{
  "type": "URL",
  "indicator": "https://api.cfp.microsoft-ppe.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://api.cfp.microsoft-ppe.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4099775435,
      "indicator": "https://api.cfp.microsoft-ppe.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "688ee92e23c9420f037dbfa9",
          "name": "Alberta Labour Relations Board - Union matters for employees, employers and employer organizations.",
          "description": "https://www.virustotal.com/gui/url/a910547247948980368531c301b6f25a529bc6f94ef4daa4180a05604adb33cc/details",
          "modified": "2025-10-01T00:01:22.860000",
          "created": "2025-08-03T04:44:30.433000",
          "tags": [
            "ssdeep",
            "sha256",
            "vhash",
            "anchor hrefs"
          ],
          "references": [
            "http://aemadev.gov.ab.ca",
            "https://crt.sh/?q=alberta.ca"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 254,
            "URL": 582,
            "FileHash-MD5": 24,
            "FileHash-SHA1": 25,
            "FileHash-SHA256": 349,
            "domain": 45
          },
          "indicator_count": 1279,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "200 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "689d14258dd07e26a3bb1d46",
          "name": "PalantirFoundry.com (?) Multiple Remote Controlled Devices",
          "description": "Hacking.\nI\u2019m not sure if this is masquerading or not yet. Anything with \u2018PalantirFoundry.com\u2019 redirects to actual Palanrir login. Multiple users. Potentially 5000+ devices included in pulse. All monitored targets.",
          "modified": "2025-09-12T22:00:43.252000",
          "created": "2025-08-13T22:39:33.511000",
          "tags": [
            "passive dns",
            "urls",
            "files",
            "ip address",
            "asn as16509",
            "less whois",
            "registrar",
            "unknown related",
            "servers",
            "status",
            "hostname",
            "domain",
            "files ip",
            "address",
            "united",
            "unknown ns",
            "a domains",
            "search",
            "script urls",
            "authority",
            "record value",
            "service",
            "mirai",
            "cloud provider",
            "reverse dns",
            "sydney",
            "australia asn",
            "as16509",
            "dns resolutions",
            "related tags",
            "none indicator",
            "write c",
            "mozilla",
            "nsisinetc",
            "show",
            "medium",
            "entries",
            "high",
            "http",
            "delete",
            "write",
            "malware",
            "data upload",
            "ms windows",
            "intel",
            "pe32",
            "lowfi",
            "next",
            "showing",
            "present feb",
            "present jun",
            "present dec",
            "present aug",
            "present may",
            "present jul",
            "moved",
            "media",
            "segoe ui",
            "ipv4",
            "url analysis",
            "location united",
            "error",
            "regopenkeyexa",
            "regsetvalueexa",
            "read c",
            "port",
            "destination",
            "regdword",
            "windows nt",
            "hostile",
            "win32",
            "unknown",
            "delphi",
            "persistence",
            "execution",
            "extraction",
            "l data",
            "learn",
            "command",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "spawns",
            "defense evasion",
            "t1480 execution",
            "file defense",
            "sha1",
            "sha256",
            "ascii text",
            "mitre att",
            "pattern match",
            "show technique",
            "null",
            "refresh",
            "body",
            "span",
            "august",
            "hybrid",
            "general",
            "local",
            "path",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "type",
            "please",
            "pulse submit",
            "url add",
            "pulse pulses",
            "related nids",
            "files location",
            "flag united",
            "ddos",
            "next associated",
            "files show",
            "date hash",
            "avast avg",
            "virtool",
            "downloader",
            "dadobra",
            "date",
            "certificate",
            "montreal",
            "canada",
            "asn16509",
            "amazon02",
            "screenshot",
            "title login",
            "palantir",
            "page url",
            "history https",
            "evasion att",
            "remember",
            "label",
            "button",
            "form",
            "general full",
            "url https",
            "protocol h2",
            "security tls",
            "software envoy",
            "value",
            "domainpath name",
            "header value",
            "self",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "returnur",
            "south korea",
            "as9318 sk",
            "sqlite rollback",
            "journal",
            "as701 verizon",
            "bittorrent dht",
            "win64",
            "copy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "#LowFi:LinkularNSIS",
              "display_name": "#LowFi:LinkularNSIS",
              "target": null
            },
            {
              "id": "#Lowfi:HSTR:Win32/ObfuscatorDynMemJmpAPI",
              "display_name": "#Lowfi:HSTR:Win32/ObfuscatorDynMemJmpAPI",
              "target": null
            },
            {
              "id": "Fareit",
              "display_name": "Fareit",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Dadobra.E",
              "display_name": "TrojanDownloader:Win32/Dadobra.E",
              "target": "/malware/TrojanDownloader:Win32/Dadobra.E"
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1023",
              "name": "Shortcut Modification",
              "display_name": "T1023 - Shortcut Modification"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 31,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 3149,
            "domain": 1304,
            "URL": 5269,
            "FileHash-SHA256": 968,
            "FileHash-SHA1": 206,
            "email": 7,
            "FileHash-MD5": 274,
            "SSLCertFingerprint": 1,
            "CVE": 1
          },
          "indicator_count": 11179,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 139,
          "modified_text": "218 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "687f33a5ddf830e2f3e5acac",
          "name": "Trojan Dropper | Espionage | Keylogger affecting medical centers",
          "description": "PII and PHI at risk. Highest access spyware available infiltrates a small niche medical center. \ntrojandropper, keyloggers, advanced spyware, monitored rooms , mitre att, ||\nIDS: PROTOCOL-ICMP PATH MTU denial of service attempt \u2022  PROTOCOL-ICMP Destination Unreachable Fragmentation Needed and DF bit was set\n\n\u2022   https://foundry2sdbl.dvr.dn2.n-helix.com/\n\u2022 https://www.pegasustech.net/products/mobility-barcode-scanning/Data-collector-mobile-computer\n\n\u2022 \nrobloxlogger.com\n\u2022\n\nhttps://video.welnext.com\n\u2022\nhttps://app1.oceantg.com/sta40/views/personnelscreenview.aspx",
          "modified": "2025-08-21T06:00:20.607000",
          "created": "2025-07-22T06:45:57.499000",
          "tags": [
            "pegasus",
            "report spam",
            "gotham foundry",
            "espionage",
            "spinal cord",
            "injured created",
            "minutes ago",
            "strange",
            "foundry",
            "palantir",
            "alexa",
            "service",
            "url http",
            "url https",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "ipv4",
            "united",
            "germany",
            "singapore",
            "netherlands",
            "iran",
            "india",
            "search",
            "domain",
            "hostname",
            "filehashmd5",
            "filehashsha1",
            "extraction",
            "data upload",
            "sc type",
            "dren aeu",
            "extr source",
            "ur data",
            "include",
            "review exclude",
            "sugges",
            "mtu denial",
            "matches rule",
            "needed",
            "df bit",
            "unique rule",
            "catalog tree",
            "c0002 wininet",
            "ta0005 command",
            "control ta0011",
            "get http",
            "resolved ips",
            "dns resolutions",
            "cloudflare",
            "flag",
            "server",
            "date",
            "contacted hosts",
            "ip address",
            "process details",
            "t1158",
            "hidden",
            "t1031",
            "modify existing",
            "t1053",
            "taskjob",
            "t1060",
            "run keys",
            "startup",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "spawns",
            "command",
            "found",
            "itre att",
            "show process",
            "prefetch8",
            "mitre att",
            "show technique",
            "ck matrix",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "april",
            "hybrid",
            "general",
            "path",
            "click",
            "strings",
            "entries",
            "unknown ns",
            "creation date",
            "record value",
            "showing",
            "gmt content",
            "accept encoding",
            "encrypt",
            "checked url",
            "hostname server",
            "response ip",
            "address google",
            "safe browsing",
            "present jan"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1096",
              "name": "NTFS File Attributes",
              "display_name": "T1096 - NTFS File Attributes"
            },
            {
              "id": "T1158",
              "name": "Hidden Files and Directories",
              "display_name": "T1158 - Hidden Files and Directories"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2628,
            "domain": 472,
            "hostname": 880,
            "FileHash-SHA256": 805,
            "FileHash-MD5": 151,
            "FileHash-SHA1": 128,
            "CIDR": 1,
            "SSLCertFingerprint": 3,
            "email": 1
          },
          "indicator_count": 5069,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "241 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://crt.sh/?q=alberta.ca",
        "http://aemadev.gov.ab.ca"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Fareit",
            "#lowfi:linkularnsis",
            "#lowfi:hstr:win32/obfuscatordynmemjmpapi",
            "Trojandownloader:win32/dadobra.e"
          ],
          "industries": [],
          "unique_indicators": 30705
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/microsoft-ppe.com",
    "whois": "http://whois.domaintools.com/microsoft-ppe.com",
    "domain": "microsoft-ppe.com",
    "hostname": "api.cfp.microsoft-ppe.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "688ee92e23c9420f037dbfa9",
      "name": "Alberta Labour Relations Board - Union matters for employees, employers and employer organizations.",
      "description": "https://www.virustotal.com/gui/url/a910547247948980368531c301b6f25a529bc6f94ef4daa4180a05604adb33cc/details",
      "modified": "2025-10-01T00:01:22.860000",
      "created": "2025-08-03T04:44:30.433000",
      "tags": [
        "ssdeep",
        "sha256",
        "vhash",
        "anchor hrefs"
      ],
      "references": [
        "http://aemadev.gov.ab.ca",
        "https://crt.sh/?q=alberta.ca"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 254,
        "URL": 582,
        "FileHash-MD5": 24,
        "FileHash-SHA1": 25,
        "FileHash-SHA256": 349,
        "domain": 45
      },
      "indicator_count": 1279,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "200 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "689d14258dd07e26a3bb1d46",
      "name": "PalantirFoundry.com (?) Multiple Remote Controlled Devices",
      "description": "Hacking.\nI\u2019m not sure if this is masquerading or not yet. Anything with \u2018PalantirFoundry.com\u2019 redirects to actual Palanrir login. Multiple users. Potentially 5000+ devices included in pulse. All monitored targets.",
      "modified": "2025-09-12T22:00:43.252000",
      "created": "2025-08-13T22:39:33.511000",
      "tags": [
        "passive dns",
        "urls",
        "files",
        "ip address",
        "asn as16509",
        "less whois",
        "registrar",
        "unknown related",
        "servers",
        "status",
        "hostname",
        "domain",
        "files ip",
        "address",
        "united",
        "unknown ns",
        "a domains",
        "search",
        "script urls",
        "authority",
        "record value",
        "service",
        "mirai",
        "cloud provider",
        "reverse dns",
        "sydney",
        "australia asn",
        "as16509",
        "dns resolutions",
        "related tags",
        "none indicator",
        "write c",
        "mozilla",
        "nsisinetc",
        "show",
        "medium",
        "entries",
        "high",
        "http",
        "delete",
        "write",
        "malware",
        "data upload",
        "ms windows",
        "intel",
        "pe32",
        "lowfi",
        "next",
        "showing",
        "present feb",
        "present jun",
        "present dec",
        "present aug",
        "present may",
        "present jul",
        "moved",
        "media",
        "segoe ui",
        "ipv4",
        "url analysis",
        "location united",
        "error",
        "regopenkeyexa",
        "regsetvalueexa",
        "read c",
        "port",
        "destination",
        "regdword",
        "windows nt",
        "hostile",
        "win32",
        "unknown",
        "delphi",
        "persistence",
        "execution",
        "extraction",
        "l data",
        "learn",
        "command",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "spawns",
        "defense evasion",
        "t1480 execution",
        "file defense",
        "sha1",
        "sha256",
        "ascii text",
        "mitre att",
        "pattern match",
        "show technique",
        "null",
        "refresh",
        "body",
        "span",
        "august",
        "hybrid",
        "general",
        "local",
        "path",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "type",
        "please",
        "pulse submit",
        "url add",
        "pulse pulses",
        "related nids",
        "files location",
        "flag united",
        "ddos",
        "next associated",
        "files show",
        "date hash",
        "avast avg",
        "virtool",
        "downloader",
        "dadobra",
        "date",
        "certificate",
        "montreal",
        "canada",
        "asn16509",
        "amazon02",
        "screenshot",
        "title login",
        "palantir",
        "page url",
        "history https",
        "evasion att",
        "remember",
        "label",
        "button",
        "form",
        "general full",
        "url https",
        "protocol h2",
        "security tls",
        "software envoy",
        "value",
        "domainpath name",
        "header value",
        "self",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "returnur",
        "south korea",
        "as9318 sk",
        "sqlite rollback",
        "journal",
        "as701 verizon",
        "bittorrent dht",
        "win64",
        "copy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "#LowFi:LinkularNSIS",
          "display_name": "#LowFi:LinkularNSIS",
          "target": null
        },
        {
          "id": "#Lowfi:HSTR:Win32/ObfuscatorDynMemJmpAPI",
          "display_name": "#Lowfi:HSTR:Win32/ObfuscatorDynMemJmpAPI",
          "target": null
        },
        {
          "id": "Fareit",
          "display_name": "Fareit",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Dadobra.E",
          "display_name": "TrojanDownloader:Win32/Dadobra.E",
          "target": "/malware/TrojanDownloader:Win32/Dadobra.E"
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1023",
          "name": "Shortcut Modification",
          "display_name": "T1023 - Shortcut Modification"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 31,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 3149,
        "domain": 1304,
        "URL": 5269,
        "FileHash-SHA256": 968,
        "FileHash-SHA1": 206,
        "email": 7,
        "FileHash-MD5": 274,
        "SSLCertFingerprint": 1,
        "CVE": 1
      },
      "indicator_count": 11179,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 139,
      "modified_text": "218 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "687f33a5ddf830e2f3e5acac",
      "name": "Trojan Dropper | Espionage | Keylogger affecting medical centers",
      "description": "PII and PHI at risk. Highest access spyware available infiltrates a small niche medical center. \ntrojandropper, keyloggers, advanced spyware, monitored rooms , mitre att, ||\nIDS: PROTOCOL-ICMP PATH MTU denial of service attempt \u2022  PROTOCOL-ICMP Destination Unreachable Fragmentation Needed and DF bit was set\n\n\u2022   https://foundry2sdbl.dvr.dn2.n-helix.com/\n\u2022 https://www.pegasustech.net/products/mobility-barcode-scanning/Data-collector-mobile-computer\n\n\u2022 \nrobloxlogger.com\n\u2022\n\nhttps://video.welnext.com\n\u2022\nhttps://app1.oceantg.com/sta40/views/personnelscreenview.aspx",
      "modified": "2025-08-21T06:00:20.607000",
      "created": "2025-07-22T06:45:57.499000",
      "tags": [
        "pegasus",
        "report spam",
        "gotham foundry",
        "espionage",
        "spinal cord",
        "injured created",
        "minutes ago",
        "strange",
        "foundry",
        "palantir",
        "alexa",
        "service",
        "url http",
        "url https",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "ipv4",
        "united",
        "germany",
        "singapore",
        "netherlands",
        "iran",
        "india",
        "search",
        "domain",
        "hostname",
        "filehashmd5",
        "filehashsha1",
        "extraction",
        "data upload",
        "sc type",
        "dren aeu",
        "extr source",
        "ur data",
        "include",
        "review exclude",
        "sugges",
        "mtu denial",
        "matches rule",
        "needed",
        "df bit",
        "unique rule",
        "catalog tree",
        "c0002 wininet",
        "ta0005 command",
        "control ta0011",
        "get http",
        "resolved ips",
        "dns resolutions",
        "cloudflare",
        "flag",
        "server",
        "date",
        "contacted hosts",
        "ip address",
        "process details",
        "t1158",
        "hidden",
        "t1031",
        "modify existing",
        "t1053",
        "taskjob",
        "t1060",
        "run keys",
        "startup",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "spawns",
        "command",
        "found",
        "itre att",
        "show process",
        "prefetch8",
        "mitre att",
        "show technique",
        "ck matrix",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "april",
        "hybrid",
        "general",
        "path",
        "click",
        "strings",
        "entries",
        "unknown ns",
        "creation date",
        "record value",
        "showing",
        "gmt content",
        "accept encoding",
        "encrypt",
        "checked url",
        "hostname server",
        "response ip",
        "address google",
        "safe browsing",
        "present jan"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1096",
          "name": "NTFS File Attributes",
          "display_name": "T1096 - NTFS File Attributes"
        },
        {
          "id": "T1158",
          "name": "Hidden Files and Directories",
          "display_name": "T1158 - Hidden Files and Directories"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2628,
        "domain": 472,
        "hostname": 880,
        "FileHash-SHA256": 805,
        "FileHash-MD5": 151,
        "FileHash-SHA1": 128,
        "CIDR": 1,
        "SSLCertFingerprint": 3,
        "email": 1
      },
      "indicator_count": 5069,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "241 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://api.cfp.microsoft-ppe.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://api.cfp.microsoft-ppe.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776629944.269089
}