{
  "type": "URL",
  "indicator": "https://auth.cn-pgcloud.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://auth.cn-pgcloud.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 2987291176,
      "indicator": "https://auth.cn-pgcloud.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 12,
      "pulses": [
        {
          "id": "653a092e3e9270a3ccff2aa0",
          "name": "Apple iOS compromise. CVE Jar",
          "description": "ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable.exe\nTargets Tsara Brashears iPhone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \n\nTarget at eminent risk",
          "modified": "2024-08-28T12:01:51.699000",
          "created": "2023-10-26T06:37:34.613000",
          "tags": [
            "apple ios",
            "tsara brashears",
            "unlocker",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "apple phone",
            "shell code",
            "script",
            "spyware",
            "hacktool",
            "installer",
            "banker",
            "keylogger",
            "name verdict",
            "falcon sandbox",
            "beginstring",
            "sha256",
            "sha1",
            "runtime process",
            "segoe ui",
            "internet",
            "null",
            "size",
            "misc attack",
            "unknown",
            "error",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "generator",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "hiddentears",
            "PyInstaller",
            "ransomware",
            "verified",
            "et",
            "legal entities",
            "phishing",
            "e-devlet",
            "buff achievement tracker",
            "cyber warfare",
            "malware",
            "ransom",
            "malware spreader",
            "et malware",
            "neurevt.a.betabot check in",
            "atlassian",
            "Tulach malware",
            "shell code script",
            "TrojanSpy",
            "remote access",
            "cve",
            "collection",
            "monitoring",
            "cyber threat",
            "cyber stalking",
            "cybercrime",
            "lockbin.1",
            "python connection",
            "elf",
            "redirect",
            "watchhers",
            "tracking",
            "fed",
            "us",
            "blob",
            "vortex",
            "Amazon aes",
            "spyware",
            "banker",
            "synaptics",
            "fraud service",
            "python initiated connection",
            "Trojan_Win_Generic_101",
            "malware trojan",
            "evader",
            "contacted",
            "execution",
            "cobaltstrike",
            "hacking_tool",
            "trojan",
            "cve exploit",
            "red team tools",
            "fireeye",
            "noname057",
            "adult content",
            "pornographer",
            "attack",
            "unsafe",
            "tulach malware",
            "remote attacks",
            "Rat"
          ],
          "references": [
            "1.116.132.182/weblogic_CVE_2020_2551.jar",
            "http://1.116.132.182/.git/HEAD"
          ],
          "public": 1,
          "adversary": "[Unnamed group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "trojan.barys/cobalt",
              "display_name": "trojan.barys/cobalt",
              "target": null
            },
            {
              "id": "NoName057",
              "display_name": "NoName057",
              "target": null
            },
            {
              "id": "Network RAT",
              "display_name": "Network RAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1445",
              "name": "Abuse of iOS Enterprise App Signing Key",
              "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1493",
              "name": "Transmitted Data Manipulation",
              "display_name": "T1493 - Transmitted Data Manipulation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1110.002",
              "name": "Password Cracking",
              "display_name": "T1110.002 - Password Cracking"
            },
            {
              "id": "T1088",
              "name": "Bypass User Account Control",
              "display_name": "T1088 - Bypass User Account Control"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 40,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 92,
            "FileHash-SHA256": 984,
            "URL": 2184,
            "domain": 274,
            "hostname": 782,
            "CVE": 10
          },
          "indicator_count": 4425,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "599 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65574cb4447c8d87ad85fa75",
          "name": "Masquerading",
          "description": "",
          "modified": "2023-12-17T11:03:45.376000",
          "created": "2023-11-17T11:21:24.343000",
          "tags": [
            "no expiration",
            "filehashsha256",
            "filehashmd5",
            "iocs",
            "url http",
            "expiration",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "create new",
            "blacklist http",
            "laplasclipper",
            "malicious url",
            "cisco umbrella",
            "site",
            "alexa top",
            "blacklist",
            "safe site",
            "malware site",
            "phishing site",
            "malicious site",
            "malware",
            "china unknown",
            "united",
            "unknown",
            "as54994 quantil",
            "cname",
            "nxdomain",
            "as8068",
            "as4134 chinanet",
            "passive dns",
            "domain",
            "next",
            "filehashsha1",
            "service company",
            "servers",
            "ndicator role",
            "title added",
            "active related",
            "pulses url",
            "showing",
            "entries",
            "pulses http",
            "url https",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "report spam",
            "author avatar",
            "created",
            "hour ago",
            "trojanspy",
            "redline",
            "pulses hostname",
            "blacklist https",
            "indicator role",
            "bidid",
            "adid",
            "v4us",
            "v51845481",
            "hostname",
            "http",
            "cisco",
            "umbrella rank",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de summary",
            "frankfurt",
            "main",
            "reverse dns",
            "general full",
            "asn16509",
            "amazon02",
            "resource",
            "protocol h2",
            "security tls",
            "hash",
            "de indicators",
            "domains",
            "hashes",
            "copyright",
            "gmbh version",
            "follow",
            "value",
            "postitem",
            "variables",
            "parameters",
            "systemid object",
            "def function",
            "login",
            "get h2",
            "secrets llc",
            "agreement",
            "the site",
            "content",
            "policy",
            "this site",
            "claims",
            "florida",
            "please",
            "premium",
            "service",
            "restrict",
            "express",
            "media",
            "facebook",
            "twitter",
            "final",
            "first",
            "cloudflarenet",
            "gts ca",
            "software",
            "million",
            "hours ago",
            "chameleon",
            "heur",
            "phishing",
            "riskware",
            "agent",
            "unsafe",
            "opencandy",
            "exploit",
            "mimikatz",
            "iframe",
            "downldr",
            "presenoker",
            "artemis",
            "download",
            "beach research",
            "germany",
            "asn20940",
            "akamaiasn1",
            "threat report",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "alexa",
            "maltiverse",
            "google",
            "qtsas",
            "name value",
            "no data",
            "tag count",
            "count blacklist",
            "pbiptbmvd0k4",
            "glelexoputyh",
            "suppobox",
            "team",
            "bambernek",
            "internet storm",
            "phishtank",
            "phish",
            "trickbot",
            "telecom",
            "bank",
            "ipv4",
            "octoseek report",
            "spam https",
            "tsara brashears",
            "malvertizing",
            "tracking",
            "tagging",
            "spyder",
            "cybercrime",
            "email collection",
            "apple data collection",
            "win32 exe",
            "ms word",
            "document",
            "type name",
            "javascript",
            "network capture",
            "files",
            "detections type",
            "name",
            "ssl certificate",
            "whois whois",
            "tsara brashears",
            "whois record",
            "asn owner",
            "highly targeted",
            "kgs0",
            "kls0",
            "relacionada",
            "family",
            "lolkek",
            "emotet",
            "dark power",
            "wiper",
            "ransomware",
            "cobalt strike",
            "quasar rat",
            "ursnif",
            "remcos",
            "core",
            "redline stealer",
            "bitrat",
            "hacktool",
            "critical",
            "copy",
            "installer",
            "execution",
            "network",
            "communicating",
            "referrer",
            "parent",
            "historical ssl",
            "siblings",
            "resolutions",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "error",
            "file",
            "indicator",
            "script",
            "typeof e",
            "ascii text",
            "appdata",
            "date",
            "windir",
            "span",
            "body",
            "meta",
            "class",
            "generator",
            "info",
            "null",
            "refresh",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "form",
            "footer",
            "html",
            "union",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "threat roundup",
            "contacted",
            "june",
            "july",
            "october",
            "august"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Beach Research",
              "display_name": "Beach Research",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            }
          ],
          "industries": [
            "Health",
            "Nutritional",
            "Medical",
            "Medicine"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 103,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 400,
            "FileHash-SHA1": 240,
            "FileHash-SHA256": 6459,
            "hostname": 4845,
            "URL": 11514,
            "CVE": 15,
            "domain": 3179,
            "email": 31
          },
          "indicator_count": 26683,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "854 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65574cbe6bdbe24ecb170b24",
          "name": "Masquerading",
          "description": "",
          "modified": "2023-12-17T11:03:45.376000",
          "created": "2023-11-17T11:21:34.083000",
          "tags": [
            "no expiration",
            "filehashsha256",
            "filehashmd5",
            "iocs",
            "url http",
            "expiration",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "create new",
            "blacklist http",
            "laplasclipper",
            "malicious url",
            "cisco umbrella",
            "site",
            "alexa top",
            "blacklist",
            "safe site",
            "malware site",
            "phishing site",
            "malicious site",
            "malware",
            "china unknown",
            "united",
            "unknown",
            "as54994 quantil",
            "cname",
            "nxdomain",
            "as8068",
            "as4134 chinanet",
            "passive dns",
            "domain",
            "next",
            "filehashsha1",
            "service company",
            "servers",
            "ndicator role",
            "title added",
            "active related",
            "pulses url",
            "showing",
            "entries",
            "pulses http",
            "url https",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "report spam",
            "author avatar",
            "created",
            "hour ago",
            "trojanspy",
            "redline",
            "pulses hostname",
            "blacklist https",
            "indicator role",
            "bidid",
            "adid",
            "v4us",
            "v51845481",
            "hostname",
            "http",
            "cisco",
            "umbrella rank",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de summary",
            "frankfurt",
            "main",
            "reverse dns",
            "general full",
            "asn16509",
            "amazon02",
            "resource",
            "protocol h2",
            "security tls",
            "hash",
            "de indicators",
            "domains",
            "hashes",
            "copyright",
            "gmbh version",
            "follow",
            "value",
            "postitem",
            "variables",
            "parameters",
            "systemid object",
            "def function",
            "login",
            "get h2",
            "secrets llc",
            "agreement",
            "the site",
            "content",
            "policy",
            "this site",
            "claims",
            "florida",
            "please",
            "premium",
            "service",
            "restrict",
            "express",
            "media",
            "facebook",
            "twitter",
            "final",
            "first",
            "cloudflarenet",
            "gts ca",
            "software",
            "million",
            "hours ago",
            "chameleon",
            "heur",
            "phishing",
            "riskware",
            "agent",
            "unsafe",
            "opencandy",
            "exploit",
            "mimikatz",
            "iframe",
            "downldr",
            "presenoker",
            "artemis",
            "download",
            "beach research",
            "germany",
            "asn20940",
            "akamaiasn1",
            "threat report",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "alexa",
            "maltiverse",
            "google",
            "qtsas",
            "name value",
            "no data",
            "tag count",
            "count blacklist",
            "pbiptbmvd0k4",
            "glelexoputyh",
            "suppobox",
            "team",
            "bambernek",
            "internet storm",
            "phishtank",
            "phish",
            "trickbot",
            "telecom",
            "bank",
            "ipv4",
            "octoseek report",
            "spam https",
            "tsara brashears",
            "malvertizing",
            "tracking",
            "tagging",
            "spyder",
            "cybercrime",
            "email collection",
            "apple data collection",
            "win32 exe",
            "ms word",
            "document",
            "type name",
            "javascript",
            "network capture",
            "files",
            "detections type",
            "name",
            "ssl certificate",
            "whois whois",
            "tsara brashears",
            "whois record",
            "asn owner",
            "highly targeted",
            "kgs0",
            "kls0",
            "relacionada",
            "family",
            "lolkek",
            "emotet",
            "dark power",
            "wiper",
            "ransomware",
            "cobalt strike",
            "quasar rat",
            "ursnif",
            "remcos",
            "core",
            "redline stealer",
            "bitrat",
            "hacktool",
            "critical",
            "copy",
            "installer",
            "execution",
            "network",
            "communicating",
            "referrer",
            "parent",
            "historical ssl",
            "siblings",
            "resolutions",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "error",
            "file",
            "indicator",
            "script",
            "typeof e",
            "ascii text",
            "appdata",
            "date",
            "windir",
            "span",
            "body",
            "meta",
            "class",
            "generator",
            "info",
            "null",
            "refresh",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "form",
            "footer",
            "html",
            "union",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "threat roundup",
            "contacted",
            "june",
            "july",
            "october",
            "august"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Beach Research",
              "display_name": "Beach Research",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            }
          ],
          "industries": [
            "Health",
            "Nutritional",
            "Medical",
            "Medicine"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 102,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 400,
            "FileHash-SHA1": 240,
            "FileHash-SHA256": 6459,
            "hostname": 4845,
            "URL": 11514,
            "CVE": 15,
            "domain": 3179,
            "email": 31
          },
          "indicator_count": 26683,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "854 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65580c1516990d69644fb3d0",
          "name": "Masquerading",
          "description": "",
          "modified": "2023-12-17T11:03:45.376000",
          "created": "2023-11-18T00:57:57.372000",
          "tags": [
            "no expiration",
            "filehashsha256",
            "filehashmd5",
            "iocs",
            "url http",
            "expiration",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "create new",
            "blacklist http",
            "laplasclipper",
            "malicious url",
            "cisco umbrella",
            "site",
            "alexa top",
            "blacklist",
            "safe site",
            "malware site",
            "phishing site",
            "malicious site",
            "malware",
            "china unknown",
            "united",
            "unknown",
            "as54994 quantil",
            "cname",
            "nxdomain",
            "as8068",
            "as4134 chinanet",
            "passive dns",
            "domain",
            "next",
            "filehashsha1",
            "service company",
            "servers",
            "ndicator role",
            "title added",
            "active related",
            "pulses url",
            "showing",
            "entries",
            "pulses http",
            "url https",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "report spam",
            "author avatar",
            "created",
            "hour ago",
            "trojanspy",
            "redline",
            "pulses hostname",
            "blacklist https",
            "indicator role",
            "bidid",
            "adid",
            "v4us",
            "v51845481",
            "hostname",
            "http",
            "cisco",
            "umbrella rank",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de summary",
            "frankfurt",
            "main",
            "reverse dns",
            "general full",
            "asn16509",
            "amazon02",
            "resource",
            "protocol h2",
            "security tls",
            "hash",
            "de indicators",
            "domains",
            "hashes",
            "copyright",
            "gmbh version",
            "follow",
            "value",
            "postitem",
            "variables",
            "parameters",
            "systemid object",
            "def function",
            "login",
            "get h2",
            "secrets llc",
            "agreement",
            "the site",
            "content",
            "policy",
            "this site",
            "claims",
            "florida",
            "please",
            "premium",
            "service",
            "restrict",
            "express",
            "media",
            "facebook",
            "twitter",
            "final",
            "first",
            "cloudflarenet",
            "gts ca",
            "software",
            "million",
            "hours ago",
            "chameleon",
            "heur",
            "phishing",
            "riskware",
            "agent",
            "unsafe",
            "opencandy",
            "exploit",
            "mimikatz",
            "iframe",
            "downldr",
            "presenoker",
            "artemis",
            "download",
            "beach research",
            "germany",
            "asn20940",
            "akamaiasn1",
            "threat report",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "alexa",
            "maltiverse",
            "google",
            "qtsas",
            "name value",
            "no data",
            "tag count",
            "count blacklist",
            "pbiptbmvd0k4",
            "glelexoputyh",
            "suppobox",
            "team",
            "bambernek",
            "internet storm",
            "phishtank",
            "phish",
            "trickbot",
            "telecom",
            "bank",
            "ipv4",
            "octoseek report",
            "spam https",
            "tsara brashears",
            "malvertizing",
            "tracking",
            "tagging",
            "spyder",
            "cybercrime",
            "email collection",
            "apple data collection",
            "win32 exe",
            "ms word",
            "document",
            "type name",
            "javascript",
            "network capture",
            "files",
            "detections type",
            "name",
            "ssl certificate",
            "whois whois",
            "tsara brashears",
            "whois record",
            "asn owner",
            "highly targeted",
            "kgs0",
            "kls0",
            "relacionada",
            "family",
            "lolkek",
            "emotet",
            "dark power",
            "wiper",
            "ransomware",
            "cobalt strike",
            "quasar rat",
            "ursnif",
            "remcos",
            "core",
            "redline stealer",
            "bitrat",
            "hacktool",
            "critical",
            "copy",
            "installer",
            "execution",
            "network",
            "communicating",
            "referrer",
            "parent",
            "historical ssl",
            "siblings",
            "resolutions",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "error",
            "file",
            "indicator",
            "script",
            "typeof e",
            "ascii text",
            "appdata",
            "date",
            "windir",
            "span",
            "body",
            "meta",
            "class",
            "generator",
            "info",
            "null",
            "refresh",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "form",
            "footer",
            "html",
            "union",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "threat roundup",
            "contacted",
            "june",
            "july",
            "october",
            "august"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Beach Research",
              "display_name": "Beach Research",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            }
          ],
          "industries": [
            "Health",
            "Nutritional",
            "Medical",
            "Medicine"
          ],
          "TLP": "white",
          "cloned_from": "65574cb4447c8d87ad85fa75",
          "export_count": 100,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 400,
            "FileHash-SHA1": 240,
            "FileHash-SHA256": 6459,
            "hostname": 4845,
            "URL": 11514,
            "CVE": 15,
            "domain": 3179,
            "email": 31
          },
          "indicator_count": 26683,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "854 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65580c17e69371b34a573f72",
          "name": "Masquerading",
          "description": "",
          "modified": "2023-12-17T11:03:45.376000",
          "created": "2023-11-18T00:57:59.619000",
          "tags": [
            "no expiration",
            "filehashsha256",
            "filehashmd5",
            "iocs",
            "url http",
            "expiration",
            "scan endpoints",
            "all search",
            "otx octoseek",
            "create new",
            "blacklist http",
            "laplasclipper",
            "malicious url",
            "cisco umbrella",
            "site",
            "alexa top",
            "blacklist",
            "safe site",
            "malware site",
            "phishing site",
            "malicious site",
            "malware",
            "china unknown",
            "united",
            "unknown",
            "as54994 quantil",
            "cname",
            "nxdomain",
            "as8068",
            "as4134 chinanet",
            "passive dns",
            "domain",
            "next",
            "filehashsha1",
            "service company",
            "servers",
            "ndicator role",
            "title added",
            "active related",
            "pulses url",
            "showing",
            "entries",
            "pulses http",
            "url https",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "report spam",
            "author avatar",
            "created",
            "hour ago",
            "trojanspy",
            "redline",
            "pulses hostname",
            "blacklist https",
            "indicator role",
            "bidid",
            "adid",
            "v4us",
            "v51845481",
            "hostname",
            "http",
            "cisco",
            "umbrella rank",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de summary",
            "frankfurt",
            "main",
            "reverse dns",
            "general full",
            "asn16509",
            "amazon02",
            "resource",
            "protocol h2",
            "security tls",
            "hash",
            "de indicators",
            "domains",
            "hashes",
            "copyright",
            "gmbh version",
            "follow",
            "value",
            "postitem",
            "variables",
            "parameters",
            "systemid object",
            "def function",
            "login",
            "get h2",
            "secrets llc",
            "agreement",
            "the site",
            "content",
            "policy",
            "this site",
            "claims",
            "florida",
            "please",
            "premium",
            "service",
            "restrict",
            "express",
            "media",
            "facebook",
            "twitter",
            "final",
            "first",
            "cloudflarenet",
            "gts ca",
            "software",
            "million",
            "hours ago",
            "chameleon",
            "heur",
            "phishing",
            "riskware",
            "agent",
            "unsafe",
            "opencandy",
            "exploit",
            "mimikatz",
            "iframe",
            "downldr",
            "presenoker",
            "artemis",
            "download",
            "beach research",
            "germany",
            "asn20940",
            "akamaiasn1",
            "threat report",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "alexa",
            "maltiverse",
            "google",
            "qtsas",
            "name value",
            "no data",
            "tag count",
            "count blacklist",
            "pbiptbmvd0k4",
            "glelexoputyh",
            "suppobox",
            "team",
            "bambernek",
            "internet storm",
            "phishtank",
            "phish",
            "trickbot",
            "telecom",
            "bank",
            "ipv4",
            "octoseek report",
            "spam https",
            "tsara brashears",
            "malvertizing",
            "tracking",
            "tagging",
            "spyder",
            "cybercrime",
            "email collection",
            "apple data collection",
            "win32 exe",
            "ms word",
            "document",
            "type name",
            "javascript",
            "network capture",
            "files",
            "detections type",
            "name",
            "ssl certificate",
            "whois whois",
            "tsara brashears",
            "whois record",
            "asn owner",
            "highly targeted",
            "kgs0",
            "kls0",
            "relacionada",
            "family",
            "lolkek",
            "emotet",
            "dark power",
            "wiper",
            "ransomware",
            "cobalt strike",
            "quasar rat",
            "ursnif",
            "remcos",
            "core",
            "redline stealer",
            "bitrat",
            "hacktool",
            "critical",
            "copy",
            "installer",
            "execution",
            "network",
            "communicating",
            "referrer",
            "parent",
            "historical ssl",
            "siblings",
            "resolutions",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "error",
            "file",
            "indicator",
            "script",
            "typeof e",
            "ascii text",
            "appdata",
            "date",
            "windir",
            "span",
            "body",
            "meta",
            "class",
            "generator",
            "info",
            "null",
            "refresh",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "form",
            "footer",
            "html",
            "union",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "threat roundup",
            "contacted",
            "june",
            "july",
            "october",
            "august"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Beach Research",
              "display_name": "Beach Research",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            }
          ],
          "industries": [
            "Health",
            "Nutritional",
            "Medical",
            "Medicine"
          ],
          "TLP": "white",
          "cloned_from": "65574cb4447c8d87ad85fa75",
          "export_count": 103,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 400,
            "FileHash-SHA1": 240,
            "FileHash-SHA256": 6459,
            "hostname": 4845,
            "URL": 11514,
            "CVE": 15,
            "domain": 3179,
            "email": 31
          },
          "indicator_count": 26683,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "854 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f08130783a080ec06bcc6",
          "name": "Apple iOS compromise. CVE Jar",
          "description": "",
          "modified": "2023-11-25T06:03:08.846000",
          "created": "2023-10-30T01:34:11.970000",
          "tags": [
            "apple ios",
            "tsara brashears",
            "unlocker",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "apple phone",
            "shell code",
            "script",
            "spyware",
            "hacktool",
            "installer",
            "banker",
            "keylogger",
            "name verdict",
            "falcon sandbox",
            "beginstring",
            "sha256",
            "sha1",
            "runtime process",
            "segoe ui",
            "internet",
            "null",
            "size",
            "misc attack",
            "unknown",
            "error",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "generator",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "hiddentears",
            "PyInstaller",
            "ransomware",
            "verified",
            "et",
            "legal entities",
            "phishing",
            "e-devlet",
            "buff achievement tracker",
            "cyber warfare",
            "malware",
            "ransom",
            "malware spreader",
            "et malware",
            "neurevt.a.betabot check in",
            "atlassian",
            "Tulach malware",
            "shell code script",
            "TrojanSpy",
            "remote access",
            "cve",
            "collection",
            "monitoring",
            "cyber threat",
            "cyber stalking",
            "cybercrime",
            "lockbin.1",
            "python connection",
            "elf",
            "redirect",
            "watchhers",
            "tracking",
            "fed",
            "us",
            "blob",
            "vortex",
            "Amazon aes",
            "spyware",
            "banker",
            "synaptics",
            "fraud service",
            "python initiated connection",
            "Trojan_Win_Generic_101",
            "malware trojan",
            "evader",
            "contacted",
            "execution",
            "cobaltstrike",
            "hacking_tool",
            "trojan",
            "cve exploit",
            "red team tools",
            "fireeye",
            "noname057",
            "adult content",
            "pornographer",
            "attack",
            "unsafe",
            "tulach malware",
            "remote attacks",
            "Rat"
          ],
          "references": [
            "1.116.132.182/weblogic_CVE_2020_2551.jar",
            "http://1.116.132.182/.git/HEAD"
          ],
          "public": 1,
          "adversary": "[Unnamed group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "trojan.barys/cobalt",
              "display_name": "trojan.barys/cobalt",
              "target": null
            },
            {
              "id": "NoName057",
              "display_name": "NoName057",
              "target": null
            },
            {
              "id": "Network RAT",
              "display_name": "Network RAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1445",
              "name": "Abuse of iOS Enterprise App Signing Key",
              "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1493",
              "name": "Transmitted Data Manipulation",
              "display_name": "T1493 - Transmitted Data Manipulation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1110.002",
              "name": "Password Cracking",
              "display_name": "T1110.002 - Password Cracking"
            },
            {
              "id": "T1088",
              "name": "Bypass User Account Control",
              "display_name": "T1088 - Bypass User Account Control"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "653a092e3e9270a3ccff2aa0",
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 92,
            "FileHash-SHA256": 924,
            "URL": 2050,
            "domain": 244,
            "hostname": 771,
            "CVE": 10
          },
          "indicator_count": 4190,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "876 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1db16fe8c699422bfbbc",
          "name": "Apple iOS compromise. CVE Jar",
          "description": "",
          "modified": "2023-11-25T06:03:08.846000",
          "created": "2023-10-30T03:06:25.113000",
          "tags": [
            "apple ios",
            "tsara brashears",
            "unlocker",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "apple phone",
            "shell code",
            "script",
            "spyware",
            "hacktool",
            "installer",
            "banker",
            "keylogger",
            "name verdict",
            "falcon sandbox",
            "beginstring",
            "sha256",
            "sha1",
            "runtime process",
            "segoe ui",
            "internet",
            "null",
            "size",
            "misc attack",
            "unknown",
            "error",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "generator",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "hiddentears",
            "PyInstaller",
            "ransomware",
            "verified",
            "et",
            "legal entities",
            "phishing",
            "e-devlet",
            "buff achievement tracker",
            "cyber warfare",
            "malware",
            "ransom",
            "malware spreader",
            "et malware",
            "neurevt.a.betabot check in",
            "atlassian",
            "Tulach malware",
            "shell code script",
            "TrojanSpy",
            "remote access",
            "cve",
            "collection",
            "monitoring",
            "cyber threat",
            "cyber stalking",
            "cybercrime",
            "lockbin.1",
            "python connection",
            "elf",
            "redirect",
            "watchhers",
            "tracking",
            "fed",
            "us",
            "blob",
            "vortex",
            "Amazon aes",
            "spyware",
            "banker",
            "synaptics",
            "fraud service",
            "python initiated connection",
            "Trojan_Win_Generic_101",
            "malware trojan",
            "evader",
            "contacted",
            "execution",
            "cobaltstrike",
            "hacking_tool",
            "trojan",
            "cve exploit",
            "red team tools",
            "fireeye",
            "noname057",
            "adult content",
            "pornographer",
            "attack",
            "unsafe",
            "tulach malware",
            "remote attacks",
            "Rat"
          ],
          "references": [
            "1.116.132.182/weblogic_CVE_2020_2551.jar",
            "http://1.116.132.182/.git/HEAD"
          ],
          "public": 1,
          "adversary": "[Unnamed group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "trojan.barys/cobalt",
              "display_name": "trojan.barys/cobalt",
              "target": null
            },
            {
              "id": "NoName057",
              "display_name": "NoName057",
              "target": null
            },
            {
              "id": "Network RAT",
              "display_name": "Network RAT",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1445",
              "name": "Abuse of iOS Enterprise App Signing Key",
              "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1493",
              "name": "Transmitted Data Manipulation",
              "display_name": "T1493 - Transmitted Data Manipulation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1110.002",
              "name": "Password Cracking",
              "display_name": "T1110.002 - Password Cracking"
            },
            {
              "id": "T1088",
              "name": "Bypass User Account Control",
              "display_name": "T1088 - Bypass User Account Control"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "653f08130783a080ec06bcc6",
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 92,
            "FileHash-SHA256": 924,
            "URL": 2050,
            "domain": 244,
            "hostname": 771,
            "CVE": 10
          },
          "indicator_count": 4190,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "876 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653a0778872fbe01f36f9e4d",
          "name": "Apple iOS compromise. ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable exe",
          "description": "Targets phone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \nTarget: Tsara Brashears",
          "modified": "2023-11-25T05:02:44.879000",
          "created": "2023-10-26T06:30:16.812000",
          "tags": [
            "apple ios",
            "tsara brashears",
            "unlocker",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "apple phone",
            "shell code",
            "script",
            "spyware",
            "hacktool",
            "installer",
            "banker",
            "keylogger",
            "name verdict",
            "falcon sandbox",
            "beginstring",
            "sha256",
            "sha1",
            "runtime process",
            "segoe ui",
            "internet",
            "null",
            "size",
            "misc attack",
            "unknown",
            "error",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "generator",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "hiddentears",
            "PyInstaller",
            "ransomware",
            "verified",
            "et",
            "legal entities",
            "phishing",
            "e-devlet",
            "buff achievement tracker",
            "cyber warfare",
            "malware",
            "ransom",
            "malware spreader",
            "et malware",
            "neurevt.a.betabot check in",
            "atlassian",
            "Tulach malware",
            "shell code script",
            "TrojanSpy",
            "remote access",
            "cve",
            "collection",
            "monitoring",
            "cyber threat",
            "cyber stalking",
            "cybercrime",
            "lockbin.1",
            "python connection",
            "elf",
            "redirect",
            "watchhers",
            "tracking",
            "fed",
            "us",
            "blob",
            "vortex",
            "Amazon aes",
            "spyware",
            "banker",
            "synaptics",
            "fraud service",
            "python initiated connection",
            "Trojan_Win_Generic_101",
            "malware trojan",
            "evader",
            "contacted",
            "execution",
            "cobaltstrike",
            "hacking_tool",
            "trojan",
            "cve exploit",
            "red team tools",
            "fireeye"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "trojan.barys/cobalt",
              "display_name": "trojan.barys/cobalt",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1445",
              "name": "Abuse of iOS Enterprise App Signing Key",
              "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1493",
              "name": "Transmitted Data Manipulation",
              "display_name": "T1493 - Transmitted Data Manipulation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1110.002",
              "name": "Password Cracking",
              "display_name": "T1110.002 - Password Cracking"
            },
            {
              "id": "T1088",
              "name": "Bypass User Account Control",
              "display_name": "T1088 - Bypass User Account Control"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 92,
            "FileHash-SHA256": 924,
            "URL": 2007,
            "domain": 243,
            "hostname": 767
          },
          "indicator_count": 4132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "876 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653a078459913ce7eaae6fd1",
          "name": "Apple iOS compromise. ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable exe",
          "description": "Targets phone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \nTarget: Tsara Brashears",
          "modified": "2023-11-25T05:02:44.879000",
          "created": "2023-10-26T06:30:28.765000",
          "tags": [
            "apple ios",
            "tsara brashears",
            "unlocker",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "apple phone",
            "shell code",
            "script",
            "spyware",
            "hacktool",
            "installer",
            "banker",
            "keylogger",
            "name verdict",
            "falcon sandbox",
            "beginstring",
            "sha256",
            "sha1",
            "runtime process",
            "segoe ui",
            "internet",
            "null",
            "size",
            "misc attack",
            "unknown",
            "error",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "generator",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "hiddentears",
            "PyInstaller",
            "ransomware",
            "verified",
            "et",
            "legal entities",
            "phishing",
            "e-devlet",
            "buff achievement tracker",
            "cyber warfare",
            "malware",
            "ransom",
            "malware spreader",
            "et malware",
            "neurevt.a.betabot check in",
            "atlassian",
            "Tulach malware",
            "shell code script",
            "TrojanSpy",
            "remote access",
            "cve",
            "collection",
            "monitoring",
            "cyber threat",
            "cyber stalking",
            "cybercrime",
            "lockbin.1",
            "python connection",
            "elf",
            "redirect",
            "watchhers",
            "tracking",
            "fed",
            "us",
            "blob",
            "vortex",
            "Amazon aes",
            "spyware",
            "banker",
            "synaptics",
            "fraud service",
            "python initiated connection",
            "Trojan_Win_Generic_101",
            "malware trojan",
            "evader",
            "contacted",
            "execution",
            "cobaltstrike",
            "hacking_tool",
            "trojan",
            "cve exploit",
            "red team tools",
            "fireeye"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "trojan.barys/cobalt",
              "display_name": "trojan.barys/cobalt",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1445",
              "name": "Abuse of iOS Enterprise App Signing Key",
              "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1493",
              "name": "Transmitted Data Manipulation",
              "display_name": "T1493 - Transmitted Data Manipulation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1110.002",
              "name": "Password Cracking",
              "display_name": "T1110.002 - Password Cracking"
            },
            {
              "id": "T1088",
              "name": "Bypass User Account Control",
              "display_name": "T1088 - Bypass User Account Control"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 92,
            "FileHash-SHA256": 924,
            "URL": 2007,
            "domain": 243,
            "hostname": 767
          },
          "indicator_count": 4132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "876 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653a0784db4f775c260e0eb9",
          "name": "Apple iOS compromise. ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable exe",
          "description": "Targets phone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \nTarget: Tsara Brashears",
          "modified": "2023-11-25T05:02:44.879000",
          "created": "2023-10-26T06:30:28.584000",
          "tags": [
            "apple ios",
            "tsara brashears",
            "unlocker",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "apple phone",
            "shell code",
            "script",
            "spyware",
            "hacktool",
            "installer",
            "banker",
            "keylogger",
            "name verdict",
            "falcon sandbox",
            "beginstring",
            "sha256",
            "sha1",
            "runtime process",
            "segoe ui",
            "internet",
            "null",
            "size",
            "misc attack",
            "unknown",
            "error",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "generator",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "hiddentears",
            "PyInstaller",
            "ransomware",
            "verified",
            "et",
            "legal entities",
            "phishing",
            "e-devlet",
            "buff achievement tracker",
            "cyber warfare",
            "malware",
            "ransom",
            "malware spreader",
            "et malware",
            "neurevt.a.betabot check in",
            "atlassian",
            "Tulach malware",
            "shell code script",
            "TrojanSpy",
            "remote access",
            "cve",
            "collection",
            "monitoring",
            "cyber threat",
            "cyber stalking",
            "cybercrime",
            "lockbin.1",
            "python connection",
            "elf",
            "redirect",
            "watchhers",
            "tracking",
            "fed",
            "us",
            "blob",
            "vortex",
            "Amazon aes",
            "spyware",
            "banker",
            "synaptics",
            "fraud service",
            "python initiated connection",
            "Trojan_Win_Generic_101",
            "malware trojan",
            "evader",
            "contacted",
            "execution",
            "cobaltstrike",
            "hacking_tool",
            "trojan",
            "cve exploit",
            "red team tools",
            "fireeye"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "trojan.barys/cobalt",
              "display_name": "trojan.barys/cobalt",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1445",
              "name": "Abuse of iOS Enterprise App Signing Key",
              "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1493",
              "name": "Transmitted Data Manipulation",
              "display_name": "T1493 - Transmitted Data Manipulation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1110.002",
              "name": "Password Cracking",
              "display_name": "T1110.002 - Password Cracking"
            },
            {
              "id": "T1088",
              "name": "Bypass User Account Control",
              "display_name": "T1088 - Bypass User Account Control"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 92,
            "FileHash-SHA256": 924,
            "URL": 2007,
            "domain": 243,
            "hostname": 767
          },
          "indicator_count": 4132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "876 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653a07854465c840088a4c7b",
          "name": "Apple iOS compromise. ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable exe",
          "description": "Targets phone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \nTarget: Tsara Brashears",
          "modified": "2023-11-25T05:02:44.879000",
          "created": "2023-10-26T06:30:29.847000",
          "tags": [
            "apple ios",
            "tsara brashears",
            "unlocker",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "apple phone",
            "shell code",
            "script",
            "spyware",
            "hacktool",
            "installer",
            "banker",
            "keylogger",
            "name verdict",
            "falcon sandbox",
            "beginstring",
            "sha256",
            "sha1",
            "runtime process",
            "segoe ui",
            "internet",
            "null",
            "size",
            "misc attack",
            "unknown",
            "error",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "generator",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "hiddentears",
            "PyInstaller",
            "ransomware",
            "verified",
            "et",
            "legal entities",
            "phishing",
            "e-devlet",
            "buff achievement tracker",
            "cyber warfare",
            "malware",
            "ransom",
            "malware spreader",
            "et malware",
            "neurevt.a.betabot check in",
            "atlassian",
            "Tulach malware",
            "shell code script",
            "TrojanSpy",
            "remote access",
            "cve",
            "collection",
            "monitoring",
            "cyber threat",
            "cyber stalking",
            "cybercrime",
            "lockbin.1",
            "python connection",
            "elf",
            "redirect",
            "watchhers",
            "tracking",
            "fed",
            "us",
            "blob",
            "vortex",
            "Amazon aes",
            "spyware",
            "banker",
            "synaptics",
            "fraud service",
            "python initiated connection",
            "Trojan_Win_Generic_101",
            "malware trojan",
            "evader",
            "contacted",
            "execution",
            "cobaltstrike",
            "hacking_tool",
            "trojan",
            "cve exploit",
            "red team tools",
            "fireeye"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "trojan.barys/cobalt",
              "display_name": "trojan.barys/cobalt",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1445",
              "name": "Abuse of iOS Enterprise App Signing Key",
              "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1493",
              "name": "Transmitted Data Manipulation",
              "display_name": "T1493 - Transmitted Data Manipulation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1110.002",
              "name": "Password Cracking",
              "display_name": "T1110.002 - Password Cracking"
            },
            {
              "id": "T1088",
              "name": "Bypass User Account Control",
              "display_name": "T1088 - Bypass User Account Control"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 92,
            "FileHash-SHA256": 924,
            "URL": 2007,
            "domain": 243,
            "hostname": 767
          },
          "indicator_count": 4132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "876 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f08fb12f0ef5a96e7d95c",
          "name": "Apple iOS compromise. ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual ",
          "description": "",
          "modified": "2023-11-25T05:02:44.879000",
          "created": "2023-10-30T01:38:03.623000",
          "tags": [
            "apple ios",
            "tsara brashears",
            "unlocker",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "apple phone",
            "shell code",
            "script",
            "spyware",
            "hacktool",
            "installer",
            "banker",
            "keylogger",
            "name verdict",
            "falcon sandbox",
            "beginstring",
            "sha256",
            "sha1",
            "runtime process",
            "segoe ui",
            "internet",
            "null",
            "size",
            "misc attack",
            "unknown",
            "error",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "generator",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "hiddentears",
            "PyInstaller",
            "ransomware",
            "verified",
            "et",
            "legal entities",
            "phishing",
            "e-devlet",
            "buff achievement tracker",
            "cyber warfare",
            "malware",
            "ransom",
            "malware spreader",
            "et malware",
            "neurevt.a.betabot check in",
            "atlassian",
            "Tulach malware",
            "shell code script",
            "TrojanSpy",
            "remote access",
            "cve",
            "collection",
            "monitoring",
            "cyber threat",
            "cyber stalking",
            "cybercrime",
            "lockbin.1",
            "python connection",
            "elf",
            "redirect",
            "watchhers",
            "tracking",
            "fed",
            "us",
            "blob",
            "vortex",
            "Amazon aes",
            "spyware",
            "banker",
            "synaptics",
            "fraud service",
            "python initiated connection",
            "Trojan_Win_Generic_101",
            "malware trojan",
            "evader",
            "contacted",
            "execution",
            "cobaltstrike",
            "hacking_tool",
            "trojan",
            "cve exploit",
            "red team tools",
            "fireeye"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "trojan.barys/cobalt",
              "display_name": "trojan.barys/cobalt",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1445",
              "name": "Abuse of iOS Enterprise App Signing Key",
              "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1493",
              "name": "Transmitted Data Manipulation",
              "display_name": "T1493 - Transmitted Data Manipulation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "T1459",
              "name": "Device Unlock Code Guessing or Brute Force",
              "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1110.002",
              "name": "Password Cracking",
              "display_name": "T1110.002 - Password Cracking"
            },
            {
              "id": "T1088",
              "name": "Bypass User Account Control",
              "display_name": "T1088 - Bypass User Account Control"
            },
            {
              "id": "T1583.002",
              "name": "DNS Server",
              "display_name": "T1583.002 - DNS Server"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "653a07854465c840088a4c7b",
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 92,
            "FileHash-SHA256": 924,
            "URL": 2007,
            "domain": 243,
            "hostname": 767
          },
          "indicator_count": 4132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 218,
          "modified_text": "876 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "1.116.132.182/weblogic_CVE_2020_2551.jar",
        "http://1.116.132.182/.git/HEAD"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "[Unnamed group]"
          ],
          "malware_families": [
            "Noname057",
            "Emotet",
            "Trojan.barys/cobalt",
            "Maltiverse",
            "Beach research",
            "Colbalt strike",
            "Trojanspy",
            "Network rat",
            "Et",
            "Webtoolbar",
            "Verified",
            "Hiddentear"
          ],
          "industries": [
            "Medical",
            "Health",
            "Nutritional",
            "Medicine"
          ],
          "unique_indicators": 31129
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/cn-pgcloud.com",
    "whois": "http://whois.domaintools.com/cn-pgcloud.com",
    "domain": "cn-pgcloud.com",
    "hostname": "auth.cn-pgcloud.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 12,
  "pulses": [
    {
      "id": "653a092e3e9270a3ccff2aa0",
      "name": "Apple iOS compromise. CVE Jar",
      "description": "ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable.exe\nTargets Tsara Brashears iPhone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \n\nTarget at eminent risk",
      "modified": "2024-08-28T12:01:51.699000",
      "created": "2023-10-26T06:37:34.613000",
      "tags": [
        "apple ios",
        "tsara brashears",
        "unlocker",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "apple phone",
        "shell code",
        "script",
        "spyware",
        "hacktool",
        "installer",
        "banker",
        "keylogger",
        "name verdict",
        "falcon sandbox",
        "beginstring",
        "sha256",
        "sha1",
        "runtime process",
        "segoe ui",
        "internet",
        "null",
        "size",
        "misc attack",
        "unknown",
        "error",
        "span",
        "date",
        "body",
        "refresh",
        "class",
        "generator",
        "critical",
        "tools",
        "look",
        "verify",
        "restart",
        "hybrid",
        "general",
        "click",
        "strings",
        "meta",
        "hiddentears",
        "PyInstaller",
        "ransomware",
        "verified",
        "et",
        "legal entities",
        "phishing",
        "e-devlet",
        "buff achievement tracker",
        "cyber warfare",
        "malware",
        "ransom",
        "malware spreader",
        "et malware",
        "neurevt.a.betabot check in",
        "atlassian",
        "Tulach malware",
        "shell code script",
        "TrojanSpy",
        "remote access",
        "cve",
        "collection",
        "monitoring",
        "cyber threat",
        "cyber stalking",
        "cybercrime",
        "lockbin.1",
        "python connection",
        "elf",
        "redirect",
        "watchhers",
        "tracking",
        "fed",
        "us",
        "blob",
        "vortex",
        "Amazon aes",
        "spyware",
        "banker",
        "synaptics",
        "fraud service",
        "python initiated connection",
        "Trojan_Win_Generic_101",
        "malware trojan",
        "evader",
        "contacted",
        "execution",
        "cobaltstrike",
        "hacking_tool",
        "trojan",
        "cve exploit",
        "red team tools",
        "fireeye",
        "noname057",
        "adult content",
        "pornographer",
        "attack",
        "unsafe",
        "tulach malware",
        "remote attacks",
        "Rat"
      ],
      "references": [
        "1.116.132.182/weblogic_CVE_2020_2551.jar",
        "http://1.116.132.182/.git/HEAD"
      ],
      "public": 1,
      "adversary": "[Unnamed group]",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Verified",
          "display_name": "Verified",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        },
        {
          "id": "Colbalt Strike",
          "display_name": "Colbalt Strike",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HiddenTear",
          "display_name": "HiddenTear",
          "target": null
        },
        {
          "id": "trojan.barys/cobalt",
          "display_name": "trojan.barys/cobalt",
          "target": null
        },
        {
          "id": "NoName057",
          "display_name": "NoName057",
          "target": null
        },
        {
          "id": "Network RAT",
          "display_name": "Network RAT",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1445",
          "name": "Abuse of iOS Enterprise App Signing Key",
          "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1493",
          "name": "Transmitted Data Manipulation",
          "display_name": "T1493 - Transmitted Data Manipulation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1114.002",
          "name": "Remote Email Collection",
          "display_name": "T1114.002 - Remote Email Collection"
        },
        {
          "id": "T1459",
          "name": "Device Unlock Code Guessing or Brute Force",
          "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1110.002",
          "name": "Password Cracking",
          "display_name": "T1110.002 - Password Cracking"
        },
        {
          "id": "T1088",
          "name": "Bypass User Account Control",
          "display_name": "T1088 - Bypass User Account Control"
        },
        {
          "id": "T1583.002",
          "name": "DNS Server",
          "display_name": "T1583.002 - DNS Server"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 40,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 92,
        "FileHash-SHA256": 984,
        "URL": 2184,
        "domain": 274,
        "hostname": 782,
        "CVE": 10
      },
      "indicator_count": 4425,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "599 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65574cb4447c8d87ad85fa75",
      "name": "Masquerading",
      "description": "",
      "modified": "2023-12-17T11:03:45.376000",
      "created": "2023-11-17T11:21:24.343000",
      "tags": [
        "no expiration",
        "filehashsha256",
        "filehashmd5",
        "iocs",
        "url http",
        "expiration",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "create new",
        "blacklist http",
        "laplasclipper",
        "malicious url",
        "cisco umbrella",
        "site",
        "alexa top",
        "blacklist",
        "safe site",
        "malware site",
        "phishing site",
        "malicious site",
        "malware",
        "china unknown",
        "united",
        "unknown",
        "as54994 quantil",
        "cname",
        "nxdomain",
        "as8068",
        "as4134 chinanet",
        "passive dns",
        "domain",
        "next",
        "filehashsha1",
        "service company",
        "servers",
        "ndicator role",
        "title added",
        "active related",
        "pulses url",
        "showing",
        "entries",
        "pulses http",
        "url https",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "report spam",
        "author avatar",
        "created",
        "hour ago",
        "trojanspy",
        "redline",
        "pulses hostname",
        "blacklist https",
        "indicator role",
        "bidid",
        "adid",
        "v4us",
        "v51845481",
        "hostname",
        "http",
        "cisco",
        "umbrella rank",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de summary",
        "frankfurt",
        "main",
        "reverse dns",
        "general full",
        "asn16509",
        "amazon02",
        "resource",
        "protocol h2",
        "security tls",
        "hash",
        "de indicators",
        "domains",
        "hashes",
        "copyright",
        "gmbh version",
        "follow",
        "value",
        "postitem",
        "variables",
        "parameters",
        "systemid object",
        "def function",
        "login",
        "get h2",
        "secrets llc",
        "agreement",
        "the site",
        "content",
        "policy",
        "this site",
        "claims",
        "florida",
        "please",
        "premium",
        "service",
        "restrict",
        "express",
        "media",
        "facebook",
        "twitter",
        "final",
        "first",
        "cloudflarenet",
        "gts ca",
        "software",
        "million",
        "hours ago",
        "chameleon",
        "heur",
        "phishing",
        "riskware",
        "agent",
        "unsafe",
        "opencandy",
        "exploit",
        "mimikatz",
        "iframe",
        "downldr",
        "presenoker",
        "artemis",
        "download",
        "beach research",
        "germany",
        "asn20940",
        "akamaiasn1",
        "threat report",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "alexa",
        "maltiverse",
        "google",
        "qtsas",
        "name value",
        "no data",
        "tag count",
        "count blacklist",
        "pbiptbmvd0k4",
        "glelexoputyh",
        "suppobox",
        "team",
        "bambernek",
        "internet storm",
        "phishtank",
        "phish",
        "trickbot",
        "telecom",
        "bank",
        "ipv4",
        "octoseek report",
        "spam https",
        "tsara brashears",
        "malvertizing",
        "tracking",
        "tagging",
        "spyder",
        "cybercrime",
        "email collection",
        "apple data collection",
        "win32 exe",
        "ms word",
        "document",
        "type name",
        "javascript",
        "network capture",
        "files",
        "detections type",
        "name",
        "ssl certificate",
        "whois whois",
        "tsara brashears",
        "whois record",
        "asn owner",
        "highly targeted",
        "kgs0",
        "kls0",
        "relacionada",
        "family",
        "lolkek",
        "emotet",
        "dark power",
        "wiper",
        "ransomware",
        "cobalt strike",
        "quasar rat",
        "ursnif",
        "remcos",
        "core",
        "redline stealer",
        "bitrat",
        "hacktool",
        "critical",
        "copy",
        "installer",
        "execution",
        "network",
        "communicating",
        "referrer",
        "parent",
        "historical ssl",
        "siblings",
        "resolutions",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "error",
        "file",
        "indicator",
        "script",
        "typeof e",
        "ascii text",
        "appdata",
        "date",
        "windir",
        "span",
        "body",
        "meta",
        "class",
        "generator",
        "info",
        "null",
        "refresh",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "form",
        "footer",
        "html",
        "union",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "threat roundup",
        "contacted",
        "june",
        "july",
        "october",
        "august"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Beach Research",
          "display_name": "Beach Research",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1199",
          "name": "Trusted Relationship",
          "display_name": "T1199 - Trusted Relationship"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        }
      ],
      "industries": [
        "Health",
        "Nutritional",
        "Medical",
        "Medicine"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 103,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 400,
        "FileHash-SHA1": 240,
        "FileHash-SHA256": 6459,
        "hostname": 4845,
        "URL": 11514,
        "CVE": 15,
        "domain": 3179,
        "email": 31
      },
      "indicator_count": 26683,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "854 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65574cbe6bdbe24ecb170b24",
      "name": "Masquerading",
      "description": "",
      "modified": "2023-12-17T11:03:45.376000",
      "created": "2023-11-17T11:21:34.083000",
      "tags": [
        "no expiration",
        "filehashsha256",
        "filehashmd5",
        "iocs",
        "url http",
        "expiration",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "create new",
        "blacklist http",
        "laplasclipper",
        "malicious url",
        "cisco umbrella",
        "site",
        "alexa top",
        "blacklist",
        "safe site",
        "malware site",
        "phishing site",
        "malicious site",
        "malware",
        "china unknown",
        "united",
        "unknown",
        "as54994 quantil",
        "cname",
        "nxdomain",
        "as8068",
        "as4134 chinanet",
        "passive dns",
        "domain",
        "next",
        "filehashsha1",
        "service company",
        "servers",
        "ndicator role",
        "title added",
        "active related",
        "pulses url",
        "showing",
        "entries",
        "pulses http",
        "url https",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "report spam",
        "author avatar",
        "created",
        "hour ago",
        "trojanspy",
        "redline",
        "pulses hostname",
        "blacklist https",
        "indicator role",
        "bidid",
        "adid",
        "v4us",
        "v51845481",
        "hostname",
        "http",
        "cisco",
        "umbrella rank",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de summary",
        "frankfurt",
        "main",
        "reverse dns",
        "general full",
        "asn16509",
        "amazon02",
        "resource",
        "protocol h2",
        "security tls",
        "hash",
        "de indicators",
        "domains",
        "hashes",
        "copyright",
        "gmbh version",
        "follow",
        "value",
        "postitem",
        "variables",
        "parameters",
        "systemid object",
        "def function",
        "login",
        "get h2",
        "secrets llc",
        "agreement",
        "the site",
        "content",
        "policy",
        "this site",
        "claims",
        "florida",
        "please",
        "premium",
        "service",
        "restrict",
        "express",
        "media",
        "facebook",
        "twitter",
        "final",
        "first",
        "cloudflarenet",
        "gts ca",
        "software",
        "million",
        "hours ago",
        "chameleon",
        "heur",
        "phishing",
        "riskware",
        "agent",
        "unsafe",
        "opencandy",
        "exploit",
        "mimikatz",
        "iframe",
        "downldr",
        "presenoker",
        "artemis",
        "download",
        "beach research",
        "germany",
        "asn20940",
        "akamaiasn1",
        "threat report",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "alexa",
        "maltiverse",
        "google",
        "qtsas",
        "name value",
        "no data",
        "tag count",
        "count blacklist",
        "pbiptbmvd0k4",
        "glelexoputyh",
        "suppobox",
        "team",
        "bambernek",
        "internet storm",
        "phishtank",
        "phish",
        "trickbot",
        "telecom",
        "bank",
        "ipv4",
        "octoseek report",
        "spam https",
        "tsara brashears",
        "malvertizing",
        "tracking",
        "tagging",
        "spyder",
        "cybercrime",
        "email collection",
        "apple data collection",
        "win32 exe",
        "ms word",
        "document",
        "type name",
        "javascript",
        "network capture",
        "files",
        "detections type",
        "name",
        "ssl certificate",
        "whois whois",
        "tsara brashears",
        "whois record",
        "asn owner",
        "highly targeted",
        "kgs0",
        "kls0",
        "relacionada",
        "family",
        "lolkek",
        "emotet",
        "dark power",
        "wiper",
        "ransomware",
        "cobalt strike",
        "quasar rat",
        "ursnif",
        "remcos",
        "core",
        "redline stealer",
        "bitrat",
        "hacktool",
        "critical",
        "copy",
        "installer",
        "execution",
        "network",
        "communicating",
        "referrer",
        "parent",
        "historical ssl",
        "siblings",
        "resolutions",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "error",
        "file",
        "indicator",
        "script",
        "typeof e",
        "ascii text",
        "appdata",
        "date",
        "windir",
        "span",
        "body",
        "meta",
        "class",
        "generator",
        "info",
        "null",
        "refresh",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "form",
        "footer",
        "html",
        "union",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "threat roundup",
        "contacted",
        "june",
        "july",
        "october",
        "august"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Beach Research",
          "display_name": "Beach Research",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1199",
          "name": "Trusted Relationship",
          "display_name": "T1199 - Trusted Relationship"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        }
      ],
      "industries": [
        "Health",
        "Nutritional",
        "Medical",
        "Medicine"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 102,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 400,
        "FileHash-SHA1": 240,
        "FileHash-SHA256": 6459,
        "hostname": 4845,
        "URL": 11514,
        "CVE": 15,
        "domain": 3179,
        "email": 31
      },
      "indicator_count": 26683,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "854 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65580c1516990d69644fb3d0",
      "name": "Masquerading",
      "description": "",
      "modified": "2023-12-17T11:03:45.376000",
      "created": "2023-11-18T00:57:57.372000",
      "tags": [
        "no expiration",
        "filehashsha256",
        "filehashmd5",
        "iocs",
        "url http",
        "expiration",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "create new",
        "blacklist http",
        "laplasclipper",
        "malicious url",
        "cisco umbrella",
        "site",
        "alexa top",
        "blacklist",
        "safe site",
        "malware site",
        "phishing site",
        "malicious site",
        "malware",
        "china unknown",
        "united",
        "unknown",
        "as54994 quantil",
        "cname",
        "nxdomain",
        "as8068",
        "as4134 chinanet",
        "passive dns",
        "domain",
        "next",
        "filehashsha1",
        "service company",
        "servers",
        "ndicator role",
        "title added",
        "active related",
        "pulses url",
        "showing",
        "entries",
        "pulses http",
        "url https",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "report spam",
        "author avatar",
        "created",
        "hour ago",
        "trojanspy",
        "redline",
        "pulses hostname",
        "blacklist https",
        "indicator role",
        "bidid",
        "adid",
        "v4us",
        "v51845481",
        "hostname",
        "http",
        "cisco",
        "umbrella rank",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de summary",
        "frankfurt",
        "main",
        "reverse dns",
        "general full",
        "asn16509",
        "amazon02",
        "resource",
        "protocol h2",
        "security tls",
        "hash",
        "de indicators",
        "domains",
        "hashes",
        "copyright",
        "gmbh version",
        "follow",
        "value",
        "postitem",
        "variables",
        "parameters",
        "systemid object",
        "def function",
        "login",
        "get h2",
        "secrets llc",
        "agreement",
        "the site",
        "content",
        "policy",
        "this site",
        "claims",
        "florida",
        "please",
        "premium",
        "service",
        "restrict",
        "express",
        "media",
        "facebook",
        "twitter",
        "final",
        "first",
        "cloudflarenet",
        "gts ca",
        "software",
        "million",
        "hours ago",
        "chameleon",
        "heur",
        "phishing",
        "riskware",
        "agent",
        "unsafe",
        "opencandy",
        "exploit",
        "mimikatz",
        "iframe",
        "downldr",
        "presenoker",
        "artemis",
        "download",
        "beach research",
        "germany",
        "asn20940",
        "akamaiasn1",
        "threat report",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "alexa",
        "maltiverse",
        "google",
        "qtsas",
        "name value",
        "no data",
        "tag count",
        "count blacklist",
        "pbiptbmvd0k4",
        "glelexoputyh",
        "suppobox",
        "team",
        "bambernek",
        "internet storm",
        "phishtank",
        "phish",
        "trickbot",
        "telecom",
        "bank",
        "ipv4",
        "octoseek report",
        "spam https",
        "tsara brashears",
        "malvertizing",
        "tracking",
        "tagging",
        "spyder",
        "cybercrime",
        "email collection",
        "apple data collection",
        "win32 exe",
        "ms word",
        "document",
        "type name",
        "javascript",
        "network capture",
        "files",
        "detections type",
        "name",
        "ssl certificate",
        "whois whois",
        "tsara brashears",
        "whois record",
        "asn owner",
        "highly targeted",
        "kgs0",
        "kls0",
        "relacionada",
        "family",
        "lolkek",
        "emotet",
        "dark power",
        "wiper",
        "ransomware",
        "cobalt strike",
        "quasar rat",
        "ursnif",
        "remcos",
        "core",
        "redline stealer",
        "bitrat",
        "hacktool",
        "critical",
        "copy",
        "installer",
        "execution",
        "network",
        "communicating",
        "referrer",
        "parent",
        "historical ssl",
        "siblings",
        "resolutions",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "error",
        "file",
        "indicator",
        "script",
        "typeof e",
        "ascii text",
        "appdata",
        "date",
        "windir",
        "span",
        "body",
        "meta",
        "class",
        "generator",
        "info",
        "null",
        "refresh",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "form",
        "footer",
        "html",
        "union",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "threat roundup",
        "contacted",
        "june",
        "july",
        "october",
        "august"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Beach Research",
          "display_name": "Beach Research",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1199",
          "name": "Trusted Relationship",
          "display_name": "T1199 - Trusted Relationship"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        }
      ],
      "industries": [
        "Health",
        "Nutritional",
        "Medical",
        "Medicine"
      ],
      "TLP": "white",
      "cloned_from": "65574cb4447c8d87ad85fa75",
      "export_count": 100,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 400,
        "FileHash-SHA1": 240,
        "FileHash-SHA256": 6459,
        "hostname": 4845,
        "URL": 11514,
        "CVE": 15,
        "domain": 3179,
        "email": 31
      },
      "indicator_count": 26683,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "854 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65580c17e69371b34a573f72",
      "name": "Masquerading",
      "description": "",
      "modified": "2023-12-17T11:03:45.376000",
      "created": "2023-11-18T00:57:59.619000",
      "tags": [
        "no expiration",
        "filehashsha256",
        "filehashmd5",
        "iocs",
        "url http",
        "expiration",
        "scan endpoints",
        "all search",
        "otx octoseek",
        "create new",
        "blacklist http",
        "laplasclipper",
        "malicious url",
        "cisco umbrella",
        "site",
        "alexa top",
        "blacklist",
        "safe site",
        "malware site",
        "phishing site",
        "malicious site",
        "malware",
        "china unknown",
        "united",
        "unknown",
        "as54994 quantil",
        "cname",
        "nxdomain",
        "as8068",
        "as4134 chinanet",
        "passive dns",
        "domain",
        "next",
        "filehashsha1",
        "service company",
        "servers",
        "ndicator role",
        "title added",
        "active related",
        "pulses url",
        "showing",
        "entries",
        "pulses http",
        "url https",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "report spam",
        "author avatar",
        "created",
        "hour ago",
        "trojanspy",
        "redline",
        "pulses hostname",
        "blacklist https",
        "indicator role",
        "bidid",
        "adid",
        "v4us",
        "v51845481",
        "hostname",
        "http",
        "cisco",
        "umbrella rank",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de summary",
        "frankfurt",
        "main",
        "reverse dns",
        "general full",
        "asn16509",
        "amazon02",
        "resource",
        "protocol h2",
        "security tls",
        "hash",
        "de indicators",
        "domains",
        "hashes",
        "copyright",
        "gmbh version",
        "follow",
        "value",
        "postitem",
        "variables",
        "parameters",
        "systemid object",
        "def function",
        "login",
        "get h2",
        "secrets llc",
        "agreement",
        "the site",
        "content",
        "policy",
        "this site",
        "claims",
        "florida",
        "please",
        "premium",
        "service",
        "restrict",
        "express",
        "media",
        "facebook",
        "twitter",
        "final",
        "first",
        "cloudflarenet",
        "gts ca",
        "software",
        "million",
        "hours ago",
        "chameleon",
        "heur",
        "phishing",
        "riskware",
        "agent",
        "unsafe",
        "opencandy",
        "exploit",
        "mimikatz",
        "iframe",
        "downldr",
        "presenoker",
        "artemis",
        "download",
        "beach research",
        "germany",
        "asn20940",
        "akamaiasn1",
        "threat report",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "alexa",
        "maltiverse",
        "google",
        "qtsas",
        "name value",
        "no data",
        "tag count",
        "count blacklist",
        "pbiptbmvd0k4",
        "glelexoputyh",
        "suppobox",
        "team",
        "bambernek",
        "internet storm",
        "phishtank",
        "phish",
        "trickbot",
        "telecom",
        "bank",
        "ipv4",
        "octoseek report",
        "spam https",
        "tsara brashears",
        "malvertizing",
        "tracking",
        "tagging",
        "spyder",
        "cybercrime",
        "email collection",
        "apple data collection",
        "win32 exe",
        "ms word",
        "document",
        "type name",
        "javascript",
        "network capture",
        "files",
        "detections type",
        "name",
        "ssl certificate",
        "whois whois",
        "tsara brashears",
        "whois record",
        "asn owner",
        "highly targeted",
        "kgs0",
        "kls0",
        "relacionada",
        "family",
        "lolkek",
        "emotet",
        "dark power",
        "wiper",
        "ransomware",
        "cobalt strike",
        "quasar rat",
        "ursnif",
        "remcos",
        "core",
        "redline stealer",
        "bitrat",
        "hacktool",
        "critical",
        "copy",
        "installer",
        "execution",
        "network",
        "communicating",
        "referrer",
        "parent",
        "historical ssl",
        "siblings",
        "resolutions",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "error",
        "file",
        "indicator",
        "script",
        "typeof e",
        "ascii text",
        "appdata",
        "date",
        "windir",
        "span",
        "body",
        "meta",
        "class",
        "generator",
        "info",
        "null",
        "refresh",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "form",
        "footer",
        "html",
        "union",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "threat roundup",
        "contacted",
        "june",
        "july",
        "october",
        "august"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Beach Research",
          "display_name": "Beach Research",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1199",
          "name": "Trusted Relationship",
          "display_name": "T1199 - Trusted Relationship"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        }
      ],
      "industries": [
        "Health",
        "Nutritional",
        "Medical",
        "Medicine"
      ],
      "TLP": "white",
      "cloned_from": "65574cb4447c8d87ad85fa75",
      "export_count": 103,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 400,
        "FileHash-SHA1": 240,
        "FileHash-SHA256": 6459,
        "hostname": 4845,
        "URL": 11514,
        "CVE": 15,
        "domain": 3179,
        "email": 31
      },
      "indicator_count": 26683,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "854 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f08130783a080ec06bcc6",
      "name": "Apple iOS compromise. CVE Jar",
      "description": "",
      "modified": "2023-11-25T06:03:08.846000",
      "created": "2023-10-30T01:34:11.970000",
      "tags": [
        "apple ios",
        "tsara brashears",
        "unlocker",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "apple phone",
        "shell code",
        "script",
        "spyware",
        "hacktool",
        "installer",
        "banker",
        "keylogger",
        "name verdict",
        "falcon sandbox",
        "beginstring",
        "sha256",
        "sha1",
        "runtime process",
        "segoe ui",
        "internet",
        "null",
        "size",
        "misc attack",
        "unknown",
        "error",
        "span",
        "date",
        "body",
        "refresh",
        "class",
        "generator",
        "critical",
        "tools",
        "look",
        "verify",
        "restart",
        "hybrid",
        "general",
        "click",
        "strings",
        "meta",
        "hiddentears",
        "PyInstaller",
        "ransomware",
        "verified",
        "et",
        "legal entities",
        "phishing",
        "e-devlet",
        "buff achievement tracker",
        "cyber warfare",
        "malware",
        "ransom",
        "malware spreader",
        "et malware",
        "neurevt.a.betabot check in",
        "atlassian",
        "Tulach malware",
        "shell code script",
        "TrojanSpy",
        "remote access",
        "cve",
        "collection",
        "monitoring",
        "cyber threat",
        "cyber stalking",
        "cybercrime",
        "lockbin.1",
        "python connection",
        "elf",
        "redirect",
        "watchhers",
        "tracking",
        "fed",
        "us",
        "blob",
        "vortex",
        "Amazon aes",
        "spyware",
        "banker",
        "synaptics",
        "fraud service",
        "python initiated connection",
        "Trojan_Win_Generic_101",
        "malware trojan",
        "evader",
        "contacted",
        "execution",
        "cobaltstrike",
        "hacking_tool",
        "trojan",
        "cve exploit",
        "red team tools",
        "fireeye",
        "noname057",
        "adult content",
        "pornographer",
        "attack",
        "unsafe",
        "tulach malware",
        "remote attacks",
        "Rat"
      ],
      "references": [
        "1.116.132.182/weblogic_CVE_2020_2551.jar",
        "http://1.116.132.182/.git/HEAD"
      ],
      "public": 1,
      "adversary": "[Unnamed group]",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Verified",
          "display_name": "Verified",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        },
        {
          "id": "Colbalt Strike",
          "display_name": "Colbalt Strike",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HiddenTear",
          "display_name": "HiddenTear",
          "target": null
        },
        {
          "id": "trojan.barys/cobalt",
          "display_name": "trojan.barys/cobalt",
          "target": null
        },
        {
          "id": "NoName057",
          "display_name": "NoName057",
          "target": null
        },
        {
          "id": "Network RAT",
          "display_name": "Network RAT",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1445",
          "name": "Abuse of iOS Enterprise App Signing Key",
          "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1493",
          "name": "Transmitted Data Manipulation",
          "display_name": "T1493 - Transmitted Data Manipulation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1114.002",
          "name": "Remote Email Collection",
          "display_name": "T1114.002 - Remote Email Collection"
        },
        {
          "id": "T1459",
          "name": "Device Unlock Code Guessing or Brute Force",
          "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1110.002",
          "name": "Password Cracking",
          "display_name": "T1110.002 - Password Cracking"
        },
        {
          "id": "T1088",
          "name": "Bypass User Account Control",
          "display_name": "T1088 - Bypass User Account Control"
        },
        {
          "id": "T1583.002",
          "name": "DNS Server",
          "display_name": "T1583.002 - DNS Server"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "653a092e3e9270a3ccff2aa0",
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 92,
        "FileHash-SHA256": 924,
        "URL": 2050,
        "domain": 244,
        "hostname": 771,
        "CVE": 10
      },
      "indicator_count": 4190,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 219,
      "modified_text": "876 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f1db16fe8c699422bfbbc",
      "name": "Apple iOS compromise. CVE Jar",
      "description": "",
      "modified": "2023-11-25T06:03:08.846000",
      "created": "2023-10-30T03:06:25.113000",
      "tags": [
        "apple ios",
        "tsara brashears",
        "unlocker",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "apple phone",
        "shell code",
        "script",
        "spyware",
        "hacktool",
        "installer",
        "banker",
        "keylogger",
        "name verdict",
        "falcon sandbox",
        "beginstring",
        "sha256",
        "sha1",
        "runtime process",
        "segoe ui",
        "internet",
        "null",
        "size",
        "misc attack",
        "unknown",
        "error",
        "span",
        "date",
        "body",
        "refresh",
        "class",
        "generator",
        "critical",
        "tools",
        "look",
        "verify",
        "restart",
        "hybrid",
        "general",
        "click",
        "strings",
        "meta",
        "hiddentears",
        "PyInstaller",
        "ransomware",
        "verified",
        "et",
        "legal entities",
        "phishing",
        "e-devlet",
        "buff achievement tracker",
        "cyber warfare",
        "malware",
        "ransom",
        "malware spreader",
        "et malware",
        "neurevt.a.betabot check in",
        "atlassian",
        "Tulach malware",
        "shell code script",
        "TrojanSpy",
        "remote access",
        "cve",
        "collection",
        "monitoring",
        "cyber threat",
        "cyber stalking",
        "cybercrime",
        "lockbin.1",
        "python connection",
        "elf",
        "redirect",
        "watchhers",
        "tracking",
        "fed",
        "us",
        "blob",
        "vortex",
        "Amazon aes",
        "spyware",
        "banker",
        "synaptics",
        "fraud service",
        "python initiated connection",
        "Trojan_Win_Generic_101",
        "malware trojan",
        "evader",
        "contacted",
        "execution",
        "cobaltstrike",
        "hacking_tool",
        "trojan",
        "cve exploit",
        "red team tools",
        "fireeye",
        "noname057",
        "adult content",
        "pornographer",
        "attack",
        "unsafe",
        "tulach malware",
        "remote attacks",
        "Rat"
      ],
      "references": [
        "1.116.132.182/weblogic_CVE_2020_2551.jar",
        "http://1.116.132.182/.git/HEAD"
      ],
      "public": 1,
      "adversary": "[Unnamed group]",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Verified",
          "display_name": "Verified",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        },
        {
          "id": "Colbalt Strike",
          "display_name": "Colbalt Strike",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HiddenTear",
          "display_name": "HiddenTear",
          "target": null
        },
        {
          "id": "trojan.barys/cobalt",
          "display_name": "trojan.barys/cobalt",
          "target": null
        },
        {
          "id": "NoName057",
          "display_name": "NoName057",
          "target": null
        },
        {
          "id": "Network RAT",
          "display_name": "Network RAT",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1445",
          "name": "Abuse of iOS Enterprise App Signing Key",
          "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1493",
          "name": "Transmitted Data Manipulation",
          "display_name": "T1493 - Transmitted Data Manipulation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1114.002",
          "name": "Remote Email Collection",
          "display_name": "T1114.002 - Remote Email Collection"
        },
        {
          "id": "T1459",
          "name": "Device Unlock Code Guessing or Brute Force",
          "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1110.002",
          "name": "Password Cracking",
          "display_name": "T1110.002 - Password Cracking"
        },
        {
          "id": "T1088",
          "name": "Bypass User Account Control",
          "display_name": "T1088 - Bypass User Account Control"
        },
        {
          "id": "T1583.002",
          "name": "DNS Server",
          "display_name": "T1583.002 - DNS Server"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "653f08130783a080ec06bcc6",
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 92,
        "FileHash-SHA256": 924,
        "URL": 2050,
        "domain": 244,
        "hostname": 771,
        "CVE": 10
      },
      "indicator_count": 4190,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "876 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653a0778872fbe01f36f9e4d",
      "name": "Apple iOS compromise. ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable exe",
      "description": "Targets phone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \nTarget: Tsara Brashears",
      "modified": "2023-11-25T05:02:44.879000",
      "created": "2023-10-26T06:30:16.812000",
      "tags": [
        "apple ios",
        "tsara brashears",
        "unlocker",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "apple phone",
        "shell code",
        "script",
        "spyware",
        "hacktool",
        "installer",
        "banker",
        "keylogger",
        "name verdict",
        "falcon sandbox",
        "beginstring",
        "sha256",
        "sha1",
        "runtime process",
        "segoe ui",
        "internet",
        "null",
        "size",
        "misc attack",
        "unknown",
        "error",
        "span",
        "date",
        "body",
        "refresh",
        "class",
        "generator",
        "critical",
        "tools",
        "look",
        "verify",
        "restart",
        "hybrid",
        "general",
        "click",
        "strings",
        "meta",
        "hiddentears",
        "PyInstaller",
        "ransomware",
        "verified",
        "et",
        "legal entities",
        "phishing",
        "e-devlet",
        "buff achievement tracker",
        "cyber warfare",
        "malware",
        "ransom",
        "malware spreader",
        "et malware",
        "neurevt.a.betabot check in",
        "atlassian",
        "Tulach malware",
        "shell code script",
        "TrojanSpy",
        "remote access",
        "cve",
        "collection",
        "monitoring",
        "cyber threat",
        "cyber stalking",
        "cybercrime",
        "lockbin.1",
        "python connection",
        "elf",
        "redirect",
        "watchhers",
        "tracking",
        "fed",
        "us",
        "blob",
        "vortex",
        "Amazon aes",
        "spyware",
        "banker",
        "synaptics",
        "fraud service",
        "python initiated connection",
        "Trojan_Win_Generic_101",
        "malware trojan",
        "evader",
        "contacted",
        "execution",
        "cobaltstrike",
        "hacking_tool",
        "trojan",
        "cve exploit",
        "red team tools",
        "fireeye"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Verified",
          "display_name": "Verified",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        },
        {
          "id": "Colbalt Strike",
          "display_name": "Colbalt Strike",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HiddenTear",
          "display_name": "HiddenTear",
          "target": null
        },
        {
          "id": "trojan.barys/cobalt",
          "display_name": "trojan.barys/cobalt",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1445",
          "name": "Abuse of iOS Enterprise App Signing Key",
          "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1493",
          "name": "Transmitted Data Manipulation",
          "display_name": "T1493 - Transmitted Data Manipulation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1114.002",
          "name": "Remote Email Collection",
          "display_name": "T1114.002 - Remote Email Collection"
        },
        {
          "id": "T1459",
          "name": "Device Unlock Code Guessing or Brute Force",
          "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1110.002",
          "name": "Password Cracking",
          "display_name": "T1110.002 - Password Cracking"
        },
        {
          "id": "T1088",
          "name": "Bypass User Account Control",
          "display_name": "T1088 - Bypass User Account Control"
        },
        {
          "id": "T1583.002",
          "name": "DNS Server",
          "display_name": "T1583.002 - DNS Server"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 92,
        "FileHash-SHA256": 924,
        "URL": 2007,
        "domain": 243,
        "hostname": 767
      },
      "indicator_count": 4132,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 225,
      "modified_text": "876 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653a078459913ce7eaae6fd1",
      "name": "Apple iOS compromise. ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable exe",
      "description": "Targets phone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \nTarget: Tsara Brashears",
      "modified": "2023-11-25T05:02:44.879000",
      "created": "2023-10-26T06:30:28.765000",
      "tags": [
        "apple ios",
        "tsara brashears",
        "unlocker",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "apple phone",
        "shell code",
        "script",
        "spyware",
        "hacktool",
        "installer",
        "banker",
        "keylogger",
        "name verdict",
        "falcon sandbox",
        "beginstring",
        "sha256",
        "sha1",
        "runtime process",
        "segoe ui",
        "internet",
        "null",
        "size",
        "misc attack",
        "unknown",
        "error",
        "span",
        "date",
        "body",
        "refresh",
        "class",
        "generator",
        "critical",
        "tools",
        "look",
        "verify",
        "restart",
        "hybrid",
        "general",
        "click",
        "strings",
        "meta",
        "hiddentears",
        "PyInstaller",
        "ransomware",
        "verified",
        "et",
        "legal entities",
        "phishing",
        "e-devlet",
        "buff achievement tracker",
        "cyber warfare",
        "malware",
        "ransom",
        "malware spreader",
        "et malware",
        "neurevt.a.betabot check in",
        "atlassian",
        "Tulach malware",
        "shell code script",
        "TrojanSpy",
        "remote access",
        "cve",
        "collection",
        "monitoring",
        "cyber threat",
        "cyber stalking",
        "cybercrime",
        "lockbin.1",
        "python connection",
        "elf",
        "redirect",
        "watchhers",
        "tracking",
        "fed",
        "us",
        "blob",
        "vortex",
        "Amazon aes",
        "spyware",
        "banker",
        "synaptics",
        "fraud service",
        "python initiated connection",
        "Trojan_Win_Generic_101",
        "malware trojan",
        "evader",
        "contacted",
        "execution",
        "cobaltstrike",
        "hacking_tool",
        "trojan",
        "cve exploit",
        "red team tools",
        "fireeye"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Verified",
          "display_name": "Verified",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        },
        {
          "id": "Colbalt Strike",
          "display_name": "Colbalt Strike",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HiddenTear",
          "display_name": "HiddenTear",
          "target": null
        },
        {
          "id": "trojan.barys/cobalt",
          "display_name": "trojan.barys/cobalt",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1445",
          "name": "Abuse of iOS Enterprise App Signing Key",
          "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1493",
          "name": "Transmitted Data Manipulation",
          "display_name": "T1493 - Transmitted Data Manipulation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1114.002",
          "name": "Remote Email Collection",
          "display_name": "T1114.002 - Remote Email Collection"
        },
        {
          "id": "T1459",
          "name": "Device Unlock Code Guessing or Brute Force",
          "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1110.002",
          "name": "Password Cracking",
          "display_name": "T1110.002 - Password Cracking"
        },
        {
          "id": "T1088",
          "name": "Bypass User Account Control",
          "display_name": "T1088 - Bypass User Account Control"
        },
        {
          "id": "T1583.002",
          "name": "DNS Server",
          "display_name": "T1583.002 - DNS Server"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 92,
        "FileHash-SHA256": 924,
        "URL": 2007,
        "domain": 243,
        "hostname": 767
      },
      "indicator_count": 4132,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "876 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653a0784db4f775c260e0eb9",
      "name": "Apple iOS compromise. ASpeakSoft iOS iPhone Unlocker v1.0.36 Multilingual Portable exe",
      "description": "Targets phone unlocked, Total command and control. Dumping, remote access, hidden users, privilege escalation,  malware spreading, tracking, defacement, libel, harassment. \nTarget: Tsara Brashears",
      "modified": "2023-11-25T05:02:44.879000",
      "created": "2023-10-26T06:30:28.584000",
      "tags": [
        "apple ios",
        "tsara brashears",
        "unlocker",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "apple phone",
        "shell code",
        "script",
        "spyware",
        "hacktool",
        "installer",
        "banker",
        "keylogger",
        "name verdict",
        "falcon sandbox",
        "beginstring",
        "sha256",
        "sha1",
        "runtime process",
        "segoe ui",
        "internet",
        "null",
        "size",
        "misc attack",
        "unknown",
        "error",
        "span",
        "date",
        "body",
        "refresh",
        "class",
        "generator",
        "critical",
        "tools",
        "look",
        "verify",
        "restart",
        "hybrid",
        "general",
        "click",
        "strings",
        "meta",
        "hiddentears",
        "PyInstaller",
        "ransomware",
        "verified",
        "et",
        "legal entities",
        "phishing",
        "e-devlet",
        "buff achievement tracker",
        "cyber warfare",
        "malware",
        "ransom",
        "malware spreader",
        "et malware",
        "neurevt.a.betabot check in",
        "atlassian",
        "Tulach malware",
        "shell code script",
        "TrojanSpy",
        "remote access",
        "cve",
        "collection",
        "monitoring",
        "cyber threat",
        "cyber stalking",
        "cybercrime",
        "lockbin.1",
        "python connection",
        "elf",
        "redirect",
        "watchhers",
        "tracking",
        "fed",
        "us",
        "blob",
        "vortex",
        "Amazon aes",
        "spyware",
        "banker",
        "synaptics",
        "fraud service",
        "python initiated connection",
        "Trojan_Win_Generic_101",
        "malware trojan",
        "evader",
        "contacted",
        "execution",
        "cobaltstrike",
        "hacking_tool",
        "trojan",
        "cve exploit",
        "red team tools",
        "fireeye"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Verified",
          "display_name": "Verified",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        },
        {
          "id": "Colbalt Strike",
          "display_name": "Colbalt Strike",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "HiddenTear",
          "display_name": "HiddenTear",
          "target": null
        },
        {
          "id": "trojan.barys/cobalt",
          "display_name": "trojan.barys/cobalt",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1445",
          "name": "Abuse of iOS Enterprise App Signing Key",
          "display_name": "T1445 - Abuse of iOS Enterprise App Signing Key"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1493",
          "name": "Transmitted Data Manipulation",
          "display_name": "T1493 - Transmitted Data Manipulation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1114.002",
          "name": "Remote Email Collection",
          "display_name": "T1114.002 - Remote Email Collection"
        },
        {
          "id": "T1459",
          "name": "Device Unlock Code Guessing or Brute Force",
          "display_name": "T1459 - Device Unlock Code Guessing or Brute Force"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1110.002",
          "name": "Password Cracking",
          "display_name": "T1110.002 - Password Cracking"
        },
        {
          "id": "T1088",
          "name": "Bypass User Account Control",
          "display_name": "T1088 - Bypass User Account Control"
        },
        {
          "id": "T1583.002",
          "name": "DNS Server",
          "display_name": "T1583.002 - DNS Server"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 92,
        "FileHash-SHA256": 924,
        "URL": 2007,
        "domain": 243,
        "hostname": 767
      },
      "indicator_count": 4132,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "876 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://auth.cn-pgcloud.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://auth.cn-pgcloud.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776631393.2626047
}