.452000",
      "created": "2025-08-26T17:27:01.650000",
      "tags": [
        "http",
        "https",
        "kgs0",
        "kls0",
        "Malcerts",
        "Certificates",
        "Alberta",
        "GovAB",
        "UAlberta",
        "Speader"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g0cfdc207f7d14c9a9173c2f9b804dd92b17706ef2a8c41dba3e0af36353cd70b?theme=dark",
        "https://viz.greynoise.io/ip/analysis/408b56e2-1932-4975-b348-5a8a7c5991d4",
        "https://report.netcraft.com/submission/ATkcJjvq2iKUQhELceQs7q4WVU76Q8QG - Submitted IPv4s to Netcraft 08.29.25",
        "https://www.filescan.io/uploads/68b261771c81c34281d8af6d/reports/44924eb0-000d-42ad-944e-36bf849a406d/overview",
        "https://www.virustotal.com/gui/file/19ec86ce10a716e8e63804239052c96cfa0a7fb66c2820bda2e66358f622525c/community",
        "Added some URLs from FSio Report to URLScan"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada",
        "Netherlands",
        "Aruba",
        "Panama",
        "Poland",
        "Ukraine",
        "United Kingdom of Great Britain and Northern Ireland",
        "Anguilla",
        "United Arab Emirates",
        "Ireland",
        "Tanzania, United Republic of",
        "Philippines",
        "Japan",
        "Guatemala",
        "Mexico",
        "Bahamas",
        "Barbados",
        "Georgia",
        "Slovakia",
        "Sint Maarten (Dutch part)",
        "Kenya"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education",
        "Government",
        "Technology",
        "Telecommunications",
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1639,
        "FileHash-MD5": 1481,
        "FileHash-SHA1": 1421,
        "FileHash-SHA256": 5969,
        "domain": 707,
        "hostname": 2311,
        "email": 5,
        "CIDR": 13
      },
      "indicator_count": 13546,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 133,
      "modified_text": "229 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6818573fa6fa1ba5a75ee652",
      "name": "Page not found - SSL.com",
      "description": "https://www.virustotal.com/gui/file/1747bb2eb1fca933a67c54e930563151d1127c88a352602dbd02389b17e82f5b/behavior",
      "modified": "2025-06-04T00:04:41.418000",
      "created": "2025-05-05T06:14:23.448000",
      "tags": [
        "vhash",
        "ssdeep"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 209,
        "URL": 108,
        "hostname": 14,
        "domain": 4
      },
      "indicator_count": 340,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "363 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67d9aa3446a826d09e3fcbd1",
      "name": "SSL [.] com - (Unenriched)",
      "description": "Analysis of phishing domain/service - ssl dot com\n\nUpdated 04.09.25: was able to pull IOCs from graph (vT): https://www.virustotal.com/graph/embed/ga5becca9d0964040a5408d2de66d37952e5d92e7a3694941a8d11cc8bbf1fc94?theme=dark",
      "modified": "2025-05-08T21:00:41.641000",
      "created": "2025-03-18T17:15:32.007000",
      "tags": [
        "malware",
        "virus",
        "trojan",
        "ransomware",
        "static",
        "analysis",
        "indicator of compromise",
        "ioc",
        "extraction",
        "emulation",
        "online",
        "submit",
        "sample",
        "download",
        "platform",
        "sandbox",
        "vxstream",
        "apt",
        "hybrid analysis",
        "api key",
        "vetting process",
        "please note",
        "please",
        "javascript",
        "ansi",
        "pcap processing",
        "pcap",
        "prefetch8 ansi",
        "united",
        "date",
        "threat level",
        "show process",
        "hash seen",
        "programfiles",
        "win64",
        "comspec",
        "suspicious",
        "model",
        "hybrid",
        "close",
        "click",
        "hosts",
        "service",
        "general",
        "path",
        "encrypt",
        "strings",
        "contact",
        "SSL"
      ],
      "references": [
        "https://www.filescan.io/uploads/67d9a1b50a7899f3579c2e15/reports/e94f370c-9b21-4fc7-be6d-a23f17a236a0/ioc",
        "https://hybrid-analysis.com/sample/225749540c7c585ae4567062cfb85980f0966cc3386540b5259471b8e2e5315e",
        "https://www.virustotal.com/gui/domain/ssl.com/details",
        "https://hybrid-analysis.com/sample/225749540c7c585ae4567062cfb85980f0966cc3386540b5259471b8e2e5315e/67d9a21c369b542db10921d1",
        "https://www.virustotal.com/graph/embed/ga5becca9d0964040a5408d2de66d37952e5d92e7a3694941a8d11cc8bbf1fc94?theme=dark",
        "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c",
        "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c/iocs",
        "https://www.virustotal.com/gui/collection/9ba080a708abedd7a118bdc24ce5cf5d842d87a86b89b9cc2191afe0f0d4231c/summary",
        "https://metadefender.com/results/url/aHR0cDovL3NzbC5jb20=",
        "https://pastebin.com/yYxyUWra - 03.18.25 = Paste to CERT Related Pulses/References",
        "https://www.virustotal.com/graph/embed/ga5becca9d0964040a5408d2de66d37952e5d92e7a3694941a8d11cc8bbf1fc94?theme=dark - 04.09.25"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        }
      ],
      "industries": [
        "Technology",
        "Education",
        "Government",
        "Telecommunications",
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 39,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 218,
        "FileHash-MD5": 80,
        "FileHash-SHA1": 80,
        "FileHash-SHA256": 462,
        "domain": 31,
        "hostname": 225,
        "SSLCertFingerprint": 15,
        "email": 10
      },
      "indicator_count": 1121,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 129,
      "modified_text": "389 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://affiliates.ssl.com/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://affiliates.ssl.com/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780396521.25582
}