{
  "type": "URL",
  "indicator": "https://ar.graph.meta.com/,",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://ar.graph.meta.com/,",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4106920016,
      "indicator": "https://ar.graph.meta.com/,",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6a15ad403ba61be50e09d42e",
          "name": "research indicators tlp: amber",
          "description": "This post is not a reflection of any companies tagged.",
          "modified": "2026-05-29T09:50:48.467000",
          "created": "2026-05-26T14:25:04.421000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 53,
            "URL": 131,
            "hostname": 73,
            "domain": 21,
            "FileHash-MD5": 17,
            "FileHash-SHA1": 26,
            "IPv4": 1
          },
          "indicator_count": 322,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "1 day ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "688e31b80edd775fe5d2f34f",
          "name": "Social Engineering led to -#Lowfi:HSTR:Win32/iWin.B",
          "description": "Likely: Phone referral led to an in person meeting, financial transaction, telephone numbers exchange, website click, in home service call. The alternative is compromised target was redirected to malicious host or service provider became compromised by targeted persons issue.\nThere are several targeted people. This person is closely associated with a target.(idk -malicious)\nMitre: T1055.015\tListPlanting\t\nDefense Evasion\nPrivilege Escalation\nAdversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.",
          "modified": "2025-09-01T15:02:58.791000",
          "created": "2025-08-02T15:41:44.319000",
          "tags": [
            "united",
            "search",
            "moved",
            "ip address",
            "creation date",
            "record value",
            "date",
            "gmt server",
            "gmt content",
            "certificate",
            "apache",
            "encrypt",
            "gmt path",
            "set cookie",
            "httponly",
            "passive dns",
            "urls",
            "address",
            "meta",
            "dynamicloader",
            "write c",
            "medium",
            "tlsv1",
            "show",
            "entries",
            "high",
            "http",
            "copy",
            "upatre",
            "write",
            "unknown",
            "asn15169",
            "google",
            "asn46606",
            "unifiedlayeras1",
            "frankfurt",
            "main",
            "germany",
            "google safe",
            "browsing",
            "script urls",
            "a domains",
            "libs",
            "monstroid2",
            "link",
            "accept encoding",
            "script domains",
            "title",
            "vary",
            "jquery",
            "pulse pulses",
            "hostname xn",
            "files domain",
            "showing",
            "next associated",
            "urls show",
            "date checked",
            "url hostname",
            "server response",
            "present jul",
            "for privacy",
            "roboto",
            "delete",
            "trojan",
            "globalc",
            "mozilla",
            "guard",
            "malware",
            "iwin",
            "local",
            "lowfi",
            "helper",
            "nsisdl",
            "executable",
            "amazon s3",
            "pe exe",
            "dll windows",
            "http yara",
            "alerts",
            "meta http",
            "content",
            "pragma",
            "content type",
            "body",
            "service",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "spawns",
            "found",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "sha1",
            "sha256",
            "windows nt",
            "mitre att",
            "ascii text",
            "show technique",
            "path",
            "span",
            "click",
            "august",
            "hybrid",
            "general",
            "strings",
            "footer",
            "ck matrix"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 460,
            "hostname": 744,
            "URL": 3496,
            "email": 4,
            "domain": 394,
            "FileHash-SHA256": 2072,
            "FileHash-MD5": 464,
            "SSLCertFingerprint": 7
          },
          "indicator_count": 7641,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "271 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "688af30ab2a5242f48ba2c21",
          "name": "IoC\u2019s of Potentially \u2018falsified\u2019 LinkedIn of attempted Hitman DPD let walk",
          "description": "IoC\u2019s of Potentially \u2018falsified\u2019 LinkedIn profile of attempted Hitman DPD let walk. Name removed from pulse attempted HM. Denver Police positively identified driver , plates& vehicle positive walk. All attorneys accepted then dropped her case alleging \u2019she \u2019was too hacked?\u2019 \n\nAlleged traffic officer lets positively identified driver who intentionally tried to drive target Tsara Brashears of of the I - 25 after a PT  unexpectedly reported Jeffrey Reimer to DORA without victims knowledge or permission . Officer falsely states Brashears didn\u2019t have a drivers license. Wreck led to worsening a new SCI injury that eventually led to \u2026\n\n#corruption #denver #why #rip #dpd #stop",
          "modified": "2025-08-30T04:01:11.958000",
          "created": "2025-07-31T04:37:30.179000",
          "tags": [
            "dynamicloader",
            "entries",
            "search",
            "stun binding",
            "request",
            "port",
            "show",
            "write c",
            "medium",
            "whitelisted",
            "copy",
            "themida",
            "guard",
            "write",
            "risepro",
            "malware",
            "win64",
            "next",
            "software",
            "united",
            "for privacy",
            "unknown aaaa",
            "ip address",
            "creation date",
            "found",
            "gmt content",
            "443 ma2592000",
            "error"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 587,
            "FileHash-SHA256": 1137,
            "URL": 2279,
            "FileHash-MD5": 109,
            "FileHash-SHA1": 100,
            "domain": 291,
            "email": 1,
            "CVE": 1
          },
          "indicator_count": 4505,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "274 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "688865644a38fd5eef407891",
          "name": "Denver Apartment Community website with multiple compromises",
          "description": "Network of a multi block Denver Townhome complex experiencing issues with info stealing, password o, spyware, ransomware, malware\u2026 \u2022Win.Trojan.Crypted-30\tPWS:Win32/Zbot\u2022(phish_alert_sp2_2.0.0.0) \u2022 (phish_alert_sp1_1.0.0.0 )(30)_url_001.bin\tFile detected as \"image\", this format is not supported on WINDOWS\terror\t\nMay 23rd 2023 06:20:30 (UTC)\tRe__Motherson_INVENSITY_Project_Discussion_url_001.bin\tFile \"Re__Motherson_INVENSITY_Project_Discussion_url_001.bin\" was detected as \"image\", this format is not supported on WINDOWS\terror\t\nMay 5th 2023 07:59:14 (UTC)\tRE XDR Roadmap Planning Workshop for Temasek Polytechnic_url_007.bin\tFile \"RE XDR Roadmap Planning Workshop for Temasek Polytechnic_url_007.bin\" was detected as \"image\", this format is not supported on WINDOWS\terror",
          "modified": "2025-08-28T06:00:46.366000",
          "created": "2025-07-29T06:08:36.869000",
          "tags": [
            "context related",
            "associated urls",
            "community",
            "present jul",
            "present jun",
            "present may",
            "present apr",
            "checked url",
            "hostname server",
            "response ip",
            "address google",
            "safe browsing",
            "present showing",
            "sha256",
            "submitted",
            "urls",
            "passive dns",
            "http",
            "unique",
            "ip asn",
            "as701 verizon",
            "url add",
            "pulse pulses",
            "ip address",
            "related nids",
            "windows error",
            "file",
            "re xdr",
            "workshop",
            "march",
            "february",
            "january",
            "windows nt",
            "klpx",
            "span",
            "script",
            "united",
            "indicator",
            "appdata",
            "pattern match",
            "runtime process",
            "copy md5",
            "iframe",
            "date",
            "jquery",
            "null",
            "solid",
            "code",
            "summer",
            "polish",
            "body",
            "hybrid",
            "general",
            "local",
            "accept",
            "click",
            "strings",
            "music",
            "class",
            "core",
            "contact",
            "flag",
            "united kingdom",
            "name server",
            "tcp system",
            "private limited",
            "prefetch2",
            "dns requests",
            "win32",
            "mtb jul",
            "susp",
            "worm",
            "trojan",
            "entries",
            "next associated",
            "mtb apr",
            "showing",
            "trojandropper",
            "virtool",
            "country",
            "csc corporate",
            "domains",
            "ransom",
            "lowfi",
            "urls show",
            "date checked",
            "url hostname",
            "domain address",
            "learn",
            "command",
            "control att",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "t1105 ingress",
            "tool transfer",
            "t1573 encrypted",
            "dynamicloader",
            "medium",
            "yara rule",
            "high",
            "windows",
            "remote data",
            "http traffic",
            "installs",
            "windows startup",
            "malware",
            "copy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1134,
            "hostname": 292,
            "domain": 197,
            "FileHash-MD5": 139,
            "FileHash-SHA1": 130,
            "FileHash-SHA256": 708,
            "email": 2
          },
          "indicator_count": 2602,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "276 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68886564cdc44059c7b2ef08",
          "name": "Denver Apartment Community website with multiple compromises",
          "description": "Network of a multi block Denver Townhome complex experiencing issues with info stealing, password o, spyware, ransomware, malware\u2026 \u2022Win.Trojan.Crypted-30\tPWS:Win32/Zbot\u2022(phish_alert_sp2_2.0.0.0) \u2022 (phish_alert_sp1_1.0.0.0 )(30)_url_001.bin\tFile detected as \"image\", this format is not supported on WINDOWS\terror\t\nMay 23rd 2023 06:20:30 (UTC)\tRe__Motherson_INVENSITY_Project_Discussion_url_001.bin\tFile \"Re__Motherson_INVENSITY_Project_Discussion_url_001.bin\" was detected as \"image\", this format is not supported on WINDOWS\terror\t\nMay 5th 2023 07:59:14 (UTC)\tRE XDR Roadmap Planning Workshop for Temasek Polytechnic_url_007.bin\tFile \"RE XDR Roadmap Planning Workshop for Temasek Polytechnic_url_007.bin\" was detected as \"image\", this format is not supported on WINDOWS\terror",
          "modified": "2025-08-28T06:00:46.366000",
          "created": "2025-07-29T06:08:36.770000",
          "tags": [
            "context related",
            "associated urls",
            "community",
            "present jul",
            "present jun",
            "present may",
            "present apr",
            "checked url",
            "hostname server",
            "response ip",
            "address google",
            "safe browsing",
            "present showing",
            "sha256",
            "submitted",
            "urls",
            "passive dns",
            "http",
            "unique",
            "ip asn",
            "as701 verizon",
            "url add",
            "pulse pulses",
            "ip address",
            "related nids",
            "windows error",
            "file",
            "re xdr",
            "workshop",
            "march",
            "february",
            "january",
            "windows nt",
            "klpx",
            "span",
            "script",
            "united",
            "indicator",
            "appdata",
            "pattern match",
            "runtime process",
            "copy md5",
            "iframe",
            "date",
            "jquery",
            "null",
            "solid",
            "code",
            "summer",
            "polish",
            "body",
            "hybrid",
            "general",
            "local",
            "accept",
            "click",
            "strings",
            "music",
            "class",
            "core",
            "contact",
            "flag",
            "united kingdom",
            "name server",
            "tcp system",
            "private limited",
            "prefetch2",
            "dns requests",
            "win32",
            "mtb jul",
            "susp",
            "worm",
            "trojan",
            "entries",
            "next associated",
            "mtb apr",
            "showing",
            "trojandropper",
            "virtool",
            "country",
            "csc corporate",
            "domains",
            "ransom",
            "lowfi",
            "urls show",
            "date checked",
            "url hostname",
            "domain address",
            "learn",
            "command",
            "control att",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "t1105 ingress",
            "tool transfer",
            "t1573 encrypted",
            "dynamicloader",
            "medium",
            "yara rule",
            "high",
            "windows",
            "remote data",
            "http traffic",
            "installs",
            "windows startup",
            "malware",
            "copy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1134,
            "hostname": 292,
            "domain": 197,
            "FileHash-MD5": 139,
            "FileHash-SHA1": 130,
            "FileHash-SHA256": 708,
            "email": 2
          },
          "indicator_count": 2602,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "276 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 14736
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/meta.com",
    "whois": "http://whois.domaintools.com/meta.com",
    "domain": "meta.com",
    "hostname": "ar.graph.meta.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6a15ad403ba61be50e09d42e",
      "name": "research indicators tlp: amber",
      "description": "This post is not a reflection of any companies tagged.",
      "modified": "2026-05-29T09:50:48.467000",
      "created": "2026-05-26T14:25:04.421000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 53,
        "URL": 131,
        "hostname": 73,
        "domain": 21,
        "FileHash-MD5": 17,
        "FileHash-SHA1": 26,
        "IPv4": 1
      },
      "indicator_count": 322,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "1 day ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "688e31b80edd775fe5d2f34f",
      "name": "Social Engineering led to -#Lowfi:HSTR:Win32/iWin.B",
      "description": "Likely: Phone referral led to an in person meeting, financial transaction, telephone numbers exchange, website click, in home service call. The alternative is compromised target was redirected to malicious host or service provider became compromised by targeted persons issue.\nThere are several targeted people. This person is closely associated with a target.(idk -malicious)\nMitre: T1055.015\tListPlanting\t\nDefense Evasion\nPrivilege Escalation\nAdversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.",
      "modified": "2025-09-01T15:02:58.791000",
      "created": "2025-08-02T15:41:44.319000",
      "tags": [
        "united",
        "search",
        "moved",
        "ip address",
        "creation date",
        "record value",
        "date",
        "gmt server",
        "gmt content",
        "certificate",
        "apache",
        "encrypt",
        "gmt path",
        "set cookie",
        "httponly",
        "passive dns",
        "urls",
        "address",
        "meta",
        "dynamicloader",
        "write c",
        "medium",
        "tlsv1",
        "show",
        "entries",
        "high",
        "http",
        "copy",
        "upatre",
        "write",
        "unknown",
        "asn15169",
        "google",
        "asn46606",
        "unifiedlayeras1",
        "frankfurt",
        "main",
        "germany",
        "google safe",
        "browsing",
        "script urls",
        "a domains",
        "libs",
        "monstroid2",
        "link",
        "accept encoding",
        "script domains",
        "title",
        "vary",
        "jquery",
        "pulse pulses",
        "hostname xn",
        "files domain",
        "showing",
        "next associated",
        "urls show",
        "date checked",
        "url hostname",
        "server response",
        "present jul",
        "for privacy",
        "roboto",
        "delete",
        "trojan",
        "globalc",
        "mozilla",
        "guard",
        "malware",
        "iwin",
        "local",
        "lowfi",
        "helper",
        "nsisdl",
        "executable",
        "amazon s3",
        "pe exe",
        "dll windows",
        "http yara",
        "alerts",
        "meta http",
        "content",
        "pragma",
        "content type",
        "body",
        "service",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "spawns",
        "found",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "sha1",
        "sha256",
        "windows nt",
        "mitre att",
        "ascii text",
        "show technique",
        "path",
        "span",
        "click",
        "august",
        "hybrid",
        "general",
        "strings",
        "footer",
        "ck matrix"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 460,
        "hostname": 744,
        "URL": 3496,
        "email": 4,
        "domain": 394,
        "FileHash-SHA256": 2072,
        "FileHash-MD5": 464,
        "SSLCertFingerprint": 7
      },
      "indicator_count": 7641,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "271 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "688af30ab2a5242f48ba2c21",
      "name": "IoC\u2019s of Potentially \u2018falsified\u2019 LinkedIn of attempted Hitman DPD let walk",
      "description": "IoC\u2019s of Potentially \u2018falsified\u2019 LinkedIn profile of attempted Hitman DPD let walk. Name removed from pulse attempted HM. Denver Police positively identified driver , plates& vehicle positive walk. All attorneys accepted then dropped her case alleging \u2019she \u2019was too hacked?\u2019 \n\nAlleged traffic officer lets positively identified driver who intentionally tried to drive target Tsara Brashears of of the I - 25 after a PT  unexpectedly reported Jeffrey Reimer to DORA without victims knowledge or permission . Officer falsely states Brashears didn\u2019t have a drivers license. Wreck led to worsening a new SCI injury that eventually led to \u2026\n\n#corruption #denver #why #rip #dpd #stop",
      "modified": "2025-08-30T04:01:11.958000",
      "created": "2025-07-31T04:37:30.179000",
      "tags": [
        "dynamicloader",
        "entries",
        "search",
        "stun binding",
        "request",
        "port",
        "show",
        "write c",
        "medium",
        "whitelisted",
        "copy",
        "themida",
        "guard",
        "write",
        "risepro",
        "malware",
        "win64",
        "next",
        "software",
        "united",
        "for privacy",
        "unknown aaaa",
        "ip address",
        "creation date",
        "found",
        "gmt content",
        "443 ma2592000",
        "error"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 587,
        "FileHash-SHA256": 1137,
        "URL": 2279,
        "FileHash-MD5": 109,
        "FileHash-SHA1": 100,
        "domain": 291,
        "email": 1,
        "CVE": 1
      },
      "indicator_count": 4505,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "274 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "688865644a38fd5eef407891",
      "name": "Denver Apartment Community website with multiple compromises",
      "description": "Network of a multi block Denver Townhome complex experiencing issues with info stealing, password o, spyware, ransomware, malware\u2026 \u2022Win.Trojan.Crypted-30\tPWS:Win32/Zbot\u2022(phish_alert_sp2_2.0.0.0) \u2022 (phish_alert_sp1_1.0.0.0 )(30)_url_001.bin\tFile detected as \"image\", this format is not supported on WINDOWS\terror\t\nMay 23rd 2023 06:20:30 (UTC)\tRe__Motherson_INVENSITY_Project_Discussion_url_001.bin\tFile \"Re__Motherson_INVENSITY_Project_Discussion_url_001.bin\" was detected as \"image\", this format is not supported on WINDOWS\terror\t\nMay 5th 2023 07:59:14 (UTC)\tRE XDR Roadmap Planning Workshop for Temasek Polytechnic_url_007.bin\tFile \"RE XDR Roadmap Planning Workshop for Temasek Polytechnic_url_007.bin\" was detected as \"image\", this format is not supported on WINDOWS\terror",
      "modified": "2025-08-28T06:00:46.366000",
      "created": "2025-07-29T06:08:36.869000",
      "tags": [
        "context related",
        "associated urls",
        "community",
        "present jul",
        "present jun",
        "present may",
        "present apr",
        "checked url",
        "hostname server",
        "response ip",
        "address google",
        "safe browsing",
        "present showing",
        "sha256",
        "submitted",
        "urls",
        "passive dns",
        "http",
        "unique",
        "ip asn",
        "as701 verizon",
        "url add",
        "pulse pulses",
        "ip address",
        "related nids",
        "windows error",
        "file",
        "re xdr",
        "workshop",
        "march",
        "february",
        "january",
        "windows nt",
        "klpx",
        "span",
        "script",
        "united",
        "indicator",
        "appdata",
        "pattern match",
        "runtime process",
        "copy md5",
        "iframe",
        "date",
        "jquery",
        "null",
        "solid",
        "code",
        "summer",
        "polish",
        "body",
        "hybrid",
        "general",
        "local",
        "accept",
        "click",
        "strings",
        "music",
        "class",
        "core",
        "contact",
        "flag",
        "united kingdom",
        "name server",
        "tcp system",
        "private limited",
        "prefetch2",
        "dns requests",
        "win32",
        "mtb jul",
        "susp",
        "worm",
        "trojan",
        "entries",
        "next associated",
        "mtb apr",
        "showing",
        "trojandropper",
        "virtool",
        "country",
        "csc corporate",
        "domains",
        "ransom",
        "lowfi",
        "urls show",
        "date checked",
        "url hostname",
        "domain address",
        "learn",
        "command",
        "control att",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "t1105 ingress",
        "tool transfer",
        "t1573 encrypted",
        "dynamicloader",
        "medium",
        "yara rule",
        "high",
        "windows",
        "remote data",
        "http traffic",
        "installs",
        "windows startup",
        "malware",
        "copy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1134,
        "hostname": 292,
        "domain": 197,
        "FileHash-MD5": 139,
        "FileHash-SHA1": 130,
        "FileHash-SHA256": 708,
        "email": 2
      },
      "indicator_count": 2602,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "276 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68886564cdc44059c7b2ef08",
      "name": "Denver Apartment Community website with multiple compromises",
      "description": "Network of a multi block Denver Townhome complex experiencing issues with info stealing, password o, spyware, ransomware, malware\u2026 \u2022Win.Trojan.Crypted-30\tPWS:Win32/Zbot\u2022(phish_alert_sp2_2.0.0.0) \u2022 (phish_alert_sp1_1.0.0.0 )(30)_url_001.bin\tFile detected as \"image\", this format is not supported on WINDOWS\terror\t\nMay 23rd 2023 06:20:30 (UTC)\tRe__Motherson_INVENSITY_Project_Discussion_url_001.bin\tFile \"Re__Motherson_INVENSITY_Project_Discussion_url_001.bin\" was detected as \"image\", this format is not supported on WINDOWS\terror\t\nMay 5th 2023 07:59:14 (UTC)\tRE XDR Roadmap Planning Workshop for Temasek Polytechnic_url_007.bin\tFile \"RE XDR Roadmap Planning Workshop for Temasek Polytechnic_url_007.bin\" was detected as \"image\", this format is not supported on WINDOWS\terror",
      "modified": "2025-08-28T06:00:46.366000",
      "created": "2025-07-29T06:08:36.770000",
      "tags": [
        "context related",
        "associated urls",
        "community",
        "present jul",
        "present jun",
        "present may",
        "present apr",
        "checked url",
        "hostname server",
        "response ip",
        "address google",
        "safe browsing",
        "present showing",
        "sha256",
        "submitted",
        "urls",
        "passive dns",
        "http",
        "unique",
        "ip asn",
        "as701 verizon",
        "url add",
        "pulse pulses",
        "ip address",
        "related nids",
        "windows error",
        "file",
        "re xdr",
        "workshop",
        "march",
        "february",
        "january",
        "windows nt",
        "klpx",
        "span",
        "script",
        "united",
        "indicator",
        "appdata",
        "pattern match",
        "runtime process",
        "copy md5",
        "iframe",
        "date",
        "jquery",
        "null",
        "solid",
        "code",
        "summer",
        "polish",
        "body",
        "hybrid",
        "general",
        "local",
        "accept",
        "click",
        "strings",
        "music",
        "class",
        "core",
        "contact",
        "flag",
        "united kingdom",
        "name server",
        "tcp system",
        "private limited",
        "prefetch2",
        "dns requests",
        "win32",
        "mtb jul",
        "susp",
        "worm",
        "trojan",
        "entries",
        "next associated",
        "mtb apr",
        "showing",
        "trojandropper",
        "virtool",
        "country",
        "csc corporate",
        "domains",
        "ransom",
        "lowfi",
        "urls show",
        "date checked",
        "url hostname",
        "domain address",
        "learn",
        "command",
        "control att",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "t1105 ingress",
        "tool transfer",
        "t1573 encrypted",
        "dynamicloader",
        "medium",
        "yara rule",
        "high",
        "windows",
        "remote data",
        "http traffic",
        "installs",
        "windows startup",
        "malware",
        "copy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1134,
        "hostname": 292,
        "domain": 197,
        "FileHash-MD5": 139,
        "FileHash-SHA1": 130,
        "FileHash-SHA256": 708,
        "email": 2
      },
      "indicator_count": 2602,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "276 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://ar.graph.meta.com/,",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://ar.graph.meta.com/,",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780213084.6156545
}