{
  "type": "URL",
  "indicator": "https://bitcoin.sipa.be/miniscript",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://bitcoin.sipa.be/miniscript",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4011481528,
      "indicator": "https://bitcoin.sipa.be/miniscript",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "687059a339b3b2a79765dbec",
          "name": "inverte",
          "description": "",
          "modified": "2026-02-01T17:53:50.806000",
          "created": "2025-07-11T00:24:03.079000",
          "tags": [],
          "references": [
            "https://github.com/Abjuri5t/SarlackLab/raw/refs/heads/main/IOCs.csv"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 10129,
            "URL": 14767,
            "domain": 3421,
            "hostname": 7022,
            "CVE": 7
          },
          "indicator_count": 35346,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 179,
          "modified_text": "77 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69479bd1714bb9552aeb3623",
          "name": "Cyber trails of malicious actor KillNet by skocherhan",
          "description": "",
          "modified": "2025-12-21T07:03:45.053000",
          "created": "2025-12-21T07:03:45.053000",
          "tags": [],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6758fd5afdfe6960ccda2cca",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 28942,
            "FileHash-SHA256": 2586,
            "hostname": 15671,
            "domain": 9429,
            "CVE": 4
          },
          "indicator_count": 56632,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "119 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68851d56edbe226314c31445",
          "name": "LinuxTsunami - Mirai_Botnet_Malware",
          "description": "[EXE:CPUByteOrder - Little endian]\n\u2022 ELF:Mirai-APD\\ [Trj]\n\u2022 Unix.Trojan.Mirai-1\nIDS Detections: SUSPICIOUS Path to BusyBox TELNET login failed ||\n\u2022 Yara Detections: Mirai_Botnet_Malware ,  SUSP_XORed_Mozilla ,  is__elf ,  Linux_Mirai Alerts dead_host network_icmp tcp_syn_scan nolookup_communication writes_to_stdout ||\n\nInteresting: 162.93.126.142\nLocation: \nUnited States of America\n[ASN:  AS6949 charles schwab & co inc]\n*Unix.Trojan.Mirai-1\n\nAssociated Files: [5e2b1e9f7aa3dbfe8494a1ffd30e8a552f06d47f03e8ce17d4fb3b63c67991a1] \u2022 ELF:Mirai-APD\\ [Trj]\t\t\u2022 Unix.Trojan.Mirai-1 || 5\n\u2022 Backdoor:Linux/Tsunami.C!MTB\nIDS Detections:\nIRC Nick change on non-standard port\nTeamTNT IRC Bot Joining Channel\nIRC Channel JOIN on non-standard port\nIRC authorization message\nYara Detections:\nis__elf ||\n\nLinuxTsunami\nAlerts: \nnetwork_irc\nnolookup_communication\nIP\u2019s Contacted:\n194.31.98.17\nDomains Contacted:\nc6a7d807.vpn.njalla.net\n#hackers #lawfirms #mirai #botnets #remote_control #quasi",
          "modified": "2025-08-25T17:00:22.985000",
          "created": "2025-07-26T18:24:22.495000",
          "tags": [
            "pulse",
            "http",
            "ip address",
            "passive dns",
            "related nids",
            "urls",
            "files location",
            "czechia flag",
            "czechia related",
            "pulses otx",
            "ipv4 add",
            "pulse pulses",
            "files",
            "hosting",
            "czechia asn",
            "as2118",
            "pulses",
            "related tags",
            "port",
            "destination",
            "light",
            "high",
            "tcp syn",
            "meerkat",
            "resolverror",
            "yara detections",
            "malware",
            "icmp traffic",
            "path",
            "copy",
            "pv4 add",
            "pulse submit",
            "url analysis",
            "location united",
            "america flag",
            "united",
            "america asn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "learn",
            "spawns",
            "command",
            "found",
            "defense evasion",
            "t1480 execution",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "sha256",
            "sha1",
            "ascii text",
            "pattern match",
            "mitre att",
            "show technique",
            "null",
            "refresh",
            "body",
            "span",
            "hybrid",
            "local",
            "click",
            "strings",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "google safe",
            "browsing",
            "windows error",
            "april",
            "october",
            "september",
            "sandbox reports",
            "rejectedfailed",
            "timestamp input",
            "message status",
            "actions april",
            "june",
            "august",
            "july",
            "internal error",
            "entries",
            "show",
            "search",
            "backdoor",
            "teamtnt irc",
            "bot joining",
            "intel",
            "notice",
            "irc server",
            "tsunami",
            "domain",
            "creation date",
            "privacy inc",
            "customer",
            "domain add",
            "p address",
            "process details",
            "domains",
            "a domains",
            "script urls",
            "date",
            "status",
            "meta",
            "ov ssl",
            "record value",
            "showing",
            "certificate",
            "hostname add",
            "present may",
            "present jun",
            "present oct",
            "present jul",
            "present mar",
            "present nov",
            "present sep",
            "present feb",
            "next associated",
            "urls show",
            "date checked",
            "url hostname",
            "server response"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 73,
            "FileHash-SHA1": 77,
            "FileHash-SHA256": 404,
            "URL": 647,
            "domain": 124,
            "hostname": 487,
            "CVE": 1,
            "email": 3
          },
          "indicator_count": 1816,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 141,
          "modified_text": "237 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6775b17c488523ee9d290afd",
          "name": "agressive extra",
          "description": "",
          "modified": "2025-03-17T22:57:49.933000",
          "created": "2025-01-01T21:19:56.847000",
          "tags": [],
          "references": [
            "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 35208,
            "URL": 79504,
            "domain": 19527,
            "hostname": 28058,
            "CVE": 9
          },
          "indicator_count": 162306,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 199,
          "modified_text": "397 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6758fd5afdfe6960ccda2cca",
          "name": "Cyber trails of malicious actor KillNet",
          "description": "",
          "modified": "2024-12-11T02:47:54.379000",
          "created": "2024-12-11T02:47:54.379000",
          "tags": [],
          "references": [
            "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 28942,
            "FileHash-SHA256": 2586,
            "hostname": 15671,
            "domain": 9429,
            "CVE": 4
          },
          "indicator_count": 56632,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 180,
          "modified_text": "494 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://github.com/Abjuri5t/SarlackLab/raw/refs/heads/main/IOCs.csv",
        "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules",
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 259170
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/sipa.be",
    "whois": "http://whois.domaintools.com/sipa.be",
    "domain": "sipa.be",
    "hostname": "bitcoin.sipa.be"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "687059a339b3b2a79765dbec",
      "name": "inverte",
      "description": "",
      "modified": "2026-02-01T17:53:50.806000",
      "created": "2025-07-11T00:24:03.079000",
      "tags": [],
      "references": [
        "https://github.com/Abjuri5t/SarlackLab/raw/refs/heads/main/IOCs.csv"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 10129,
        "URL": 14767,
        "domain": 3421,
        "hostname": 7022,
        "CVE": 7
      },
      "indicator_count": 35346,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 179,
      "modified_text": "77 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69479bd1714bb9552aeb3623",
      "name": "Cyber trails of malicious actor KillNet by skocherhan",
      "description": "",
      "modified": "2025-12-21T07:03:45.053000",
      "created": "2025-12-21T07:03:45.053000",
      "tags": [],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6758fd5afdfe6960ccda2cca",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 28942,
        "FileHash-SHA256": 2586,
        "hostname": 15671,
        "domain": 9429,
        "CVE": 4
      },
      "indicator_count": 56632,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "119 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68851d56edbe226314c31445",
      "name": "LinuxTsunami - Mirai_Botnet_Malware",
      "description": "[EXE:CPUByteOrder - Little endian]\n\u2022 ELF:Mirai-APD\\ [Trj]\n\u2022 Unix.Trojan.Mirai-1\nIDS Detections: SUSPICIOUS Path to BusyBox TELNET login failed ||\n\u2022 Yara Detections: Mirai_Botnet_Malware ,  SUSP_XORed_Mozilla ,  is__elf ,  Linux_Mirai Alerts dead_host network_icmp tcp_syn_scan nolookup_communication writes_to_stdout ||\n\nInteresting: 162.93.126.142\nLocation: \nUnited States of America\n[ASN:  AS6949 charles schwab & co inc]\n*Unix.Trojan.Mirai-1\n\nAssociated Files: [5e2b1e9f7aa3dbfe8494a1ffd30e8a552f06d47f03e8ce17d4fb3b63c67991a1] \u2022 ELF:Mirai-APD\\ [Trj]\t\t\u2022 Unix.Trojan.Mirai-1 || 5\n\u2022 Backdoor:Linux/Tsunami.C!MTB\nIDS Detections:\nIRC Nick change on non-standard port\nTeamTNT IRC Bot Joining Channel\nIRC Channel JOIN on non-standard port\nIRC authorization message\nYara Detections:\nis__elf ||\n\nLinuxTsunami\nAlerts: \nnetwork_irc\nnolookup_communication\nIP\u2019s Contacted:\n194.31.98.17\nDomains Contacted:\nc6a7d807.vpn.njalla.net\n#hackers #lawfirms #mirai #botnets #remote_control #quasi",
      "modified": "2025-08-25T17:00:22.985000",
      "created": "2025-07-26T18:24:22.495000",
      "tags": [
        "pulse",
        "http",
        "ip address",
        "passive dns",
        "related nids",
        "urls",
        "files location",
        "czechia flag",
        "czechia related",
        "pulses otx",
        "ipv4 add",
        "pulse pulses",
        "files",
        "hosting",
        "czechia asn",
        "as2118",
        "pulses",
        "related tags",
        "port",
        "destination",
        "light",
        "high",
        "tcp syn",
        "meerkat",
        "resolverror",
        "yara detections",
        "malware",
        "icmp traffic",
        "path",
        "copy",
        "pv4 add",
        "pulse submit",
        "url analysis",
        "location united",
        "america flag",
        "united",
        "america asn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "learn",
        "spawns",
        "command",
        "found",
        "defense evasion",
        "t1480 execution",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "sha256",
        "sha1",
        "ascii text",
        "pattern match",
        "mitre att",
        "show technique",
        "null",
        "refresh",
        "body",
        "span",
        "hybrid",
        "local",
        "click",
        "strings",
        "error",
        "tools",
        "look",
        "verify",
        "restart",
        "google safe",
        "browsing",
        "windows error",
        "april",
        "october",
        "september",
        "sandbox reports",
        "rejectedfailed",
        "timestamp input",
        "message status",
        "actions april",
        "june",
        "august",
        "july",
        "internal error",
        "entries",
        "show",
        "search",
        "backdoor",
        "teamtnt irc",
        "bot joining",
        "intel",
        "notice",
        "irc server",
        "tsunami",
        "domain",
        "creation date",
        "privacy inc",
        "customer",
        "domain add",
        "p address",
        "process details",
        "domains",
        "a domains",
        "script urls",
        "date",
        "status",
        "meta",
        "ov ssl",
        "record value",
        "showing",
        "certificate",
        "hostname add",
        "present may",
        "present jun",
        "present oct",
        "present jul",
        "present mar",
        "present nov",
        "present sep",
        "present feb",
        "next associated",
        "urls show",
        "date checked",
        "url hostname",
        "server response"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 73,
        "FileHash-SHA1": 77,
        "FileHash-SHA256": 404,
        "URL": 647,
        "domain": 124,
        "hostname": 487,
        "CVE": 1,
        "email": 3
      },
      "indicator_count": 1816,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 141,
      "modified_text": "237 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6775b17c488523ee9d290afd",
      "name": "agressive extra",
      "description": "",
      "modified": "2025-03-17T22:57:49.933000",
      "created": "2025-01-01T21:19:56.847000",
      "tags": [],
      "references": [
        "https://sslbl.abuse.ch/blacklist/sslipblacklist_aggressive.rules"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 35208,
        "URL": 79504,
        "domain": 19527,
        "hostname": 28058,
        "CVE": 9
      },
      "indicator_count": 162306,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 199,
      "modified_text": "397 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6758fd5afdfe6960ccda2cca",
      "name": "Cyber trails of malicious actor KillNet",
      "description": "",
      "modified": "2024-12-11T02:47:54.379000",
      "created": "2024-12-11T02:47:54.379000",
      "tags": [],
      "references": [
        "https://raw.githubusercontent.com/securityscorecard/SSC-Threat-Intel-IoCs/master/KillNet-DDoS-Blocklist/proxylist.txt"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 28942,
        "FileHash-SHA256": 2586,
        "hostname": 15671,
        "domain": 9429,
        "CVE": 4
      },
      "indicator_count": 56632,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 180,
      "modified_text": "494 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://bitcoin.sipa.be/miniscript",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://bitcoin.sipa.be/miniscript",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776628722.9995353
}