{
  "type": "URL",
  "indicator": "https://api.wildwestdomains.com/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://api.wildwestdomains.com/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4019281705,
      "indicator": "https://api.wildwestdomains.com/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "69560fa62bddc3d965359168",
          "name": "Mirai H5DATACENTERS.COM \u2022 Regis University Blackout  | Extranet",
          "description": "It was Data Center 5. \nH5DATACENTERS.COM \u2022 Regis University Blackout PrometheusIntelligenceTechnology.com - Extranet.  Forced out of RU for finding malicious link that targeted , tracked ,conversations , behavior, etc.,  \u201cNo one willingly signed up to be tracked.\u201dis what Tsara told Dean Archer. He said he\u2019d never seen anything like this in his life. RU ignored the risks Tsara cautioned could irreparably damage incoming students college experience and negatively impact their future. I just hope the many students who attended do not continue to suffer. Guess who the villain was? The truth teller. \n\nToday activity has stepped up. Somehow the PIT Pulse has caused a crusade of aggressive following and investigation. \n\nThere may be 10,000 vs 1 in this battle. But the One is God.",
          "modified": "2026-01-31T03:04:09.490000",
          "created": "2026-01-01T06:09:42.057000",
          "tags": [
            "http",
            "files related",
            "related tags",
            "ipv4",
            "ccus asnas20029",
            "urls",
            "domain",
            "files ip",
            "address domain",
            "ip whois",
            "passive dns",
            "gmt path",
            "hostname add",
            "files",
            "united",
            "a li",
            "trackingpin a",
            "ip address",
            "unknown aaaa",
            "error",
            "back",
            "darkness",
            "present sep",
            "a domains",
            "script urls",
            "unknown ns",
            "script domains",
            "meta",
            "apache",
            "body doctype",
            "gmt server",
            "url analysis",
            "path",
            "accept",
            "pragma",
            "west domains",
            "present dec",
            "object",
            "com cnt",
            "dem fin",
            "gov int",
            "nav onl",
            "phy pre",
            "data upload",
            "extraction",
            "found",
            "datacenter",
            "hosting",
            "vps reverse",
            "america united",
            "america asn",
            "as398101",
            "body html",
            "head title",
            "title",
            "status",
            "name servers",
            "failed",
            "all se",
            "enter sc",
            "type",
            "extra data",
            "referen",
            "manualv add",
            "indicator data",
            "port",
            "destination",
            "south korea",
            "china as4134",
            "taiwan as3462",
            "as3786 lg",
            "as4766 korea",
            "as9318 sk",
            "high",
            "tcp syn",
            "trojan",
            "pegasus",
            "malware",
            "unknown",
            "search",
            "present jan",
            "pur sta",
            "uni idc",
            "cao oti",
            "dsp cor",
            "body",
            "win32",
            "united states",
            "pulse tags",
            "palantir",
            "ad maven",
            "technology",
            "url https",
            "url http",
            "indicator role",
            "title added",
            "active related",
            "Palantir",
            "Ad-Maven",
            "Palantir",
            "Ad- Maven",
            "Prometheus Intelligence Technology",
            "skynet",
            "starfield tech",
            "flock",
            "report spam",
            "palantir ad",
            "maven",
            "botnet",
            "created",
            "days ago",
            "education",
            "tsara",
            "mirai",
            "regis",
            "brashears",
            "discovery",
            "universities",
            "tsara brashears",
            "close",
            "stop",
            "ransom",
            "capture",
            "denver"
          ],
          "references": [
            "H5DATACENTERS.COM Name Servers: NS74.DOMAINCONTROL.COM",
            "https://prometheusintelligencetechnology.com/pit/",
            "https://prometheusintelligencetechnology.com/404javascript.js",
            "https://www.secureserver.net/default404.aspx",
            "http://ocsp.starfieldtech.com/ 443 Certificate",
            "https://www.secureserver.net/default404.aspx  Server: Microsoft-IIS/7.0",
            "Set-Cookie: market=en-US; domain=secureserver.net; expires=path=/  P3P:",
            "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
            "Powered-By: ARR/2.5  X-Powered-By: ASP.NET",
            "href= here /a . /h2 /body /html 443 Header \u2022 HTTP/1.1 302 Found  Content-Length: 161",
            "Location: policyref=\"/w3c/p3p.xml\", CP=\"COM   X-P3P: policyref=\"/w3c/p3p.xml\", CP=\"COM",
            "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
            "(Date: Tue, 13 Jun 2017 10:21:34 GMT 443 )",
            "Certificate Crldistributionpoints",
            "http://crl.starfieldtech.com/sfig2s2-0.crl 443",
            "Certificate Subjectaltname\t*.secureserver.net 443 Certificate Subjectaltname\tsecureserver.net",
            "443 Certificate Notbefore\tAug 25 16:21:59 2014 GMT 443 Certificate Caissuers",
            "Serialnumber\t27B78B2246C9C1 443 Certificate Notafter \u2022 Aug 25 16:21:59 2017 GMT 443",
            "Certificate Version 3 443 Certificate Subject\tUS 443 Certificate Subject\tArizona 443",
            "Certificate Subject Scottsdale 443 Certificate Subject\tSpecial Domain Services, LLC 443",
            "Certificate Issuer\tStarfield Technologies, Inc. 443 Certificate Issuer",
            "http://certs.starfieldtech.com/repository/ 443",
            "Certificate Issuer: Starfield Secure Certificate Authority - G2 443 Title: Object moved 443",
            "A Domains \u2022 www.secureserver.net 443 Certificate",
            "Object moved /title /head body h2 Object moved to a href= http://www.secureserver.net/default404.aspx",
            "80 Body\t here /a . /h2 /body /html 80 Header\tHTTP/1.1 302 Found  Cache-Control: private",
            "Content-Length: 160  Location: http://www.secureserver.net/default404.aspx",
            "Server: Microsoft-IIS/7.0  Set-Cookie: market=en-US; domain=secureserver.net;",
            "expires=Wed, 13-Jun-2018 10:21:35 GMT; path=/  P3P: policyref=\"/w3c/p3p.xml\",",
            "CP=\"COM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
            "X-Powered-By: ARR/2.5  X-Powered-By: ASP.NET  P3P: policyref=\"/w3c/p3p.xml\", CP=\"",
            "\u201cCOM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
            "Date: Tue, 13 Jun 2017 10:21:34 GMT",
            "Sha1 :e4ca8288d5e4912a00482418765b58a2e22fd5dc",
            "TrackingPin (Error) A Domains: trackingpin.com \u2022 Domains: forum.trackingpin.org",
            "PDNS11.DOMAINCONTROL.COM",
            "https://otx.alienvault.com/indicator/domain/secureserver.net",
            "Unix.TrojanMirai-7640640-0 IDS Detections Bad Login root login Yara Detections is__elf",
            "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication",
            "https://den.h5datacenters.com/",
            "http://prometheusintelligencetechnology.com/pitframeitem=22fsbout-regis-univer",
            "register.blackgirldroneworld.com (Is this racist)",
            "https://stetsed.xyz/apple",
            "Palantir Ad-Maven Palantir, Ad- Maven, Prometheus Intelligence Technology",
            "Review: Jeffrey Reimer DPT assaulted & egregiously injured a patient at AMS Concentra in Denver, Co",
            "It\u2019s was sexual and violent. Patient was under the oversight of Mark Montano MD and John T. Sacha MD",
            "Patient/ Victim unaware of her workers compensation rights.",
            "Do you line how they spend your tax dollars? Attacking victims? Protecting Corporations!",
            "Quasi Government, Meta, Twitter , Palantir , Gotham , Christopher P. Ahmann , Brian Sabey",
            "I haven\u2019t mentioned the hit men they hired.",
            "Fastly.com",
            "www.skynetsoftware.com",
            "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroid&ver=1.999&key=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&platform=Android&reg=&devId=92841014150fc3fd&devInfo=&devEmail=&width=480&height=764&owner=19&model=Lenovo A360t",
            "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=2.800&key=2w6i4y1r0sdz6q9gchjcpkal0oaiem4u8ncy3bct1vcr8e6x2w&platform=Android&devId=92841014150fc3fd&width=480&height=764&owner=19&model=Lenovo%20A360t",
            "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=3.700&key=53dbnf9wrz8vc0m5xfve2q1w2r4x8fv0g1b8sfg7qi0rdxck2j&platform=Android&devId=dc9c9a616665e073&width=800&height=561&owner=19&model=VirtualBox",
            "http://www.skynetsoftware.com/myPlayer/myPlayerDroid.xml"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Virus:Win32/Triusor.A",
              "display_name": "Virus:Win32/Triusor.A",
              "target": "/malware/Virus:Win32/Triusor.A"
            },
            {
              "id": "!InstallCreatorPro_2_0",
              "display_name": "!InstallCreatorPro_2_0",
              "target": null
            },
            {
              "id": "Unix.Trojan.Mirai-7640640-0",
              "display_name": "Unix.Trojan.Mirai-7640640-0",
              "target": null
            },
            {
              "id": "#LowFiEnableDTContinueAfterUnpacking",
              "display_name": "#LowFiEnableDTContinueAfterUnpacking",
              "target": null
            },
            {
              "id": "Win.Downloader",
              "display_name": "Win.Downloader",
              "target": null
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            }
          ],
          "industries": [
            "Education",
            "Civil Society"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2817,
            "domain": 487,
            "hostname": 983,
            "FileHash-SHA256": 611,
            "FileHash-MD5": 107,
            "FileHash-SHA1": 106,
            "email": 2
          },
          "indicator_count": 5113,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "78 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69434bae6aa51aea5cbe4686",
          "name": "Malicious Entertainment Licensing Scheme attacked independent artists",
          "description": "Unique entertainment scheme that seemed to have either intentionally usurped the copyrights of artists accepted for music licensing deals. It\u2019s possible  company was attacked. Is connected to a target. Several entities related to this music licensing company were attacked by Pegasus and Lazarus Group including Sony music. Christopher P.\u2019Buzz\u2019 Ahmann is related to the attacks. Unfortunately a Colorado IT company that lists individuals related to hacked studio as an employee has been cyber stalking target.  The licensing company is unavailable online. \nInteresting mafia relationships. \nOTX auto populated - AFFixmusic.com is an unregistered domain name with an address address of 166.109.7, the same address as GoDaddy.Com.co.org, which is also known as Godaddy.{",
          "modified": "2026-01-17T00:03:29.023000",
          "created": "2025-12-18T00:32:46.567000",
          "tags": [
            "united",
            "as44273 host",
            "unknown xn",
            "title style",
            "f2f2f2 color",
            "helvetica neue",
            "twitter",
            "ipv4",
            "hosting",
            "helvetica arial",
            "united states",
            "verdict",
            "files ip",
            "name servers",
            "west domains",
            "as autonomous",
            "system",
            "cloudflar",
            "cisco",
            "umbrella rank",
            "unknown",
            "present dec",
            "nxdomain",
            "object",
            "com cnt",
            "dem fin",
            "gov int",
            "nav onl",
            "phy pre",
            "pur sta",
            "godaddycomllc",
            "linux x8664",
            "khtml",
            "gecko",
            "cloudflarenet",
            "veryhigh",
            "americachicago",
            "conflict",
            "sameorigin",
            "cloudflare",
            "please",
            "text content",
            "ray id",
            "utc dns",
            "what happened",
            "thank",
            "cloudflare ray",
            "click",
            "performance",
            "general full",
            "resource",
            "name value",
            "url http",
            "server",
            "asn398787",
            "type mimetype",
            "uni idc",
            "passive dns",
            "urls",
            "hostname add",
            "url analysis",
            "files",
            "domain",
            "october",
            "divi object",
            "waypoint object",
            "reverse dns",
            "software",
            "asn26496",
            "resource hash",
            "security",
            "main",
            "google",
            "page url",
            "address as",
            "as26496",
            "screenshot page",
            "title affix",
            "music",
            "music licensing",
            "made easy",
            "history http",
            "found",
            "title",
            "extraction",
            "lte all",
            "search otx",
            "enter",
            "data upload",
            "enter source",
            "url data",
            "bad request",
            "next associated",
            "facebook url",
            "google url",
            "new releases",
            "music url",
            "kyle troop",
            "marsna design",
            "whitelisted",
            "status",
            "ip address",
            "search",
            "aaaa nxdomain",
            "present jan",
            "trojan",
            "pegasus",
            "location united",
            "as20773 host",
            "singapore",
            "asnone country",
            "netherlands",
            "germany",
            "as21499 host",
            "temple",
            "pulse submit",
            "date",
            "lte pulse",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "ssl certificate",
            "spawns",
            "flag",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "contacted hosts",
            "lte c",
            "additionally",
            "url or",
            "text type",
            "expiration",
            "url https",
            "no expiration",
            "hostname",
            "iocs",
            "pulse show",
            "type indicator",
            "text drag",
            "drop or",
            "create c",
            "read c",
            "delete",
            "write",
            "medium",
            "create",
            "show",
            "rgba",
            "next",
            "dock",
            "execution",
            "malware",
            "mitre att",
            "show technique",
            "ck matrix",
            "pattern match",
            "ascii text",
            "sha1",
            "network traffic",
            "show process",
            "hybrid",
            "general",
            "local",
            "path",
            "strings",
            "virus",
            "high",
            "dns query",
            "packing t1045",
            "pdb path",
            "pe resource",
            "win32",
            "present jun",
            "present mar",
            "a nxdomain",
            "present aug",
            "formpere",
            "msie",
            "windows nt",
            "entries",
            "defender",
            "t1071",
            "chrome",
            "creation date",
            "expiration date",
            "body",
            "t1045",
            "copy",
            "filehashsha256",
            "showing",
            "mafia",
            "lombardi mafia",
            "gambino",
            "genovese crime family",
            "crime families",
            "john t sasha",
            "jeffrey reimer",
            "navy",
            "danica implants",
            "jon",
            "bonus",
            "silva"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Netherlands",
            "France",
            "Poland",
            "Sweden",
            "Germany",
            "United Kingdom of Great Britain and Northern Ireland",
            "Belgium",
            "Japan",
            "Slovenia",
            "Spain",
            "Finland",
            "Hungary"
          ],
          "malware_families": [
            {
              "id": "Virus:Win32/Triusor.A",
              "display_name": "Virus:Win32/Triusor.A",
              "target": "/malware/Virus:Win32/Triusor.A"
            },
            {
              "id": "#LOWFI:HSTR:MSIL/Obfuscator",
              "display_name": "#LOWFI:HSTR:MSIL/Obfuscator",
              "target": null
            },
            {
              "id": "!InstallCreatorPro_2_0",
              "display_name": "!InstallCreatorPro_2_0",
              "target": null
            },
            {
              "id": "Win.Downloader.130721-1",
              "display_name": "Win.Downloader.130721-1",
              "target": null
            },
            {
              "id": "Pegasus Family",
              "display_name": "Pegasus Family",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1172,
            "hostname": 1200,
            "URL": 2438,
            "email": 6,
            "FileHash-SHA256": 610,
            "FileHash-MD5": 490,
            "FileHash-SHA1": 463,
            "CIDR": 2,
            "SSLCertFingerprint": 3
          },
          "indicator_count": 6384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 139,
          "modified_text": "92 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68a23eef53f1124e8dc273fc",
          "name": "Sign in to your account - Anorocuriv",
          "description": "Short link sent to an iPhone user possibly by accident or maybe not. Unraveled :[https://ns4.whichkill.net/]\n[https://l.us-1.a.mimecastprotect.com/l]\n[https://api-glintstage.glintinc.com/api/client/tiaa/token/saml2/consume/includeDeskLink]\n\n[https://api.glintinc.com/api/client/tiaa/token/saml2/consume/includeDeskLink]\t\n\n*api.us1.glintinc.com #malta\n*ALF:Trojan:Win32/Anorocuriv.A.#virtool #LowFI:HookwowLow \n#tracking #tiaa #locate recording #userpics #movies #audio #screen #mobile_assets #https://biccerija.gov.mt/en/contact/",
          "modified": "2025-09-16T20:00:00.565000",
          "created": "2025-08-17T20:43:27.502000",
          "tags": [
            "url http",
            "url https",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "showing",
            "entries",
            "status",
            "msie",
            "chrome",
            "passive dns",
            "urls",
            "date",
            "pulse pulses",
            "files",
            "domain",
            "files ip",
            "body",
            "http",
            "hostname",
            "files domain",
            "present jan",
            "present dec",
            "united",
            "present aug",
            "present jun",
            "unknown aaaa",
            "present mar",
            "present may",
            "present feb",
            "present jul",
            "error",
            "a domains",
            "gmt content",
            "accept encoding",
            "config nocache",
            "hostname add",
            "pulse submit",
            "content type",
            "certificate",
            "ip address",
            "cookie",
            "mita",
            "next associated",
            "please",
            "x msedge",
            "ipv4 add",
            "learn",
            "command",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "spawns",
            "defense evasion",
            "t1480 execution",
            "signing defense",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "sha1",
            "sha256",
            "size",
            "pattern match",
            "mitre att",
            "ascii text",
            "null",
            "click",
            "august",
            "hybrid",
            "general",
            "local",
            "path",
            "strings",
            "refresh",
            "tools",
            "meta",
            "onload",
            "span",
            "adversaries",
            "ssl certificate",
            "logo",
            "av detection",
            "default browser",
            "guest system",
            "professional",
            "falcon sandbox",
            "response risk",
            "ck techniques",
            "detection",
            "show process",
            "prefetch8",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "post collect",
            "microsoft edge",
            "nota",
            "brand",
            "class",
            "facebook",
            "ascii",
            "hex dump",
            "extraction",
            "failed",
            "data upload",
            "pul data",
            "enter",
            "s data",
            "type",
            "extr error",
            "href",
            "mask",
            "extra",
            "uta support",
            "include review",
            "exclude sugges",
            "find",
            "wow64",
            "show",
            "observed dns",
            "query",
            "unknown",
            "virtool",
            "copy",
            "write",
            "defender",
            "expiro",
            "malware",
            "next",
            "lowfi",
            "hookwowlow dec",
            "mtb jan",
            "mtb nov",
            "hookwowlow nov",
            "trojan",
            "trojandropper",
            "http request",
            "delete",
            "yara detections",
            "pe exe",
            "dll windows",
            "minimal http",
            "february",
            "guard",
            "alerts",
            "analysis date",
            "file score",
            "detections alf",
            "detections http",
            "http executable",
            "retrieved",
            "location united",
            "america flag",
            "america asn",
            "urls show",
            "date checked",
            "url hostname",
            "server response"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 853,
            "hostname": 1835,
            "URL": 7127,
            "email": 3,
            "FileHash-SHA256": 1470,
            "FileHash-MD5": 293,
            "FileHash-SHA1": 284,
            "SSLCertFingerprint": 426,
            "CVE": 1
          },
          "indicator_count": 12292,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 139,
          "modified_text": "215 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6773128b197198508ca38129",
          "name": "norton extra",
          "description": "",
          "modified": "2025-05-28T16:34:24.019000",
          "created": "2024-12-30T21:37:15.935000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 3079,
            "hostname": 5287,
            "URL": 17154,
            "FileHash-SHA256": 763
          },
          "indicator_count": 26283,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "326 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://prometheusintelligencetechnology.com/pit/",
        "Certificate Subject Scottsdale 443 Certificate Subject\tSpecial Domain Services, LLC 443",
        "It\u2019s was sexual and violent. Patient was under the oversight of Mark Montano MD and John T. Sacha MD",
        "Fastly.com",
        "http://ocsp.starfieldtech.com/ 443 Certificate",
        "Unix.TrojanMirai-7640640-0 IDS Detections Bad Login root login Yara Detections is__elf",
        "http://prometheusintelligencetechnology.com/pitframeitem=22fsbout-regis-univer",
        "443 Certificate Notbefore\tAug 25 16:21:59 2014 GMT 443 Certificate Caissuers",
        "Palantir Ad-Maven Palantir, Ad- Maven, Prometheus Intelligence Technology",
        "H5DATACENTERS.COM Name Servers: NS74.DOMAINCONTROL.COM",
        "80 Body\t here /a . /h2 /body /html 80 Header\tHTTP/1.1 302 Found  Cache-Control: private",
        "X-Powered-By: ARR/2.5  X-Powered-By: ASP.NET  P3P: policyref=\"/w3c/p3p.xml\", CP=\"",
        "CP=\"COM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
        "Sha1 :e4ca8288d5e4912a00482418765b58a2e22fd5dc",
        "Powered-By: ARR/2.5  X-Powered-By: ASP.NET",
        "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
        "PDNS11.DOMAINCONTROL.COM",
        "A Domains \u2022 www.secureserver.net 443 Certificate",
        "href= here /a . /h2 /body /html 443 Header \u2022 HTTP/1.1 302 Found  Content-Length: 161",
        "Patient/ Victim unaware of her workers compensation rights.",
        "Quasi Government, Meta, Twitter , Palantir , Gotham , Christopher P. Ahmann , Brian Sabey",
        "Date: Tue, 13 Jun 2017 10:21:34 GMT",
        "Set-Cookie: market=en-US; domain=secureserver.net; expires=path=/  P3P:",
        "Serialnumber\t27B78B2246C9C1 443 Certificate Notafter \u2022 Aug 25 16:21:59 2017 GMT 443",
        "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication",
        "http://www.skynetsoftware.com/myPlayer/myPlayerDroid.xml",
        "expires=Wed, 13-Jun-2018 10:21:35 GMT; path=/  P3P: policyref=\"/w3c/p3p.xml\",",
        "Content-Length: 160  Location: http://www.secureserver.net/default404.aspx",
        "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=2.800&key=2w6i4y1r0sdz6q9gchjcpkal0oaiem4u8ncy3bct1vcr8e6x2w&platform=Android&devId=92841014150fc3fd&width=480&height=764&owner=19&model=Lenovo%20A360t",
        "Do you line how they spend your tax dollars? Attacking victims? Protecting Corporations!",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=3.700&key=53dbnf9wrz8vc0m5xfve2q1w2r4x8fv0g1b8sfg7qi0rdxck2j&platform=Android&devId=dc9c9a616665e073&width=800&height=561&owner=19&model=VirtualBox",
        "https://prometheusintelligencetechnology.com/404javascript.js",
        "\u201cCOM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
        "Review: Jeffrey Reimer DPT assaulted & egregiously injured a patient at AMS Concentra in Denver, Co",
        "Certificate Issuer: Starfield Secure Certificate Authority - G2 443 Title: Object moved 443",
        "https://otx.alienvault.com/indicator/domain/secureserver.net",
        "I haven\u2019t mentioned the hit men they hired.",
        "https://www.secureserver.net/default404.aspx",
        "Certificate Crldistributionpoints",
        "Certificate Issuer\tStarfield Technologies, Inc. 443 Certificate Issuer",
        "https://stetsed.xyz/apple",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroid&ver=1.999&key=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&platform=Android&reg=&devId=92841014150fc3fd&devInfo=&devEmail=&width=480&height=764&owner=19&model=Lenovo A360t",
        "Location: policyref=\"/w3c/p3p.xml\", CP=\"COM   X-P3P: policyref=\"/w3c/p3p.xml\", CP=\"COM",
        "TrackingPin (Error) A Domains: trackingpin.com \u2022 Domains: forum.trackingpin.org",
        "Certificate Version 3 443 Certificate Subject\tUS 443 Certificate Subject\tArizona 443",
        "http://certs.starfieldtech.com/repository/ 443",
        "Server: Microsoft-IIS/7.0  Set-Cookie: market=en-US; domain=secureserver.net;",
        "https://den.h5datacenters.com/",
        "Certificate Subjectaltname\t*.secureserver.net 443 Certificate Subjectaltname\tsecureserver.net",
        "register.blackgirldroneworld.com (Is this racist)",
        "www.skynetsoftware.com",
        "Object moved /title /head body h2 Object moved to a href= http://www.secureserver.net/default404.aspx",
        "(Date: Tue, 13 Jun 2017 10:21:34 GMT 443 )",
        "http://crl.starfieldtech.com/sfig2s2-0.crl 443",
        "https://www.secureserver.net/default404.aspx  Server: Microsoft-IIS/7.0"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "#lowfi:hstr:msil/obfuscator",
            "Virus:win32/triusor.a",
            "Mirai",
            "Win.downloader.130721-1",
            "!installcreatorpro_2_0",
            "Pegasus family",
            "#lowfienabledtcontinueafterunpacking",
            "Unix.trojan.mirai-7640640-0",
            "Win.downloader"
          ],
          "industries": [
            "Civil society",
            "Education"
          ],
          "unique_indicators": 50357
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/wildwestdomains.com",
    "whois": "http://whois.domaintools.com/wildwestdomains.com",
    "domain": "wildwestdomains.com",
    "hostname": "api.wildwestdomains.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "69560fa62bddc3d965359168",
      "name": "Mirai H5DATACENTERS.COM \u2022 Regis University Blackout  | Extranet",
      "description": "It was Data Center 5. \nH5DATACENTERS.COM \u2022 Regis University Blackout PrometheusIntelligenceTechnology.com - Extranet.  Forced out of RU for finding malicious link that targeted , tracked ,conversations , behavior, etc.,  \u201cNo one willingly signed up to be tracked.\u201dis what Tsara told Dean Archer. He said he\u2019d never seen anything like this in his life. RU ignored the risks Tsara cautioned could irreparably damage incoming students college experience and negatively impact their future. I just hope the many students who attended do not continue to suffer. Guess who the villain was? The truth teller. \n\nToday activity has stepped up. Somehow the PIT Pulse has caused a crusade of aggressive following and investigation. \n\nThere may be 10,000 vs 1 in this battle. But the One is God.",
      "modified": "2026-01-31T03:04:09.490000",
      "created": "2026-01-01T06:09:42.057000",
      "tags": [
        "http",
        "files related",
        "related tags",
        "ipv4",
        "ccus asnas20029",
        "urls",
        "domain",
        "files ip",
        "address domain",
        "ip whois",
        "passive dns",
        "gmt path",
        "hostname add",
        "files",
        "united",
        "a li",
        "trackingpin a",
        "ip address",
        "unknown aaaa",
        "error",
        "back",
        "darkness",
        "present sep",
        "a domains",
        "script urls",
        "unknown ns",
        "script domains",
        "meta",
        "apache",
        "body doctype",
        "gmt server",
        "url analysis",
        "path",
        "accept",
        "pragma",
        "west domains",
        "present dec",
        "object",
        "com cnt",
        "dem fin",
        "gov int",
        "nav onl",
        "phy pre",
        "data upload",
        "extraction",
        "found",
        "datacenter",
        "hosting",
        "vps reverse",
        "america united",
        "america asn",
        "as398101",
        "body html",
        "head title",
        "title",
        "status",
        "name servers",
        "failed",
        "all se",
        "enter sc",
        "type",
        "extra data",
        "referen",
        "manualv add",
        "indicator data",
        "port",
        "destination",
        "south korea",
        "china as4134",
        "taiwan as3462",
        "as3786 lg",
        "as4766 korea",
        "as9318 sk",
        "high",
        "tcp syn",
        "trojan",
        "pegasus",
        "malware",
        "unknown",
        "search",
        "present jan",
        "pur sta",
        "uni idc",
        "cao oti",
        "dsp cor",
        "body",
        "win32",
        "united states",
        "pulse tags",
        "palantir",
        "ad maven",
        "technology",
        "url https",
        "url http",
        "indicator role",
        "title added",
        "active related",
        "Palantir",
        "Ad-Maven",
        "Palantir",
        "Ad- Maven",
        "Prometheus Intelligence Technology",
        "skynet",
        "starfield tech",
        "flock",
        "report spam",
        "palantir ad",
        "maven",
        "botnet",
        "created",
        "days ago",
        "education",
        "tsara",
        "mirai",
        "regis",
        "brashears",
        "discovery",
        "universities",
        "tsara brashears",
        "close",
        "stop",
        "ransom",
        "capture",
        "denver"
      ],
      "references": [
        "H5DATACENTERS.COM Name Servers: NS74.DOMAINCONTROL.COM",
        "https://prometheusintelligencetechnology.com/pit/",
        "https://prometheusintelligencetechnology.com/404javascript.js",
        "https://www.secureserver.net/default404.aspx",
        "http://ocsp.starfieldtech.com/ 443 Certificate",
        "https://www.secureserver.net/default404.aspx  Server: Microsoft-IIS/7.0",
        "Set-Cookie: market=en-US; domain=secureserver.net; expires=path=/  P3P:",
        "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
        "Powered-By: ARR/2.5  X-Powered-By: ASP.NET",
        "href= here /a . /h2 /body /html 443 Header \u2022 HTTP/1.1 302 Found  Content-Length: 161",
        "Location: policyref=\"/w3c/p3p.xml\", CP=\"COM   X-P3P: policyref=\"/w3c/p3p.xml\", CP=\"COM",
        "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
        "(Date: Tue, 13 Jun 2017 10:21:34 GMT 443 )",
        "Certificate Crldistributionpoints",
        "http://crl.starfieldtech.com/sfig2s2-0.crl 443",
        "Certificate Subjectaltname\t*.secureserver.net 443 Certificate Subjectaltname\tsecureserver.net",
        "443 Certificate Notbefore\tAug 25 16:21:59 2014 GMT 443 Certificate Caissuers",
        "Serialnumber\t27B78B2246C9C1 443 Certificate Notafter \u2022 Aug 25 16:21:59 2017 GMT 443",
        "Certificate Version 3 443 Certificate Subject\tUS 443 Certificate Subject\tArizona 443",
        "Certificate Subject Scottsdale 443 Certificate Subject\tSpecial Domain Services, LLC 443",
        "Certificate Issuer\tStarfield Technologies, Inc. 443 Certificate Issuer",
        "http://certs.starfieldtech.com/repository/ 443",
        "Certificate Issuer: Starfield Secure Certificate Authority - G2 443 Title: Object moved 443",
        "A Domains \u2022 www.secureserver.net 443 Certificate",
        "Object moved /title /head body h2 Object moved to a href= http://www.secureserver.net/default404.aspx",
        "80 Body\t here /a . /h2 /body /html 80 Header\tHTTP/1.1 302 Found  Cache-Control: private",
        "Content-Length: 160  Location: http://www.secureserver.net/default404.aspx",
        "Server: Microsoft-IIS/7.0  Set-Cookie: market=en-US; domain=secureserver.net;",
        "expires=Wed, 13-Jun-2018 10:21:35 GMT; path=/  P3P: policyref=\"/w3c/p3p.xml\",",
        "CP=\"COM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
        "X-Powered-By: ARR/2.5  X-Powered-By: ASP.NET  P3P: policyref=\"/w3c/p3p.xml\", CP=\"",
        "\u201cCOM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
        "Date: Tue, 13 Jun 2017 10:21:34 GMT",
        "Sha1 :e4ca8288d5e4912a00482418765b58a2e22fd5dc",
        "TrackingPin (Error) A Domains: trackingpin.com \u2022 Domains: forum.trackingpin.org",
        "PDNS11.DOMAINCONTROL.COM",
        "https://otx.alienvault.com/indicator/domain/secureserver.net",
        "Unix.TrojanMirai-7640640-0 IDS Detections Bad Login root login Yara Detections is__elf",
        "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication",
        "https://den.h5datacenters.com/",
        "http://prometheusintelligencetechnology.com/pitframeitem=22fsbout-regis-univer",
        "register.blackgirldroneworld.com (Is this racist)",
        "https://stetsed.xyz/apple",
        "Palantir Ad-Maven Palantir, Ad- Maven, Prometheus Intelligence Technology",
        "Review: Jeffrey Reimer DPT assaulted & egregiously injured a patient at AMS Concentra in Denver, Co",
        "It\u2019s was sexual and violent. Patient was under the oversight of Mark Montano MD and John T. Sacha MD",
        "Patient/ Victim unaware of her workers compensation rights.",
        "Do you line how they spend your tax dollars? Attacking victims? Protecting Corporations!",
        "Quasi Government, Meta, Twitter , Palantir , Gotham , Christopher P. Ahmann , Brian Sabey",
        "I haven\u2019t mentioned the hit men they hired.",
        "Fastly.com",
        "www.skynetsoftware.com",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroid&ver=1.999&key=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&platform=Android&reg=&devId=92841014150fc3fd&devInfo=&devEmail=&width=480&height=764&owner=19&model=Lenovo A360t",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=2.800&key=2w6i4y1r0sdz6q9gchjcpkal0oaiem4u8ncy3bct1vcr8e6x2w&platform=Android&devId=92841014150fc3fd&width=480&height=764&owner=19&model=Lenovo%20A360t",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=3.700&key=53dbnf9wrz8vc0m5xfve2q1w2r4x8fv0g1b8sfg7qi0rdxck2j&platform=Android&devId=dc9c9a616665e073&width=800&height=561&owner=19&model=VirtualBox",
        "http://www.skynetsoftware.com/myPlayer/myPlayerDroid.xml"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Virus:Win32/Triusor.A",
          "display_name": "Virus:Win32/Triusor.A",
          "target": "/malware/Virus:Win32/Triusor.A"
        },
        {
          "id": "!InstallCreatorPro_2_0",
          "display_name": "!InstallCreatorPro_2_0",
          "target": null
        },
        {
          "id": "Unix.Trojan.Mirai-7640640-0",
          "display_name": "Unix.Trojan.Mirai-7640640-0",
          "target": null
        },
        {
          "id": "#LowFiEnableDTContinueAfterUnpacking",
          "display_name": "#LowFiEnableDTContinueAfterUnpacking",
          "target": null
        },
        {
          "id": "Win.Downloader",
          "display_name": "Win.Downloader",
          "target": null
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1203",
          "name": "Exploitation for Client Execution",
          "display_name": "T1203 - Exploitation for Client Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        }
      ],
      "industries": [
        "Education",
        "Civil Society"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2817,
        "domain": 487,
        "hostname": 983,
        "FileHash-SHA256": 611,
        "FileHash-MD5": 107,
        "FileHash-SHA1": 106,
        "email": 2
      },
      "indicator_count": 5113,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "78 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69434bae6aa51aea5cbe4686",
      "name": "Malicious Entertainment Licensing Scheme attacked independent artists",
      "description": "Unique entertainment scheme that seemed to have either intentionally usurped the copyrights of artists accepted for music licensing deals. It\u2019s possible  company was attacked. Is connected to a target. Several entities related to this music licensing company were attacked by Pegasus and Lazarus Group including Sony music. Christopher P.\u2019Buzz\u2019 Ahmann is related to the attacks. Unfortunately a Colorado IT company that lists individuals related to hacked studio as an employee has been cyber stalking target.  The licensing company is unavailable online. \nInteresting mafia relationships. \nOTX auto populated - AFFixmusic.com is an unregistered domain name with an address address of 166.109.7, the same address as GoDaddy.Com.co.org, which is also known as Godaddy.{",
      "modified": "2026-01-17T00:03:29.023000",
      "created": "2025-12-18T00:32:46.567000",
      "tags": [
        "united",
        "as44273 host",
        "unknown xn",
        "title style",
        "f2f2f2 color",
        "helvetica neue",
        "twitter",
        "ipv4",
        "hosting",
        "helvetica arial",
        "united states",
        "verdict",
        "files ip",
        "name servers",
        "west domains",
        "as autonomous",
        "system",
        "cloudflar",
        "cisco",
        "umbrella rank",
        "unknown",
        "present dec",
        "nxdomain",
        "object",
        "com cnt",
        "dem fin",
        "gov int",
        "nav onl",
        "phy pre",
        "pur sta",
        "godaddycomllc",
        "linux x8664",
        "khtml",
        "gecko",
        "cloudflarenet",
        "veryhigh",
        "americachicago",
        "conflict",
        "sameorigin",
        "cloudflare",
        "please",
        "text content",
        "ray id",
        "utc dns",
        "what happened",
        "thank",
        "cloudflare ray",
        "click",
        "performance",
        "general full",
        "resource",
        "name value",
        "url http",
        "server",
        "asn398787",
        "type mimetype",
        "uni idc",
        "passive dns",
        "urls",
        "hostname add",
        "url analysis",
        "files",
        "domain",
        "october",
        "divi object",
        "waypoint object",
        "reverse dns",
        "software",
        "asn26496",
        "resource hash",
        "security",
        "main",
        "google",
        "page url",
        "address as",
        "as26496",
        "screenshot page",
        "title affix",
        "music",
        "music licensing",
        "made easy",
        "history http",
        "found",
        "title",
        "extraction",
        "lte all",
        "search otx",
        "enter",
        "data upload",
        "enter source",
        "url data",
        "bad request",
        "next associated",
        "facebook url",
        "google url",
        "new releases",
        "music url",
        "kyle troop",
        "marsna design",
        "whitelisted",
        "status",
        "ip address",
        "search",
        "aaaa nxdomain",
        "present jan",
        "trojan",
        "pegasus",
        "location united",
        "as20773 host",
        "singapore",
        "asnone country",
        "netherlands",
        "germany",
        "as21499 host",
        "temple",
        "pulse submit",
        "date",
        "lte pulse",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "ssl certificate",
        "spawns",
        "flag",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "contacted hosts",
        "lte c",
        "additionally",
        "url or",
        "text type",
        "expiration",
        "url https",
        "no expiration",
        "hostname",
        "iocs",
        "pulse show",
        "type indicator",
        "text drag",
        "drop or",
        "create c",
        "read c",
        "delete",
        "write",
        "medium",
        "create",
        "show",
        "rgba",
        "next",
        "dock",
        "execution",
        "malware",
        "mitre att",
        "show technique",
        "ck matrix",
        "pattern match",
        "ascii text",
        "sha1",
        "network traffic",
        "show process",
        "hybrid",
        "general",
        "local",
        "path",
        "strings",
        "virus",
        "high",
        "dns query",
        "packing t1045",
        "pdb path",
        "pe resource",
        "win32",
        "present jun",
        "present mar",
        "a nxdomain",
        "present aug",
        "formpere",
        "msie",
        "windows nt",
        "entries",
        "defender",
        "t1071",
        "chrome",
        "creation date",
        "expiration date",
        "body",
        "t1045",
        "copy",
        "filehashsha256",
        "showing",
        "mafia",
        "lombardi mafia",
        "gambino",
        "genovese crime family",
        "crime families",
        "john t sasha",
        "jeffrey reimer",
        "navy",
        "danica implants",
        "jon",
        "bonus",
        "silva"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Netherlands",
        "France",
        "Poland",
        "Sweden",
        "Germany",
        "United Kingdom of Great Britain and Northern Ireland",
        "Belgium",
        "Japan",
        "Slovenia",
        "Spain",
        "Finland",
        "Hungary"
      ],
      "malware_families": [
        {
          "id": "Virus:Win32/Triusor.A",
          "display_name": "Virus:Win32/Triusor.A",
          "target": "/malware/Virus:Win32/Triusor.A"
        },
        {
          "id": "#LOWFI:HSTR:MSIL/Obfuscator",
          "display_name": "#LOWFI:HSTR:MSIL/Obfuscator",
          "target": null
        },
        {
          "id": "!InstallCreatorPro_2_0",
          "display_name": "!InstallCreatorPro_2_0",
          "target": null
        },
        {
          "id": "Win.Downloader.130721-1",
          "display_name": "Win.Downloader.130721-1",
          "target": null
        },
        {
          "id": "Pegasus Family",
          "display_name": "Pegasus Family",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1172,
        "hostname": 1200,
        "URL": 2438,
        "email": 6,
        "FileHash-SHA256": 610,
        "FileHash-MD5": 490,
        "FileHash-SHA1": 463,
        "CIDR": 2,
        "SSLCertFingerprint": 3
      },
      "indicator_count": 6384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 139,
      "modified_text": "92 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68a23eef53f1124e8dc273fc",
      "name": "Sign in to your account - Anorocuriv",
      "description": "Short link sent to an iPhone user possibly by accident or maybe not. Unraveled :[https://ns4.whichkill.net/]\n[https://l.us-1.a.mimecastprotect.com/l]\n[https://api-glintstage.glintinc.com/api/client/tiaa/token/saml2/consume/includeDeskLink]\n\n[https://api.glintinc.com/api/client/tiaa/token/saml2/consume/includeDeskLink]\t\n\n*api.us1.glintinc.com #malta\n*ALF:Trojan:Win32/Anorocuriv.A.#virtool #LowFI:HookwowLow \n#tracking #tiaa #locate recording #userpics #movies #audio #screen #mobile_assets #https://biccerija.gov.mt/en/contact/",
      "modified": "2025-09-16T20:00:00.565000",
      "created": "2025-08-17T20:43:27.502000",
      "tags": [
        "url http",
        "url https",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "showing",
        "entries",
        "status",
        "msie",
        "chrome",
        "passive dns",
        "urls",
        "date",
        "pulse pulses",
        "files",
        "domain",
        "files ip",
        "body",
        "http",
        "hostname",
        "files domain",
        "present jan",
        "present dec",
        "united",
        "present aug",
        "present jun",
        "unknown aaaa",
        "present mar",
        "present may",
        "present feb",
        "present jul",
        "error",
        "a domains",
        "gmt content",
        "accept encoding",
        "config nocache",
        "hostname add",
        "pulse submit",
        "content type",
        "certificate",
        "ip address",
        "cookie",
        "mita",
        "next associated",
        "please",
        "x msedge",
        "ipv4 add",
        "learn",
        "command",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "spawns",
        "defense evasion",
        "t1480 execution",
        "signing defense",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "sha1",
        "sha256",
        "size",
        "pattern match",
        "mitre att",
        "ascii text",
        "null",
        "click",
        "august",
        "hybrid",
        "general",
        "local",
        "path",
        "strings",
        "refresh",
        "tools",
        "meta",
        "onload",
        "span",
        "adversaries",
        "ssl certificate",
        "logo",
        "av detection",
        "default browser",
        "guest system",
        "professional",
        "falcon sandbox",
        "response risk",
        "ck techniques",
        "detection",
        "show process",
        "prefetch8",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "post collect",
        "microsoft edge",
        "nota",
        "brand",
        "class",
        "facebook",
        "ascii",
        "hex dump",
        "extraction",
        "failed",
        "data upload",
        "pul data",
        "enter",
        "s data",
        "type",
        "extr error",
        "href",
        "mask",
        "extra",
        "uta support",
        "include review",
        "exclude sugges",
        "find",
        "wow64",
        "show",
        "observed dns",
        "query",
        "unknown",
        "virtool",
        "copy",
        "write",
        "defender",
        "expiro",
        "malware",
        "next",
        "lowfi",
        "hookwowlow dec",
        "mtb jan",
        "mtb nov",
        "hookwowlow nov",
        "trojan",
        "trojandropper",
        "http request",
        "delete",
        "yara detections",
        "pe exe",
        "dll windows",
        "minimal http",
        "february",
        "guard",
        "alerts",
        "analysis date",
        "file score",
        "detections alf",
        "detections http",
        "http executable",
        "retrieved",
        "location united",
        "america flag",
        "america asn",
        "urls show",
        "date checked",
        "url hostname",
        "server response"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 853,
        "hostname": 1835,
        "URL": 7127,
        "email": 3,
        "FileHash-SHA256": 1470,
        "FileHash-MD5": 293,
        "FileHash-SHA1": 284,
        "SSLCertFingerprint": 426,
        "CVE": 1
      },
      "indicator_count": 12292,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 139,
      "modified_text": "215 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6773128b197198508ca38129",
      "name": "norton extra",
      "description": "",
      "modified": "2025-05-28T16:34:24.019000",
      "created": "2024-12-30T21:37:15.935000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 3079,
        "hostname": 5287,
        "URL": 17154,
        "FileHash-SHA256": 763
      },
      "indicator_count": 26283,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "326 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://api.wildwestdomains.com/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://api.wildwestdomains.com/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776642450.4073157
}